Skip to content

Commit bd4113d

Browse files
committed
disabled unsafe DH kex algorithms by default
1 parent 266575d commit bd4113d

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

russh/src/negotiation.rs

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -82,7 +82,7 @@ const HMAC_ORDER: &[mac::Name] = &[
8282
impl Preferred {
8383
#[cfg(feature = "openssl")]
8484
pub const DEFAULT: Preferred = Preferred {
85-
kex: KEX_ORDER,
85+
kex: &[kex::CURVE25519, kex::DH_G14_SHA256],
8686
key: &[key::ED25519, key::RSA_SHA2_256, key::RSA_SHA2_512],
8787
cipher: CIPHER_ORDER,
8888
mac: HMAC_ORDER,

0 commit comments

Comments
 (0)