Re: TLS cipersuites for Rserpool

Peter Lei <[email protected]>
Newsgroups gmane.ietf.rserpool
Message-ID <[email protected]>
Maureen,

I agree with mandating the AES-128-CBC/SHA cipher, but what
is the rationale for the SHOULD for the 3DES cipher?  What
"backward compatibility" is desired/required here?

thanks,
--peter

[email protected] wrote:
> I recommend Rserpool security text as follows (for ENRP and ASAP security
> sections):
> 
> The TLS_RSA_WITH_AES_128_CBC_SHA ciphersuite MUST be supported at a minimum
> by implementers of TLS for Rserpool.   For purposes of backwards
> compatibility, ENRP SHOULD support TLS_RSA_WITH_3DES_EDE_CBC_SHA.
> Implementers MAY also support any other ciphersuite.
> 
> I'll get Eric Rescorla's advice about this TLS cipher suite being the right one
> to make mandatory to support and also his take on backward compatibility.  We
 > might not need this in ENRP assuming that everyone will write new code
 > for Rserpool infrastructure.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.