Don't use weak ciphers for client HTTPS connections

https://pagure.io/freeipa/issue/6730

Reviewed-By: Martin Basti <mbasti@redhat.com>
This commit is contained in:
Stanislav Laznicka
2017-03-09 10:27:55 +01:00
committed by Tomas Krizek
parent 61cd4372e1
commit fda22c3344
2 changed files with 8 additions and 1 deletions
+5 -1
View File
@@ -52,7 +52,7 @@ except ImportError:
from ipalib import errors, messages
from ipalib.constants import (
DOMAIN_LEVEL_0,
TLS_VERSIONS, TLS_VERSION_MINIMAL
TLS_VERSIONS, TLS_VERSION_MINIMAL, TLS_HIGH_CIPHERS
)
from ipalib.text import _
from ipapython.ssh import SSHPublicKey
@@ -303,6 +303,10 @@ def create_https_connection(
ssl.OP_SINGLE_ECDH_USE
)
# high ciphers without RC4, MD5, TripleDES, pre-shared key
# and secure remote password
ctx.set_ciphers(TLS_HIGH_CIPHERS)
# pylint: enable=no-member
# set up the correct TLS version flags for the SSL context
for version in TLS_VERSIONS: