配置加密套件
更新時間 2025-09-15 18:01:50
最近更新時間: 2025-09-15 18:01:50
分享文章
本文介紹CDN支持的SSL/TLS加密套件及對應套件支持的最低版本的SSL/TLS協議和配置方法。
功能介紹
加密套件是用于在SSL/TLS握手期間協商安全設置的算法的組合。在Client Hello和Server Hello消息交換之后,客戶端發送密碼支持套件列表,服務器從列表中選擇密碼套件進行響應。
天翼云CDN加速在域名配置完HTTPS證書后,可選擇加密套件類型:全部加密套件、強加密套件、自定義加密套件。
選擇全部加密套件后,默認支持的加密套件及對應套件支持的最低版本的SSL/TLS協議如下:
| 加密算法 | 最低版本的SSL/TLS協議 |
|---|---|
| TLS_AES_256_GCM_SHA384 | TLSv1.3 |
| TLS_CHACHA20_POLY1305_SHA256 | TLSv1.3 |
| TLS_AES_128_GCM_SHA256 | TLSv1.3 |
| ECDHE-ECDSA-AES256-GCM-SHA384 | TLSv1.2 |
| ECDHE-RSA-AES256-GCM-SHA384 | TLSv1.2 |
| DHE-DSS-AES256-GCM-SHA384 | TLSv1.2 |
| DHE-RSA-AES256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ECDSA-CHACHA20-POLY1305 | TLSv1.2 |
| ECDHE-RSA-CHACHA20-POLY1305 | TLSv1.2 |
| DHE-RSA-CHACHA20-POLY1305 | TLSv1.2 |
| ECDHE-ECDSA-AES256-CCM8 | TLSv1.2 |
| ECDHE-ECDSA-AES256-CCM | TLSv1.2 |
| DHE-RSA-AES256-CCM8 | TLSv1.2 |
| DHE-RSA-AES256-CCM | TLSv1.2 |
| ECDHE-ECDSA-ARIA256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ARIA256-GCM-SHA384 | TLSv1.2 |
| DHE-DSS-ARIA256-GCM-SHA384 | TLSv1.2 |
| DHE-RSA-ARIA256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ECDSA-AES128-GCM-SHA256 | TLSv1.2 |
| ECDHE-RSA-AES128-GCM-SHA256 | TLSv1.2 |
| DHE-DSS-AES128-GCM-SHA256 | TLSv1.2 |
| DHE-RSA-AES128-GCM-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-AES128-CCM8 | TLSv1.2 |
| ECDHE-ECDSA-AES128-CCM | TLSv1.2 |
| DHE-RSA-AES128-CCM8 | TLSv1.2 |
| DHE-RSA-AES128-CCM | TLSv1.2 |
| ECDHE-ECDSA-ARIA128-GCM-SHA256 | TLSv1.2 |
| ECDHE-ARIA128-GCM-SHA256 | TLSv1.2 |
| DHE-DSS-ARIA128-GCM-SHA256 | TLSv1.2 |
| DHE-RSA-ARIA128-GCM-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-AES256-SHA384 | TLSv1.2 |
| ECDHE-RSA-AES256-SHA384 | TLSv1.2 |
| DHE-RSA-AES256-SHA256 | TLSv1.2 |
| DHE-DSS-AES256-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-CAMELLIA256-SHA384 | TLSv1.2 |
| ECDHE-RSA-CAMELLIA256-SHA384 | TLSv1.2 |
| DHE-RSA-CAMELLIA256-SHA256 | TLSv1.2 |
| DHE-DSS-CAMELLIA256-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-AES128-SHA256 | TLSv1.2 |
| ECDHE-RSA-AES128-SHA256 | TLSv1.2 |
| DHE-RSA-AES128-SHA256 | TLSv1.2 |
| DHE-DSS-AES128-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-CAMELLIA128-SHA256 | TLSv1.2 |
| ECDHE-RSA-CAMELLIA128-SHA256 | TLSv1.2 |
| DHE-RSA-CAMELLIA128-SHA256 | TLSv1.2 |
| DHE-DSS-CAMELLIA128-SHA256 | TLSv1.2 |
| RSA-PSK-AES256-GCM-SHA384 | TLSv1.2 |
| DHE-PSK-AES256-GCM-SHA384 | TLSv1.2 |
| RSA-PSK-CHACHA20-POLY1305 | TLSv1.2 |
| DHE-PSK-CHACHA20-POLY1305 | TLSv1.2 |
| ECDHE-PSK-CHACHA20-POLY1305 | TLSv1.2 |
| DHE-PSK-AES256-CCM8 | TLSv1.2 |
| DHE-PSK-AES256-CCM | TLSv1.2 |
| RSA-PSK-ARIA256-GCM-SHA384 | TLSv1.2 |
| DHE-PSK-ARIA256-GCM-SHA384 | TLSv1.2 |
| AES256-GCM-SHA384 | TLSv1.2 |
| AES256-CCM8 | TLSv1.2 |
| AES256-CCM | TLSv1.2 |
| ARIA256-GCM-SHA384 | TLSv1.2 |
| PSK-AES256-GCM-SHA384 | TLSv1.2 |
| PSK-CHACHA20-POLY1305 | TLSv1.2 |
| PSK-AES256-CCM8 | TLSv1.2 |
| PSK-AES256-CCM | TLSv1.2 |
| PSK-ARIA256-GCM-SHA384 | TLSv1.2 |
| RSA-PSK-AES128-GCM-SHA256 | TLSv1.2 |
| DHE-PSK-AES128-GCM-SHA256 | TLSv1.2 |
| DHE-PSK-AES128-CCM8 | TLSv1.2 |
| DHE-PSK-AES128-CCM | TLSv1.2 |
| RSA-PSK-ARIA128-GCM-SHA256 | TLSv1.2 |
| DHE-PSK-ARIA128-GCM-SHA256 | TLSv1.2 |
| AES128-GCM-SHA256 | TLSv1.2 |
| AES128-CCM8 | TLSv1.2 |
| AES128-CCM | TLSv1.2 |
| ARIA128-GCM-SHA256 | TLSv1.2 |
| PSK-AES128-GCM-SHA256 | TLSv1.2 |
| PSK-AES128-CCM8 | TLSv1.2 |
| PSK-AES128-CCM | TLSv1.2 |
| PSK-ARIA128-GCM-SHA256 | TLSv1.2 |
| AES256-SHA256 | TLSv1.2 |
| CAMELLIA256-SHA256 | TLSv1.2 |
| AES128-SHA256 | TLSv1.2 |
| CAMELLIA128-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-AES256-SHA | TLSv1 |
| ECDHE-RSA-AES256-SHA | TLSv1 |
| ECDHE-ECDSA-AES128-SHA | TLSv1 |
| ECDHE-RSA-AES128-SHA | TLSv1 |
| ECDHE-PSK-AES256-CBC-SHA384 | TLSv1 |
| ECDHE-PSK-AES256-CBC-SHA | TLSv1 |
| RSA-PSK-AES256-CBC-SHA384 | TLSv1 |
| DHE-PSK-AES256-CBC-SHA384 | TLSv1 |
| ECDHE-PSK-CAMELLIA256-SHA384 | TLSv1 |
| RSA-PSK-CAMELLIA256-SHA384 | TLSv1 |
| DHE-PSK-CAMELLIA256-SHA384 | TLSv1 |
| PSK-AES256-CBC-SHA384 | TLSv1 |
| PSK-CAMELLIA256-SHA384 | TLSv1 |
| ECDHE-PSK-AES128-CBC-SHA256 | TLSv1 |
| ECDHE-PSK-AES128-CBC-SHA | TLSv1 |
| RSA-PSK-AES128-CBC-SHA256 | TLSv1 |
| DHE-PSK-AES128-CBC-SHA256 | TLSv1 |
| ECDHE-PSK-CAMELLIA128-SHA256 | TLSv1 |
| RSA-PSK-CAMELLIA128-SHA256 | TLSv1 |
| DHE-PSK-CAMELLIA128-SHA256 | TLSv1 |
| PSK-AES128-CBC-SHA256 | TLSv1 |
| PSK-CAMELLIA128-SHA256 | TLSv1 |
| DHE-RSA-AES256-SHA | SSLv3 |
| DHE-DSS-AES256-SHA | SSLv3 |
| DHE-RSA-CAMELLIA256-SHA | SSLv3 |
| DHE-DSS-CAMELLIA256-SHA | SSLv3 |
| DHE-RSA-AES128-SHA | SSLv3 |
| DHE-DSS-AES128-SHA | SSLv3 |
| DHE-RSA-CAMELLIA128-SHA | SSLv3 |
| DHE-DSS-CAMELLIA128-SHA | SSLv3 |
| SRP-DSS-AES-256-CBC-SHA | SSLv3 |
| SRP-RSA-AES-256-CBC-SHA | SSLv3 |
| SRP-AES-256-CBC-SHA | SSLv3 |
| RSA-PSK-AES256-CBC-SHA | SSLv3 |
| DHE-PSK-AES256-CBC-SHA | SSLv3 |
| AES256-SHA | SSLv3 |
| CAMELLIA256-SHA | SSLv3 |
| PSK-AES256-CBC-SHA | SSLv3 |
| SRP-DSS-AES-128-CBC-SHA | SSLv3 |
| SRP-RSA-AES-128-CBC-SHA | SSLv3 |
| SRP-AES-128-CBC-SHA | SSLv3 |
| RSA-PSK-AES128-CBC-SHA | SSLv3 |
| DHE-PSK-AES128-CBC-SHA | SSLv3 |
| AES128-SHA | SSLv3 |
| CAMELLIA128-SHA | SSLv3 |
| PSK-AES128-CBC-SHA | SSLv3 |
| DHE-RSA-AES256-GCM-SHA384 | TLSv1.2 |
| DHE-RSA-CHACHA20-POLY1305 | TLSv1.2 |
| DHE-RSA-AES256-CCM8 | TLSv1.2 |
| DHE-RSA-AES256-CCM | TLSv1.2 |
| DHE-RSA-ARIA256-GCM-SHA384 | TLSv1.2 |
| DHE-RSA-AES128-GCM-SHA256 | TLSv1.2 |
| DHE-RSA-AES128-CCM8 | TLSv1.2 |
| DHE-RSA-AES128-CCM | TLSv1.2 |
| DHE-RSA-ARIA128-GCM-SHA256 | TLSv1.2 |
| DHE-RSA-AES256-SHA256 | TLSv1.2 |
| DHE-RSA-CAMELLIA256-SHA256 | TLSv1.2 |
| DHE-RSA-AES128-SHA256 | TLSv1.2 |
| DHE-RSA-CAMELLIA128-SHA256 | TLSv1.2 |
| DHE-RSA-AES256-SHA | SSLv3 |
| DHE-RSA-CAMELLIA256-SHA | SSLv3 |
| DHE-RSA-AES128-SHA | SSLv3 |
| DHE-RSA-AES128-SHA | SSLv3 |
| ECC-SM2-SM4-GCM-SM3 | GMTLS1.1 |
| ECDHE-SM2-SM4-GCM-SM3 | GMTLS1.1 |
| ECC-SM2-SM4-CBC-SM3 | GMTLS1.1 |
| ECDHE-SM2-SM4-CBC-SM3 | GMTLS1.1 |
選擇強加密套件后,默認支持的加密套件及對應套件支持的最低版本的SSL/TLS協議如下:
| 加密算法 | 最低版本的SSL/TLS協議 |
|---|---|
| TLS_AES_256_GCM_SHA384 | TLSv1.3 |
| TLS_CHACHA20_POLY1305_SHA256 | TLSv1.3 |
| TLS_AES_128_GCM_SHA256 | TLSv1.3 |
| ECDHE-ECDSA-CHACHA20-POLY1305 | TLSv1.2 |
| ECDHE-RSA-CHACHA20-POLY1305 | TLSv1.2 |
| ECDHE-ECDSA-AES256-GCM-SHA384 | TLSv1.2 |
| ECDHE-RSA-AES256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ECDSA-AES256-CCM8 | TLSv1.2 |
| ECDHE-ECDSA-AES256-CCM | TLSv1.2 |
| ECDHE-ECDSA-ARIA256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ARIA256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ECDSA-AES128-GCM-SHA256 | TLSv1.2 |
| ECDHE-RSA-AES128-GCM-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-AES128-CCM8 | TLSv1.2 |
| ECDHE-ECDSA-AES128-CCM | TLSv1.2 |
| ECDHE-ECDSA-ARIA128-GCM-SHA256 | TLSv1.2 |
| ECDHE-ARIA128-GCM-SHA256 | TLSv1.2 |
選擇自定義加密套件后,可從如下列表中自定義選擇1個或多個加密套件:
| 加密算法 | 最低版本的SSL/TLS協議 |
|---|---|
| TLS_AES_256_GCM_SHA384 | TLSv1.3 |
| TLS_CHACHA20_POLY1305_SHA256 | TLSv1.3 |
| TLS_AES_128_GCM_SHA256 | TLSv1.3 |
| ECDHE-ECDSA-AES256-GCM-SHA384 | TLSv1.2 |
| ECDHE-RSA-AES256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ECDSA-CHACHA20-POLY1305 | TLSv1.2 |
| ECDHE-RSA-CHACHA20-POLY1305 | TLSv1.2 |
| ECDHE-ECDSA-AES256-CCM8 | TLSv1.2 |
| ECDHE-ECDSA-AES256-CCM | TLSv1.2 |
| ECDHE-ECDSA-ARIA256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ARIA256-GCM-SHA384 | TLSv1.2 |
| ECDHE-ECDSA-AES128-GCM-SHA256 | TLSv1.2 |
| ECDHE-RSA-AES128-GCM-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-AES128-CCM8 | TLSv1.2 |
| ECDHE-ECDSA-AES128-CCM | TLSv1.2 |
| ECDHE-ECDSA-ARIA128-GCM-SHA256 | TLSv1.2 |
| ECDHE-ARIA128-GCM-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-AES256-SHA384 | TLSv1.2 |
| ECDHE-RSA-AES256-SHA384 | TLSv1.2 |
| ECDHE-ECDSA-CAMELLIA256-SHA384 | TLSv1.2 |
| ECDHE-RSA-CAMELLIA256-SHA384 | TLSv1.2 |
| ECDHE-ECDSA-AES128-SHA256 | TLSv1.2 |
| ECDHE-RSA-AES128-SHA256 | TLSv1.2 |
| ECDHE-ECDSA-CAMELLIA128-SHA256 | TLSv1.2 |
| ECDHE-RSA-CAMELLIA128-SHA256 | TLSv1.2 |
| AES256-GCM-SHA384 | TLSv1.2 |
| AES256-CCM8 | TLSv1.2 |
| AES256-CCM | TLSv1.2 |
| ARIA256-GCM-SHA384 | TLSv1.2 |
| AES128-GCM-SHA256 | TLSv1.2 |
| AES128-CCM8 | TLSv1.2 |
| AES128-CCM | TLSv1.2 |
| ARIA128-GCM-SHA256 | TLSv1.2 |
| AES256-SHA256 | TLSv1.2 |
| CAMELLIA256-SHA256 | TLSv1.2 |
| AES128-SHA256 | TLSv1.2 |
| CAMELLIA128-SHA256 | TLSv1.2 |
| DHE-RSA-AES256-GCM-SHA384 | TLSv1.2 |
| DHE-RSA-CHACHA20-POLY1305 | TLSv1.2 |
| DHE-RSA-AES256-CCM8 | TLSv1.2 |
| DHE-RSA-AES256-CCM | TLSv1.2 |
| DHE-RSA-ARIA256-GCM-SHA384 | TLSv1.2 |
| DHE-RSA-AES128-GCM-SHA256 | TLSv1.2 |
| DHE-RSA-AES128-CCM8 | TLSv1.2 |
| DHE-RSA-AES128-CCM | TLSv1.2 |
| DHE-RSA-ARIA128-GCM-SHA256 | TLSv1.2 |
| DHE-RSA-AES256-SHA256 | TLSv1.2 |
| DHE-RSA-CAMELLIA256-SHA256 | TLSv1.2 |
| DHE-RSA-AES128-SHA256 | TLSv1.2 |
| DHE-RSA-CAMELLIA128-SHA256 | TLSv1.2 |
| DHE-RSA-AES256-SHA | SSLv3 |
| DHE-RSA-CAMELLIA256-SHA | SSLv3 |
| DHE-RSA-AES128-SHA | SSLv3 |
| DHE-RSA-CAMELLIA128-SHA | SSLv3 |
| ECC-SM2-SM4-GCM-SM3 | GMTLS1.1 |
| ECDHE-SM2-SM4-GCM-SM3 | GMTLS1.1 |
| ECC-SM2-SM4-CBC-SM3 | GMTLS1.1 |
| ECDHE-SM2-SM4-CBC-SM3 | GMTLS1.1 |
注意事項
配置加密套件前,請確保已成功配置HTTPS證書,操作方法詳情請見:新增證書。
TLS版本默認開啟 TLS v1.0、TLS v1.1、TLS v1.2、TLS v1.3、GMTLSv1.1。
配置說明
登錄。
單擊左側導航欄【域名管理】-【域名列表】。
在【域名列表】頁面,找到目標域名,單擊【操作】列的【編輯】。
單擊右側【請求協議】。
在【請求協議】模塊,勾選【HTTPS】。
單擊右側【HTTPS配置】。
選擇域名對應的證書。如果已經在證書管理上傳證書,可直接選擇對應域名證書。如果還未上傳證書,可單擊【點擊上傳】,添加自有證書。添加完畢后,再選擇對應證書。
在【加密套件】模塊,根據需求選擇加密套件。
說明
選擇加密套件前,請確保已配置證書,未配置證書將無法選擇加密套件。
僅配置國際標準證書時,加密套件支持選擇全部加密套件、強加密套件、自定義加密套件。
僅配置國密證書時,加密套件僅支持選擇全部加密套件、自定義加密套件。
同時配置國際標準證書和國密證書時,加密套件僅支持選擇全部加密套件、自定義加密套件。