Welcome! Log In Create A New Profile

Advanced

Use of boringssl equal-preference cipher groups with nginx

Alex
August 18, 2014 03:20AM
Hi,

I have successfully compiled nginx/1.7.4 with boringssl. One thing I am
not sure if it's possible already is to take advantage of
equal-preference cipher groups that Boringssl supports. For reference:

https://www.imperialviolet.org/2014/02/27/tlssymmetriccrypto.html

https://boringssl.googlesource.com/boringssl/+/858a88daf27975f67d9f63e18f95645be2886bfb%5E!/

"... new concept of an equal-preference group: a set of cipher suites in
the server's preference order which are all “equally good”. When
choosing a cipher suite using the server preferences, the server finds
its most preferable cipher suite that the client also supports and, if
that is in an equal preference group, picks whichever member of the
group is the client's most preferable. For example, Google servers have
a cipher suite preference that includes AES-GCM and ChaCha20-Poly1305
cipher suites in an equal preference group at the top of the preference
list. So if the client supports any cipher suite in that group, then the
server will pick whichever was most preferable for the client."

Would this already work with nginx' ssl_ciphers parameter or would nginx
require further patching to support such grouping parameter?

Alex

_______________________________________________
nginx mailing list
nginx@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx
Subject Author Posted

Use of boringssl equal-preference cipher groups with nginx

Alex August 18, 2014 03:20AM

Re: Use of boringssl equal-preference cipher groups with nginx

Alex August 23, 2014 02:40PM

Re: Use of boringssl equal-preference cipher groups with nginx

George August 23, 2014 06:37PM



Sorry, only registered users may post in this forum.

Click here to login

Online Users

Guests: 205
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready