Skip to content

Commit

Permalink
Update CloudFront's upstream ECC Preference list
Browse files Browse the repository at this point in the history
- from s2n_ecc_pref_list_20140601 to s2n_ecc_pref_list_20230623
  to include X25519 inline with CloudFront's documentation
  in https://docs.aws.amazon.com/AmazonCloudFront/latest/DeveloperGuide/secure-connections-supported-ciphers-cloudfront-to-origin.html
  • Loading branch information
zz85 committed Nov 30, 2023
1 parent dacf2b1 commit 9715cf5
Showing 1 changed file with 4 additions and 4 deletions.
8 changes: 4 additions & 4 deletions tls/s2n_security_policies.c
Original file line number Diff line number Diff line change
Expand Up @@ -180,31 +180,31 @@ const struct s2n_security_policy security_policy_cloudfront_upstream = {
.cipher_preferences = &cipher_preferences_cloudfront_upstream,
.kem_preferences = &kem_preferences_null,
.signature_preferences = &s2n_signature_preferences_20140601,
.ecc_preferences = &s2n_ecc_preferences_20140601,
.ecc_preferences = &s2n_ecc_preferences_20230623,
};

const struct s2n_security_policy security_policy_cloudfront_upstream_tls10 = {
.minimum_protocol_version = S2N_TLS10,
.cipher_preferences = &cipher_preferences_cloudfront_upstream_tls10,
.kem_preferences = &kem_preferences_null,
.signature_preferences = &s2n_signature_preferences_20140601,
.ecc_preferences = &s2n_ecc_preferences_20140601,
.ecc_preferences = &s2n_ecc_preferences_20230623,
};

const struct s2n_security_policy security_policy_cloudfront_upstream_tls11 = {
.minimum_protocol_version = S2N_TLS11,
.cipher_preferences = &cipher_preferences_cloudfront_upstream_tls11,
.kem_preferences = &kem_preferences_null,
.signature_preferences = &s2n_signature_preferences_20140601,
.ecc_preferences = &s2n_ecc_preferences_20140601,
.ecc_preferences = &s2n_ecc_preferences_20230623,
};

const struct s2n_security_policy security_policy_cloudfront_upstream_tls12 = {
.minimum_protocol_version = S2N_TLS12,
.cipher_preferences = &cipher_preferences_cloudfront_upstream_tls12,
.kem_preferences = &kem_preferences_null,
.signature_preferences = &s2n_signature_preferences_20140601,
.ecc_preferences = &s2n_ecc_preferences_20140601,
.ecc_preferences = &s2n_ecc_preferences_20230623,
};

/* CloudFront viewer facing */
Expand Down

0 comments on commit 9715cf5

Please sign in to comment.