]> git.ipfire.org Git - thirdparty/freeswitch.git/commitdiff
clarify tls ciphers and update num to allow for ipv6 and tls options
authorBrian West <brian@freeswitch.org>
Wed, 10 Sep 2014 19:49:56 +0000 (14:49 -0500)
committerBrian West <brian@freeswitch.org>
Wed, 10 Sep 2014 19:49:59 +0000 (14:49 -0500)
conf/vanilla/autoload_configs/enum.conf.xml
conf/vanilla/vars.xml

index b9813efa273011e8f70af931ae3f6f561fd5e1d6..a8f6f52f851227e1b51a624bda669cea51d190f5 100644 (file)
@@ -14,8 +14,8 @@
   </settings>
 
   <routes>
-    <route service="E2U+SIP" regex="sip:(.*)" replace="sofia/${use_profile}/$1;transport=udp"/>
-    <route service="E2T+SIP" regex="sip:(.*)" replace="sofia/${use_profile}/$1;transport=tcp"/>
-    <!--<route service="E2U+XMPP" regex="XMPP:(.*)" replace="dingaling/$${xmpp_server_profile}/$1"/>-->
+    <route service="E2U+SIP" regex="sip:(.*)" replace="sofia/${use_profile}-ipv6/$1;transport=udp|sofia/${use_profile}/$1;transport=udp"/>
+    <route service="E2T+SIP" regex="sip:(.*)" replace="sofia/${use_profile}-ipv6/$1;transport=tcp|sofia/${use_profile}/$1;transport=tcp"/>
+    <route service="E2T+SIPS" regex="sip:(.*)" replace="sofia/${use_profile}-ipv6/$1;transport=tls|sofia/${use_profile}/$1;transport=tls"/>
   </routes>
 </configuration>
index 28a6dc96fb579bf449ae176974394738a9d493eb..ff40fc7cfc976bbf569e023a5ffae98eead19612 100644 (file)
@@ -61,7 +61,7 @@
   <X-PRE-PROCESS cmd="set" data="domain=$${local_ip_v4}"/>
   <X-PRE-PROCESS cmd="set" data="domain_name=$${domain}"/>
   <X-PRE-PROCESS cmd="set" data="hold_music=local_stream://moh"/>
-  <X-PRE-PROCESS cmd="set" data="use_profile=internal"/>
+  <X-PRE-PROCESS cmd="set" data="use_profile=external"/>
   <X-PRE-PROCESS cmd="set" data="rtp_sdes_suites=AEAD_AES_256_GCM_8|AEAD_AES_128_GCM_8|AES_CM_256_HMAC_SHA1_80|AES_CM_192_HMAC_SHA1_80|AES_CM_128_HMAC_SHA1_80|AES_CM_256_HMAC_SHA1_32|AES_CM_192_HMAC_SHA1_32|AES_CM_128_HMAC_SHA1_32|AES_CM_128_NULL_AUTH"/>
   <!--
       Enable ZRTP globally you can override this on a per channel basis
 
   <!--
      TLS cipher suite: default ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH
+
+     The actual ciphers supported will change per platform.
+
+     openssl ciphers -v 'ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH'
+
+     Will show you what is available in your verion of openssl.
+     Freeswitch does not support non-Elliptic Curve Diffie Hellman key 
+     exchange.  
   -->
   <X-PRE-PROCESS cmd="set" data="sip_tls_ciphers=ALL:!ADH:!LOW:!EXP:!MD5:@STRENGTH"/>