src: Make DEFAULT_CIPHER_LIST constexpr char[]
This commit is contained in:
parent
3f97e6cd3a
commit
fc9bdf024f
16
src/ssl.cc
16
src/ssl.cc
|
@ -38,22 +38,6 @@ namespace nghttp2 {
|
||||||
|
|
||||||
namespace ssl {
|
namespace ssl {
|
||||||
|
|
||||||
// Recommended general purpose "Intermediate compatibility" cipher
|
|
||||||
// suites by mozilla.
|
|
||||||
//
|
|
||||||
// https://wiki.mozilla.org/Security/Server_Side_TLS
|
|
||||||
const char *const DEFAULT_CIPHER_LIST =
|
|
||||||
"ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-"
|
|
||||||
"AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-"
|
|
||||||
"SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-"
|
|
||||||
"AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-"
|
|
||||||
"ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-"
|
|
||||||
"AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-"
|
|
||||||
"SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-"
|
|
||||||
"ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-"
|
|
||||||
"SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-"
|
|
||||||
"SHA:DES-CBC3-SHA:!DSS";
|
|
||||||
|
|
||||||
#if OPENSSL_1_1_API
|
#if OPENSSL_1_1_API
|
||||||
|
|
||||||
// CRYPTO_LOCK is deprecated as of OpenSSL 1.1.0
|
// CRYPTO_LOCK is deprecated as of OpenSSL 1.1.0
|
||||||
|
|
16
src/ssl.h
16
src/ssl.h
|
@ -45,7 +45,21 @@ public:
|
||||||
LibsslGlobalLock &operator=(const LibsslGlobalLock &) = delete;
|
LibsslGlobalLock &operator=(const LibsslGlobalLock &) = delete;
|
||||||
};
|
};
|
||||||
|
|
||||||
extern const char *const DEFAULT_CIPHER_LIST;
|
// Recommended general purpose "Intermediate compatibility" cipher
|
||||||
|
// suites by mozilla.
|
||||||
|
//
|
||||||
|
// https://wiki.mozilla.org/Security/Server_Side_TLS
|
||||||
|
constexpr char DEFAULT_CIPHER_LIST[] =
|
||||||
|
"ECDHE-ECDSA-CHACHA20-POLY1305:ECDHE-RSA-CHACHA20-POLY1305:ECDHE-ECDSA-"
|
||||||
|
"AES128-GCM-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-ECDSA-AES256-GCM-"
|
||||||
|
"SHA384:ECDHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-"
|
||||||
|
"AES256-GCM-SHA384:ECDHE-ECDSA-AES128-SHA256:ECDHE-RSA-AES128-SHA256:ECDHE-"
|
||||||
|
"ECDSA-AES128-SHA:ECDHE-RSA-AES256-SHA384:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-"
|
||||||
|
"AES256-SHA384:ECDHE-ECDSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-AES128-"
|
||||||
|
"SHA256:DHE-RSA-AES128-SHA:DHE-RSA-AES256-SHA256:DHE-RSA-AES256-SHA:ECDHE-"
|
||||||
|
"ECDSA-DES-CBC3-SHA:ECDHE-RSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:AES128-GCM-"
|
||||||
|
"SHA256:AES256-GCM-SHA384:AES128-SHA256:AES256-SHA256:AES128-SHA:AES256-"
|
||||||
|
"SHA:DES-CBC3-SHA:!DSS";
|
||||||
|
|
||||||
const char *get_tls_protocol(SSL *ssl);
|
const char *get_tls_protocol(SSL *ssl);
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue