Re: What happens to CPAN clients when TLS 1.2 is required?

[email protected] (Ask Bjørn Hansen) Tue, 24 Apr 2018 17:44:53 -0700
Newsgroups perl.cpan.workers
Message-ID <[email protected]>
--Apple-Mail-9AD4457D-9F38-469A-A89E-136CB6D70755
Content-Type: text/plain;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

www.cpan.org only forces TLS on modern browsers and the =E2=80=9Cuser visibl=
e=E2=80=9D pages. The index and distributions are TLS optional.

--=20
http://askask.com/

> On Apr 24, 2018, at 11:52, David Golden <[email protected]> wrote:
>=20
> A colleague wrote this article about Python, which also uses Fastly: https=
://pyfound.blogspot.com/2017/01/time-to-upgrade-your-python-tls-v12.html
>=20
> I realize that a lot of clients may not even use TLS for CPAN downloads, b=
ut for those that do, will they be in for a surprise when our cpan.org and m=
etacpan.org Fastly-backed CPAN mirrors stop serving insecure TLS traffic?
>=20
> David
>=20
> --=20
> David Golden <[email protected]> Twitter/IRC/GitHub: @xdg

--Apple-Mail-9AD4457D-9F38-469A-A89E-136CB6D70755
Content-Type: text/html;
	charset=utf-8
Content-Transfer-Encoding: quoted-printable

<html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D=
utf-8"></head><body dir=3D"auto"><a href=3D"http://www.cpan.org">www.cpan.or=
g</a> only forces TLS on modern browsers and the =E2=80=9Cuser visible=E2=80=
=9D pages. The index and distributions are TLS optional.<div><br><div id=3D"=
AppleMailSignature">--&nbsp;<div><a href=3D"http://askask">http://askask</a>=
<span class=3D"Apple-style-span" style=3D"-webkit-tap-highlight-color: rgba(=
26, 26, 26, 0.296875); -webkit-composition-fill-color: rgba(175, 192, 227, 0=
.230469); -webkit-composition-frame-color: rgba(77, 128, 180, 0.230469); ">.=
com/</span></div></div><div><br>On Apr 24, 2018, at 11:52, David Golden &lt;=
<a href=3D"mailto:[email protected]">[email protected]</a>&gt; wrote:<br><br></div><blockq=
uote type=3D"cite"><div><div dir=3D"ltr"><div><div>A colleague wrote this ar=
ticle about Python, which also uses Fastly: <a href=3D"https://pyfound.blogs=
pot.com/2017/01/time-to-upgrade-your-python-tls-v12.html">https://pyfound.bl=
ogspot.com/2017/01/time-to-upgrade-your-python-tls-v12.html</a><br><br></div=
>I realize that a lot of clients may not even use TLS for CPAN downloads, bu=
t for those that do, will they be in for a surprise when our <a href=3D"http=
://cpan.org">cpan.org</a> and <a href=3D"http://metacpan.org">metacpan.org</=
a> Fastly-backed CPAN mirrors stop serving insecure TLS traffic?<br><br></di=
v>David<br clear=3D"all"><div><div><div><div><br>-- <br><div class=3D"gmail_=
signature"><div dir=3D"ltr"><div><div dir=3D"ltr"><div>David Golden &lt;<a h=
ref=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>&gt; Twitter/IRC/G=
itHub: @xdg</div></div></div></div></div>
</div></div></div></div></div>
</div></blockquote></div></body></html>=

--Apple-Mail-9AD4457D-9F38-469A-A89E-136CB6D70755--