By default even recent versions of OpenSSL support and accept both "export strength" ciphers, small-bitsize ciphers as well as downright deprecated ones. This change sets a default cipher set that avoids the worst ciphers, and subsequently makes https://www.howsmyssl.com/a/check no longer grade curl/OpenSSL connects as 'Bad'. Bug: http://curl.haxx.se/bug/view.cgi?id=1323 Reported-by: Jeff Hodges |
||
|---|---|---|
| .. | ||
| axtls.c | ||
| axtls.h | ||
| curl_darwinssl.c | ||
| curl_darwinssl.h | ||
| curl_schannel.c | ||
| curl_schannel.h | ||
| cyassl.c | ||
| cyassl.h | ||
| gskit.c | ||
| gskit.h | ||
| gtls.c | ||
| gtls.h | ||
| nss.c | ||
| nssg.h | ||
| openssl.c | ||
| openssl.h | ||
| polarssl_threadlock.c | ||
| polarssl_threadlock.h | ||
| polarssl.c | ||
| polarssl.h | ||
| qssl.c | ||
| qssl.h | ||
| vtls.c | ||
| vtls.h | ||