# Next generation GOST algorithms mac = AEAD HMAC-STREEBOG-256 HMAC-STREEBOG-512 MAGMA-OMAC KUZNYECHIK-OMAC MAGMA-OMAC-ACPKM KUZNYECHIK-OMAC-ACPKM GOST28147-TC26Z-IMIT GOST28147-CPA-IMIT group = GOST-GC256A GOST-GC256B GOST-GC256C GOST-GC256D GOST-GC512A GOST-GC512B GOST-GC512C hash = GOSTR94 STREEBOG-256 STREEBOG-512 sign = GOSTR341001 GOSTR341012-256 GOSTR341012-512 cipher@TLS = GOST28147-TC26Z-CNT GOST28147-CPA-CFB MAGMA-CTR-ACPKM KUZNYECHIK-CTR-ACPKM cipher@!TLS = GOST28147-TC26Z-CNT MAGMA-CTR-ACPKM KUZNYECHIK-CTR-ACPKM GOST28147-CPA-CFB GOST28147-CPB-CFB GOST28147-CPC-CFB GOST28147-CPD-CFB GOST28147-TC26Z-CFB key_exchange = VKO-GOST-2001 VKO-GOST-2012 VKO-GOST-KDF protocol@TLS = TLS1.3 TLS1.2 TLS1.1 TLS1.0 # Parameter sizes # GOST ciphersuites don't use DH params. The value is set to fit SECLEVEL=2 for OpenSSL min_dh_size = 2048 min_dsa_size = 2048 min_rsa_size = 2048 # GnuTLS only for now sha1_in_certs = 0