]> git.ipfire.org Git - thirdparty/unbound.git/commitdiff
- Fix #2362: TLS1.3/openssl-1.1.1 not working.
authorWouter Wijngaards <wouter@nlnetlabs.nl>
Fri, 3 Nov 2017 07:40:36 +0000 (07:40 +0000)
committerWouter Wijngaards <wouter@nlnetlabs.nl>
Fri, 3 Nov 2017 07:40:36 +0000 (07:40 +0000)
git-svn-id: file:///svn/unbound/trunk@4396 be551aaa-1e26-0410-a405-d3ace91eadb9

doc/Changelog
util/net_help.c

index 14f535804724442c5f8c5ddafb8a944e2e052397..5e9b0a8cb98e099a30d1af13499100c11d69dd4a 100644 (file)
@@ -1,3 +1,6 @@
+3 November 2017: Wouter 
+       - Fix #2362: TLS1.3/openssl-1.1.1 not working.
+
 2 November 2017: Wouter 
        - Fix #1913: ub_ctx_config is under circumstances thread-safe.
        - make ip-transparent option work on OpenBSD.
index ce136a337cff1a15fd90d8a91c56d6ad985548fe..d99a2f974bc23b94fd51a07fd5399e8063bc8758 100644 (file)
@@ -645,7 +645,7 @@ listen_sslctx_setup(void* ctxt)
 #endif
 #if defined(SHA256_DIGEST_LENGTH) && defined(USE_ECDSA)
        /* if we have sha256, set the cipher list to have no known vulns */
-       if(!SSL_CTX_set_cipher_list(ctx, "ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256"))
+       if(!SSL_CTX_set_cipher_list(ctx, "TLS13-CHACHA20-POLY1305-SHA256:TLS13-AES-256-GCM-SHA384:TLS13-AES-128-GCM-SHA256:ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256"))
                log_crypto_err("could not set cipher list with SSL_CTX_set_cipher_list");
 #endif