| 
									
										
										
										
											2000-09-19 00:42:30 +08:00
										 |  |  | =pod | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | =head1 NAME | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-04-27 18:38:19 +08:00
										 |  |  | SSL_get1_supported_ciphers, | 
					
						
							|  |  |  | SSL_get_client_ciphers, | 
					
						
							|  |  |  | SSL_get_ciphers, | 
					
						
							|  |  |  | SSL_CTX_get_ciphers, | 
					
						
							|  |  |  | SSL_bytes_to_cipher_list, | 
					
						
							|  |  |  | SSL_get_cipher_list, | 
					
						
							|  |  |  | SSL_get_shared_ciphers | 
					
						
							| 
									
										
										
										
											2016-06-21 19:03:34 +08:00
										 |  |  | - get list of available SSL_CIPHERs | 
					
						
							| 
									
										
										
										
											2000-09-19 00:42:30 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =head1 SYNOPSIS | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  |  #include <openssl/ssl.h> | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2005-03-30 19:50:14 +08:00
										 |  |  |  STACK_OF(SSL_CIPHER) *SSL_get_ciphers(const SSL *ssl); | 
					
						
							| 
									
										
										
										
											2016-04-10 12:18:50 +08:00
										 |  |  |  STACK_OF(SSL_CIPHER) *SSL_CTX_get_ciphers(const SSL_CTX *ctx); | 
					
						
							| 
									
										
										
										
											2016-02-08 03:33:43 +08:00
										 |  |  |  STACK_OF(SSL_CIPHER) *SSL_get1_supported_ciphers(SSL *s); | 
					
						
							| 
									
										
										
										
											2015-05-26 09:16:53 +08:00
										 |  |  |  STACK_OF(SSL_CIPHER) *SSL_get_client_ciphers(const SSL *ssl); | 
					
						
							| 
									
										
										
										
											2017-01-31 09:20:14 +08:00
										 |  |  |  int SSL_bytes_to_cipher_list(SSL *s, const unsigned char *bytes, size_t len, | 
					
						
							|  |  |  |                               int isv2format, STACK_OF(SSL_CIPHER) **sk, | 
					
						
							|  |  |  |                               STACK_OF(SSL_CIPHER) **scsvs); | 
					
						
							| 
									
										
										
										
											2005-03-30 19:50:14 +08:00
										 |  |  |  const char *SSL_get_cipher_list(const SSL *ssl, int priority); | 
					
						
							| 
									
										
										
										
											2018-04-27 18:38:19 +08:00
										 |  |  |  char *SSL_get_shared_ciphers(const SSL *s, char *buf, int size); | 
					
						
							| 
									
										
										
										
											2000-09-19 00:42:30 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | =head1 DESCRIPTION | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | SSL_get_ciphers() returns the stack of available SSL_CIPHERs for B<ssl>, | 
					
						
							|  |  |  | sorted by preference. If B<ssl> is NULL or no ciphers are available, NULL | 
					
						
							|  |  |  | is returned. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-10 12:18:50 +08:00
										 |  |  | SSL_CTX_get_ciphers() returns the stack of available SSL_CIPHERs for B<ctx>. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-02-08 03:33:43 +08:00
										 |  |  | SSL_get1_supported_ciphers() returns the stack of enabled SSL_CIPHERs for | 
					
						
							| 
									
										
										
										
											2017-08-30 00:31:20 +08:00
										 |  |  | B<ssl> as would be sent in a ClientHello (that is, sorted by preference). | 
					
						
							| 
									
										
										
										
											2016-02-08 03:33:43 +08:00
										 |  |  | The list depends on settings like the cipher list, the supported protocol | 
					
						
							|  |  |  | versions, the security level, and the enabled signature algorithms. | 
					
						
							|  |  |  | SRP and PSK ciphers are only enabled if the appropriate callbacks or settings | 
					
						
							|  |  |  | have been applied. | 
					
						
							| 
									
										
										
										
											2017-08-30 00:31:20 +08:00
										 |  |  | The list of ciphers that would be sent in a ClientHello can differ from | 
					
						
							|  |  |  | the list of ciphers that would be acceptable when acting as a server. | 
					
						
							|  |  |  | For example, additional ciphers may be usable by a server if there is | 
					
						
							|  |  |  | a gap in the list of supported protocols, and some ciphers may not be | 
					
						
							|  |  |  | usable by a server if there is not a suitable certificate configured. | 
					
						
							| 
									
										
										
										
											2016-02-08 03:33:43 +08:00
										 |  |  | If B<ssl> is NULL or no ciphers are available, NULL is returned. | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | SSL_get_client_ciphers() returns the stack of available SSL_CIPHERs matching the | 
					
						
							|  |  |  | list received from the client on B<ssl>. If B<ssl> is NULL, no ciphers are | 
					
						
							| 
									
										
										
										
											2015-05-26 09:16:53 +08:00
										 |  |  | available, or B<ssl> is not operating in server mode, NULL is returned. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-01-31 01:24:17 +08:00
										 |  |  | SSL_bytes_to_cipher_list() treats the supplied B<len> octets in B<bytes> | 
					
						
							|  |  |  | as a wire-protocol cipher suite specification (in the three-octet-per-cipher | 
					
						
							|  |  |  | SSLv2 wire format if B<isv2format> is nonzero; otherwise the two-octet | 
					
						
							|  |  |  | SSLv3/TLS wire format), and parses the cipher suites supported by the library | 
					
						
							| 
									
										
										
										
											2017-01-31 09:20:14 +08:00
										 |  |  | into the returned stacks of SSL_CIPHER objects sk and Signalling Cipher-Suite | 
					
						
							|  |  |  | Values scsvs.  Unsupported cipher suites are ignored.  Returns 1 on success | 
					
						
							|  |  |  | and 0 on failure. | 
					
						
							| 
									
										
										
										
											2017-01-31 01:24:17 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2000-09-19 00:42:30 +08:00
										 |  |  | SSL_get_cipher_list() returns a pointer to the name of the SSL_CIPHER | 
					
						
							|  |  |  | listed for B<ssl> with B<priority>. If B<ssl> is NULL, no ciphers are | 
					
						
							|  |  |  | available, or there are less ciphers than B<priority> available, NULL | 
					
						
							|  |  |  | is returned. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-04-27 18:38:19 +08:00
										 |  |  | SSL_get_shared_ciphers() creates a colon separated and NUL terminated list of | 
					
						
							|  |  |  | SSL_CIPHER names that are available in both the client and the server. B<buf> is | 
					
						
							|  |  |  | the buffer that should be populated with the list of names and B<size> is the | 
					
						
							|  |  |  | size of that buffer. A pointer to B<buf> is returned on success or NULL on | 
					
						
							|  |  |  | error. If the supplied buffer is not large enough to contain the complete list | 
					
						
							|  |  |  | of names then a truncated list of names will be returned. Note that just because | 
					
						
							|  |  |  | a ciphersuite is available (i.e. it is configured in the cipher list) and shared | 
					
						
							|  |  |  | by both the client and the server it does not mean that it is enabled (see the | 
					
						
							|  |  |  | description of SSL_get1_supported_ciphers() above). This function will return | 
					
						
							|  |  |  | available shared ciphersuites whether or not they are enabled. This is a server | 
					
						
							|  |  |  | side function only and must only be called after the completion of the initial | 
					
						
							|  |  |  | handshake. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2000-09-19 00:42:30 +08:00
										 |  |  | =head1 NOTES | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-10 12:18:50 +08:00
										 |  |  | The details of the ciphers obtained by SSL_get_ciphers(), SSL_CTX_get_ciphers() | 
					
						
							| 
									
										
										
										
											2016-02-08 03:33:43 +08:00
										 |  |  | SSL_get1_supported_ciphers() and SSL_get_client_ciphers() can be obtained using | 
					
						
							| 
									
										
										
										
											2015-08-18 03:21:33 +08:00
										 |  |  | the L<SSL_CIPHER_get_name(3)> family of functions. | 
					
						
							| 
									
										
										
										
											2000-09-19 00:42:30 +08:00
										 |  |  | 
 | 
					
						
							|  |  |  | Call SSL_get_cipher_list() with B<priority> starting from 0 to obtain the | 
					
						
							|  |  |  | sorted list of available ciphers, until NULL is returned. | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-04-10 12:18:50 +08:00
										 |  |  | Note: SSL_get_ciphers(), SSL_CTX_get_ciphers() and SSL_get_client_ciphers() | 
					
						
							|  |  |  | return a pointer to an internal cipher stack, which will be freed later on when | 
					
						
							|  |  |  | the SSL or SSL_SESSION object is freed.  Therefore, the calling code B<MUST NOT> | 
					
						
							|  |  |  | free the return value itself. | 
					
						
							| 
									
										
										
										
											2015-05-26 21:46:57 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-02-08 03:33:43 +08:00
										 |  |  | The stack returned by SSL_get1_supported_ciphers() should be freed using | 
					
						
							|  |  |  | sk_SSL_CIPHER_free(). | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2017-01-31 09:20:14 +08:00
										 |  |  | The stacks returned by SSL_bytes_to_cipher_list() should be freed using | 
					
						
							| 
									
										
										
										
											2017-01-31 01:24:17 +08:00
										 |  |  | sk_SSL_CIPHER_free(). | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2000-09-19 00:42:30 +08:00
										 |  |  | =head1 RETURN VALUES | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | See DESCRIPTION | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | =head1 SEE ALSO | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-11-11 16:33:09 +08:00
										 |  |  | L<ssl(7)>, L<SSL_CTX_set_cipher_list(3)>, | 
					
						
							| 
									
										
										
										
											2015-08-18 03:21:33 +08:00
										 |  |  | L<SSL_CIPHER_get_name(3)> | 
					
						
							| 
									
										
										
										
											2000-09-19 00:42:30 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2016-05-18 23:44:05 +08:00
										 |  |  | =head1 COPYRIGHT | 
					
						
							|  |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-05-29 20:07:08 +08:00
										 |  |  | Copyright 2000-2018 The OpenSSL Project Authors. All Rights Reserved. | 
					
						
							| 
									
										
										
										
											2016-05-18 23:44:05 +08:00
										 |  |  | 
 | 
					
						
							| 
									
										
										
										
											2018-12-06 21:04:44 +08:00
										 |  |  | Licensed under the Apache License 2.0 (the "License").  You may not use | 
					
						
							| 
									
										
										
										
											2016-05-18 23:44:05 +08:00
										 |  |  | this file except in compliance with the License.  You can obtain a copy | 
					
						
							|  |  |  | in the file LICENSE in the source distribution or at | 
					
						
							|  |  |  | L<https://www.openssl.org/source/license.html>. | 
					
						
							|  |  |  | 
 | 
					
						
							|  |  |  | =cut |