ssl: Update SSL_CIPHER_get_min_version to reflect SSL 3.0 removal

We have stopped supporting SSLv3 since 2018 and it is untenable for us
to report ciphers as supported in SSLv3 as the minimum protocol version
anymore. Therefore, we now bump their minimum version to TLS1_VERSION.

SSLv3 stays as a cipher alias.

Update-Note: SSL_CIPHER_get_min_version now returns TLS1_VERSION in any
case where it would previously report SSL3_VERSION.

Signed-off-by: Xiangfei Ding <xfding@google.com>
Change-Id: I33eb8a77980cba1983911914ef96652e6a6a6964
Reviewed-on: https://boringssl-review.googlesource.com/c/boringssl/+/103367
Reviewed-by: David Benjamin <davidben@google.com>
diff --git a/include/openssl/ssl.h b/include/openssl/ssl.h
index ca1c2d5..cc330a0 100644
--- a/include/openssl/ssl.h
+++ b/include/openssl/ssl.h
@@ -1761,7 +1761,7 @@
 // - `FIPS` is an alias for `HIGH`.
 //
 // - `SSLv3` and `TLSv1` match ciphers available in TLS 1.1 or earlier.
-//   `TLSv1_2` matches ciphers new in TLS 1.2. This is confusing and should not
+//   `TLSv1.2` matches ciphers new in TLS 1.2. This is confusing and should not
 //   be used.
 //
 // Unknown rules are silently ignored by legacy APIs, and rejected by APIs with
diff --git a/rust/bssl-tls/src/context.rs b/rust/bssl-tls/src/context.rs
index 7858e68..5797286 100644
--- a/rust/bssl-tls/src/context.rs
+++ b/rust/bssl-tls/src/context.rs
@@ -400,7 +400,7 @@
     /// - `FIPS` is an alias for `HIGH`.
     ///
     /// - `SSLv3` and `TLSv1` match ciphers available in TLS 1.1 or earlier.
-    ///   `TLSv1_2` matches ciphers new in TLS 1.2. This is confusing and should not
+    ///   `TLSv1.2` matches ciphers new in TLS 1.2. This is confusing and should not
     ///   be used.
     ///
     /// [cipher suite configuration]: <https://docs.openssl.org/3.0/man1/openssl-ciphers/#cipher-list-format>
diff --git a/ssl/ssl_cipher.cc b/ssl/ssl_cipher.cc
index be2e725..60142fc 100644
--- a/ssl/ssl_cipher.cc
+++ b/ssl/ssl_cipher.cc
@@ -30,7 +30,6 @@
 #include <openssl/sha.h>
 #include <openssl/stack.h>
 
-#include "../crypto/internal.h"
 #include "internal.h"
 
 
@@ -450,8 +449,8 @@
 
     // Legacy protocol minimum version aliases. "TLSv1" is intentionally the
     // same as "SSLv3".
-    {"SSLv3", ~0u, ~0u, ~0u, ~0u, SSL3_VERSION},
-    {"TLSv1", ~0u, ~0u, ~0u, ~0u, SSL3_VERSION},
+    {"SSLv3", ~0u, ~0u, ~0u, ~0u, TLS1_VERSION},
+    {"TLSv1", ~0u, ~0u, ~0u, ~0u, TLS1_VERSION},
     {"TLSv1.2", ~0u, ~0u, ~0u, ~0u, TLS1_2_VERSION},
 
     // Legacy strength classes.
@@ -1518,7 +1517,7 @@
     // afterwards specify a particular hash.
     return TLS1_2_VERSION;
   }
-  return SSL3_VERSION;
+  return TLS1_VERSION;
 }
 
 uint16_t SSL_CIPHER_get_max_version(const SSL_CIPHER *cipher) {