[gnutls-help] How to enable AES-256-CBC?

John Jiang john.sha.jiang at gmail.com
Wed Jan 8 05:40:48 CET 2020

I'm using GnuTLS 3.6.10.
It looks this version disables AES-256-CBC.
With my testing on gnutls-serv, if a client supports cipher suite
TLS_RSA_WITH_AES_256_CBC_SHA256 only, the connecting just fails.
But if the client uses TLS_RSA_WITH_AES_128_GCM_SHA256, the connection can
be established.
Could this cipher suite be enabled by priority string?
I have tried "NORMAL:+RSA:+AES-256-CBC", but it didn't work.

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <https://lists.gnupg.org/pipermail/gnutls-help/attachments/20200108/697b54d1/attachment-0001.html>

More information about the Gnutls-help mailing list