mirror of
https://gitlab.uni-freiburg.de/opensourcevdi/spice
synced 2025-12-29 17:07:15 +00:00
ssl: Allow to use ECDH ciphers with OpenSSL 1.0
Without an explicit call to SSL_CTX_set_ecdh_auto(reds->ctx, 1), OpenSSL 1.0 (still used by el7) would not use ECDH ciphers (this is now automatic with OpenSSL 1.1.0). This commit adds this missing call. It's based on a suggestion from David Jasa Signed-off-by: Christophe Fergeau <cfergeau@redhat.com> Acked-by: Frediano Ziglio <fziglio@redhat.com> https://bugzilla.redhat.com/show_bug.cgi?id=1566597
This commit is contained in:
parent
dbc4bcb24b
commit
8822161833
@ -2784,6 +2784,7 @@ static int reds_init_ssl(RedsState *reds)
|
||||
}
|
||||
|
||||
SSL_CTX_set_options(reds->ctx, ssl_options);
|
||||
SSL_CTX_set_ecdh_auto(reds->ctx, 1);
|
||||
|
||||
/* Load our keys and certificates*/
|
||||
return_code = SSL_CTX_use_certificate_chain_file(reds->ctx, reds->config->ssl_parameters.certs_file);
|
||||
|
||||
Loading…
Reference in New Issue
Block a user