Re: TLSv1.2 needed in Debian 6 LTS

2015-02-09 Thread Florian Weimer
* Disch Services GmbH: > To sum this up: we need Debian 6 LTS with TLSv1.2 (i.e. with a recent > OpenSSL implemenation). Alternatively, you could set up proxies running wheezy and continue to use a squeeze-based core infrastructure. HTTPS has very good support for this, but for SMTP and IMAP, it

Re: Re: TLSv1.2 needed in Debian 6 LTS

2015-02-03 Thread Isidor Zeuner
Hi there, comments in-line: Den 02.02.15 15.54, skrev Disch Services GmbH: > Dear List, Hi there! Please note that what I write are my impressions and opinions, and not any official statement regarding what LTS can or should support. I'm not in a position to make such statements, either. Me n

Re: Fwd: Re: TLSv1.2 needed in Debian 6 LTS

2015-02-02 Thread Moritz Muehlenhoff
On Tue, Feb 03, 2015 at 01:02:11AM +0100, Disch Services GmbH wrote: > Am 03.02.2015 um 00:04 schrieb Ben Hutchings: > >> No, the point is the claim that Debain 6 LTS has 5 year support until > >> mid. 2016. > > With a limited subset of package and architectures, and subject to > > developers being

Re: Fwd: Re: TLSv1.2 needed in Debian 6 LTS

2015-02-02 Thread Disch Services GmbH
Am 03.02.2015 um 00:04 schrieb Ben Hutchings: >> No, the point is the claim that Debain 6 LTS has 5 year support until >> mid. 2016. > With a limited subset of package and architectures, and subject to > developers being available to do this. A limited subset of packages! This should be documented

Re: Fwd: Re: TLSv1.2 needed in Debian 6 LTS

2015-02-02 Thread Ben Hutchings
On Mon, 2015-02-02 at 18:23 +0100, Disch Services GmbH wrote: > > Am 02.02.2015 um 17:12 schrieb Jan Ingvoldstad: > > > But Ubuntu 12 LTS has OpenSSL which supports TLSv1.2 and PFS. > > > > > Debian Squeeze was feature-frozen in August 2010, one and a half > > year before Ubuntu 12.04 LTS. That i

Re: TLSv1.2 needed in Debian 6 LTS

2015-02-02 Thread Disch Services GmbH
Am 02.02.2015 um 17:33 schrieb Matus UHLAR - fantomas: > On 02.02.15 15:54, Disch Services GmbH wrote: >> The technical recommendation of BSI (See 1.) for TLS is stating, that >> TLSv1.0 isn't recommended any more starting in 2015. > > my german is not very good, but I haven't seen it there. > Whe

Fwd: Re: TLSv1.2 needed in Debian 6 LTS

2015-02-02 Thread Disch Services GmbH
Am 02.02.2015 um 17:12 schrieb Jan Ingvoldstad: >> But Ubuntu 12 LTS has OpenSSL which supports TLSv1.2 and PFS. > Debian Squeeze was feature-frozen in August 2010, one and a half year > before Ubuntu 12.04 LTS. That is, it was feature-frozen while Ubuntu > 10.04 was the current Ubuntu version. >

Re: TLSv1.2 needed in Debian 6 LTS

2015-02-02 Thread Matus UHLAR - fantomas
On 02.02.15 15:54, Disch Services GmbH wrote: The technical recommendation of BSI (See 1.) for TLS is stating, that TLSv1.0 isn't recommended any more starting in 2015. my german is not very good, but I haven't seen it there. Where did you (or other) get the info that TLS1.0 is not recommended

Re: TLSv1.2 needed in Debian 6 LTS

2015-02-02 Thread Jan Ingvoldstad
Den 02.02.15 15.54, skrev Disch Services GmbH: Dear List, Hi there! Please note that what I write are my impressions and opinions, and not any official statement regarding what LTS can or should support. I'm not in a position to make such statements, either. right now I struggle with some i

TLSv1.2 needed in Debian 6 LTS

2015-02-02 Thread Disch Services GmbH
Dear List, right now I struggle with some issues about supported encryption protocols in Debian 6 LTS. The technical recommendation of BSI (See 1.) for TLS is stating, that TLSv1.0 isn't recommended any more starting in 2015. The same document says, that TLSv1.1 may be used in 2015 rsp. 2017+ wi