Yo Eric! On Sat, 02 Feb 2019 20:12:32 +0000 "Eric S. Raymond via vc" <v...@ntpsec.org> wrote:
> > +To avoid having to hand-configure ciphers offered to the remote, we > +can initially have a list of common known-good ones wired in. > +Eventually, look into how openssl-ciphers does this and > autoconfigure. + > Per-server options now implemented in the config parser are now > described in docs/includes/assoc-options.txt > This goes against all existing practice. Bad idea. I suggest you look at the history of this in the Apache, nginx, portfix and sendmail worlds to see why this is a very bad idea. RGDS GARY --------------------------------------------------------------------------- Gary E. Miller Rellim 109 NW Wilmington Ave., Suite E, Bend, OR 97703 g...@rellim.com Tel:+1 541 382 8588 Veritas liberabit vos. -- Quid est veritas? "If you can’t measure it, you can’t improve it." - Lord Kelvin
pgpGCLAg22fQG.pgp
Description: OpenPGP digital signature
_______________________________________________ devel mailing list devel@ntpsec.org http://lists.ntpsec.org/mailman/listinfo/devel