[Cryptography] What TLS ciphersuites are still OK?

Yaron Sheffer yaronf.ietf at gmail.com
Tue Sep 10 02:00:07 EDT 2013


Hi Hanno,

Please send any comments on this draft to the TLS Working Group mailing 
list, tls at ietf.org.

Thanks,
	Yaron

On 09/10/2013 12:14 AM, Hanno Böck wrote:
> On Mon, 9 Sep 2013 17:29:24 +0100
> Ben Laurie <ben at links.org> wrote:
>
>> Perry asked me to summarise the status of TLS a while back ...
>> luckily I don't have to because someone else has:
>>
>> http://tools.ietf.org/html/draft-sheffer-tls-bcp-00
>>
>> In short, I agree with that draft. And the brief summary is: there's
>> only one ciphersuite left that's good, and unfortunately its only
>> available in TLS 1.2:
>>
>> TLS_DHE_RSA_WITH_AES_128_GCM_SHA256
>
> I don't really see from the document why the authors discourage
> ECDHE-suites and AES-256. Both should be okay and we end up with four
> suites:

[...]


More information about the cryptography mailing list