On Thu, Dec 16, 1999 at 05:29:15PM -0000, Oliver King wrote:
> So far, using some simple home-brewed test programs, I've successfully
> managed to establish connections using EDH ciphers such as
> EDH-RSA-DES-CBC-SHA by using the appropriate cert/key files and setting up
> temp DH params using SSL_CTX_set_tmp_dh().
>
> My first question is about the ADH cipher suites. Try as I might, I cannot
> get a successful connection using any ADH cipher, e.g. ADH-DES-CBC-SHA. The
> server always fails in SSL_accept() and gives the following output from
> ERR_print_errors_fp():
>
> 420:error:1408A0C1:SSL routines:SSL3_GET_CLIENT_HELLO:no shared
> cipher:.\ssl\s3_srvr.c:714:
>
> Is there anything special I should be doing to allow ADH to work?
Please check the list of supported ciphers with "openssl ciphers". You might
note, that the ADH ciphers are not listed. The reason is, that the default
cipher selection string is (see ssl.h)
"ALL:!ADH:RC4+RSA:+HIGH:+MEDIUM:+LOW:+SSLv2:+EXP"
with "!ADH" removing the ADH ciphers.
You might need to use the SSL_set_cipher_list() call to change the list
of available ciphers including ADH ciphers before you can use them.
(s_server has the -ciphers option, please check there for an example on how
to call it.)
Best regards,
Lutz
--
Lutz Jaenicke [EMAIL PROTECTED]
BTU Cottbus http://www.aet.TU-Cottbus.DE/personen/jaenicke/
Lehrstuhl Allgemeine Elektrotechnik Tel. +49 355 69-4129
Universitaetsplatz 3-4, D-03044 Cottbus Fax. +49 355 69-4153
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [EMAIL PROTECTED]
Automated List Manager [EMAIL PROTECTED]