fixes SSL version check logic [backport] (#21324)
* fixed version check logic [backport] * add ciphersuites * debug nimble * fixes returns omission * finally * remove debug message * add ciphersuites --------- Co-authored-by: Araq <rumpf_a@web.de>
This commit is contained in:
parent
43b1b9d077
commit
17115cbc73
4 changed files with 8 additions and 8 deletions
|
|
@ -621,7 +621,7 @@ when defineSsl:
|
||||||
|
|
||||||
proc newContext*(protVersion = protSSLv23, verifyMode = CVerifyPeer,
|
proc newContext*(protVersion = protSSLv23, verifyMode = CVerifyPeer,
|
||||||
certFile = "", keyFile = "", cipherList = CiphersIntermediate,
|
certFile = "", keyFile = "", cipherList = CiphersIntermediate,
|
||||||
caDir = "", caFile = ""): SslContext =
|
caDir = "", caFile = "", ciphersuites = CiphersModern): SslContext =
|
||||||
## Creates an SSL context.
|
## Creates an SSL context.
|
||||||
##
|
##
|
||||||
## Protocol version is currently ignored by default and TLS is used.
|
## Protocol version is currently ignored by default and TLS is used.
|
||||||
|
|
@ -675,10 +675,10 @@ when defineSsl:
|
||||||
raiseSSLError()
|
raiseSSLError()
|
||||||
when not defined(openssl10) and not defined(libressl):
|
when not defined(openssl10) and not defined(libressl):
|
||||||
let sslVersion = getOpenSSLVersion()
|
let sslVersion = getOpenSSLVersion()
|
||||||
if sslVersion >= 0x010101000 and not sslVersion == 0x020000000:
|
if sslVersion >= 0x010101000 and sslVersion != 0x020000000:
|
||||||
# In OpenSSL >= 1.1.1, TLSv1.3 cipher suites can only be configured via
|
# In OpenSSL >= 1.1.1, TLSv1.3 cipher suites can only be configured via
|
||||||
# this API.
|
# this API.
|
||||||
if newCTX.SSL_CTX_set_ciphersuites(cipherList) != 1:
|
if newCTX.SSL_CTX_set_ciphersuites(ciphersuites) != 1:
|
||||||
raiseSSLError()
|
raiseSSLError()
|
||||||
# Automatically the best ECDH curve for client exchange. Without this, ECDH
|
# Automatically the best ECDH curve for client exchange. Without this, ECDH
|
||||||
# ciphers will be ignored by the server.
|
# ciphers will be ignored by the server.
|
||||||
|
|
|
||||||
|
|
@ -887,7 +887,7 @@ proc reversed*(s: openArray[char]): string =
|
||||||
|
|
||||||
proc graphemeLen*(s: openArray[char]; i: Natural): Natural =
|
proc graphemeLen*(s: openArray[char]; i: Natural): Natural =
|
||||||
## The number of bytes belonging to byte index ``s[i]``,
|
## The number of bytes belonging to byte index ``s[i]``,
|
||||||
## including following combining code unit.
|
## including following combining code units.
|
||||||
runnableExamples:
|
runnableExamples:
|
||||||
let a = "añyóng"
|
let a = "añyóng"
|
||||||
doAssert a.graphemeLen(1) == 2 ## ñ
|
doAssert a.graphemeLen(1) == 2 ## ñ
|
||||||
|
|
|
||||||
|
|
@ -467,10 +467,10 @@ else:
|
||||||
raiseInvalidLibrary MainProc
|
raiseInvalidLibrary MainProc
|
||||||
|
|
||||||
proc SSL_CTX_set_ciphersuites*(ctx: SslCtx, str: cstring): cint =
|
proc SSL_CTX_set_ciphersuites*(ctx: SslCtx, str: cstring): cint =
|
||||||
var theProc {.global.}: proc(ctx: SslCtx, str: cstring) {.cdecl, gcsafe.}
|
var theProc {.global.}: proc(ctx: SslCtx, str: cstring): cint {.cdecl, gcsafe.}
|
||||||
if theProc.isNil:
|
if theProc.isNil:
|
||||||
theProc = cast[typeof(theProc)](sslSymThrows("SSL_CTX_set_ciphersuites"))
|
theProc = cast[typeof(theProc)](sslSymThrows("SSL_CTX_set_ciphersuites"))
|
||||||
theProc(ctx, str)
|
result = theProc(ctx, str)
|
||||||
|
|
||||||
proc SSL_new*(context: SslCtx): SslPtr{.cdecl, dynlib: DLLSSLName, importc.}
|
proc SSL_new*(context: SslCtx): SslPtr{.cdecl, dynlib: DLLSSLName, importc.}
|
||||||
proc SSL_free*(ssl: SslPtr){.cdecl, dynlib: DLLSSLName, importc.}
|
proc SSL_free*(ssl: SslPtr){.cdecl, dynlib: DLLSSLName, importc.}
|
||||||
|
|
|
||||||
Loading…
Add table
Add a link
Reference in a new issue