[NNTP] RC4 TLS cipher with NNTP
Julien ÉLIE <[email protected]> Tue, 1 Sep 2015 21:46:52 +0200
| Newsgroups | gmane.ietf.nntp |
|---|---|
| Organization | TrigoFACILE -- http://www.trigofacile.com/ |
| Message-ID | <[email protected]> |
Hi all,
The recently published RFC 7465 prohibits the use of RC4 cipher suites:=20
"This document requires that TLS clients and servers never negotiate=20
the use of RC4 cipher suites."
Yet, our RFC 4642 about the use of TLS with NNTP states:
NNTP client and server implementations MUST implement the
TLS_RSA_WITH_RC4_128_MD5 cipher suite and SHOULD implement the
TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA cipher suite. This is
important, as it assures that any two compliant implementations can
be configured to interoperate. All other cipher suites are OPTIONAL.
There is a discrepancy now between these two RFCs. Shouldn't something=20
be done about that? Interoperability will be broken in NNTP as=20
TLS_DHE_DSS_WITH_3DES_EDE_CBC_SHA is not mandatory. Furthermore, that=20
chipher suite may also become unsecure one day...
--=20
Julien =C3=89LIE
=C2=AB =E2=80=93 Nous voyageons plus vite que la lumi=C3=A8re !
=E2=80=93 Alors comment y voir clair dans tout =C3=A7a ? =C2=BB (Ast=C3=
=A9rix)