GNOME Bugzilla – Bug 792604
Disable TLS compression
Last modified: 2018-01-19 07:40:32 UTC
Created attachment 366939 [details] [review] Patch to disable TLS compression The current configuration of OpenSSL enables support for TLS compression which isn't good from a security perspective due to CRIME (CVE-2012-4929). The attached patch ensures that support for TLS compression is disabled.
Created attachment 366940 [details] [review] Patch to disable TLS compression
Review of attachment 366940 [details] [review]: Makes sense, do we need it server side as well?
Created attachment 366992 [details] [review] Patch to disable TLS compression Disable for both client and server
Review of attachment 366992 [details] [review]: Looks good
Thanks for the patch