net: enable automatic EC curve selection for OpenSSL 1.0.2

This setting is required for servers running OpenSSL < 1.1.0 to support
EC-based secure ciphers that is now part of the default cipher list.
This commit is contained in:
Leorize 2020-06-04 00:01:13 -05:00 • committed by Andreas Rumpf
commit 6c0f86c486
2 changed files with 23 additions and 0 deletions

View file

@ -580,6 +580,13 @@ when defineSsl:
if newCTX.SSL_CTX_set_cipher_list(cipherList) != 1:
raiseSSLError()
# Automatically the best ECDH curve for client exchange. Without this, ECDH
# ciphers will be ignored by the server.
#
# From OpenSSL >= 1.1.0, this setting is set by default and can't be
# overriden.
if newCTX.SSL_CTX_set_ecdh_auto(1) != 1:
raiseSSLError()
when defined(nimDisableCertificateValidation) or defined(windows):
newCTX.SSL_CTX_set_verify(SSL_VERIFY_NONE, nil)