{{ message }}
Commit dae4341
doc: fix broken TLS security level example
The example under "Setting security levels" does not run. The client
sets `maxVersion: 'TLSv1'` while its `minVersion` stays at the
`tls.DEFAULT_MIN_VERSION` default of `'TLSv1.2'`, so no version overlaps
and the connection fails with ERR_SSL_NO_PROTOCOLS_AVAILABLE. Setting
the client's `minVersion` is not enough on its own: the handshake then
fails with an alert 40, because `createServer` is given no key or
certificate and the server has no shared cipher.
Set `minVersion` on the client, add the key and certificate placeholders
and the openssl recipe that the other sections using them already carry,
pass the server certificate as the client's `ca`, and use port 8000 like
the rest of the file. The section now runs from an empty directory and
prints "Client connected with protocol: TLSv1".
Signed-off-by: Julian Soreavis <julian.soreavis@gmail.com>
PR-URL: #65391
Fixes: #60569
Refs: #60571
Reviewed-By: Tim Perry <pimterry@gmail.com>
Reviewed-By: James M Snell <jasnell@gmail.com>1 parent 35b18b4 commit dae4341
1 file changed
Lines changed: 35 additions & 6 deletions

0 commit comments