Skip to content

Identify TLS 1.3 ciphers by OpenSSL name#3023

Merged
drwetter merged 1 commit intotestssl:3.3devfrom
dcooper16:identity_ossl_tls13_ciphers
Apr 17, 2026
Merged

Identify TLS 1.3 ciphers by OpenSSL name#3023
drwetter merged 1 commit intotestssl:3.3devfrom
dcooper16:identity_ossl_tls13_ciphers

Conversation

@dcooper16
Copy link
Copy Markdown
Collaborator

Describe your changes

This PR changes the way that TLS 1.3 ciphers are identified by the OpenSSL names. To the degree possible, rather than checking for prefixes that have historically been used in various versions of OpenSSL and LibreSSL, the cipher name is checked against the known list of TLS 1.3 cipher suites that $OPENSSL supports.

In the few places in which the cipher suite name to be checked may not be supported by $OPENSSL, a check for the prefix "TLS_" is also used.

What is your pull request about?

  • Bug fix
  • Improvement
  • New feature (adds functionality)
  • Breaking change (bug fix, feature or improvement that would cause existing functionality to not work as expected)
  • Typo fix
  • Documentation update
  • Update of other files

If it's a code change please check the boxes which are applicable

  • For the main program: My edits contain no tabs, indentation is five spaces and any line endings do not contain any blank chars
  • I've read CONTRIBUTING.md and Coding_Convention.md
  • I have tested this fix or improvement against >=2 hosts and I couldn't spot a problem
  • I have tested this new feature against >=2 hosts which show this feature and >=2 host which does not (in order to avoid side effects) . I couldn't spot a problem
  • For the new feature I have made corresponding changes to the documentation and / or to help()
  • If it's a bigger change: I added myself to CREDITS.md (alphabetical order) and the change to CHANGELOG.md

This commit changes the way that TLS 1.3 ciphers are identified by the OpenSSL names. To the degree possible, rather than checking for prefixes that have historically been used in various versions of OpenSSL and LibreSSL, the cipher name being checked against the known list of TLS 1.3 cipher suites that $OPENSSL supports.

In the few places in which the cipher suite name to be checked may not be supported by $OPENSSL, a check for the prefix "TLS_" is also used.
@drwetter drwetter merged commit 7c47d8a into testssl:3.3dev Apr 17, 2026
4 checks passed
@drwetter
Copy link
Copy Markdown
Collaborator

Thanks!

@dcooper16 dcooper16 deleted the identity_ossl_tls13_ciphers branch April 18, 2026 18:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants