TLS_RSA_WITH_AES_128_CBC_SHA and SSL_RSA_WITH_AES_128_CBC_SHA

Is there any difference between these cipher suites? They look the same, but the first three letters are different.

I mean TLS_RSA_WITH_AES_128_CBC_SHA and SSL_RSA_WITH_AES_128_CBC_SHA.

+4
source share
1 answer

IANA maintains a registry of TLS encryption sets in TLS Parameters . In SSL / TLS, the cipher suite is defined by two octets.

TLS_RSA_WITH_AES_128_CBC_SHA 0x00,0x2F RFC 3268, AES Ciphersuites TLS. TLS 1.0 RFC 2246. RFC 5246, (TLS) 1.2 .

IANA SSL_RSA_WITH_AES_128_CBC_SHA. SSL 3.0. RFC 6101, SSL ( SSL) 3.0. , , RFC 3268.

: SSL IETF. ., , RFC 5746, 4.5:

SSLv3 IETF (. [SSLv3]), TLS TLS- SSLv3.

OpenSSL TLS_RSA_WITH_AES_128_CBC_SHA - AES128-SHA . OpenSSL SSL_RSA_WITH_AES_128_CBC_SHA. . ciphers(1).

TLSv1 SSLv3 AES128-SHA.

$ openssl s_client -tls1 -connect google.com:443 -cipher "AES128-SHA"
CONNECTED(00000003)
depth=2 C = US, O = GeoTrust Inc., CN = GeoTrust Global CA
verify error:num=20:unable to get local issuer certificate
verify return:0
---
Certificate chain
 0 s:/C=US/ST=California/L=Mountain View/O=Google Inc/CN=*.google.com
   i:/C=US/O=Google Inc/CN=Google Internet Authority G2
 1 s:/C=US/O=Google Inc/CN=Google Internet Authority G2
   i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
 2 s:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
   i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority
...
SSL-Session:
    Protocol  : TLSv1
    Cipher    : AES128-SHA
...

$ openssl s_client -ssl3 -connect google.com:443 -cipher "AES128-SHA"
CONNECTED(00000003)
depth=2 C = US, O = GeoTrust Inc., CN = GeoTrust Global CA
verify error:num=20:unable to get local issuer certificate
verify return:0
---
Certificate chain
 0 s:/C=US/ST=California/L=Mountain View/O=Google Inc/CN=*.google.com
   i:/C=US/O=Google Inc/CN=Google Internet Authority G2
 1 s:/C=US/O=Google Inc/CN=Google Internet Authority G2
   i:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
 2 s:/C=US/O=GeoTrust Inc./CN=GeoTrust Global CA
   i:/C=US/O=Equifax/OU=Equifax Secure Certificate Authority
...
SSL-Session:
    Protocol  : SSLv3
    Cipher    : AES128-SHA
...

SSL_RSA_WITH_AES_128_CBC_SHA ​​ SSLv3 , RFC 3268. , .

: RSA , AES , CBC , SHA HAMC .. (SSLv3 vs. TLS 1.0 ).

+9

Source: https://habr.com/ru/post/1545227/


All Articles