Add cipher selection for TV 40/189340/3 submit/tizen_base/20180918.070325
authorSeonah Moon <seonah1.moon@samsung.com>
Mon, 17 Sep 2018 06:39:17 +0000 (15:39 +0900)
committerSeonah Moon <seonah1.moon@samsung.com>
Tue, 18 Sep 2018 06:54:24 +0000 (15:54 +0900)
ipv6 option will be enabled next commit

Change-Id: Ie0e32617cf8140b6267b82548bc9b531de2f09d5

lib/vtls/openssl.c

index 2a6b3cfacb25846449c8f6a2e0e095f2bfb2d289..04c4e399b70d478a7e7dfe54e0c217941a9f29d7 100644 (file)
@@ -164,7 +164,18 @@ static unsigned long OpenSSL_version_num(void)
 #define OSSL_PACKAGE "OpenSSL"
 #endif
 
-#if (OPENSSL_VERSION_NUMBER >= 0x10100000L)
+#if defined (TIZEN_TV_EXT)
+#define DEFAULT_CIPHER_SELECTION \
+"ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA:ECDHE-ECDSA-AES256-SHA:" \
+"DHE-RSA-AES256-SHA:DHE-DSS-AES256-SHA:ECDH-RSA-AES256-SHA:" \
+"ECDH-ECDSA-AES256-SHA:AES256-SHA:ECDHE-RSA-AES128-GCM-SHA256:" \
+"ECDHE-ECDSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA:ECDHE-ECDSA-AES128-SHA:" \
+"DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA:" \
+"AES128-GCM-SHA256:AES128-SHA256:AES128-SHA:" \
+"ECDHE-RSA-DES-CBC3-SHA:ECDHE-ECDSA-DES-CBC3-SHA:EDH-RSA-DES-CBC3-SHA:" \
+"EDH-DSS-DES-CBC3-SHA:ECDH-RSA-DES-CBC3-SHA:ECDH-ECDSA-DES-CBC3-SHA:" \
+"DES-CBC3-SHA:ECDHE-RSA-RC4-SHA:ECDHE-ECDSA-RC4-SHA"
+#elif (OPENSSL_VERSION_NUMBER >= 0x10100000L)
 /* up2date versions of OpenSSL maintain the default reasonably secure without
  * breaking compatibility, so it is better not to override the default by curl
  */