Welcome! Log In Create A New Profile

Advanced

[PATCH] SSL: don't enable SSLv3 by default

Piotr Sikora
October 30, 2014 12:18AM
# HG changeset patch
# User Piotr Sikora <piotr@cloudflare.com>
# Date 1414642398 25200
# Wed Oct 29 21:13:18 2014 -0700
# Node ID bf17486e5d30574b870926b76c1d6f421e4def75
# Parent 87ada3ba1392fadaf4d9193b5d345c248be32f77
SSL: don't enable SSLv3 by default.

Prodded by Jagannath Das.

Signed-off-by: Piotr Sikora <piotr@cloudflare.com>

diff -r 87ada3ba1392 -r bf17486e5d30 src/http/modules/ngx_http_proxy_module.c
--- a/src/http/modules/ngx_http_proxy_module.c Mon Oct 27 14:25:56 2014 -0700
+++ b/src/http/modules/ngx_http_proxy_module.c Wed Oct 29 21:13:18 2014 -0700
@@ -2815,9 +2815,8 @@ ngx_http_proxy_merge_loc_conf(ngx_conf_t
prev->upstream.ssl_session_reuse, 1);

ngx_conf_merge_bitmask_value(conf->ssl_protocols, prev->ssl_protocols,
- (NGX_CONF_BITMASK_SET|NGX_SSL_SSLv3
- |NGX_SSL_TLSv1|NGX_SSL_TLSv1_1
- |NGX_SSL_TLSv1_2));
+ (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1
+ |NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2));

ngx_conf_merge_str_value(conf->ssl_ciphers, prev->ssl_ciphers,
"DEFAULT");
diff -r 87ada3ba1392 -r bf17486e5d30 src/http/modules/ngx_http_ssl_module.c
--- a/src/http/modules/ngx_http_ssl_module.c Mon Oct 27 14:25:56 2014 -0700
+++ b/src/http/modules/ngx_http_ssl_module.c Wed Oct 29 21:13:18 2014 -0700
@@ -561,7 +561,7 @@ ngx_http_ssl_merge_srv_conf(ngx_conf_t *
prev->prefer_server_ciphers, 0);

ngx_conf_merge_bitmask_value(conf->protocols, prev->protocols,
- (NGX_CONF_BITMASK_SET|NGX_SSL_SSLv3|NGX_SSL_TLSv1
+ (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1
|NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2));

ngx_conf_merge_size_value(conf->buffer_size, prev->buffer_size,
diff -r 87ada3ba1392 -r bf17486e5d30 src/http/modules/ngx_http_uwsgi_module.c
--- a/src/http/modules/ngx_http_uwsgi_module.c Mon Oct 27 14:25:56 2014 -0700
+++ b/src/http/modules/ngx_http_uwsgi_module.c Wed Oct 29 21:13:18 2014 -0700
@@ -1598,9 +1598,8 @@ ngx_http_uwsgi_merge_loc_conf(ngx_conf_t
prev->upstream.ssl_session_reuse, 1);

ngx_conf_merge_bitmask_value(conf->ssl_protocols, prev->ssl_protocols,
- (NGX_CONF_BITMASK_SET|NGX_SSL_SSLv3
- |NGX_SSL_TLSv1|NGX_SSL_TLSv1_1
- |NGX_SSL_TLSv1_2));
+ (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1
+ |NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2));

ngx_conf_merge_str_value(conf->ssl_ciphers, prev->ssl_ciphers,
"DEFAULT");
diff -r 87ada3ba1392 -r bf17486e5d30 src/mail/ngx_mail_ssl_module.c
--- a/src/mail/ngx_mail_ssl_module.c Mon Oct 27 14:25:56 2014 -0700
+++ b/src/mail/ngx_mail_ssl_module.c Wed Oct 29 21:13:18 2014 -0700
@@ -235,7 +235,7 @@ ngx_mail_ssl_merge_conf(ngx_conf_t *cf,
prev->prefer_server_ciphers, 0);

ngx_conf_merge_bitmask_value(conf->protocols, prev->protocols,
- (NGX_CONF_BITMASK_SET|NGX_SSL_SSLv3|NGX_SSL_TLSv1
+ (NGX_CONF_BITMASK_SET|NGX_SSL_TLSv1
|NGX_SSL_TLSv1_1|NGX_SSL_TLSv1_2));

ngx_conf_merge_str_value(conf->certificate, prev->certificate, "");

_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH] SSL: don't enable SSLv3 by default

Piotr Sikora 977 October 30, 2014 12:18AM

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin 579 October 30, 2014 09:48AM

Re: [PATCH] SSL: don't enable SSLv3 by default Attachments

Richard Fussenegger 529 October 30, 2014 10:08AM

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin 647 October 30, 2014 11:28AM

Re: [PATCH] SSL: don't enable SSLv3 by default Attachments

Richard Fussenegger 586 October 30, 2014 11:32AM

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin 543 October 30, 2014 11:48AM

Re: [PATCH] SSL: don't enable SSLv3 by default Attachments

Richard Fussenegger 563 October 30, 2014 11:56AM

Re: [PATCH] SSL: don't enable SSLv3 by default

Piotr Sikora 751 October 30, 2014 07:34PM

Re: [PATCH] SSL: don't enable SSLv3 by default

Maxim Dounin 554 October 31, 2014 12:26AM

Re: [PATCH] SSL: don't enable SSLv3 by default

nginxorg 1016 October 31, 2014 09:36AM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 191
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready