Re: What happens to CPAN clients when TLS 1.2 is required?
[email protected] (Ask Bjørn Hansen) Tue, 24 Apr 2018 17:44:53 -0700
| Newsgroups | perl.cpan.workers |
|---|---|
| Message-ID | <[email protected]> |
--Apple-Mail-9AD4457D-9F38-469A-A89E-136CB6D70755 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable www.cpan.org only forces TLS on modern browsers and the =E2=80=9Cuser visibl= e=E2=80=9D pages. The index and distributions are TLS optional. --=20 http://askask.com/ > On Apr 24, 2018, at 11:52, David Golden <[email protected]> wrote: >=20 > A colleague wrote this article about Python, which also uses Fastly: https= ://pyfound.blogspot.com/2017/01/time-to-upgrade-your-python-tls-v12.html >=20 > I realize that a lot of clients may not even use TLS for CPAN downloads, b= ut for those that do, will they be in for a surprise when our cpan.org and m= etacpan.org Fastly-backed CPAN mirrors stop serving insecure TLS traffic? >=20 > David >=20 > --=20 > David Golden <[email protected]> Twitter/IRC/GitHub: @xdg --Apple-Mail-9AD4457D-9F38-469A-A89E-136CB6D70755 Content-Type: text/html; charset=utf-8 Content-Transfer-Encoding: quoted-printable <html><head><meta http-equiv=3D"content-type" content=3D"text/html; charset=3D= utf-8"></head><body dir=3D"auto"><a href=3D"http://www.cpan.org">www.cpan.or= g</a> only forces TLS on modern browsers and the =E2=80=9Cuser visible=E2=80= =9D pages. The index and distributions are TLS optional.<div><br><div id=3D"= AppleMailSignature">-- <div><a href=3D"http://askask">http://askask</a>= <span class=3D"Apple-style-span" style=3D"-webkit-tap-highlight-color: rgba(= 26, 26, 26, 0.296875); -webkit-composition-fill-color: rgba(175, 192, 227, 0= .230469); -webkit-composition-frame-color: rgba(77, 128, 180, 0.230469); ">.= com/</span></div></div><div><br>On Apr 24, 2018, at 11:52, David Golden <= <a href=3D"mailto:[email protected]">[email protected]</a>> wrote:<br><br></div><blockq= uote type=3D"cite"><div><div dir=3D"ltr"><div><div>A colleague wrote this ar= ticle about Python, which also uses Fastly: <a href=3D"https://pyfound.blogs= pot.com/2017/01/time-to-upgrade-your-python-tls-v12.html">https://pyfound.bl= ogspot.com/2017/01/time-to-upgrade-your-python-tls-v12.html</a><br><br></div= >I realize that a lot of clients may not even use TLS for CPAN downloads, bu= t for those that do, will they be in for a surprise when our <a href=3D"http= ://cpan.org">cpan.org</a> and <a href=3D"http://metacpan.org">metacpan.org</= a> Fastly-backed CPAN mirrors stop serving insecure TLS traffic?<br><br></di= v>David<br clear=3D"all"><div><div><div><div><br>-- <br><div class=3D"gmail_= signature"><div dir=3D"ltr"><div><div dir=3D"ltr"><div>David Golden <<a h= ref=3D"mailto:[email protected]" target=3D"_blank">[email protected]</a>> Twitter/IRC/G= itHub: @xdg</div></div></div></div></div> </div></div></div></div></div> </div></blockquote></div></body></html>= --Apple-Mail-9AD4457D-9F38-469A-A89E-136CB6D70755--