cpython: 041a27298cf3 (original) (raw)
Mercurial > cpython
changeset 94688:041a27298cf3
merge 3.4 (#23481) [#23481]
Benjamin Peterson benjamin@python.org | |
---|---|
date | Thu, 19 Feb 2015 17:58:19 -0500 |
parents | 70a55b2dee71(current diff)c509e6f18d7d(diff) |
children | 7b63e7bc5b3d |
files | Lib/ssl.py Misc/NEWS |
diffstat | 2 files changed, 4 insertions(+), 4 deletions(-)[+] [-] Lib/ssl.py 6 Misc/NEWS 2 |
line wrap: on
line diff
--- a/Lib/ssl.py +++ b/Lib/ssl.py @@ -164,14 +164,12 @@ else:
* Prefer any AES-GCM over any AES-CBC for better performance and security
* Then Use HIGH cipher suites as a fallback
* Then Use 3DES as fallback which is secure but slow
-# * Finally use RC4 as a fallback which is problematic but needed for -# compatibility some times.
* Disable NULL authentication, NULL encryption, and MD5 MACs for security
reasons
_DEFAULT_CIPHERS = ( 'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:'
- 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:ECDH+RC4:'
- 'DH+RC4:RSA+RC4:!aNULL:!eNULL:!MD5'
Restricted and more secure ciphers for the server side
--- a/Misc/NEWS +++ b/Misc/NEWS @@ -13,6 +13,8 @@ Core and Builtins Library ------- +- Issue #23481: Remove RC4 from the SSL module's default cipher list. +