|
|
8fbb1c |
diff -up openssl-1.0.1e/ssl/ssl_lib.c.disable-sslv2 openssl-1.0.1e/ssl/ssl_lib.c
|
|
|
8fbb1c |
--- openssl-1.0.1e/ssl/ssl_lib.c.disable-sslv2 2016-01-14 17:38:50.018210499 +0100
|
|
|
8fbb1c |
+++ openssl-1.0.1e/ssl/ssl_lib.c 2016-02-16 16:00:57.151508715 +0100
|
|
|
8fbb1c |
@@ -1903,6 +1903,9 @@ SSL_CTX *SSL_CTX_new(const SSL_METHOD *m
|
|
|
8fbb1c |
*/
|
|
|
8fbb1c |
ret->options |= SSL_OP_LEGACY_SERVER_CONNECT;
|
|
|
8fbb1c |
|
|
|
8fbb1c |
+ /* Disable SSLv2 by default (affects the SSLv23_method() only) */
|
|
|
8fbb1c |
+ ret->options |= SSL_OP_NO_SSLv2;
|
|
|
8fbb1c |
+
|
|
|
8fbb1c |
return(ret);
|
|
|
8fbb1c |
err:
|
|
|
8fbb1c |
SSLerr(SSL_F_SSL_CTX_NEW,ERR_R_MALLOC_FAILURE);
|
|
|
8fbb1c |
diff -up openssl-1.0.1e/doc/apps/ciphers.pod.disable-sslv2 openssl-1.0.1e/doc/apps/ciphers.pod
|
|
|
8fbb1c |
--- openssl-1.0.1e/doc/apps/ciphers.pod.disable-sslv2 2016-01-14 17:38:50.000000000 +0100
|
|
|
8fbb1c |
+++ openssl-1.0.1e/doc/apps/ciphers.pod 2016-02-24 11:17:36.297955053 +0100
|
|
|
8fbb1c |
@@ -572,11 +572,11 @@ Note: these ciphers can also be used in
|
|
|
8fbb1c |
=head2 Deprecated SSL v2.0 cipher suites.
|
|
|
8fbb1c |
|
|
|
8fbb1c |
SSL_CK_RC4_128_WITH_MD5 RC4-MD5
|
|
|
8fbb1c |
- SSL_CK_RC4_128_EXPORT40_WITH_MD5 EXP-RC4-MD5
|
|
|
8fbb1c |
- SSL_CK_RC2_128_CBC_WITH_MD5 RC2-MD5
|
|
|
8fbb1c |
- SSL_CK_RC2_128_CBC_EXPORT40_WITH_MD5 EXP-RC2-MD5
|
|
|
8fbb1c |
+ SSL_CK_RC4_128_EXPORT40_WITH_MD5 Not implemented.
|
|
|
8fbb1c |
+ SSL_CK_RC2_128_CBC_WITH_MD5 RC2-CBC-MD5
|
|
|
8fbb1c |
+ SSL_CK_RC2_128_CBC_EXPORT40_WITH_MD5 Not implemented.
|
|
|
8fbb1c |
SSL_CK_IDEA_128_CBC_WITH_MD5 IDEA-CBC-MD5
|
|
|
8fbb1c |
- SSL_CK_DES_64_CBC_WITH_MD5 DES-CBC-MD5
|
|
|
8fbb1c |
+ SSL_CK_DES_64_CBC_WITH_MD5 Not implemented.
|
|
|
8fbb1c |
SSL_CK_DES_192_EDE3_CBC_WITH_MD5 DES-CBC3-MD5
|
|
|
8fbb1c |
|
|
|
8fbb1c |
=head1 NOTES
|
|
|
8fbb1c |
diff -up openssl-1.0.1e/ssl/s2_lib.c.disable-sslv2 openssl-1.0.1e/ssl/s2_lib.c
|
|
|
8fbb1c |
--- openssl-1.0.1e/ssl/s2_lib.c.disable-sslv2 2016-02-24 11:23:24.012237164 +0100
|
|
|
8fbb1c |
+++ openssl-1.0.1e/ssl/s2_lib.c 2016-02-24 11:19:34.623773423 +0100
|
|
|
8fbb1c |
@@ -156,6 +156,7 @@ OPENSSL_GLOBAL const SSL_CIPHER ssl2_cip
|
|
|
8fbb1c |
128,
|
|
|
8fbb1c |
},
|
|
|
8fbb1c |
|
|
|
8fbb1c |
+#if 0
|
|
|
8fbb1c |
/* RC4_128_EXPORT40_WITH_MD5 */
|
|
|
8fbb1c |
{
|
|
|
8fbb1c |
1,
|
|
|
8fbb1c |
@@ -171,6 +172,7 @@ OPENSSL_GLOBAL const SSL_CIPHER ssl2_cip
|
|
|
8fbb1c |
40,
|
|
|
8fbb1c |
128,
|
|
|
8fbb1c |
},
|
|
|
8fbb1c |
+#endif
|
|
|
8fbb1c |
|
|
|
8fbb1c |
/* RC2_128_CBC_WITH_MD5 */
|
|
|
8fbb1c |
{
|
|
|
8fbb1c |
@@ -188,6 +190,7 @@ OPENSSL_GLOBAL const SSL_CIPHER ssl2_cip
|
|
|
8fbb1c |
128,
|
|
|
8fbb1c |
},
|
|
|
8fbb1c |
|
|
|
8fbb1c |
+#if 0
|
|
|
8fbb1c |
/* RC2_128_CBC_EXPORT40_WITH_MD5 */
|
|
|
8fbb1c |
{
|
|
|
8fbb1c |
1,
|
|
|
8fbb1c |
@@ -203,6 +206,7 @@ OPENSSL_GLOBAL const SSL_CIPHER ssl2_cip
|
|
|
8fbb1c |
40,
|
|
|
8fbb1c |
128,
|
|
|
8fbb1c |
},
|
|
|
8fbb1c |
+#endif
|
|
|
8fbb1c |
|
|
|
8fbb1c |
#ifndef OPENSSL_NO_IDEA
|
|
|
8fbb1c |
/* IDEA_128_CBC_WITH_MD5 */
|
|
|
8fbb1c |
@@ -222,6 +226,7 @@ OPENSSL_GLOBAL const SSL_CIPHER ssl2_cip
|
|
|
8fbb1c |
},
|
|
|
8fbb1c |
#endif
|
|
|
8fbb1c |
|
|
|
8fbb1c |
+#if 0
|
|
|
8fbb1c |
/* DES_64_CBC_WITH_MD5 */
|
|
|
8fbb1c |
{
|
|
|
8fbb1c |
1,
|
|
|
8fbb1c |
@@ -237,6 +242,7 @@ OPENSSL_GLOBAL const SSL_CIPHER ssl2_cip
|
|
|
8fbb1c |
56,
|
|
|
8fbb1c |
56,
|
|
|
8fbb1c |
},
|
|
|
8fbb1c |
+#endif
|
|
|
8fbb1c |
|
|
|
8fbb1c |
/* DES_192_EDE3_CBC_WITH_MD5 */
|
|
|
8fbb1c |
{
|