git/list[1] front-page[2] threads[3] people[4] search[5] about
 

Re: [PATCH] send-email: clarify SMTP encryption settings

From
Junio C Hamano <gitster@pobox.com>
Date
Apr 10, 2021, 01:09 UTC
Message-ID
<xmqqczv3kks4.fsf@gitster.g>
In-Reply-To
<CAJMW3X0O81L.8TNFDEFUNML1@taiga>
"Drew DeVault" <sir@cmpwn.com> writes:
Show 10 quoted lines
>> I couldn't find a justification for our log message to call
>> STARTTLS-style explicit TLS "deprecated". When you send an updated
>> version, please give a reference.
>
> The main concern with STARTTLS is downgrade attacks. I'll note this in
> the commit message for v2.
> ...
> If I may propose a bold alternative: what I added as "ssl/tls", i.e.
> "modern" SSL, should be "yes", no encryption should be "no", and if you
> specifically need starttls: "starttls".
Well, "is starttls deprecated" given to search engine gives me
    SMTPS (implicit SSL) has been deprecated/obsolete since
    SMTP+STARTTLS (explicit SSL) was defined in RFC2487.

as the "featured snippet", and there are debates like "SMTPS has been deprecated since forever (late 90's or thereabouts)" https://news.ycombinator.com/item?id=10556797

I strongly prefer to keep our documentation out of that mess by not taking sides. To me, both are valid options to make the world safer over cleartext, and we won't have to make recommendations when both are available.

Thanks.
Previous: Drew DeVaultNext: Bagas Sanjaya
Message 7 of 11 in “send-email: clarify SMTP encryption settings”
  1. send-email: clarify SMTP encryption settingsDrew DeVault, Apr 9, 2021
  2. Eric SunshineApr 9, 2021
  3. Georgios KontaxisApr 9, 2021
  4. Drew DeVaultApr 9, 2021
  5. Junio C HamanoApr 10, 2021
  6. Drew DeVaultApr 10, 2021
  7. Junio C HamanoApr 10, 2021
  8. Bagas SanjayaApr 11, 2021
  9. brian m. carlsonApr 10, 2021
  10. Drew DeVaultApr 10, 2021
  11. Junio C HamanoApr 10, 2021

Read the whole thread, see it on lore, or plain text.

$ cat FOOTERMessages come from the public archive at lore.kernel.org/git, fetched every hour. The front page is chosen and written each morning by an AI editor and can be wrong; the threads themselves are the record. About and API. For agents: an MCP server at https://gitlist.dev/mcp, and any thread, story or person page as Markdown by adding .md to its URL (or sending Accept: text/markdown). Details in /llms.txt.