Re: System-wide crypto policy transition tracker

2015-01-07 Thread Michael Catanzaro
On Tue, Jan 6, 2015 at 9:20 AM, Nikos Mavrogiannopoulos wrote: Hello, I've created a transition tracker to system-wide crypto policy at: https://bugzilla.redhat.com/show_bug.cgi?id=1179209 Currently it contains bugs filled against openssl and gnutls applications in Fedora. If you use some appl

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Miloslav Trmač
> On Tue, Jan 6, 2015 at 10:20 AM, Nikos Mavrogiannopoulos < n...@redhat.com > > wrote: > > I've created a transition tracker to system-wide crypto policy at: > > > https://bugzilla.redhat.com/show_bug.cgi?id=1179209 > > Also, what about situations where SSL/TLS is off by default in the > ap

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Christopher
On Wed, Jan 7, 2015 at 4:04 AM, Nikos Mavrogiannopoulos wrote: > On Tue, 2015-01-06 at 12:16 -0500, Christopher wrote: > > > > Are there any guidelines for enforcing crypto policies in Java > > applications. > > Primarily, I was thinking about those Java applications that use JSSE > > system prop

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Paul Wouters
On Wed, 7 Jan 2015, Petr Spacek wrote: The tracker also contains a dependency on NSS respecting the system crypto policy: https://bugzilla.redhat.com/show_bug.cgi?id=1157720 I wonder what is your plan moving forward. Is it going to be 'TLS policy'? Or are you planning to generalize it in futur

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Nikos Mavrogiannopoulos
On Tue, 2015-01-06 at 09:55 -0700, Kevin Fenzi wrote: > > Currently it contains bugs filled against openssl and gnutls > > applications in Fedora. If you use some application which utilizes > > SSL/TLS and isn't included in the tracker feel free to request it use > > the policy, and include a link

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Nikos Mavrogiannopoulos
On Wed, 2015-01-07 at 09:18 +0100, Petr Spacek wrote: > > Currently it contains bugs filled against openssl and gnutls > > applications in Fedora. If you use some application which utilizes > > SSL/TLS and isn't included in the tracker feel free to request it use > > the policy, and include a link

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Nikos Mavrogiannopoulos
On Tue, 2015-01-06 at 11:27 -0600, Michael Cronenworth wrote: > On 01/06/2015 09:20 AM, Nikos Mavrogiannopoulos wrote: > > I've created a transition tracker to system-wide crypto policy at: > > https://bugzilla.redhat.com/show_bug.cgi?id=1179209 > > > > Currently it contains bugs filled against o

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Nikos Mavrogiannopoulos
On Tue, 2015-01-06 at 18:41 +0100, Till Maas wrote: > On Tue, Jan 06, 2015 at 04:20:55PM +0100, Nikos Mavrogiannopoulos wrote: > > > I've created a transition tracker to system-wide crypto policy at: > > https://bugzilla.redhat.com/show_bug.cgi?id=1179209 > Should the proposed changes be pushed u

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Nikos Mavrogiannopoulos
On Tue, 2015-01-06 at 12:16 -0500, Christopher wrote: > Are there any guidelines for enforcing crypto policies in Java > applications. > Primarily, I was thinking about those Java applications that use JSSE > system properties or similar user-driven configuration to specify > keystores. Are those

Re: System-wide crypto policy transition tracker

2015-01-07 Thread Petr Spacek
On 6.1.2015 16:20, Nikos Mavrogiannopoulos wrote: > Hello, > I've created a transition tracker to system-wide crypto policy at: > https://bugzilla.redhat.com/show_bug.cgi?id=1179209 > > Currently it contains bugs filled against openssl and gnutls > applications in Fedora. If you use some applicat

Re: System-wide crypto policy transition tracker

2015-01-06 Thread Till Maas
On Tue, Jan 06, 2015 at 04:20:55PM +0100, Nikos Mavrogiannopoulos wrote: > I've created a transition tracker to system-wide crypto policy at: > https://bugzilla.redhat.com/show_bug.cgi?id=1179209 > > Currently it contains bugs filled against openssl and gnutls > applications in Fedora. If you us

Re: System-wide crypto policy transition tracker

2015-01-06 Thread Michael Cronenworth
On 01/06/2015 09:20 AM, Nikos Mavrogiannopoulos wrote: I've created a transition tracker to system-wide crypto policy at: https://bugzilla.redhat.com/show_bug.cgi?id=1179209 Currently it contains bugs filled against openssl and gnutls applications in Fedora. If you use some application which u

Re: System-wide crypto policy transition tracker

2015-01-06 Thread Christopher
On Tue, Jan 6, 2015 at 10:20 AM, Nikos Mavrogiannopoulos wrote: > Hello, > I've created a transition tracker to system-wide crypto policy at: > https://bugzilla.redhat.com/show_bug.cgi?id=1179209 > > Currently it contains bugs filled against openssl and gnutls > applications in Fedora. If you us

Re: System-wide crypto policy transition tracker

2015-01-06 Thread Kevin Fenzi
On Tue, 06 Jan 2015 16:20:55 +0100 Nikos Mavrogiannopoulos wrote: > Hello, > I've created a transition tracker to system-wide crypto policy at: > https://bugzilla.redhat.com/show_bug.cgi?id=1179209 > > Currently it contains bugs filled against openssl and gnutls > applications in Fedora. If you