% ruby -ropenssl -e 'ctx = OpenSSL::SSL::SSLContext.new; ctx.ciphers = "DEFAULT:!aNULL"'
OpenSSL::SSL::SSLError: no cipher match
ciphers= at org/jruby/ext/openssl/SSLContext.java:391
(root) at -e:1
Interestingly, if I look at the ciphers for DEFAULT and for aNULL specifically, I see no overlap:
[12] pry(main)> default.sort
=> [["AES128-SHA", "TLSv1/SSLv3", 128, 128],
["AES256-SHA", "TLSv1/SSLv3", 256, 256],
["DES-CBC-SHA", "TLSv1/SSLv3", 56, 56],
["DES-CBC3-SHA", "TLSv1/SSLv3", 168, 168],
["DHE-DSS-AES128-SHA", "TLSv1/SSLv3", 128, 128],
["DHE-DSS-AES256-SHA", "TLSv1/SSLv3", 256, 256],
["DHE-RSA-AES128-SHA", "TLSv1/SSLv3", 128, 128],
["DHE-RSA-AES256-SHA", "TLSv1/SSLv3", 256, 256],
["EDH-DSS-DES-CBC3-SHA", "TLSv1/SSLv3", 168, 168],
["EDH-RSA-DES-CBC-SHA", "TLSv1/SSLv3", 56, 56],
["EDH-RSA-DES-CBC3-SHA", "TLSv1/SSLv3", 168, 168],
["EXP-DES-CBC-SHA", "TLSv1/SSLv3", 40, 56],
["EXP-EDH-DSS-DES-CBC-SHA", "TLSv1/SSLv3", 40, 56],
["EXP-EDH-RSA-DES-CBC-SHA", "TLSv1/SSLv3", 40, 56],
["EXP-RC4-MD5", "TLSv1/SSLv3", 40, 128],
["RC4-MD5", "TLSv1/SSLv3", 128, 128],
["RC4-SHA", "TLSv1/SSLv3", 128, 128]]
[13] pry(main)> null.sort
=> [["ADH-AES128-SHA", "TLSv1/SSLv3", 128, 128],
["ADH-AES256-SHA", "TLSv1/SSLv3", 256, 256],
["ADH-DES-CBC-SHA", "TLSv1/SSLv3", 56, 56],
["ADH-DES-CBC3-SHA", "TLSv1/SSLv3", 168, 168],
["ADH-RC4-MD5", "TLSv1/SSLv3", 128, 128],
["EXP-ADH-DES-CBC-SHA", "TLSv1/SSLv3", 40, 128],
["EXP-ADH-RC4-MD5", "TLSv1/SSLv3", 40, 128]]
def ciphers(string)
ctx = OpenSSL::SSL::SSLContext.new
ctx.ciphers = string
ctx.ciphers
end
In trying to disable
aNULLciphers, I get an exception -The code example below is a minimal reproduction of this problem.
The following examples do not raise exceptions:
ctx.ciphers = "DEFAULT"ctx.ciphers = "aNULL"ctx.ciphers = "ALL:!aNULL"Interestingly, if I look at the ciphers for DEFAULT and for aNULL specifically, I see no overlap:
All the
aNULLciphers use anonymous diffie-helman. None of theDEFAULTones do.As a workaround, I think I can generate my own list of ciphers using this kind of hack:
Then doing something like:
ctx.ciphers = ciphers("DEFAULT") - ciphers("aNULL") - ciphers("eNULL") ...