From a0dd7dc1b02a00970eba8ddc0430f74ff7506be0 Mon Sep 17 00:00:00 2001 From: Benjamin Peterson Date: Thu, 19 Feb 2015 17:57:08 -0500 Subject: [PATCH] remove rc4 from the default client ciphers (closes #23481) --- Lib/ssl.py | 6 ++---- Misc/NEWS | 2 ++ 2 files changed, 4 insertions(+), 4 deletions(-) diff --git a/Lib/ssl.py b/Lib/ssl.py index 7b8f21a2ec..d6fed88cfe 100644 --- a/Lib/ssl.py +++ b/Lib/ssl.py @@ -157,14 +157,12 @@ else: # * Prefer any AES-GCM over any AES-CBC for better performance and security # * Then Use HIGH cipher suites as a fallback # * Then Use 3DES as fallback which is secure but slow -# * Finally use RC4 as a fallback which is problematic but needed for -# compatibility some times. # * Disable NULL authentication, NULL encryption, and MD5 MACs for security # reasons _DEFAULT_CIPHERS = ( 'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:' - 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:ECDH+RC4:' - 'DH+RC4:RSA+RC4:!aNULL:!eNULL:!MD5' + 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:!aNULL:' + '!eNULL:!MD5' ) # Restricted and more secure ciphers for the server side diff --git a/Misc/NEWS b/Misc/NEWS index 5f9c8144b8..2f171c26c3 100644 --- a/Misc/NEWS +++ b/Misc/NEWS @@ -21,6 +21,8 @@ Library - Issue #22885: Fixed arbitrary code execution vulnerability in the dumbdbm module. Original patch by Claudiu Popa. +- Issue #23481: Remove RC4 from the SSL module's default cipher list. + - Issue #21849: Fixed xmlrpclib serialization of non-ASCII unicode strings in the multiprocessing module. -- 2.50.1