Move 3DES from HIGH to MEDIUM
authorRich Salz <rsalz@openssl.org>
Thu, 5 May 2016 21:08:41 +0000 (17:08 -0400)
committerRich Salz <rsalz@openssl.org>
Thu, 5 May 2016 21:31:53 +0000 (17:31 -0400)
Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
CHANGES
ssl/s3_lib.c

diff --git a/CHANGES b/CHANGES
index 7aececbd837b824187db8086283e53f826892f35..3d91a6bc0f04758ace56abae3a88a802c35ff963 100644 (file)
--- a/CHANGES
+++ b/CHANGES
@@ -4,6 +4,8 @@
 
  Changes between 1.0.2g and 1.1.0  [xx XXX xxxx]
 
+  *) Triple-DES ciphers have been moved from HIGH to MEDIUM.
+
   *) To enable users to have their own config files and build file templates,
      Configure looks in the directory indicated by the environment variable
      OPENSSL_LOCAL_CONFIG_DIR as well as the in-source Configurations/
index fc2aac890e11977af08d802de26d9371ee59f11a..9064abb7ce3e382ce8d5987f35a4a98add78ee14 100644 (file)
@@ -208,7 +208,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH | SSL_FIPS,
+     SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -223,7 +223,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS,
+     SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -238,7 +238,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH | SSL_FIPS,
+     SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -253,7 +253,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS,
+     SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -960,7 +960,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH | SSL_FIPS,
+     SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1020,7 +1020,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH | SSL_FIPS,
+     SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1080,7 +1080,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_NOT_DEFAULT | SSL_HIGH | SSL_FIPS,
+     SSL_NOT_DEFAULT | SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1293,7 +1293,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH | SSL_FIPS,
+     SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1338,7 +1338,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH | SSL_FIPS,
+     SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1383,7 +1383,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH | SSL_FIPS,
+     SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1699,7 +1699,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH | SSL_FIPS,
+     SSL_MEDIUM | SSL_FIPS,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1823,7 +1823,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH,
+     SSL_MEDIUM,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1838,7 +1838,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_HIGH,
+     SSL_MEDIUM,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,
@@ -1853,7 +1853,7 @@ static SSL_CIPHER ssl3_ciphers[] =
      SSL_SHA1,
      SSL3_VERSION, TLS1_2_VERSION,
      DTLS1_VERSION, DTLS1_2_VERSION,
-     SSL_NOT_DEFAULT | SSL_HIGH,
+     SSL_NOT_DEFAULT | SSL_MEDIUM,
      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
      112,
      168,