From 4e691d06ffdb4d1fd940996f419308fe53454df7 Mon Sep 17 00:00:00 2001 From: Brendan Le Foll Date: Mon, 16 Feb 2015 11:18:29 +0000 Subject: openssl: disable SSLv3 by default Because of the SSLv3 POODLE vulnerability, it's preferred to simply disable SSLv3 even if patched with the TLS_FALLBACK_SCSV Signed-off-by: Brendan Le Foll Signed-off-by: Richard Purdie --- meta/recipes-connectivity/openssl/openssl.inc | 4 ++++ 1 file changed, 4 insertions(+) (limited to 'meta/recipes-connectivity/openssl/openssl.inc') diff --git a/meta/recipes-connectivity/openssl/openssl.inc b/meta/recipes-connectivity/openssl/openssl.inc index 6eb1b5eac9..ba9bca6af4 100644 --- a/meta/recipes-connectivity/openssl/openssl.inc +++ b/meta/recipes-connectivity/openssl/openssl.inc @@ -50,6 +50,10 @@ CONFFILES_openssl-conf = "${libdir}/ssl/openssl.cnf" RRECOMMENDS_libcrypto += "openssl-conf" RDEPENDS_${PN}-ptest += "${PN}-misc make perl perl-module-filehandle bc" +# Remove this to enable SSLv3. SSLv3 is defaulted to disabled due to the POODLE +# vulnerability +EXTRA_OECONF = " -no-ssl3" + do_configure_prepend_darwin () { sed -i -e '/version-script=openssl\.ld/d' Configure } -- cgit 1.2.3-korg