Re: [TLS] No cypher overlap (was: ban more old crap)

2015-07-29 Thread Hubert Kario
On Tuesday 28 July 2015 16:01:55 Viktor Dukhovni wrote: > On Tue, Jul 28, 2015 at 05:41:58PM +0200, Hubert Kario wrote: > > I see one possible problem with TLS1.3 not being a superset of TLS1.2. > > > > Consider the following: > > Server which supports TLSv1.3 but is configured to accept only AES2

Re: [TLS] No cypher overlap (was: ban more old crap)

2015-07-28 Thread Viktor Dukhovni
On Tue, Jul 28, 2015 at 05:41:58PM +0200, Hubert Kario wrote: > I see one possible problem with TLS1.3 not being a superset of TLS1.2. > > Consider the following: > Server which supports TLSv1.3 but is configured to accept only AES256 > ciphers. > > Client which advertises TLSv1.3, but no suppor