net: use a secure cipher list by default
Previously, the `net` module use the blanket "ALL" as the default cipher list. This list may contain security ciphers that are weak and/or outdated according to the current standard. This commit introduces a new module `ssl_config` that contains the latest OpenSSL configurations as recommended by Mozilla OpSec, and make the `net` module use the cipher list targeting `intermediate` compatibility level as the default.
This commit is contained in:
parent
6cb94b5da6
commit
1fb2a58674
5 changed files with 125 additions and 1 deletions
|
|
@ -68,6 +68,7 @@ import std/private/since
|
|||
|
||||
import nativesockets, os, strutils, times, sets, options, std/monotimes
|
||||
from ssl_certs import scanSSLCertificates
|
||||
import ssl_config
|
||||
export nativesockets.Port, nativesockets.`$`, nativesockets.`==`
|
||||
export Domain, SockType, Protocol
|
||||
|
||||
|
|
@ -533,7 +534,7 @@ when defineSsl:
|
|||
raiseSSLError("Verification of private key file failed.")
|
||||
|
||||
proc newContext*(protVersion = protSSLv23, verifyMode = CVerifyPeer,
|
||||
certFile = "", keyFile = "", cipherList = "ALL",
|
||||
certFile = "", keyFile = "", cipherList = CiphersIntermediate,
|
||||
caDir = "", caFile = ""): SSLContext =
|
||||
## Creates an SSL context.
|
||||
##
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue