Commit 71bd8dd2 authored by Benjamin Peterson's avatar Benjamin Peterson

remove rc4 from the default client ciphers (closes #23481)

parent 3905d8a8
...@@ -157,14 +157,12 @@ else: ...@@ -157,14 +157,12 @@ else:
# * Prefer any AES-GCM over any AES-CBC for better performance and security # * Prefer any AES-GCM over any AES-CBC for better performance and security
# * Then Use HIGH cipher suites as a fallback # * Then Use HIGH cipher suites as a fallback
# * Then Use 3DES as fallback which is secure but slow # * Then Use 3DES as fallback which is secure but slow
# * Finally use RC4 as a fallback which is problematic but needed for
# compatibility some times.
# * Disable NULL authentication, NULL encryption, and MD5 MACs for security # * Disable NULL authentication, NULL encryption, and MD5 MACs for security
# reasons # reasons
_DEFAULT_CIPHERS = ( _DEFAULT_CIPHERS = (
'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:' 'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:'
'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:ECDH+RC4:' 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:!aNULL:'
'DH+RC4:RSA+RC4:!aNULL:!eNULL:!MD5' '!eNULL:!MD5'
) )
# Restricted and more secure ciphers for the server side # Restricted and more secure ciphers for the server side
......
...@@ -21,6 +21,8 @@ Library ...@@ -21,6 +21,8 @@ Library
- Issue #22885: Fixed arbitrary code execution vulnerability in the dumbdbm - Issue #22885: Fixed arbitrary code execution vulnerability in the dumbdbm
module. Original patch by Claudiu Popa. module. Original patch by Claudiu Popa.
- Issue #23481: Remove RC4 from the SSL module's default cipher list.
- Issue #21849: Fixed xmlrpclib serialization of non-ASCII unicode strings in - Issue #21849: Fixed xmlrpclib serialization of non-ASCII unicode strings in
the multiprocessing module. the multiprocessing module.
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment