mirror of
https://repo.dactyloidae.xyz/Dactyloidae/UXP.git
synced 2026-09-04 14:58:37 +09:00
Issue #2180 - Add pref to control NSS TLS 1.3 protocol downgrade sentinel
This commit is contained in:
parent
ca93d4b42d
commit
dc4bf9b823
2 changed files with 23 additions and 1 deletions
|
|
@ -1444,6 +1444,7 @@ static const bool NPN_ENABLED_DEFAULT = true;
|
|||
static const bool ALPN_ENABLED_DEFAULT = false;
|
||||
static const bool ENABLED_0RTT_DATA_DEFAULT = false;
|
||||
static const bool TLS13_COMPAT_MODE_DEFAULT = false;
|
||||
static const bool HELLO_DOWNGRADE_CHECK_DEFAULT = true;
|
||||
|
||||
static void
|
||||
ConfigureTLSSessionIdentifiers()
|
||||
|
|
@ -1857,7 +1858,7 @@ nsNSSComponent::InitializeNSS()
|
|||
SSL_OptionSetDefault(SSL_ENABLE_RENEGOTIATION, SSL_RENEGOTIATE_REQUIRES_XTN);
|
||||
|
||||
SSL_OptionSetDefault(SSL_ENABLE_EXTENDED_MASTER_SECRET, true);
|
||||
|
||||
|
||||
SSL_OptionSetDefault(SSL_ENABLE_FALSE_START,
|
||||
Preferences::GetBool("security.ssl.enable_false_start",
|
||||
FALSE_START_ENABLED_DEFAULT));
|
||||
|
|
@ -1881,6 +1882,13 @@ nsNSSComponent::InitializeNSS()
|
|||
SSL_OptionSetDefault(SSL_ENABLE_TLS13_COMPAT_MODE,
|
||||
Preferences::GetBool("security.ssl.enable_tls13_compat_mode",
|
||||
TLS13_COMPAT_MODE_DEFAULT));
|
||||
|
||||
// Set TLS 1.3 hello downgrade sentinel?
|
||||
bool enableDowngradeCheck =
|
||||
Preferences::GetBool("security.tls.hello_downgrade_check",
|
||||
HELLO_DOWNGRADE_CHECK_DEFAULT);
|
||||
SSL_OptionSetDefault(SSL_ENABLE_HELLO_DOWNGRADE_CHECK, enableDowngradeCheck);
|
||||
|
||||
|
||||
if (NS_FAILED(InitializeCipherSuite())) {
|
||||
|
||||
|
|
@ -2044,6 +2052,11 @@ nsNSSComponent::Observe(nsISupports* aSubject, const char* aTopic,
|
|||
if (prefName.EqualsLiteral("security.tls.version.min") ||
|
||||
prefName.EqualsLiteral("security.tls.version.max")) {
|
||||
(void) setEnabledTLSVersions();
|
||||
} else if (prefName.EqualsLiteral("security.tls.hello_downgrade_check")) {
|
||||
bool enableDowngradeCheck =
|
||||
Preferences::GetBool("security.tls.hello_downgrade_check",
|
||||
HELLO_DOWNGRADE_CHECK_DEFAULT);
|
||||
SSL_OptionSetDefault(SSL_ENABLE_HELLO_DOWNGRADE_CHECK, enableDowngradeCheck);
|
||||
} else if (prefName.EqualsLiteral("security.ssl.require_safe_negotiation")) {
|
||||
bool requireSafeNegotiation =
|
||||
Preferences::GetBool("security.ssl.require_safe_negotiation",
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue