diff options
author | Steffan Karger | 2017-11-12 17:36:36 +0100 |
---|---|---|
committer | Gert Doering | 2017-11-19 21:19:28 +0100 |
commit | aba758740d26224b7b3957df221def7ab80c5802 (patch) | |
tree | 70025f9eee53e54205212aeaff6c6ed0c0c20305 /.gitignore | |
parent | dd99646347bc5461fa83b0e62114550504bb128f (diff) | |
download | openvpn-aba758740d26224b7b3957df221def7ab80c5802.zip openvpn-aba758740d26224b7b3957df221def7ab80c5802.tar.gz |
Add --tls-cert-profile option.
This allows the user to specify what certificate crypto algorithms to
support. The supported profiles are 'preferred', 'legacy' (default) and
'suiteb', as discussed in <84590a17-1c48-9df2-c48e-4160750b2e33@fox-it.com>
(https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg14214.
html).
This fully implements the feature for mbed TLS builds, because for mbed it
is both more easy to implement and the most relevant because mbed TLS 2+
is by default somewhat restrictive by requiring 2048-bit+ for RSA keys.
For OpenSSL, this implements an approximation based on security levels, as
discussed at the hackathon in Karlsruhe.
This patch uses 'legacy' as the default profile following discussion on
the openvpn-devel mailing list. This way this patch can be applied to
both the release/2.4 and master branches. I'll send a follow-up patch for
the master branch to change the default to 'preferred' later.
Signed-off-by: Steffan Karger <steffan.karger@fox-it.com>
Acked-by: Antonio Quartulli <antonio@openvpn.net>
Message-Id: <20171112163636.17434-1-steffan@karger.me>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg15848.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
Diffstat (limited to '.gitignore')
0 files changed, 0 insertions, 0 deletions