On 2/1/19 9:07 PM, Richard Laager wrote:
> On 2/1/19 7:56 PM, Gary E. Miller via devel wrote:
>> "tlsver [1.2 1.3]*
> If forcing a maximum version (e.g. for testing) is important, tlsver
> seems like a good approach.

Another approach would be to allow specifying a minimum and maximum
version. That's what Firefox recently did, citing "We need policies for
min/max TLS to be consistent Chrome and for the DOD STIG."

https://bugzilla.mozilla.org/show_bug.cgi?id=1522182

So maybe that's a better way.

I'm not familiar with DOD security policies, so I'm not able to find a
reference either way as to whether a _maximum_ TLS version setting is
required.

-- 
Richard

Attachment: signature.asc
Description: OpenPGP digital signature

_______________________________________________
devel mailing list
devel@ntpsec.org
http://lists.ntpsec.org/mailman/listinfo/devel

Reply via email to