From 48fa1ecf79fae8ae33967deedce8d8be86dea340 Mon Sep 17 00:00:00 2001 From: Simon Ruderich Date: Mon, 6 Jan 2014 01:50:42 +0100 Subject: [PATCH] Disable RC4. --- src/tlsproxy.h | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/tlsproxy.h b/src/tlsproxy.h index 7bd573b..af58ff2 100644 --- a/src/tlsproxy.h +++ b/src/tlsproxy.h @@ -57,6 +57,8 @@ "SECURE" \ /* Lower priority of SHA-1, user better hashes if possible. */ \ ":-SHA1:+SHA1" \ + /* No RC4, it's broken. */ \ + ":-ARCFOUR-40:-ARCFOUR-128" \ /* Force safe renegotiations. Shouldn't cause any problems as this \ * option only affects the server side (with GnuTLS defaults) and the \ * local clients most-likely already support safe renegotiations (old \ -- 2.43.2