-
Notifications
You must be signed in to change notification settings - Fork 456
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Full Server Ciphersuite Order Preference Detection #338
Comments
I have some C code that does this, would sslyze be open to integrating it? |
I have a PR with a green build up for this, #339, but I haven't been able to get any feedback on it. |
Sorry, I haven't had time to look at this yet. |
I'm hoping to finally get to this on the next release. For now I've removed the "preferred cipher suite" functionality as it was too buggy. When implementing cipher suite order detection, the following behavior will have to be considered: #456. |
I got asked about this recently, so here's an update : I've kind of given up on adding server cipher order preference, for a couple reasons:
|
In order to verify certain aspects of a given server's TLS configuration, e.g., full Forward Secrecy support, sslyze should be able to detect a server's full cipher suite order preference, for those that have them.
The text was updated successfully, but these errors were encountered: