summaryrefslogtreecommitdiff
path: root/src/lib
diff options
context:
space:
mode:
authortedu <>2014-10-14 22:05:28 +0000
committertedu <>2014-10-14 22:05:28 +0000
commitdcf0c85a37d1b2da6424029201cb837c14348dc0 (patch)
tree1eb19615831e225a44f5be2650bb6bce8319e6b8 /src/lib
parentb1d01e6f356d5697eb970fe901d012de69084c84 (diff)
downloadopenbsd-dcf0c85a37d1b2da6424029201cb837c14348dc0.tar.gz
openbsd-dcf0c85a37d1b2da6424029201cb837c14348dc0.tar.bz2
openbsd-dcf0c85a37d1b2da6424029201cb837c14348dc0.zip
seems like a good time to make the ressl default TLSv1 only.
ok guenther
Diffstat (limited to 'src/lib')
-rw-r--r--src/lib/libressl/ressl.h5
-rw-r--r--src/lib/libressl/ressl_init.36
2 files changed, 5 insertions, 6 deletions
diff --git a/src/lib/libressl/ressl.h b/src/lib/libressl/ressl.h
index 0795a33162..8fa2788077 100644
--- a/src/lib/libressl/ressl.h
+++ b/src/lib/libressl/ressl.h
@@ -1,4 +1,4 @@
1/* $OpenBSD: ressl.h,v 1.19 2014/10/09 22:04:33 tedu Exp $ */ 1/* $OpenBSD: ressl.h,v 1.20 2014/10/14 22:05:28 tedu Exp $ */
2/* 2/*
3 * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> 3 * Copyright (c) 2014 Joel Sing <jsing@openbsd.org>
4 * 4 *
@@ -26,8 +26,7 @@
26#define RESSL_PROTOCOL_TLSv1_2 (1 << 3) 26#define RESSL_PROTOCOL_TLSv1_2 (1 << 3)
27#define RESSL_PROTOCOL_TLSv1 \ 27#define RESSL_PROTOCOL_TLSv1 \
28 (RESSL_PROTOCOL_TLSv1_0|RESSL_PROTOCOL_TLSv1_1|RESSL_PROTOCOL_TLSv1_2) 28 (RESSL_PROTOCOL_TLSv1_0|RESSL_PROTOCOL_TLSv1_1|RESSL_PROTOCOL_TLSv1_2)
29#define RESSL_PROTOCOLS_DEFAULT \ 29#define RESSL_PROTOCOLS_DEFAULT RESSL_PROTOCOL_TLSv1
30 (RESSL_PROTOCOL_SSLv3|RESSL_PROTOCOL_TLSv1)
31 30
32#define RESSL_READ_AGAIN -2 31#define RESSL_READ_AGAIN -2
33#define RESSL_WRITE_AGAIN -3 32#define RESSL_WRITE_AGAIN -3
diff --git a/src/lib/libressl/ressl_init.3 b/src/lib/libressl/ressl_init.3
index 8f47a667eb..b881d171e4 100644
--- a/src/lib/libressl/ressl_init.3
+++ b/src/lib/libressl/ressl_init.3
@@ -1,4 +1,4 @@
1.\" $OpenBSD: ressl_init.3,v 1.5 2014/10/08 19:17:55 tedu Exp $ 1.\" $OpenBSD: ressl_init.3,v 1.6 2014/10/14 22:05:28 tedu Exp $
2.\" 2.\"
3.\" Copyright (c) 2014 Ted Unangst <tedu@openbsd.org> 3.\" Copyright (c) 2014 Ted Unangst <tedu@openbsd.org>
4.\" 4.\"
@@ -14,7 +14,7 @@
14.\" ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF 14.\" ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF
15.\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. 15.\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE.
16.\" 16.\"
17.Dd $Mdocdate: October 8 2014 $ 17.Dd $Mdocdate: October 14 2014 $
18.Dt RESSL 3 18.Dt RESSL 3
19.Os 19.Os
20.Sh NAME 20.Sh NAME
@@ -227,7 +227,7 @@ Additionally, the values
227.Dv RESSL_PROTOCOL_TLSv1 227.Dv RESSL_PROTOCOL_TLSv1
228(all TLS versions) and 228(all TLS versions) and
229.Dv RESSL_PROTOCOLS_DEFAULT 229.Dv RESSL_PROTOCOLS_DEFAULT
230(all versions) may be used. 230(currently all TLS versions) may be used.
231.Em (Client and server) 231.Em (Client and server)
232.It 232.It
233.Fn ressl_config_clear_keys 233.Fn ressl_config_clear_keys