Blame SOURCES/freeradius-Use-system-crypto-policy-by-default.patch

33c701
From d78bf5ab1f5c8102b2b6051cfb1198488be9597d Mon Sep 17 00:00:00 2001
33c701
From: Nikolai Kondrashov <Nikolai.Kondrashov@redhat.com>
33c701
Date: Mon, 26 Sep 2016 19:48:36 +0300
33c701
Subject: [PATCH] Use system crypto policy by default
33c701
33c701
---
33c701
 raddb/mods-available/eap        | 2 +-
33c701
 raddb/mods-available/inner-eap  | 2 +-
33c701
 raddb/sites-available/abfab-tls | 2 +-
33c701
 raddb/sites-available/tls       | 4 ++--
33c701
 4 files changed, 5 insertions(+), 5 deletions(-)
33c701
33c701
diff --git a/raddb/mods-available/eap b/raddb/mods-available/eap
33c701
index 94494b2c6..9a8dc9327 100644
33c701
--- a/raddb/mods-available/eap
33c701
+++ b/raddb/mods-available/eap
33c701
@@ -323,7 +323,7 @@ eap {
33c701
 		#
33c701
 		# For EAP-FAST, use "ALL:!EXPORT:!eNULL:!SSLv2"
33c701
 		#
33c701
-		cipher_list = "DEFAULT"
33c701
+		cipher_list = "PROFILE=SYSTEM"
33c701
 
33c701
 		# If enabled, OpenSSL will use server cipher list
33c701
 		# (possibly defined by cipher_list option above)
33c701
diff --git a/raddb/mods-available/inner-eap b/raddb/mods-available/inner-eap
33c701
index 2b4df6267..af9aa88cd 100644
33c701
--- a/raddb/mods-available/inner-eap
33c701
+++ b/raddb/mods-available/inner-eap
33c701
@@ -68,7 +68,7 @@ eap inner-eap {
33c701
 		#  certificates.  If so, edit this file.
33c701
 		ca_file = ${cadir}/ca.pem
33c701
 
33c701
-		cipher_list = "DEFAULT"
33c701
+		cipher_list = "PROFILE=SYSTEM"
33c701
 
33c701
 		#  You may want to set a very small fragment size.
33c701
 		#  The TLS data here needs to go inside of the
33c701
diff --git a/raddb/sites-available/abfab-tls b/raddb/sites-available/abfab-tls
33c701
index 5dbe143da..46b5fea78 100644
33c701
--- a/raddb/sites-available/abfab-tls
33c701
+++ b/raddb/sites-available/abfab-tls
33c701
@@ -19,7 +19,7 @@ listen {
33c701
 		dh_file = ${certdir}/dh
33c701
 		fragment_size = 8192
33c701
 		ca_path = ${cadir}
33c701
-		cipher_list = "DEFAULT"
33c701
+		cipher_list = "PROFILE=SYSTEM"
33c701
 
33c701
 		cache {
33c701
 			enable = no
33c701
diff --git a/raddb/sites-available/tls b/raddb/sites-available/tls
33c701
index cf1cd7a8a..7dd59cb6f 100644
33c701
--- a/raddb/sites-available/tls
33c701
+++ b/raddb/sites-available/tls
33c701
@@ -197,7 +197,7 @@ listen {
33c701
 		# Set this option to specify the allowed
33c701
 		# TLS cipher suites.  The format is listed
33c701
 		# in "man 1 ciphers".
33c701
-		cipher_list = "DEFAULT"
33c701
+		cipher_list = "PROFILE=SYSTEM"
33c701
 
33c701
 		# If enabled, OpenSSL will use server cipher list
33c701
 		# (possibly defined by cipher_list option above)
33c701
@@ -499,7 +499,7 @@ home_server tls {
33c701
 		# Set this option to specify the allowed
33c701
 		# TLS cipher suites.  The format is listed
33c701
 		# in "man 1 ciphers".
33c701
-		cipher_list = "DEFAULT"
33c701
+		cipher_list = "PROFILE=SYSTEM"
33c701
 	}
33c701
 
33c701
 }
33c701
-- 
33c701
2.13.2
33c701