Re: F23 System Wide Change: Disable SSL3 and RC4 by default

2015-05-06 Thread Debarshi Ray
On Tue, Apr 28, 2015 at 04:51:32PM +0200, Nikos Mavrogiannopoulos wrote: > The plan is to allow re-enabling by switching the system to legacy > crypto policy. That would work for RC4. For SSL 3.0, since OpenSSL > doesn't provide knobs to enable or disable on runtime, that will not be > possible. Ho

Re: F23 System Wide Change: Disable SSL3 and RC4 by default

2015-05-06 Thread Stephen Gallagher
- Original Message - > From: "Jan Kurik" > To: devel-annou...@lists.fedoraproject.org > Sent: Tuesday, April 28, 2015 6:10:37 AM > Subject: F23 System Wide Change: Disable SSL3 and RC4 by default > > = Proposed System Wide Change: Disable SSL3

Re: F23 System Wide Change: Disable SSL3 and RC4 by default

2015-04-28 Thread Nikos Mavrogiannopoulos
On Tue, 2015-04-28 at 10:15 -0400, Russell Doty wrote: > > == Scope == > > * Proposal owners: The crypto-policies package has to be updated to > > accommodate the new policies. > > * Other developers: Should verify that their package works after the > > change. That is that their package doesn't

Re: F23 System Wide Change: Disable SSL3 and RC4 by default

2015-04-28 Thread Russell Doty
On Tue, 2015-04-28 at 06:10 -0400, Jan Kurik wrote: > = Proposed System Wide Change: Disable SSL3 and RC4 by default = > https://fedoraproject.org/wiki/Changes/RemoveSSL3andRc4 > > Change owner(s): Nikos Mavrogiannopoulos > > This change will disable by default the SSL 3.0 protocol and the RC4 c

F23 System Wide Change: Disable SSL3 and RC4 by default

2015-04-28 Thread Jan Kurik
= Proposed System Wide Change: Disable SSL3 and RC4 by default = https://fedoraproject.org/wiki/Changes/RemoveSSL3andRc4 Change owner(s): Nikos Mavrogiannopoulos This change will disable by default the SSL 3.0 protocol and the RC4 cipher in components which use the system wide crypto policy. Th