Update TLS settings (#72)
This commit is contained in:
parent
86bb9a4c71
commit
a4bacca812
1 changed files with 5 additions and 2 deletions
|
@ -85,8 +85,11 @@ base by `doom!' and for calculating how many packages exist.")
|
||||||
;; than pulled, so packages are often out of date with upstream.
|
;; than pulled, so packages are often out of date with upstream.
|
||||||
|
|
||||||
;; security settings
|
;; security settings
|
||||||
tls-checktrust (not (getenv "INSECURE"))
|
gnutls-verify-error (not (getenv "INSECURE")) ; INSECURE is for integrated testing
|
||||||
gnutls-verify-error tls-checktrust
|
tls-checktrust gnutls-verify-error
|
||||||
|
tls-program (list "gnutls-cli --x509cafile %t -p %p %h"
|
||||||
|
;; less likely to be secure, but allow for backwards compatibility
|
||||||
|
"openssl s_client -connect %h:%p -no_ssl2 -ign_eof")
|
||||||
|
|
||||||
use-package-always-defer t
|
use-package-always-defer t
|
||||||
use-package-always-ensure nil
|
use-package-always-ensure nil
|
||||||
|
|
Loading…
Add table
Add a link
Reference in a new issue