How to set cipher's order for SSL-TLS connections?
I want to set another cipher's order for SSL-TLS connections. How can I do it?
所有回复 (10)
You can't do that.
The server sends a list of supported ciphers and Firefox processes this list.
You can only disable ciphers that you do not want to use and enable them in case you get an SSL error (no overlap)
由cor-el于
>You can only disable ciphers that you do not want to use and enable them Thank you for answer. I found how to disable ciphers in about:config.
>The server sends a list of supported ciphers and Firefox processes this list. No. ClientHello goes first. That's why ciphers' order of client matter for server. First cipher suits are more preferred.
Of course, Server can choose any what it wants according to it's preferences - for example perfomance. But not all servers, that's why the order may be significative.
cor-el, can you see Bad Firefox implementation of SSL/TLS (error: ssl_error_no_cypher_overlap, RC4 and 3DES are turned OFF)
See also:
- http://mxr.mozilla.org/chromium/source/src/net/ssl/ssl_cipher_suite_names.cc
- http://mxr.mozilla.org/chromium/source/src/net/ssl/ssl_cipher_suite_names.h
Note that you may need to enable TLS 1.2 or later to see the other cipher suites.
See also these other two threads (now locked) created by the OP:
What can I do as user with that source code? :)
TLS 1.2 is enabled. I have security.tls.version.max=3
You must leave at least one question from those, because it's another question: Why in Firefox v25 (last release) there are no cipher suits with SHA-256?
I see many cipher suits on page source code with cipher suits
Why only some of them NOW in Firefox! Why others are absent! That's why I said "Firefox have bad implementation of SSL/TLS". Don't you agree? If so, please answer to my question.
由rasj于
I'm not sure if that is the correct for Firefox.
These might be more accurate:
- http://mxr.mozilla.org/mozilla-central/source/security/nss/lib/ssl/sslproto.h
- http://mxr.mozilla.org/mozilla-central/source/security/nss/lib/ssl/ssl3con.c
Do you have a link to a website that supports SHA256 cipher suites?
I'm not sure how Firefox would report those in the security tab in Tools > Page Info > Security.
>These might be more accurate
These links are more correct. First were for Chromium. I see that there are SHA256 cipher suits but they are not present in the current release version of Firefox - v25. Why? :)
>Do you have a link to a website that supports SHA256 cipher suites?
Many and long ago.
由rasj于
https://www.ssllabs.com/ssltest/viewMyClient.html
Gives you an example of its preferred Cipher Suits. I would like to arrange them from strongest to weakest.
The only browser that has them all in correct order OOB is SRWare Iron, but I am not saying i would recommend using it. [cross platform]
I would love to see firefox settings to rearrange or customize. I want it to remain my primary browser but unless I can change these I may end up switching.