TLS: new method to specify SSL/TLS version

SSL/TLS protocols only listed in ssl_protocols should be used.
The name "ssl_protocols" comes from nginx.

Resolves #428.
This commit is contained in:
Koichiro IWAO
2016-12-13 15:49:13 +09:00
committed by metalefty
parent 657f6f3756
commit e94ab10e14
8 changed files with 49 additions and 16 deletions
+2 -2
View File
@@ -882,7 +882,7 @@ trans_get_out_s(struct trans *self, int size)
/* returns error */
int APP_CC
trans_set_tls_mode(struct trans *self, const char *key, const char *cert,
int disableSSLv3, const char *tls_ciphers)
long ssl_protocols, const char *tls_ciphers)
{
self->tls = ssl_tls_create(self, key, cert);
if (self->tls == NULL)
@@ -891,7 +891,7 @@ trans_set_tls_mode(struct trans *self, const char *key, const char *cert,
return 1;
}
if (ssl_tls_accept(self->tls, disableSSLv3, tls_ciphers) != 0)
if (ssl_tls_accept(self->tls, ssl_protocols, tls_ciphers) != 0)
{
g_writeln("trans_set_tls_mode: ssl_tls_accept failed");
return 1;