Re: SSL: better default ciphersuite

Поиск
Список
Период
Сортировка
От Peter Eisentraut
Тема Re: SSL: better default ciphersuite
Дата
Msg-id 53094F62.4010308@gmx.net
обсуждение исходный текст
Ответ на Re: SSL: better default ciphersuite  (Marko Kreen <markokr@gmail.com>)
Ответы Re: SSL: better default ciphersuite  (Marko Kreen <markokr@gmail.com>)
Список pgsql-hackers
On 2/2/14, 7:16 AM, Marko Kreen wrote:
> On Thu, Dec 12, 2013 at 04:32:07PM +0200, Marko Kreen wrote:
>> Attached patch changes default ciphersuite to HIGH:MEDIUM:+3DES:!aNULL
>> and also adds documentation about reasoning for it.
> 
> This is the last pending SSL cleanup related patch:
> 
>   https://commitfest.postgresql.org/action/patch_view?id=1310
> 
> Peter, you have claimed it as committer, do you see any remaining
> issues with it?

I'm OK with this change on the principle of clarifying and refining the
existing default.  But after inspecting the expanded cipher list with
the "openssl cipher" tool, I noticed that the new default re-enabled MD5
ciphers.  Was that intentional?





В списке pgsql-hackers по дате отправления:

Предыдущее
От: Peter Eisentraut
Дата:
Сообщение: Re: Review: tests for client programs
Следующее
От: Mohsen SM
Дата:
Сообщение: typemode for variable types