[tor-bugs] #11528 [Tor]: Consider using ​SSL_OP_CIPHER_SERVER_PREFERENCE

Tor Bug Tracker & Wiki blackhole at torproject.org
Thu Apr 17 14:33:44 UTC 2014


#11528: Consider using ​SSL_OP_CIPHER_SERVER_PREFERENCE
-------------------------+-------------------------------------------------
     Reporter:  nickm    |      Owner:
         Type:  defect   |     Status:  needs_review
     Priority:  normal   |  Milestone:  Tor: 0.2.5.x-final
    Component:  Tor      |    Version:
   Resolution:           |   Keywords:  tor-relay tls 024-backport nickm-
Actual Points:           |  review-0254
       Points:           |  Parent ID:
-------------------------+-------------------------------------------------
Changes (by nickm):

 * status:  new => needs_review


Comment:

 After discussion, I think that the right move here is to apply this flag.
 The new server cipher list fits our needs much better than the old client
 list or even the new one.

 Trivial patch in bug11528_024.  (Yes, I have confirmed that every OpenSSL
 we support has SSL_OP_CIPHER_SERVER_PREFERENCE)

--
Ticket URL: <https://trac.torproject.org/projects/tor/ticket/11528#comment:4>
Tor Bug Tracker & Wiki <https://trac.torproject.org/>
The Tor Project: anonymity online


More information about the tor-bugs mailing list