From f6ca45b1bab63cbb75d81de3c17b8e7c43983acc Mon Sep 17 00:00:00 2001 From: Nikolai Kondrashov Date: Mon, 26 Sep 2016 19:48:36 +0300 Subject: [PATCH] Use system crypto policy by default --- raddb/mods-available/eap | 2 +- raddb/mods-available/inner-eap | 2 +- raddb/sites-available/abfab-tls | 2 +- raddb/sites-available/tls | 4 ++-- 4 files changed, 5 insertions(+), 5 deletions(-) diff --git a/raddb/mods-available/eap b/raddb/mods-available/eap index 5c99b09d4..83b5f95c7 100644 --- a/raddb/mods-available/eap +++ b/raddb/mods-available/eap @@ -323,7 +323,7 @@ eap { # # For EAP-FAST, use "ALL:!EXPORT:!eNULL:!SSLv2" # - cipher_list = "DEFAULT" + cipher_list = "PROFILE=SYSTEM" # Work-arounds for OpenSSL nonsense # OpenSSL 1.0.1f and 1.0.1g do not calculate diff --git a/raddb/mods-available/inner-eap b/raddb/mods-available/inner-eap index 2b4df6267..af9aa88cd 100644 --- a/raddb/mods-available/inner-eap +++ b/raddb/mods-available/inner-eap @@ -68,7 +68,7 @@ eap inner-eap { # certificates. If so, edit this file. ca_file = ${cadir}/ca.pem - cipher_list = "DEFAULT" + cipher_list = "PROFILE=SYSTEM" # You may want to set a very small fragment size. # The TLS data here needs to go inside of the diff --git a/raddb/sites-available/abfab-tls b/raddb/sites-available/abfab-tls index 79d74e6fc..d04d6be89 100644 --- a/raddb/sites-available/abfab-tls +++ b/raddb/sites-available/abfab-tls @@ -19,7 +19,7 @@ listen { dh_file = ${certdir}/dh fragment_size = 8192 ca_path = ${cadir} - cipher_list = "DEFAULT" + cipher_list = "PROFILE=SYSTEM" cache { enable = no diff --git a/raddb/sites-available/tls b/raddb/sites-available/tls index eb60fa57b..9b340d2af 100644 --- a/raddb/sites-available/tls +++ b/raddb/sites-available/tls @@ -197,7 +197,7 @@ listen { # Set this option to specify the allowed # TLS cipher suites. The format is listed # in "man 1 ciphers". - cipher_list = "DEFAULT" + cipher_list = "PROFILE=SYSTEM" # # Session resumption / fast reauthentication @@ -493,7 +493,7 @@ home_server tls { # Set this option to specify the allowed # TLS cipher suites. The format is listed # in "man 1 ciphers". - cipher_list = "DEFAULT" + cipher_list = "PROFILE=SYSTEM" } } -- 2.11.0