Re: introduce a function like SSL_CTX_set_security_standards()?

"'Wiebe Cazemier' via openssl-users" <[email protected]>
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
----- Original Message -----
> From: "Dmitry Belyavsky" <[email protected]>
> To: "Wiebe Cazemier" <[email protected]>
> Cc: [email protected]
> Sent: Sunday, 4 May, 2025 22:12:21
> Subject: Re: introduce a function like SSL_CTX_set_security_standards()?
>
> You probably may be interested in the solution named "crypto-policies" present
> in Fedora, CentOS, RHEL and some more systems. It ensures system-wide defaults
> for cryptographic libraries and correctly written applications via
> configuration snippets
>
> SY, Dmitry Belyavsky


Hi Dmitry,

Definitely something I can look at, but I was hoping to introduce a common practice between all programmers who use OpenSSL to not just create options for end-users to configure protocols and ciphers, but move more towards sane defaults without knowing anything about them (in other words, not putting it on me as a program writer to keep the protocols and ciphers up-to-date). Having a crypto library that by default enables everything weak is bad practice in my opinion.

This function should then also clearly be named in the SSL_CTX_new() function, so that use is encouraged. Perhaps eventually moving towards setting DEPRECATED as default level.

Regards,

Wiebe

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/2123895636.581.1746416025044.JavaMail.zimbra%40halfgaar.net.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.