Re: SSL: better default ciphersuite

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: SSL: better default ciphersuite
Дата
Msg-id 1386815383.28197.2.camel@vanquo.pezone.net
обсуждение исходный текст
Ответ на Re: SSL: better default ciphersuite  (Marko Kreen <markokr@gmail.com>)
Ответы Re: SSL: better default ciphersuite
Re: SSL: better default ciphersuite
Список pgsql-hackers
On Fri, 2013-11-29 at 18:43 +0200, Marko Kreen wrote:
> Well, we should - the DEFAULT is clearly a client-side default
> for compatibility only.  No server should ever run with it.

Any other opinions on this out there?  All instances of other
SSL-enabled servers out there, except nginx, default to some variant of
DEFAULT:!LOW:... or HIGH:MEDIUM:....  The proposal here is essentially
to disable MEDIUM ciphers by default, which is explicitly advised
against in the Postfix and Dovecot documentation, for example.




В списке pgsql-hackers по дате отправления:

Предыдущее
От: Kyotaro HORIGUCHI
Дата:
Сообщение: [BUG] Archive recovery failure on 9.3+.
Следующее
От: Tatsuo Ishii
Дата:
Сообщение: pgbench with large scale factor