Skip to content

Commit

Permalink
Set minimum to TLSv1.3
Browse files Browse the repository at this point in the history
  • Loading branch information
emlowe committed Dec 20, 2024
1 parent 69555bc commit 7c06c13
Showing 1 changed file with 1 addition and 13 deletions.
14 changes: 1 addition & 13 deletions chia/server/server.py
Original file line number Diff line number Diff line change
Expand Up @@ -58,19 +58,7 @@ def ssl_context_for_server(

ssl_context = ssl._create_unverified_context(purpose=ssl.Purpose.CLIENT_AUTH, cafile=str(ca_cert))
ssl_context.check_hostname = False
ssl_context.minimum_version = ssl.TLSVersion.TLSv1_2
ssl_context.set_ciphers(
"ECDHE-ECDSA-AES256-GCM-SHA384:"
"ECDHE-RSA-AES256-GCM-SHA384:"
"ECDHE-ECDSA-CHACHA20-POLY1305:"
"ECDHE-RSA-CHACHA20-POLY1305:"
"ECDHE-ECDSA-AES128-GCM-SHA256:"
"ECDHE-RSA-AES128-GCM-SHA256:"
"ECDHE-ECDSA-AES256-SHA384:"
"ECDHE-RSA-AES256-SHA384:"
"ECDHE-ECDSA-AES128-SHA256:"
"ECDHE-RSA-AES128-SHA256"
)
ssl_context.minimum_version = ssl.TLSVersion.TLSv1_3
ssl_context.load_cert_chain(certfile=str(cert_path), keyfile=str(key_path))
ssl_context.verify_mode = ssl.CERT_REQUIRED
return ssl_context
Expand Down

0 comments on commit 7c06c13

Please sign in to comment.