diff options
author | Kenneth Lakin <[email protected]> | 2016-04-30 02:31:51 -0700 |
---|---|---|
committer | Kenneth Lakin <[email protected]> | 2016-05-26 02:58:55 -0700 |
commit | df0c5663dd944a3dd06936105d0696a704c20e4e (patch) | |
tree | 0327c1f812afe0a9786acb3bf303ab665135825c /lib/ssl/src/ssl_internal.hrl | |
parent | 42a0229c44875f927bc1fda138d24131874a1c3c (diff) | |
download | otp-df0c5663dd944a3dd06936105d0696a704c20e4e.tar.gz otp-df0c5663dd944a3dd06936105d0696a704c20e4e.tar.bz2 otp-df0c5663dd944a3dd06936105d0696a704c20e4e.zip |
ssl: Add BEAST mitigation selection option
Some legacy TLS 1.0 software does not tolerate the 1/n-1 content
split BEAST mitigation technique. This commit adds a beast_mitigation
SSL option (defaulting to one_n_minus_one) to select or disable the
BEAST mitigation technique.
Valid option values are (one_n_minus_one | zero_n | disabled).
Diffstat (limited to 'lib/ssl/src/ssl_internal.hrl')
-rw-r--r-- | lib/ssl/src/ssl_internal.hrl | 3 |
1 files changed, 3 insertions, 0 deletions
diff --git a/lib/ssl/src/ssl_internal.hrl b/lib/ssl/src/ssl_internal.hrl index 076e663cd4..dddcbdeeda 100644 --- a/lib/ssl/src/ssl_internal.hrl +++ b/lib/ssl/src/ssl_internal.hrl @@ -133,6 +133,9 @@ %% the client? honor_cipher_order = false :: boolean(), padding_check = true :: boolean(), + %%Should we use 1/n-1 or 0/n splitting to mitigate BEAST, or disable + %%mitigation entirely? + beast_mitigation = one_n_minus_one :: one_n_minus_one | zero_n | disabled, fallback = false :: boolean(), crl_check :: boolean() | peer | best_effort, crl_cache, |