aboutsummaryrefslogtreecommitdiff
path: root/contrib/sendmail
diff options
context:
space:
mode:
authorGregory Neil Shapiro <gshapiro@FreeBSD.org>2015-06-23 04:33:54 +0000
committerGregory Neil Shapiro <gshapiro@FreeBSD.org>2015-06-23 04:33:54 +0000
commit3df48792f2060cabd1b4e2b805ead49ac6fa6966 (patch)
tree8d29bf12cf9bece5bb38645412991e48ee661631 /contrib/sendmail
parent90e528f838fe5d4ab6a9286126e954996ad3e4a7 (diff)
downloadsrc-3df48792f2060cabd1b4e2b805ead49ac6fa6966.tar.gz
src-3df48792f2060cabd1b4e2b805ead49ac6fa6966.zip
An additional fix for the openssl Weak DH remediation:
The import of openssl to address the FreeBSD-SA-15:10.openssl security advisory includes a change which rejects handshakes with DH parameters below 768 bits. sendmail releases prior to 8.15.2 (not yet released), defaulted to a 512 bit DH parameter setting for client connections. The first fix committed last week changed the default to 1024 bits. This commit fixes the case where the DHParameters option is set to a file which doesn't exist, which is the case on newer versions of FreeBSD which enable STARTTLS by default by auto-creating TLS certificates. MFC after: 2 days
Notes
Notes: svn path=/head/; revision=284717
Diffstat (limited to 'contrib/sendmail')
-rw-r--r--contrib/sendmail/src/sendmail.h2
1 files changed, 1 insertions, 1 deletions
diff --git a/contrib/sendmail/src/sendmail.h b/contrib/sendmail/src/sendmail.h
index 1a079c0e1538..07a58e9f921e 100644
--- a/contrib/sendmail/src/sendmail.h
+++ b/contrib/sendmail/src/sendmail.h
@@ -1935,7 +1935,7 @@ struct termescape
/* server requirements */
#define TLS_I_SRV (TLS_I_SRV_CERT | TLS_I_RSA_TMP | TLS_I_VRFY_PATH | \
- TLS_I_VRFY_LOC | TLS_I_TRY_DH | TLS_I_DH512 | \
+ TLS_I_VRFY_LOC | TLS_I_TRY_DH | TLS_I_DH1024 | \
TLS_I_CACHE)
/* client requirements */