46 • Configuration HP NonStop SSL Reference Manual
Speci-
fier
RFC Algo Name OpenSSL Name KEX Enc Mac
192.13
TLS_ECDH_RSA_WITH_3DES
_EDE_CBC_SHA
ECDH-RSA-DES-
CBC3-SHA
ECDH_RSA
3DES_EDE_CB
C
SHA
192.14
TLS_ECDH_RSA_WITH_AES_
128_CBC_SHA
ECDH-RSA-
AES128-SHA
ECDH_RSA AES_128_CBC SHA
192.15
TLS_ECDH_RSA_WITH_AES_
256_CBC_SHA
ECDH-RSA-
AES256-SHA
ECDH_RSA AES_256_CBC SHA
192.16
TLS_ECDHE_RSA_WITH_NUL
L_SHA
ECDHE-RSA-NULL-
SHA
ECDHE_RSA NULL SHA
192.17
TLS_ECDHE_RSA_WITH_RC4
_128_SHA
ECDHE-RSA-RC4-
SHA
ECDHE_RSA RC4_128 SHA
192.18
TLS_ECDHE_RSA_WITH_3DE
S_EDE_CBC_SHA
ECDHE-RSA-DES-
CBC3-SHA
ECDHE_RSA
3DES_EDE_CB
C
SHA
192.19
TLS_ECDHE_RSA_WITH_AES
_128_CBC_SHA
ECDHE-RSA-
AES128-SHA
ECDHE_RSA AES_128_CBC SHA
192.20
TLS_ECDHE_RSA_WITH_AES
_256_CBC_SHA
ECDHE-RSA-
AES256-SHA
ECDHE_RSA AES_256_CBC SHA
192.21
TLS_ECDH_anon_WITH_NULL
_SHA
AECDH-NULL-SHA ECDH_anon NULL SHA
192.22
TLS_ECDH_anon_WITH_RC4_
128_SHA
AECDH-RC4-SHA ECDH_anon RC4_128 SHA
192.23
TLS_ECDH_anon_WITH_3DES
_EDE_CBC_SHA
AECDH-DES-CBC3-
SHA
ECDH_anon
3DES_EDE_CB
C
SHA
192.24
TLS_ECDH_anon_WITH_AES_
128_CBC_SHA
AECDH-AES128-
SHA
ECDH_anon AES_128_CBC SHA
192.25
TLS_ECDH_anon_WITH_AES_
256_CBC_SHA
AECDH-AES256-
SHA
ECDH_anon AES_256_CBC SHA
Default
If omitted, NonStop SSL will use the high security ciphers and the RC4 ciphers, i.e. currently:
ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:DHE-RSA-AES256-SHA:DHE-DSS-AES256-
SHA:DHE-RSA-CAMELLIA256-SHA:DHE-DSS-CAMELLIA256-SHA:AECDH-AES256-SHA:ECDH-RSA-
AES256-SHA:ECDH-ECDSA-AES256-SHA:AES256-SHA:CAMELLIA256-SHA:ECDHE-RSA-DES-CBC3-
SHA:ECDHE-ECDSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:EDH-DSS-DES-CBC3-SHA:AECDH-DES-
CBC3-SHA:ECDH-RSA-DES-CBC3-SHA:ECDH-ECDSA-DES-CBC3-SHA:DES-CBC3-SHA:DES-CBC3-
MD5:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:DHE-RSA-AES128-SHA:DHE-DSS-AES128-
SHA:DHE-RSA-CAMELLIA128-SHA:DHE-DSS-CAMELLIA128-SHA:AECDH-AES128-SHA:ECDH-RSA-
AES128-SHA:ECDH-ECDSA-AES128-SHA:AES128-SHA:CAMELLIA128-SHA:ECDHE-RSA-RC4-SHA:ECDHE-
ECDSA-RC4-SHA:AECDH-RC4-SHA:ECDH-RSA-RC4-SHA:ECDH-ECDSA-RC4-SHA:RC4-SHA:RC4-MD5:RC4-
MD5:EXP-RC4-MD5:EXP-RC4-MD5
Example
CIPHERSUITES 0.53,0.47
Considerations
• Please note that the default CIPHERSUITES are subject to change in order to make sure that only the most
secure ciphers are used by default.
• When running as an SSL client, CIPHERSUITES specifies the cipher suites that should be allowed in order of
preference (favorite choice first). During the SSL handshake, HP NonStop SSL will present the list of cipher