ECDSA cipher suites use elliptical curve cryptography (ECC). Because of its smaller size, it is helpful in environments where processing power, storage space, bandwidth, and power consumption are constrained.
When the ECDHE_ECDSA cipher group is used, the server's certificate must contain an ECDSA-capable public key.
The following table lists the ECDSA ciphers that are supported on the NetScaler MPX and SDX appliances with N3 chips, NetScaler VPX appliances, MPX 5900/26000, and MPX/SDX 8900/15000 appliances.
| Cipher Name |
Priority |
Description |
Key Exchange Algorithm |
Authentication Algorithm |
Encryption Algorithm (Key Size) |
Message Authentication Code (MAC) Algorithm |
HexCode |
| TLS1-ECDHE-ECDSA-AES128-SHA |
1 |
SSLv3 |
ECC-DHE |
ECDSA |
AES(128) |
SHA1 |
0xc009 |
| TLS1-ECDHE-ECDSA-AES256-SHA |
2 |
SSLv3 |
ECC-DHE |
ECDSA |
AES(256) |
SHA1 |
0xc00a |
| TLS1.2-ECDHE-ECDSA-AES128-SHA256 |
3 |
TLSv1.2 |
ECC-DHE |
ECDSA |
AES(128) |
SHA-256 |
0xc023 |
| TLS1.2-ECDHE-ECDSA-AES256-SHA384 |
4 |
TLSv1.2 |
ECC-DHE |
ECDSA |
AES(256) |
SHA-384 |
0xc024 |
| TLS1.2-ECDHE-ECDSA-AES128-GCM-SHA256 |
5 |
TLSv1.2 |
ECC-DHE |
ECDSA |
AES-GCM(128) |
SHA-256 |
0xc02b |
| TLS1.2-ECDHE-ECDSA-AES256-GCM-SHA384 |
6 |
TLSv1.2 |
ECC-DHE |
ECDSA |
AES-GCM(256) |
SHA-384 |
0xc02c |
| TLS1-ECDHE-ECDSA-RC4-SHA |
7 |
SSLv3 |
ECC-DHE |
ECDSA |
RC4(128) |
SHA1 |
0xc007 |
| TLS1-ECDHE-ECDSA-DES-CBC3-SHA |
8 |
SSLv3 |
ECC-DHE |
ECDSA |
3DES(168) |
SHA1 |
0xc008 |
| TLS1.2-ECDHE-ECDSA-CHACHA20-POLY1305 |
9 |
TLSv1.2 |
ECC-DHE |
ECDSA |
CHACHA20/POLY1305(256) |
AEAD |
0xcca9 |