On 2/1/19 9:07 PM, Richard Laager wrote: > On 2/1/19 7:56 PM, Gary E. Miller via devel wrote: >> "tlsver [1.2 1.3]* > If forcing a maximum version (e.g. for testing) is important, tlsver > seems like a good approach.
Another approach would be to allow specifying a minimum and maximum version. That's what Firefox recently did, citing "We need policies for min/max TLS to be consistent Chrome and for the DOD STIG." https://bugzilla.mozilla.org/show_bug.cgi?id=1522182 So maybe that's a better way. I'm not familiar with DOD security policies, so I'm not able to find a reference either way as to whether a _maximum_ TLS version setting is required. -- Richard
signature.asc
Description: OpenPGP digital signature
_______________________________________________ devel mailing list devel@ntpsec.org http://lists.ntpsec.org/mailman/listinfo/devel