Re: introduce a function like SSL_CTX_set_security_standards()?

Viktor Dukhovni <[email protected]>
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
On Tue, May 06, 2025 at 03:46:32PM +0200, 'Wiebe Cazemier' via openssl-users wrote:

> > Don't do that.  There's really no need.  Reject incompetent auditors who
> > don't understand that TLS is as strong as the strongest mutually
> > supported parameters, and prematurely rejecting slightly dated
> > parameters is often a bad tradeoff.
> 
> 
> People do though. Ubuntu/Debian's Nginx config contains:
> 
>   ssl_protocols TLSv1 TLSv1.1 TLSv1.2 TLSv1.3; # Dropping SSLv3, ref: POODLE
> 
> So, they are indeed frozen in today's best practices. 

File bugs against those systems.  They need to support the
OpenSSL "MinProtocol" setting.  Postfix has supported this
since version 3.6 (released Feb 24 2016).  I might expect
that 9 years later, some of these other software packages
would offer equivalent functionality:

    http://www.postfix.org/postconf.5.html#smtp_tls_protocols

-- 
    Viktor.

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/aBoWMk1nMCUAyge-%40chardros.imrryr.org.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.