]> git.ipfire.org Git - thirdparty/asterisk.git/commit
AST-2016-001 http: Provide greater control of TLS and set modern defaults. 84/2184/2
authorJoshua Colp <jcolp@digium.com>
Wed, 3 Feb 2016 18:05:20 +0000 (14:05 -0400)
committerKevin Harwell <kharwell@digium.com>
Wed, 3 Feb 2016 21:09:15 +0000 (15:09 -0600)
commit1e7854dfa24dfd47e1810941a4860ea8a6b7dcad
treefc36c119275674732ef4081282c1d57e688b90ea
parentf3a578ce98f33b7302fca71066e96ab581aa5167
AST-2016-001 http: Provide greater control of TLS and set modern defaults.

This change exposes the configuration of various aspects of the TLS
support and sets the default to the modern standards.

The TLS cipher is now set to the best values according to the
Mozilla OpSec team, different TLS versions can now be disabled, and
the cipher order can be forced to be that of the server instead of
the client.

ASTERISK-24972 #close

Change-Id: I0a10f2883f7559af5e48dee0901251dbf30d45b8
configs/samples/http.conf.sample
include/asterisk/tcptls.h
main/http.c
main/tcptls.c