From 3c1bbbc5137306ac0b650dfd0aee0097582475a5 Mon Sep 17 00:00:00 2001 From: Přemysl Janouch Date: Sun, 12 Jul 2015 17:15:33 +0200 Subject: degesch: add an "ssl_ciphers" option to servers --- degesch.c | 9 ++++++++- 1 file changed, 8 insertions(+), 1 deletion(-) diff --git a/degesch.c b/degesch.c index 0ba4880..b839cd1 100644 --- a/degesch.c +++ b/degesch.c @@ -1539,6 +1539,10 @@ static struct config_schema g_config_server[] = { .name = "ssl_ca_path", .comment = "OpenSSL CA bundle path", .type = CONFIG_ITEM_STRING }, + { .name = "ssl_ciphers", + .comment = "OpenSSL cipher preference list", + .type = CONFIG_ITEM_STRING, + .default_ = "\"DEFAULT:!MEDIUM:!LOW\"" }, { .name = "autoconnect", .comment = "Connect automatically on startup", @@ -3884,7 +3888,10 @@ transport_tls_init_ctx (struct server *s, SSL_CTX *ssl_ctx, struct error **e) SSL_CTX_get_ex_new_index (0, "server", NULL, NULL, NULL); SSL_CTX_set_ex_data (ssl_ctx, g_transport_tls_data_index, s); - // TODO: allow specifying SSL_CTX_set_cipher_list() + const char *ciphers = get_config_string (s->config, "ssl_ciphers"); + if (ciphers && !SSL_CTX_set_cipher_list (ssl_ctx, ciphers)) + log_server_error (s, s->buffer, + "Failed to select any cipher from the cipher list"); SSL_CTX_set_mode (ssl_ctx, SSL_MODE_ENABLE_PARTIAL_WRITE | SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER); -- cgit v1.2.3-70-g09d2