Re: Cipher list presented by wpa_supplicant does not reflect type of ca_cert used, causes authentication failures

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

 



> What we really want is the union of the server's acceptable ciphers and the clients acceptable ciphers, I don't think OpenSSL is calculating this irrespective of SSL_OP_CIPHER_SERVER_PREFERENCE, but i'd need to investigate more.  This issue is orthogonal to the next issue and something we'll deal with internally.

It really seems like it will be the union of the ciphers set by SSL_CTX_set_cipher_list, and cipher list presented by the client.

I don't think the contributor really understood what that option did.  I'm setting the default to disable it in FreeRADIUS and adding big warnings.

-Arran
_______________________________________________
Hostap mailing list
Hostap@xxxxxxxxxxxxxxxxxxx
http://lists.infradead.org/mailman/listinfo/hostap



[Index of Archives]     [Linux Wireless]     [Linux Kernel]     [ATH6KL]     [Linux Bluetooth]     [Linux Netdev]     [Kernel Newbies]     [IDE]     [Security]     [Git]     [Netfilter]     [Bugtraq]     [Yosemite News]     [MIPS Linux]     [ARM Linux]     [Linux Security]     [Linux RAID]     [Linux ATA RAID]     [Samba]     [Device Mapper]

  Powered by Linux