From b3a09056efed64d143068860e6e84492e8851f6d Mon Sep 17 00:00:00 2001 From: deuce <> Date: Mon, 17 Feb 2020 21:06:42 +0000 Subject: [PATCH] Disable TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 again, there's more issues here, and it's not really needed. --- 3rdp/build/cl-ssl-suite-blocksizes.patch | 16 +++++++++++----- 1 file changed, 11 insertions(+), 5 deletions(-) diff --git a/3rdp/build/cl-ssl-suite-blocksizes.patch b/3rdp/build/cl-ssl-suite-blocksizes.patch index 05cdc2ac2a..2c6599dc71 100644 --- a/3rdp/build/cl-ssl-suite-blocksizes.patch +++ b/3rdp/build/cl-ssl-suite-blocksizes.patch @@ -1,5 +1,5 @@ ---- session/ssl_suites.c.orig 2020-02-17 15:37:41.582802000 -0500 -+++ session/ssl_suites.c 2020-02-17 15:40:10.099185000 -0500 +--- session/ssl_suites.c.orig 2020-02-17 15:42:41.411268000 -0500 ++++ session/ssl_suites.c 2020-02-17 16:05:59.563026000 -0500 @@ -135,7 +135,7 @@ { TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256, DESCRIPTION( "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256" ) @@ -9,15 +9,21 @@ CIPHERSUITE_FLAG_ECC | CIPHERSUITE_FLAG_TLS12 }, /* { TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, DESCRIPTION( "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384" ) -@@ -190,7 +190,7 @@ - { TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, +@@ -187,11 +187,11 @@ + CRYPT_ALGO_ECDH, CRYPT_ALGO_RSA, CRYPT_ALGO_AES, + CRYPT_ALGO_HMAC_SHA2, 0, 16, GCMICV_SIZE, + CIPHERSUITE_FLAG_ECC | CIPHERSUITE_FLAG_GCM | CIPHERSUITE_FLAG_TLS12 }, +- { TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, ++/* { TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384, DESCRIPTION( "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384" ) CRYPT_ALGO_ECDH, CRYPT_ALGO_RSA, CRYPT_ALGO_AES, - CRYPT_ALGO_HMAC_SHA2, 48, 16, GCMICV_SIZE, +- CIPHERSUITE_FLAG_ECC | CIPHERSUITE_FLAG_GCM | CIPHERSUITE_FLAG_TLS12 }, + CRYPT_ALGO_HMAC_SHA2, 48, 32, GCMICV_SIZE, - CIPHERSUITE_FLAG_ECC | CIPHERSUITE_FLAG_GCM | CIPHERSUITE_FLAG_TLS12 }, ++ CIPHERSUITE_FLAG_ECC | CIPHERSUITE_FLAG_GCM | CIPHERSUITE_FLAG_TLS12 },*/ /* AES-GCM with DH */ + { TLS_DHE_RSA_WITH_AES_128_GCM_SHA256, @@ -200,9 +200,9 @@ CRYPT_ALGO_HMAC_SHA2, 0, 16, GCMICV_SIZE, CIPHERSUITE_FLAG_DH | CIPHERSUITE_FLAG_GCM | CIPHERSUITE_FLAG_TLS12 }, -- GitLab