summary refs log tree commit diff
path: root/synapse/crypto
diff options
context:
space:
mode:
authorWill Hunt <will@half-shot.uk>2018-04-30 16:21:11 +0100
committerRichard van der Hoff <1389908+richvdh@users.noreply.github.com>2018-04-30 16:21:11 +0100
commit2ad3fc36e66fcc86cc3fde99760e4851402a8d56 (patch)
tree9fe3904457ccf98faaf3be5fb61f237e3933fd92 /synapse/crypto
parentMerge pull request #3160 from krombel/fix_3076 (diff)
downloadsynapse-2ad3fc36e66fcc86cc3fde99760e4851402a8d56.tar.xz
Fixes #3135 - Replace _OpenSSLECCurve with crypto.get_elliptic_curve (#3157)
fixes #3135

Signed-off-by: Will Hunt will@half-shot.uk
Diffstat (limited to 'synapse/crypto')
-rw-r--r--synapse/crypto/context_factory.py9
1 files changed, 5 insertions, 4 deletions
diff --git a/synapse/crypto/context_factory.py b/synapse/crypto/context_factory.py
index cff3ca809a..0397f73ab4 100644
--- a/synapse/crypto/context_factory.py
+++ b/synapse/crypto/context_factory.py
@@ -13,8 +13,8 @@
 # limitations under the License.
 
 from twisted.internet import ssl
-from OpenSSL import SSL
-from twisted.internet._sslverify import _OpenSSLECCurve, _defaultCurveName
+from OpenSSL import SSL, crypto
+from twisted.internet._sslverify import _defaultCurveName
 
 import logging
 
@@ -32,8 +32,9 @@ class ServerContextFactory(ssl.ContextFactory):
     @staticmethod
     def configure_context(context, config):
         try:
-            _ecCurve = _OpenSSLECCurve(_defaultCurveName)
-            _ecCurve.addECKeyToContext(context)
+            _ecCurve = crypto.get_elliptic_curve(_defaultCurveName)
+            context.set_tmp_ecdh(_ecCurve)
+
         except Exception:
             logger.exception("Failed to enable elliptic curve for TLS")
         context.set_options(SSL.OP_NO_SSLv2 | SSL.OP_NO_SSLv3)