changeset: 94688:041a27298cf3 parent: 94685:70a55b2dee71 parent: 94686:c509e6f18d7d user: Benjamin Peterson date: Thu Feb 19 17:58:19 2015 -0500 files: Lib/ssl.py Misc/NEWS description: merge 3.4 (#23481) diff -r 70a55b2dee71 -r 041a27298cf3 Lib/ssl.py --- a/Lib/ssl.py Wed Feb 18 18:02:22 2015 -0800 +++ b/Lib/ssl.py Thu Feb 19 17:58:19 2015 -0500 @@ -164,14 +164,12 @@ # * Prefer any AES-GCM over any AES-CBC for better performance and security # * Then Use HIGH cipher suites as a fallback # * Then Use 3DES as fallback which is secure but slow -# * Finally use RC4 as a fallback which is problematic but needed for -# compatibility some times. # * Disable NULL authentication, NULL encryption, and MD5 MACs for security # reasons _DEFAULT_CIPHERS = ( 'ECDH+AESGCM:DH+AESGCM:ECDH+AES256:DH+AES256:ECDH+AES128:DH+AES:ECDH+HIGH:' - 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:ECDH+RC4:' - 'DH+RC4:RSA+RC4:!aNULL:!eNULL:!MD5' + 'DH+HIGH:ECDH+3DES:DH+3DES:RSA+AESGCM:RSA+AES:RSA+HIGH:RSA+3DES:!aNULL:' + '!eNULL:!MD5' ) # Restricted and more secure ciphers for the server side diff -r 70a55b2dee71 -r 041a27298cf3 Misc/NEWS --- a/Misc/NEWS Wed Feb 18 18:02:22 2015 -0800 +++ b/Misc/NEWS Thu Feb 19 17:58:19 2015 -0500 @@ -13,6 +13,8 @@ Library ------- +- Issue #23481: Remove RC4 from the SSL module's default cipher list. + - Issue #21548: Fix pydoc.synopsis() and pydoc.apropos() on modules with empty docstrings.