fixes SSL version check logic [backport] (#21324)

* fixed version check logic [backport]

* add ciphersuites

* debug nimble

* fixes returns omission

* finally

* remove debug message

* add ciphersuites

---------

Co-authored-by: Araq <rumpf_a@web.de>
This commit is contained in:
ringabout 2023-02-02 23:44:14 +08:00 • committed by GitHub
commit 17115cbc73
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23
4 changed files with 8 additions and 8 deletions

View file

@ -621,7 +621,7 @@ when defineSsl:
proc newContext*(protVersion = protSSLv23, verifyMode = CVerifyPeer,
certFile = "", keyFile = "", cipherList = CiphersIntermediate,
caDir = "", caFile = ""): SslContext =
caDir = "", caFile = "", ciphersuites = CiphersModern): SslContext =
## Creates an SSL context.
##
## Protocol version is currently ignored by default and TLS is used.
@ -675,10 +675,10 @@ when defineSsl:
raiseSSLError()
when not defined(openssl10) and not defined(libressl):
let sslVersion = getOpenSSLVersion()
if sslVersion >= 0x010101000 and not sslVersion == 0x020000000:
if sslVersion >= 0x010101000 and sslVersion != 0x020000000:
# In OpenSSL >= 1.1.1, TLSv1.3 cipher suites can only be configured via
# this API.
if newCTX.SSL_CTX_set_ciphersuites(cipherList) != 1:
if newCTX.SSL_CTX_set_ciphersuites(ciphersuites) != 1:
raiseSSLError()
# Automatically the best ECDH curve for client exchange. Without this, ECDH
# ciphers will be ignored by the server.