components/openldap/patches/01-no-ssl3.patch
changeset 5911 a8d897c4c442
parent 4748 976281af43d9
--- a/components/openldap/patches/01-no-ssl3.patch	Tue May 03 15:56:45 2016 -0700
+++ b/components/openldap/patches/01-no-ssl3.patch	Tue May 03 19:23:30 2016 -0700
@@ -3,8 +3,8 @@
 Patch was developed in-house; it is Solaris specific and
 will not be contributed upstream.
 
---- openldap-2.4.30/libraries/libldap/ldap.conf.old	Mon Jun  1 16:46:56 2015
-+++ openldap-2.4.30/libraries/libldap/ldap.conf	Mon Jun  1 16:47:08 2015
+--- openldap-2.4.44/libraries/libldap/ldap.conf.old     Thu Nov  5 10:11:14 2015
++++ openldap-2.4.44/libraries/libldap/ldap.conf Thu Nov  5 10:16:44 2015
 @@ -9,5 +9,8 @@
  #URI	ldap://ldap.example.com ldap://ldap-master.example.com:666
  
@@ -14,18 +14,14 @@
 +
 +TLS_PROTOCOL_MIN	3.2
 +TLS_CIPHER_SUITE	TLSv1.2:!aNULL:!eNULL:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA:DHE-RSA-AES256-SHA:DHE-DSS-AES256-SHA:DHE-RSA-DES-CBC3-SHA:DHE-DSS-DES-CBC3-SHA:AES128-SHA:AES256-SHA:DES-CBC3-SHA
---- openldap-2.4.30/servers/slapd/slapd.conf.old	Mon Jun  1 16:47:47 2015
-+++ openldap-2.4.30/servers/slapd/slapd.conf	Mon Jun  1 16:47:59 2015
-@@ -22,10 +22,12 @@
- # Sample security restrictions
- #	Require integrity protection (prevent hijacking)
+--- openldap-2.4.44/servers/slapd/slapd.conf.old        Thu Nov  5 10:11:25 2015
++++ openldap-2.4.44/servers/slapd/slapd.conf    Thu Nov  5 10:16:24 2015
+@@ -23,6 +23,8 @@
  #	Require 112-bit (3DES or better) encryption for updates
  #	Require 63-bit encryption for simple bind
  # security ssf=1 update_ssf=112 simple_bind=64
-+TLSProtocolMin	770
++TLSProtocolMin	3.2
 +TLSCipherSuite	TLSv1.2:!aNULL:!eNULL:DHE-RSA-AES128-SHA:DHE-DSS-AES128-SHA:DHE-RSA-AES256-SHA:DHE-DSS-AES256-SHA:DHE-RSA-DES-CBC3-SHA:DHE-DSS-DES-CBC3-SHA:AES128-SHA:AES256-SHA:DES-CBC3-SHA
  
  # Sample access control policy:
  #	Root DSE: allow anyone to read it
- #	Subschema (sub)entry DSE: allow anyone to read it
- #	Other DSEs: