mirror of
https://github.com/mumble-voip/mumble.git
synced 2025-10-26 11:19:16 +00:00
Mumble is an open-source, low-latency, high quality voice chat software.
audioclientcmakecross-platformgaminghacktoberfestlinuxmacosopen-sourcequality-voice-chatservervoicechatvoipwindows
This commit adds a new method to MumbleSSL that returns Mumble's preferred cipher suites represented in the OpenSSL cipher list format. This commit does not hook up the function to anything. It merely implements it. Previously, Mumble relied on OpenSSL's default cipher suites. However, that decision has increasingly turned out to be unwise. Often, new TLS vulnerabilities require server admins and users to be able to change the cipher suites advertised by their software to help mitigate the damage. This was not previously possible in Mumble. The other thing that prompted this change is the Logjam TLS vulnerablity (https://weakdh.org/, CVE-2015-4000). Mumble is not vulnerable to Logjam, because Mumble has never allowed export grade DH groups. However, one of the other key takeaways from the Logjam paper, "Imperfect Forward Secrecy: How Diffie-Hellman Fails in Practice", is that the Internet community should move towards DH groups bigger than 1024 bits, and preferably use unique groups on a per-server basis. Unfortunately, neither of these two solutions are possible with API that Qt provides for TLS. To remedy this, we instead drop support for non-Elliptic Curve DH in the default cipher configuration. We don't have any legacy clients to support that can only use DH, so this is fine. The OpenSSL cipher list in MumbleSSL::defaultOpenSSLCipherString() evaluates to the following set of cipher suites, in order of preference: ECDHE-RSA-AES256-GCM-SHA384 (TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) ECDHE-ECDSA-AES256-GCM-SHA384 (TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384) ECDHE-RSA-AES128-GCM-SHA256 (TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256) ECDHE-ECDSA-AES128-GCM-SHA256 (TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256) AES256-SHA (TLS_RSA_WITH_AES_256_CBC_SHA) AES128-SHA (TLS_RSA_WITH_AES_128_CBC_SHA) The CBC-mode cipher suites are included for backwards compatibility with older 1.2.x Mumble clients and other implementations that only use TLSv1.0. |
||
|---|---|---|
| .tx | ||
| 3rdparty | ||
| 3rdPartyLicenses | ||
| g15helper | ||
| icons | ||
| installer | ||
| macx | ||
| man | ||
| overlay | ||
| overlay_gl | ||
| overlay_winx64 | ||
| plugins | ||
| samples | ||
| scripts | ||
| src | ||
| toolchain/win32-msvc2013 | ||
| .gitignore | ||
| .gitmodules | ||
| CHANGES | ||
| compiler.pri | ||
| Doxyfile | ||
| INSTALL | ||
| LICENSE | ||
| main.pro | ||
| qt.pri | ||
| README | ||
| README.Linux | ||
| README.static.linux | ||
| README.static.osx | ||
| symbols.pri | ||
| winpaths_default.pri | ||
| winpaths_static.pri | ||
M U M B L E
A voicechat utility for gamers
http://mumble.info/
#mumble on freenode
Mumble is a voicechat program for gamers written on top of Qt and Speex.
There are two modules in Mumble; the client (mumble) and the server
(murmur). The client works on Win32/64, Linux and Mac OS X, while the
server should work on anything Qt can be installed on.
Note that when we say Win32, we mean Windows XP or newer.
Running Mumble
==============
On Windows, after installation, you should have a new Mumble folder in your
Start Menu, from which you can start Mumble.
On Mac OS X, to install Mumble, drag the application from the downloaded
disk image into your /Applications folder.
Once Mumble is launched, you need a server to connect to. Either create your
own or join a friend's.
Running Murmur on Unix-like systems
===================================
Murmur should be run from the command line, so start a shell (command prompt)
and go to wherever you installed Mumble. Run murmur as
murmurd [-supw <password>] [-ini <inifile>] [-fg] [v]
-supw Set new password for the user SuperUser, which is hardcoded to
bypass ACLs. Keep this password safe. Until you set a password,
the SuperUser is disabled. If you use this option, murmur will
set the password in the database and then exit.
-ini Use a inifile other than murmur.ini, use this to run several instances
of murmur from the same directory. Make sure each instance is using
a separate database.
-fg Run in the foreground, logging to standard output.
-v More verbose logging.
Running Murmur on Mac OS X
==========================
On Mac OS X, Murmur is available inside your Mumble application bundle. If you
copied the Mumble program into your Applications directory, you should be able
to run it by executing:
/Applications/Mumble.app/Contents/MacOS/murmurd -v -fg
in a Terminal. For more information, please see the 'Running Murmur on Unix-
like sytems' above.
To easily override the default Murmur configuration, a murmur.ini file can be placed in
your user's 'Library/Preferences/Mumble/' directory.
Example configuration files and other scripts can be found inside the Murmur
directory of the Mumble installation disk image.
Running Murmur on Win32
=======================
Doubleclick the Murmur icon to start murmur. There will be a small icon on your
taskbar from which you can view the log.
To set the superuser password, run murmur with the parameters '-supw <password>'.
Bandwidth usage
===============
Mumble will use 10-40 kbit/s outgoing, and the same incoming for each user.
So if there are 10 other users on the server with you, your incoming
bandwidth requirement will be 100-400 kbit/s if they all talk at the same time.