summaryrefslogtreecommitdiff
path: root/netwerk
diff options
context:
space:
mode:
authorPale Moon <git-repo@palemoon.org>2017-02-25 10:13:37 +0100
committerPale Moon <git-repo@palemoon.org>2017-02-25 10:13:37 +0100
commit274f867828c5938a180c3452d58c8f22ecf8b025 (patch)
tree88348ecc0f1cc4d4e4cd6f9ba59348d247eb5f8a /netwerk
parente42586bb2dd7a974949d08ccc1dbe5ad84740967 (diff)
downloadpalemoon-gre-274f867828c5938a180c3452d58c8f22ecf8b025.tar.gz
Add AES256-GCM suites to secmanager.
Disabled by default for known wasted performance (40%) on a suite weaker to key attacks than AES128.
Diffstat (limited to 'netwerk')
-rw-r--r--netwerk/base/security-prefs.js2
1 files changed, 2 insertions, 0 deletions
diff --git a/netwerk/base/security-prefs.js b/netwerk/base/security-prefs.js
index 0f5309935..5801c384c 100644
--- a/netwerk/base/security-prefs.js
+++ b/netwerk/base/security-prefs.js
@@ -43,6 +43,8 @@ pref("security.ssl3.rsa_aes_256_sha", true);
pref("security.ssl3.rsa_camellia_256_sha", true);
// Cipher suites disabled by default //Reason:
+pref("security.ssl3.ecdhe_ecdsa_aes_256_gcm_sha384", false); // performance
+pref("security.ssl3.ecdhe_rsa_aes_256_gcm_sha384", false); // performance
pref("security.ssl3.ecdhe_rsa_des_ede3_sha", false); //3DES
pref("security.ssl3.ecdhe_rsa_rc4_128_sha", false); //RC4
pref("security.ssl3.ecdhe_ecdsa_rc4_128_sha", false); //RC4