Permalink
Please sign in to comment.
Browse files
Only allow ephemeral RSA keys in export ciphersuites.
OpenSSL clients would tolerate temporary RSA keys in non-export ciphersuites. It also had an option SSL_OP_EPHEMERAL_RSA which enabled this server side. Remove both options as they are a protocol violation. Thanks to Karthikeyan Bhargavan for reporting this issue. (CVE-2015-0204) Reviewed-by: Matt Caswell <matt@openssl.org>
- Loading branch information...
Showing
with
38 additions
and 57 deletions.
- +8 −0 CHANGES
- +1 −9 doc/ssl/SSL_CTX_set_options.pod
- +8 −15 doc/ssl/SSL_CTX_set_tmp_rsa_callback.pod
- +6 −15 ssl/d1_srvr.c
- +7 −0 ssl/s3_clnt.c
- +6 −15 ssl/s3_srvr.c
- +2 −3 ssl/ssl.h
0 comments on commit
ce325c6