mirror of
https://github.com/guanzhi/GmSSL.git
synced 2026-05-30 14:42:36 +08:00
Remove some ciphers
This commit is contained in:
16
Configure
16
Configure
@@ -312,9 +312,9 @@ $config{sdirs} = [
|
||||
"buffer", "bio", "stack", "lhash", "rand", "err",
|
||||
"evp", "asn1", "pem", "x509", "x509v3", "conf", "txt_db", "pkcs7", "pkcs12", "comp", "ocsp", "ui",
|
||||
"cms", "ts", "srp", "cmac", "ct", "async", "kdf",
|
||||
"sm3", "base58", "sms4", "zuc", "serpent", "speck", "kdf2", "ffx", "otp",
|
||||
"ecies", "sm2", "paillier", "ec2", "sm9", "bfibe", "bb1ibe",
|
||||
"gmapi", "skf", "sdf", "saf", "sof"
|
||||
"sm3", "base58", "sms4", "zuc", "kdf2", "otp",
|
||||
"ecies", "sm2", "paillier", "sm9",
|
||||
"gmapi", "skf", "sdf"
|
||||
];
|
||||
|
||||
# Known TLS and DTLS protocols
|
||||
@@ -421,8 +421,6 @@ my @disablables = (
|
||||
"otp",
|
||||
"gmapi",
|
||||
"ec2",
|
||||
"bfibe",
|
||||
"bb1ibe",
|
||||
"sm9",
|
||||
"sdf",
|
||||
"skf",
|
||||
@@ -433,8 +431,6 @@ my @disablables = (
|
||||
"rsa",
|
||||
"pem",
|
||||
"pkcs7",
|
||||
"serpent",
|
||||
"speck",
|
||||
"base58",
|
||||
"java",
|
||||
"ca",
|
||||
@@ -480,7 +476,6 @@ our %disabled = ( # "what" => "comment"
|
||||
"skfeng" => "default",
|
||||
"sdfeng" => "default",
|
||||
"gmieng" => "default",
|
||||
"speck" => "default",
|
||||
);
|
||||
|
||||
# Note: => pair form used for aesthetics, not to truly make a hash table
|
||||
@@ -499,15 +494,12 @@ my @disable_cascades = (
|
||||
"dtls" => [ @dtls ],
|
||||
|
||||
"sm3" => [ "sm2" ],
|
||||
"sdf" => [ "saf" ],
|
||||
"saf" => [ "sof" ],
|
||||
|
||||
# SSL 3.0, (D)TLS 1.0 and TLS 1.1 require MD5 and SHA
|
||||
"md5" => [ "ssl", "tls1", "tls1_1", "dtls1", "engine" ],
|
||||
# current pkcs12 rfc only define sha1/des bag
|
||||
"sha" => [ "ssl", "tls1", "tls1_1", "dtls1", "engine", "rsa", "dh", "dsa", "ocsp", "ct", "srp", "ts", "ec2"],
|
||||
"sha" => [ "ssl", "tls1", "tls1_1", "dtls1", "engine", "rsa", "dh", "dsa", "ocsp", "ct", "srp", "ts"],
|
||||
"aes" => [ "engine" ],
|
||||
"ec2" => [ "sm9", "bfibe", "bb1ibe" ],
|
||||
|
||||
# Additionally, SSL 3.0 requires either RSA or DSA+DH
|
||||
sub { $disabled{rsa}
|
||||
|
||||
Reference in New Issue
Block a user