mirror of
https://gitlab.torproject.org/tpo/core/tor.git
synced 2024-12-06 19:41:15 +01:00
Switch ECDHE group default logic for bridge/relay TLS
According to the manpage, bridges use P256 for conformity and relays use P224 for speed. But skruffy points out that we've gotten it backwards in the code. In this patch, we make the default P256 for everybody. Fixes bug 9780; bugfix on 0.2.4.8-alpha.
This commit is contained in:
+1
-3
@@ -1369,10 +1369,8 @@ tor_tls_context_new(crypto_pk_t *identity, unsigned int key_lifetime,
|
||||
nid = NID_secp224r1;
|
||||
else if (flags & TOR_TLS_CTX_USE_ECDHE_P256)
|
||||
nid = NID_X9_62_prime256v1;
|
||||
else if (flags & TOR_TLS_CTX_IS_PUBLIC_SERVER)
|
||||
nid = NID_X9_62_prime256v1;
|
||||
else
|
||||
nid = NID_secp224r1;
|
||||
nid = NID_X9_62_prime256v1;
|
||||
/* Use P-256 for ECDHE. */
|
||||
ec_key = EC_KEY_new_by_curve_name(nid);
|
||||
if (ec_key != NULL) /*XXXX Handle errors? */
|
||||
|
||||
Reference in New Issue
Block a user