-
Allow the application to control which TLS versions and cipher suites are used for a particular socket.
TLS version and cipher configuration should be available in all TLS-based XCM transports (TLS…
-
Hi.
> There's another issue why I believe in general the result maybe not reliable: for some cipher suites you would need to provide TLS extensions or specific values in those extensions, otherwise t…
kylak updated
4 months ago
-
kangle hosts模块,443s的https访问 Client Hello中alpn没有包含h2,是不支持h2回源吗?
是否应当支持http的h2回源,和https的h2回源
比如chrome浏览器,握手阶段会和服务器声明支持h2,kangle在回源的时候,应该和源站服务器声明alpn(application_layer_protocol_negotiation)
![image](h…
-
### Is your feature request related to a problem? Please describe.
We have security and audit requirements to scan for weak ciphers and insecure/obsolete TLS/SSL versions enabled on sites. There is s…
-
### Is your feature request related to a problem? Please describe.
We ran into an issue when using perf-test with a RabbitMQ-Cluster that uses ECDSA TLS certificates.
As far as we found out, only RS…
-
Seems like Cloudflare has gradually started to enable Encrypted ClientHello support. You can see it on `rutracker.org` and `bo0om.ru` for example.
ECH was instroduced on Cloudflare several years ag…
-
- With issues:
- Use the search tool before opening a new issue.
- Please provide source code and commit sha if you found a bug.
- Review existing issues and provide feedback or react to them…
-
(1) Deltek: Was on a call to review their mTLS settings for their Helidon setup and ADB connection
(2) Sibashis Chatterjee: ADB connectivity using cipher suites. Helped with the connection properties…
-
We currently do ad-hoc key derivation for finite field DH.
- Check whether the parameters are properly chosen.
- Figure out what to do for EC.
- Probably implement key derivation as a special mod…
-
An up-to-date list of the cipher suites that should be supported for EAP-TLS must be provided so that the relevant SFR can be updated.