diff options
| author | beck <> | 2019-11-16 06:44:33 +0000 |
|---|---|---|
| committer | beck <> | 2019-11-16 06:44:33 +0000 |
| commit | 91f9d7d40c9378009df5654394df39b98eaff9f3 (patch) | |
| tree | cc00cad3dd1d3312a1ee097f4017a93682e43c6b /src | |
| parent | 012ffe7e29715fc11e923001a0a745a412e2041e (diff) | |
| download | openbsd-91f9d7d40c9378009df5654394df39b98eaff9f3.tar.gz openbsd-91f9d7d40c9378009df5654394df39b98eaff9f3.tar.bz2 openbsd-91f9d7d40c9378009df5654394df39b98eaff9f3.zip | |
Allow portable to override the default CA bundle location
ok kinichiro@ jsing@
Diffstat (limited to 'src')
| -rw-r--r-- | src/lib/libtls/tls_config.c | 4 | ||||
| -rw-r--r-- | src/lib/libtls/tls_internal.h | 6 |
2 files changed, 7 insertions, 3 deletions
diff --git a/src/lib/libtls/tls_config.c b/src/lib/libtls/tls_config.c index 6a717abd48..424fd73c93 100644 --- a/src/lib/libtls/tls_config.c +++ b/src/lib/libtls/tls_config.c | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: tls_config.c,v 1.56 2019/04/04 15:09:09 jsing Exp $ */ | 1 | /* $OpenBSD: tls_config.c,v 1.57 2019/11/16 06:44:33 beck Exp $ */ |
| 2 | /* | 2 | /* |
| 3 | * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> | 3 | * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> |
| 4 | * | 4 | * |
| @@ -28,7 +28,7 @@ | |||
| 28 | 28 | ||
| 29 | #include "tls_internal.h" | 29 | #include "tls_internal.h" |
| 30 | 30 | ||
| 31 | static const char default_ca_file[] = "/etc/ssl/cert.pem"; | 31 | static const char default_ca_file[] = TLS_DEFAULT_CA_FILE; |
| 32 | 32 | ||
| 33 | const char * | 33 | const char * |
| 34 | tls_default_ca_cert_file(void) | 34 | tls_default_ca_cert_file(void) |
diff --git a/src/lib/libtls/tls_internal.h b/src/lib/libtls/tls_internal.h index efccc9fdbe..3d806f8b6e 100644 --- a/src/lib/libtls/tls_internal.h +++ b/src/lib/libtls/tls_internal.h | |||
| @@ -1,4 +1,4 @@ | |||
| 1 | /* $OpenBSD: tls_internal.h,v 1.75 2019/11/02 13:37:59 jsing Exp $ */ | 1 | /* $OpenBSD: tls_internal.h,v 1.76 2019/11/16 06:44:33 beck Exp $ */ |
| 2 | /* | 2 | /* |
| 3 | * Copyright (c) 2014 Jeremie Courreges-Anglas <jca@openbsd.org> | 3 | * Copyright (c) 2014 Jeremie Courreges-Anglas <jca@openbsd.org> |
| 4 | * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> | 4 | * Copyright (c) 2014 Joel Sing <jsing@openbsd.org> |
| @@ -28,6 +28,10 @@ | |||
| 28 | 28 | ||
| 29 | __BEGIN_HIDDEN_DECLS | 29 | __BEGIN_HIDDEN_DECLS |
| 30 | 30 | ||
| 31 | #ifndef TLS_DEFAULT_CA_FILE | ||
| 32 | #define TLS_DEFAULT_CA_FILE "/etc/ssl/cert.pem" | ||
| 33 | #endif | ||
| 34 | |||
| 31 | #define TLS_CIPHERS_DEFAULT "TLSv1.2+AEAD+ECDHE:TLSv1.2+AEAD+DHE" | 35 | #define TLS_CIPHERS_DEFAULT "TLSv1.2+AEAD+ECDHE:TLSv1.2+AEAD+DHE" |
| 32 | #define TLS_CIPHERS_COMPAT "HIGH:!aNULL" | 36 | #define TLS_CIPHERS_COMPAT "HIGH:!aNULL" |
| 33 | #define TLS_CIPHERS_LEGACY "HIGH:MEDIUM:!aNULL" | 37 | #define TLS_CIPHERS_LEGACY "HIGH:MEDIUM:!aNULL" |
