ECDHE 算法 DHE 算法由于计算性能不佳,因为需要做大量的乘法,为了提升 DHE 算法的性能,所以就出现了现在广泛用于密钥交换算法 —— ECDHE 算法。 ECDHE 算法是在 DHE 算法的基础上利用了ECC 椭圆曲线特性,可以用更少的计算量计算出公钥,以及最终的会话密钥。 小红和小明使用 ECDHE 密钥交换算法的过程: 双方事先确...
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P256 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P384 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA TLS_DHE_RSA_WITH_AES_128_CBC_SHA TLS_RSA_WI...
V var TLS_DHE_DSS_WITH_AES_256_GCM_SHA384: SSLCipherSuite V var TLS_DHE_PSK_WITH_3DES_EDE_CBC_SHA: SSLCipherSuite V var TLS_DHE_PSK_WITH_AES_128_CBC_SHA: SSLCipherSuite V var TLS_DHE_PSK_WITH_AES_128_CBC_SHA256: SSLCipherSuite V var TLS_DHE_PSK_WITH_AES_128_GCM_SHA256: SSLCipher...
TLS_DH_anon_WITH_3DES_EDE_CBC_SHA27 代表TLS_DH_anon_WITH_3DES_EDE_CBC_SHA 加密套件。 TLS_DH_anon_WITH_AES_128_CBC_SHA52 代表TLS_DH_anon_WITH_AES_128_CBC_SHA 加密套件。 TLS_DH_anon_WITH_AES_128_CBC_SHA256108 代表TLS_DH_anon_WITH_AES_128_CBC_SHA256 加密套件。
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA✓✓✓✗✗ TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA✓✓✓✗✗ TLS_DHE_RSA_WITH_AES_256_GCM_SHA384✓✗✗✗✗ TLS_DHE_RSA_WITH_AES_128_GCM_SHA256✓✗✗✗✗ TLS_DHE_RSA_WITH_AES_256_CBC_SHA✓✗✗✗✗ ...
TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384 ecc证书 (2)在1的安全要求下,考虑效率,因为DHE算法效率低,通常不建议。则满足前向安全,禁用CBC,保证高效率推荐的算法套如下所示: TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256 TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 ...
TLS_DHE_RSA_WITH_AES_256_GCM_SHA384是TLS 1.2 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256是TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384是TLS 1.2 TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256是TLS 1.2 TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384是TLS 1.2 ...
TlsCipherSuite.TLS_DHE_DSS_WITH_AES_128_GCM_SHA256, TlsCipherSuite.TLS_DHE_DSS_WITH_AES_256_GCM_SHA384, TlsCipherSuite.TLS_PSK_WITH_AES_128_GCM_SHA256, TlsCipherSuite.TLS_PSK_WITH_AES_256_GCM_SHA384, TlsCipherSuite.TLS_DHE_PSK_WITH_AES_128_GCM_SHA256, ...
TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA_P384 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P256 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA_P384 TLS_DHE_RSA_WITH_AES_256_GCM_SHA384 TLS_DHE_RSA_WITH_AES_128_GCM_SHA256 TLS_DHE_RSA_WITH_AES_256_CBC_SHA ...
TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256(0xc029)Cipher Suite: TLS_DHE_RSA_WITH_AES_128_CBC_SHA256(0x0067)Cipher Suite: TLS_DHE_DSS_WITH_AES_128_CBC_SHA256(0x0040)Cipher Suite: TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA(0xc009)Cipher Suite: TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA(0xc013)Ci...