]> www.infradead.org Git - users/dwmw2/openconnect.git/commitdiff
Enable DHE ciphers for Cisco DTLS
authorDavid Woodhouse <David.Woodhouse@intel.com>
Mon, 3 Oct 2016 20:49:27 +0000 (21:49 +0100)
committerDavid Woodhouse <David.Woodhouse@intel.com>
Mon, 3 Oct 2016 20:49:27 +0000 (21:49 +0100)
Tested-by: Peter Brant <peter.brant@gmail.com>
Signed-off-by: David Woodhouse <David.Woodhouse@intel.com>
gnutls-dtls.c
openssl-dtls.c
www/changelog.xml

index 07cb8f4a6e3dd82b78f408f445066140b721c335..3017cefbfad4e68e6efa781cfffc68dbbbb88571 100644 (file)
@@ -58,6 +58,10 @@ struct {
        const char *prio;
        const char *min_gnutls_version;
 } gnutls_dtls_ciphers[] = {
+       { "DHE-RSA-AES128-SHA", GNUTLS_DTLS0_9, GNUTLS_CIPHER_AES_128_CBC, GNUTLS_KX_DHE_RSA, GNUTLS_MAC_SHA1,
+         "NONE:+VERS-DTLS0.9:+COMP-NULL:+AES-128-CBC:+SHA1:+DHE-RSA:%COMPAT", "3.0.0" },
+       { "DHE-RSA-AES256-SHA", GNUTLS_DTLS0_9, GNUTLS_CIPHER_AES_256_CBC, GNUTLS_KX_DHE_RSA, GNUTLS_MAC_SHA1,
+         "NONE:+VERS-DTLS0.9:+COMP-NULL:+AES-256-CBC:+SHA1:+DHE-RSA:%COMPAT", "3.0.0" },
        { "AES128-SHA", GNUTLS_DTLS0_9, GNUTLS_CIPHER_AES_128_CBC, GNUTLS_KX_RSA, GNUTLS_MAC_SHA1,
          "NONE:+VERS-DTLS0.9:+COMP-NULL:+AES-128-CBC:+SHA1:+RSA:%COMPAT", "3.0.0" },
        { "AES256-SHA", GNUTLS_DTLS0_9, GNUTLS_CIPHER_AES_256_CBC, GNUTLS_KX_RSA, GNUTLS_MAC_SHA1,
index ede21b54d070ebe19084ba4839a106debebbbd6e..89fce6463c52a5550354a9b537e3e99c1f51d6cc 100644 (file)
@@ -537,6 +537,7 @@ void append_dtls_ciphers(struct openconnect_info *vpninfo, struct oc_text_buf *b
 #endif
        buf_append(buf, "OC-DTLS1_2-AES256-GCM:OC-DTLS1_2-AES128-GCM:");
 #endif
+       buf_append(buf, "DHE-RSA-AES256-SHA:DHE-RSA-AES128-SHA:");
        buf_append(buf, "AES256-SHA:AES128-SHA:DES-CBC3-SHA:DES-CBC-SHA");
 }
 
index c051d2006b0806feb4924f48e59ee65573e00d79..083f2c7e7bd8d6054c2bad6f2284ca64960cde3c 100644 (file)
@@ -15,6 +15,7 @@
 <ul>
    <li><b>OpenConnect HEAD</b>
      <ul>
+       <li>Enable DHE ciphers for Cisco DTLS.</li>
        <li>Increase initial oNCP configuration buffer size.</li>
        <li>Reopen <tt>CONIN$</tt> when stdin is redirected on Windows.</li>
        <li>Improve support for point-to-point routing on Windows.</li>