Message214309
| Author | dstufft |
|---|
| Recipients | Arfrever, alex, benjamin.peterson, christian.heimes, dstufft, ezio.melotti, lemburg, ncoghlan, pitrou, r.david.murray, vstinner |
|---|
| Date | 2014-03-20.23:38:48 |
|---|
| SpamBayes Score | -1.0 |
|---|
| Marked as misclassified | Yes |
|---|
| Message-id | <1395358728.76.0.429058404543.issue20995@psf.upfronthosting.co.za> |
|---|
| In-reply-to | |
|---|
| Content |
|---|
> > However I still content that using HIGH in the cipherstring actually> > adds additional maintenance burden. In order to know if that> > cipherstring is still safe you must run it against every target> > OpenSSL you want to make secure to ensure that it doesn't allow a new> > cipher that doesn't meet the security strength that was attempted to> > be had with that cipherstring.> I think that is a bit reverse. The main configuration point for ciphers> should be the server, not the client. We set a cipher string to guide> cipher selection in case the server lets us choose amongst its supported> ciphers, but that's all.The Python ssl module is used for servers and clients. Ideally servers willhave prefer server ciphers on, but that doesn't always happen and providinga modern level of security for end users is preferable. > Besides, the ssl module doesn't promise a specific "security strength".> The defaults are a best effort thing, and paranoid people should> probably override the cipher string (and deal with the consequences).These are not things that affect only paranoid people and expecting someoneto even know what OpenSSL is much less how to configure it and what they wantto configure it to in order to get modern levels of security is backwards. Thedanger for breakage here is *tiny*, *miniscule*, almost non existent and thefailure case is obvious and easy to fix. |
| History |
|---|
| Date | User | Action | Args |
|---|
| 2014-03-20 23:38:48 | dstufft | set | recipients: +dstufft,lemburg,ncoghlan,pitrou,vstinner,christian.heimes,benjamin.peterson,ezio.melotti,Arfrever,alex,r.david.murray | | 2014-03-20 23:38:48 | dstufft | set | messageid: <1395358728.76.0.429058404543.issue20995@psf.upfronthosting.co.za> | | 2014-03-20 23:38:48 | dstufft | link | issue20995 messages | | 2014-03-20 23:38:48 | dstufft | create | |
|