Dr. Stephen Henson
08a88774bd
Only allow ephemeral RSA keys in export ciphersuites.
...
OpenSSL clients would tolerate temporary RSA keys in non-export
ciphersuites. It also had an option SSL_OP_EPHEMERAL_RSA which
enabled this server side. Remove both options as they are a
protocol violation.
Thanks to Karthikeyan Bhargavan for reporting this issue.
(CVE-2015-0204)
Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: Tim Hudson <tjh@openssl.org>
(cherry picked from commit 4b4c1fcc88aec8c9e001b0a0077d3cd4de1ed0e6)
Conflicts:
CHANGES
doc/ssl/SSL_CTX_set_options.pod
2015-01-06 13:18:46 +00:00
..
2005-04-11 14:17:07 +00:00
2012-04-16 17:43:28 +00:00
2014-12-16 00:11:02 +00:00
2014-12-15 21:29:49 +00:00
2014-11-27 21:58:31 +00:00
2014-12-04 14:25:09 +00:00
2005-08-14 21:48:33 +00:00
2014-11-27 21:58:31 +00:00
2015-01-06 13:18:46 +00:00
2014-12-03 09:43:47 +00:00
2011-03-19 09:44:53 +00:00
2009-04-21 22:20:12 +00:00
2010-03-03 15:41:00 +00:00
2014-02-26 15:33:31 +00:00
2014-09-24 15:58:20 +02:00
2013-02-05 16:46:15 +00:00
2014-11-27 21:58:32 +00:00
2014-10-15 04:05:57 +02:00
2008-10-12 14:32:47 +00:00
2014-11-27 21:58:32 +00:00
2014-12-13 00:06:10 +00:00
2014-11-28 23:31:53 +01:00
2014-09-24 14:35:03 +02:00
2015-01-06 13:18:46 +00:00
2014-11-27 21:58:31 +00:00
2014-12-16 10:22:20 +00:00
2008-10-12 14:32:47 +00:00
2014-11-27 21:58:31 +00:00
2015-01-06 13:18:46 +00:00
2014-10-15 08:49:50 -04:00
2014-06-27 16:52:10 +01:00
2006-01-15 17:35:28 +00:00
2002-07-10 07:01:54 +00:00
2014-12-13 00:06:10 +00:00
2001-11-10 01:16:28 +00:00
2014-10-15 04:05:57 +02:00
1998-12-21 10:56:39 +00:00
2013-02-05 16:46:17 +00:00
2014-05-08 00:04:16 +01:00
2014-11-27 20:55:52 +00:00
2014-07-14 18:31:54 +01:00
2001-02-20 08:13:47 +00:00
2014-10-15 04:05:57 +02:00
2014-12-08 16:51:01 +00:00
2014-12-03 09:43:47 +00:00
2009-09-12 23:09:26 +00:00
2010-02-01 16:49:42 +00:00
2014-06-28 00:56:59 +01:00
2002-11-13 15:43:43 +00:00
2009-06-30 22:26:28 +00:00
2014-10-15 11:32:17 +02:00
2015-01-06 13:18:46 +00:00
2013-02-11 18:27:06 +00:00
2005-08-14 21:48:33 +00:00
2014-10-15 04:05:57 +02:00
2014-10-15 08:49:50 -04:00
2005-08-14 21:48:33 +00:00
2009-12-27 22:59:09 +00:00
2005-08-14 21:48:33 +00:00
2014-10-15 04:25:41 +02:00