Re: introduce a function like SSL_CTX_set_security_standards()?
"'Wiebe Cazemier' via openssl-users" <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <[email protected]> |
----- Original Message ----- > From: "Dmitry Belyavsky" <[email protected]> > To: "Wiebe Cazemier" <[email protected]> > Cc: [email protected] > Sent: Sunday, 4 May, 2025 22:12:21 > Subject: Re: introduce a function like SSL_CTX_set_security_standards()? > > You probably may be interested in the solution named "crypto-policies" present > in Fedora, CentOS, RHEL and some more systems. It ensures system-wide defaults > for cryptographic libraries and correctly written applications via > configuration snippets > > SY, Dmitry Belyavsky Hi Dmitry, Definitely something I can look at, but I was hoping to introduce a common practice between all programmers who use OpenSSL to not just create options for end-users to configure protocols and ciphers, but move more towards sane defaults without knowing anything about them (in other words, not putting it on me as a program writer to keep the protocols and ciphers up-to-date). Having a crypto library that by default enables everything weak is bad practice in my opinion. This function should then also clearly be named in the SSL_CTX_new() function, so that use is encouraged. Perhaps eventually moving towards setting DEPRECATED as default level. Regards, Wiebe -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/2123895636.581.1746416025044.JavaMail.zimbra%40halfgaar.net.