🛡️ Sentinel: Allow configurable Cipher Suite #11
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🛡️ Sentinel: Allow configurable Cipher Suite
Vulnerability: The
entrypoint.shscript hardcodedDHE-RSA-AES256-SHAas the only allowed cipher suite.Impact: Users were unable to use modern, stronger ciphers (e.g., AES-GCM) supported by newer SoftEther versions and TLS 1.2+ clients.
Fix: Introduced
CIPHER_SUITESenvironment variable with a default ofDHE-RSA-AES256-SHA. This allows overriding the cipher suite at runtime.Verification: Reviewed
entrypoint.shlogic to ensure the variable is used and defaults correctly. Verified script syntax withbash -n.PR created automatically by Jules for task 14272976687347461831 started by @bluPhy