Hello,

> > AES256-SHA means also RSA key_exchange. Are you setting
> > private RSA keys, certificate, and CA certificate also in SSL context ?
> 
> does this imply that when I want to use EDH for key exchange that the cipher
> will not be able to be AES*?
No, AES encryption may be used with the following SSL ciphers:
        $ openssl ciphers -v | grep AES
        DHE-RSA-AES256-SHA  SSLv3 Kx=DH   Au=RSA  Enc=AES(256)  Mac=SHA1
        DHE-DSS-AES256-SHA  SSLv3 Kx=DH   Au=DSS  Enc=AES(256)  Mac=SHA1
        AES256-SHA          SSLv3 Kx=RSA  Au=RSA  Enc=AES(256)  Mac=SHA1
        DHE-RSA-AES128-SHA  SSLv3 Kx=DH   Au=RSA  Enc=AES(128)  Mac=SHA1
        DHE-DSS-AES128-SHA  SSLv3 Kx=DH   Au=DSS  Enc=AES(128)  Mac=SHA1
        AES128-SHA          SSLv3 Kx=RSA  Au=RSA  Enc=AES(128)  Mac=SHA1


Best regards,
-- 
Marek Marcola <[EMAIL PROTECTED]>

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    openssl-users@openssl.org
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to