git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH v3] http: add support for specifying the SSL version

From
ILIlari Liusvaara <ilari.liusvaara@elisanet.fi>
Date
Aug 13, 2015, 16:24 UTC
Message-ID
<20150813162454.GA18545@LK-Perkele-VII>
In-Reply-To
<CA+EOSBkzU=6pKkqYdGqRRcbbudTJkRwcXxswP+zMshVrZaM_mw@mail.gmail.com>
On Thu, Aug 13, 2015 at 06:10:48PM +0200, Elia Pinto wrote:
Show 9 quoted lines
> 2015-08-13 18:01 GMT+02:00 Torsten Bögershausen <tboegi@web.de>:
> >> +
> > from
> > https://en.wikipedia.org/wiki/Transport_Layer_Security#SSL_1.0.2C_2.0_and_3.0
> > sslv2 and sslv3 are deprecated.
> > Should there be a motivation in the commit message why we want to support them ?
> They are those provided by the documentation (TLS in particular). We
> let the underlying library to say what is deprecated or not. In this
> case the call fail.

The statement from the relevant SDO is much stronger than "deprecated", it is "not to be used under any cirmumstances".

Option like this looks only useful for connecting to really broken servers, damn security.

It could be useful for connecting to buggy servers after TLS 1.3 comes out and is implemented, as there are lots of servers (IIRC, on order of 10%) that can't deal with TLS 1.3 properly (but very few, IIRC <<0.1%, that can't deal with TLS 1.2 correctly[1]).

Also, is this option settable globally for all HTTP servers? One definitely does not want that to be possible. Configurations like this need to be per-server if they exist at all.

[1] Where correctly includes secure downnegotiation, as TLS is intended to do when faced with version mismatch.

-Ilari
Previous: Elia PintoNext: Elia Pinto
Message 10 of 13 in “http: add support for specifying the SSL version”
  1. http: add support for specifying the SSL versionElia Pinto, Aug 13, 2015
  2. Eric SunshineAug 13, 2015
  3. Elia PintoAug 13, 2015
  4. Eric SunshineAug 13, 2015
  5. Elia PintoAug 13, 2015
  6. Eric SunshineAug 13, 2015
  7. Eric SunshineAug 13, 2015
  8. Torsten BögershausenAug 13, 2015
  9. Elia PintoAug 13, 2015
  10. Ilari LiusvaaraAug 13, 2015
  11. Elia PintoAug 13, 2015
  12. Junio C HamanoAug 14, 2015
  13. Elia PintoAug 14, 2015

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.