tls-crypto: Filter TLS cipher suites by min/max version

There is no point proposing legacy (or future) cipher suites depending on
the proposed TLS versions. It was actually possible to negotiate and use
cipher suites only defined for TLS 1.2 with earlier TLS versions.
This commit is contained in:
Tobias Brunner
2021-02-12 11:45:44 +01:00
parent 436571b2f0
commit 281766c5e6
3 changed files with 88 additions and 72 deletions
+3 -1
View File
@@ -615,9 +615,11 @@ tls_crypto_t *tls_crypto_create(tls_t *tls, tls_cache_t *cache);
* Get a list of all supported TLS cipher suites.
*
* @param null include supported NULL encryption suites
* @param version TLS version
* @param suites pointer to allocated suites array, to free(), or NULL
* @return number of suites supported
*/
int tls_crypto_get_supported_suites(bool null, tls_cipher_suite_t **suites);
int tls_crypto_get_supported_suites(bool null, tls_version_t version,
tls_cipher_suite_t **suites);
#endif /** TLS_CRYPTO_H_ @}*/