b=95987 r=relyea sr=sfraser a=asa

Fixing SSL crash by disabling ciphers
This commit is contained in:
kaie%netscape.com 2001-08-23 04:58:27 +00:00
parent 05a31115ed
commit 65bfe90ec3

View File

@ -467,6 +467,13 @@ nsNSSComponent::InitializeNSS()
NSS_InitReadWrite(profileStr);
NSS_SetDomesticPolicy();
// SSL_EnableCipher(SSL_RSA_WITH_NULL_MD5, SSL_ALLOWED);
// temporarily disabling Diffie Hellman ciphers, see bug 95987
SSL_CipherPolicySet(SSL_DHE_RSA_WITH_DES_CBC_SHA, SSL_NOT_ALLOWED);
SSL_CipherPolicySet(SSL_DHE_DSS_WITH_DES_CBC_SHA, SSL_NOT_ALLOWED);
SSL_CipherPolicySet(SSL_DHE_RSA_WITH_3DES_EDE_CBC_SHA, SSL_NOT_ALLOWED);
SSL_CipherPolicySet(SSL_DHE_DSS_WITH_3DES_EDE_CBC_SHA, SSL_NOT_ALLOWED);
SSL_CipherPolicySet(TLS_DHE_DSS_WITH_RC4_128_SHA, SSL_NOT_ALLOWED);
mPref = do_GetService(NS_PREF_CONTRACTID);