summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDarren Tucker <dtucker@zip.com.au>2013-06-11 11:47:24 +1000
committerDarren Tucker <dtucker@zip.com.au>2013-06-11 11:47:24 +1000
commit97b62f41adcb0dcbeff142d0540793a7ea17c910 (patch)
tree72760674310073300403bc8a3f864323ee9323a3
parent6d8bd57448b45b42809da32857d7804444349ee7 (diff)
- (dtucker) [myproposal.h] Do not advertise AES GSM ciphers if we don't have
the required OpenSSL support. Patch from naddy at freebsd.
-rw-r--r--ChangeLog2
-rw-r--r--myproposal.h9
2 files changed, 10 insertions, 1 deletions
diff --git a/ChangeLog b/ChangeLog
index a7ab9a693..6805e8a10 100644
--- a/ChangeLog
+++ b/ChangeLog
@@ -11,6 +11,8 @@
11 bz#1917, also reported and tested by tedu@. ok djm@ markus@. 11 bz#1917, also reported and tested by tedu@. ok djm@ markus@.
12 - (dtucker) [Makefile.in configure.ac fixalgorithms] Remove unsupported 12 - (dtucker) [Makefile.in configure.ac fixalgorithms] Remove unsupported
13 algorithms (Ciphers, MACs and HostKeyAlgorithms) from man pages. 13 algorithms (Ciphers, MACs and HostKeyAlgorithms) from man pages.
14 - (dtucker) [myproposal.h] Do not advertise AES GSM ciphers if we don't have
15 the required OpenSSL support. Patch from naddy at freebsd.
14 16
1520130605 1720130605
16 - (dtucker) [myproposal.h] Enable sha256 kex methods based on the presence of 18 - (dtucker) [myproposal.h] Enable sha256 kex methods based on the presence of
diff --git a/myproposal.h b/myproposal.h
index f13c74850..276108bf6 100644
--- a/myproposal.h
+++ b/myproposal.h
@@ -45,6 +45,13 @@
45# define HOSTKEY_ECDSA_METHODS 45# define HOSTKEY_ECDSA_METHODS
46#endif 46#endif
47 47
48#ifdef OPENSSL_HAVE_EVPGCM
49# define AESGCM_CIPHER_MODES \
50 "aes128-gcm@openssh.com,aes256-gcm@openssh.com,"
51#else
52# define AESGCM_CIPHER_MODES
53#endif
54
48/* Old OpenSSL doesn't support what we need for DHGEX-sha256 */ 55/* Old OpenSSL doesn't support what we need for DHGEX-sha256 */
49#ifdef HAVE_EVP_SHA256 56#ifdef HAVE_EVP_SHA256
50# define KEX_SHA256_METHODS \ 57# define KEX_SHA256_METHODS \
@@ -73,7 +80,7 @@
73#define KEX_DEFAULT_ENCRYPT \ 80#define KEX_DEFAULT_ENCRYPT \
74 "aes128-ctr,aes192-ctr,aes256-ctr," \ 81 "aes128-ctr,aes192-ctr,aes256-ctr," \
75 "arcfour256,arcfour128," \ 82 "arcfour256,arcfour128," \
76 "aes128-gcm@openssh.com,aes256-gcm@openssh.com," \ 83 AESGCM_CIPHER_MODES \
77 "aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc," \ 84 "aes128-cbc,3des-cbc,blowfish-cbc,cast128-cbc," \
78 "aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se" 85 "aes192-cbc,aes256-cbc,arcfour,rijndael-cbc@lysator.liu.se"
79#ifdef HAVE_EVP_SHA256 86#ifdef HAVE_EVP_SHA256