Networks, devices, and sensors · GraphQL enum

TLSCipherSuite enum

SSL (Secure Sockets Layer) and TLS (Transport Layer Security) Cipher Suites enum in IANA format see OpenSSL to IANA cipher suite mapping.

Values

Enum Value Description

TLS_RSA_WITH_RC4_128_SHA

Rivest Shamir Adleman algorithm (RSA) see RFC 5246 — TLS Protocol Version 1.2. Conclusion: INSECURE.

Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream.

Rivest Cipher 4: IETF has officially prohibited RC4 for use in TLS in RFC 7465. Therefore, it can be considered insecure.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_RSA_WITH_3DES_EDE_CBC_SHA

Rivest Shamir Adleman algorithm (RSA) see RFC 5246 — TLS Protocol Version 1.2. Conclusion: WEAK.

This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

Triple-DES: While Triple-DES is still recognized as a secure symmetric-key encryption, a more and more standardizations bodies and projects decide to deprecate this algorithm. Though not broken, it has been proven to suffer from several vulnerabilities in the past (see sweet32.info).

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_RSA_WITH_AES_128_CBC_SHA

Rivest Shamir Adleman algorithm (RSA) see RFC 5246 — TLS Protocol Version 1.2. Conclusion: WEAK.

Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_RSA_WITH_AES_256_CBC_SHA

Rivest Shamir Adleman algorithm (RSA) see RFC 5246 — TLS Protocol Version 1.2. Conclusion: WEAK.

Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_RSA_WITH_AES_128_CBC_SHA256

Rivest Shamir Adleman algorithm (RSA) see RFC 5246 — TLS Protocol Version 1.2. Conclusion: WEAK.

Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

TLS_RSA_WITH_AES_128_GCM_SHA256

Rivest Shamir Adleman algorithm (RSA) see RFC 5246 — TLS Protocol Version 1.2. Conclusion: WEAK.

Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream.

TLS_RSA_WITH_AES_256_GCM_SHA384

Rivest Shamir Adleman algorithm (RSA) see RFC 5246 — TLS Protocol Version 1.2. Conclusion: WEAK.

Non-ephemeral Key Exchange: This key exchange algorithm does not support Perfect Forward Secrecy (PFS) which is recommended, so attackers cannot decrypt the complete communication stream.

TLS_ECDHE_ECDSA_WITH_RC4_128_SHA

Rivest Cipher 4 with 128bit key (RC4 128) see RFC 8422 — ECC Cipher Suites for TLS. Conclusion: INSECURE.

Rivest Cipher 4: IETF has officially prohibited RC4 for use in TLS in RFC 7465. Therefore, it can be considered insecure.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA

Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: RFC 8422 — ECC Cipher Suites for TLS. Conclusion: WEAK.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA

Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see RFC 8422 — ECC Cipher Suites for TLS. Conclusion: WEAK.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_ECDHE_RSA_WITH_RC4_128_SHA

Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: RFC 8422 — ECC Cipher Suites for TLS. Conclusion: INSECURE.

Rivest Cipher 4: IETF has officially prohibited RC4 for use in TLS in RFC 7465. Therefore, it can be considered insecure.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA

Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: RFC 8422 — ECC Cipher Suites for TLS. Conclusion: WEAK.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

Triple-DES: While Triple-DES is still recognized as a secure symmetric-key encryption, a more and more standardizations bodies and projects decide to deprecate this algorithm. Though not broken, it has been proven to suffer from several vulnerabilities in the past (see sweet32.info).

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA

Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: RFC 8422 — ECC Cipher Suites for TLS. Conclusion: WEAK.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA

Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) for Transport Layer Security (TLS) Versions 1.2 and Earlier see: RFC 8422 — ECC Cipher Suites for TLS. Conclusion: WEAK.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

Secure Hash Algorithm 1: The Secure Hash Algorithm 1 has been proven to be insecure as of 2017 (see shattered.io).

TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256

Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384 Conclusion: WEAK.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256

Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384 Conclusion: WEAK.

Cipher Block Chaining: In 2013, researchers demonstrated a timing attack against several TLS implementations using the CBC encryption algorithm (see isg.rhul.ac.uk). Additionally, the CBC mode is vulnerable to plain-text attacks in TLS 1.0, SSL 3.0 and lower. A fix has been introduced with TLS 1.2 in form of the GCM mode which is not vulnerable to the BEAST attack. GCM should be preferred over CBC.

TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256

Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384 Conclusion: SECURE.

TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256

Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384 Conclusion: RECOMMENDED.

TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384

Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384 Conclusion: SECURE.

TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384

Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: RFC 5289 — TLS Elliptic Curve Cipher Suites with SHA-256/384 Conclusion: RECOMMENDED.

TLS_ECDHE_RSA_WITH_CHACHA20_POLY1305_SHA256

Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: RFC 7905 — ChaCha20-Poly1305 Cipher Suites for TLS Conclusion: SECURE.

TLS_ECDHE_ECDSA_WITH_CHACHA20_POLY1305_SHA256

Transport Layer Security (TLS) Elliptic Curve Diffie-Hellman Ephemeral (ECDHE) see: RFC 7905 — ChaCha20-Poly1305 Cipher Suites for TLS Conclusion: RECOMMENDED.

TLS_AES_128_GCM_SHA256

Transport Layer Security (TLS) Protocol Version 1.3 see RFC 8446 — TLS Protocol Version 1.3 Conclusion: RECOMMENDED.

TLS_AES_256_GCM_SHA384

Transport Layer Security (TLS) Protocol Version 1.3 see RFC 8446 — TLS Protocol Version 1.3 Conclusion: RECOMMENDED.

TLS_CHACHA20_POLY1305_SHA256

Transport Layer Security (TLS) Protocol Version 1.3 see RFC 8446 — TLS Protocol Version 1.3 Conclusion: RECOMMENDED.

TLS_FALLBACK_SCSV

Signaling cipher suite value used to prevent protocol downgrade attacks.

UNKNOWN

The cipher suite is not recognized.

Used by

  • TLS type: Reports on SSL (Secure Sockets Layer) and TLS (Transport Layer Security).

Example

Example

"TLS_RSA_WITH_RC4_128_SHA"