ssl-renegotiate-transitional.patch 903 B

12345678910111213141516171819202122
  1. Enable transitional scheme for ssl renegotiation:
  2. (from mozilla/security/nss/lib/ssl/ssl.h)
  3. Disallow unsafe renegotiation in server sockets only, but allow clients
  4. to continue to renegotiate with vulnerable servers.
  5. This value should only be used during the transition period when few
  6. servers have been upgraded.
  7. diff --git a/mozilla/security/nss/lib/ssl/sslsock.c b/mozilla/security/nss/lib/ssl/sslsock.c
  8. index f1d1921..c074360 100644
  9. --- a/mozilla/security/nss/lib/ssl/sslsock.c
  10. +++ b/mozilla/security/nss/lib/ssl/sslsock.c
  11. @@ -181,7 +181,7 @@ static sslOptions ssl_defaults = {
  12. PR_FALSE, /* noLocks */
  13. PR_FALSE, /* enableSessionTickets */
  14. PR_FALSE, /* enableDeflate */
  15. - 2, /* enableRenegotiation (default: requires extension) */
  16. + 3, /* enableRenegotiation (default: transitional) */
  17. PR_FALSE, /* requireSafeNegotiation */
  18. };