What crypto suite options does Email Security offer (Strong, Normal, Weak) when TLS over SMTP is enabled?
The OpenSSL Cipherstring selectors are:
Strong | HIGH:!MD5:!SSLv2:!aNULL:!eNULL:@STRENGTH |
Normal | HIGH:MEDIUM:-3DES:!SSLv2:!aNULL:!eNULL:@STRENGTH:3DES |
Weak | ALL:!EXPORT:!SSLv2:!aNULL:!eNULL:@STRENGTH |
In versions 8.3, the complete set of ciphers are:
OpenSSL Cipherstring Name | TLS | Key Exchange | Authenticator | Cipher | HMAC | PFS? |
Strong | ||||||
ECDHE-RSA-AES256-GCM-SHA384 | v1.2 | ECDH | RSA | AESGCM(256) | AEAD | Yes |
ECDHE-ECDSA-AES256-GCM-SHA384 | v1.2 | ECDH | ECDSA | AESGCM(256) | AEAD | Yes |
ECDHE-RSA-AES256-SHA384 | v1.2 | ECDH | RSA | AES(256) | SHA384 | Yes |
ECDHE-ECDSA-AES256-SHA384 | v1.2 | ECDH | ECDSA | AES(256) | SHA384 | Yes |
ECDHE-RSA-AES256-SHA | v1 | ECDH | RSA | AES(256) | SHA1 | Yes |
ECDHE-ECDSA-AES256-SHA | v1 | ECDH | ECDSA | AES(256) | SHA1 | Yes |
ECDH-RSA-AES256-GCM-SHA384 | v1.2 | ECDH/RSA | ECDH | AESGCM(256) | AEAD | |
ECDH-ECDSA-AES256-GCM-SHA384 | v1.2 | ECDH/ECDSA | ECDH | AESGCM(256) | AEAD | |
ECDH-RSA-AES256-SHA384 | v1.2 | ECDH/RSA | ECDH | AES(256) | SHA384 | |
ECDH-ECDSA-AES256-SHA384 | v1.2 | ECDH/ECDSA | ECDH | AES(256) | SHA384 | |
ECDH-RSA-AES256-SHA | v1 | ECDH/RSA | ECDH | AES(256) | SHA1 | |
ECDH-ECDSA-AES256-SHA | v1 | ECDH/ECDSA | ECDH | AES(256) | SHA1 | |
AES256-GCM-SHA384 | v1.2 | RSA | RSA | AESGCM(256) | AEAD | |
AES256-SHA256 | v1.2 | RSA | RSA | AES(256) | SHA256 | |
AES256-SHA | v1 | RSA | RSA | AES(256) | SHA1 | |
CAMELLIA256-SHA | v1 | RSA | RSA | Camellia(256) | SHA1 | |
ECDHE-RSA-AES128-GCM-SHA256 | v1.2 | ECDH | RSA | AESGCM(128) | AEAD | Yes |
ECDHE-ECDSA-AES128-GCM-SHA256 | v1.2 | ECDH | ECDSA | AESGCM(128) | AEAD | Yes |
ECDHE-RSA-AES128-SHA256 | v1.2 | ECDH | RSA | AES(128) | SHA256 | Yes |
ECDHE-ECDSA-AES128-SHA256 | v1.2 | ECDH | ECDSA | AES(128) | SHA256 | Yes |
ECDHE-RSA-AES128-SHA | v1 | ECDH | RSA | AES(128) | SHA1 | Yes |
ECDHE-ECDSA-AES128-SHA | v1 | ECDH | ECDSA | AES(128) | SHA1 | Yes |
ECDH-RSA-AES128-GCM-SHA256 | v1.2 | ECDH/RSA | ECDH | AESGCM(128) | AEAD | |
ECDH-ECDSA-AES128-GCM-SHA256 | v1.2 | ECDH/ECDSA | ECDH | AESGCM(128) | AEAD | |
ECDH-RSA-AES128-SHA256 | v1.2 | ECDH/RSA | ECDH | AES(128) | SHA256 | |
ECDH-ECDSA-AES128-SHA256 | v1.2 | ECDH/ECDSA | ECDH | AES(128) | SHA256 | |
ECDH-RSA-AES128-SHA | v1 | ECDH/RSA | ECDH | AES(128) | SHA1 | |
ECDH-ECDSA-AES128-SHA | v1 | ECDH/ECDSA | ECDH | AES(128) | SHA1 | |
AES128-GCM-SHA256 | v1.2 | RSA | RSA | AESGCM(128) | AEAD | |
AES128-SHA256 | v1.2 | RSA | RSA | AES(128) | SHA256 | |
AES128-SHA | v1 | RSA | RSA | AES(128) | SHA1 | |
CAMELLIA128-SHA | v1 | RSA | RSA | Camellia(128) | SHA1 | |
ECDHE-RSA-DES-CBC3-SHA | v1 | ECDH | RSA | 3DES(168) | SHA1 | Yes |
ECDHE-ECDSA-DES-CBC3-SHA | v1 | ECDH | ECDSA | 3DES(168) | SHA1 | Yes |
EDH-RSA-DES-CBC3-SHA | v1 | DH | RSA | 3DES(168) | SHA1 | Yes |
EDH-DSS-DES-CBC3-SHA | v1 | DH | DSS | 3DES(168) | SHA1 | Yes |
ECDH-RSA-DES-CBC3-SHA | v1 | ECDH/RSA | ECDH | 3DES(168) | SHA1 | |
ECDH-ECDSA-DES-CBC3-SHA | v1 | ECDH/ECDSA | ECDH | 3DES(168) | SHA1 | |
DES-CBC3-SHA | v1 | RSA | RSA | 3DES(168) | SHA1 | |
Normal | ||||||
SEED-SHA | v1 | RSA | RSA | SEED(128) | SHA1 | |
ECDHE-RSA-RC4-SHA | v1 | ECDH | RSA | RC4(128) | SHA1 | Yes |
ECDHE-ECDSA-RC4-SHA | v1 | ECDH | ECDSA | RC4(128) | SHA1 | Yes |
ECDH-RSA-RC4-SHA | v1 | ECDH/RSA | ECDH | RC4(128) | SHA1 | |
ECDH-ECDSA-RC4-SHA | v1 | ECDH/ECDSA | ECDH | RC4(128) | SHA1 | |
Weak | ||||||
EDH-RSA-DES-CBC-SHA | v1 | DH | RSA | DES(56) | SHA1 | Yes |
EDH-DSS-DES-CBC-SHA | v1 | DH | DSS | DES(56) | SHA1 | Yes |
DES-CBC-SHA | v1 | RSA | RSA | DES(56) | SHA1 | |
| RC4-SHA1 | v1 | RSA | RSA | RC4(128) | SHA1 |
|
| RC4-MD5 | v1 | RSA | RSA | RC4(128) | MD5 |
|
Notes: