Salz, Rich
2014-09-08 22:42:47 UTC
We are considering removing weak cryptography from the value of DEFAULT. That is, append ":!LOW:!EXPORT"
It is currently defined as this in include/openssl/ssl.h:
#define SSL_DEFAULT_CIPHER_LIST "ALL:!aNULL:!eNULL:!SSLv2"
Please let us know if you have strong objections to this.
--
Principal Security Engineer
Akamai Technologies, Cambridge MA
IM: rsalz-dbVaDHFsUTizQB+***@public.gmane.org Twitter: RichSalz
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List openssl-users-MCmKBN63+***@public.gmane.org
Automated List Manager majordomo-MCmKBN63+***@public.gmane.org
It is currently defined as this in include/openssl/ssl.h:
#define SSL_DEFAULT_CIPHER_LIST "ALL:!aNULL:!eNULL:!SSLv2"
Please let us know if you have strong objections to this.
--
Principal Security Engineer
Akamai Technologies, Cambridge MA
IM: rsalz-dbVaDHFsUTizQB+***@public.gmane.org Twitter: RichSalz
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List openssl-users-MCmKBN63+***@public.gmane.org
Automated List Manager majordomo-MCmKBN63+***@public.gmane.org