Browse Source

let crypto/tls choose the proper ciphers

vcptr 5 years ago
parent
commit
524b2aca56
1 changed files with 2 additions and 5 deletions
  1. 2 5
      transport/internet/tls/config.go

+ 2 - 5
transport/internet/tls/config.go

@@ -187,11 +187,8 @@ func (c *Config) GetTLSConfig(opts ...Option) *tls.Config {
 	}
 	}
 
 
 	if !c.AllowInsecureCiphers && len(config.CipherSuites) == 0 {
 	if !c.AllowInsecureCiphers && len(config.CipherSuites) == 0 {
-		// use tls cipher suites from cryto/tls
-		config.CipherSuites = []uint16{}
-		for _, s := range tls.CipherSuites() {
-			config.CipherSuites = append(config.CipherSuites, s.ID)
-		}
+		// crypto/tls will use the proper ciphers
+		config.CipherSuites = nil
 	}
 	}
 
 
 	config.InsecureSkipVerify = c.AllowInsecure
 	config.InsecureSkipVerify = c.AllowInsecure