X-Git-Url: https://ruderich.org/simon/gitweb/?a=blobdiff_plain;f=src%2Ftlsproxy.h;h=33df814f622331f3b6ab464858fd749c19758f26;hb=caf3e07bab2e42bd10fe7966542a37b41f336a0a;hp=f93be4609f9573fe49b578c3227a99222eae46d9;hpb=a8a45901f08376d0f4b8a6fe72d2cc90e2fc991e;p=tlsproxy%2Ftlsproxy.git diff --git a/src/tlsproxy.h b/src/tlsproxy.h index f93be46..33df814 100644 --- a/src/tlsproxy.h +++ b/src/tlsproxy.h @@ -30,6 +30,7 @@ #include "log.h" + /* Length for path arrays. */ #define TLSPROXY_MAX_PATH_LENGTH 1024 @@ -49,6 +50,13 @@ * certificate. */ #define STORED_SERVER_CERT_FILE_FORMAT "./certificate-%s-server.pem" +/* GnuTLS priority string used for both server and client connections. */ +#define PROXY_TLS_PRIORITIES \ + /* Don't use known insecure algorithms. */ \ + "SECURE" \ + /* Lower priority of SHA-1, user better hashes if possible. */ \ + ":-SHA1:+SHA1" + /* Proxy hostname and port if specified on the command line. */ char *global_proxy_host;