[Python-checkins] cpython (merge 3.4 -> default): merge 3.4 (#23481)
benjamin.peterson
python-checkins at python.org
Thu Feb 19 23:58:24 CET 2015
https://hg.python.org/cpython/rev/041a27298cf3
changeset: 94688:041a27298cf3
parent: 94685:70a55b2dee71
parent: 94686:c509e6f18d7d
user: Benjamin Peterson <benjamin at python.org>
date: Thu Feb 19 17:58:19 2015 -0500
summary:
merge 3.4 (#23481)
files:
Lib/ssl.py | 6 ++----
Misc/NEWS | 2 ++
2 files changed, 4 insertions(+), 4 deletions(-)
diff --git a/Lib/ssl.py b/Lib/ssl.py
--- a/Lib/ssl.py
+++ b/Lib/ssl.py
@@ -164,14 +164,12 @@
# * Prefer any AES-GCM over any AES-CBC for better performance and security
# * Then Use HIGH cipher suites as a fallback
# * Then Use 3DES as fallback which is secure but slow
-# * Finally use RC4 as a fallback which is problematic but needed for
-# compatibility some times.
# * Disable NULL authentication, NULL encryption, and MD5 MACs for security
# reasons
_DEFAULT_CIPHERS = (
'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:'
- 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:ECDH+RC4:'
- 'DH+RC4:RSA+RC4:!aNULL:!eNULL:!MD5'
+ 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:!aNULL:'
+ '!eNULL:!MD5'
)
# Restricted and more secure ciphers for the server side
diff --git a/Misc/NEWS b/Misc/NEWS
--- a/Misc/NEWS
+++ b/Misc/NEWS
@@ -13,6 +13,8 @@
Library
-------
+- Issue #23481: Remove RC4 from the SSL module's default cipher list.
+
- Issue #21548: Fix pydoc.synopsis() and pydoc.apropos() on modules with empty
docstrings.
--
Repository URL: https://hg.python.org/cpython
More information about the Python-checkins
mailing list