|
commit a2919cab08fff3fad434c574506b5ae23b4db131
|
|
Author: Pierre Cheynier <p.cheynier@criteo.com>
|
|
Date: Thu Mar 21 16:15:47 2019 +0000
|
|
|
|
BUG/MEDIUM: ssl: ability to set TLS 1.3 ciphers using ssl-default-server-ciphersuites
|
|
|
|
Any attempt to put TLS 1.3 ciphers on servers failed with output 'unable
|
|
to set TLS 1.3 cipher suites'.
|
|
|
|
This was due to usage of SSL_CTX_set_cipher_list instead of
|
|
SSL_CTX_set_ciphersuites in the TLS 1.3 block (protected by
|
|
OPENSSL_VERSION_NUMBER >= 0x10101000L & so).
|
|
|
|
This should be backported to 1.9 and 1.8.
|
|
|
|
Signed-off-by: Pierre Cheynier <p.cheynier@criteo.com>
|
|
Reported-by: Damien Claisse <d.claisse@criteo.com>
|
|
Cc: Emeric Brun <ebrun@haproxy.com>
|
|
(cherry picked from commit bc34cd1de2ee80de63b5c4d319a501fc0d4ea2f5)
|
|
Signed-off-by: Willy Tarreau <w@1wt.eu>
|
|
(cherry picked from commit 4a8b9e3d5f4e76295c571900771fd1728bec474f)
|
|
Signed-off-by: Christopher Faulet <cfaulet@haproxy.com>
|
|
|
|
diff --git a/src/ssl_sock.c b/src/ssl_sock.c
|
|
index afdb1fce..fbb7cf2b 100644
|
|
--- a/src/ssl_sock.c
|
|
+++ b/src/ssl_sock.c
|
|
@@ -4696,7 +4696,7 @@ int ssl_sock_prepare_srv_ctx(struct server *srv)
|
|
|
|
#if (OPENSSL_VERSION_NUMBER >= 0x10101000L && !defined OPENSSL_IS_BORINGSSL && !defined LIBRESSL_VERSION_NUMBER)
|
|
if (srv->ssl_ctx.ciphersuites &&
|
|
- !SSL_CTX_set_cipher_list(srv->ssl_ctx.ctx, srv->ssl_ctx.ciphersuites)) {
|
|
+ !SSL_CTX_set_ciphersuites(srv->ssl_ctx.ctx, srv->ssl_ctx.ciphersuites)) {
|
|
ha_alert("Proxy '%s', server '%s' [%s:%d] : unable to set TLS 1.3 cipher suites to '%s'.\n",
|
|
curproxy->id, srv->id,
|
|
srv->conf.file, srv->conf.line, srv->ssl_ctx.ciphersuites);
|