Re: introduce a function like SSL_CTX_set_security_standards()?
Matt Caswell <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <CAODx15c2quaxg1-p0HyRnF8xvcam_euu1VRt4228MoAmJhETdg@mail.gmail.com> |
How is this proposal different to the existing `SSL_CTX_set_security_level()`? Matt On Mon, 5 May 2025 at 04:33, 'Wiebe Cazemier' via openssl-users < [email protected]> wrote: > ----- Original Message ----- > > From: "Dmitry Belyavsky" <[email protected]> > > To: "Wiebe Cazemier" <[email protected]> > > Cc: [email protected] > > Sent: Sunday, 4 May, 2025 22:12:21 > > Subject: Re: introduce a function like SSL_CTX_set_security_standards()? > > > > You probably may be interested in the solution named "crypto-policies" > present > > in Fedora, CentOS, RHEL and some more systems. It ensures system-wide > defaults > > for cryptographic libraries and correctly written applications via > > configuration snippets > > > > SY, Dmitry Belyavsky > > > Hi Dmitry, > > Definitely something I can look at, but I was hoping to introduce a common > practice between all programmers who use OpenSSL to not just create options > for end-users to configure protocols and ciphers, but move more towards > sane defaults without knowing anything about them (in other words, not > putting it on me as a program writer to keep the protocols and ciphers > up-to-date). Having a crypto library that by default enables everything > weak is bad practice in my opinion. > > This function should then also clearly be named in the SSL_CTX_new() > function, so that use is encouraged. Perhaps eventually moving towards > setting DEPRECATED as default level. > > Regards, > > Wiebe > > -- > You received this message because you are subscribed to the Google Groups > "openssl-users" group. > To unsubscribe from this group and stop receiving emails from it, send an > email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org > To view this discussion visit > https://groups.google.com/a/openssl.org/d/msgid/openssl-users/2123895636.581.1746416025044.JavaMail.zimbra%40halfgaar.net > . > -- You received this message because you are subscribed to the Google Groups "openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/CAODx15c2quaxg1-p0HyRnF8xvcam_euu1VRt4228MoAmJhETdg%40mail.gmail.com.