new options for xrdp.ini disableSSlv3=yes and tls_ciphers=HIGH and code to implement

This commit is contained in:
Alex Illsley
2016-08-25 11:20:47 -07:00
committed by Jay Sorg
parent e28f529a94
commit 47124df4ed
8 changed files with 46 additions and 10 deletions
+3 -2
View File
@@ -881,7 +881,8 @@ trans_get_out_s(struct trans *self, int size)
/*****************************************************************************/
/* returns error */
int APP_CC
trans_set_tls_mode(struct trans *self, const char *key, const char *cert)
trans_set_tls_mode(struct trans *self, const char *key, const char *cert,
int disableSSLv3, const char *tls_ciphers)
{
self->tls = ssl_tls_create(self, key, cert);
if (self->tls == NULL)
@@ -890,7 +891,7 @@ trans_set_tls_mode(struct trans *self, const char *key, const char *cert)
return 1;
}
if (ssl_tls_accept(self->tls) != 0)
if (ssl_tls_accept(self->tls, disableSSLv3, tls_ciphers) != 0)
{
g_writeln("trans_set_tls_mode: ssl_tls_accept failed");
return 1;