Codebase list openssl / debian/openssl-1.1.0g-1
release 1.1.0g-1 Signed-off-by: Sebastian Andrzej Siewior <sebastian@breakpoint.cc> Sebastian Andrzej Siewior 6 years ago
3 changed file(s) with 13 addition(s) and 2669 deletion(s). Raw diff Collapse all Expand all
0 openssl (1.1.0g-1) unstable; urgency=medium
1
2 [ Kurt Roeckx ]
3 * New upstream version
4 - Fixes CVE-2017-3735
5 - Fixes CVE-2017-3736
6 * Remove patches applied upstream
7 * Temporary enable TLS 1.0 and 1.1 again (#875423)
8 * Attempt to fix testsuite race condition
9 * update no-symbolic.patch to apply
10
11 -- Kurt Roeckx <kurt@roeckx.be> Thu, 02 Nov 2017 15:22:48 +0100
12
013 openssl (1.1.0f-5) unstable; urgency=medium
114
215 * Instead of completly disabling TLS 1.0 and 1.1, just set the minimum
22 no-symbolic.patch
33 pic.patch
44 c_rehash-compat.patch
5 tls1_2_default.patch
+0
-2668
debian/patches/tls1_2_default.patch less more
0 From: Kurt Roeckx <kurt@roeckx.be>
1 Date: Thu, 10 Aug 2017 02:54:17 +0200
2 Subject: [PATCH] Only enable TLS 1.2 by default
3
4 ---
5 ssl/ssl_lib.c | 5 +-
6 test/ssl-tests/02-protocol-version.conf | 190 +++++++++++++++++++++++++++
7 test/ssl-tests/07-dtls-protocol-version.conf | 48 +++++++
8 test/ssl-tests/10-resumption.conf | 72 ++++++++++
9 test/ssl-tests/11-dtls_resumption.conf | 32 +++++
10 test/ssl-tests/protocol_version.pm | 8 +-
11 6 files changed, 353 insertions(+), 2 deletions(-)
12
13 diff --git a/ssl/ssl_lib.c b/ssl/ssl_lib.c
14 index 6908f1677b75..11d30838cd44 100644
15 --- a/ssl/ssl_lib.c
16 +++ b/ssl/ssl_lib.c
17 @@ -2483,7 +2483,10 @@ SSL_CTX *SSL_CTX_new(const SSL_METHOD *meth)
18 goto err;
19
20 ret->method = meth;
21 - ret->min_proto_version = 0;
22 + if (meth->version == TLS_ANY_VERSION)
23 + ret->min_proto_version = TLS1_2_VERSION;
24 + else
25 + ret->min_proto_version = 0;
26 ret->max_proto_version = 0;
27 ret->session_cache_mode = SSL_SESS_CACHE_SERVER;
28 ret->session_cache_size = SSL_SESSION_CACHE_MAX_SIZE_DEFAULT;
29 diff --git a/test/ssl-tests/02-protocol-version.conf b/test/ssl-tests/02-protocol-version.conf
30 index cb89dbc10aa6..67e681e4261a 100644
31 --- a/test/ssl-tests/02-protocol-version.conf
32 +++ b/test/ssl-tests/02-protocol-version.conf
33 @@ -376,11 +376,13 @@ client = 0-version-negotiation-client
34 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
35 CipherString = DEFAULT
36 MaxProtocol = SSLv3
37 +MinProtocol = None
38 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
39
40 [0-version-negotiation-client]
41 CipherString = DEFAULT
42 MaxProtocol = SSLv3
43 +MinProtocol = None
44 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
45 VerifyMode = Peer
46
47 @@ -401,11 +403,13 @@ client = 1-version-negotiation-client
48 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
49 CipherString = DEFAULT
50 MaxProtocol = TLSv1
51 +MinProtocol = None
52 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
53
54 [1-version-negotiation-client]
55 CipherString = DEFAULT
56 MaxProtocol = SSLv3
57 +MinProtocol = None
58 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
59 VerifyMode = Peer
60
61 @@ -426,11 +430,13 @@ client = 2-version-negotiation-client
62 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
63 CipherString = DEFAULT
64 MaxProtocol = TLSv1.1
65 +MinProtocol = None
66 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
67
68 [2-version-negotiation-client]
69 CipherString = DEFAULT
70 MaxProtocol = SSLv3
71 +MinProtocol = None
72 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
73 VerifyMode = Peer
74
75 @@ -451,11 +457,13 @@ client = 3-version-negotiation-client
76 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
77 CipherString = DEFAULT
78 MaxProtocol = TLSv1.2
79 +MinProtocol = None
80 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
81
82 [3-version-negotiation-client]
83 CipherString = DEFAULT
84 MaxProtocol = SSLv3
85 +MinProtocol = None
86 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
87 VerifyMode = Peer
88
89 @@ -475,11 +483,13 @@ client = 4-version-negotiation-client
90 [4-version-negotiation-server]
91 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
92 CipherString = DEFAULT
93 +MinProtocol = None
94 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
95
96 [4-version-negotiation-client]
97 CipherString = DEFAULT
98 MaxProtocol = SSLv3
99 +MinProtocol = None
100 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
101 VerifyMode = Peer
102
103 @@ -506,6 +516,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
104 [5-version-negotiation-client]
105 CipherString = DEFAULT
106 MaxProtocol = SSLv3
107 +MinProtocol = None
108 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
109 VerifyMode = Peer
110
111 @@ -532,6 +543,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
112 [6-version-negotiation-client]
113 CipherString = DEFAULT
114 MaxProtocol = SSLv3
115 +MinProtocol = None
116 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
117 VerifyMode = Peer
118
119 @@ -558,6 +570,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
120 [7-version-negotiation-client]
121 CipherString = DEFAULT
122 MaxProtocol = SSLv3
123 +MinProtocol = None
124 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
125 VerifyMode = Peer
126
127 @@ -584,6 +597,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
128 [8-version-negotiation-client]
129 CipherString = DEFAULT
130 MaxProtocol = SSLv3
131 +MinProtocol = None
132 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
133 VerifyMode = Peer
134
135 @@ -609,6 +623,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
136 [9-version-negotiation-client]
137 CipherString = DEFAULT
138 MaxProtocol = SSLv3
139 +MinProtocol = None
140 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
141 VerifyMode = Peer
142
143 @@ -635,6 +650,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
144 [10-version-negotiation-client]
145 CipherString = DEFAULT
146 MaxProtocol = SSLv3
147 +MinProtocol = None
148 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
149 VerifyMode = Peer
150
151 @@ -661,6 +677,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
152 [11-version-negotiation-client]
153 CipherString = DEFAULT
154 MaxProtocol = SSLv3
155 +MinProtocol = None
156 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
157 VerifyMode = Peer
158
159 @@ -687,6 +704,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
160 [12-version-negotiation-client]
161 CipherString = DEFAULT
162 MaxProtocol = SSLv3
163 +MinProtocol = None
164 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
165 VerifyMode = Peer
166
167 @@ -712,6 +730,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
168 [13-version-negotiation-client]
169 CipherString = DEFAULT
170 MaxProtocol = SSLv3
171 +MinProtocol = None
172 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
173 VerifyMode = Peer
174
175 @@ -738,6 +757,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
176 [14-version-negotiation-client]
177 CipherString = DEFAULT
178 MaxProtocol = SSLv3
179 +MinProtocol = None
180 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
181 VerifyMode = Peer
182
183 @@ -764,6 +784,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
184 [15-version-negotiation-client]
185 CipherString = DEFAULT
186 MaxProtocol = SSLv3
187 +MinProtocol = None
188 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
189 VerifyMode = Peer
190
191 @@ -789,6 +810,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
192 [16-version-negotiation-client]
193 CipherString = DEFAULT
194 MaxProtocol = SSLv3
195 +MinProtocol = None
196 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
197 VerifyMode = Peer
198
199 @@ -815,6 +837,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
200 [17-version-negotiation-client]
201 CipherString = DEFAULT
202 MaxProtocol = SSLv3
203 +MinProtocol = None
204 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
205 VerifyMode = Peer
206
207 @@ -840,6 +863,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
208 [18-version-negotiation-client]
209 CipherString = DEFAULT
210 MaxProtocol = SSLv3
211 +MinProtocol = None
212 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
213 VerifyMode = Peer
214
215 @@ -860,11 +884,13 @@ client = 19-version-negotiation-client
216 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
217 CipherString = DEFAULT
218 MaxProtocol = SSLv3
219 +MinProtocol = None
220 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
221
222 [19-version-negotiation-client]
223 CipherString = DEFAULT
224 MaxProtocol = TLSv1
225 +MinProtocol = None
226 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
227 VerifyMode = Peer
228
229 @@ -885,11 +911,13 @@ client = 20-version-negotiation-client
230 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
231 CipherString = DEFAULT
232 MaxProtocol = TLSv1
233 +MinProtocol = None
234 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
235
236 [20-version-negotiation-client]
237 CipherString = DEFAULT
238 MaxProtocol = TLSv1
239 +MinProtocol = None
240 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
241 VerifyMode = Peer
242
243 @@ -911,11 +939,13 @@ client = 21-version-negotiation-client
244 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
245 CipherString = DEFAULT
246 MaxProtocol = TLSv1.1
247 +MinProtocol = None
248 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
249
250 [21-version-negotiation-client]
251 CipherString = DEFAULT
252 MaxProtocol = TLSv1
253 +MinProtocol = None
254 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
255 VerifyMode = Peer
256
257 @@ -937,11 +967,13 @@ client = 22-version-negotiation-client
258 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
259 CipherString = DEFAULT
260 MaxProtocol = TLSv1.2
261 +MinProtocol = None
262 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
263
264 [22-version-negotiation-client]
265 CipherString = DEFAULT
266 MaxProtocol = TLSv1
267 +MinProtocol = None
268 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
269 VerifyMode = Peer
270
271 @@ -962,11 +994,13 @@ client = 23-version-negotiation-client
272 [23-version-negotiation-server]
273 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
274 CipherString = DEFAULT
275 +MinProtocol = None
276 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
277
278 [23-version-negotiation-client]
279 CipherString = DEFAULT
280 MaxProtocol = TLSv1
281 +MinProtocol = None
282 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
283 VerifyMode = Peer
284
285 @@ -994,6 +1028,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
286 [24-version-negotiation-client]
287 CipherString = DEFAULT
288 MaxProtocol = TLSv1
289 +MinProtocol = None
290 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
291 VerifyMode = Peer
292
293 @@ -1020,6 +1055,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
294 [25-version-negotiation-client]
295 CipherString = DEFAULT
296 MaxProtocol = TLSv1
297 +MinProtocol = None
298 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
299 VerifyMode = Peer
300
301 @@ -1047,6 +1083,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
302 [26-version-negotiation-client]
303 CipherString = DEFAULT
304 MaxProtocol = TLSv1
305 +MinProtocol = None
306 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
307 VerifyMode = Peer
308
309 @@ -1074,6 +1111,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
310 [27-version-negotiation-client]
311 CipherString = DEFAULT
312 MaxProtocol = TLSv1
313 +MinProtocol = None
314 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
315 VerifyMode = Peer
316
317 @@ -1100,6 +1138,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
318 [28-version-negotiation-client]
319 CipherString = DEFAULT
320 MaxProtocol = TLSv1
321 +MinProtocol = None
322 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
323 VerifyMode = Peer
324
325 @@ -1127,6 +1166,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
326 [29-version-negotiation-client]
327 CipherString = DEFAULT
328 MaxProtocol = TLSv1
329 +MinProtocol = None
330 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
331 VerifyMode = Peer
332
333 @@ -1154,6 +1194,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
334 [30-version-negotiation-client]
335 CipherString = DEFAULT
336 MaxProtocol = TLSv1
337 +MinProtocol = None
338 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
339 VerifyMode = Peer
340
341 @@ -1181,6 +1222,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
342 [31-version-negotiation-client]
343 CipherString = DEFAULT
344 MaxProtocol = TLSv1
345 +MinProtocol = None
346 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
347 VerifyMode = Peer
348
349 @@ -1207,6 +1249,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
350 [32-version-negotiation-client]
351 CipherString = DEFAULT
352 MaxProtocol = TLSv1
353 +MinProtocol = None
354 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
355 VerifyMode = Peer
356
357 @@ -1234,6 +1277,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
358 [33-version-negotiation-client]
359 CipherString = DEFAULT
360 MaxProtocol = TLSv1
361 +MinProtocol = None
362 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
363 VerifyMode = Peer
364
365 @@ -1260,6 +1304,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
366 [34-version-negotiation-client]
367 CipherString = DEFAULT
368 MaxProtocol = TLSv1
369 +MinProtocol = None
370 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
371 VerifyMode = Peer
372
373 @@ -1285,6 +1330,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
374 [35-version-negotiation-client]
375 CipherString = DEFAULT
376 MaxProtocol = TLSv1
377 +MinProtocol = None
378 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
379 VerifyMode = Peer
380
381 @@ -1311,6 +1357,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
382 [36-version-negotiation-client]
383 CipherString = DEFAULT
384 MaxProtocol = TLSv1
385 +MinProtocol = None
386 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
387 VerifyMode = Peer
388
389 @@ -1336,6 +1383,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
390 [37-version-negotiation-client]
391 CipherString = DEFAULT
392 MaxProtocol = TLSv1
393 +MinProtocol = None
394 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
395 VerifyMode = Peer
396
397 @@ -1356,11 +1404,13 @@ client = 38-version-negotiation-client
398 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
399 CipherString = DEFAULT
400 MaxProtocol = SSLv3
401 +MinProtocol = None
402 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
403
404 [38-version-negotiation-client]
405 CipherString = DEFAULT
406 MaxProtocol = TLSv1.1
407 +MinProtocol = None
408 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
409 VerifyMode = Peer
410
411 @@ -1381,11 +1431,13 @@ client = 39-version-negotiation-client
412 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
413 CipherString = DEFAULT
414 MaxProtocol = TLSv1
415 +MinProtocol = None
416 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
417
418 [39-version-negotiation-client]
419 CipherString = DEFAULT
420 MaxProtocol = TLSv1.1
421 +MinProtocol = None
422 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
423 VerifyMode = Peer
424
425 @@ -1407,11 +1459,13 @@ client = 40-version-negotiation-client
426 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
427 CipherString = DEFAULT
428 MaxProtocol = TLSv1.1
429 +MinProtocol = None
430 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
431
432 [40-version-negotiation-client]
433 CipherString = DEFAULT
434 MaxProtocol = TLSv1.1
435 +MinProtocol = None
436 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
437 VerifyMode = Peer
438
439 @@ -1433,11 +1487,13 @@ client = 41-version-negotiation-client
440 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
441 CipherString = DEFAULT
442 MaxProtocol = TLSv1.2
443 +MinProtocol = None
444 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
445
446 [41-version-negotiation-client]
447 CipherString = DEFAULT
448 MaxProtocol = TLSv1.1
449 +MinProtocol = None
450 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
451 VerifyMode = Peer
452
453 @@ -1458,11 +1514,13 @@ client = 42-version-negotiation-client
454 [42-version-negotiation-server]
455 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
456 CipherString = DEFAULT
457 +MinProtocol = None
458 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
459
460 [42-version-negotiation-client]
461 CipherString = DEFAULT
462 MaxProtocol = TLSv1.1
463 +MinProtocol = None
464 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
465 VerifyMode = Peer
466
467 @@ -1490,6 +1548,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
468 [43-version-negotiation-client]
469 CipherString = DEFAULT
470 MaxProtocol = TLSv1.1
471 +MinProtocol = None
472 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
473 VerifyMode = Peer
474
475 @@ -1516,6 +1575,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
476 [44-version-negotiation-client]
477 CipherString = DEFAULT
478 MaxProtocol = TLSv1.1
479 +MinProtocol = None
480 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
481 VerifyMode = Peer
482
483 @@ -1543,6 +1603,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
484 [45-version-negotiation-client]
485 CipherString = DEFAULT
486 MaxProtocol = TLSv1.1
487 +MinProtocol = None
488 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
489 VerifyMode = Peer
490
491 @@ -1570,6 +1631,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
492 [46-version-negotiation-client]
493 CipherString = DEFAULT
494 MaxProtocol = TLSv1.1
495 +MinProtocol = None
496 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
497 VerifyMode = Peer
498
499 @@ -1596,6 +1658,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
500 [47-version-negotiation-client]
501 CipherString = DEFAULT
502 MaxProtocol = TLSv1.1
503 +MinProtocol = None
504 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
505 VerifyMode = Peer
506
507 @@ -1623,6 +1686,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
508 [48-version-negotiation-client]
509 CipherString = DEFAULT
510 MaxProtocol = TLSv1.1
511 +MinProtocol = None
512 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
513 VerifyMode = Peer
514
515 @@ -1650,6 +1714,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
516 [49-version-negotiation-client]
517 CipherString = DEFAULT
518 MaxProtocol = TLSv1.1
519 +MinProtocol = None
520 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
521 VerifyMode = Peer
522
523 @@ -1677,6 +1742,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
524 [50-version-negotiation-client]
525 CipherString = DEFAULT
526 MaxProtocol = TLSv1.1
527 +MinProtocol = None
528 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
529 VerifyMode = Peer
530
531 @@ -1703,6 +1769,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
532 [51-version-negotiation-client]
533 CipherString = DEFAULT
534 MaxProtocol = TLSv1.1
535 +MinProtocol = None
536 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
537 VerifyMode = Peer
538
539 @@ -1730,6 +1797,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
540 [52-version-negotiation-client]
541 CipherString = DEFAULT
542 MaxProtocol = TLSv1.1
543 +MinProtocol = None
544 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
545 VerifyMode = Peer
546
547 @@ -1757,6 +1825,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
548 [53-version-negotiation-client]
549 CipherString = DEFAULT
550 MaxProtocol = TLSv1.1
551 +MinProtocol = None
552 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
553 VerifyMode = Peer
554
555 @@ -1783,6 +1852,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
556 [54-version-negotiation-client]
557 CipherString = DEFAULT
558 MaxProtocol = TLSv1.1
559 +MinProtocol = None
560 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
561 VerifyMode = Peer
562
563 @@ -1810,6 +1880,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
564 [55-version-negotiation-client]
565 CipherString = DEFAULT
566 MaxProtocol = TLSv1.1
567 +MinProtocol = None
568 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
569 VerifyMode = Peer
570
571 @@ -1835,6 +1906,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
572 [56-version-negotiation-client]
573 CipherString = DEFAULT
574 MaxProtocol = TLSv1.1
575 +MinProtocol = None
576 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
577 VerifyMode = Peer
578
579 @@ -1855,11 +1927,13 @@ client = 57-version-negotiation-client
580 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
581 CipherString = DEFAULT
582 MaxProtocol = SSLv3
583 +MinProtocol = None
584 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
585
586 [57-version-negotiation-client]
587 CipherString = DEFAULT
588 MaxProtocol = TLSv1.2
589 +MinProtocol = None
590 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
591 VerifyMode = Peer
592
593 @@ -1880,11 +1954,13 @@ client = 58-version-negotiation-client
594 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
595 CipherString = DEFAULT
596 MaxProtocol = TLSv1
597 +MinProtocol = None
598 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
599
600 [58-version-negotiation-client]
601 CipherString = DEFAULT
602 MaxProtocol = TLSv1.2
603 +MinProtocol = None
604 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
605 VerifyMode = Peer
606
607 @@ -1906,11 +1982,13 @@ client = 59-version-negotiation-client
608 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
609 CipherString = DEFAULT
610 MaxProtocol = TLSv1.1
611 +MinProtocol = None
612 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
613
614 [59-version-negotiation-client]
615 CipherString = DEFAULT
616 MaxProtocol = TLSv1.2
617 +MinProtocol = None
618 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
619 VerifyMode = Peer
620
621 @@ -1932,11 +2010,13 @@ client = 60-version-negotiation-client
622 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
623 CipherString = DEFAULT
624 MaxProtocol = TLSv1.2
625 +MinProtocol = None
626 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
627
628 [60-version-negotiation-client]
629 CipherString = DEFAULT
630 MaxProtocol = TLSv1.2
631 +MinProtocol = None
632 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
633 VerifyMode = Peer
634
635 @@ -1957,11 +2037,13 @@ client = 61-version-negotiation-client
636 [61-version-negotiation-server]
637 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
638 CipherString = DEFAULT
639 +MinProtocol = None
640 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
641
642 [61-version-negotiation-client]
643 CipherString = DEFAULT
644 MaxProtocol = TLSv1.2
645 +MinProtocol = None
646 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
647 VerifyMode = Peer
648
649 @@ -1989,6 +2071,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
650 [62-version-negotiation-client]
651 CipherString = DEFAULT
652 MaxProtocol = TLSv1.2
653 +MinProtocol = None
654 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
655 VerifyMode = Peer
656
657 @@ -2015,6 +2098,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
658 [63-version-negotiation-client]
659 CipherString = DEFAULT
660 MaxProtocol = TLSv1.2
661 +MinProtocol = None
662 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
663 VerifyMode = Peer
664
665 @@ -2042,6 +2126,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
666 [64-version-negotiation-client]
667 CipherString = DEFAULT
668 MaxProtocol = TLSv1.2
669 +MinProtocol = None
670 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
671 VerifyMode = Peer
672
673 @@ -2069,6 +2154,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
674 [65-version-negotiation-client]
675 CipherString = DEFAULT
676 MaxProtocol = TLSv1.2
677 +MinProtocol = None
678 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
679 VerifyMode = Peer
680
681 @@ -2095,6 +2181,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
682 [66-version-negotiation-client]
683 CipherString = DEFAULT
684 MaxProtocol = TLSv1.2
685 +MinProtocol = None
686 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
687 VerifyMode = Peer
688
689 @@ -2122,6 +2209,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
690 [67-version-negotiation-client]
691 CipherString = DEFAULT
692 MaxProtocol = TLSv1.2
693 +MinProtocol = None
694 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
695 VerifyMode = Peer
696
697 @@ -2149,6 +2237,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
698 [68-version-negotiation-client]
699 CipherString = DEFAULT
700 MaxProtocol = TLSv1.2
701 +MinProtocol = None
702 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
703 VerifyMode = Peer
704
705 @@ -2176,6 +2265,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
706 [69-version-negotiation-client]
707 CipherString = DEFAULT
708 MaxProtocol = TLSv1.2
709 +MinProtocol = None
710 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
711 VerifyMode = Peer
712
713 @@ -2202,6 +2292,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
714 [70-version-negotiation-client]
715 CipherString = DEFAULT
716 MaxProtocol = TLSv1.2
717 +MinProtocol = None
718 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
719 VerifyMode = Peer
720
721 @@ -2229,6 +2320,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
722 [71-version-negotiation-client]
723 CipherString = DEFAULT
724 MaxProtocol = TLSv1.2
725 +MinProtocol = None
726 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
727 VerifyMode = Peer
728
729 @@ -2256,6 +2348,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
730 [72-version-negotiation-client]
731 CipherString = DEFAULT
732 MaxProtocol = TLSv1.2
733 +MinProtocol = None
734 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
735 VerifyMode = Peer
736
737 @@ -2282,6 +2375,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
738 [73-version-negotiation-client]
739 CipherString = DEFAULT
740 MaxProtocol = TLSv1.2
741 +MinProtocol = None
742 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
743 VerifyMode = Peer
744
745 @@ -2309,6 +2403,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
746 [74-version-negotiation-client]
747 CipherString = DEFAULT
748 MaxProtocol = TLSv1.2
749 +MinProtocol = None
750 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
751 VerifyMode = Peer
752
753 @@ -2335,6 +2430,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
754 [75-version-negotiation-client]
755 CipherString = DEFAULT
756 MaxProtocol = TLSv1.2
757 +MinProtocol = None
758 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
759 VerifyMode = Peer
760
761 @@ -2356,10 +2452,12 @@ client = 76-version-negotiation-client
762 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
763 CipherString = DEFAULT
764 MaxProtocol = SSLv3
765 +MinProtocol = None
766 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
767
768 [76-version-negotiation-client]
769 CipherString = DEFAULT
770 +MinProtocol = None
771 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
772 VerifyMode = Peer
773
774 @@ -2380,10 +2478,12 @@ client = 77-version-negotiation-client
775 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
776 CipherString = DEFAULT
777 MaxProtocol = TLSv1
778 +MinProtocol = None
779 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
780
781 [77-version-negotiation-client]
782 CipherString = DEFAULT
783 +MinProtocol = None
784 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
785 VerifyMode = Peer
786
787 @@ -2405,10 +2505,12 @@ client = 78-version-negotiation-client
788 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
789 CipherString = DEFAULT
790 MaxProtocol = TLSv1.1
791 +MinProtocol = None
792 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
793
794 [78-version-negotiation-client]
795 CipherString = DEFAULT
796 +MinProtocol = None
797 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
798 VerifyMode = Peer
799
800 @@ -2430,10 +2532,12 @@ client = 79-version-negotiation-client
801 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
802 CipherString = DEFAULT
803 MaxProtocol = TLSv1.2
804 +MinProtocol = None
805 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
806
807 [79-version-negotiation-client]
808 CipherString = DEFAULT
809 +MinProtocol = None
810 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
811 VerifyMode = Peer
812
813 @@ -2454,10 +2558,12 @@ client = 80-version-negotiation-client
814 [80-version-negotiation-server]
815 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
816 CipherString = DEFAULT
817 +MinProtocol = None
818 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
819
820 [80-version-negotiation-client]
821 CipherString = DEFAULT
822 +MinProtocol = None
823 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
824 VerifyMode = Peer
825
826 @@ -2484,6 +2590,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
827
828 [81-version-negotiation-client]
829 CipherString = DEFAULT
830 +MinProtocol = None
831 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
832 VerifyMode = Peer
833
834 @@ -2509,6 +2616,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
835
836 [82-version-negotiation-client]
837 CipherString = DEFAULT
838 +MinProtocol = None
839 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
840 VerifyMode = Peer
841
842 @@ -2535,6 +2643,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
843
844 [83-version-negotiation-client]
845 CipherString = DEFAULT
846 +MinProtocol = None
847 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
848 VerifyMode = Peer
849
850 @@ -2561,6 +2670,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
851
852 [84-version-negotiation-client]
853 CipherString = DEFAULT
854 +MinProtocol = None
855 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
856 VerifyMode = Peer
857
858 @@ -2586,6 +2696,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
859
860 [85-version-negotiation-client]
861 CipherString = DEFAULT
862 +MinProtocol = None
863 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
864 VerifyMode = Peer
865
866 @@ -2612,6 +2723,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
867
868 [86-version-negotiation-client]
869 CipherString = DEFAULT
870 +MinProtocol = None
871 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
872 VerifyMode = Peer
873
874 @@ -2638,6 +2750,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
875
876 [87-version-negotiation-client]
877 CipherString = DEFAULT
878 +MinProtocol = None
879 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
880 VerifyMode = Peer
881
882 @@ -2664,6 +2777,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
883
884 [88-version-negotiation-client]
885 CipherString = DEFAULT
886 +MinProtocol = None
887 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
888 VerifyMode = Peer
889
890 @@ -2689,6 +2803,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
891
892 [89-version-negotiation-client]
893 CipherString = DEFAULT
894 +MinProtocol = None
895 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
896 VerifyMode = Peer
897
898 @@ -2715,6 +2830,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
899
900 [90-version-negotiation-client]
901 CipherString = DEFAULT
902 +MinProtocol = None
903 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
904 VerifyMode = Peer
905
906 @@ -2741,6 +2857,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
907
908 [91-version-negotiation-client]
909 CipherString = DEFAULT
910 +MinProtocol = None
911 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
912 VerifyMode = Peer
913
914 @@ -2766,6 +2883,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
915
916 [92-version-negotiation-client]
917 CipherString = DEFAULT
918 +MinProtocol = None
919 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
920 VerifyMode = Peer
921
922 @@ -2792,6 +2910,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
923
924 [93-version-negotiation-client]
925 CipherString = DEFAULT
926 +MinProtocol = None
927 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
928 VerifyMode = Peer
929
930 @@ -2817,6 +2936,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
931
932 [94-version-negotiation-client]
933 CipherString = DEFAULT
934 +MinProtocol = None
935 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
936 VerifyMode = Peer
937
938 @@ -2838,6 +2958,7 @@ client = 95-version-negotiation-client
939 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
940 CipherString = DEFAULT
941 MaxProtocol = SSLv3
942 +MinProtocol = None
943 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
944
945 [95-version-negotiation-client]
946 @@ -2864,6 +2985,7 @@ client = 96-version-negotiation-client
947 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
948 CipherString = DEFAULT
949 MaxProtocol = TLSv1
950 +MinProtocol = None
951 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
952
953 [96-version-negotiation-client]
954 @@ -2890,6 +3012,7 @@ client = 97-version-negotiation-client
955 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
956 CipherString = DEFAULT
957 MaxProtocol = TLSv1.1
958 +MinProtocol = None
959 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
960
961 [97-version-negotiation-client]
962 @@ -2916,6 +3039,7 @@ client = 98-version-negotiation-client
963 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
964 CipherString = DEFAULT
965 MaxProtocol = TLSv1.2
966 +MinProtocol = None
967 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
968
969 [98-version-negotiation-client]
970 @@ -2941,6 +3065,7 @@ client = 99-version-negotiation-client
971 [99-version-negotiation-server]
972 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
973 CipherString = DEFAULT
974 +MinProtocol = None
975 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
976
977 [99-version-negotiation-client]
978 @@ -3341,6 +3466,7 @@ client = 114-version-negotiation-client
979 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
980 CipherString = DEFAULT
981 MaxProtocol = SSLv3
982 +MinProtocol = None
983 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
984
985 [114-version-negotiation-client]
986 @@ -3367,6 +3493,7 @@ client = 115-version-negotiation-client
987 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
988 CipherString = DEFAULT
989 MaxProtocol = TLSv1
990 +MinProtocol = None
991 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
992
993 [115-version-negotiation-client]
994 @@ -3394,6 +3521,7 @@ client = 116-version-negotiation-client
995 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
996 CipherString = DEFAULT
997 MaxProtocol = TLSv1.1
998 +MinProtocol = None
999 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1000
1001 [116-version-negotiation-client]
1002 @@ -3421,6 +3549,7 @@ client = 117-version-negotiation-client
1003 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1004 CipherString = DEFAULT
1005 MaxProtocol = TLSv1.2
1006 +MinProtocol = None
1007 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1008
1009 [117-version-negotiation-client]
1010 @@ -3447,6 +3576,7 @@ client = 118-version-negotiation-client
1011 [118-version-negotiation-server]
1012 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1013 CipherString = DEFAULT
1014 +MinProtocol = None
1015 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1016
1017 [118-version-negotiation-client]
1018 @@ -3856,6 +3986,7 @@ client = 133-version-negotiation-client
1019 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1020 CipherString = DEFAULT
1021 MaxProtocol = SSLv3
1022 +MinProtocol = None
1023 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1024
1025 [133-version-negotiation-client]
1026 @@ -3882,6 +4013,7 @@ client = 134-version-negotiation-client
1027 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1028 CipherString = DEFAULT
1029 MaxProtocol = TLSv1
1030 +MinProtocol = None
1031 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1032
1033 [134-version-negotiation-client]
1034 @@ -3909,6 +4041,7 @@ client = 135-version-negotiation-client
1035 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1036 CipherString = DEFAULT
1037 MaxProtocol = TLSv1.1
1038 +MinProtocol = None
1039 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1040
1041 [135-version-negotiation-client]
1042 @@ -3936,6 +4069,7 @@ client = 136-version-negotiation-client
1043 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1044 CipherString = DEFAULT
1045 MaxProtocol = TLSv1.2
1046 +MinProtocol = None
1047 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1048
1049 [136-version-negotiation-client]
1050 @@ -3962,6 +4096,7 @@ client = 137-version-negotiation-client
1051 [137-version-negotiation-server]
1052 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1053 CipherString = DEFAULT
1054 +MinProtocol = None
1055 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1056
1057 [137-version-negotiation-client]
1058 @@ -4374,6 +4509,7 @@ client = 152-version-negotiation-client
1059 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1060 CipherString = DEFAULT
1061 MaxProtocol = SSLv3
1062 +MinProtocol = None
1063 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1064
1065 [152-version-negotiation-client]
1066 @@ -4400,6 +4536,7 @@ client = 153-version-negotiation-client
1067 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1068 CipherString = DEFAULT
1069 MaxProtocol = TLSv1
1070 +MinProtocol = None
1071 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1072
1073 [153-version-negotiation-client]
1074 @@ -4427,6 +4564,7 @@ client = 154-version-negotiation-client
1075 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1076 CipherString = DEFAULT
1077 MaxProtocol = TLSv1.1
1078 +MinProtocol = None
1079 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1080
1081 [154-version-negotiation-client]
1082 @@ -4454,6 +4592,7 @@ client = 155-version-negotiation-client
1083 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1084 CipherString = DEFAULT
1085 MaxProtocol = TLSv1.2
1086 +MinProtocol = None
1087 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1088
1089 [155-version-negotiation-client]
1090 @@ -4480,6 +4619,7 @@ client = 156-version-negotiation-client
1091 [156-version-negotiation-server]
1092 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1093 CipherString = DEFAULT
1094 +MinProtocol = None
1095 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1096
1097 [156-version-negotiation-client]
1098 @@ -4894,6 +5034,7 @@ client = 171-version-negotiation-client
1099 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1100 CipherString = DEFAULT
1101 MaxProtocol = SSLv3
1102 +MinProtocol = None
1103 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1104
1105 [171-version-negotiation-client]
1106 @@ -4919,6 +5060,7 @@ client = 172-version-negotiation-client
1107 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1108 CipherString = DEFAULT
1109 MaxProtocol = TLSv1
1110 +MinProtocol = None
1111 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1112
1113 [172-version-negotiation-client]
1114 @@ -4945,6 +5087,7 @@ client = 173-version-negotiation-client
1115 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1116 CipherString = DEFAULT
1117 MaxProtocol = TLSv1.1
1118 +MinProtocol = None
1119 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1120
1121 [173-version-negotiation-client]
1122 @@ -4971,6 +5114,7 @@ client = 174-version-negotiation-client
1123 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1124 CipherString = DEFAULT
1125 MaxProtocol = TLSv1.2
1126 +MinProtocol = None
1127 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1128
1129 [174-version-negotiation-client]
1130 @@ -4996,6 +5140,7 @@ client = 175-version-negotiation-client
1131 [175-version-negotiation-server]
1132 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1133 CipherString = DEFAULT
1134 +MinProtocol = None
1135 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1136
1137 [175-version-negotiation-client]
1138 @@ -5395,6 +5540,7 @@ client = 190-version-negotiation-client
1139 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1140 CipherString = DEFAULT
1141 MaxProtocol = SSLv3
1142 +MinProtocol = None
1143 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1144
1145 [190-version-negotiation-client]
1146 @@ -5421,6 +5567,7 @@ client = 191-version-negotiation-client
1147 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1148 CipherString = DEFAULT
1149 MaxProtocol = TLSv1
1150 +MinProtocol = None
1151 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1152
1153 [191-version-negotiation-client]
1154 @@ -5448,6 +5595,7 @@ client = 192-version-negotiation-client
1155 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1156 CipherString = DEFAULT
1157 MaxProtocol = TLSv1.1
1158 +MinProtocol = None
1159 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1160
1161 [192-version-negotiation-client]
1162 @@ -5475,6 +5623,7 @@ client = 193-version-negotiation-client
1163 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1164 CipherString = DEFAULT
1165 MaxProtocol = TLSv1.2
1166 +MinProtocol = None
1167 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1168
1169 [193-version-negotiation-client]
1170 @@ -5501,6 +5650,7 @@ client = 194-version-negotiation-client
1171 [194-version-negotiation-server]
1172 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1173 CipherString = DEFAULT
1174 +MinProtocol = None
1175 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1176
1177 [194-version-negotiation-client]
1178 @@ -5910,6 +6060,7 @@ client = 209-version-negotiation-client
1179 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1180 CipherString = DEFAULT
1181 MaxProtocol = SSLv3
1182 +MinProtocol = None
1183 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1184
1185 [209-version-negotiation-client]
1186 @@ -5936,6 +6087,7 @@ client = 210-version-negotiation-client
1187 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1188 CipherString = DEFAULT
1189 MaxProtocol = TLSv1
1190 +MinProtocol = None
1191 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1192
1193 [210-version-negotiation-client]
1194 @@ -5963,6 +6115,7 @@ client = 211-version-negotiation-client
1195 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1196 CipherString = DEFAULT
1197 MaxProtocol = TLSv1.1
1198 +MinProtocol = None
1199 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1200
1201 [211-version-negotiation-client]
1202 @@ -5990,6 +6143,7 @@ client = 212-version-negotiation-client
1203 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1204 CipherString = DEFAULT
1205 MaxProtocol = TLSv1.2
1206 +MinProtocol = None
1207 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1208
1209 [212-version-negotiation-client]
1210 @@ -6016,6 +6170,7 @@ client = 213-version-negotiation-client
1211 [213-version-negotiation-server]
1212 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1213 CipherString = DEFAULT
1214 +MinProtocol = None
1215 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1216
1217 [213-version-negotiation-client]
1218 @@ -6428,6 +6583,7 @@ client = 228-version-negotiation-client
1219 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1220 CipherString = DEFAULT
1221 MaxProtocol = SSLv3
1222 +MinProtocol = None
1223 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1224
1225 [228-version-negotiation-client]
1226 @@ -6454,6 +6610,7 @@ client = 229-version-negotiation-client
1227 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1228 CipherString = DEFAULT
1229 MaxProtocol = TLSv1
1230 +MinProtocol = None
1231 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1232
1233 [229-version-negotiation-client]
1234 @@ -6481,6 +6638,7 @@ client = 230-version-negotiation-client
1235 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1236 CipherString = DEFAULT
1237 MaxProtocol = TLSv1.1
1238 +MinProtocol = None
1239 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1240
1241 [230-version-negotiation-client]
1242 @@ -6508,6 +6666,7 @@ client = 231-version-negotiation-client
1243 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1244 CipherString = DEFAULT
1245 MaxProtocol = TLSv1.2
1246 +MinProtocol = None
1247 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1248
1249 [231-version-negotiation-client]
1250 @@ -6534,6 +6693,7 @@ client = 232-version-negotiation-client
1251 [232-version-negotiation-server]
1252 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1253 CipherString = DEFAULT
1254 +MinProtocol = None
1255 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1256
1257 [232-version-negotiation-client]
1258 @@ -6948,6 +7108,7 @@ client = 247-version-negotiation-client
1259 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1260 CipherString = DEFAULT
1261 MaxProtocol = SSLv3
1262 +MinProtocol = None
1263 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1264
1265 [247-version-negotiation-client]
1266 @@ -6973,6 +7134,7 @@ client = 248-version-negotiation-client
1267 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1268 CipherString = DEFAULT
1269 MaxProtocol = TLSv1
1270 +MinProtocol = None
1271 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1272
1273 [248-version-negotiation-client]
1274 @@ -6999,6 +7161,7 @@ client = 249-version-negotiation-client
1275 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1276 CipherString = DEFAULT
1277 MaxProtocol = TLSv1.1
1278 +MinProtocol = None
1279 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1280
1281 [249-version-negotiation-client]
1282 @@ -7025,6 +7188,7 @@ client = 250-version-negotiation-client
1283 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1284 CipherString = DEFAULT
1285 MaxProtocol = TLSv1.2
1286 +MinProtocol = None
1287 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1288
1289 [250-version-negotiation-client]
1290 @@ -7050,6 +7214,7 @@ client = 251-version-negotiation-client
1291 [251-version-negotiation-server]
1292 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1293 CipherString = DEFAULT
1294 +MinProtocol = None
1295 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1296
1297 [251-version-negotiation-client]
1298 @@ -7449,6 +7614,7 @@ client = 266-version-negotiation-client
1299 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1300 CipherString = DEFAULT
1301 MaxProtocol = SSLv3
1302 +MinProtocol = None
1303 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1304
1305 [266-version-negotiation-client]
1306 @@ -7475,6 +7641,7 @@ client = 267-version-negotiation-client
1307 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1308 CipherString = DEFAULT
1309 MaxProtocol = TLSv1
1310 +MinProtocol = None
1311 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1312
1313 [267-version-negotiation-client]
1314 @@ -7501,6 +7668,7 @@ client = 268-version-negotiation-client
1315 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1316 CipherString = DEFAULT
1317 MaxProtocol = TLSv1.1
1318 +MinProtocol = None
1319 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1320
1321 [268-version-negotiation-client]
1322 @@ -7528,6 +7696,7 @@ client = 269-version-negotiation-client
1323 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1324 CipherString = DEFAULT
1325 MaxProtocol = TLSv1.2
1326 +MinProtocol = None
1327 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1328
1329 [269-version-negotiation-client]
1330 @@ -7554,6 +7723,7 @@ client = 270-version-negotiation-client
1331 [270-version-negotiation-server]
1332 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1333 CipherString = DEFAULT
1334 +MinProtocol = None
1335 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1336
1337 [270-version-negotiation-client]
1338 @@ -7964,6 +8134,7 @@ client = 285-version-negotiation-client
1339 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1340 CipherString = DEFAULT
1341 MaxProtocol = SSLv3
1342 +MinProtocol = None
1343 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1344
1345 [285-version-negotiation-client]
1346 @@ -7990,6 +8161,7 @@ client = 286-version-negotiation-client
1347 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1348 CipherString = DEFAULT
1349 MaxProtocol = TLSv1
1350 +MinProtocol = None
1351 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1352
1353 [286-version-negotiation-client]
1354 @@ -8016,6 +8188,7 @@ client = 287-version-negotiation-client
1355 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1356 CipherString = DEFAULT
1357 MaxProtocol = TLSv1.1
1358 +MinProtocol = None
1359 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1360
1361 [287-version-negotiation-client]
1362 @@ -8043,6 +8216,7 @@ client = 288-version-negotiation-client
1363 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1364 CipherString = DEFAULT
1365 MaxProtocol = TLSv1.2
1366 +MinProtocol = None
1367 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1368
1369 [288-version-negotiation-client]
1370 @@ -8069,6 +8243,7 @@ client = 289-version-negotiation-client
1371 [289-version-negotiation-server]
1372 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1373 CipherString = DEFAULT
1374 +MinProtocol = None
1375 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1376
1377 [289-version-negotiation-client]
1378 @@ -8481,6 +8656,7 @@ client = 304-version-negotiation-client
1379 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1380 CipherString = DEFAULT
1381 MaxProtocol = SSLv3
1382 +MinProtocol = None
1383 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1384
1385 [304-version-negotiation-client]
1386 @@ -8506,6 +8682,7 @@ client = 305-version-negotiation-client
1387 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1388 CipherString = DEFAULT
1389 MaxProtocol = TLSv1
1390 +MinProtocol = None
1391 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1392
1393 [305-version-negotiation-client]
1394 @@ -8531,6 +8708,7 @@ client = 306-version-negotiation-client
1395 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1396 CipherString = DEFAULT
1397 MaxProtocol = TLSv1.1
1398 +MinProtocol = None
1399 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1400
1401 [306-version-negotiation-client]
1402 @@ -8557,6 +8735,7 @@ client = 307-version-negotiation-client
1403 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1404 CipherString = DEFAULT
1405 MaxProtocol = TLSv1.2
1406 +MinProtocol = None
1407 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1408
1409 [307-version-negotiation-client]
1410 @@ -8582,6 +8761,7 @@ client = 308-version-negotiation-client
1411 [308-version-negotiation-server]
1412 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1413 CipherString = DEFAULT
1414 +MinProtocol = None
1415 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1416
1417 [308-version-negotiation-client]
1418 @@ -8979,6 +9159,7 @@ client = 323-version-negotiation-client
1419 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1420 CipherString = DEFAULT
1421 MaxProtocol = SSLv3
1422 +MinProtocol = None
1423 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1424
1425 [323-version-negotiation-client]
1426 @@ -9005,6 +9186,7 @@ client = 324-version-negotiation-client
1427 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1428 CipherString = DEFAULT
1429 MaxProtocol = TLSv1
1430 +MinProtocol = None
1431 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1432
1433 [324-version-negotiation-client]
1434 @@ -9031,6 +9213,7 @@ client = 325-version-negotiation-client
1435 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1436 CipherString = DEFAULT
1437 MaxProtocol = TLSv1.1
1438 +MinProtocol = None
1439 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1440
1441 [325-version-negotiation-client]
1442 @@ -9057,6 +9240,7 @@ client = 326-version-negotiation-client
1443 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1444 CipherString = DEFAULT
1445 MaxProtocol = TLSv1.2
1446 +MinProtocol = None
1447 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1448
1449 [326-version-negotiation-client]
1450 @@ -9083,6 +9267,7 @@ client = 327-version-negotiation-client
1451 [327-version-negotiation-server]
1452 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1453 CipherString = DEFAULT
1454 +MinProtocol = None
1455 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1456
1457 [327-version-negotiation-client]
1458 @@ -9492,6 +9677,7 @@ client = 342-version-negotiation-client
1459 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1460 CipherString = DEFAULT
1461 MaxProtocol = SSLv3
1462 +MinProtocol = None
1463 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1464
1465 [342-version-negotiation-client]
1466 @@ -9517,6 +9703,7 @@ client = 343-version-negotiation-client
1467 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1468 CipherString = DEFAULT
1469 MaxProtocol = TLSv1
1470 +MinProtocol = None
1471 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1472
1473 [343-version-negotiation-client]
1474 @@ -9542,6 +9729,7 @@ client = 344-version-negotiation-client
1475 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1476 CipherString = DEFAULT
1477 MaxProtocol = TLSv1.1
1478 +MinProtocol = None
1479 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1480
1481 [344-version-negotiation-client]
1482 @@ -9567,6 +9755,7 @@ client = 345-version-negotiation-client
1483 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1484 CipherString = DEFAULT
1485 MaxProtocol = TLSv1.2
1486 +MinProtocol = None
1487 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1488
1489 [345-version-negotiation-client]
1490 @@ -9592,6 +9781,7 @@ client = 346-version-negotiation-client
1491 [346-version-negotiation-server]
1492 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1493 CipherString = DEFAULT
1494 +MinProtocol = None
1495 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1496
1497 [346-version-negotiation-client]
1498 diff --git a/test/ssl-tests/07-dtls-protocol-version.conf b/test/ssl-tests/07-dtls-protocol-version.conf
1499 index 3304a3bbaaec..4746581c97b2 100644
1500 --- a/test/ssl-tests/07-dtls-protocol-version.conf
1501 +++ b/test/ssl-tests/07-dtls-protocol-version.conf
1502 @@ -79,11 +79,13 @@ client = 0-version-negotiation-client
1503 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1504 CipherString = DEFAULT
1505 MaxProtocol = DTLSv1
1506 +MinProtocol = None
1507 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1508
1509 [0-version-negotiation-client]
1510 CipherString = DEFAULT
1511 MaxProtocol = DTLSv1
1512 +MinProtocol = None
1513 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1514 VerifyMode = Peer
1515
1516 @@ -106,11 +108,13 @@ client = 1-version-negotiation-client
1517 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1518 CipherString = DEFAULT
1519 MaxProtocol = DTLSv1.2
1520 +MinProtocol = None
1521 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1522
1523 [1-version-negotiation-client]
1524 CipherString = DEFAULT
1525 MaxProtocol = DTLSv1
1526 +MinProtocol = None
1527 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1528 VerifyMode = Peer
1529
1530 @@ -132,11 +136,13 @@ client = 2-version-negotiation-client
1531 [2-version-negotiation-server]
1532 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1533 CipherString = DEFAULT
1534 +MinProtocol = None
1535 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1536
1537 [2-version-negotiation-client]
1538 CipherString = DEFAULT
1539 MaxProtocol = DTLSv1
1540 +MinProtocol = None
1541 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1542 VerifyMode = Peer
1543
1544 @@ -165,6 +171,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1545 [3-version-negotiation-client]
1546 CipherString = DEFAULT
1547 MaxProtocol = DTLSv1
1548 +MinProtocol = None
1549 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1550 VerifyMode = Peer
1551
1552 @@ -193,6 +200,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1553 [4-version-negotiation-client]
1554 CipherString = DEFAULT
1555 MaxProtocol = DTLSv1
1556 +MinProtocol = None
1557 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1558 VerifyMode = Peer
1559
1560 @@ -220,6 +228,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1561 [5-version-negotiation-client]
1562 CipherString = DEFAULT
1563 MaxProtocol = DTLSv1
1564 +MinProtocol = None
1565 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1566 VerifyMode = Peer
1567
1568 @@ -248,6 +257,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1569 [6-version-negotiation-client]
1570 CipherString = DEFAULT
1571 MaxProtocol = DTLSv1
1572 +MinProtocol = None
1573 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1574 VerifyMode = Peer
1575
1576 @@ -274,6 +284,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1577 [7-version-negotiation-client]
1578 CipherString = DEFAULT
1579 MaxProtocol = DTLSv1
1580 +MinProtocol = None
1581 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1582 VerifyMode = Peer
1583
1584 @@ -295,11 +306,13 @@ client = 8-version-negotiation-client
1585 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1586 CipherString = DEFAULT
1587 MaxProtocol = DTLSv1
1588 +MinProtocol = None
1589 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1590
1591 [8-version-negotiation-client]
1592 CipherString = DEFAULT
1593 MaxProtocol = DTLSv1.2
1594 +MinProtocol = None
1595 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1596 VerifyMode = Peer
1597
1598 @@ -322,11 +335,13 @@ client = 9-version-negotiation-client
1599 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1600 CipherString = DEFAULT
1601 MaxProtocol = DTLSv1.2
1602 +MinProtocol = None
1603 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1604
1605 [9-version-negotiation-client]
1606 CipherString = DEFAULT
1607 MaxProtocol = DTLSv1.2
1608 +MinProtocol = None
1609 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1610 VerifyMode = Peer
1611
1612 @@ -348,11 +363,13 @@ client = 10-version-negotiation-client
1613 [10-version-negotiation-server]
1614 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1615 CipherString = DEFAULT
1616 +MinProtocol = None
1617 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1618
1619 [10-version-negotiation-client]
1620 CipherString = DEFAULT
1621 MaxProtocol = DTLSv1.2
1622 +MinProtocol = None
1623 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1624 VerifyMode = Peer
1625
1626 @@ -381,6 +398,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1627 [11-version-negotiation-client]
1628 CipherString = DEFAULT
1629 MaxProtocol = DTLSv1.2
1630 +MinProtocol = None
1631 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1632 VerifyMode = Peer
1633
1634 @@ -409,6 +427,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1635 [12-version-negotiation-client]
1636 CipherString = DEFAULT
1637 MaxProtocol = DTLSv1.2
1638 +MinProtocol = None
1639 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1640 VerifyMode = Peer
1641
1642 @@ -436,6 +455,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1643 [13-version-negotiation-client]
1644 CipherString = DEFAULT
1645 MaxProtocol = DTLSv1.2
1646 +MinProtocol = None
1647 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1648 VerifyMode = Peer
1649
1650 @@ -464,6 +484,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1651 [14-version-negotiation-client]
1652 CipherString = DEFAULT
1653 MaxProtocol = DTLSv1.2
1654 +MinProtocol = None
1655 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1656 VerifyMode = Peer
1657
1658 @@ -491,6 +512,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1659 [15-version-negotiation-client]
1660 CipherString = DEFAULT
1661 MaxProtocol = DTLSv1.2
1662 +MinProtocol = None
1663 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1664 VerifyMode = Peer
1665
1666 @@ -513,10 +535,12 @@ client = 16-version-negotiation-client
1667 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1668 CipherString = DEFAULT
1669 MaxProtocol = DTLSv1
1670 +MinProtocol = None
1671 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1672
1673 [16-version-negotiation-client]
1674 CipherString = DEFAULT
1675 +MinProtocol = None
1676 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1677 VerifyMode = Peer
1678
1679 @@ -539,10 +563,12 @@ client = 17-version-negotiation-client
1680 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1681 CipherString = DEFAULT
1682 MaxProtocol = DTLSv1.2
1683 +MinProtocol = None
1684 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1685
1686 [17-version-negotiation-client]
1687 CipherString = DEFAULT
1688 +MinProtocol = None
1689 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1690 VerifyMode = Peer
1691
1692 @@ -564,10 +590,12 @@ client = 18-version-negotiation-client
1693 [18-version-negotiation-server]
1694 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1695 CipherString = DEFAULT
1696 +MinProtocol = None
1697 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1698
1699 [18-version-negotiation-client]
1700 CipherString = DEFAULT
1701 +MinProtocol = None
1702 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1703 VerifyMode = Peer
1704
1705 @@ -595,6 +623,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1706
1707 [19-version-negotiation-client]
1708 CipherString = DEFAULT
1709 +MinProtocol = None
1710 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1711 VerifyMode = Peer
1712
1713 @@ -622,6 +651,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1714
1715 [20-version-negotiation-client]
1716 CipherString = DEFAULT
1717 +MinProtocol = None
1718 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1719 VerifyMode = Peer
1720
1721 @@ -648,6 +678,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1722
1723 [21-version-negotiation-client]
1724 CipherString = DEFAULT
1725 +MinProtocol = None
1726 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1727 VerifyMode = Peer
1728
1729 @@ -675,6 +706,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1730
1731 [22-version-negotiation-client]
1732 CipherString = DEFAULT
1733 +MinProtocol = None
1734 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1735 VerifyMode = Peer
1736
1737 @@ -701,6 +733,7 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1738
1739 [23-version-negotiation-client]
1740 CipherString = DEFAULT
1741 +MinProtocol = None
1742 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1743 VerifyMode = Peer
1744
1745 @@ -723,6 +756,7 @@ client = 24-version-negotiation-client
1746 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1747 CipherString = DEFAULT
1748 MaxProtocol = DTLSv1
1749 +MinProtocol = None
1750 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1751
1752 [24-version-negotiation-client]
1753 @@ -751,6 +785,7 @@ client = 25-version-negotiation-client
1754 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1755 CipherString = DEFAULT
1756 MaxProtocol = DTLSv1.2
1757 +MinProtocol = None
1758 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1759
1760 [25-version-negotiation-client]
1761 @@ -778,6 +813,7 @@ client = 26-version-negotiation-client
1762 [26-version-negotiation-server]
1763 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1764 CipherString = DEFAULT
1765 +MinProtocol = None
1766 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1767
1768 [26-version-negotiation-client]
1769 @@ -947,6 +983,7 @@ client = 32-version-negotiation-client
1770 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1771 CipherString = DEFAULT
1772 MaxProtocol = DTLSv1
1773 +MinProtocol = None
1774 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1775
1776 [32-version-negotiation-client]
1777 @@ -975,6 +1012,7 @@ client = 33-version-negotiation-client
1778 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1779 CipherString = DEFAULT
1780 MaxProtocol = DTLSv1.2
1781 +MinProtocol = None
1782 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1783
1784 [33-version-negotiation-client]
1785 @@ -1002,6 +1040,7 @@ client = 34-version-negotiation-client
1786 [34-version-negotiation-server]
1787 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1788 CipherString = DEFAULT
1789 +MinProtocol = None
1790 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1791
1792 [34-version-negotiation-client]
1793 @@ -1173,6 +1212,7 @@ client = 40-version-negotiation-client
1794 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1795 CipherString = DEFAULT
1796 MaxProtocol = DTLSv1
1797 +MinProtocol = None
1798 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1799
1800 [40-version-negotiation-client]
1801 @@ -1200,6 +1240,7 @@ client = 41-version-negotiation-client
1802 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1803 CipherString = DEFAULT
1804 MaxProtocol = DTLSv1.2
1805 +MinProtocol = None
1806 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1807
1808 [41-version-negotiation-client]
1809 @@ -1226,6 +1267,7 @@ client = 42-version-negotiation-client
1810 [42-version-negotiation-server]
1811 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1812 CipherString = DEFAULT
1813 +MinProtocol = None
1814 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1815
1816 [42-version-negotiation-client]
1817 @@ -1391,6 +1433,7 @@ client = 48-version-negotiation-client
1818 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1819 CipherString = DEFAULT
1820 MaxProtocol = DTLSv1
1821 +MinProtocol = None
1822 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1823
1824 [48-version-negotiation-client]
1825 @@ -1418,6 +1461,7 @@ client = 49-version-negotiation-client
1826 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1827 CipherString = DEFAULT
1828 MaxProtocol = DTLSv1.2
1829 +MinProtocol = None
1830 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1831
1832 [49-version-negotiation-client]
1833 @@ -1445,6 +1489,7 @@ client = 50-version-negotiation-client
1834 [50-version-negotiation-server]
1835 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1836 CipherString = DEFAULT
1837 +MinProtocol = None
1838 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1839
1840 [50-version-negotiation-client]
1841 @@ -1615,6 +1660,7 @@ client = 56-version-negotiation-client
1842 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1843 CipherString = DEFAULT
1844 MaxProtocol = DTLSv1
1845 +MinProtocol = None
1846 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1847
1848 [56-version-negotiation-client]
1849 @@ -1641,6 +1687,7 @@ client = 57-version-negotiation-client
1850 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1851 CipherString = DEFAULT
1852 MaxProtocol = DTLSv1.2
1853 +MinProtocol = None
1854 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1855
1856 [57-version-negotiation-client]
1857 @@ -1667,6 +1714,7 @@ client = 58-version-negotiation-client
1858 [58-version-negotiation-server]
1859 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1860 CipherString = DEFAULT
1861 +MinProtocol = None
1862 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1863
1864 [58-version-negotiation-client]
1865 diff --git a/test/ssl-tests/10-resumption.conf b/test/ssl-tests/10-resumption.conf
1866 index b2deee4209fd..0e9f539f4ea5 100644
1867 --- a/test/ssl-tests/10-resumption.conf
1868 +++ b/test/ssl-tests/10-resumption.conf
1869 @@ -61,10 +61,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1870 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1871 CipherString = DEFAULT
1872 MaxProtocol = TLSv1
1873 +MinProtocol = None
1874 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1875
1876 [0-resumption-client]
1877 CipherString = DEFAULT
1878 +MinProtocol = None
1879 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1880 VerifyMode = Peer
1881
1882 @@ -97,10 +99,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1883 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1884 CipherString = DEFAULT
1885 MaxProtocol = TLSv1
1886 +MinProtocol = None
1887 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1888
1889 [1-resumption-client]
1890 CipherString = DEFAULT
1891 +MinProtocol = None
1892 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1893 VerifyMode = Peer
1894
1895 @@ -133,10 +137,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1896 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1897 CipherString = DEFAULT
1898 MaxProtocol = TLSv1.1
1899 +MinProtocol = None
1900 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1901
1902 [2-resumption-client]
1903 CipherString = DEFAULT
1904 +MinProtocol = None
1905 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1906 VerifyMode = Peer
1907
1908 @@ -169,10 +175,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1909 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1910 CipherString = DEFAULT
1911 MaxProtocol = TLSv1.1
1912 +MinProtocol = None
1913 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1914
1915 [3-resumption-client]
1916 CipherString = DEFAULT
1917 +MinProtocol = None
1918 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1919 VerifyMode = Peer
1920
1921 @@ -205,10 +213,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1922 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1923 CipherString = DEFAULT
1924 MaxProtocol = TLSv1.2
1925 +MinProtocol = None
1926 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1927
1928 [4-resumption-client]
1929 CipherString = DEFAULT
1930 +MinProtocol = None
1931 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1932 VerifyMode = Peer
1933
1934 @@ -241,10 +251,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1935 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1936 CipherString = DEFAULT
1937 MaxProtocol = TLSv1.2
1938 +MinProtocol = None
1939 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1940
1941 [5-resumption-client]
1942 CipherString = DEFAULT
1943 +MinProtocol = None
1944 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1945 VerifyMode = Peer
1946
1947 @@ -277,10 +289,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1948 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1949 CipherString = DEFAULT
1950 MaxProtocol = TLSv1
1951 +MinProtocol = None
1952 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1953
1954 [6-resumption-client]
1955 CipherString = DEFAULT
1956 +MinProtocol = None
1957 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1958 VerifyMode = Peer
1959
1960 @@ -313,10 +327,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1961 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1962 CipherString = DEFAULT
1963 MaxProtocol = TLSv1
1964 +MinProtocol = None
1965 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1966
1967 [7-resumption-client]
1968 CipherString = DEFAULT
1969 +MinProtocol = None
1970 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1971 VerifyMode = Peer
1972
1973 @@ -349,10 +365,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1974 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1975 CipherString = DEFAULT
1976 MaxProtocol = TLSv1.1
1977 +MinProtocol = None
1978 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1979
1980 [8-resumption-client]
1981 CipherString = DEFAULT
1982 +MinProtocol = None
1983 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1984 VerifyMode = Peer
1985
1986 @@ -385,10 +403,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1987 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
1988 CipherString = DEFAULT
1989 MaxProtocol = TLSv1.1
1990 +MinProtocol = None
1991 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
1992
1993 [9-resumption-client]
1994 CipherString = DEFAULT
1995 +MinProtocol = None
1996 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
1997 VerifyMode = Peer
1998
1999 @@ -421,10 +441,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2000 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2001 CipherString = DEFAULT
2002 MaxProtocol = TLSv1.2
2003 +MinProtocol = None
2004 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2005
2006 [10-resumption-client]
2007 CipherString = DEFAULT
2008 +MinProtocol = None
2009 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2010 VerifyMode = Peer
2011
2012 @@ -457,10 +479,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2013 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2014 CipherString = DEFAULT
2015 MaxProtocol = TLSv1.2
2016 +MinProtocol = None
2017 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2018
2019 [11-resumption-client]
2020 CipherString = DEFAULT
2021 +MinProtocol = None
2022 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2023 VerifyMode = Peer
2024
2025 @@ -493,10 +517,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2026 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2027 CipherString = DEFAULT
2028 MaxProtocol = TLSv1
2029 +MinProtocol = None
2030 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2031
2032 [12-resumption-client]
2033 CipherString = DEFAULT
2034 +MinProtocol = None
2035 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2036 VerifyMode = Peer
2037
2038 @@ -529,10 +555,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2039 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2040 CipherString = DEFAULT
2041 MaxProtocol = TLSv1
2042 +MinProtocol = None
2043 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2044
2045 [13-resumption-client]
2046 CipherString = DEFAULT
2047 +MinProtocol = None
2048 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2049 VerifyMode = Peer
2050
2051 @@ -565,10 +593,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2052 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2053 CipherString = DEFAULT
2054 MaxProtocol = TLSv1.1
2055 +MinProtocol = None
2056 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2057
2058 [14-resumption-client]
2059 CipherString = DEFAULT
2060 +MinProtocol = None
2061 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2062 VerifyMode = Peer
2063
2064 @@ -601,10 +631,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2065 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2066 CipherString = DEFAULT
2067 MaxProtocol = TLSv1.1
2068 +MinProtocol = None
2069 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2070
2071 [15-resumption-client]
2072 CipherString = DEFAULT
2073 +MinProtocol = None
2074 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2075 VerifyMode = Peer
2076
2077 @@ -637,10 +669,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2078 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2079 CipherString = DEFAULT
2080 MaxProtocol = TLSv1.2
2081 +MinProtocol = None
2082 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2083
2084 [16-resumption-client]
2085 CipherString = DEFAULT
2086 +MinProtocol = None
2087 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2088 VerifyMode = Peer
2089
2090 @@ -673,10 +707,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2091 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2092 CipherString = DEFAULT
2093 MaxProtocol = TLSv1.2
2094 +MinProtocol = None
2095 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2096
2097 [17-resumption-client]
2098 CipherString = DEFAULT
2099 +MinProtocol = None
2100 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2101 VerifyMode = Peer
2102
2103 @@ -700,6 +736,7 @@ resume-client = 18-resumption-resume-client
2104 [18-resumption-server]
2105 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2106 CipherString = DEFAULT
2107 +MinProtocol = None
2108 Options = SessionTicket
2109 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2110
2111 @@ -713,6 +750,7 @@ VerifyMode = Peer
2112 [18-resumption-resume-client]
2113 CipherString = DEFAULT
2114 MaxProtocol = TLSv1
2115 +MinProtocol = None
2116 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2117 VerifyMode = Peer
2118
2119 @@ -736,6 +774,7 @@ resume-client = 19-resumption-resume-client
2120 [19-resumption-server]
2121 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2122 CipherString = DEFAULT
2123 +MinProtocol = None
2124 Options = -SessionTicket
2125 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2126
2127 @@ -749,6 +788,7 @@ VerifyMode = Peer
2128 [19-resumption-resume-client]
2129 CipherString = DEFAULT
2130 MaxProtocol = TLSv1
2131 +MinProtocol = None
2132 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2133 VerifyMode = Peer
2134
2135 @@ -772,6 +812,7 @@ resume-client = 20-resumption-resume-client
2136 [20-resumption-server]
2137 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2138 CipherString = DEFAULT
2139 +MinProtocol = None
2140 Options = SessionTicket
2141 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2142
2143 @@ -785,6 +826,7 @@ VerifyMode = Peer
2144 [20-resumption-resume-client]
2145 CipherString = DEFAULT
2146 MaxProtocol = TLSv1.1
2147 +MinProtocol = None
2148 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2149 VerifyMode = Peer
2150
2151 @@ -808,6 +850,7 @@ resume-client = 21-resumption-resume-client
2152 [21-resumption-server]
2153 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2154 CipherString = DEFAULT
2155 +MinProtocol = None
2156 Options = -SessionTicket
2157 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2158
2159 @@ -821,6 +864,7 @@ VerifyMode = Peer
2160 [21-resumption-resume-client]
2161 CipherString = DEFAULT
2162 MaxProtocol = TLSv1.1
2163 +MinProtocol = None
2164 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2165 VerifyMode = Peer
2166
2167 @@ -844,6 +888,7 @@ resume-client = 22-resumption-resume-client
2168 [22-resumption-server]
2169 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2170 CipherString = DEFAULT
2171 +MinProtocol = None
2172 Options = SessionTicket
2173 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2174
2175 @@ -857,6 +902,7 @@ VerifyMode = Peer
2176 [22-resumption-resume-client]
2177 CipherString = DEFAULT
2178 MaxProtocol = TLSv1.2
2179 +MinProtocol = None
2180 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2181 VerifyMode = Peer
2182
2183 @@ -880,6 +926,7 @@ resume-client = 23-resumption-resume-client
2184 [23-resumption-server]
2185 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2186 CipherString = DEFAULT
2187 +MinProtocol = None
2188 Options = -SessionTicket
2189 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2190
2191 @@ -893,6 +940,7 @@ VerifyMode = Peer
2192 [23-resumption-resume-client]
2193 CipherString = DEFAULT
2194 MaxProtocol = TLSv1.2
2195 +MinProtocol = None
2196 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2197 VerifyMode = Peer
2198
2199 @@ -916,6 +964,7 @@ resume-client = 24-resumption-resume-client
2200 [24-resumption-server]
2201 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2202 CipherString = DEFAULT
2203 +MinProtocol = None
2204 Options = SessionTicket
2205 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2206
2207 @@ -929,6 +978,7 @@ VerifyMode = Peer
2208 [24-resumption-resume-client]
2209 CipherString = DEFAULT
2210 MaxProtocol = TLSv1
2211 +MinProtocol = None
2212 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2213 VerifyMode = Peer
2214
2215 @@ -952,6 +1002,7 @@ resume-client = 25-resumption-resume-client
2216 [25-resumption-server]
2217 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2218 CipherString = DEFAULT
2219 +MinProtocol = None
2220 Options = -SessionTicket
2221 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2222
2223 @@ -965,6 +1016,7 @@ VerifyMode = Peer
2224 [25-resumption-resume-client]
2225 CipherString = DEFAULT
2226 MaxProtocol = TLSv1
2227 +MinProtocol = None
2228 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2229 VerifyMode = Peer
2230
2231 @@ -988,6 +1040,7 @@ resume-client = 26-resumption-resume-client
2232 [26-resumption-server]
2233 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2234 CipherString = DEFAULT
2235 +MinProtocol = None
2236 Options = SessionTicket
2237 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2238
2239 @@ -1001,6 +1054,7 @@ VerifyMode = Peer
2240 [26-resumption-resume-client]
2241 CipherString = DEFAULT
2242 MaxProtocol = TLSv1.1
2243 +MinProtocol = None
2244 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2245 VerifyMode = Peer
2246
2247 @@ -1024,6 +1078,7 @@ resume-client = 27-resumption-resume-client
2248 [27-resumption-server]
2249 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2250 CipherString = DEFAULT
2251 +MinProtocol = None
2252 Options = -SessionTicket
2253 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2254
2255 @@ -1037,6 +1092,7 @@ VerifyMode = Peer
2256 [27-resumption-resume-client]
2257 CipherString = DEFAULT
2258 MaxProtocol = TLSv1.1
2259 +MinProtocol = None
2260 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2261 VerifyMode = Peer
2262
2263 @@ -1060,6 +1116,7 @@ resume-client = 28-resumption-resume-client
2264 [28-resumption-server]
2265 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2266 CipherString = DEFAULT
2267 +MinProtocol = None
2268 Options = SessionTicket
2269 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2270
2271 @@ -1073,6 +1130,7 @@ VerifyMode = Peer
2272 [28-resumption-resume-client]
2273 CipherString = DEFAULT
2274 MaxProtocol = TLSv1.2
2275 +MinProtocol = None
2276 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2277 VerifyMode = Peer
2278
2279 @@ -1096,6 +1154,7 @@ resume-client = 29-resumption-resume-client
2280 [29-resumption-server]
2281 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2282 CipherString = DEFAULT
2283 +MinProtocol = None
2284 Options = -SessionTicket
2285 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2286
2287 @@ -1109,6 +1168,7 @@ VerifyMode = Peer
2288 [29-resumption-resume-client]
2289 CipherString = DEFAULT
2290 MaxProtocol = TLSv1.2
2291 +MinProtocol = None
2292 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2293 VerifyMode = Peer
2294
2295 @@ -1132,6 +1192,7 @@ resume-client = 30-resumption-resume-client
2296 [30-resumption-server]
2297 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2298 CipherString = DEFAULT
2299 +MinProtocol = None
2300 Options = SessionTicket
2301 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2302
2303 @@ -1145,6 +1206,7 @@ VerifyMode = Peer
2304 [30-resumption-resume-client]
2305 CipherString = DEFAULT
2306 MaxProtocol = TLSv1
2307 +MinProtocol = None
2308 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2309 VerifyMode = Peer
2310
2311 @@ -1168,6 +1230,7 @@ resume-client = 31-resumption-resume-client
2312 [31-resumption-server]
2313 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2314 CipherString = DEFAULT
2315 +MinProtocol = None
2316 Options = -SessionTicket
2317 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2318
2319 @@ -1181,6 +1244,7 @@ VerifyMode = Peer
2320 [31-resumption-resume-client]
2321 CipherString = DEFAULT
2322 MaxProtocol = TLSv1
2323 +MinProtocol = None
2324 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2325 VerifyMode = Peer
2326
2327 @@ -1204,6 +1268,7 @@ resume-client = 32-resumption-resume-client
2328 [32-resumption-server]
2329 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2330 CipherString = DEFAULT
2331 +MinProtocol = None
2332 Options = SessionTicket
2333 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2334
2335 @@ -1217,6 +1282,7 @@ VerifyMode = Peer
2336 [32-resumption-resume-client]
2337 CipherString = DEFAULT
2338 MaxProtocol = TLSv1.1
2339 +MinProtocol = None
2340 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2341 VerifyMode = Peer
2342
2343 @@ -1240,6 +1306,7 @@ resume-client = 33-resumption-resume-client
2344 [33-resumption-server]
2345 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2346 CipherString = DEFAULT
2347 +MinProtocol = None
2348 Options = -SessionTicket
2349 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2350
2351 @@ -1253,6 +1320,7 @@ VerifyMode = Peer
2352 [33-resumption-resume-client]
2353 CipherString = DEFAULT
2354 MaxProtocol = TLSv1.1
2355 +MinProtocol = None
2356 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2357 VerifyMode = Peer
2358
2359 @@ -1276,6 +1344,7 @@ resume-client = 34-resumption-resume-client
2360 [34-resumption-server]
2361 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2362 CipherString = DEFAULT
2363 +MinProtocol = None
2364 Options = SessionTicket
2365 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2366
2367 @@ -1289,6 +1358,7 @@ VerifyMode = Peer
2368 [34-resumption-resume-client]
2369 CipherString = DEFAULT
2370 MaxProtocol = TLSv1.2
2371 +MinProtocol = None
2372 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2373 VerifyMode = Peer
2374
2375 @@ -1312,6 +1382,7 @@ resume-client = 35-resumption-resume-client
2376 [35-resumption-server]
2377 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2378 CipherString = DEFAULT
2379 +MinProtocol = None
2380 Options = -SessionTicket
2381 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2382
2383 @@ -1325,6 +1396,7 @@ VerifyMode = Peer
2384 [35-resumption-resume-client]
2385 CipherString = DEFAULT
2386 MaxProtocol = TLSv1.2
2387 +MinProtocol = None
2388 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2389 VerifyMode = Peer
2390
2391 diff --git a/test/ssl-tests/11-dtls_resumption.conf b/test/ssl-tests/11-dtls_resumption.conf
2392 index ceed95974472..d19aa8e6bed1 100644
2393 --- a/test/ssl-tests/11-dtls_resumption.conf
2394 +++ b/test/ssl-tests/11-dtls_resumption.conf
2395 @@ -41,10 +41,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2396 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2397 CipherString = DEFAULT
2398 MaxProtocol = DTLSv1
2399 +MinProtocol = None
2400 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2401
2402 [0-resumption-client]
2403 CipherString = DEFAULT
2404 +MinProtocol = None
2405 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2406 VerifyMode = Peer
2407
2408 @@ -78,10 +80,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2409 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2410 CipherString = DEFAULT
2411 MaxProtocol = DTLSv1
2412 +MinProtocol = None
2413 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2414
2415 [1-resumption-client]
2416 CipherString = DEFAULT
2417 +MinProtocol = None
2418 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2419 VerifyMode = Peer
2420
2421 @@ -115,10 +119,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2422 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2423 CipherString = DEFAULT
2424 MaxProtocol = DTLSv1.2
2425 +MinProtocol = None
2426 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2427
2428 [2-resumption-client]
2429 CipherString = DEFAULT
2430 +MinProtocol = None
2431 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2432 VerifyMode = Peer
2433
2434 @@ -152,10 +158,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2435 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2436 CipherString = DEFAULT
2437 MaxProtocol = DTLSv1.2
2438 +MinProtocol = None
2439 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2440
2441 [3-resumption-client]
2442 CipherString = DEFAULT
2443 +MinProtocol = None
2444 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2445 VerifyMode = Peer
2446
2447 @@ -189,10 +197,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2448 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2449 CipherString = DEFAULT
2450 MaxProtocol = DTLSv1
2451 +MinProtocol = None
2452 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2453
2454 [4-resumption-client]
2455 CipherString = DEFAULT
2456 +MinProtocol = None
2457 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2458 VerifyMode = Peer
2459
2460 @@ -226,10 +236,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2461 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2462 CipherString = DEFAULT
2463 MaxProtocol = DTLSv1
2464 +MinProtocol = None
2465 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2466
2467 [5-resumption-client]
2468 CipherString = DEFAULT
2469 +MinProtocol = None
2470 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2471 VerifyMode = Peer
2472
2473 @@ -263,10 +275,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2474 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2475 CipherString = DEFAULT
2476 MaxProtocol = DTLSv1.2
2477 +MinProtocol = None
2478 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2479
2480 [6-resumption-client]
2481 CipherString = DEFAULT
2482 +MinProtocol = None
2483 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2484 VerifyMode = Peer
2485
2486 @@ -300,10 +314,12 @@ PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2487 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2488 CipherString = DEFAULT
2489 MaxProtocol = DTLSv1.2
2490 +MinProtocol = None
2491 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2492
2493 [7-resumption-client]
2494 CipherString = DEFAULT
2495 +MinProtocol = None
2496 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2497 VerifyMode = Peer
2498
2499 @@ -328,6 +344,7 @@ resume-client = 8-resumption-resume-client
2500 [8-resumption-server]
2501 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2502 CipherString = DEFAULT
2503 +MinProtocol = None
2504 Options = SessionTicket
2505 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2506
2507 @@ -341,6 +358,7 @@ VerifyMode = Peer
2508 [8-resumption-resume-client]
2509 CipherString = DEFAULT
2510 MaxProtocol = DTLSv1
2511 +MinProtocol = None
2512 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2513 VerifyMode = Peer
2514
2515 @@ -365,6 +383,7 @@ resume-client = 9-resumption-resume-client
2516 [9-resumption-server]
2517 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2518 CipherString = DEFAULT
2519 +MinProtocol = None
2520 Options = -SessionTicket
2521 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2522
2523 @@ -378,6 +397,7 @@ VerifyMode = Peer
2524 [9-resumption-resume-client]
2525 CipherString = DEFAULT
2526 MaxProtocol = DTLSv1
2527 +MinProtocol = None
2528 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2529 VerifyMode = Peer
2530
2531 @@ -402,6 +422,7 @@ resume-client = 10-resumption-resume-client
2532 [10-resumption-server]
2533 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2534 CipherString = DEFAULT
2535 +MinProtocol = None
2536 Options = SessionTicket
2537 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2538
2539 @@ -415,6 +436,7 @@ VerifyMode = Peer
2540 [10-resumption-resume-client]
2541 CipherString = DEFAULT
2542 MaxProtocol = DTLSv1.2
2543 +MinProtocol = None
2544 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2545 VerifyMode = Peer
2546
2547 @@ -439,6 +461,7 @@ resume-client = 11-resumption-resume-client
2548 [11-resumption-server]
2549 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2550 CipherString = DEFAULT
2551 +MinProtocol = None
2552 Options = -SessionTicket
2553 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2554
2555 @@ -452,6 +475,7 @@ VerifyMode = Peer
2556 [11-resumption-resume-client]
2557 CipherString = DEFAULT
2558 MaxProtocol = DTLSv1.2
2559 +MinProtocol = None
2560 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2561 VerifyMode = Peer
2562
2563 @@ -476,6 +500,7 @@ resume-client = 12-resumption-resume-client
2564 [12-resumption-server]
2565 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2566 CipherString = DEFAULT
2567 +MinProtocol = None
2568 Options = SessionTicket
2569 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2570
2571 @@ -489,6 +514,7 @@ VerifyMode = Peer
2572 [12-resumption-resume-client]
2573 CipherString = DEFAULT
2574 MaxProtocol = DTLSv1
2575 +MinProtocol = None
2576 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2577 VerifyMode = Peer
2578
2579 @@ -513,6 +539,7 @@ resume-client = 13-resumption-resume-client
2580 [13-resumption-server]
2581 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2582 CipherString = DEFAULT
2583 +MinProtocol = None
2584 Options = -SessionTicket
2585 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2586
2587 @@ -526,6 +553,7 @@ VerifyMode = Peer
2588 [13-resumption-resume-client]
2589 CipherString = DEFAULT
2590 MaxProtocol = DTLSv1
2591 +MinProtocol = None
2592 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2593 VerifyMode = Peer
2594
2595 @@ -550,6 +578,7 @@ resume-client = 14-resumption-resume-client
2596 [14-resumption-server]
2597 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2598 CipherString = DEFAULT
2599 +MinProtocol = None
2600 Options = SessionTicket
2601 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2602
2603 @@ -563,6 +592,7 @@ VerifyMode = Peer
2604 [14-resumption-resume-client]
2605 CipherString = DEFAULT
2606 MaxProtocol = DTLSv1.2
2607 +MinProtocol = None
2608 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2609 VerifyMode = Peer
2610
2611 @@ -587,6 +617,7 @@ resume-client = 15-resumption-resume-client
2612 [15-resumption-server]
2613 Certificate = ${ENV::TEST_CERTS_DIR}/servercert.pem
2614 CipherString = DEFAULT
2615 +MinProtocol = None
2616 Options = -SessionTicket
2617 PrivateKey = ${ENV::TEST_CERTS_DIR}/serverkey.pem
2618
2619 @@ -600,6 +631,7 @@ VerifyMode = Peer
2620 [15-resumption-resume-client]
2621 CipherString = DEFAULT
2622 MaxProtocol = DTLSv1.2
2623 +MinProtocol = None
2624 VerifyCAFile = ${ENV::TEST_CERTS_DIR}/rootcert.pem
2625 VerifyMode = Peer
2626
2627 diff --git a/test/ssl-tests/protocol_version.pm b/test/ssl-tests/protocol_version.pm
2628 index c7113629496f..09daf5b14ef9 100644
2629 --- a/test/ssl-tests/protocol_version.pm
2630 +++ b/test/ssl-tests/protocol_version.pm
2631 @@ -89,6 +89,7 @@ sub generate_version_tests {
2632 my @max_protocols = $dtls ? @max_dtls_protocols : @max_tls_protocols;
2633 my $min_enabled = $dtls ? $min_dtls_enabled : $min_tls_enabled;
2634 my $max_enabled = $dtls ? $max_dtls_enabled : $max_tls_enabled;
2635 + $min_protocols[0] = "None";
2636
2637 if (no_tests($dtls)) {
2638 return;
2639 @@ -162,13 +163,16 @@ sub generate_resumption_tests {
2640 # Client is flexible, server upgrades/downgrades.
2641 push @server_tests, {
2642 "name" => "resumption",
2643 - "client" => { },
2644 + "client" => {
2645 + "MinProtocol" => "None",
2646 + },
2647 "server" => {
2648 "MinProtocol" => $protocols[$original_protocol],
2649 "MaxProtocol" => $protocols[$original_protocol],
2650 "Options" => $ticket,
2651 },
2652 "resume_server" => {
2653 + "MinProtocol" => "None",
2654 "MaxProtocol" => $protocols[$resume_protocol],
2655 },
2656 "test" => {
2657 @@ -187,8 +191,10 @@ sub generate_resumption_tests {
2658 },
2659 "server" => {
2660 "Options" => $ticket,
2661 + "MinProtocol" => "None",
2662 },
2663 "resume_client" => {
2664 + "MinProtocol" => "None",
2665 "MaxProtocol" => $protocols[$resume_protocol],
2666 },
2667 "test" => {