| 1234567891011121314151617181920212223242526272829303132333435363738394041424344454647484950515253545556575859606162636465666768697071727374757677787980818283848586878889909192939495969798991001011021031041051061071081091101111121131141151161171181191201211221231241251261271281291301311321331341351361371381391401411421431441451461471481491501511521531541551561571581591601611621631641651661671681691701711721731741751761771781791801811821831841851861871881891901911921931941951961971981992002012022032042052062072082092102112122132142152162172182192202212222232242252262272282292302312322332342352362372382392402412422432442452462472482492502512522532542552562572582592602612622632642652662672682692702712722732742752762772782792802812822832842852862872882892902912922932942952962972982993003013023033043053063073083093103113123133143153163173183193203213223233243253263273283293303313323333343353363373383393403413423433443453463473483493503513523533543553563573583593603613623633643653663673683693703713723733743753763773783793803813823833843853863873883893903913923933943953963973983994004014024034044054064074084094104114124134144154164174184194204214224234244254264274284294304314324334344354364374384394404414424434444454464474484494504514524534544554564574584594604614624634644654664674684694704714724734744754764774784794804814824834844854864874884894904914924934944954964974984995005015025035045055065075085095105115125135145155165175185195205215225235245255265275285295305315325335345355365375385395405415425435445455465475485495505515525535545555565575585595605615625635645655665675685695705715725735745755765775785795805815825835845855865875885895905915925935945955965975985996006016026036046056066076086096106116126136146156166176186196206216226236246256266276286296306316326336346356366376386396406416426436446456466476486496506516526536546556566576586596606616626636646656666676686696706716726736746756766776786796806816826836846856866876886896906916926936946956966976986997007017027037047057067077087097107117127137147157167177187197207217227237247257267277287297307317327337347357367377387397407417427437447457467477487497507517527537547557567577587597607617627637647657667677687697707717727737747757767777787797807817827837847857867877887897907917927937947957967977987998008018028038048058068078088098108118128138148158168178188198208218228238248258268278288298308318328338348358368378388398408418428438448458468478488498508518528538548558568578588598608618628638648658668678688698708718728738748758768778788798808818828838848858868878888898908918928938948958968978988999009019029039049059069079089099109119129139149159169179189199209219229239249259269279289299309319329339349359369379389399409419429439449459469479489499509519529539549559569579589599609619629639649659669679689699709719729739749759769779789799809819829839849859869879889899909919929939949959969979989991000100110021003100410051006100710081009101010111012101310141015101610171018101910201021102210231024102510261027102810291030103110321033103410351036103710381039104010411042104310441045104610471048104910501051105210531054105510561057105810591060106110621063106410651066106710681069107010711072107310741075107610771078107910801081108210831084108510861087108810891090109110921093109410951096109710981099110011011102110311041105110611071108110911101111111211131114111511161117111811191120112111221123112411251126112711281129113011311132113311341135113611371138113911401141114211431144114511461147114811491150115111521153115411551156115711581159116011611162116311641165116611671168116911701171117211731174117511761177117811791180118111821183118411851186118711881189119011911192119311941195119611971198119912001201120212031204120512061207120812091210121112121213121412151216121712181219122012211222122312241225122612271228122912301231123212331234123512361237123812391240124112421243124412451246124712481249125012511252125312541255125612571258125912601261126212631264126512661267126812691270127112721273127412751276127712781279128012811282128312841285128612871288128912901291129212931294129512961297129812991300130113021303130413051306130713081309131013111312131313141315131613171318131913201321132213231324132513261327132813291330133113321333133413351336133713381339134013411342134313441345134613471348134913501351135213531354135513561357135813591360136113621363136413651366136713681369137013711372137313741375137613771378137913801381138213831384138513861387138813891390139113921393139413951396139713981399140014011402140314041405140614071408140914101411141214131414141514161417141814191420142114221423142414251426142714281429143014311432143314341435143614371438143914401441144214431444144514461447144814491450145114521453145414551456145714581459146014611462146314641465146614671468146914701471147214731474147514761477147814791480148114821483148414851486148714881489149014911492149314941495149614971498149915001501150215031504150515061507150815091510151115121513151415151516151715181519152015211522152315241525152615271528152915301531153215331534153515361537153815391540154115421543154415451546154715481549155015511552155315541555155615571558155915601561156215631564156515661567156815691570157115721573157415751576157715781579158015811582158315841585158615871588158915901591159215931594159515961597159815991600160116021603160416051606160716081609161016111612161316141615161616171618161916201621162216231624162516261627162816291630163116321633163416351636163716381639164016411642164316441645164616471648164916501651165216531654165516561657165816591660166116621663166416651666166716681669167016711672167316741675167616771678167916801681168216831684168516861687168816891690169116921693169416951696169716981699170017011702170317041705170617071708170917101711171217131714171517161717171817191720172117221723172417251726172717281729173017311732173317341735173617371738173917401741174217431744174517461747174817491750175117521753175417551756175717581759176017611762176317641765176617671768176917701771177217731774177517761777177817791780178117821783178417851786178717881789179017911792179317941795179617971798179918001801180218031804180518061807180818091810181118121813181418151816181718181819182018211822182318241825182618271828182918301831183218331834183518361837183818391840184118421843184418451846184718481849185018511852185318541855185618571858185918601861186218631864186518661867186818691870187118721873187418751876187718781879188018811882188318841885188618871888188918901891189218931894189518961897189818991900190119021903190419051906190719081909191019111912191319141915191619171918191919201921192219231924192519261927192819291930193119321933193419351936193719381939194019411942194319441945194619471948194919501951195219531954195519561957195819591960196119621963196419651966196719681969197019711972197319741975197619771978197919801981198219831984198519861987198819891990199119921993199419951996199719981999200020012002200320042005200620072008200920102011201220132014201520162017201820192020202120222023202420252026202720282029203020312032203320342035203620372038203920402041204220432044204520462047204820492050205120522053205420552056205720582059206020612062206320642065206620672068206920702071207220732074207520762077207820792080208120822083208420852086208720882089209020912092209320942095209620972098209921002101210221032104210521062107210821092110211121122113211421152116211721182119212021212122212321242125212621272128212921302131213221332134213521362137213821392140214121422143214421452146214721482149215021512152215321542155215621572158215921602161216221632164216521662167216821692170217121722173217421752176217721782179218021812182218321842185218621872188218921902191219221932194219521962197219821992200220122022203220422052206220722082209221022112212221322142215221622172218221922202221222222232224222522262227222822292230223122322233223422352236223722382239224022412242224322442245224622472248224922502251225222532254225522562257225822592260226122622263226422652266226722682269227022712272227322742275227622772278227922802281228222832284228522862287228822892290229122922293229422952296229722982299230023012302230323042305230623072308230923102311231223132314231523162317231823192320232123222323232423252326232723282329233023312332233323342335233623372338233923402341234223432344234523462347234823492350235123522353235423552356235723582359236023612362236323642365236623672368236923702371237223732374237523762377237823792380238123822383238423852386238723882389239023912392239323942395239623972398239924002401240224032404240524062407240824092410241124122413241424152416241724182419242024212422242324242425242624272428242924302431243224332434243524362437243824392440244124422443244424452446244724482449245024512452245324542455245624572458245924602461246224632464246524662467246824692470247124722473247424752476247724782479248024812482248324842485248624872488248924902491249224932494249524962497249824992500250125022503250425052506250725082509251025112512251325142515251625172518251925202521252225232524252525262527252825292530253125322533253425352536253725382539254025412542254325442545254625472548254925502551255225532554255525562557255825592560256125622563256425652566256725682569257025712572257325742575257625772578257925802581258225832584258525862587258825892590259125922593259425952596259725982599260026012602260326042605260626072608260926102611261226132614261526162617261826192620262126222623262426252626262726282629263026312632263326342635263626372638263926402641264226432644264526462647264826492650265126522653265426552656265726582659266026612662266326642665266626672668266926702671267226732674267526762677267826792680268126822683268426852686268726882689269026912692269326942695269626972698269927002701270227032704270527062707270827092710271127122713271427152716271727182719272027212722272327242725272627272728272927302731273227332734273527362737273827392740274127422743274427452746274727482749275027512752275327542755275627572758275927602761276227632764276527662767276827692770277127722773277427752776277727782779278027812782278327842785278627872788278927902791279227932794279527962797279827992800280128022803280428052806280728082809281028112812281328142815281628172818281928202821282228232824282528262827282828292830283128322833283428352836283728382839284028412842284328442845284628472848284928502851285228532854285528562857285828592860286128622863286428652866286728682869287028712872287328742875287628772878287928802881288228832884288528862887288828892890289128922893289428952896289728982899290029012902290329042905290629072908290929102911291229132914291529162917291829192920292129222923292429252926292729282929293029312932293329342935293629372938293929402941294229432944294529462947294829492950295129522953295429552956295729582959296029612962296329642965296629672968296929702971297229732974297529762977297829792980298129822983298429852986298729882989299029912992299329942995299629972998299930003001300230033004300530063007300830093010301130123013301430153016301730183019302030213022302330243025302630273028302930303031303230333034303530363037303830393040304130423043304430453046304730483049305030513052305330543055305630573058305930603061306230633064306530663067306830693070307130723073307430753076307730783079308030813082308330843085308630873088308930903091309230933094309530963097309830993100310131023103310431053106310731083109311031113112311331143115311631173118311931203121312231233124312531263127312831293130313131323133313431353136313731383139314031413142314331443145314631473148314931503151315231533154315531563157315831593160316131623163316431653166316731683169317031713172317331743175317631773178317931803181318231833184318531863187318831893190319131923193319431953196319731983199320032013202320332043205320632073208320932103211321232133214321532163217321832193220322132223223322432253226322732283229323032313232323332343235323632373238323932403241324232433244324532463247324832493250325132523253325432553256325732583259326032613262326332643265326632673268326932703271327232733274327532763277327832793280328132823283328432853286328732883289329032913292329332943295329632973298329933003301330233033304330533063307330833093310331133123313331433153316331733183319332033213322332333243325332633273328332933303331333233333334333533363337333833393340334133423343334433453346334733483349335033513352335333543355335633573358335933603361336233633364336533663367336833693370337133723373337433753376337733783379338033813382338333843385338633873388338933903391339233933394339533963397339833993400340134023403340434053406340734083409341034113412341334143415341634173418341934203421342234233424342534263427342834293430343134323433343434353436343734383439344034413442344334443445344634473448344934503451345234533454345534563457345834593460346134623463346434653466346734683469347034713472347334743475347634773478347934803481348234833484348534863487348834893490349134923493349434953496349734983499350035013502350335043505350635073508350935103511351235133514351535163517351835193520352135223523352435253526352735283529353035313532353335343535353635373538353935403541354235433544354535463547354835493550355135523553355435553556355735583559356035613562356335643565356635673568356935703571357235733574357535763577357835793580358135823583358435853586358735883589359035913592359335943595359635973598359936003601360236033604360536063607360836093610361136123613361436153616361736183619362036213622362336243625362636273628362936303631363236333634363536363637363836393640364136423643364436453646364736483649365036513652365336543655365636573658365936603661366236633664366536663667366836693670367136723673367436753676367736783679368036813682368336843685368636873688368936903691369236933694369536963697369836993700370137023703370437053706370737083709371037113712371337143715371637173718371937203721372237233724372537263727372837293730373137323733373437353736373737383739374037413742374337443745374637473748374937503751375237533754375537563757375837593760376137623763376437653766376737683769377037713772377337743775377637773778377937803781378237833784378537863787378837893790379137923793379437953796379737983799380038013802380338043805380638073808380938103811381238133814381538163817381838193820382138223823382438253826382738283829383038313832383338343835383638373838383938403841384238433844384538463847384838493850385138523853385438553856385738583859386038613862386338643865386638673868386938703871387238733874387538763877387838793880388138823883388438853886388738883889389038913892389338943895389638973898389939003901390239033904390539063907390839093910391139123913391439153916391739183919392039213922392339243925392639273928392939303931393239333934393539363937393839393940394139423943394439453946394739483949395039513952395339543955395639573958395939603961396239633964396539663967396839693970397139723973397439753976397739783979398039813982398339843985398639873988398939903991399239933994399539963997399839994000400140024003400440054006400740084009401040114012401340144015401640174018401940204021402240234024402540264027402840294030403140324033403440354036403740384039404040414042404340444045404640474048404940504051405240534054405540564057405840594060406140624063406440654066406740684069407040714072407340744075407640774078407940804081408240834084408540864087408840894090409140924093409440954096409740984099410041014102410341044105410641074108410941104111411241134114411541164117411841194120412141224123412441254126412741284129413041314132413341344135413641374138413941404141414241434144414541464147414841494150415141524153415441554156415741584159416041614162416341644165416641674168416941704171417241734174417541764177417841794180418141824183418441854186418741884189419041914192419341944195419641974198419942004201420242034204420542064207420842094210421142124213421442154216421742184219422042214222422342244225422642274228422942304231423242334234423542364237423842394240424142424243424442454246424742484249425042514252425342544255425642574258425942604261426242634264426542664267426842694270427142724273427442754276427742784279428042814282428342844285428642874288428942904291429242934294429542964297429842994300430143024303430443054306430743084309431043114312431343144315431643174318431943204321432243234324432543264327432843294330433143324333433443354336433743384339434043414342434343444345434643474348434943504351435243534354435543564357435843594360436143624363436443654366 | 
							- /* ssl/s3_lib.c */
 
- /* Copyright (C) 1995-1998 Eric Young ([email protected])
 
-  * All rights reserved.
 
-  *
 
-  * This package is an SSL implementation written
 
-  * by Eric Young ([email protected]).
 
-  * The implementation was written so as to conform with Netscapes SSL.
 
-  *
 
-  * This library is free for commercial and non-commercial use as long as
 
-  * the following conditions are aheared to.  The following conditions
 
-  * apply to all code found in this distribution, be it the RC4, RSA,
 
-  * lhash, DES, etc., code; not just the SSL code.  The SSL documentation
 
-  * included with this distribution is covered by the same copyright terms
 
-  * except that the holder is Tim Hudson ([email protected]).
 
-  *
 
-  * Copyright remains Eric Young's, and as such any Copyright notices in
 
-  * the code are not to be removed.
 
-  * If this package is used in a product, Eric Young should be given attribution
 
-  * as the author of the parts of the library used.
 
-  * This can be in the form of a textual message at program startup or
 
-  * in documentation (online or textual) provided with the package.
 
-  *
 
-  * Redistribution and use in source and binary forms, with or without
 
-  * modification, are permitted provided that the following conditions
 
-  * are met:
 
-  * 1. Redistributions of source code must retain the copyright
 
-  *    notice, this list of conditions and the following disclaimer.
 
-  * 2. Redistributions in binary form must reproduce the above copyright
 
-  *    notice, this list of conditions and the following disclaimer in the
 
-  *    documentation and/or other materials provided with the distribution.
 
-  * 3. All advertising materials mentioning features or use of this software
 
-  *    must display the following acknowledgement:
 
-  *    "This product includes cryptographic software written by
 
-  *     Eric Young ([email protected])"
 
-  *    The word 'cryptographic' can be left out if the rouines from the library
 
-  *    being used are not cryptographic related :-).
 
-  * 4. If you include any Windows specific code (or a derivative thereof) from
 
-  *    the apps directory (application code) you must include an acknowledgement:
 
-  *    "This product includes software written by Tim Hudson ([email protected])"
 
-  *
 
-  * THIS SOFTWARE IS PROVIDED BY ERIC YOUNG ``AS IS'' AND
 
-  * ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 
-  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
 
-  * ARE DISCLAIMED.  IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
 
-  * FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
 
-  * DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
 
-  * OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 
-  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
 
-  * LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
 
-  * OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
 
-  * SUCH DAMAGE.
 
-  *
 
-  * The licence and distribution terms for any publically available version or
 
-  * derivative of this code cannot be changed.  i.e. this code cannot simply be
 
-  * copied and put under another distribution licence
 
-  * [including the GNU Public Licence.]
 
-  */
 
- /* ====================================================================
 
-  * Copyright (c) 1998-2007 The OpenSSL Project.  All rights reserved.
 
-  *
 
-  * Redistribution and use in source and binary forms, with or without
 
-  * modification, are permitted provided that the following conditions
 
-  * are met:
 
-  *
 
-  * 1. Redistributions of source code must retain the above copyright
 
-  *    notice, this list of conditions and the following disclaimer.
 
-  *
 
-  * 2. Redistributions in binary form must reproduce the above copyright
 
-  *    notice, this list of conditions and the following disclaimer in
 
-  *    the documentation and/or other materials provided with the
 
-  *    distribution.
 
-  *
 
-  * 3. All advertising materials mentioning features or use of this
 
-  *    software must display the following acknowledgment:
 
-  *    "This product includes software developed by the OpenSSL Project
 
-  *    for use in the OpenSSL Toolkit. (http://www.openssl.org/)"
 
-  *
 
-  * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
 
-  *    endorse or promote products derived from this software without
 
-  *    prior written permission. For written permission, please contact
 
-  *    [email protected].
 
-  *
 
-  * 5. Products derived from this software may not be called "OpenSSL"
 
-  *    nor may "OpenSSL" appear in their names without prior written
 
-  *    permission of the OpenSSL Project.
 
-  *
 
-  * 6. Redistributions of any form whatsoever must retain the following
 
-  *    acknowledgment:
 
-  *    "This product includes software developed by the OpenSSL Project
 
-  *    for use in the OpenSSL Toolkit (http://www.openssl.org/)"
 
-  *
 
-  * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
 
-  * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
 
-  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
 
-  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
 
-  * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
 
-  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
 
-  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
 
-  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
 
-  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
 
-  * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
 
-  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
 
-  * OF THE POSSIBILITY OF SUCH DAMAGE.
 
-  * ====================================================================
 
-  *
 
-  * This product includes cryptographic software written by Eric Young
 
-  * ([email protected]).  This product includes software written by Tim
 
-  * Hudson ([email protected]).
 
-  *
 
-  */
 
- /* ====================================================================
 
-  * Copyright 2002 Sun Microsystems, Inc. ALL RIGHTS RESERVED.
 
-  *
 
-  * Portions of the attached software ("Contribution") are developed by
 
-  * SUN MICROSYSTEMS, INC., and are contributed to the OpenSSL project.
 
-  *
 
-  * The Contribution is licensed pursuant to the OpenSSL open source
 
-  * license provided above.
 
-  *
 
-  * ECC cipher suite support in OpenSSL originally written by
 
-  * Vipul Gupta and Sumit Gupta of Sun Microsystems Laboratories.
 
-  *
 
-  */
 
- /* ====================================================================
 
-  * Copyright 2005 Nokia. All rights reserved.
 
-  *
 
-  * The portions of the attached software ("Contribution") is developed by
 
-  * Nokia Corporation and is licensed pursuant to the OpenSSL open source
 
-  * license.
 
-  *
 
-  * The Contribution, originally written by Mika Kousa and Pasi Eronen of
 
-  * Nokia Corporation, consists of the "PSK" (Pre-Shared Key) ciphersuites
 
-  * support (see RFC 4279) to OpenSSL.
 
-  *
 
-  * No patent licenses or other rights except those expressly stated in
 
-  * the OpenSSL open source license shall be deemed granted or received
 
-  * expressly, by implication, estoppel, or otherwise.
 
-  *
 
-  * No assurances are provided by Nokia that the Contribution does not
 
-  * infringe the patent or other intellectual property rights of any third
 
-  * party or that the license provides you with all the necessary rights
 
-  * to make use of the Contribution.
 
-  *
 
-  * THE SOFTWARE IS PROVIDED "AS IS" WITHOUT WARRANTY OF ANY KIND. IN
 
-  * ADDITION TO THE DISCLAIMERS INCLUDED IN THE LICENSE, NOKIA
 
-  * SPECIFICALLY DISCLAIMS ANY LIABILITY FOR CLAIMS BROUGHT BY YOU OR ANY
 
-  * OTHER ENTITY BASED ON INFRINGEMENT OF INTELLECTUAL PROPERTY RIGHTS OR
 
-  * OTHERWISE.
 
-  */
 
- #include <stdio.h>
 
- #include <openssl/objects.h>
 
- #include "ssl_locl.h"
 
- #include "kssl_lcl.h"
 
- #ifndef OPENSSL_NO_TLSEXT
 
- # ifndef OPENSSL_NO_EC
 
- #  include "../crypto/ec/ec_lcl.h"
 
- # endif                         /* OPENSSL_NO_EC */
 
- #endif                          /* OPENSSL_NO_TLSEXT */
 
- #include <openssl/md5.h>
 
- #ifndef OPENSSL_NO_DH
 
- # include <openssl/dh.h>
 
- #endif
 
- const char ssl3_version_str[] = "SSLv3" OPENSSL_VERSION_PTEXT;
 
- #define SSL3_NUM_CIPHERS        (sizeof(ssl3_ciphers)/sizeof(SSL_CIPHER))
 
- /* list of available SSLv3 ciphers (sorted by id) */
 
- OPENSSL_GLOBAL SSL_CIPHER ssl3_ciphers[] = {
 
- /* The RSA ciphers */
 
- /* Cipher 01 */
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_NULL_MD5,
 
-      SSL3_CK_RSA_NULL_MD5,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_eNULL,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
- /* Cipher 02 */
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_NULL_SHA,
 
-      SSL3_CK_RSA_NULL_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_eNULL,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
- /* Cipher 03 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_RC4_40_MD5,
 
-      SSL3_CK_RSA_RC4_40_MD5,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_RC4,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      128,
 
-      },
 
- #endif
 
- /* Cipher 04 */
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_RC4_128_MD5,
 
-      SSL3_CK_RSA_RC4_128_MD5,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_RC4,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 05 */
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_RC4_128_SHA,
 
-      SSL3_CK_RSA_RC4_128_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 06 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_RC2_40_MD5,
 
-      SSL3_CK_RSA_RC2_40_MD5,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_RC2,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      128,
 
-      },
 
- #endif
 
- /* Cipher 07 */
 
- #ifndef OPENSSL_NO_IDEA
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_IDEA_128_SHA,
 
-      SSL3_CK_RSA_IDEA_128_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_IDEA,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- #endif
 
- /* Cipher 08 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_DES_40_CBC_SHA,
 
-      SSL3_CK_RSA_DES_40_CBC_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 09 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_DES_64_CBC_SHA,
 
-      SSL3_CK_RSA_DES_64_CBC_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_LOW,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 0A */
 
-     {
 
-      1,
 
-      SSL3_TXT_RSA_DES_192_CBC3_SHA,
 
-      SSL3_CK_RSA_DES_192_CBC3_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
- /* The DH ciphers */
 
- /* Cipher 0B */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      0,
 
-      SSL3_TXT_DH_DSS_DES_40_CBC_SHA,
 
-      SSL3_CK_DH_DSS_DES_40_CBC_SHA,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 0C */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      SSL3_TXT_DH_DSS_DES_64_CBC_SHA,
 
-      SSL3_CK_DH_DSS_DES_64_CBC_SHA,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_LOW,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 0D */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      SSL3_TXT_DH_DSS_DES_192_CBC3_SHA,
 
-      SSL3_CK_DH_DSS_DES_192_CBC3_SHA,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
- /* Cipher 0E */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      SSL3_TXT_DH_RSA_DES_40_CBC_SHA,
 
-      SSL3_CK_DH_RSA_DES_40_CBC_SHA,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 0F */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      SSL3_TXT_DH_RSA_DES_64_CBC_SHA,
 
-      SSL3_CK_DH_RSA_DES_64_CBC_SHA,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_LOW,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 10 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      SSL3_TXT_DH_RSA_DES_192_CBC3_SHA,
 
-      SSL3_CK_DH_RSA_DES_192_CBC3_SHA,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
- /* The Ephemeral DH ciphers */
 
- /* Cipher 11 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_EDH_DSS_DES_40_CBC_SHA,
 
-      SSL3_CK_EDH_DSS_DES_40_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 12 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_EDH_DSS_DES_64_CBC_SHA,
 
-      SSL3_CK_EDH_DSS_DES_64_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_LOW,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 13 */
 
-     {
 
-      1,
 
-      SSL3_TXT_EDH_DSS_DES_192_CBC3_SHA,
 
-      SSL3_CK_EDH_DSS_DES_192_CBC3_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
- /* Cipher 14 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_EDH_RSA_DES_40_CBC_SHA,
 
-      SSL3_CK_EDH_RSA_DES_40_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 15 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_EDH_RSA_DES_64_CBC_SHA,
 
-      SSL3_CK_EDH_RSA_DES_64_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_LOW,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 16 */
 
-     {
 
-      1,
 
-      SSL3_TXT_EDH_RSA_DES_192_CBC3_SHA,
 
-      SSL3_CK_EDH_RSA_DES_192_CBC3_SHA,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
- /* Cipher 17 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_ADH_RC4_40_MD5,
 
-      SSL3_CK_ADH_RC4_40_MD5,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_RC4,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      128,
 
-      },
 
- #endif
 
- /* Cipher 18 */
 
-     {
 
-      1,
 
-      SSL3_TXT_ADH_RC4_128_MD5,
 
-      SSL3_CK_ADH_RC4_128_MD5,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_RC4,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 19 */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_ADH_DES_40_CBC_SHA,
 
-      SSL3_CK_ADH_DES_40_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      128,
 
-      },
 
- #endif
 
- /* Cipher 1A */
 
- #ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_ADH_DES_64_CBC_SHA,
 
-      SSL3_CK_ADH_DES_64_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_LOW,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- #endif
 
- /* Cipher 1B */
 
-     {
 
-      1,
 
-      SSL3_TXT_ADH_DES_192_CBC_SHA,
 
-      SSL3_CK_ADH_DES_192_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
- /* Fortezza ciphersuite from SSL 3.0 spec */
 
- #if 0
 
- /* Cipher 1C */
 
-     {
 
-      0,
 
-      SSL3_TXT_FZA_DMS_NULL_SHA,
 
-      SSL3_CK_FZA_DMS_NULL_SHA,
 
-      SSL_kFZA,
 
-      SSL_aFZA,
 
-      SSL_eNULL,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
- /* Cipher 1D */
 
-     {
 
-      0,
 
-      SSL3_TXT_FZA_DMS_FZA_SHA,
 
-      SSL3_CK_FZA_DMS_FZA_SHA,
 
-      SSL_kFZA,
 
-      SSL_aFZA,
 
-      SSL_eFZA,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
- /* Cipher 1E */
 
-     {
 
-      0,
 
-      SSL3_TXT_FZA_DMS_RC4_SHA,
 
-      SSL3_CK_FZA_DMS_RC4_SHA,
 
-      SSL_kFZA,
 
-      SSL_aFZA,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- #endif
 
- #ifndef OPENSSL_NO_KRB5
 
- /* The Kerberos ciphers*/
 
- /* Cipher 1E */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_DES_64_CBC_SHA,
 
-      SSL3_CK_KRB5_DES_64_CBC_SHA,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_LOW,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- # endif
 
- /* Cipher 1F */
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_DES_192_CBC3_SHA,
 
-      SSL3_CK_KRB5_DES_192_CBC3_SHA,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
- /* Cipher 20 */
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_RC4_128_SHA,
 
-      SSL3_CK_KRB5_RC4_128_SHA,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 21 */
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_IDEA_128_CBC_SHA,
 
-      SSL3_CK_KRB5_IDEA_128_CBC_SHA,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_IDEA,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 22 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_DES_64_CBC_MD5,
 
-      SSL3_CK_KRB5_DES_64_CBC_MD5,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_DES,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_LOW,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- # endif
 
- /* Cipher 23 */
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_DES_192_CBC3_MD5,
 
-      SSL3_CK_KRB5_DES_192_CBC3_MD5,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_3DES,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
- /* Cipher 24 */
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_RC4_128_MD5,
 
-      SSL3_CK_KRB5_RC4_128_MD5,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_RC4,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 25 */
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_IDEA_128_CBC_MD5,
 
-      SSL3_CK_KRB5_IDEA_128_CBC_MD5,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_IDEA,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 26 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_DES_40_CBC_SHA,
 
-      SSL3_CK_KRB5_DES_40_CBC_SHA,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      56,
 
-      },
 
- # endif
 
- /* Cipher 27 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_RC2_40_CBC_SHA,
 
-      SSL3_CK_KRB5_RC2_40_CBC_SHA,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_RC2,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      128,
 
-      },
 
- # endif
 
- /* Cipher 28 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_RC4_40_SHA,
 
-      SSL3_CK_KRB5_RC4_40_SHA,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      128,
 
-      },
 
- # endif
 
- /* Cipher 29 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_DES_40_CBC_MD5,
 
-      SSL3_CK_KRB5_DES_40_CBC_MD5,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_DES,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      56,
 
-      },
 
- # endif
 
- /* Cipher 2A */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_RC2_40_CBC_MD5,
 
-      SSL3_CK_KRB5_RC2_40_CBC_MD5,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_RC2,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      128,
 
-      },
 
- # endif
 
- /* Cipher 2B */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      SSL3_TXT_KRB5_RC4_40_MD5,
 
-      SSL3_CK_KRB5_RC4_40_MD5,
 
-      SSL_kKRB5,
 
-      SSL_aKRB5,
 
-      SSL_RC4,
 
-      SSL_MD5,
 
-      SSL_SSLV3,
 
-      SSL_EXPORT | SSL_EXP40,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      40,
 
-      128,
 
-      },
 
- # endif
 
- #endif                          /* OPENSSL_NO_KRB5 */
 
- /* New AES ciphersuites */
 
- /* Cipher 2F */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_AES_128_SHA,
 
-      TLS1_CK_RSA_WITH_AES_128_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 30 */
 
-     {
 
-      0,
 
-      TLS1_TXT_DH_DSS_WITH_AES_128_SHA,
 
-      TLS1_CK_DH_DSS_WITH_AES_128_SHA,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 31 */
 
-     {
 
-      0,
 
-      TLS1_TXT_DH_RSA_WITH_AES_128_SHA,
 
-      TLS1_CK_DH_RSA_WITH_AES_128_SHA,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 32 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_AES_128_SHA,
 
-      TLS1_CK_DHE_DSS_WITH_AES_128_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 33 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_AES_128_SHA,
 
-      TLS1_CK_DHE_RSA_WITH_AES_128_SHA,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 34 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_AES_128_SHA,
 
-      TLS1_CK_ADH_WITH_AES_128_SHA,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- /* Cipher 35 */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_AES_256_SHA,
 
-      TLS1_CK_RSA_WITH_AES_256_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
- /* Cipher 36 */
 
-     {
 
-      0,
 
-      TLS1_TXT_DH_DSS_WITH_AES_256_SHA,
 
-      TLS1_CK_DH_DSS_WITH_AES_256_SHA,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
- /* Cipher 37 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_RSA_WITH_AES_256_SHA,
 
-      TLS1_CK_DH_RSA_WITH_AES_256_SHA,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
- /* Cipher 38 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_AES_256_SHA,
 
-      TLS1_CK_DHE_DSS_WITH_AES_256_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
- /* Cipher 39 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_AES_256_SHA,
 
-      TLS1_CK_DHE_RSA_WITH_AES_256_SHA,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 3A */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_AES_256_SHA,
 
-      TLS1_CK_ADH_WITH_AES_256_SHA,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* TLS v1.2 ciphersuites */
 
-     /* Cipher 3B */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_NULL_SHA256,
 
-      TLS1_CK_RSA_WITH_NULL_SHA256,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_eNULL,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
-     /* Cipher 3C */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_AES_128_SHA256,
 
-      TLS1_CK_RSA_WITH_AES_128_SHA256,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 3D */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_AES_256_SHA256,
 
-      TLS1_CK_RSA_WITH_AES_256_SHA256,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_AES256,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 3E */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_DSS_WITH_AES_128_SHA256,
 
-      TLS1_CK_DH_DSS_WITH_AES_128_SHA256,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 3F */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_RSA_WITH_AES_128_SHA256,
 
-      TLS1_CK_DH_RSA_WITH_AES_128_SHA256,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 40 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_AES_128_SHA256,
 
-      TLS1_CK_DHE_DSS_WITH_AES_128_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- #ifndef OPENSSL_NO_CAMELLIA
 
-     /* Camellia ciphersuites from RFC4132 (128-bit portion) */
 
-     /* Cipher 41 */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_CAMELLIA_128_CBC_SHA,
 
-      TLS1_CK_RSA_WITH_CAMELLIA_128_CBC_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_CAMELLIA128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 42 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_DSS_WITH_CAMELLIA_128_CBC_SHA,
 
-      TLS1_CK_DH_DSS_WITH_CAMELLIA_128_CBC_SHA,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_CAMELLIA128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 43 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_RSA_WITH_CAMELLIA_128_CBC_SHA,
 
-      TLS1_CK_DH_RSA_WITH_CAMELLIA_128_CBC_SHA,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_CAMELLIA128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 44 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA,
 
-      TLS1_CK_DHE_DSS_WITH_CAMELLIA_128_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_CAMELLIA128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 45 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA,
 
-      TLS1_CK_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_CAMELLIA128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 46 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_CAMELLIA_128_CBC_SHA,
 
-      TLS1_CK_ADH_WITH_CAMELLIA_128_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_CAMELLIA128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- #endif                          /* OPENSSL_NO_CAMELLIA */
 
- #if TLS1_ALLOW_EXPERIMENTAL_CIPHERSUITES
 
-     /* New TLS Export CipherSuites from expired ID */
 
- # if 0
 
-     /* Cipher 60 */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_EXPORT1024_WITH_RC4_56_MD5,
 
-      TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_MD5,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_RC4,
 
-      SSL_MD5,
 
-      SSL_TLSV1,
 
-      SSL_EXPORT | SSL_EXP56,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      128,
 
-      },
 
-     /* Cipher 61 */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5,
 
-      TLS1_CK_RSA_EXPORT1024_WITH_RC2_CBC_56_MD5,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_RC2,
 
-      SSL_MD5,
 
-      SSL_TLSV1,
 
-      SSL_EXPORT | SSL_EXP56,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      128,
 
-      },
 
- # endif
 
-     /* Cipher 62 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_EXPORT1024_WITH_DES_CBC_SHA,
 
-      TLS1_CK_RSA_EXPORT1024_WITH_DES_CBC_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_EXPORT | SSL_EXP56,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- # endif
 
-     /* Cipher 63 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA,
 
-      TLS1_CK_DHE_DSS_EXPORT1024_WITH_DES_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_EXPORT | SSL_EXP56,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      56,
 
-      },
 
- # endif
 
-     /* Cipher 64 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_EXPORT1024_WITH_RC4_56_SHA,
 
-      TLS1_CK_RSA_EXPORT1024_WITH_RC4_56_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_EXPORT | SSL_EXP56,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      128,
 
-      },
 
- # endif
 
-     /* Cipher 65 */
 
- # ifndef OPENSSL_NO_WEAK_SSL_CIPHERS
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA,
 
-      TLS1_CK_DHE_DSS_EXPORT1024_WITH_RC4_56_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_EXPORT | SSL_EXP56,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      56,
 
-      128,
 
-      },
 
- # endif
 
-     /* Cipher 66 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_RC4_128_SHA,
 
-      TLS1_CK_DHE_DSS_WITH_RC4_128_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- #endif
 
-     /* TLS v1.2 ciphersuites */
 
-     /* Cipher 67 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_AES_128_SHA256,
 
-      TLS1_CK_DHE_RSA_WITH_AES_128_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 68 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_DSS_WITH_AES_256_SHA256,
 
-      TLS1_CK_DH_DSS_WITH_AES_256_SHA256,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_AES256,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 69 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_RSA_WITH_AES_256_SHA256,
 
-      TLS1_CK_DH_RSA_WITH_AES_256_SHA256,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_AES256,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 6A */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_AES_256_SHA256,
 
-      TLS1_CK_DHE_DSS_WITH_AES_256_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_AES256,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 6B */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_AES_256_SHA256,
 
-      TLS1_CK_DHE_RSA_WITH_AES_256_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_AES256,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 6C */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_AES_128_SHA256,
 
-      TLS1_CK_ADH_WITH_AES_128_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 6D */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_AES_256_SHA256,
 
-      TLS1_CK_ADH_WITH_AES_256_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_AES256,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* GOST Ciphersuites */
 
-     {
 
-      1,
 
-      "GOST94-GOST89-GOST89",
 
-      0x3000080,
 
-      SSL_kGOST,
 
-      SSL_aGOST94,
 
-      SSL_eGOST2814789CNT,
 
-      SSL_GOST89MAC,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_GOST94 | TLS1_PRF_GOST94 | TLS1_STREAM_MAC,
 
-      256,
 
-      256},
 
-     {
 
-      1,
 
-      "GOST2001-GOST89-GOST89",
 
-      0x3000081,
 
-      SSL_kGOST,
 
-      SSL_aGOST01,
 
-      SSL_eGOST2814789CNT,
 
-      SSL_GOST89MAC,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_GOST94 | TLS1_PRF_GOST94 | TLS1_STREAM_MAC,
 
-      256,
 
-      256},
 
-     {
 
-      1,
 
-      "GOST94-NULL-GOST94",
 
-      0x3000082,
 
-      SSL_kGOST,
 
-      SSL_aGOST94,
 
-      SSL_eNULL,
 
-      SSL_GOST94,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE,
 
-      SSL_HANDSHAKE_MAC_GOST94 | TLS1_PRF_GOST94,
 
-      0,
 
-      0},
 
-     {
 
-      1,
 
-      "GOST2001-NULL-GOST94",
 
-      0x3000083,
 
-      SSL_kGOST,
 
-      SSL_aGOST01,
 
-      SSL_eNULL,
 
-      SSL_GOST94,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE,
 
-      SSL_HANDSHAKE_MAC_GOST94 | TLS1_PRF_GOST94,
 
-      0,
 
-      0},
 
- #ifndef OPENSSL_NO_CAMELLIA
 
-     /* Camellia ciphersuites from RFC4132 (256-bit portion) */
 
-     /* Cipher 84 */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_CAMELLIA_256_CBC_SHA,
 
-      TLS1_CK_RSA_WITH_CAMELLIA_256_CBC_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_CAMELLIA256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 85 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_DSS_WITH_CAMELLIA_256_CBC_SHA,
 
-      TLS1_CK_DH_DSS_WITH_CAMELLIA_256_CBC_SHA,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_CAMELLIA256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 86 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_RSA_WITH_CAMELLIA_256_CBC_SHA,
 
-      TLS1_CK_DH_RSA_WITH_CAMELLIA_256_CBC_SHA,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_CAMELLIA256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 87 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA,
 
-      TLS1_CK_DHE_DSS_WITH_CAMELLIA_256_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_CAMELLIA256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 88 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA,
 
-      TLS1_CK_DHE_RSA_WITH_CAMELLIA_256_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_CAMELLIA256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 89 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_CAMELLIA_256_CBC_SHA,
 
-      TLS1_CK_ADH_WITH_CAMELLIA_256_CBC_SHA,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_CAMELLIA256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
- #endif                          /* OPENSSL_NO_CAMELLIA */
 
- #ifndef OPENSSL_NO_PSK
 
-     /* Cipher 8A */
 
-     {
 
-      1,
 
-      TLS1_TXT_PSK_WITH_RC4_128_SHA,
 
-      TLS1_CK_PSK_WITH_RC4_128_SHA,
 
-      SSL_kPSK,
 
-      SSL_aPSK,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 8B */
 
-     {
 
-      1,
 
-      TLS1_TXT_PSK_WITH_3DES_EDE_CBC_SHA,
 
-      TLS1_CK_PSK_WITH_3DES_EDE_CBC_SHA,
 
-      SSL_kPSK,
 
-      SSL_aPSK,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher 8C */
 
-     {
 
-      1,
 
-      TLS1_TXT_PSK_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_PSK_WITH_AES_128_CBC_SHA,
 
-      SSL_kPSK,
 
-      SSL_aPSK,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 8D */
 
-     {
 
-      1,
 
-      TLS1_TXT_PSK_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_PSK_WITH_AES_256_CBC_SHA,
 
-      SSL_kPSK,
 
-      SSL_aPSK,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
- #endif                          /* OPENSSL_NO_PSK */
 
- #ifndef OPENSSL_NO_SEED
 
-     /* SEED ciphersuites from RFC4162 */
 
-     /* Cipher 96 */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_SEED_SHA,
 
-      TLS1_CK_RSA_WITH_SEED_SHA,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_SEED,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 97 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_DSS_WITH_SEED_SHA,
 
-      TLS1_CK_DH_DSS_WITH_SEED_SHA,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_SEED,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 98 */
 
-     {
 
-      0,                         /* not implemented (non-ephemeral DH) */
 
-      TLS1_TXT_DH_RSA_WITH_SEED_SHA,
 
-      TLS1_CK_DH_RSA_WITH_SEED_SHA,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_SEED,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 99 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_SEED_SHA,
 
-      TLS1_CK_DHE_DSS_WITH_SEED_SHA,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_SEED,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 9A */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_SEED_SHA,
 
-      TLS1_CK_DHE_RSA_WITH_SEED_SHA,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_SEED,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 9B */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_SEED_SHA,
 
-      TLS1_CK_ADH_WITH_SEED_SHA,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_SEED,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
- #endif                          /* OPENSSL_NO_SEED */
 
-     /* GCM ciphersuites from RFC5288 */
 
-     /* Cipher 9C */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_RSA_WITH_AES_128_GCM_SHA256,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 9D */
 
-     {
 
-      1,
 
-      TLS1_TXT_RSA_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_RSA_WITH_AES_256_GCM_SHA384,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher 9E */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_DHE_RSA_WITH_AES_128_GCM_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher 9F */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_RSA_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_DHE_RSA_WITH_AES_256_GCM_SHA384,
 
-      SSL_kEDH,
 
-      SSL_aRSA,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher A0 */
 
-     {
 
-      0,
 
-      TLS1_TXT_DH_RSA_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_DH_RSA_WITH_AES_128_GCM_SHA256,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher A1 */
 
-     {
 
-      0,
 
-      TLS1_TXT_DH_RSA_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_DH_RSA_WITH_AES_256_GCM_SHA384,
 
-      SSL_kDHr,
 
-      SSL_aDH,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher A2 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_DHE_DSS_WITH_AES_128_GCM_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher A3 */
 
-     {
 
-      1,
 
-      TLS1_TXT_DHE_DSS_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_DHE_DSS_WITH_AES_256_GCM_SHA384,
 
-      SSL_kEDH,
 
-      SSL_aDSS,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher A4 */
 
-     {
 
-      0,
 
-      TLS1_TXT_DH_DSS_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_DH_DSS_WITH_AES_128_GCM_SHA256,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher A5 */
 
-     {
 
-      0,
 
-      TLS1_TXT_DH_DSS_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_DH_DSS_WITH_AES_256_GCM_SHA384,
 
-      SSL_kDHd,
 
-      SSL_aDH,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher A6 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_ADH_WITH_AES_128_GCM_SHA256,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher A7 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ADH_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_ADH_WITH_AES_256_GCM_SHA384,
 
-      SSL_kEDH,
 
-      SSL_aNULL,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
- #ifndef OPENSSL_NO_ECDH
 
-     /* Cipher C001 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_NULL_SHA,
 
-      TLS1_CK_ECDH_ECDSA_WITH_NULL_SHA,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_eNULL,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
-     /* Cipher C002 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_RC4_128_SHA,
 
-      TLS1_CK_ECDH_ECDSA_WITH_RC4_128_SHA,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C003 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_DES_192_CBC3_SHA,
 
-      TLS1_CK_ECDH_ECDSA_WITH_DES_192_CBC3_SHA,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher C004 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_ECDH_ECDSA_WITH_AES_128_CBC_SHA,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C005 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_ECDH_ECDSA_WITH_AES_256_CBC_SHA,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C006 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_NULL_SHA,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_NULL_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_eNULL,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
-     /* Cipher C007 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_RC4_128_SHA,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_RC4_128_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C008 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_DES_192_CBC3_SHA,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_DES_192_CBC3_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher C009 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_AES_128_CBC_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C00A */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_AES_256_CBC_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C00B */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_NULL_SHA,
 
-      TLS1_CK_ECDH_RSA_WITH_NULL_SHA,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_eNULL,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
-     /* Cipher C00C */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_RC4_128_SHA,
 
-      TLS1_CK_ECDH_RSA_WITH_RC4_128_SHA,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C00D */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_DES_192_CBC3_SHA,
 
-      TLS1_CK_ECDH_RSA_WITH_DES_192_CBC3_SHA,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher C00E */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_ECDH_RSA_WITH_AES_128_CBC_SHA,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C00F */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_ECDH_RSA_WITH_AES_256_CBC_SHA,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C010 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_NULL_SHA,
 
-      TLS1_CK_ECDHE_RSA_WITH_NULL_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_eNULL,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
-     /* Cipher C011 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_RC4_128_SHA,
 
-      TLS1_CK_ECDHE_RSA_WITH_RC4_128_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C012 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_DES_192_CBC3_SHA,
 
-      TLS1_CK_ECDHE_RSA_WITH_DES_192_CBC3_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher C013 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_ECDHE_RSA_WITH_AES_128_CBC_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C014 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_ECDHE_RSA_WITH_AES_256_CBC_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C015 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_anon_WITH_NULL_SHA,
 
-      TLS1_CK_ECDH_anon_WITH_NULL_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aNULL,
 
-      SSL_eNULL,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_STRONG_NONE | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      0,
 
-      0,
 
-      },
 
-     /* Cipher C016 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_anon_WITH_RC4_128_SHA,
 
-      TLS1_CK_ECDH_anon_WITH_RC4_128_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aNULL,
 
-      SSL_RC4,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_MEDIUM,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C017 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_anon_WITH_DES_192_CBC3_SHA,
 
-      TLS1_CK_ECDH_anon_WITH_DES_192_CBC3_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aNULL,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher C018 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_anon_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_ECDH_anon_WITH_AES_128_CBC_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aNULL,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C019 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_anon_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_ECDH_anon_WITH_AES_256_CBC_SHA,
 
-      SSL_kEECDH,
 
-      SSL_aNULL,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
- #endif                          /* OPENSSL_NO_ECDH */
 
- #ifndef OPENSSL_NO_SRP
 
-     /* Cipher C01A */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_WITH_3DES_EDE_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_WITH_3DES_EDE_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aSRP,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher C01B */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_RSA_WITH_3DES_EDE_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_RSA_WITH_3DES_EDE_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aRSA,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher C01C */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_DSS_WITH_3DES_EDE_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_DSS_WITH_3DES_EDE_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aDSS,
 
-      SSL_3DES,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      112,
 
-      168,
 
-      },
 
-     /* Cipher C01D */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_WITH_AES_128_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aSRP,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C01E */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_RSA_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_RSA_WITH_AES_128_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aRSA,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C01F */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_DSS_WITH_AES_128_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_DSS_WITH_AES_128_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aDSS,
 
-      SSL_AES128,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C020 */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_WITH_AES_256_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aSRP,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C021 */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_RSA_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_RSA_WITH_AES_256_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aRSA,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C022 */
 
-     {
 
-      1,
 
-      TLS1_TXT_SRP_SHA_DSS_WITH_AES_256_CBC_SHA,
 
-      TLS1_CK_SRP_SHA_DSS_WITH_AES_256_CBC_SHA,
 
-      SSL_kSRP,
 
-      SSL_aDSS,
 
-      SSL_AES256,
 
-      SSL_SHA1,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
- #endif                          /* OPENSSL_NO_SRP */
 
- #ifndef OPENSSL_NO_ECDH
 
-     /* HMAC based TLS v1.2 ciphersuites from RFC5289 */
 
-     /* Cipher C023 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_AES_128_SHA256,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_AES_128_SHA256,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C024 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_AES_256_SHA384,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_AES_256_SHA384,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_AES256,
 
-      SSL_SHA384,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C025 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_AES_128_SHA256,
 
-      TLS1_CK_ECDH_ECDSA_WITH_AES_128_SHA256,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C026 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_AES_256_SHA384,
 
-      TLS1_CK_ECDH_ECDSA_WITH_AES_256_SHA384,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_AES256,
 
-      SSL_SHA384,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C027 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_AES_128_SHA256,
 
-      TLS1_CK_ECDHE_RSA_WITH_AES_128_SHA256,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C028 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_AES_256_SHA384,
 
-      TLS1_CK_ECDHE_RSA_WITH_AES_256_SHA384,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_AES256,
 
-      SSL_SHA384,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C029 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_AES_128_SHA256,
 
-      TLS1_CK_ECDH_RSA_WITH_AES_128_SHA256,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_AES128,
 
-      SSL_SHA256,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C02A */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_AES_256_SHA384,
 
-      TLS1_CK_ECDH_RSA_WITH_AES_256_SHA384,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_AES256,
 
-      SSL_SHA384,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* GCM based TLS v1.2 ciphersuites from RFC5289 */
 
-     /* Cipher C02B */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C02C */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384,
 
-      SSL_kEECDH,
 
-      SSL_aECDSA,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C02D */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_ECDH_ECDSA_WITH_AES_128_GCM_SHA256,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C02E */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_ECDSA_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_ECDH_ECDSA_WITH_AES_256_GCM_SHA384,
 
-      SSL_kECDHe,
 
-      SSL_aECDH,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C02F */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_ECDHE_RSA_WITH_AES_128_GCM_SHA256,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C030 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_ECDHE_RSA_WITH_AES_256_GCM_SHA384,
 
-      SSL_kEECDH,
 
-      SSL_aRSA,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
-     /* Cipher C031 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_AES_128_GCM_SHA256,
 
-      TLS1_CK_ECDH_RSA_WITH_AES_128_GCM_SHA256,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_AES128GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256,
 
-      128,
 
-      128,
 
-      },
 
-     /* Cipher C032 */
 
-     {
 
-      1,
 
-      TLS1_TXT_ECDH_RSA_WITH_AES_256_GCM_SHA384,
 
-      TLS1_CK_ECDH_RSA_WITH_AES_256_GCM_SHA384,
 
-      SSL_kECDHr,
 
-      SSL_aECDH,
 
-      SSL_AES256GCM,
 
-      SSL_AEAD,
 
-      SSL_TLSV1_2,
 
-      SSL_NOT_EXP | SSL_HIGH | SSL_FIPS,
 
-      SSL_HANDSHAKE_MAC_SHA384 | TLS1_PRF_SHA384,
 
-      256,
 
-      256,
 
-      },
 
- #endif                          /* OPENSSL_NO_ECDH */
 
- #ifdef TEMP_GOST_TLS
 
- /* Cipher FF00 */
 
-     {
 
-      1,
 
-      "GOST-MD5",
 
-      0x0300ff00,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_eGOST2814789CNT,
 
-      SSL_MD5,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256,
 
-      },
 
-     {
 
-      1,
 
-      "GOST-GOST94",
 
-      0x0300ff01,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_eGOST2814789CNT,
 
-      SSL_GOST94,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256},
 
-     {
 
-      1,
 
-      "GOST-GOST89MAC",
 
-      0x0300ff02,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_eGOST2814789CNT,
 
-      SSL_GOST89MAC,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF,
 
-      256,
 
-      256},
 
-     {
 
-      1,
 
-      "GOST-GOST89STREAM",
 
-      0x0300ff03,
 
-      SSL_kRSA,
 
-      SSL_aRSA,
 
-      SSL_eGOST2814789CNT,
 
-      SSL_GOST89MAC,
 
-      SSL_TLSV1,
 
-      SSL_NOT_EXP | SSL_HIGH,
 
-      SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF | TLS1_STREAM_MAC,
 
-      256,
 
-      256},
 
- #endif
 
- /* end of list */
 
- };
 
- SSL3_ENC_METHOD SSLv3_enc_data = {
 
-     ssl3_enc,
 
-     n_ssl3_mac,
 
-     ssl3_setup_key_block,
 
-     ssl3_generate_master_secret,
 
-     ssl3_change_cipher_state,
 
-     ssl3_final_finish_mac,
 
-     MD5_DIGEST_LENGTH + SHA_DIGEST_LENGTH,
 
-     ssl3_cert_verify_mac,
 
-     SSL3_MD_CLIENT_FINISHED_CONST, 4,
 
-     SSL3_MD_SERVER_FINISHED_CONST, 4,
 
-     ssl3_alert_code,
 
-     (int (*)(SSL *, unsigned char *, size_t, const char *,
 
-              size_t, const unsigned char *, size_t,
 
-              int use_context))ssl_undefined_function,
 
- };
 
- long ssl3_default_timeout(void)
 
- {
 
-     /*
 
-      * 2 hours, the 24 hours mentioned in the SSLv3 spec is way too long for
 
-      * http, the cache would over fill
 
-      */
 
-     return (60 * 60 * 2);
 
- }
 
- int ssl3_num_ciphers(void)
 
- {
 
-     return (SSL3_NUM_CIPHERS);
 
- }
 
- const SSL_CIPHER *ssl3_get_cipher(unsigned int u)
 
- {
 
-     if (u < SSL3_NUM_CIPHERS)
 
-         return (&(ssl3_ciphers[SSL3_NUM_CIPHERS - 1 - u]));
 
-     else
 
-         return (NULL);
 
- }
 
- int ssl3_pending(const SSL *s)
 
- {
 
-     if (s->rstate == SSL_ST_READ_BODY)
 
-         return 0;
 
-     return (s->s3->rrec.type ==
 
-             SSL3_RT_APPLICATION_DATA) ? s->s3->rrec.length : 0;
 
- }
 
- int ssl3_new(SSL *s)
 
- {
 
-     SSL3_STATE *s3;
 
-     if ((s3 = OPENSSL_malloc(sizeof *s3)) == NULL)
 
-         goto err;
 
-     memset(s3, 0, sizeof *s3);
 
-     memset(s3->rrec.seq_num, 0, sizeof(s3->rrec.seq_num));
 
-     memset(s3->wrec.seq_num, 0, sizeof(s3->wrec.seq_num));
 
-     s->s3 = s3;
 
- #ifndef OPENSSL_NO_SRP
 
-     SSL_SRP_CTX_init(s);
 
- #endif
 
-     s->method->ssl_clear(s);
 
-     return (1);
 
-  err:
 
-     return (0);
 
- }
 
- void ssl3_free(SSL *s)
 
- {
 
-     if (s == NULL || s->s3 == NULL)
 
-         return;
 
- #ifdef TLSEXT_TYPE_opaque_prf_input
 
-     if (s->s3->client_opaque_prf_input != NULL)
 
-         OPENSSL_free(s->s3->client_opaque_prf_input);
 
-     if (s->s3->server_opaque_prf_input != NULL)
 
-         OPENSSL_free(s->s3->server_opaque_prf_input);
 
- #endif
 
-     ssl3_cleanup_key_block(s);
 
-     if (s->s3->rbuf.buf != NULL)
 
-         ssl3_release_read_buffer(s);
 
-     if (s->s3->wbuf.buf != NULL)
 
-         ssl3_release_write_buffer(s);
 
-     if (s->s3->rrec.comp != NULL)
 
-         OPENSSL_free(s->s3->rrec.comp);
 
- #ifndef OPENSSL_NO_DH
 
-     if (s->s3->tmp.dh != NULL)
 
-         DH_free(s->s3->tmp.dh);
 
- #endif
 
- #ifndef OPENSSL_NO_ECDH
 
-     if (s->s3->tmp.ecdh != NULL)
 
-         EC_KEY_free(s->s3->tmp.ecdh);
 
- #endif
 
-     if (s->s3->tmp.ca_names != NULL)
 
-         sk_X509_NAME_pop_free(s->s3->tmp.ca_names, X509_NAME_free);
 
-     if (s->s3->handshake_buffer) {
 
-         BIO_free(s->s3->handshake_buffer);
 
-     }
 
-     if (s->s3->handshake_dgst)
 
-         ssl3_free_digest_list(s);
 
- #ifndef OPENSSL_NO_SRP
 
-     SSL_SRP_CTX_free(s);
 
- #endif
 
-     OPENSSL_cleanse(s->s3, sizeof *s->s3);
 
-     OPENSSL_free(s->s3);
 
-     s->s3 = NULL;
 
- }
 
- void ssl3_clear(SSL *s)
 
- {
 
-     unsigned char *rp, *wp;
 
-     size_t rlen, wlen;
 
-     int init_extra;
 
- #ifdef TLSEXT_TYPE_opaque_prf_input
 
-     if (s->s3->client_opaque_prf_input != NULL)
 
-         OPENSSL_free(s->s3->client_opaque_prf_input);
 
-     s->s3->client_opaque_prf_input = NULL;
 
-     if (s->s3->server_opaque_prf_input != NULL)
 
-         OPENSSL_free(s->s3->server_opaque_prf_input);
 
-     s->s3->server_opaque_prf_input = NULL;
 
- #endif
 
-     ssl3_cleanup_key_block(s);
 
-     if (s->s3->tmp.ca_names != NULL)
 
-         sk_X509_NAME_pop_free(s->s3->tmp.ca_names, X509_NAME_free);
 
-     if (s->s3->rrec.comp != NULL) {
 
-         OPENSSL_free(s->s3->rrec.comp);
 
-         s->s3->rrec.comp = NULL;
 
-     }
 
- #ifndef OPENSSL_NO_DH
 
-     if (s->s3->tmp.dh != NULL) {
 
-         DH_free(s->s3->tmp.dh);
 
-         s->s3->tmp.dh = NULL;
 
-     }
 
- #endif
 
- #ifndef OPENSSL_NO_ECDH
 
-     if (s->s3->tmp.ecdh != NULL) {
 
-         EC_KEY_free(s->s3->tmp.ecdh);
 
-         s->s3->tmp.ecdh = NULL;
 
-     }
 
- #endif
 
- #ifndef OPENSSL_NO_TLSEXT
 
- # ifndef OPENSSL_NO_EC
 
-     s->s3->is_probably_safari = 0;
 
- # endif                         /* !OPENSSL_NO_EC */
 
- #endif                          /* !OPENSSL_NO_TLSEXT */
 
-     rp = s->s3->rbuf.buf;
 
-     wp = s->s3->wbuf.buf;
 
-     rlen = s->s3->rbuf.len;
 
-     wlen = s->s3->wbuf.len;
 
-     init_extra = s->s3->init_extra;
 
-     if (s->s3->handshake_buffer) {
 
-         BIO_free(s->s3->handshake_buffer);
 
-         s->s3->handshake_buffer = NULL;
 
-     }
 
-     if (s->s3->handshake_dgst) {
 
-         ssl3_free_digest_list(s);
 
-     }
 
-     memset(s->s3, 0, sizeof *s->s3);
 
-     s->s3->rbuf.buf = rp;
 
-     s->s3->wbuf.buf = wp;
 
-     s->s3->rbuf.len = rlen;
 
-     s->s3->wbuf.len = wlen;
 
-     s->s3->init_extra = init_extra;
 
-     ssl_free_wbio_buffer(s);
 
-     s->packet_length = 0;
 
-     s->s3->renegotiate = 0;
 
-     s->s3->total_renegotiations = 0;
 
-     s->s3->num_renegotiations = 0;
 
-     s->s3->in_read_app_data = 0;
 
-     s->version = SSL3_VERSION;
 
- #if !defined(OPENSSL_NO_TLSEXT) && !defined(OPENSSL_NO_NEXTPROTONEG)
 
-     if (s->next_proto_negotiated) {
 
-         OPENSSL_free(s->next_proto_negotiated);
 
-         s->next_proto_negotiated = NULL;
 
-         s->next_proto_negotiated_len = 0;
 
-     }
 
- #endif
 
- }
 
- #ifndef OPENSSL_NO_SRP
 
- static char *MS_CALLBACK srp_password_from_info_cb(SSL *s, void *arg)
 
- {
 
-     return BUF_strdup(s->srp_ctx.info);
 
- }
 
- #endif
 
- long ssl3_ctrl(SSL *s, int cmd, long larg, void *parg)
 
- {
 
-     int ret = 0;
 
- #if !defined(OPENSSL_NO_DSA) || !defined(OPENSSL_NO_RSA)
 
-     if (
 
- # ifndef OPENSSL_NO_RSA
 
-            cmd == SSL_CTRL_SET_TMP_RSA || cmd == SSL_CTRL_SET_TMP_RSA_CB ||
 
- # endif
 
- # ifndef OPENSSL_NO_DSA
 
-            cmd == SSL_CTRL_SET_TMP_DH || cmd == SSL_CTRL_SET_TMP_DH_CB ||
 
- # endif
 
-            0) {
 
-         if (!ssl_cert_inst(&s->cert)) {
 
-             SSLerr(SSL_F_SSL3_CTRL, ERR_R_MALLOC_FAILURE);
 
-             return (0);
 
-         }
 
-     }
 
- #endif
 
-     switch (cmd) {
 
-     case SSL_CTRL_GET_SESSION_REUSED:
 
-         ret = s->hit;
 
-         break;
 
-     case SSL_CTRL_GET_CLIENT_CERT_REQUEST:
 
-         break;
 
-     case SSL_CTRL_GET_NUM_RENEGOTIATIONS:
 
-         ret = s->s3->num_renegotiations;
 
-         break;
 
-     case SSL_CTRL_CLEAR_NUM_RENEGOTIATIONS:
 
-         ret = s->s3->num_renegotiations;
 
-         s->s3->num_renegotiations = 0;
 
-         break;
 
-     case SSL_CTRL_GET_TOTAL_RENEGOTIATIONS:
 
-         ret = s->s3->total_renegotiations;
 
-         break;
 
-     case SSL_CTRL_GET_FLAGS:
 
-         ret = (int)(s->s3->flags);
 
-         break;
 
- #ifndef OPENSSL_NO_RSA
 
-     case SSL_CTRL_NEED_TMP_RSA:
 
-         if ((s->cert != NULL) && (s->cert->rsa_tmp == NULL) &&
 
-             ((s->cert->pkeys[SSL_PKEY_RSA_ENC].privatekey == NULL) ||
 
-              (EVP_PKEY_size(s->cert->pkeys[SSL_PKEY_RSA_ENC].privatekey) >
 
-               (512 / 8))))
 
-             ret = 1;
 
-         break;
 
-     case SSL_CTRL_SET_TMP_RSA:
 
-         {
 
-             RSA *rsa = (RSA *)parg;
 
-             if (rsa == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTRL, ERR_R_PASSED_NULL_PARAMETER);
 
-                 return (ret);
 
-             }
 
-             if ((rsa = RSAPrivateKey_dup(rsa)) == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTRL, ERR_R_RSA_LIB);
 
-                 return (ret);
 
-             }
 
-             if (s->cert->rsa_tmp != NULL)
 
-                 RSA_free(s->cert->rsa_tmp);
 
-             s->cert->rsa_tmp = rsa;
 
-             ret = 1;
 
-         }
 
-         break;
 
-     case SSL_CTRL_SET_TMP_RSA_CB:
 
-         {
 
-             SSLerr(SSL_F_SSL3_CTRL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
 
-             return (ret);
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_DH
 
-     case SSL_CTRL_SET_TMP_DH:
 
-         {
 
-             DH *dh = (DH *)parg;
 
-             if (dh == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTRL, ERR_R_PASSED_NULL_PARAMETER);
 
-                 return (ret);
 
-             }
 
-             if ((dh = DHparams_dup(dh)) == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTRL, ERR_R_DH_LIB);
 
-                 return (ret);
 
-             }
 
-             if (s->cert->dh_tmp != NULL)
 
-                 DH_free(s->cert->dh_tmp);
 
-             s->cert->dh_tmp = dh;
 
-             ret = 1;
 
-         }
 
-         break;
 
-     case SSL_CTRL_SET_TMP_DH_CB:
 
-         {
 
-             SSLerr(SSL_F_SSL3_CTRL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
 
-             return (ret);
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_ECDH
 
-     case SSL_CTRL_SET_TMP_ECDH:
 
-         {
 
-             EC_KEY *ecdh = NULL;
 
-             if (parg == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTRL, ERR_R_PASSED_NULL_PARAMETER);
 
-                 return (ret);
 
-             }
 
-             if (!EC_KEY_up_ref((EC_KEY *)parg)) {
 
-                 SSLerr(SSL_F_SSL3_CTRL, ERR_R_ECDH_LIB);
 
-                 return (ret);
 
-             }
 
-             ecdh = (EC_KEY *)parg;
 
-             if (!(s->options & SSL_OP_SINGLE_ECDH_USE)) {
 
-                 if (!EC_KEY_generate_key(ecdh)) {
 
-                     EC_KEY_free(ecdh);
 
-                     SSLerr(SSL_F_SSL3_CTRL, ERR_R_ECDH_LIB);
 
-                     return (ret);
 
-                 }
 
-             }
 
-             if (s->cert->ecdh_tmp != NULL)
 
-                 EC_KEY_free(s->cert->ecdh_tmp);
 
-             s->cert->ecdh_tmp = ecdh;
 
-             ret = 1;
 
-         }
 
-         break;
 
-     case SSL_CTRL_SET_TMP_ECDH_CB:
 
-         {
 
-             SSLerr(SSL_F_SSL3_CTRL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
 
-             return (ret);
 
-         }
 
-         break;
 
- #endif                          /* !OPENSSL_NO_ECDH */
 
- #ifndef OPENSSL_NO_TLSEXT
 
-     case SSL_CTRL_SET_TLSEXT_HOSTNAME:
 
-         if (larg == TLSEXT_NAMETYPE_host_name) {
 
-             size_t len;
 
-             if (s->tlsext_hostname != NULL)
 
-                 OPENSSL_free(s->tlsext_hostname);
 
-             s->tlsext_hostname = NULL;
 
-             ret = 1;
 
-             if (parg == NULL)
 
-                 break;
 
-             len = strlen((char *)parg);
 
-             if (len == 0 || len > TLSEXT_MAXLEN_host_name) {
 
-                 SSLerr(SSL_F_SSL3_CTRL, SSL_R_SSL3_EXT_INVALID_SERVERNAME);
 
-                 return 0;
 
-             }
 
-             if ((s->tlsext_hostname = BUF_strdup((char *)parg)) == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTRL, ERR_R_INTERNAL_ERROR);
 
-                 return 0;
 
-             }
 
-         } else {
 
-             SSLerr(SSL_F_SSL3_CTRL, SSL_R_SSL3_EXT_INVALID_SERVERNAME_TYPE);
 
-             return 0;
 
-         }
 
-         break;
 
-     case SSL_CTRL_SET_TLSEXT_DEBUG_ARG:
 
-         s->tlsext_debug_arg = parg;
 
-         ret = 1;
 
-         break;
 
- # ifdef TLSEXT_TYPE_opaque_prf_input
 
-     case SSL_CTRL_SET_TLSEXT_OPAQUE_PRF_INPUT:
 
-         if (larg > 12288) {     /* actual internal limit is 2^16 for the
 
-                                  * complete hello message * (including the
 
-                                  * cert chain and everything) */
 
-             SSLerr(SSL_F_SSL3_CTRL, SSL_R_OPAQUE_PRF_INPUT_TOO_LONG);
 
-             break;
 
-         }
 
-         if (s->tlsext_opaque_prf_input != NULL)
 
-             OPENSSL_free(s->tlsext_opaque_prf_input);
 
-         if ((size_t)larg == 0)
 
-             s->tlsext_opaque_prf_input = OPENSSL_malloc(1); /* dummy byte
 
-                                                              * just to get
 
-                                                              * non-NULL */
 
-         else
 
-             s->tlsext_opaque_prf_input = BUF_memdup(parg, (size_t)larg);
 
-         if (s->tlsext_opaque_prf_input != NULL) {
 
-             s->tlsext_opaque_prf_input_len = (size_t)larg;
 
-             ret = 1;
 
-         } else
 
-             s->tlsext_opaque_prf_input_len = 0;
 
-         break;
 
- # endif
 
-     case SSL_CTRL_SET_TLSEXT_STATUS_REQ_TYPE:
 
-         s->tlsext_status_type = larg;
 
-         ret = 1;
 
-         break;
 
-     case SSL_CTRL_GET_TLSEXT_STATUS_REQ_EXTS:
 
-         *(STACK_OF(X509_EXTENSION) **)parg = s->tlsext_ocsp_exts;
 
-         ret = 1;
 
-         break;
 
-     case SSL_CTRL_SET_TLSEXT_STATUS_REQ_EXTS:
 
-         s->tlsext_ocsp_exts = parg;
 
-         ret = 1;
 
-         break;
 
-     case SSL_CTRL_GET_TLSEXT_STATUS_REQ_IDS:
 
-         *(STACK_OF(OCSP_RESPID) **)parg = s->tlsext_ocsp_ids;
 
-         ret = 1;
 
-         break;
 
-     case SSL_CTRL_SET_TLSEXT_STATUS_REQ_IDS:
 
-         s->tlsext_ocsp_ids = parg;
 
-         ret = 1;
 
-         break;
 
-     case SSL_CTRL_GET_TLSEXT_STATUS_REQ_OCSP_RESP:
 
-         *(unsigned char **)parg = s->tlsext_ocsp_resp;
 
-         return s->tlsext_ocsp_resplen;
 
-     case SSL_CTRL_SET_TLSEXT_STATUS_REQ_OCSP_RESP:
 
-         if (s->tlsext_ocsp_resp)
 
-             OPENSSL_free(s->tlsext_ocsp_resp);
 
-         s->tlsext_ocsp_resp = parg;
 
-         s->tlsext_ocsp_resplen = larg;
 
-         ret = 1;
 
-         break;
 
- # ifndef OPENSSL_NO_HEARTBEATS
 
-     case SSL_CTRL_TLS_EXT_SEND_HEARTBEAT:
 
-         if (SSL_version(s) == DTLS1_VERSION
 
-             || SSL_version(s) == DTLS1_BAD_VER)
 
-             ret = dtls1_heartbeat(s);
 
-         else
 
-             ret = tls1_heartbeat(s);
 
-         break;
 
-     case SSL_CTRL_GET_TLS_EXT_HEARTBEAT_PENDING:
 
-         ret = s->tlsext_hb_pending;
 
-         break;
 
-     case SSL_CTRL_SET_TLS_EXT_HEARTBEAT_NO_REQUESTS:
 
-         if (larg)
 
-             s->tlsext_heartbeat |= SSL_TLSEXT_HB_DONT_RECV_REQUESTS;
 
-         else
 
-             s->tlsext_heartbeat &= ~SSL_TLSEXT_HB_DONT_RECV_REQUESTS;
 
-         ret = 1;
 
-         break;
 
- # endif
 
- #endif                          /* !OPENSSL_NO_TLSEXT */
 
-     case SSL_CTRL_CHECK_PROTO_VERSION:
 
-         /*
 
-          * For library-internal use; checks that the current protocol is the
 
-          * highest enabled version (according to s->ctx->method, as version
 
-          * negotiation may have changed s->method).
 
-          */
 
-         if (s->version == s->ctx->method->version)
 
-             return 1;
 
-         /*
 
-          * Apparently we're using a version-flexible SSL_METHOD (not at its
 
-          * highest protocol version).
 
-          */
 
-         if (s->ctx->method->version == SSLv23_method()->version) {
 
- #if TLS_MAX_VERSION != TLS1_2_VERSION
 
- # error Code needs update for SSLv23_method() support beyond TLS1_2_VERSION.
 
- #endif
 
-             if (!(s->options & SSL_OP_NO_TLSv1_2))
 
-                 return s->version == TLS1_2_VERSION;
 
-             if (!(s->options & SSL_OP_NO_TLSv1_1))
 
-                 return s->version == TLS1_1_VERSION;
 
-             if (!(s->options & SSL_OP_NO_TLSv1))
 
-                 return s->version == TLS1_VERSION;
 
-             if (!(s->options & SSL_OP_NO_SSLv3))
 
-                 return s->version == SSL3_VERSION;
 
-             if (!(s->options & SSL_OP_NO_SSLv2))
 
-                 return s->version == SSL2_VERSION;
 
-         }
 
-         return 0;               /* Unexpected state; fail closed. */
 
-     default:
 
-         break;
 
-     }
 
-     return (ret);
 
- }
 
- long ssl3_callback_ctrl(SSL *s, int cmd, void (*fp) (void))
 
- {
 
-     int ret = 0;
 
- #if !defined(OPENSSL_NO_DSA) || !defined(OPENSSL_NO_RSA)
 
-     if (
 
- # ifndef OPENSSL_NO_RSA
 
-            cmd == SSL_CTRL_SET_TMP_RSA_CB ||
 
- # endif
 
- # ifndef OPENSSL_NO_DSA
 
-            cmd == SSL_CTRL_SET_TMP_DH_CB ||
 
- # endif
 
-            0) {
 
-         if (!ssl_cert_inst(&s->cert)) {
 
-             SSLerr(SSL_F_SSL3_CALLBACK_CTRL, ERR_R_MALLOC_FAILURE);
 
-             return (0);
 
-         }
 
-     }
 
- #endif
 
-     switch (cmd) {
 
- #ifndef OPENSSL_NO_RSA
 
-     case SSL_CTRL_SET_TMP_RSA_CB:
 
-         {
 
-             s->cert->rsa_tmp_cb = (RSA *(*)(SSL *, int, int))fp;
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_DH
 
-     case SSL_CTRL_SET_TMP_DH_CB:
 
-         {
 
-             s->cert->dh_tmp_cb = (DH *(*)(SSL *, int, int))fp;
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_ECDH
 
-     case SSL_CTRL_SET_TMP_ECDH_CB:
 
-         {
 
-             s->cert->ecdh_tmp_cb = (EC_KEY *(*)(SSL *, int, int))fp;
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_TLSEXT
 
-     case SSL_CTRL_SET_TLSEXT_DEBUG_CB:
 
-         s->tlsext_debug_cb = (void (*)(SSL *, int, int,
 
-                                        unsigned char *, int, void *))fp;
 
-         break;
 
- #endif
 
-     default:
 
-         break;
 
-     }
 
-     return (ret);
 
- }
 
- long ssl3_ctx_ctrl(SSL_CTX *ctx, int cmd, long larg, void *parg)
 
- {
 
-     CERT *cert;
 
-     cert = ctx->cert;
 
-     switch (cmd) {
 
- #ifndef OPENSSL_NO_RSA
 
-     case SSL_CTRL_NEED_TMP_RSA:
 
-         if ((cert->rsa_tmp == NULL) &&
 
-             ((cert->pkeys[SSL_PKEY_RSA_ENC].privatekey == NULL) ||
 
-              (EVP_PKEY_size(cert->pkeys[SSL_PKEY_RSA_ENC].privatekey) >
 
-               (512 / 8)))
 
-             )
 
-             return (1);
 
-         else
 
-             return (0);
 
-         /* break; */
 
-     case SSL_CTRL_SET_TMP_RSA:
 
-         {
 
-             RSA *rsa;
 
-             int i;
 
-             rsa = (RSA *)parg;
 
-             i = 1;
 
-             if (rsa == NULL)
 
-                 i = 0;
 
-             else {
 
-                 if ((rsa = RSAPrivateKey_dup(rsa)) == NULL)
 
-                     i = 0;
 
-             }
 
-             if (!i) {
 
-                 SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_RSA_LIB);
 
-                 return (0);
 
-             } else {
 
-                 if (cert->rsa_tmp != NULL)
 
-                     RSA_free(cert->rsa_tmp);
 
-                 cert->rsa_tmp = rsa;
 
-                 return (1);
 
-             }
 
-         }
 
-         /* break; */
 
-     case SSL_CTRL_SET_TMP_RSA_CB:
 
-         {
 
-             SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
 
-             return (0);
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_DH
 
-     case SSL_CTRL_SET_TMP_DH:
 
-         {
 
-             DH *new = NULL, *dh;
 
-             dh = (DH *)parg;
 
-             if ((new = DHparams_dup(dh)) == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_DH_LIB);
 
-                 return 0;
 
-             }
 
-             if (cert->dh_tmp != NULL)
 
-                 DH_free(cert->dh_tmp);
 
-             cert->dh_tmp = new;
 
-             return 1;
 
-         }
 
-         /*
 
-          * break;
 
-          */
 
-     case SSL_CTRL_SET_TMP_DH_CB:
 
-         {
 
-             SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
 
-             return (0);
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_ECDH
 
-     case SSL_CTRL_SET_TMP_ECDH:
 
-         {
 
-             EC_KEY *ecdh = NULL;
 
-             if (parg == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_ECDH_LIB);
 
-                 return 0;
 
-             }
 
-             ecdh = EC_KEY_dup((EC_KEY *)parg);
 
-             if (ecdh == NULL) {
 
-                 SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_EC_LIB);
 
-                 return 0;
 
-             }
 
-             if (!(ctx->options & SSL_OP_SINGLE_ECDH_USE)) {
 
-                 if (!EC_KEY_generate_key(ecdh)) {
 
-                     EC_KEY_free(ecdh);
 
-                     SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_ECDH_LIB);
 
-                     return 0;
 
-                 }
 
-             }
 
-             if (cert->ecdh_tmp != NULL) {
 
-                 EC_KEY_free(cert->ecdh_tmp);
 
-             }
 
-             cert->ecdh_tmp = ecdh;
 
-             return 1;
 
-         }
 
-         /* break; */
 
-     case SSL_CTRL_SET_TMP_ECDH_CB:
 
-         {
 
-             SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_SHOULD_NOT_HAVE_BEEN_CALLED);
 
-             return (0);
 
-         }
 
-         break;
 
- #endif                          /* !OPENSSL_NO_ECDH */
 
- #ifndef OPENSSL_NO_TLSEXT
 
-     case SSL_CTRL_SET_TLSEXT_SERVERNAME_ARG:
 
-         ctx->tlsext_servername_arg = parg;
 
-         break;
 
-     case SSL_CTRL_SET_TLSEXT_TICKET_KEYS:
 
-     case SSL_CTRL_GET_TLSEXT_TICKET_KEYS:
 
-         {
 
-             unsigned char *keys = parg;
 
-             if (!keys)
 
-                 return 48;
 
-             if (larg != 48) {
 
-                 SSLerr(SSL_F_SSL3_CTX_CTRL, SSL_R_INVALID_TICKET_KEYS_LENGTH);
 
-                 return 0;
 
-             }
 
-             if (cmd == SSL_CTRL_SET_TLSEXT_TICKET_KEYS) {
 
-                 memcpy(ctx->tlsext_tick_key_name, keys, 16);
 
-                 memcpy(ctx->tlsext_tick_hmac_key, keys + 16, 16);
 
-                 memcpy(ctx->tlsext_tick_aes_key, keys + 32, 16);
 
-             } else {
 
-                 memcpy(keys, ctx->tlsext_tick_key_name, 16);
 
-                 memcpy(keys + 16, ctx->tlsext_tick_hmac_key, 16);
 
-                 memcpy(keys + 32, ctx->tlsext_tick_aes_key, 16);
 
-             }
 
-             return 1;
 
-         }
 
- # ifdef TLSEXT_TYPE_opaque_prf_input
 
-     case SSL_CTRL_SET_TLSEXT_OPAQUE_PRF_INPUT_CB_ARG:
 
-         ctx->tlsext_opaque_prf_input_callback_arg = parg;
 
-         return 1;
 
- # endif
 
-     case SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB_ARG:
 
-         ctx->tlsext_status_arg = parg;
 
-         return 1;
 
-         break;
 
- # ifndef OPENSSL_NO_SRP
 
-     case SSL_CTRL_SET_TLS_EXT_SRP_USERNAME:
 
-         ctx->srp_ctx.srp_Mask |= SSL_kSRP;
 
-         if (ctx->srp_ctx.login != NULL)
 
-             OPENSSL_free(ctx->srp_ctx.login);
 
-         ctx->srp_ctx.login = NULL;
 
-         if (parg == NULL)
 
-             break;
 
-         if (strlen((const char *)parg) > 255
 
-             || strlen((const char *)parg) < 1) {
 
-             SSLerr(SSL_F_SSL3_CTX_CTRL, SSL_R_INVALID_SRP_USERNAME);
 
-             return 0;
 
-         }
 
-         if ((ctx->srp_ctx.login = BUF_strdup((char *)parg)) == NULL) {
 
-             SSLerr(SSL_F_SSL3_CTX_CTRL, ERR_R_INTERNAL_ERROR);
 
-             return 0;
 
-         }
 
-         break;
 
-     case SSL_CTRL_SET_TLS_EXT_SRP_PASSWORD:
 
-         ctx->srp_ctx.SRP_give_srp_client_pwd_callback =
 
-             srp_password_from_info_cb;
 
-         ctx->srp_ctx.info = parg;
 
-         break;
 
-     case SSL_CTRL_SET_SRP_ARG:
 
-         ctx->srp_ctx.srp_Mask |= SSL_kSRP;
 
-         ctx->srp_ctx.SRP_cb_arg = parg;
 
-         break;
 
-     case SSL_CTRL_SET_TLS_EXT_SRP_STRENGTH:
 
-         ctx->srp_ctx.strength = larg;
 
-         break;
 
- # endif
 
- #endif                          /* !OPENSSL_NO_TLSEXT */
 
-         /* A Thawte special :-) */
 
-     case SSL_CTRL_EXTRA_CHAIN_CERT:
 
-         if (ctx->extra_certs == NULL) {
 
-             if ((ctx->extra_certs = sk_X509_new_null()) == NULL)
 
-                 return (0);
 
-         }
 
-         sk_X509_push(ctx->extra_certs, (X509 *)parg);
 
-         break;
 
-     case SSL_CTRL_GET_EXTRA_CHAIN_CERTS:
 
-         *(STACK_OF(X509) **)parg = ctx->extra_certs;
 
-         break;
 
-     case SSL_CTRL_CLEAR_EXTRA_CHAIN_CERTS:
 
-         if (ctx->extra_certs) {
 
-             sk_X509_pop_free(ctx->extra_certs, X509_free);
 
-             ctx->extra_certs = NULL;
 
-         }
 
-         break;
 
-     default:
 
-         return (0);
 
-     }
 
-     return (1);
 
- }
 
- long ssl3_ctx_callback_ctrl(SSL_CTX *ctx, int cmd, void (*fp) (void))
 
- {
 
-     CERT *cert;
 
-     cert = ctx->cert;
 
-     switch (cmd) {
 
- #ifndef OPENSSL_NO_RSA
 
-     case SSL_CTRL_SET_TMP_RSA_CB:
 
-         {
 
-             cert->rsa_tmp_cb = (RSA *(*)(SSL *, int, int))fp;
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_DH
 
-     case SSL_CTRL_SET_TMP_DH_CB:
 
-         {
 
-             cert->dh_tmp_cb = (DH *(*)(SSL *, int, int))fp;
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_ECDH
 
-     case SSL_CTRL_SET_TMP_ECDH_CB:
 
-         {
 
-             cert->ecdh_tmp_cb = (EC_KEY *(*)(SSL *, int, int))fp;
 
-         }
 
-         break;
 
- #endif
 
- #ifndef OPENSSL_NO_TLSEXT
 
-     case SSL_CTRL_SET_TLSEXT_SERVERNAME_CB:
 
-         ctx->tlsext_servername_callback = (int (*)(SSL *, int *, void *))fp;
 
-         break;
 
- # ifdef TLSEXT_TYPE_opaque_prf_input
 
-     case SSL_CTRL_SET_TLSEXT_OPAQUE_PRF_INPUT_CB:
 
-         ctx->tlsext_opaque_prf_input_callback =
 
-             (int (*)(SSL *, void *, size_t, void *))fp;
 
-         break;
 
- # endif
 
-     case SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB:
 
-         ctx->tlsext_status_cb = (int (*)(SSL *, void *))fp;
 
-         break;
 
-     case SSL_CTRL_SET_TLSEXT_TICKET_KEY_CB:
 
-         ctx->tlsext_ticket_key_cb = (int (*)(SSL *, unsigned char *,
 
-                                              unsigned char *,
 
-                                              EVP_CIPHER_CTX *,
 
-                                              HMAC_CTX *, int))fp;
 
-         break;
 
- # ifndef OPENSSL_NO_SRP
 
-     case SSL_CTRL_SET_SRP_VERIFY_PARAM_CB:
 
-         ctx->srp_ctx.srp_Mask |= SSL_kSRP;
 
-         ctx->srp_ctx.SRP_verify_param_callback = (int (*)(SSL *, void *))fp;
 
-         break;
 
-     case SSL_CTRL_SET_TLS_EXT_SRP_USERNAME_CB:
 
-         ctx->srp_ctx.srp_Mask |= SSL_kSRP;
 
-         ctx->srp_ctx.TLS_ext_srp_username_callback =
 
-             (int (*)(SSL *, int *, void *))fp;
 
-         break;
 
-     case SSL_CTRL_SET_SRP_GIVE_CLIENT_PWD_CB:
 
-         ctx->srp_ctx.srp_Mask |= SSL_kSRP;
 
-         ctx->srp_ctx.SRP_give_srp_client_pwd_callback =
 
-             (char *(*)(SSL *, void *))fp;
 
-         break;
 
- # endif
 
- #endif
 
-     default:
 
-         return (0);
 
-     }
 
-     return (1);
 
- }
 
- /*
 
-  * This function needs to check if the ciphers required are actually
 
-  * available
 
-  */
 
- const SSL_CIPHER *ssl3_get_cipher_by_char(const unsigned char *p)
 
- {
 
-     SSL_CIPHER c;
 
-     const SSL_CIPHER *cp;
 
-     unsigned long id;
 
-     id = 0x03000000L | ((unsigned long)p[0] << 8L) | (unsigned long)p[1];
 
-     c.id = id;
 
-     cp = OBJ_bsearch_ssl_cipher_id(&c, ssl3_ciphers, SSL3_NUM_CIPHERS);
 
- #ifdef DEBUG_PRINT_UNKNOWN_CIPHERSUITES
 
-     if (cp == NULL)
 
-         fprintf(stderr, "Unknown cipher ID %x\n", (p[0] << 8) | p[1]);
 
- #endif
 
-     if (cp == NULL || cp->valid == 0)
 
-         return NULL;
 
-     else
 
-         return cp;
 
- }
 
- int ssl3_put_cipher_by_char(const SSL_CIPHER *c, unsigned char *p)
 
- {
 
-     long l;
 
-     if (p != NULL) {
 
-         l = c->id;
 
-         if ((l & 0xff000000) != 0x03000000)
 
-             return (0);
 
-         p[0] = ((unsigned char)(l >> 8L)) & 0xFF;
 
-         p[1] = ((unsigned char)(l)) & 0xFF;
 
-     }
 
-     return (2);
 
- }
 
- SSL_CIPHER *ssl3_choose_cipher(SSL *s, STACK_OF(SSL_CIPHER) *clnt,
 
-                                STACK_OF(SSL_CIPHER) *srvr)
 
- {
 
-     SSL_CIPHER *c, *ret = NULL;
 
-     STACK_OF(SSL_CIPHER) *prio, *allow;
 
-     int i, ii, ok;
 
- #if !defined(OPENSSL_NO_TLSEXT) && !defined(OPENSSL_NO_EC)
 
-     unsigned int j;
 
-     int ec_ok, ec_nid;
 
-     unsigned char ec_search1 = 0, ec_search2 = 0;
 
- #endif
 
-     CERT *cert;
 
-     unsigned long alg_k, alg_a, mask_k, mask_a, emask_k, emask_a;
 
-     /* Let's see which ciphers we can support */
 
-     cert = s->cert;
 
- #if 0
 
-     /*
 
-      * Do not set the compare functions, because this may lead to a
 
-      * reordering by "id". We want to keep the original ordering. We may pay
 
-      * a price in performance during sk_SSL_CIPHER_find(), but would have to
 
-      * pay with the price of sk_SSL_CIPHER_dup().
 
-      */
 
-     sk_SSL_CIPHER_set_cmp_func(srvr, ssl_cipher_ptr_id_cmp);
 
-     sk_SSL_CIPHER_set_cmp_func(clnt, ssl_cipher_ptr_id_cmp);
 
- #endif
 
- #ifdef CIPHER_DEBUG
 
-     fprintf(stderr, "Server has %d from %p:\n", sk_SSL_CIPHER_num(srvr),
 
-             (void *)srvr);
 
-     for (i = 0; i < sk_SSL_CIPHER_num(srvr); ++i) {
 
-         c = sk_SSL_CIPHER_value(srvr, i);
 
-         fprintf(stderr, "%p:%s\n", (void *)c, c->name);
 
-     }
 
-     fprintf(stderr, "Client sent %d from %p:\n", sk_SSL_CIPHER_num(clnt),
 
-             (void *)clnt);
 
-     for (i = 0; i < sk_SSL_CIPHER_num(clnt); ++i) {
 
-         c = sk_SSL_CIPHER_value(clnt, i);
 
-         fprintf(stderr, "%p:%s\n", (void *)c, c->name);
 
-     }
 
- #endif
 
-     if (s->options & SSL_OP_CIPHER_SERVER_PREFERENCE) {
 
-         prio = srvr;
 
-         allow = clnt;
 
-     } else {
 
-         prio = clnt;
 
-         allow = srvr;
 
-     }
 
-     for (i = 0; i < sk_SSL_CIPHER_num(prio); i++) {
 
-         c = sk_SSL_CIPHER_value(prio, i);
 
-         /* Skip TLS v1.2 only ciphersuites if lower than v1.2 */
 
-         if ((c->algorithm_ssl & SSL_TLSV1_2) &&
 
-             (TLS1_get_version(s) < TLS1_2_VERSION))
 
-             continue;
 
-         ssl_set_cert_masks(cert, c);
 
-         mask_k = cert->mask_k;
 
-         mask_a = cert->mask_a;
 
-         emask_k = cert->export_mask_k;
 
-         emask_a = cert->export_mask_a;
 
- #ifndef OPENSSL_NO_SRP
 
-         if (s->srp_ctx.srp_Mask & SSL_kSRP) {
 
-             mask_k |= SSL_kSRP;
 
-             emask_k |= SSL_kSRP;
 
-             mask_a |= SSL_aSRP;
 
-             emask_a |= SSL_aSRP;
 
-         }
 
- #endif
 
- #ifdef KSSL_DEBUG
 
-         /*
 
-          * fprintf(stderr,"ssl3_choose_cipher %d alg= %lx\n",
 
-          * i,c->algorithms);
 
-          */
 
- #endif                          /* KSSL_DEBUG */
 
-         alg_k = c->algorithm_mkey;
 
-         alg_a = c->algorithm_auth;
 
- #ifndef OPENSSL_NO_KRB5
 
-         if (alg_k & SSL_kKRB5) {
 
-             if (!kssl_keytab_is_available(s->kssl_ctx))
 
-                 continue;
 
-         }
 
- #endif                          /* OPENSSL_NO_KRB5 */
 
- #ifndef OPENSSL_NO_PSK
 
-         /* with PSK there must be server callback set */
 
-         if ((alg_k & SSL_kPSK) && s->psk_server_callback == NULL)
 
-             continue;
 
- #endif                          /* OPENSSL_NO_PSK */
 
-         if (SSL_C_IS_EXPORT(c)) {
 
-             ok = (alg_k & emask_k) && (alg_a & emask_a);
 
- #ifdef CIPHER_DEBUG
 
-             fprintf(stderr, "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s (export)\n",
 
-                     ok, alg_k, alg_a, emask_k, emask_a, (void *)c, c->name);
 
- #endif
 
-         } else {
 
-             ok = (alg_k & mask_k) && (alg_a & mask_a);
 
- #ifdef CIPHER_DEBUG
 
-             fprintf(stderr, "%d:[%08lX:%08lX:%08lX:%08lX]%p:%s\n", ok, alg_k,
 
-                     alg_a, mask_k, mask_a, (void *)c, c->name);
 
- #endif
 
-         }
 
- #ifndef OPENSSL_NO_TLSEXT
 
- # ifndef OPENSSL_NO_EC
 
-         if (
 
-                /*
 
-                 * if we are considering an ECC cipher suite that uses our
 
-                 * certificate
 
-                 */
 
-                (alg_a & SSL_aECDSA || alg_a & SSL_aECDH)
 
-                /* and we have an ECC certificate */
 
-                && (s->cert->pkeys[SSL_PKEY_ECC].x509 != NULL)
 
-                /*
 
-                 * and the client specified a Supported Point Formats
 
-                 * extension
 
-                 */
 
-                && ((s->session->tlsext_ecpointformatlist_length > 0)
 
-                    && (s->session->tlsext_ecpointformatlist != NULL))
 
-                /* and our certificate's point is compressed */
 
-                && ((s->cert->pkeys[SSL_PKEY_ECC].x509->cert_info != NULL)
 
-                    && (s->cert->pkeys[SSL_PKEY_ECC].x509->cert_info->key !=
 
-                        NULL)
 
-                    && (s->cert->pkeys[SSL_PKEY_ECC].x509->cert_info->
 
-                        key->public_key != NULL)
 
-                    && (s->cert->pkeys[SSL_PKEY_ECC].x509->cert_info->
 
-                        key->public_key->data != NULL)
 
-                    &&
 
-                    ((*
 
-                      (s->cert->pkeys[SSL_PKEY_ECC].x509->cert_info->
 
-                       key->public_key->data) == POINT_CONVERSION_COMPRESSED)
 
-                     ||
 
-                     (*
 
-                      (s->cert->pkeys[SSL_PKEY_ECC].x509->cert_info->
 
-                       key->public_key->data) ==
 
-                      POINT_CONVERSION_COMPRESSED + 1)
 
-                    )
 
-                )
 
-             ) {
 
-             ec_ok = 0;
 
-             /*
 
-              * if our certificate's curve is over a field type that the
 
-              * client does not support then do not allow this cipher suite to
 
-              * be negotiated
 
-              */
 
-             if ((s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.ec != NULL)
 
-                 && (s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.ec->group !=
 
-                     NULL)
 
-                 && (s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.ec->
 
-                     group->meth != NULL)
 
-                 &&
 
-                 (EC_METHOD_get_field_type
 
-                  (s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.ec->
 
-                   group->meth) == NID_X9_62_prime_field)
 
-                 ) {
 
-                 for (j = 0; j < s->session->tlsext_ecpointformatlist_length;
 
-                      j++) {
 
-                     if (s->session->tlsext_ecpointformatlist[j] ==
 
-                         TLSEXT_ECPOINTFORMAT_ansiX962_compressed_prime) {
 
-                         ec_ok = 1;
 
-                         break;
 
-                     }
 
-                 }
 
-             } else
 
-                 if (EC_METHOD_get_field_type
 
-                     (s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.ec->
 
-                      group->meth) == NID_X9_62_characteristic_two_field) {
 
-                 for (j = 0; j < s->session->tlsext_ecpointformatlist_length;
 
-                      j++) {
 
-                     if (s->session->tlsext_ecpointformatlist[j] ==
 
-                         TLSEXT_ECPOINTFORMAT_ansiX962_compressed_char2) {
 
-                         ec_ok = 1;
 
-                         break;
 
-                     }
 
-                 }
 
-             }
 
-             ok = ok && ec_ok;
 
-         }
 
-         if (
 
-                /*
 
-                 * if we are considering an ECC cipher suite that uses our
 
-                 * certificate
 
-                 */
 
-                (alg_a & SSL_aECDSA || alg_a & SSL_aECDH)
 
-                /* and we have an ECC certificate */
 
-                && (s->cert->pkeys[SSL_PKEY_ECC].x509 != NULL)
 
-                /*
 
-                 * and the client specified an EllipticCurves extension
 
-                 */
 
-                && ((s->session->tlsext_ellipticcurvelist_length > 0)
 
-                    && (s->session->tlsext_ellipticcurvelist != NULL))
 
-             ) {
 
-             ec_ok = 0;
 
-             if ((s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.ec != NULL)
 
-                 && (s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.ec->group !=
 
-                     NULL)
 
-                 ) {
 
-                 ec_nid =
 
-                     EC_GROUP_get_curve_name(s->cert->
 
-                                             pkeys[SSL_PKEY_ECC].privatekey->
 
-                                             pkey.ec->group);
 
-                 if ((ec_nid == 0)
 
-                     && (s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.
 
-                         ec->group->meth != NULL)
 
-                     ) {
 
-                     if (EC_METHOD_get_field_type
 
-                         (s->cert->pkeys[SSL_PKEY_ECC].privatekey->pkey.
 
-                          ec->group->meth) == NID_X9_62_prime_field) {
 
-                         ec_search1 = 0xFF;
 
-                         ec_search2 = 0x01;
 
-                     } else
 
-                         if (EC_METHOD_get_field_type
 
-                             (s->cert->pkeys[SSL_PKEY_ECC].privatekey->
 
-                              pkey.ec->group->meth) ==
 
-                             NID_X9_62_characteristic_two_field) {
 
-                         ec_search1 = 0xFF;
 
-                         ec_search2 = 0x02;
 
-                     }
 
-                 } else {
 
-                     ec_search1 = 0x00;
 
-                     ec_search2 = tls1_ec_nid2curve_id(ec_nid);
 
-                 }
 
-                 if ((ec_search1 != 0) || (ec_search2 != 0)) {
 
-                     for (j = 0;
 
-                          j < s->session->tlsext_ellipticcurvelist_length / 2;
 
-                          j++) {
 
-                         if ((s->session->tlsext_ellipticcurvelist[2 * j] ==
 
-                              ec_search1)
 
-                             && (s->session->tlsext_ellipticcurvelist[2 * j +
 
-                                                                      1] ==
 
-                                 ec_search2)) {
 
-                             ec_ok = 1;
 
-                             break;
 
-                         }
 
-                     }
 
-                 }
 
-             }
 
-             ok = ok && ec_ok;
 
-         }
 
- #  ifndef OPENSSL_NO_ECDH
 
-         if (
 
-                /*
 
-                 * if we are considering an ECC cipher suite that uses an
 
-                 * ephemeral EC key
 
-                 */
 
-                (alg_k & SSL_kEECDH)
 
-                /* and we have an ephemeral EC key */
 
-                && (s->cert->ecdh_tmp != NULL)
 
-                /*
 
-                 * and the client specified an EllipticCurves extension
 
-                 */
 
-                && ((s->session->tlsext_ellipticcurvelist_length > 0)
 
-                    && (s->session->tlsext_ellipticcurvelist != NULL))
 
-             ) {
 
-             ec_ok = 0;
 
-             if (s->cert->ecdh_tmp->group != NULL) {
 
-                 ec_nid = EC_GROUP_get_curve_name(s->cert->ecdh_tmp->group);
 
-                 if ((ec_nid == 0)
 
-                     && (s->cert->ecdh_tmp->group->meth != NULL)
 
-                     ) {
 
-                     if (EC_METHOD_get_field_type
 
-                         (s->cert->ecdh_tmp->group->meth) ==
 
-                         NID_X9_62_prime_field) {
 
-                         ec_search1 = 0xFF;
 
-                         ec_search2 = 0x01;
 
-                     } else
 
-                         if (EC_METHOD_get_field_type
 
-                             (s->cert->ecdh_tmp->group->meth) ==
 
-                             NID_X9_62_characteristic_two_field) {
 
-                         ec_search1 = 0xFF;
 
-                         ec_search2 = 0x02;
 
-                     }
 
-                 } else {
 
-                     ec_search1 = 0x00;
 
-                     ec_search2 = tls1_ec_nid2curve_id(ec_nid);
 
-                 }
 
-                 if ((ec_search1 != 0) || (ec_search2 != 0)) {
 
-                     for (j = 0;
 
-                          j < s->session->tlsext_ellipticcurvelist_length / 2;
 
-                          j++) {
 
-                         if ((s->session->tlsext_ellipticcurvelist[2 * j] ==
 
-                              ec_search1)
 
-                             && (s->session->tlsext_ellipticcurvelist[2 * j +
 
-                                                                      1] ==
 
-                                 ec_search2)) {
 
-                             ec_ok = 1;
 
-                             break;
 
-                         }
 
-                     }
 
-                 }
 
-             }
 
-             ok = ok && ec_ok;
 
-         }
 
- #  endif                        /* OPENSSL_NO_ECDH */
 
- # endif                         /* OPENSSL_NO_EC */
 
- #endif                          /* OPENSSL_NO_TLSEXT */
 
-         if (!ok)
 
-             continue;
 
-         ii = sk_SSL_CIPHER_find(allow, c);
 
-         if (ii >= 0) {
 
- #if !defined(OPENSSL_NO_EC) && !defined(OPENSSL_NO_TLSEXT)
 
-             if ((alg_k & SSL_kEECDH) && (alg_a & SSL_aECDSA)
 
-                 && s->s3->is_probably_safari) {
 
-                 if (!ret)
 
-                     ret = sk_SSL_CIPHER_value(allow, ii);
 
-                 continue;
 
-             }
 
- #endif
 
-             ret = sk_SSL_CIPHER_value(allow, ii);
 
-             break;
 
-         }
 
-     }
 
-     return (ret);
 
- }
 
- int ssl3_get_req_cert_type(SSL *s, unsigned char *p)
 
- {
 
-     int ret = 0;
 
-     unsigned long alg_k;
 
-     alg_k = s->s3->tmp.new_cipher->algorithm_mkey;
 
- #ifndef OPENSSL_NO_GOST
 
-     if (s->version >= TLS1_VERSION) {
 
-         if (alg_k & SSL_kGOST) {
 
-             p[ret++] = TLS_CT_GOST94_SIGN;
 
-             p[ret++] = TLS_CT_GOST01_SIGN;
 
-             return (ret);
 
-         }
 
-     }
 
- #endif
 
- #ifndef OPENSSL_NO_DH
 
-     if (alg_k & (SSL_kDHr | SSL_kEDH)) {
 
- # ifndef OPENSSL_NO_RSA
 
-         p[ret++] = SSL3_CT_RSA_FIXED_DH;
 
- # endif
 
- # ifndef OPENSSL_NO_DSA
 
-         p[ret++] = SSL3_CT_DSS_FIXED_DH;
 
- # endif
 
-     }
 
-     if ((s->version == SSL3_VERSION) &&
 
-         (alg_k & (SSL_kEDH | SSL_kDHd | SSL_kDHr))) {
 
- # ifndef OPENSSL_NO_RSA
 
-         p[ret++] = SSL3_CT_RSA_EPHEMERAL_DH;
 
- # endif
 
- # ifndef OPENSSL_NO_DSA
 
-         p[ret++] = SSL3_CT_DSS_EPHEMERAL_DH;
 
- # endif
 
-     }
 
- #endif                          /* !OPENSSL_NO_DH */
 
- #ifndef OPENSSL_NO_RSA
 
-     p[ret++] = SSL3_CT_RSA_SIGN;
 
- #endif
 
- #ifndef OPENSSL_NO_DSA
 
-     p[ret++] = SSL3_CT_DSS_SIGN;
 
- #endif
 
- #ifndef OPENSSL_NO_ECDH
 
-     if ((alg_k & (SSL_kECDHr | SSL_kECDHe)) && (s->version >= TLS1_VERSION)) {
 
-         p[ret++] = TLS_CT_RSA_FIXED_ECDH;
 
-         p[ret++] = TLS_CT_ECDSA_FIXED_ECDH;
 
-     }
 
- #endif
 
- #ifndef OPENSSL_NO_ECDSA
 
-     /*
 
-      * ECDSA certs can be used with RSA cipher suites as well so we don't
 
-      * need to check for SSL_kECDH or SSL_kEECDH
 
-      */
 
-     if (s->version >= TLS1_VERSION) {
 
-         p[ret++] = TLS_CT_ECDSA_SIGN;
 
-     }
 
- #endif
 
-     return (ret);
 
- }
 
- int ssl3_shutdown(SSL *s)
 
- {
 
-     int ret;
 
-     /*
 
-      * Don't do anything much if we have not done the handshake or we don't
 
-      * want to send messages :-)
 
-      */
 
-     if ((s->quiet_shutdown) || (s->state == SSL_ST_BEFORE)) {
 
-         s->shutdown = (SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN);
 
-         return (1);
 
-     }
 
-     if (!(s->shutdown & SSL_SENT_SHUTDOWN)) {
 
-         s->shutdown |= SSL_SENT_SHUTDOWN;
 
- #if 1
 
-         ssl3_send_alert(s, SSL3_AL_WARNING, SSL_AD_CLOSE_NOTIFY);
 
- #endif
 
-         /*
 
-          * our shutdown alert has been sent now, and if it still needs to be
 
-          * written, s->s3->alert_dispatch will be true
 
-          */
 
-         if (s->s3->alert_dispatch)
 
-             return (-1);        /* return WANT_WRITE */
 
-     } else if (s->s3->alert_dispatch) {
 
-         /* resend it if not sent */
 
- #if 1
 
-         ret = s->method->ssl_dispatch_alert(s);
 
-         if (ret == -1) {
 
-             /*
 
-              * we only get to return -1 here the 2nd/Nth invocation, we must
 
-              * have already signalled return 0 upon a previous invoation,
 
-              * return WANT_WRITE
 
-              */
 
-             return (ret);
 
-         }
 
- #endif
 
-     } else if (!(s->shutdown & SSL_RECEIVED_SHUTDOWN)) {
 
-         /*
 
-          * If we are waiting for a close from our peer, we are closed
 
-          */
 
-         s->method->ssl_read_bytes(s, 0, NULL, 0, 0);
 
-         if (!(s->shutdown & SSL_RECEIVED_SHUTDOWN)) {
 
-             return (-1);        /* return WANT_READ */
 
-         }
 
-     }
 
-     if ((s->shutdown == (SSL_SENT_SHUTDOWN | SSL_RECEIVED_SHUTDOWN)) &&
 
-         !s->s3->alert_dispatch)
 
-         return (1);
 
-     else
 
-         return (0);
 
- }
 
- int ssl3_write(SSL *s, const void *buf, int len)
 
- {
 
-     int ret, n;
 
- #if 0
 
-     if (s->shutdown & SSL_SEND_SHUTDOWN) {
 
-         s->rwstate = SSL_NOTHING;
 
-         return (0);
 
-     }
 
- #endif
 
-     clear_sys_error();
 
-     if (s->s3->renegotiate)
 
-         ssl3_renegotiate_check(s);
 
-     /*
 
-      * This is an experimental flag that sends the last handshake message in
 
-      * the same packet as the first use data - used to see if it helps the
 
-      * TCP protocol during session-id reuse
 
-      */
 
-     /* The second test is because the buffer may have been removed */
 
-     if ((s->s3->flags & SSL3_FLAGS_POP_BUFFER) && (s->wbio == s->bbio)) {
 
-         /* First time through, we write into the buffer */
 
-         if (s->s3->delay_buf_pop_ret == 0) {
 
-             ret = ssl3_write_bytes(s, SSL3_RT_APPLICATION_DATA, buf, len);
 
-             if (ret <= 0)
 
-                 return (ret);
 
-             s->s3->delay_buf_pop_ret = ret;
 
-         }
 
-         s->rwstate = SSL_WRITING;
 
-         n = BIO_flush(s->wbio);
 
-         if (n <= 0)
 
-             return (n);
 
-         s->rwstate = SSL_NOTHING;
 
-         /* We have flushed the buffer, so remove it */
 
-         ssl_free_wbio_buffer(s);
 
-         s->s3->flags &= ~SSL3_FLAGS_POP_BUFFER;
 
-         ret = s->s3->delay_buf_pop_ret;
 
-         s->s3->delay_buf_pop_ret = 0;
 
-     } else {
 
-         ret = s->method->ssl_write_bytes(s, SSL3_RT_APPLICATION_DATA,
 
-                                          buf, len);
 
-         if (ret <= 0)
 
-             return (ret);
 
-     }
 
-     return (ret);
 
- }
 
- static int ssl3_read_internal(SSL *s, void *buf, int len, int peek)
 
- {
 
-     int ret;
 
-     clear_sys_error();
 
-     if (s->s3->renegotiate)
 
-         ssl3_renegotiate_check(s);
 
-     s->s3->in_read_app_data = 1;
 
-     ret =
 
-         s->method->ssl_read_bytes(s, SSL3_RT_APPLICATION_DATA, buf, len,
 
-                                   peek);
 
-     if ((ret == -1) && (s->s3->in_read_app_data == 2)) {
 
-         /*
 
-          * ssl3_read_bytes decided to call s->handshake_func, which called
 
-          * ssl3_read_bytes to read handshake data. However, ssl3_read_bytes
 
-          * actually found application data and thinks that application data
 
-          * makes sense here; so disable handshake processing and try to read
 
-          * application data again.
 
-          */
 
-         s->in_handshake++;
 
-         ret =
 
-             s->method->ssl_read_bytes(s, SSL3_RT_APPLICATION_DATA, buf, len,
 
-                                       peek);
 
-         s->in_handshake--;
 
-     } else
 
-         s->s3->in_read_app_data = 0;
 
-     return (ret);
 
- }
 
- int ssl3_read(SSL *s, void *buf, int len)
 
- {
 
-     return ssl3_read_internal(s, buf, len, 0);
 
- }
 
- int ssl3_peek(SSL *s, void *buf, int len)
 
- {
 
-     return ssl3_read_internal(s, buf, len, 1);
 
- }
 
- int ssl3_renegotiate(SSL *s)
 
- {
 
-     if (s->handshake_func == NULL)
 
-         return (1);
 
-     if (s->s3->flags & SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS)
 
-         return (0);
 
-     s->s3->renegotiate = 1;
 
-     return (1);
 
- }
 
- int ssl3_renegotiate_check(SSL *s)
 
- {
 
-     int ret = 0;
 
-     if (s->s3->renegotiate) {
 
-         if ((s->s3->rbuf.left == 0) &&
 
-             (s->s3->wbuf.left == 0) && !SSL_in_init(s)) {
 
-             /*
 
-              * if we are the server, and we have sent a 'RENEGOTIATE'
 
-              * message, we need to go to SSL_ST_ACCEPT.
 
-              */
 
-             /* SSL_ST_ACCEPT */
 
-             s->state = SSL_ST_RENEGOTIATE;
 
-             s->s3->renegotiate = 0;
 
-             s->s3->num_renegotiations++;
 
-             s->s3->total_renegotiations++;
 
-             ret = 1;
 
-         }
 
-     }
 
-     return (ret);
 
- }
 
- /*
 
-  * If we are using TLS v1.2 or later and default SHA1+MD5 algorithms switch
 
-  * to new SHA256 PRF and handshake macs
 
-  */
 
- long ssl_get_algorithm2(SSL *s)
 
- {
 
-     long alg2 = s->s3->tmp.new_cipher->algorithm2;
 
-     if (s->method->version == TLS1_2_VERSION &&
 
-         alg2 == (SSL_HANDSHAKE_MAC_DEFAULT | TLS1_PRF))
 
-         return SSL_HANDSHAKE_MAC_SHA256 | TLS1_PRF_SHA256;
 
-     return alg2;
 
- }
 
 
  |