| Electronic Components Datasheet Search |
|
AN4683 Datasheet(PDF) 12 Page - STMicroelectronics |
|
|
|||||||||||||||||||||||||||||
AN4683 Datasheet(HTML) 12 Page - STMicroelectronics |
|
12 / 31 page ![]() SPWF01Sxxx use modes AN4683 12/31 DocID027745 Rev 1 2.3 Domain name check for server certificate When making a TLS connection, the client requests a digital certificate from the server. Once the server sends the certificate, the client examines it and compares the domain it was trying to connect to with the name (common name or others) included in the certificate. If a match is found, the connection proceeds as normal. If a match is not found, the user may be warned of the discrepancy and the connection may be aborted as the mismatch may indicate an attempted man-in-the-middle attack. The demonstrator allows the user to bypass the warning to proceed with the connection, with the user taking on the responsibility of trusting the certificate and the connection. 2.4 Authentication As mentioned in Section 1, SSL/TLS requires a server certificate and, optionally, a client certificate to be exchanged during handshake. Depending on the required level of trust, we can have three authentication modes: anonymous, one-way and mutual authentication. The following three sub-sections describe how to configure the SPWF01Sxxx module to enable the three different modes. 2.4.1 Anonymous negotiation In case of anonymous TLS connection, the user assumes to be in a trusted environment, thus party authentication is not required. Even if server sends a certificate, the client will skip the verification of authenticity. TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA 0xC0,0x14 TLS1.0/1.1/1.2 TLS_ECDH_RSA_WITH_AES_256_CBC_SHA 0xC0,0x0F TLS1.0/1.1/1.2 TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA 0xC0,0x13 TLS1.0/1.1/1.2 TLS_ECDH_RSA_WITH_AES_128_CBC_SHA 0xC0,0x0E TLS1.0/1.1/1.2 TLS_ECDHE_RSA_WITH_RC4_128_SHA 0xC0,0x11 TLS1.0/1.1/1.2 TLS_ECDH_RSA_WITH_RC4_128_SHA 0xC0,0x0C TLS1.0/1.1/1.2 TLS_ECDHE_RSA_WITH_3DES_EDE_CBC_SHA 0xC0,0x12 TLS1.0/1.1/1.2 TLS_ECDH_RSA_WITH_3DES_EDE_CBC_SHA 0xC0,0x0D TLS1.0/1.1/1.2 TLS_RSA_WITH_AES_256_CBC_SHA256 0x00,0x3D TLS1.2 TLS_RSA_WITH_AES_128_CBC_SHA256 0x00,0x3C TLS1.2 TLS_RSA_WITH_AES_256_CBC_SHA 0x00,0x35 TLS1.0/1.1/1.2 TLS_RSA_WITH_AES_128_CBC_SHA 0x00,0x2F TLS1.0/1.1/1.2 SSL_RSA_WITH_RC4_128_SHA 0x00,0x05 SSL3.0/TLS1.0/1.1/1.2 SSL_RSA_WITH_RC4_128_MD5 0x00,0x04 SSL3.0/TLS1.0/1.1/1.2 SSL_RSA_WITH_3DES_EDE_CBC_SHA 0x00,0x0A SSL3.0/TLS1.0/1.1/1.2 Table 2. Demonstrator cipher suites (continued) Cipher suites 2 byte codes (hex format) Version |
|
Link URL |
| Does ALLDATASHEET help your business so far? [ DONATE ] |
About Alldatasheet | Advertisement | Contact us | Privacy Policy | Link to Datasheet | Link Exchange | Manufacturer List All Rights Reserved©Alldatasheet.com |
| Russian : Alldatasheetru.com | Korean : Alldatasheet.co.kr | Spanish : Alldatasheet.es | French : Alldatasheet.fr | Italian : Alldatasheetit.com Portuguese : Alldatasheetpt.com | Polish : Alldatasheet.pl | Vietnamese : Alldatasheet.vn Indian : Alldatasheet.in | Mexican : Alldatasheet.com.mx | British : Alldatasheet.co.uk | New Zealand : Alldatasheet.co.nz |
|
Family Site : ic2ic.com |
icmetro.com |