]> code.ossystems Code Review - openembedded-core.git/commitdiff
openssl: disable SSLv3 by default
authorBrendan Le Foll <brendan.le.foll@intel.com>
Mon, 16 Feb 2015 11:18:29 +0000 (11:18 +0000)
committerRichard Purdie <richard.purdie@linuxfoundation.org>
Thu, 19 Feb 2015 07:50:44 +0000 (07:50 +0000)
Because of the SSLv3 POODLE vulnerability, it's preferred to simply disable
SSLv3 even if patched with the TLS_FALLBACK_SCSV

Signed-off-by: Brendan Le Foll <brendan.le.foll@intel.com>
Signed-off-by: Richard Purdie <richard.purdie@linuxfoundation.org>
meta/recipes-connectivity/openssl/openssl.inc

index 6eb1b5eac9982e266557dc9217782ffe203dae4b..ba9bca6af4a0bb328ec3f9d24c451ef1f427e751 100644 (file)
@@ -50,6 +50,10 @@ CONFFILES_openssl-conf = "${libdir}/ssl/openssl.cnf"
 RRECOMMENDS_libcrypto += "openssl-conf"
 RDEPENDS_${PN}-ptest += "${PN}-misc make perl perl-module-filehandle bc"
 
+# Remove this to enable SSLv3. SSLv3 is defaulted to disabled due to the POODLE
+# vulnerability
+EXTRA_OECONF = " -no-ssl3"
+
 do_configure_prepend_darwin () {
        sed -i -e '/version-script=openssl\.ld/d' Configure
 }