-
-
Notifications
You must be signed in to change notification settings - Fork 86
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
all IANA cipher suites #135
Comments
Hi,
Does this answer your question? Please keep in mind that the list of ciphers with their attributes is compiled manually. This does not restrict to test for ciphers not listed (see dump above), you always may check for the complete range with: |
just check the IANA list (didn't change since ages). It's now possible to do: Am I right that your test purpose is to check if non-IANA ciphers are supported? |
No actually, I want to test any possible cipher suite on each TLS/SSL protocol version to see which cipher suite is permitted by the server and hence which TLS/SSL protocol version is permited also. A brute force technique. So the tool I would need, has to have all the cipher suite that could be used on a TLS/SSL communication, it includes therefore the IANA cipher suites and the non-IANA cipher suites, in total I found 376 cipher suites that could be used (but maybe I forgot some?). |
yes for sure: Add the However, I rarely found a target which responded to ciphers not in If you're testing targets with a proprietry SSL/TLS-stack, we know of some strange and unexpected behaviours. Then you need to look at the more advanced options for --ssl-*: |
Ok. I'm going to try that, thanks. |
Hello, does O-Saft uses all IANA cipher suites ?
Thanks.
The text was updated successfully, but these errors were encountered: