Hi,

In OpenSSL 1.0.2, and 1.0.1i, 3DES-CBC’s bit-strength was changed from 168 to 
112, which makes sense. However, it is still considered a HIGH-strength cipher.

RC4 is listed as having a bit strength of MEDIUM, and is a 128-bit strength 
cipher (kinda).

This is a bit contradictory. According to the OpenSSL cipher documentation, 
HIGH refers to 128-bit, or stronger, ciphers.

Should 3DES ciphers be moved to the MEDIUM category?

--
-Todd Short
// tsh...@akamai.com<mailto:tsh...@akamai.com>
// "One if by land, two if by sea, three if by the Internet."

-- 
openssl-dev mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

Reply via email to