net: enable automatic EC curve selection for OpenSSL 1.0.2
This setting is required for servers running OpenSSL < 1.1.0 to support EC-based secure ciphers that is now part of the default cipher list.
This commit is contained in:
parent
9278e785bd
commit
6c0f86c486
2 changed files with 23 additions and 0 deletions
|
|
@ -580,6 +580,13 @@ when defineSsl:
|
|||
|
||||
if newCTX.SSL_CTX_set_cipher_list(cipherList) != 1:
|
||||
raiseSSLError()
|
||||
# Automatically the best ECDH curve for client exchange. Without this, ECDH
|
||||
# ciphers will be ignored by the server.
|
||||
#
|
||||
# From OpenSSL >= 1.1.0, this setting is set by default and can't be
|
||||
# overriden.
|
||||
if newCTX.SSL_CTX_set_ecdh_auto(1) != 1:
|
||||
raiseSSLError()
|
||||
|
||||
when defined(nimDisableCertificateValidation) or defined(windows):
|
||||
newCTX.SSL_CTX_set_verify(SSL_VERIFY_NONE, nil)
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue