
Ciphers Used with SSL
Appendix K
Introduction to SSL
803
Table K-1
Cipher Suites Supported by the SSL Protocol That Use the RSA Key-Exchange Algorithm
Strength Category and
Recommended Use
Cipher Suites
Strongest Cipher Suite
Permitted for deployments within
the United States only. This cipher
suite is appropriate for banks and
other institutions that handle highly
sensitive data.
Red Hat
Console does not support
this cipher suite.
Triple DES With 168-Bit Encryption and SHA-1 Message Authentication
Triple DES is the strongest cipher supported by SSL, but it is not as fast as
RC4. Triple DES uses a key three times as long as the key for standard DES.
Because the key size is so large, there are more possible keys than for any other
cipher—approximately 3.7 * 10
50
.
This cipher suite is FIPS-compliant.
Both SSL 2.0 and SSL 3.0 support this cipher suite.
Strong Cipher Suites
Permitted for deployments within
the United States only. These
cipher suites support encryption
that is strong enough for most
business or government needs.
RC4 With 128-Bit Encryption and MD5 Message Authentication
Because the RC4 and RC2 ciphers have 128-bit encryption, they are the second
strongest next to Triple DES (Data Encryption Standard), with 168-bit
encryption. RC4 and RC2 128-bit encryption permits approximately 3.4 * 10
38
possible keys, making them very difficult to crack. RC4 ciphers are the fastest
of the supported ciphers.
Both SSL 2.0 and SSL 3.0 support this cipher suite.
Red Hat
Console supports only the SSL 3.0 version of this cipher suite.
RC2 With 128-Bit Encryption and MD5 Message Authentication
Because the RC4 and RC2 ciphers have 128-bit encryption, they are the second
strongest next to Triple DES (Data Encryption Standard), with 168-bit
encryption. RC4 and RC2 128-bit encryption permits approximately 3.4 * 10
38
possible keys, making them very difficult to crack. RC2 ciphers are slower
than RC4 ciphers.
This cipher suite is supported by SSL 2.0 but not by SSL 3.0.
Red Hat
Console does not support this cipher suite.
DES With 56-Bit Encryption and SHA-1 Message Authentication
DES is stronger than 40-bit encryption, but not as strong as 128-bit encryption.
DES 56-bit encryption permits approximately 7.2 * 10
16
possible keys.
This cipher suite is FIPS-compliant.
Both SSL 2.0 and SSL 3.0 support this cipher suite, except that SSL 2.0 uses
MD5 rather than SHA-1 for message authentication.
Red Hat
Console does not support this cipher suite.
Summary of Contents for CERTIFICATE 7.1 ADMINISTRATOR
Page 1: ...Administrator s Guide Red Hat Certificate System Version7 1 September 2005 ...
Page 22: ...22 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 128: ...Cloning a CA 128 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 368: ...ACL Reference 368 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 460: ...Constraints Reference 460 Red Hat Certificate System Administrator s Guide September 2005 ...
Page 592: ...CRL Extension Reference 592 Red Hat Certificate System Administrator s Guide September 2005 ...