Re: TLS cipersuites for Rserpool
Peter Lei <[email protected]>
| Newsgroups | gmane.ietf.rserpool |
|---|---|
| Message-ID | <[email protected]> |
Maureen, I agree with mandating the AES-128-CBC/SHA cipher, but what is the rationale for the SHOULD for the 3DES cipher? What "backward compatibility" is desired/required here? thanks, --peter [email protected] wrote: > I recommend Rserpool security text as follows (for ENRP and ASAP security > sections): > > The TLS_RSA_WITH_AES_128_CBC_SHA ciphersuite MUST be supported at a minimum > by implementers of TLS for Rserpool. For purposes of backwards > compatibility, ENRP SHOULD support TLS_RSA_WITH_3DES_EDE_CBC_SHA. > Implementers MAY also support any other ciphersuite. > > I'll get Eric Rescorla's advice about this TLS cipher suite being the right one > to make mandatory to support and also his take on backward compatibility. We > might not need this in ENRP assuming that everyone will write new code > for Rserpool infrastructure.