summaryrefslogtreecommitdiff
path: root/configs
diff options
context:
space:
mode:
authorzuul <zuul@gerrit.asterisk.org>2016-08-19 14:20:36 -0500
committerGerrit Code Review <gerrit2@gerrit.digium.api>2016-08-19 14:20:36 -0500
commitd0f4e71c8818c4d6c1fc412e88574352fcd32ca8 (patch)
tree450b22a39286316a0994627324ed30d0cb9a507b /configs
parentc87ff471a735dda1dde3002129b883ae1e675e8d (diff)
parentd192cd125ce1daaf12f6f6d595b64d46f74eadbb (diff)
Merge "sip.conf: tlsclientmethod is using sslv23 as default." into 14
Diffstat (limited to 'configs')
-rw-r--r--configs/samples/sip.conf.sample11
1 files changed, 10 insertions, 1 deletions
diff --git a/configs/samples/sip.conf.sample b/configs/samples/sip.conf.sample
index a7b74df69..da176b4d6 100644
--- a/configs/samples/sip.conf.sample
+++ b/configs/samples/sip.conf.sample
@@ -611,7 +611,16 @@ srvlookup=yes ; Enable DNS SRV lookups on outbound calls
;
;tlsclientmethod=tlsv1 ; values include tlsv1, sslv3, sslv2.
; Specify protocol for outbound client connections.
- ; If left unspecified, the default is sslv2.
+ ; If left unspecified, the default is the general-
+ ; purpose version-flexible SSL/TLS method (sslv23).
+ ; With that, the actual protocol version used will
+ ; be negotiated to the highest version mutually
+ ; supported by Asterisk and the remote server, i.e.
+ ; TLSv1.2. The supported protocols are listed at
+ ; http://www.openssl.org/docs/ssl/SSL_CTX_new.html
+ ; SSLv2 and SSLv3 are disabled within Asterisk.
+ ; Your distribution might have changed that list
+ ; further.
;
;--------------------------- SIP timers ----------------------------------------------------
; These timers are used primarily in INVITE transactions.