]> git.ipfire.org Git - thirdparty/tor.git/commit
Implement the client side of proposal 198
authorNick Mathewson <nickm@torproject.org>
Tue, 15 May 2012 19:32:18 +0000 (15:32 -0400)
committerNick Mathewson <nickm@torproject.org>
Wed, 13 Jun 2012 16:06:28 +0000 (12:06 -0400)
commitdf6bd478eeb8164b99156bf9528e1b058fe491fd
treeb43d0fd5a2e2a2d8cf0fd1d704cc99621c559c02
parent89c16890095d63cc6f56a378108efc3d3f063204
Implement the client side of proposal 198

This is a feature removal: we no longer fake any ciphersuite other
than the not-really-standard SSL_RSA_FIPS_WITH_3DES_EDE_CBC_SHA
(0xfeff).  This change will let servers rely on our actually
supporting what we claim to support, and thereby let Tor migrate to
better TLS ciphersuites.

As a drawback, Tor instances that use old openssl versions and
openssl builds with ciphers disabled will no longer give the
"firefox" cipher list.
changes/prop198 [new file with mode: 0644]
src/common/tortls.c