Skip to content

Fix: Add warning to tell users when RC4 cipher suites are avalible to TLS - #11277

Merged
SparkiDev merged 1 commit into
wolfSSL:masterfrom
aidankeefe2022:fix-TLS-RFC-issue
Sep 7, 2026
Merged

SparkiDev merged 1 commit into
wolfSSL:masterfrom
aidankeefe2022:fix-TLS-RFC-issue

Conversation

@aidankeefe2022

@aidankeefe2022 aidankeefe2022 commented Aug 25, 2026

Copy link
Copy Markdown
Member

Description

Reported by #11081

Added configure warning to let users know that RC4 is enabled for TLS and they should be cautious and perhaps change their configuration.

Found distribution bug during CI/CD and included that fix here as well

@wolfSSL-Bot

Copy link
Copy Markdown

Can one of the admins verify this patch?

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11277

Scan targets checked: wolfcrypt-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src

Findings: 5
5 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11277

Scan targets checked: wolfcrypt-bugs, wolfcrypt-rs-bugs, wolfcrypt-src, wolfssl-bugs, wolfssl-src

Findings: 4
4 finding(s) posted as inline comments (see file-level comments below)

This review was generated automatically by Fenrir. Reported findings require changes before merge.

Comment thread tests/api/test_tls.c Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated
Comment thread wolfssl/internal.h Outdated

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11277

No scan targets match the changed files in this PR. Review skipped.

@aidankeefe2022

Copy link
Copy Markdown
Member Author

retest this please

2 similar comments
@aidankeefe2022

Copy link
Copy Markdown
Member Author

retest this please

@aidankeefe2022

Copy link
Copy Markdown
Member Author

retest this please

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #11277

No scan targets match the changed files in this PR. Review skipped.

@aidankeefe2022 aidankeefe2022 changed the title Fix: Do not build RC4 cipher suites in D/TLS 1.3 capable configurations Fix: Add warning to tell users when RC4 cipher suites are avalible to TLS Aug 31, 2026
@aidankeefe2022

Copy link
Copy Markdown
Member Author

retest this please

3 similar comments
@aidankeefe2022

Copy link
Copy Markdown
Member Author

retest this please

@aidankeefe2022

Copy link
Copy Markdown
Member Author

retest this please

@aidankeefe2022

Copy link
Copy Markdown
Member Author

retest this please

added warning that is not a real warning to not break jenkins

removed WARNING: prefix to not break jenkins
@aidankeefe2022

Copy link
Copy Markdown
Member Author

retest this please

@SparkiDev
SparkiDev merged commit 796a824 into wolfSSL:master Sep 7, 2026
371 checks passed
@aidankeefe2022
aidankeefe2022 deleted the fix-TLS-RFC-issue branch September 15, 2026 16:28
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants