openssl/test/ossl_shim/ossl_config.json

302 lines
21 KiB
JSON
Raw Normal View History

{
"DisabledTests" : {
"*TLS13*":"No TLS1.3 support yet",
"FragmentAlert-DTLS":"Test failure - reason unknown",
"FragmentedClientVersion":"Test failure - reason unknown",
"MTU":"Test failure - reason unknown",
"EmptyCertificateList":"Test failure - reason unknown",
"AppDataBeforeHandshake-DTLS":"Test failure - reason unknown",
"AlertAfterChangeCipherSpec":"Test failure - reason unknown",
"AppDataAfterChangeCipherSpec":"Test failure - reason unknown",
"AppDataAfterChangeCipherSpec-Empty":"Test failure - reason unknown",
"AppDataAfterChangeCipherSpec-DTLS":"Test failure - reason unknown",
"AppDataBeforeHandshake-DTLS-Empty":"Test failure - reason unknown",
"AlertAfterChangeCipherSpec-DTLS":"Test failure - reason unknown",
"FragmentMessageLengthMismatch-DTLS":"Test failure - reason unknown",
"SplitFragments-Header-DTLS":"Test failure - reason unknown",
"SplitFragments-Boundary-DTLS":"Test failure - reason unknown",
"SplitFragments-Body-DTLS":"Test failure - reason unknown",
"SendEmptyFragments-DTLS":"Test failure - reason unknown",
"SendInvalidRecordType-DTLS":"Test failure - reason unknown",
"SendInvalidRecordType":"Test failure - reason unknown",
"FragmentMessageTypeMismatch-DTLS":"Test failure - reason unknown",
"SendWarningAlerts-Pass":"Test failure - reason unknown",
"SendWarningAlerts-DTLS-Pass":"Test failure - reason unknown",
"TooManyKeyUpdates":"Test failure - reason unknown",
"Unclean-Shutdown-Alert":"Test failure - reason unknown",
"V2ClientHello-WarningAlertPrefix":"Test failure - reason unknown",
"BadHelloRequest-2":"Test failure - reason unknown",
"DTLS-SendExtraFinished":"Test failure - reason unknown",
"NoNullCompression-TLS12":"Test failure - reason unknown",
"KeyUpdate-Client":"Test failure - reason unknown",
"KeyUpdate-InvalidRequestMode":"Test failure - reason unknown",
"DTLS-SendExtraFinished-Reordered":"Test failure - reason unknown",
"LargeMessage-Reject-DTLS":"Test failure - reason unknown",
"KeyUpdate-Server":"Test failure - reason unknown",
"SSL3-ECDHE-PSK-AES128-CBC-SHA-server":"Test failure - reason unknown",
"SSL3-ECDHE-PSK-AES256-CBC-SHA-server":"Test failure - reason unknown",
"DTLS1-NULL-SHA-server":"Test failure - reason unknown",
"DTLS1-NULL-SHA-client":"Test failure - reason unknown",
"DTLS12-NULL-SHA-client":"Test failure - reason unknown",
"DTLS12-NULL-SHA-server":"Test failure - reason unknown",
"BadECDSA-1-4":"Test failure - reason unknown",
"BadECDSA-3-4":"Test failure - reason unknown",
"BadECDSA-4-1":"Test failure - reason unknown",
"BadECDSA-4-4":"Test failure - reason unknown",
"BadECDSA-4-3":"Test failure - reason unknown",
"SillyDH":"Test failure - reason unknown",
"VersionNegotiationExtension-TLS1-DTLS":"Test failure - reason unknown",
"NoSupportedVersions-DTLS":"Test failure - reason unknown",
"VersionTooLow-DTLS":"Test failure - reason unknown",
"IgnoreClientVersionOrder":"Test failure - reason unknown",
"VersionTooLow":"Test failure - reason unknown",
"MinimumVersion-Server-TLS1-SSL3":"Test failure - reason unknown",
"MinimumVersion-Server2-TLS1-SSL3":"Test failure - reason unknown",
"MinimumVersion-Client2-TLS1-SSL3":"Test failure - reason unknown",
"MinimumVersion-Server2-TLS11-SSL3":"Test failure - reason unknown",
"MinimumVersion-Server-TLS11-SSL3":"Test failure - reason unknown",
"MinimumVersion-Client2-TLS11-SSL3":"Test failure - reason unknown",
"MinimumVersion-Client2-TLS11-TLS1":"Test failure - reason unknown",
"MinimumVersion-Server2-TLS12-SSL3":"Test failure - reason unknown",
"MinimumVersion-Server-TLS12-SSL3":"Test failure - reason unknown",
"MinimumVersion-Client2-TLS12-TLS1":"Test failure - reason unknown",
"MinimumVersion-Client2-TLS12-SSL3":"Test failure - reason unknown",
"MinimumVersion-Client2-TLS12-TLS1-DTLS":"Test failure - reason unknown",
"MinimumVersion-Client2-TLS12-TLS11":"Test failure - reason unknown",
"DuplicateExtensionClient-TLS1":"Test failure - reason unknown",
"DuplicateExtensionServer-TLS1":"Test failure - reason unknown",
"ALPNClient-Mismatch-TLS1":"Test failure - reason unknown",
"UnsolicitedServerNameAck-TLS1":"Test failure - reason unknown",
"ALPNServer-Decline-TLS1":"Test failure - reason unknown",
"ALPNClient-EmptyProtocolName-TLS1":"Test failure - reason unknown",
"NegotiateALPNAndNPN-Swapped-TLS1":"Test failure - reason unknown",
"NegotiateALPNAndNPN-TLS1":"Test failure - reason unknown",
"TicketSessionIDLength-33-TLS1":"Test failure - reason unknown",
"DuplicateExtensionClient-TLS11":"Test failure - reason unknown",
"DuplicateExtensionServer-TLS11":"Test failure - reason unknown",
"UnsolicitedServerNameAck-TLS11":"Test failure - reason unknown",
"ALPNServer-Decline-TLS11":"Test failure - reason unknown",
"ALPNClient-Mismatch-TLS11":"Test failure - reason unknown",
"ALPNClient-EmptyProtocolName-TLS11":"Test failure - reason unknown",
"NegotiateALPNAndNPN-TLS11":"Test failure - reason unknown",
"NegotiateALPNAndNPN-Swapped-TLS11":"Test failure - reason unknown",
"TicketSessionIDLength-33-TLS11":"Test failure - reason unknown",
"DuplicateExtensionServer-TLS12":"Test failure - reason unknown",
"DuplicateExtensionClient-TLS12":"Test failure - reason unknown",
"UnsolicitedServerNameAck-TLS12":"Test failure - reason unknown",
"ALPNServer-Decline-TLS12":"Test failure - reason unknown",
"ALPNClient-Mismatch-TLS12":"Test failure - reason unknown",
"ALPNClient-EmptyProtocolName-TLS12":"Test failure - reason unknown",
"NegotiateALPNAndNPN-TLS12":"Test failure - reason unknown",
"NegotiateALPNAndNPN-Swapped-TLS12":"Test failure - reason unknown",
"TicketSessionIDLength-33-TLS12":"Test failure - reason unknown",
"ClientHelloPadding":"Test failure - reason unknown",
"Resume-Server-UnofferedCipher":"Test failure - reason unknown",
"Resume-Client-CipherMismatch":"Test failure - reason unknown",
"Resume-Server-ExtraIdentityNoBinder":"Test failure - reason unknown",
"Resume-Server-BinderWrongLength":"Test failure - reason unknown",
"Resume-Server-ExtraPSKBinder":"Test failure - reason unknown",
"Resume-Server-NoPSKBinder":"Test failure - reason unknown",
"Resume-Server-PSKBinderFirstExtension":"Test failure - reason unknown",
"Resume-Server-InvalidPSKBinder":"Test failure - reason unknown",
"ExtendedMasterSecret-NoToYes-Client":"Test failure - reason unknown",
"Renegotiate-Server-Forbidden":"Test failure - reason unknown",
"ExtendedMasterSecret-Renego-NoEMS":"Test failure - reason unknown",
"Renegotiate-Client-SwitchVersion":"Test failure - reason unknown",
"Renegotiate-Client-Upgrade":"Test failure - reason unknown",
"Renegotiate-SameClientVersion":"Test failure - reason unknown",
"Renegotiate-Client-Downgrade":"Test failure - reason unknown",
"Renegotiate-Client-SwitchCiphers2":"Test failure - reason unknown",
"Renegotiate-Client-SwitchCiphers":"Test failure - reason unknown",
"Renegotiate-Client-Forbidden-1":"Test failure - reason unknown",
"StrayHelloRequest":"Test failure - reason unknown",
"Renegotiate-Client-Freely-2":"Test failure - reason unknown",
"Renegotiate-Client-NoIgnore":"Test failure - reason unknown",
"StrayHelloRequest-Packed":"Test failure - reason unknown",
"Renegotiate-Client-Freely-1":"Test failure - reason unknown",
"Renegotiation-CertificateChange":"Test failure - reason unknown",
"Renegotiation-CertificateChange-2":"Test failure - reason unknown",
"Renegotiate-Client-SSL3":"Test failure - reason unknown",
"ClientAuth-SHA1-Fallback-ECDSA":"Test failure - reason unknown",
"ClientAuth-SHA1-Fallback-RSA":"Test failure - reason unknown",
"P224-Server":"Test failure - reason unknown",
"RSA-PSS-Large":"Test failure - reason unknown",
"DTLS-Retransmit-Client-1":"Test failure - reason unknown",
"DTLS-Retransmit-Client-2":"Test failure - reason unknown",
"DTLS-Retransmit-Server-1":"Test failure - reason unknown",
"DTLS-Retransmit-Server-2":"Test failure - reason unknown",
"DTLS-Retransmit-Client-3":"Test failure - reason unknown",
"DTLS-Retransmit-Server-3":"Test failure - reason unknown",
"DTLS-Retransmit-Client-4":"Test failure - reason unknown",
"Renegotiate-Client-Packed":"Test failure - reason unknown",
"DTLS-Retransmit-Server-4":"Test failure - reason unknown",
"DTLS-Retransmit-Client-5":"Test failure - reason unknown",
"DTLS-Retransmit-Server-6":"Test failure - reason unknown",
"DTLS-Retransmit-Client-6":"Test failure - reason unknown",
"DTLS-Retransmit-Server-5":"Test failure - reason unknown",
"DTLS-Retransmit-Client-7":"Test failure - reason unknown",
"DTLS-Retransmit-Server-7":"Test failure - reason unknown",
"DTLS-Retransmit-Client-8":"Test failure - reason unknown",
"DTLS-Retransmit-Client-9":"Test failure - reason unknown",
"DTLS-Retransmit-Server-8":"Test failure - reason unknown",
"DTLS-Retransmit-Server-9":"Test failure - reason unknown",
"DTLS-Retransmit-Client-10":"Test failure - reason unknown",
"DTLS-Retransmit-Client-11":"Test failure - reason unknown",
"DTLS-Retransmit-Server-10":"Test failure - reason unknown",
"DTLS-Retransmit-Server-11":"Test failure - reason unknown",
"CustomExtensions-ParseError-Server":"Test failure - reason unknown",
"CustomExtensions-FailAdd-Server":"Test failure - reason unknown",
"CustomExtensions-FailAdd-Client":"Test failure - reason unknown",
"CustomExtensions-ParseError-Client":"Test failure - reason unknown",
"UnknownExtension-Client":"Test failure - reason unknown",
"UnofferedExtension-Client":"Test failure - reason unknown",
"PointFormat-Client-MissingUncompressed":"Test failure - reason unknown",
"PointFormat-Server-MissingUncompressed":"Test failure - reason unknown",
"Basic-Client-RenewTicket-Sync":"Test failure - reason unknown",
"Renegotiate-Client-Sync":"Test failure - reason unknown",
"Shutdown-Shim-Sync":"Test failure - reason unknown",
"Basic-Client-RenewTicket-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"Renegotiate-Client-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"Shutdown-Shim-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Client-RenewTicket-Sync-PackHandshakeFlight":"Test failure - reason unknown",
"Renegotiate-Client-Sync-PackHandshakeFlight":"Test failure - reason unknown",
"Shutdown-Shim-Sync-PackHandshakeFlight":"Test failure - reason unknown",
"Basic-Client-RenewTicket-DTLS-Sync":"Test failure - reason unknown",
"Basic-Client-RenewTicket-DTLS-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Server-Implicit-DTLS-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"ClientAuth-NoCertificate-Server-DTLS-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"ClientAuth-ECDSA-Client-DTLS-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Server-RSA-DTLS-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Server-ECDHE-RSA-DTLS-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Server-ECDHE-ECDSA-DTLS-Sync-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Client-RenewTicket-Async":"Test failure - reason unknown",
"Shutdown-Shim-Async":"Test failure - reason unknown",
"Basic-Client-RenewTicket-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"Shutdown-Shim-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Client-RenewTicket-Async-PackHandshakeFlight":"Test failure - reason unknown",
"Shutdown-Shim-Async-PackHandshakeFlight":"Test failure - reason unknown",
"Basic-Client-RenewTicket-DTLS-Async":"Test failure - reason unknown",
"Basic-Client-RenewTicket-DTLS-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Server-Implicit-DTLS-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"ClientAuth-NoCertificate-Server-DTLS-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"ClientAuth-ECDSA-Client-DTLS-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Server-RSA-DTLS-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Server-ECDHE-RSA-DTLS-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"Basic-Server-ECDHE-ECDSA-DTLS-Async-SplitHandshakeRecords":"Test failure - reason unknown",
"SendUnencryptedFinished-DTLS":"Test failure - reason unknown",
"PartialEncryptedExtensionsWithServerHello":"Test failure - reason unknown",
"StrayChangeCipherSpec":"Test failure - reason unknown",
"PartialClientFinishedWithClientHello":"Test failure - reason unknown",
"TrailingMessageData-ClientHello":"Test failure - reason unknown",
"TrailingMessageData-ServerHello":"Test failure - reason unknown",
"TrailingMessageData-ServerCertificate":"Test failure - reason unknown",
"TrailingMessageData-ServerKeyExchange":"Test failure - reason unknown",
"TrailingMessageData-CertificateRequest":"Test failure - reason unknown",
"TrailingMessageData-ServerHelloDone":"Test failure - reason unknown",
"TrailingMessageData-ClientKeyExchange":"Test failure - reason unknown",
"TrailingMessageData-ClientCertificate":"Test failure - reason unknown",
"TrailingMessageData-CertificateVerify":"Test failure - reason unknown",
"TrailingMessageData-NextProtocol":"Test failure - reason unknown",
"TrailingMessageData-NewSessionTicket":"Test failure - reason unknown",
"TrailingMessageData-ClientFinished":"Test failure - reason unknown",
"TrailingMessageData-ServerFinished":"Test failure - reason unknown",
"TrailingMessageData-HelloVerifyRequest-DTLS":"Test failure - reason unknown",
"TrailingMessageData-ServerHello-DTLS":"Test failure - reason unknown",
"TrailingMessageData-ServerCertificate-DTLS":"Test failure - reason unknown",
"TrailingMessageData-ServerKeyExchange-DTLS":"Test failure - reason unknown",
"TrailingMessageData-CertificateRequest-DTLS":"Test failure - reason unknown",
"TrailingMessageData-ServerHelloDone-DTLS":"Test failure - reason unknown",
"TrailingMessageData-ClientCertificate-DTLS":"Test failure - reason unknown",
"TrailingMessageData-CertificateVerify-DTLS":"Test failure - reason unknown",
"TrailingMessageData-ClientKeyExchange-DTLS":"Test failure - reason unknown",
"TrailingMessageData-ClientFinished-DTLS":"Test failure - reason unknown",
"TrailingMessageData-NewSessionTicket-DTLS":"Test failure - reason unknown",
"TrailingMessageData-ServerFinished-DTLS":"Test failure - reason unknown",
"MissingKeyShare-Client":"Test failure - reason unknown",
"MissingKeyShare-Server":"Test failure - reason unknown",
"DuplicateKeyShares":"Test failure - reason unknown",
"SkipEarlyData":"Test failure - reason unknown",
"SkipEarlyData-OmitEarlyDataExtension":"Test failure - reason unknown",
"SkipEarlyData-TooMuchData":"Test failure - reason unknown",
"SkipEarlyData-Interleaved":"Test failure - reason unknown",
"SkipEarlyData-HRR":"Test failure - reason unknown",
"SkipEarlyData-HRR-Interleaved":"Test failure - reason unknown",
"SkipEarlyData-HRR-TooMuchData":"Test failure - reason unknown",
"SkipEarlyData-HRR-FatalAlert":"Test failure - reason unknown",
"SkipEarlyData-EarlyDataInTLS12":"Test failure - reason unknown",
"SkipEarlyData-SecondClientHelloEarlyData":"Test failure - reason unknown",
"EmptyEncryptedExtensions":"Test failure - reason unknown",
"EncryptedExtensionsWithKeyShare":"Test failure - reason unknown",
"UnknownCurve-HelloRetryRequest":"Test failure - reason unknown",
"UnnecessaryHelloRetryRequest":"Test failure - reason unknown",
"HelloRetryRequest-Empty":"Test failure - reason unknown",
"SecondHelloRetryRequest":"Test failure - reason unknown",
"HelloRetryRequest-DuplicateCurve":"Test failure - reason unknown",
"HelloRetryRequest-DuplicateCookie":"Test failure - reason unknown",
"HelloRetryRequest-EmptyCookie":"Test failure - reason unknown",
"HelloRetryRequest-Unknown":"Test failure - reason unknown",
"SecondClientHelloMissingKeyShare":"Test failure - reason unknown",
"SecondClientHelloWrongCurve":"Test failure - reason unknown",
"HelloRetryRequestVersionMismatch":"Test failure - reason unknown",
"HelloRetryRequestCurveMismatch":"Test failure - reason unknown",
"SkipHelloRetryRequest":"Test failure - reason unknown",
"Peek-Renegotiate":"Test failure - reason unknown",
"Peek-KeyUpdate":"Test failure - reason unknown",
"DTLS-Retransmit-Client-12":"Test failure - reason unknown",
"DTLS-Retransmit-Timeout":"Test failure - reason unknown",
"DTLS-Retransmit-Server-12":"Test failure - reason unknown",
"DTLS-Retransmit-Fudge":"Test failure - reason unknown",
"DTLS-Retransmit-Fragmented":"Test failure - reason unknown",
Fix BoringSSL external test failures We recently turned on the TLSv1.3 downgrade sentinels by default. Unfortunately we are using a very old version of the BoringSSL test runner which uses an old draft implementation of TLSv1.3 that also uses the downgrade sentinels by default. The two implementations do not play well together and were causing spurious test failures. Until such time as we update the BoringSSL test runner we disable the failing tests: SendFallbackSCSV In this test the client is OpenSSL and the server is the boring test runner. The client and server fail to negotiate TLSv1.3 because the test runner is using an old draft TLSv1.3 version. The server does however add the TLSv1.3->TLSv1.2 downgrade sentinel in the ServerHello random. Since we recently turned on checking of the downgrade sentinels on the client side this causes the connection to fail. VersionNegotiationExtension-TLS11 In this test the test runner is the client and OpenSSL is the server. The test modifies the supported_versions extension sent by the client to only include TLSv1.1 (and some other spurious versions), even though the client does actually support TLSv1.2. The server successfully selects TLSv1.1, but adds the TLSv1.3->TLSv1.1 downgrade sentinel. This behaviour was recently switched on by default. The test runner then checks the downgrade sentinel and aborts the connection because it knows that it really supports TLSv1.2. VersionNegotiationExtension-TLS1 VersionNegotiationExtension-SSL3 The same as VersionNegotiationExtension-TLS11 but for TLSv1 and SSLv3. ConflictingVersionNegotiation In this test the client is the test runner, and OpenSSL is the server. The client offers TLSv1.2 in ClientHello.version, but also adds a supported_versions extension that only offers TLSv1.1. The supported_versions extension takes precedence and the server (correctly) selects TLSv1.1. However it also adds the TLSv1.3->TLSv1.1 downgrade sentinel. On the client side it knows it actually offered TLSv1.2 and so the downgrade sentinel check fails. [extended tests] Reviewed-by: Viktor Dukhovni <viktor@openssl.org> (Merged from https://github.com/openssl/openssl/pull/7013)
2018-08-22 13:10:48 +00:00
"TrailingMessageData-ClientHello-DTLS":"Test failure - reason unknown",
"SendFallbackSCSV":"Current runner version uses old draft TLSv1.3",
"VersionNegotiationExtension-TLS11":"Current runner version uses old draft TLSv1.3",
"VersionNegotiationExtension-TLS1":"Current runner version uses old draft TLSv1.3",
"VersionNegotiationExtension-SSL3":"Current runner version uses old draft TLSv1.3",
"ConflictingVersionNegotiation":"Current runner version uses old draft TLSv1.3"
},
"ErrorMap" : {
":UNEXPECTED_MESSAGE:":"unexpected message",
":INAPPROPRIATE_FALLBACK:":"inappropriate fallback",
":UNEXPECTED_RECORD:":"unexpected message",
":TLSV1_ALERT_RECORD_OVERFLOW:":"tlsv1 alert record overflow",
":WRONG_SSL_VERSION:":"no protocols available",
":BAD_ALERT:":"invalid alert",
":HTTP_REQUEST:":"http request",
":HTTPS_PROXY_REQUEST:":"https proxy request",
":WRONG_CERTIFICATE_TYPE:":"wrong certificate type",
":WRONG_VERSION_NUMBER:":"wrong version number",
":DECRYPTION_FAILED_OR_BAD_RECORD_MAC:":"decryption failed or bad record mac",
":DIGEST_CHECK_FAILED:":"digest check failed",
":TOO_MANY_EMPTY_FRAGMENTS:":"record too small",
":TOO_MANY_WARNING_ALERTS:":"too many warn alerts",
":DATA_LENGTH_TOO_LONG:":"data length too long",
":EXCESSIVE_MESSAGE_SIZE:":"excessive message size",
":ENCRYPTED_LENGTH_TOO_LONG:":"packet length too long",
":INVALID_COMPRESSION_LIST:":"no compression specified",
":NO_SHARED_CIPHER:":"no shared cipher",
":WRONG_CIPHER_RETURNED:":"wrong cipher returned",
":HANDSHAKE_FAILURE_ON_CLIENT_HELLO:":"sslv3 alert handshake failure",
":UNKNOWN_CIPHER_RETURNED:":"unknown cipher returned",
":BAD_SIGNATURE:":"bad signature",
":BAD_DH_P_LENGTH:":"dh key too small",
":PEER_DID_NOT_RETURN_A_CERTIFICATE:":"peer did not return a certificate",
":UNSUPPORTED_PROTOCOL:":"unsupported protocol",
":PARSE_TLSEXT:":"bad extension",
":BAD_SRTP_PROTECTION_PROFILE_LIST:":"bad srtp protection profile list",
":OLD_SESSION_VERSION_NOT_RETURNED:":"ssl session version mismatch",
":RESUMED_EMS_SESSION_WITHOUT_EMS_EXTENSION:":"inconsistent extms",
":RENEGOTIATION_EMS_MISMATCH:":"inconsistent extms",
":RENEGOTIATION_MISMATCH:":"renegotiation mismatch",
":WRONG_SIGNATURE_TYPE:":"wrong signature type",
":BAD_ECC_CERT:":"wrong curve",
":WRONG_CURVE:":"wrong curve",
":INVALID_ENCODING:":"invalid encoding",
":CERTIFICATE_VERIFY_FAILED:":"certificate verify failed",
":BAD_CHANGE_CIPHER_SPEC:":"bad change cipher spec",
":ECC_CERT_NOT_FOR_SIGNING:":"ecc cert not for signing",
":OLD_SESSION_CIPHER_NOT_RETURNED:":"old session cipher not returned",
":RESUMED_NON_EMS_SESSION_WITH_EMS_EXTENSION:":"inconsistent extms"
}
}