cpython: 3596081cfb55 (original) (raw)
Mercurial > cpython
changeset 94687:3596081cfb55 2.7
remove rc4 from the default client ciphers (closes #23481) [#23481]
Benjamin Peterson benjamin@python.org | |
---|---|
date | Thu, 19 Feb 2015 17:57:08 -0500 |
parents | ba2b0e6a888f |
children | a40481bbb62b |
files | Lib/ssl.py Misc/NEWS |
diffstat | 2 files changed, 4 insertions(+), 4 deletions(-)[+] [-] Lib/ssl.py 6 Misc/NEWS 2 |
line wrap: on
line diff
--- a/Lib/ssl.py +++ b/Lib/ssl.py @@ -157,14 +157,12 @@ else:
* Prefer any AES-GCM over any AES-CBC for better performance and security
* Then Use HIGH cipher suites as a fallback
* Then Use 3DES as fallback which is secure but slow
-# * Finally use RC4 as a fallback which is problematic but needed for -# compatibility some times.
* Disable NULL authentication, NULL encryption, and MD5 MACs for security
reasons
_DEFAULT_CIPHERS = ( 'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:'
- 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:ECDH+RC4:'
- 'DH+RC4:RSA+RC4:!aNULL:!eNULL:!MD5'