Browse Source

Merge pull request #1306 from jonboulle/tls

pkg: set minimum TLS version to 1.0 (disable SSL3)
Jonathan Boulle 11 years ago
parent
commit
c18acd7d6f
1 changed files with 5 additions and 3 deletions
  1. 5 3
      pkg/transport/listener.go

+ 5 - 3
pkg/transport/listener.go

@@ -89,9 +89,11 @@ func (info TLSInfo) baseConfig() (*tls.Config, error) {
 		return nil, err
 	}
 
-	var cfg tls.Config
-	cfg.Certificates = []tls.Certificate{tlsCert}
-	return &cfg, nil
+	cfg := &tls.Config{
+		Certificates: []tls.Certificate{tlsCert},
+		MinVersion:   tls.VersionTLS10,
+	}
+	return cfg, nil
 }
 
 // ServerConfig generates a tls.Config object for use by an HTTP server