-
- Downloads
[release-branch.go1.21] crypto/tls: align FIPS-only mode with BoringSSL policy
This enables TLS 1.3, disables P-521, and disables non-ECDHE suites. Updates #64717 Updates #62372 Fixes #64719 Change-Id: I3a65b239ef0198bbdbe5e55e0810e7128f90a091 Reviewed-on: https://go-review.googlesource.com/c/go/+/549975 Reviewed-by:Roland Shoemaker <roland@golang.org> LUCI-TryBot-Result: Go LUCI <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by:
Than McIntosh <thanm@google.com> Reviewed-on: https://go-review.googlesource.com/c/go/+/553856 Auto-Submit: Matthew Dempsky <mdempsky@google.com> Reviewed-by:
Matthew Dempsky <mdempsky@google.com>
Showing
- src/crypto/internal/boring/aes.go 22 additions, 7 deletionssrc/crypto/internal/boring/aes.go
- src/crypto/internal/boring/notboring.go 1 addition, 0 deletionssrc/crypto/internal/boring/notboring.go
- src/crypto/tls/boring.go 15 additions, 11 deletionssrc/crypto/tls/boring.go
- src/crypto/tls/boring_test.go 51 additions, 18 deletionssrc/crypto/tls/boring_test.go
- src/crypto/tls/cipher_suites.go 7 additions, 1 deletionsrc/crypto/tls/cipher_suites.go
- src/crypto/tls/handshake_client.go 3 additions, 1 deletionsrc/crypto/tls/handshake_client.go
- src/crypto/tls/handshake_client_tls13.go 0 additions, 4 deletionssrc/crypto/tls/handshake_client_tls13.go
- src/crypto/tls/handshake_server_test.go 19 additions, 9 deletionssrc/crypto/tls/handshake_server_test.go
- src/crypto/tls/handshake_server_tls13.go 3 additions, 4 deletionssrc/crypto/tls/handshake_server_tls13.go
- src/crypto/tls/notboring.go 2 additions, 0 deletionssrc/crypto/tls/notboring.go
- src/crypto/x509/boring.go 2 additions, 2 deletionssrc/crypto/x509/boring.go
Loading
Please register or sign in to comment