Re: What happens to CPAN clients when TLS 1.2 is required?
[email protected] (Leo Lapworth) Tue, 24 Apr 2018 20:41:34 +0100
| Newsgroups | perl.cpan.workers |
|---|---|
| Message-ID | <CA+rMUP4mjJX6DbffQmZNyk+10OSGEE7pAeJMaJtqq4fPAAERvg@mail.gmail.com> |
--001a114166f0c1ba72056a9d58e6 Content-Type: text/plain; charset="UTF-8" Hi, https://metacpan.org/ and http[s]://[back|c]pan.metacpan.org/ dropped everything that isn't TLS 1.2 a little while ago.. - https://www.ssllabs.com/ssltest/analyze.html?d=metacpan.org&s=151.101.130.217 - https://www.ssllabs.com/ssltest/analyze.html?d=cpan.metacpan.org&s=151.101.130.217&latest Looks like https://www.cpan.org is as well - https://www.ssllabs.com/ssltest/analyze.html?d=www.cpan.org&s=151.101.194.49&latest So I think we've done this. Leo On 24 April 2018 at 19:52, David Golden <[email protected]> wrote: > A colleague wrote this article about Python, which also uses Fastly: > https://pyfound.blogspot.com/2017/01/time-to-upgrade-your- > python-tls-v12.html > > I realize that a lot of clients may not even use TLS for CPAN downloads, > but for those that do, will they be in for a surprise when our cpan.org > and metacpan.org Fastly-backed CPAN mirrors stop serving insecure TLS > traffic? > > David > > -- > David Golden <[email protected]> Twitter/IRC/GitHub: @xdg > --001a114166f0c1ba72056a9d58e6 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">Hi,<div><div><br></div><div><a href=3D"https://metacpan.or= g/">https://metacpan.org/</a> and http[s]://[back|c]<a href=3D"http://pan.m= etacpan.org/">pan.metacpan.org/</a> dropped everything that isn't TLS 1= .2 a little while ago..</div><div><br></div><div>- <a href=3D"https://www.s= sllabs.com/ssltest/analyze.html?d=3Dmetacpan.org&s=3D151.101.130.217">h= ttps://www.ssllabs.com/ssltest/analyze.html?d=3Dmetacpan.org&s=3D151.10= 1.130.217</a><br></div><div><br></div><div>- <a href=3D"https://www.ssllabs= .com/ssltest/analyze.html?d=3Dcpan.metacpan.org&s=3D151.101.130.217&= ;latest">https://www.ssllabs.com/ssltest/analyze.html?d=3Dcpan.metacpan.org= &s=3D151.101.130.217&latest</a><br></div><div><br></div><div>Looks = like <a href=3D"https://www.cpan.org">https://www.cpan.org</a> is as well</= div><div><br></div><div>-=C2=A0<a href=3D"https://www.ssllabs.com/ssltest/a= nalyze.html?d=3Dwww.cpan.org&s=3D151.101.194.49&latest">https://www= .ssllabs.com/ssltest/analyze.html?d=3Dwww.cpan.org&s=3D151.101.194.49&a= mp;latest</a></div><div><br></div><div>So I think we've done this.</div= ><div><br></div><div>Leo</div><div><br></div><div><br></div><div><br></div>= <div><br></div></div></div><div class=3D"gmail_extra"><br><div class=3D"gma= il_quote">On 24 April 2018 at 19:52, David Golden <span dir=3D"ltr"><<a = href=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>></span> wrot= e:<br><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8ex;border-l= eft:1px #ccc solid;padding-left:1ex"><div dir=3D"ltr"><div><div>A colleague= wrote this article about Python, which also uses Fastly: <a href=3D"https:= //pyfound.blogspot.com/2017/01/time-to-upgrade-your-python-tls-v12.html" ta= rget=3D"_blank">https://pyfound.blogspot.com/<wbr>2017/01/time-to-upgrade-y= our-<wbr>python-tls-v12.html</a><br><br></div>I realize that a lot of clien= ts may not even use TLS for CPAN downloads, but for those that do, will the= y be in for a surprise when our <a href=3D"http://cpan.org" target=3D"_blan= k">cpan.org</a> and <a href=3D"http://metacpan.org" target=3D"_blank">metac= pan.org</a> Fastly-backed CPAN mirrors stop serving insecure TLS traffic?<s= pan class=3D"HOEnZb"><font color=3D"#888888"><br><br></font></span></div><s= pan class=3D"HOEnZb"><font color=3D"#888888">David<br clear=3D"all"><div><d= iv><div><div><br>-- <br><div class=3D"m_3102221023296346334gmail_signature"= ><div dir=3D"ltr"><div><div dir=3D"ltr"><div>David Golden <<a href=3D"ma= ilto:[email protected]" target=3D"_blank">[email protected]</a>> Twitter/IRC/GitHub: @= xdg</div></div></div></div></div> </div></div></div></div></font></span></div> </blockquote></div><br></div> --001a114166f0c1ba72056a9d58e6--