Solaris环境HTTP服务!3DES加密套件配置是否不可逆的技术咨询
!3DES Irreversible? Great question—let’s break this down clearly based on Oracle’s SSL cipher suite syntax and how it works for your Solaris HTTP service setup.
First, let’s ground this in the Oracle documentation note you referenced:
: 临时移除加密套件(后续可添加);! 永久移除加密套件
The key thing to understand here is that "permanent" doesn’t mean system-level irreversible—it’s strictly about how the cipher suite selection logic processes your configuration string. Here’s what that means for your scenario:
When you add
!3DESto yourSSLCipherSuiteline (HIGH:!aNULL:!eNULL:!PSK:!RC4:!MD5:!3DES), you’re telling the SSL engine to forcefully exclude 3DES from the final cipher list—even if the precedingHIGHcategory includes it. The "permanent" label here only means that no subsequent entries in the same configuration string can re-include 3DES (unlike the:syntax, which lets you re-add excluded suites later in the string).This is fully reversible via configuration changes. If you remove
!3DESfrom yourSSLCipherSuiteline (so it becomesHIGH:!aNULL:!eNULL:!PSK:!RC4:!MD5), then reload or restart your HTTP service, 3DES will be re-included in the available cipher suites—as long as theHIGHcipher category in your Solaris SSL implementation includes 3DES by default.
To confirm this works as expected, you can use the openssl ciphers command on your Solaris system to preview the cipher list for both configurations:
# Check current configuration (with !3DES) openssl ciphers -V 'HIGH:!aNULL:!eNULL:!PSK:!RC4:!MD5:!3DES' # Check modified configuration (without !3DES) openssl ciphers -V 'HIGH:!aNULL:!eNULL:!PSK:!RC4:!MD5'
You’ll see that 3DES-based ciphers reappear in the second output.
Just remember: After editing the HTTP/SSL configuration file, you must restart or reload your HTTP service for the changes to take effect. There’s no hidden system-level lock caused by !3DES—it’s purely a runtime configuration rule that you can adjust anytime by modifying the config file.
内容的提问来源于stack exchange,提问作者Sukirti Sen

