luci-app-openvpn: update tls_cipher list 4012/head
authorMartin Schiller <ms@dev.tdt.de>
Tue, 5 May 2020 09:05:41 +0000 (11:05 +0200)
committerMartin Schiller <ms@dev.tdt.de>
Tue, 5 May 2020 09:05:41 +0000 (11:05 +0200)
Update the list of selectable TLS cipher suites.

The previous list consisted mostly of unsupported ciphers and the IANA
names should be used.

Signed-off-by: Martin Schiller <ms@dev.tdt.de>
applications/luci-app-openvpn/luasrc/model/cbi/openvpn-advanced.lua

index 97c0cbcc5412046f4dca2c2221583404a3d07541..04934c8c11d9497cde98f78d7ce8374847813b0c 100644 (file)
@@ -679,25 +679,27 @@ local knownParams = {
                { DynamicList,
                        "tls_cipher",
                        {
-                               "DHE-RSA-AES256-SHA",
-                               "DHE-DSS-AES256-SHA",
-                               "AES256-SHA",
-                               "EDH-RSA-DES-CBC3-SHA",
-                               "EDH-DSS-DES-CBC3-SHA",
-                               "DES-CBC3-SHA",
-                               "DHE-RSA-AES128-SHA",
-                               "DHE-DSS-AES128-SHA",
-                               "AES128-SHA",
-                               "RC4-SHA",
-                               "RC4-MD5",
-                               "EDH-RSA-DES-CBC-SHA",
-                               "EDH-DSS-DES-CBC-SHA",
-                               "DES-CBC-SHA",
-                               "EXP-EDH-RSA-DES-CBC-SHA",
-                               "EXP-EDH-DSS-DES-CBC-SHA",
-                               "EXP-DES-CBC-SHA",
-                               "EXP-RC2-CBC-MD5",
-                               "EXP-RC4-MD5"
+                               "TLS-ECDHE-ECDSA-WITH-AES-256-GCM-SHA384",
+                               "TLS-ECDHE-RSA-WITH-AES-256-GCM-SHA384",
+                               "TLS-DHE-RSA-WITH-AES-256-GCM-SHA384",
+                               "TLS-ECDHE-ECDSA-WITH-CHACHA20-POLY1305-SHA256",
+                               "TLS-ECDHE-RSA-WITH-CHACHA20-POLY1305-SHA256",
+                               "TLS-DHE-RSA-WITH-CHACHA20-POLY1305-SHA256",
+                               "TLS-ECDHE-ECDSA-WITH-AES-128-GCM-SHA256",
+                               "TLS-ECDHE-RSA-WITH-AES-128-GCM-SHA256",
+                               "TLS-DHE-RSA-WITH-AES-128-GCM-SHA256",
+                               "TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA384",
+                               "TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA384",
+                               "TLS-DHE-RSA-WITH-AES-256-CBC-SHA256",
+                               "TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA256",
+                               "TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA256",
+                               "TLS-DHE-RSA-WITH-AES-128-CBC-SHA256",
+                               "TLS-ECDHE-ECDSA-WITH-AES-256-CBC-SHA",
+                               "TLS-ECDHE-RSA-WITH-AES-256-CBC-SHA",
+                               "TLS-DHE-RSA-WITH-AES-256-CBC-SHA",
+                               "TLS-ECDHE-ECDSA-WITH-AES-128-CBC-SHA",
+                               "TLS-ECDHE-RSA-WITH-AES-128-CBC-SHA",
+                               "TLS-DHE-RSA-WITH-AES-128-CBC-SHA"
                        },
                        translate("TLS cipher") },
                { DynamicList,