From: Magnus Kroken Date: Fri, 30 Dec 2016 00:31:29 +0000 (+0100) Subject: mbedtls: enable DHE-RSA key exchange X-Git-Url: http://git.openwrt.org/?p=openwrt%2Fstaging%2Frmilecki.git;a=commitdiff_plain;h=8ed11ebf7ddaa4888ab6f2c3ee6b744372cc9487 mbedtls: enable DHE-RSA key exchange Later OpenVPN 2.3-openssl versions only enable TLS cipher suites with perfect forward secrecy, i.e. DHE and ECDHE cipher suites. ECDHE key exchange is not supported by OpenVPN 2.3-openssl, enable DHE key exchange to allow LEDE OpenVPN 2.4-mbedtls clients to connect to such servers. Signed-off-by: Magnus Kroken Reported-by: Martin Blumenstingl Reported-by: Lucian Cristian --- diff --git a/package/libs/mbedtls/patches/200-config.patch b/package/libs/mbedtls/patches/200-config.patch index bb74e61adb9..dcee704d235 100644 --- a/package/libs/mbedtls/patches/200-config.patch +++ b/package/libs/mbedtls/patches/200-config.patch @@ -82,15 +82,6 @@ /** * \def MBEDTLS_KEY_EXCHANGE_RSA_ENABLED -@@ -622,7 +622,7 @@ - * MBEDTLS_TLS_DHE_RSA_WITH_CAMELLIA_128_CBC_SHA - * MBEDTLS_TLS_DHE_RSA_WITH_3DES_EDE_CBC_SHA - */ --#define MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED -+//#define MBEDTLS_KEY_EXCHANGE_DHE_RSA_ENABLED - - /** - * \def MBEDTLS_KEY_EXCHANGE_ECDHE_RSA_ENABLED @@ -695,7 +695,7 @@ * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_128_GCM_SHA256 * MBEDTLS_TLS_ECDH_ECDSA_WITH_CAMELLIA_256_GCM_SHA384