From f958536aac58e3be28f1e4a0a01b2c8a216c05b6 Mon Sep 17 00:00:00 2001 From: Chung-Ting Huang Date: Mon, 30 Jul 2018 12:44:37 -0500 Subject: [PATCH] TUN-829: prefer p256 curve --- tlsconfig/tlsconfig.go | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/tlsconfig/tlsconfig.go b/tlsconfig/tlsconfig.go index 61d87f87..c2e3b46a 100644 --- a/tlsconfig/tlsconfig.go +++ b/tlsconfig/tlsconfig.go @@ -60,7 +60,8 @@ func (f CLIFlags) finishGettingConfig(c *cli.Context, config *tls.Config) *tls.C if c.IsSet(f.RootCA) { config.RootCAs = LoadCert(c.String(f.RootCA)) } - + // we optimize CurveP256 + config.CurvePreferences = []tls.CurveID{tls.CurveP256} return config }