Forum Discussion

NetworkTeam_178's avatar
NetworkTeam_178
Icon for Nimbostratus rankNimbostratus
10 years ago

Cipher Suite Ordering

I need to order my ciphers in a very specific way.

Using this command 'tmm --clientciphers 'ECDHE+AES-GCM:ECDHE+AES:'

I get;

   ID  SUITE                            BITS PROT    METHOD  CIPHER  MAC     KEYX
  1. 49200 ECDHE-RSA-AES256-GCM-SHA384 256 TLS1.2 Native AES-GCM SHA384 ECDHE_RSA
  2. 49199 ECDHE-RSA-AES128-GCM-SHA256 128 TLS1.2 Native AES-GCM SHA256 ECDHE_RSA
  3. 49192 ECDHE-RSA-AES256-SHA384 256 TLS1.2 Native AES SHA384 ECDHE_RSA
  4. 49172 ECDHE-RSA-AES256-CBC-SHA 256 TLS1 Native AES SHA ECDHE_RSA
  5. 49172 ECDHE-RSA-AES256-CBC-SHA 256 TLS1.1 Native AES SHA ECDHE_RSA
  6. 49172 ECDHE-RSA-AES256-CBC-SHA 256 TLS1.2 Native AES SHA ECDHE_RSA
  7. 49191 ECDHE-RSA-AES128-SHA256 128 TLS1.2 Native AES SHA256 ECDHE_RSA
  8. 49171 ECDHE-RSA-AES128-CBC-SHA 128 TLS1 Native AES SHA ECDHE_RSA
  9. 49171 ECDHE-RSA-AES128-CBC-SHA 128 TLS1.1 Native AES SHA ECDHE_RSA
  10. 49171 ECDHE-RSA-AES128-CBC-SHA 128 TLS1.2 Native AES SHA ECDHE_RSA

What I need, however, is;

  1. ECDHE-RSA-AES256-GCM-SHA384
  2. ECDHE-RSA-AES128-GCM-SHA256
  3. ECDHE-RSA-AES256-SHA384
  4. ECDHE-RSA-AES128-SHA256
  5. ECDHE-RSA-AES256-CBC-SHA
  6. ECDHE-RSA-AES128-CBC-SHA
  7. AES256-GCM-SHA384
  8. AES128-GCM-SHA256
  9. AES256-SHA256
  10. AES128-SHA256
  11. AES256-SHA
  12. AES128-SHA

Which means moving line 7 in the original to line 4.

How can I specify the EXACT order I want them in?

Thanks in advance

3 Replies

No RepliesBe the first to reply