From 0b28bf3129a021581c51d8a02299e0326e942f8e Mon Sep 17 00:00:00 2001 From: Adam Langley Date: Thu, 18 Dec 2014 11:31:14 -0800 Subject: [PATCH] crypto/tls: change default minimum version to TLS 1.0. SSLv3 (the old minimum) is still supported and can be enabled via the tls.Config, but this change increases the default minimum version to TLS 1.0. This is now common practice in light of the POODLE[1] attack against SSLv3's CBC padding format. [1] https://www.imperialviolet.org/2014/10/14/poodle.html Fixes #9364. Change-Id: Ibae6666ee038ceee0cb18c339c393155928c6510 Reviewed-on: https://go-review.googlesource.com/1791 Reviewed-by: Minux Ma --- common.go | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/common.go b/common.go index 776b70c..e3c6004 100644 --- a/common.go +++ b/common.go @@ -30,7 +30,7 @@ const ( recordHeaderLen = 5 // record header length maxHandshake = 65536 // maximum handshake we support (protocol max is 16 MB) - minVersion = VersionSSL30 + minVersion = VersionTLS10 maxVersion = VersionTLS12 )