瀏覽代碼

crypto/tls: change default minimum version to TLS 1.0.

SSLv3 (the old minimum) is still supported and can be enabled via the
tls.Config, but this change increases the default minimum version to TLS
1.0. This is now common practice in light of the POODLE[1] attack
against SSLv3's CBC padding format.

[1] https://www.imperialviolet.org/2014/10/14/poodle.html

Fixes #9364.

Change-Id: Ibae6666ee038ceee0cb18c339c393155928c6510
Reviewed-on: https://go-review.googlesource.com/1791
Reviewed-by: Minux Ma <minux@golang.org>
tls13
Adam Langley 9 年之前
父節點
當前提交
0511e2597e
共有 1 個檔案被更改,包括 1 行新增1 行删除
  1. +1
    -1
      common.go

+ 1
- 1
common.go 查看文件

@@ -30,7 +30,7 @@ const (
recordHeaderLen = 5 // record header length
maxHandshake = 65536 // maximum handshake we support (protocol max is 16 MB)

minVersion = VersionSSL30
minVersion = VersionTLS10
maxVersion = VersionTLS12
)



Loading…
取消
儲存