Ciphers Used with SSL
Appendix
K
Introduction to SSL
801
Table K-2
Cipher Suites Supported by Netscape When Using Fortezza for SSL 3.0
Strength Category and
Recommended Use
Cipher Suites
Strong Fortezza Cipher Suites
Permitted for deployments
within the United States only.
These cipher suites support
encryption that is strong
enough for most business or
government needs.
Netscape Console does not
support these cipher suites.
RC4 With 128-bit Encryption and SHA-1 Message Authentication
Like RC4 with 128-bit encryption and MD5 message authentication,
this cipher is one of the second strongest ciphers after Triple DES. It
permits approximately 3.4 * 10
38
possible keys, making it very difficult
to crack.
This cipher suite is supported by SSL 3.0 but not by SSL 2.0.
RC4 With SKIPJACK 80-Bit Encryption and SHA-1 Message
Authentication
The SKIPJACK cipher is a classified symmetric-key cryptographic
algorithm implemented in Fortezza-compliant hardware. Some
SKIPJACK implementations support key escrow using the Law
Enforcement Access Field (LEAF). The most recent implementations do
not.
This cipher suite is supported by SSL 3.0 but not by SSL 2.0.
Weakest Fortezza Cipher Suite
This cipher suite provides
authentication and tamper
detection but no encryption.
Server administrators must be
careful about enabling it,
however, because data sent
using this cipher suite is not
encrypted and may be accessed
by eavesdroppers.
Netscape Console does not
these cipher suites.
No Encryption, SHA-1 Message Authentication Only
This cipher uses SHA-1 message authentication to detect tampering.
This cipher suite is supported by SSL 3.0 but not by SSL 2.0.
Содержание Certificate Management System 6.1
Страница 1: ...Administrator s Guide Netscape Certificate Management System Version6 1 February 2003...
Страница 28: ...Documentation 28 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 68: ...Support for Open Standards 68 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 82: ...Uninstalling CMS 82 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 166: ...How a Registration Manager Works 166 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 382: ...ACL Reference 382 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 566: ...Managing Policy Plug in Modules 566 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 710: ...1 3 Organization Security Policies 710 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 716: ...Object Identifiers 716 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 762: ...DNs in Certificate Management System 762 Netscape Certificate Management System Administrator s Guide February 2003...
Страница 794: ...Managing Certificates 794 Managing Servers with Netscape Console December 2001...
Страница 810: ...The SSL Handshake 810 Managing Servers with Netscape Console December 2001...
Страница 828: ...828 Netscape Certificate Management System Administrator s Guide February 2003...