Re: Min/max cipher suite configurations

2015-06-05 Thread Viktor Dukhovni
On Fri, Jun 05, 2015 at 10:36:03AM +0200, Per Thorsheim wrote: > RFC2595 says that TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA is REQUIRED when > configuring TLS for IMAP, POP & AMAP. > > All other cipher suites are OPTIONAL. Time marches on, while old RFCs stay the same. > I'm sure I'm missing out on so

Min/max cipher suite configurations

2015-06-05 Thread Per Thorsheim
RFC2595 says that TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA is REQUIRED when configuring TLS for IMAP, POP & AMAP. All other cipher suites are OPTIONAL. RFC4616 replaced section 6 of RFC2595, with updated info for SASL. RFC3207 obsoleted RFC247, and covers both TCP/25 and the submission port (RFC2476).