diff options
author | tedu <> | 2014-10-14 22:05:28 +0000 |
---|---|---|
committer | tedu <> | 2014-10-14 22:05:28 +0000 |
commit | dcf0c85a37d1b2da6424029201cb837c14348dc0 (patch) | |
tree | 1eb19615831e225a44f5be2650bb6bce8319e6b8 /src/lib | |
parent | b1d01e6f356d5697eb970fe901d012de69084c84 (diff) | |
download | openbsd-dcf0c85a37d1b2da6424029201cb837c14348dc0.tar.gz openbsd-dcf0c85a37d1b2da6424029201cb837c14348dc0.tar.bz2 openbsd-dcf0c85a37d1b2da6424029201cb837c14348dc0.zip |
seems like a good time to make the ressl default TLSv1 only.
ok guenther
Diffstat (limited to 'src/lib')
-rw-r--r-- | src/lib/libressl/ressl.h | 5 | ||||
-rw-r--r-- | src/lib/libressl/ressl_init.3 | 6 |
2 files changed, 5 insertions, 6 deletions
diff --git a/src/lib/libressl/ressl.h b/src/lib/libressl/ressl.h index 0795a33162..8fa2788077 100644 --- a/src/lib/libressl/ressl.h +++ b/src/lib/libressl/ressl.h | |||
@@ -1,4 +1,4 @@ | |||
1 | /* $OpenBSD: ressl.h,v 1.19 2014/10/09 22:04:33 tedu Exp $ */ | 1 | /* $OpenBSD: ressl.h,v 1.20 2014/10/14 22:05:28 tedu Exp $ */ |
2 | /* | 2 | /* |
3 | * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> | 3 | * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> |
4 | * | 4 | * |
@@ -26,8 +26,7 @@ | |||
26 | #define RESSL_PROTOCOL_TLSv1_2 (1 << 3) | 26 | #define RESSL_PROTOCOL_TLSv1_2 (1 << 3) |
27 | #define RESSL_PROTOCOL_TLSv1 \ | 27 | #define RESSL_PROTOCOL_TLSv1 \ |
28 | (RESSL_PROTOCOL_TLSv1_0|RESSL_PROTOCOL_TLSv1_1|RESSL_PROTOCOL_TLSv1_2) | 28 | (RESSL_PROTOCOL_TLSv1_0|RESSL_PROTOCOL_TLSv1_1|RESSL_PROTOCOL_TLSv1_2) |
29 | #define RESSL_PROTOCOLS_DEFAULT \ | 29 | #define RESSL_PROTOCOLS_DEFAULT RESSL_PROTOCOL_TLSv1 |
30 | (RESSL_PROTOCOL_SSLv3|RESSL_PROTOCOL_TLSv1) | ||
31 | 30 | ||
32 | #define RESSL_READ_AGAIN -2 | 31 | #define RESSL_READ_AGAIN -2 |
33 | #define RESSL_WRITE_AGAIN -3 | 32 | #define RESSL_WRITE_AGAIN -3 |
diff --git a/src/lib/libressl/ressl_init.3 b/src/lib/libressl/ressl_init.3 index 8f47a667eb..b881d171e4 100644 --- a/src/lib/libressl/ressl_init.3 +++ b/src/lib/libressl/ressl_init.3 | |||
@@ -1,4 +1,4 @@ | |||
1 | .\" $OpenBSD: ressl_init.3,v 1.5 2014/10/08 19:17:55 tedu Exp $ | 1 | .\" $OpenBSD: ressl_init.3,v 1.6 2014/10/14 22:05:28 tedu Exp $ |
2 | .\" | 2 | .\" |
3 | .\" Copyright (c) 2014 Ted Unangst <tedu@openbsd.org> | 3 | .\" Copyright (c) 2014 Ted Unangst <tedu@openbsd.org> |
4 | .\" | 4 | .\" |
@@ -14,7 +14,7 @@ | |||
14 | .\" ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF | 14 | .\" ACTION OF CONTRACT, NEGLIGENCE OR OTHER TORTIOUS ACTION, ARISING OUT OF |
15 | .\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. | 15 | .\" OR IN CONNECTION WITH THE USE OR PERFORMANCE OF THIS SOFTWARE. |
16 | .\" | 16 | .\" |
17 | .Dd $Mdocdate: October 8 2014 $ | 17 | .Dd $Mdocdate: October 14 2014 $ |
18 | .Dt RESSL 3 | 18 | .Dt RESSL 3 |
19 | .Os | 19 | .Os |
20 | .Sh NAME | 20 | .Sh NAME |
@@ -227,7 +227,7 @@ Additionally, the values | |||
227 | .Dv RESSL_PROTOCOL_TLSv1 | 227 | .Dv RESSL_PROTOCOL_TLSv1 |
228 | (all TLS versions) and | 228 | (all TLS versions) and |
229 | .Dv RESSL_PROTOCOLS_DEFAULT | 229 | .Dv RESSL_PROTOCOLS_DEFAULT |
230 | (all versions) may be used. | 230 | (currently all TLS versions) may be used. |
231 | .Em (Client and server) | 231 | .Em (Client and server) |
232 | .It | 232 | .It |
233 | .Fn ressl_config_clear_keys | 233 | .Fn ressl_config_clear_keys |