From a6462552cde98fc18b3edc285db3acec529003f7 Mon Sep 17 00:00:00 2001 From: Noah Laptop Date: Sun, 25 Oct 2020 16:24:19 -0700 Subject: [PATCH] fix: enable p384 and p512 curves in SSL engine --- src/TLS12_only_profile.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/src/TLS12_only_profile.c b/src/TLS12_only_profile.c index f812298..c5bb05a 100644 --- a/src/TLS12_only_profile.c +++ b/src/TLS12_only_profile.c @@ -221,7 +221,8 @@ br_client_init_TLS12_only(br_ssl_client_context *cc, //* Alternate: set implementations explicitly. // br_ssl_client_set_rsapub(cc, &br_rsa_i31_public); br_ssl_engine_set_rsavrfy(&cc->eng, &br_rsa_i15_pkcs1_vrfy); - br_ssl_engine_set_ec(&cc->eng, &br_ec_p256_m15); + // br_ssl_engine_set_ec(&cc->eng, &br_ec_p256_m15); + br_ssl_engine_set_ec(&cc->eng, &br_ec_prime_fast_256); br_ssl_engine_set_ecdsa(&cc->eng, &br_ecdsa_i15_vrfy_asn1); //*/ @@ -439,7 +440,7 @@ br_client_init_TLS12_only(br_ssl_client_context *cc, // br_x509_minimal_set_ecdsa(xc, // &br_ec_prime_i31, &br_ecdsa_i31_vrfy_asn1); br_x509_minimal_set_ecdsa(xc, - &br_ec_prime_fast_256, + br_ssl_engine_get_ec(&cc->eng), br_ssl_engine_get_ecdsa(&cc->eng)); /*