aboutsummaryrefslogtreecommitdiffstats
path: root/src/libtls/tls_crypto.c
diff options
context:
space:
mode:
authorMartin Willi <martin@revosec.ch>2010-09-02 19:27:37 +0200
committerMartin Willi <martin@revosec.ch>2010-09-02 19:33:08 +0200
commitef0a8e5892311e2e96488ffa317912b29979ad46 (patch)
tree2fe6e88b488390fedee59ee7a7af1f4f89847ad3 /src/libtls/tls_crypto.c
parentf14358a9b52768f1eae36bf71b22af8d321c9795 (diff)
downloadstrongswan-ef0a8e5892311e2e96488ffa317912b29979ad46.tar.bz2
strongswan-ef0a8e5892311e2e96488ffa317912b29979ad46.tar.xz
Add DHE enabled RSA variants to the supported TLS suites
Diffstat (limited to 'src/libtls/tls_crypto.c')
-rw-r--r--src/libtls/tls_crypto.c36
1 files changed, 36 insertions, 0 deletions
diff --git a/src/libtls/tls_crypto.c b/src/libtls/tls_crypto.c
index 6360591cc..954b20526 100644
--- a/src/libtls/tls_crypto.c
+++ b/src/libtls/tls_crypto.c
@@ -375,6 +375,42 @@ typedef struct {
* Mapping suites to a set of algorithms
*/
static suite_algs_t suite_algs[] = {
+ { TLS_DHE_RSA_WITH_AES_128_CBC_SHA,
+ HASH_SHA1, PRF_HMAC_SHA1, MODP_2048_BIT,
+ AUTH_HMAC_SHA1_160, ENCR_AES_CBC, 16
+ },
+ { TLS_DHE_RSA_WITH_AES_128_CBC_SHA256,
+ HASH_SHA256, PRF_HMAC_SHA2_256, MODP_3072_BIT,
+ AUTH_HMAC_SHA2_256_256, ENCR_AES_CBC, 16
+ },
+ { TLS_DHE_RSA_WITH_AES_256_CBC_SHA,
+ HASH_SHA1, PRF_HMAC_SHA1, MODP_3072_BIT,
+ AUTH_HMAC_SHA1_160, ENCR_AES_CBC, 32
+ },
+ { TLS_DHE_RSA_WITH_AES_256_CBC_SHA256,
+ HASH_SHA256, PRF_HMAC_SHA2_256, MODP_4096_BIT,
+ AUTH_HMAC_SHA2_256_256, ENCR_AES_CBC, 32
+ },
+ { TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA,
+ HASH_SHA1, PRF_HMAC_SHA1, MODP_2048_BIT,
+ AUTH_HMAC_SHA1_160, ENCR_CAMELLIA_CBC, 16
+ },
+ { TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA256,
+ HASH_SHA256, PRF_HMAC_SHA2_256, MODP_3072_BIT,
+ AUTH_HMAC_SHA2_256_256, ENCR_CAMELLIA_CBC, 16
+ },
+ { TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA,
+ HASH_SHA1, PRF_HMAC_SHA1, MODP_3072_BIT,
+ AUTH_HMAC_SHA1_160, ENCR_CAMELLIA_CBC, 32
+ },
+ { TLS_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA256,
+ HASH_SHA256, PRF_HMAC_SHA2_256, MODP_4096_BIT,
+ AUTH_HMAC_SHA2_256_256, ENCR_CAMELLIA_CBC, 32
+ },
+ { TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA,
+ HASH_SHA1, PRF_HMAC_SHA1, MODP_2048_BIT,
+ AUTH_HMAC_SHA1_160, ENCR_3DES, 0
+ },
{ TLS_RSA_WITH_AES_128_CBC_SHA,
HASH_SHA1, PRF_HMAC_SHA1, MODP_NONE,
AUTH_HMAC_SHA1_160, ENCR_AES_CBC, 16