summaryrefslogtreecommitdiff
path: root/lib/ssl/sslsock.c
diff options
context:
space:
mode:
authorMartin Thomson <martin.thomson@gmail.com>2019-10-29 00:31:04 +0000
committerMartin Thomson <martin.thomson@gmail.com>2019-10-29 00:31:04 +0000
commitb6aa93aa76f1be102f2388672a4669e1f7be4f2b (patch)
treebc0f26f256b8919fada843b966dbe5d022292e80 /lib/ssl/sslsock.c
parent3dbbff11cc3a60cd906f3b188c55400b1531a5c5 (diff)
downloadnss-hg-b6aa93aa76f1be102f2388672a4669e1f7be4f2b.tar.gz
Bug 1575411 - Enable extended master secret by default, r=jcj,kjacobs
See the bug for discussion about the implications of this. Differential Revision: https://phabricator.services.mozilla.com/D49819
Diffstat (limited to 'lib/ssl/sslsock.c')
-rw-r--r--lib/ssl/sslsock.c2
1 files changed, 1 insertions, 1 deletions
diff --git a/lib/ssl/sslsock.c b/lib/ssl/sslsock.c
index 027bb9157..aa0e76e3c 100644
--- a/lib/ssl/sslsock.c
+++ b/lib/ssl/sslsock.c
@@ -81,7 +81,7 @@ static sslOptions ssl_defaults = {
.reuseServerECDHEKey = PR_TRUE,
.enableFallbackSCSV = PR_FALSE,
.enableServerDhe = PR_TRUE,
- .enableExtendedMS = PR_FALSE,
+ .enableExtendedMS = PR_TRUE,
.enableSignedCertTimestamps = PR_FALSE,
.requireDHENamedGroups = PR_FALSE,
.enable0RttData = PR_FALSE,