]> git.ipfire.org Git - thirdparty/openvpn.git/commit
Add options to restrict cipher negotiation
authorSteffan Karger <steffan@karger.me>
Tue, 28 Jun 2016 21:35:00 +0000 (23:35 +0200)
committerGert Doering <gert@greenie.muc.de>
Mon, 11 Jul 2016 19:45:52 +0000 (21:45 +0200)
commitd728ebeda8c94fe401dc41b9fbda682ea0d780c9
tree20853e216041547647ac9994005642e9b7168709
parent49817bf0ad599b8f9e8d52be9c0bb007aece0d48
Add options to restrict cipher negotiation

Add --ncp-disable to completely disable cipher negotiation, and
--ncp-ciphers to specify which ciphers to accept from the server.

v2:
 * fix --disable-crypto builds
 * use register_signal() instead of operating directly on c->sig
 * add man-page entry for new options

v3:
 * rebased on client-side NCP v3

v4:
 * rebased on client-side NCP v4

Signed-off-by: Steffan Karger <steffan@karger.me>
Acked-by: Arne Schwabe <arne@rfc2549.org>
Acked-by: Gert Doering <gert@greenie.muc.de>
Message-Id: <1467149700-10042-1-git-send-email-steffan@karger.me>
URL: http://article.gmane.org/gmane.network.openvpn.devel/12008
Signed-off-by: Gert Doering <gert@greenie.muc.de>
doc/openvpn.8
src/openvpn/init.c
src/openvpn/init.h
src/openvpn/openvpn.h
src/openvpn/options.c
src/openvpn/options.h
src/openvpn/push.c
src/openvpn/ssl.c
src/openvpn/ssl_common.h