[pbs-devel] [PATCH proxmox-backup v2 0/3] close #3612: allow config of SSL cipher-suites for proxy
    Dietmar Maurer 
    dietmar at proxmox.com
       
    Wed Jan  5 16:16:46 CET 2022
    
    
  
> Yes, but just hardcoding the list probably wont be enough since the 
> string is allowed to contain !,+,- and some other things[1]. This check 
> was mostly thought to check if the proxy would still start with the 
> given chiphers, not if the given string was valid. Also I'm not sure if 
> we should be more strict than openssl[2].
Please test what happens when you pass a string including a newline. I am quite sure we do not want or need that.
    
    
More information about the pbs-devel
mailing list