X-Git-Url: https://www.bearssl.org/gitweb//home/git/?p=BoarSSL;a=blobdiff_plain;f=conf%2Fbearssl.json;h=ce2f9bf941bb978233e374c2f524ad0ad655b826;hp=d46f34972f29e2db9a63b732c562a2ba6f36feb3;hb=HEAD;hpb=0703319f56ad16f1b0e0632842c41b6a8ebc11e7 diff --git a/conf/bearssl.json b/conf/bearssl.json index d46f349..ce2f9bf 100644 --- a/conf/bearssl.json +++ b/conf/bearssl.json @@ -16,6 +16,10 @@ "ECDHE_RSA_WITH_AES_128_GCM_SHA256", "ECDHE_ECDSA_WITH_AES_256_GCM_SHA384", "ECDHE_RSA_WITH_AES_256_GCM_SHA384", + "ECDHE_ECDSA_WITH_AES_128_CCM", + "ECDHE_ECDSA_WITH_AES_256_CCM", + "ECDHE_ECDSA_WITH_AES_128_CCM_8", + "ECDHE_ECDSA_WITH_AES_256_CCM_8", "ECDHE_ECDSA_WITH_AES_128_CBC_SHA256", "ECDHE_RSA_WITH_AES_128_CBC_SHA256", "ECDHE_ECDSA_WITH_AES_256_CBC_SHA384", @@ -34,6 +38,10 @@ "RSA_WITH_AES_128_GCM_SHA256", "RSA_WITH_AES_256_GCM_SHA384", + "RSA_WITH_AES_128_CCM", + "RSA_WITH_AES_256_CCM", + "RSA_WITH_AES_128_CCM_8", + "RSA_WITH_AES_256_CCM_8", "RSA_WITH_AES_128_CBC_SHA256", "RSA_WITH_AES_256_CBC_SHA256", "RSA_WITH_AES_128_CBC_SHA", @@ -245,6 +253,17 @@ "comment" : "Peer should forget session. Peer should close and reconnect.", "reconnect" : "peer", "forget" : "peer" + }, + { + "name" : "tls12SuiteWithOlder", + "comment" : "Server selects a TLS-1.2 specific cipher suite with TLS-1.1; the client should refuse.", + "clientOnly" : "true", + "expectedExitCode" : 1, + "expectedFailure" : "Unexpected transport closure", + "quirks" : { + "forceVersion" : "TLS11", + "forceTls12CipherSuite" : "true" + } } ] }