summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorbeck <>2019-11-16 06:44:33 +0000
committerbeck <>2019-11-16 06:44:33 +0000
commitf117145dc734838631aa48f433feb3d75a02a184 (patch)
treecc00cad3dd1d3312a1ee097f4017a93682e43c6b
parent6ed1a438e76e4b38c933c65009239e991044c6b7 (diff)
downloadopenbsd-f117145dc734838631aa48f433feb3d75a02a184.tar.gz
openbsd-f117145dc734838631aa48f433feb3d75a02a184.tar.bz2
openbsd-f117145dc734838631aa48f433feb3d75a02a184.zip
Allow portable to override the default CA bundle location
ok kinichiro@ jsing@
-rw-r--r--src/lib/libtls/tls_config.c4
-rw-r--r--src/lib/libtls/tls_internal.h6
2 files changed, 7 insertions, 3 deletions
diff --git a/src/lib/libtls/tls_config.c b/src/lib/libtls/tls_config.c
index 6a717abd48..424fd73c93 100644
--- a/src/lib/libtls/tls_config.c
+++ b/src/lib/libtls/tls_config.c
@@ -1,4 +1,4 @@
1/* $OpenBSD: tls_config.c,v 1.56 2019/04/04 15:09:09 jsing Exp $ */ 1/* $OpenBSD: tls_config.c,v 1.57 2019/11/16 06:44:33 beck Exp $ */
2/* 2/*
3 * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> 3 * Copyright (c) 2014 Joel Sing <jsing@openbsd.org>
4 * 4 *
@@ -28,7 +28,7 @@
28 28
29#include "tls_internal.h" 29#include "tls_internal.h"
30 30
31static const char default_ca_file[] = "/etc/ssl/cert.pem"; 31static const char default_ca_file[] = TLS_DEFAULT_CA_FILE;
32 32
33const char * 33const char *
34tls_default_ca_cert_file(void) 34tls_default_ca_cert_file(void)
diff --git a/src/lib/libtls/tls_internal.h b/src/lib/libtls/tls_internal.h
index efccc9fdbe..3d806f8b6e 100644
--- a/src/lib/libtls/tls_internal.h
+++ b/src/lib/libtls/tls_internal.h
@@ -1,4 +1,4 @@
1/* $OpenBSD: tls_internal.h,v 1.75 2019/11/02 13:37:59 jsing Exp $ */ 1/* $OpenBSD: tls_internal.h,v 1.76 2019/11/16 06:44:33 beck Exp $ */
2/* 2/*
3 * Copyright (c) 2014 Jeremie Courreges-Anglas <jca@openbsd.org> 3 * Copyright (c) 2014 Jeremie Courreges-Anglas <jca@openbsd.org>
4 * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> 4 * Copyright (c) 2014 Joel Sing <jsing@openbsd.org>
@@ -28,6 +28,10 @@
28 28
29__BEGIN_HIDDEN_DECLS 29__BEGIN_HIDDEN_DECLS
30 30
31#ifndef TLS_DEFAULT_CA_FILE
32#define TLS_DEFAULT_CA_FILE "/etc/ssl/cert.pem"
33#endif
34
31#define TLS_CIPHERS_DEFAULT "TLSv1.2+AEAD+ECDHE:TLSv1.2+AEAD+DHE" 35#define TLS_CIPHERS_DEFAULT "TLSv1.2+AEAD+ECDHE:TLSv1.2+AEAD+DHE"
32#define TLS_CIPHERS_COMPAT "HIGH:!aNULL" 36#define TLS_CIPHERS_COMPAT "HIGH:!aNULL"
33#define TLS_CIPHERS_LEGACY "HIGH:MEDIUM:!aNULL" 37#define TLS_CIPHERS_LEGACY "HIGH:MEDIUM:!aNULL"