gnutls: Change the GnuTLS priority string from NORMAL to SECURE256
authorJosh Rickmar <jrick@devio.us>
Fri, 8 Jun 2012 16:57:00 +0000 (12:57 -0400)
committerDan Winship <danw@gnome.org>
Tue, 12 Jun 2012 14:36:54 +0000 (10:36 -0400)
Prefer 256-bit AES to 128-bit, like Firefox does

https://bugzilla.gnome.org/show_bug.cgi?id=677717

tls/gnutls/gtlsconnection-gnutls.c

index b8fc86c..1db7914 100644 (file)
@@ -150,16 +150,16 @@ g_tls_connection_gnutls_init_priorities (void)
   /* First field is "ssl3 only", second is "allow unsafe rehandshaking" */
 
   gnutls_priority_init (&priorities[FALSE][FALSE],
-                       "NORMAL:%COMPAT",
+                       "SECURE256:%COMPAT",
                        NULL);
   gnutls_priority_init (&priorities[TRUE][FALSE],
-                       "NORMAL:%COMPAT:!VERS-TLS1.2:!VERS-TLS1.1:!VERS-TLS1.0",
+                       "SECURE256:%COMPAT:!VERS-TLS1.2:!VERS-TLS1.1:!VERS-TLS1.0",
                        NULL);
   gnutls_priority_init (&priorities[FALSE][TRUE],
-                       "NORMAL:%COMPAT:%UNSAFE_RENEGOTIATION",
+                       "SECURE256:%COMPAT:%UNSAFE_RENEGOTIATION",
                        NULL);
   gnutls_priority_init (&priorities[TRUE][TRUE],
-                       "NORMAL:%COMPAT:!VERS-TLS1.2:!VERS-TLS1.1:!VERS-TLS1.0:%UNSAFE_RENEGOTIATION",
+                       "SECURE256:%COMPAT:!VERS-TLS1.2:!VERS-TLS1.1:!VERS-TLS1.0:%UNSAFE_RENEGOTIATION",
                        NULL);
 }