Issue #2180 - Add pref to control NSS TLS 1.3 protocol downgrade sentinel

This commit is contained in:
Moonchild 2023-03-28 13:36:37 +02:00 committed by roytam1
commit dc4bf9b823
2 changed files with 23 additions and 1 deletions

View file

@ -1444,6 +1444,7 @@ static const bool NPN_ENABLED_DEFAULT = true;
static const bool ALPN_ENABLED_DEFAULT = false;
static const bool ENABLED_0RTT_DATA_DEFAULT = false;
static const bool TLS13_COMPAT_MODE_DEFAULT = false;
static const bool HELLO_DOWNGRADE_CHECK_DEFAULT = true;
static void
ConfigureTLSSessionIdentifiers()
@ -1857,7 +1858,7 @@ nsNSSComponent::InitializeNSS()
SSL_OptionSetDefault(SSL_ENABLE_RENEGOTIATION, SSL_RENEGOTIATE_REQUIRES_XTN);
SSL_OptionSetDefault(SSL_ENABLE_EXTENDED_MASTER_SECRET, true);
SSL_OptionSetDefault(SSL_ENABLE_FALSE_START,
Preferences::GetBool("security.ssl.enable_false_start",
FALSE_START_ENABLED_DEFAULT));
@ -1881,6 +1882,13 @@ nsNSSComponent::InitializeNSS()
SSL_OptionSetDefault(SSL_ENABLE_TLS13_COMPAT_MODE,
Preferences::GetBool("security.ssl.enable_tls13_compat_mode",
TLS13_COMPAT_MODE_DEFAULT));
// Set TLS 1.3 hello downgrade sentinel?
bool enableDowngradeCheck =
Preferences::GetBool("security.tls.hello_downgrade_check",
HELLO_DOWNGRADE_CHECK_DEFAULT);
SSL_OptionSetDefault(SSL_ENABLE_HELLO_DOWNGRADE_CHECK, enableDowngradeCheck);
if (NS_FAILED(InitializeCipherSuite())) {
@ -2044,6 +2052,11 @@ nsNSSComponent::Observe(nsISupports* aSubject, const char* aTopic,
if (prefName.EqualsLiteral("security.tls.version.min") ||
prefName.EqualsLiteral("security.tls.version.max")) {
(void) setEnabledTLSVersions();
} else if (prefName.EqualsLiteral("security.tls.hello_downgrade_check")) {
bool enableDowngradeCheck =
Preferences::GetBool("security.tls.hello_downgrade_check",
HELLO_DOWNGRADE_CHECK_DEFAULT);
SSL_OptionSetDefault(SSL_ENABLE_HELLO_DOWNGRADE_CHECK, enableDowngradeCheck);
} else if (prefName.EqualsLiteral("security.ssl.require_safe_negotiation")) {
bool requireSafeNegotiation =
Preferences::GetBool("security.ssl.require_safe_negotiation",