mirror of
https://github.com/monero-project/monero.git
synced 2025-12-11 01:21:28 +09:00
Currently if a user specifies a ca file or fingerprint to verify peer, the default behavior is SSL autodetect which allows for mitm downgrade attacks. It should be investigated whether a manual override should be allowed - the configuration is likely always invalid.