3 ms·
Thanks, this is helpful. Which CBC suites work in TLS 1.1, but not 1.0? These are my test results: https://www.ssllabs.com/ssltest/analyze.html?d=forkly.com ht
by hiroprot 13y ago
Thanks, this is helpful. Which CBC suites work in TLS 1.1, but not 1.0?
These are my test results: https://www.ssllabs.com/ssltest/analyze.html?d=forkly.com https://www.ssllabs.com/ssltest/analyze.html?d=forkly.com
- ivanr 13y agoIn general, I don't think the protocol specifications call for some suites to be allowed with certain protocol and some not to. (There are some exceptions, when weak suites need to be deprecated.) In practice, it comes down to how library developers have implemented them. For example, in OpenSSL, you have SSL v2 suites, TLS 1.2 suites, and >= SSL v3 suites. I don't think there are any TLS 1.1-only suites.
- hiroprot 13y agoOkay, then my current config is probably as good as it gets for now. Thanks for the help :)