Re: Still missing: TLS_ECDH_anon_WITH_AES_xxx_GCM_SHAxxx
Peter Gutmann <[email protected]>
| Newsgroups | gmane.ietf.tls,gmane.ietf.secsh |
|---|---|
| Message-ID | <9A043F3CF02CD34C8E74AC1594475C737238B6C3@uxcn10-6.UoA.auckland.ac.nz> |
Alyssa Rowan <[email protected]> writes: >Can we perhaps make that a SHOULD NOT (or even a MUST NOT), if it somehow >isn't already? It's way too common in the wild, and it really is next to >useless practice from the same kind of wilful carelessness that brought the >world so many default/engineering/field service passwords/backdoors. I doubt it'll make any difference, those who would read and follow the RFC on this point won't be using insecure certs/keys anyway, and those who are using them will ignore (or not even read to that point) the RFC. I've heard this sort of thing referred to in the past as "workgroup posturing", and that's unfortunately what it'll be... Peter.