From 90b3d86d6a4a02d9c74945d3397ac200e327ad93 Mon Sep 17 00:00:00 2001 From: yuhan6665 <1588741+yuhan6665@users.noreply.github.com> Date: Sun, 18 Aug 2024 18:37:35 -0400 Subject: [PATCH] crypto/tls: remove RSA KEX ciphers from the default list Removes the RSA KEX based ciphers from the default list. This can be reverted using the tlsrsakex GODEBUG. Fixes #63413 Change-Id: Id221be3eb2f6c24b91039d380313f0c87d339f98 Reviewed-on: https://go-review.googlesource.com/c/go/+/541517 LUCI-TryBot-Result: Go LUCI Reviewed-by: Damien Neil --- cipher_suites.go | 29 +++++++++++++++++++++++++++-- common.go | 4 +++- 2 files changed, 30 insertions(+), 3 deletions(-) diff --git a/cipher_suites.go b/cipher_suites.go index 35bf09f..1d1670d 100644 --- a/cipher_suites.go +++ b/cipher_suites.go @@ -334,10 +334,35 @@ var disabledCipherSuites = []uint16{ } var ( - defaultCipherSuitesLen = len(cipherSuitesPreferenceOrder) - len(disabledCipherSuites) - defaultCipherSuites = cipherSuitesPreferenceOrder[:defaultCipherSuitesLen] + defaultCipherSuitesLen int + defaultCipherSuites []uint16 ) +// rsaKexCiphers contains the ciphers which use RSA based key exchange, +// which we disable by default. +var rsaKexCiphers = map[uint16]bool{ + TLS_RSA_WITH_RC4_128_SHA: true, + TLS_RSA_WITH_3DES_EDE_CBC_SHA: true, + TLS_RSA_WITH_AES_128_CBC_SHA: true, + TLS_RSA_WITH_AES_256_CBC_SHA: true, + TLS_RSA_WITH_AES_128_CBC_SHA256: true, + TLS_RSA_WITH_AES_128_GCM_SHA256: true, + TLS_RSA_WITH_AES_256_GCM_SHA384: true, +} + +//var rsaKEXgodebug = godebug.New("tlsrsakex") + +func init() { + rsaKexEnabled := false // rsaKEXgodebug.Value() == "1" + for _, c := range cipherSuitesPreferenceOrder[:len(cipherSuitesPreferenceOrder)-len(disabledCipherSuites)] { + if !rsaKexEnabled && rsaKexCiphers[c] { + continue + } + defaultCipherSuites = append(defaultCipherSuites, c) + } + defaultCipherSuitesLen = len(defaultCipherSuites) +} + // defaultCipherSuitesTLS13 is also the preference order, since there are no // disabled by default TLS 1.3 cipher suites. The same AES vs ChaCha20 logic as // cipherSuitesPreferenceOrder applies. diff --git a/common.go b/common.go index 53209a6..c64df94 100644 --- a/common.go +++ b/common.go @@ -683,7 +683,9 @@ type Config struct { // the list is ignored. Note that TLS 1.3 ciphersuites are not configurable. // // If CipherSuites is nil, a safe default list is used. The default cipher - // suites might change over time. + // suites might change over time. In Go 1.22 RSA key exchange based cipher + // suites were removed from the default list, but can be re-added with the + // GODEBUG setting tlsrsakex=1. CipherSuites []uint16 // PreferServerCipherSuites is a legacy field and has no effect.