1
0
mirror of https://github.com/minio/minio.git synced 2025-03-30 09:13:41 -04:00
Andreas Auernhammer 21a3c0f482 disable elliptic curves P-384 and P-521 for TLS. ()
This change disables the non-constant-time implementations of P-384 and P-521.
As a consequence a client using just these curves cannot connect to the server.
This should be no real issues because (all) clients at least support P-256.

Further this change also rejects ECDSA private keys of P-384 and P-521.
While non-constant-time implementations for the ECDHE exchange don't expose an
obvious vulnerability, using P-384 or P-521 keys for the ECDSA signature may allow
pratical timing attacks.

Fixes 
2018-04-24 15:47:30 -07:00
..