remove rc4 from the default client ciphers (closes #23481)
This commit is contained in:
parent
6a2c4a1a29
commit
500af332f4
|
@ -170,14 +170,12 @@ else:
|
||||||
# * Prefer any AES-GCM over any AES-CBC for better performance and security
|
# * Prefer any AES-GCM over any AES-CBC for better performance and security
|
||||||
# * Then Use HIGH cipher suites as a fallback
|
# * Then Use HIGH cipher suites as a fallback
|
||||||
# * Then Use 3DES as fallback which is secure but slow
|
# * Then Use 3DES as fallback which is secure but slow
|
||||||
# * Finally use RC4 as a fallback which is problematic but needed for
|
|
||||||
# compatibility some times.
|
|
||||||
# * Disable NULL authentication, NULL encryption, and MD5 MACs for security
|
# * Disable NULL authentication, NULL encryption, and MD5 MACs for security
|
||||||
# reasons
|
# reasons
|
||||||
_DEFAULT_CIPHERS = (
|
_DEFAULT_CIPHERS = (
|
||||||
'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:'
|
'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:'
|
||||||
'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:ECDH+RC4:'
|
'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:!aNULL:'
|
||||||
'DH+RC4:RSA+RC4:!aNULL:!eNULL:!MD5'
|
'!eNULL:!MD5'
|
||||||
)
|
)
|
||||||
|
|
||||||
# Restricted and more secure ciphers for the server side
|
# Restricted and more secure ciphers for the server side
|
||||||
|
|
|
@ -13,6 +13,8 @@ Core and Builtins
|
||||||
Library
|
Library
|
||||||
-------
|
-------
|
||||||
|
|
||||||
|
- Issue #23481: Remove RC4 from the SSL module's default cipher list.
|
||||||
|
|
||||||
- Issue #21548: Fix pydoc.synopsis() and pydoc.apropos() on modules with empty
|
- Issue #21548: Fix pydoc.synopsis() and pydoc.apropos() on modules with empty
|
||||||
docstrings.
|
docstrings.
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue