[NNTP] RC4 TLS cipher with NNTP

Julien ÉLIE <[email protected]> Tue, 1 Sep 2015 21:46:52 +0200
Newsgroups gmane.ietf.nntp
Organization TrigoFACILE -- http://www.trigofacile.com/
Message-ID <[email protected]>
Hi all,

The recently published RFC 7465 prohibits the use of RC4 cipher suites:=20
  "This document requires that TLS clients and servers never negotiate=20
the use of RC4 cipher suites."

Yet, our RFC 4642 about the use of TLS with NNTP states:

    NNTP client and server implementations MUST implement the
    TLS_RSA_WITH_RC4_128_MD5 cipher suite and SHOULD implement the
    TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA cipher suite.  This is
    important, as it assures that any two compliant implementations can
    be configured to interoperate.  All other cipher suites are OPTIONAL.


There is a discrepancy now between these two RFCs.  Shouldn't something=20
be done about that?  Interoperability will be broken in NNTP as=20
TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA is not mandatory.  Furthermore, that=20
chipher suite may also become unsecure one day...

--=20
Julien =C3=89LIE

=C2=AB =E2=80=93 Nous voyageons plus vite que la lumi=C3=A8re !
   =E2=80=93 Alors comment y voir clair dans tout =C3=A7a ? =C2=BB (Ast=C3=
=A9rix)