Blame SOURCES/grpc-0001-enforce-system-crypto-policies.patch

rdobuilder 12eb4f
From 5d56d52e0829e503e403568de66bb6cebfec3202 Mon Sep 17 00:00:00 2001
rdobuilder 12eb4f
From: Sergey Avseyev <sergey.avseyev@gmail.com>
rdobuilder 12eb4f
Date: Wed, 28 Nov 2018 18:53:22 +0300
rdobuilder 12eb4f
Subject: [PATCH 1/4] enforce system crypto policies
rdobuilder 12eb4f
rdobuilder 12eb4f
---
rdobuilder 12eb4f
 test/core/handshake/client_ssl.cc        | 3 +--
rdobuilder 12eb4f
 test/core/handshake/server_ssl_common.cc | 3 +--
rdobuilder 12eb4f
 2 files changed, 2 insertions(+), 4 deletions(-)
rdobuilder 12eb4f
rdobuilder 12eb4f
diff --git a/test/core/handshake/client_ssl.cc b/test/core/handshake/client_ssl.cc
rdobuilder 12eb4f
index 467df6e229..b31934e51b 100644
rdobuilder 12eb4f
--- a/test/core/handshake/client_ssl.cc
rdobuilder 12eb4f
+++ b/test/core/handshake/client_ssl.cc
rdobuilder 12eb4f
@@ -161,8 +161,7 @@ static void server_thread(void* arg) {
rdobuilder 12eb4f
   // Set the cipher list to match the one expressed in
rdobuilder 12eb4f
   // src/core/tsi/ssl_transport_security.c.
rdobuilder 12eb4f
   const char* cipher_list =
rdobuilder 12eb4f
-      "ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-"
rdobuilder 12eb4f
-      "SHA384:ECDHE-RSA-AES256-GCM-SHA384";
rdobuilder 12eb4f
+      "PROFILE=SYSTEM";
rdobuilder 12eb4f
   if (!SSL_CTX_set_cipher_list(ctx, cipher_list)) {
rdobuilder 12eb4f
     ERR_print_errors_fp(stderr);
rdobuilder 12eb4f
     gpr_log(GPR_ERROR, "Couldn't set server cipher list.");
rdobuilder 12eb4f
diff --git a/test/core/handshake/server_ssl_common.cc b/test/core/handshake/server_ssl_common.cc
rdobuilder 12eb4f
index 41b2829d8b..8b21ea7c73 100644
rdobuilder 12eb4f
--- a/test/core/handshake/server_ssl_common.cc
rdobuilder 12eb4f
+++ b/test/core/handshake/server_ssl_common.cc
rdobuilder 12eb4f
@@ -167,8 +167,7 @@ bool server_ssl_test(const char* alpn_list[], unsigned int alpn_list_len,
rdobuilder 12eb4f
   // Set the cipher list to match the one expressed in
rdobuilder 12eb4f
   // src/core/tsi/ssl_transport_security.c.
rdobuilder 12eb4f
   const char* cipher_list =
rdobuilder 12eb4f
-      "ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-RSA-AES256-"
rdobuilder 12eb4f
-      "SHA384:ECDHE-RSA-AES256-GCM-SHA384";
rdobuilder 12eb4f
+      "PROFILE=SYSTEM";
rdobuilder 12eb4f
   if (!SSL_CTX_set_cipher_list(ctx, cipher_list)) {
rdobuilder 12eb4f
     ERR_print_errors_fp(stderr);
rdobuilder 12eb4f
     gpr_log(GPR_ERROR, "Couldn't set server cipher list.");
rdobuilder 12eb4f
-- 
rdobuilder 12eb4f
2.21.0
rdobuilder 12eb4f