net: use a secure cipher list by default

Previously, the `net` module use the blanket "ALL" as the default cipher
list. This list may contain security ciphers that are weak and/or outdated
according to the current standard.

This commit introduces a new module `ssl_config` that contains the
latest OpenSSL configurations as recommended by Mozilla OpSec, and
make the `net` module use the cipher list targeting `intermediate`
compatibility level as the default.
This commit is contained in:
Leorize 2020-06-03 17:02:18 -05:00 • committed by Andreas Rumpf
commit 1fb2a58674
5 changed files with 125 additions and 1 deletions

View file

@ -68,6 +68,7 @@ import std/private/since
import nativesockets, os, strutils, times, sets, options, std/monotimes
from ssl_certs import scanSSLCertificates
import ssl_config
export nativesockets.Port, nativesockets.`$`, nativesockets.`==`
export Domain, SockType, Protocol
@ -533,7 +534,7 @@ when defineSsl:
raiseSSLError("Verification of private key file failed.")
proc newContext*(protVersion = protSSLv23, verifyMode = CVerifyPeer,
certFile = "", keyFile = "", cipherList = "ALL",
certFile = "", keyFile = "", cipherList = CiphersIntermediate,
caDir = "", caFile = ""): SSLContext =
## Creates an SSL context.
##