Browse Source

tighten default TLS parameters

master
Philipp Balzarek 13 years ago
parent
commit
df4dc7b41f
  1. 10
      source/Network/Xmpp/Tls.hs

10
source/Network/Xmpp/Tls.hs

@ -39,13 +39,9 @@ starttlsE = Element "{urn:ietf:params:xml:ns:xmpp-tls}starttls" [] []
exampleParams :: TLSParams exampleParams :: TLSParams
exampleParams = defaultParamsClient exampleParams = defaultParamsClient
{ pConnectVersion = TLS10 { pConnectVersion = TLS12
, pAllowedVersions = [SSL3, TLS10, TLS11] , pAllowedVersions = [TLS12]
, pCiphers = [cipher_AES128_SHA1] , pCiphers = ciphersuite_strong
, pCompressions = [nullCompression]
, pUseSecureRenegotiation = False -- No renegotiation
, onCertificatesRecv = \_certificate ->
return CertificateUsageAccept
} }
-- Pushes "<starttls/>, waits for "<proceed/>", performs the TLS handshake, and -- Pushes "<starttls/>, waits for "<proceed/>", performs the TLS handshake, and

Loading…
Cancel
Save