Re: What happens to CPAN clients when TLS 1.2 is required?

[email protected] (David Golden) Wed, 25 Apr 2018 01:11:03 +0000
Newsgroups perl.cpan.workers
Message-ID <CAOeq1c9vVngz+D8+CHYF1fbD70wn40Fc5_YHTfKAvmF_2Q1-LA@mail.gmail.com>
--f4f5e805de288be225056aa1f259
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

Thanks!

But when they do opt into TLS, it's 1.2 required, right?

On Tue, Apr 24, 2018, 8:45 PM Ask Bj=C3=B8rn Hansen <[email protected]> wrote:

> www.cpan.org only forces TLS on modern browsers and the =E2=80=9Cuser vis=
ible=E2=80=9D
> pages. The index and distributions are TLS optional.
>
> --
> http://askask.com/
>
> On Apr 24, 2018, at 11:52, David Golden <[email protected]> wrote:
>
> A colleague wrote this article about Python, which also uses Fastly:
> https://pyfound.blogspot.com/2017/01/time-to-upgrade-your-python-tls-v12.=
html
>
> I realize that a lot of clients may not even use TLS for CPAN downloads,
> but for those that do, will they be in for a surprise when our cpan.org
> and metacpan.org Fastly-backed CPAN mirrors stop serving insecure TLS
> traffic?
>
> David
>
> --
> David Golden <[email protected]> Twitter/IRC/GitHub: @xdg
>
>

--f4f5e805de288be225056aa1f259
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"auto">Thanks!<div dir=3D"auto"><br></div><div dir=3D"auto">But =
when they do opt into TLS, it&#39;s 1.2 required, right?</div></div><br><di=
v class=3D"gmail_quote"><div dir=3D"ltr">On Tue, Apr 24, 2018, 8:45 PM Ask =
Bj=C3=B8rn Hansen &lt;<a href=3D"mailto:[email protected]">[email protected]</a>&gt; =
wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8e=
x;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"auto"><a href=3D=
"http://www.cpan.org" target=3D"_blank" rel=3D"noreferrer">www.cpan.org</a>=
 only forces TLS on modern browsers and the =E2=80=9Cuser visible=E2=80=9D =
pages. The index and distributions are TLS optional.<div><br><div id=3D"m_4=
29605438407786101AppleMailSignature">--=C2=A0<div><a href=3D"http://askask"=
 target=3D"_blank" rel=3D"noreferrer">http://askask</a><span class=3D"m_429=
605438407786101Apple-style-span">.com/</span></div></div><div><br>On Apr 24=
, 2018, at 11:52, David Golden &lt;<a href=3D"mailto:[email protected]" target=3D"=
_blank" rel=3D"noreferrer">[email protected]</a>&gt; wrote:<br><br></div><blockquo=
te type=3D"cite"><div><div dir=3D"ltr"><div><div>A colleague wrote this art=
icle about Python, which also uses Fastly: <a href=3D"https://pyfound.blogs=
pot.com/2017/01/time-to-upgrade-your-python-tls-v12.html" target=3D"_blank"=
 rel=3D"noreferrer">https://pyfound.blogspot.com/2017/01/time-to-upgrade-yo=
ur-python-tls-v12.html</a><br><br></div>I realize that a lot of clients may=
 not even use TLS for CPAN downloads, but for those that do, will they be i=
n for a surprise when our <a href=3D"http://cpan.org" target=3D"_blank" rel=
=3D"noreferrer">cpan.org</a> and <a href=3D"http://metacpan.org" target=3D"=
_blank" rel=3D"noreferrer">metacpan.org</a> Fastly-backed CPAN mirrors stop=
 serving insecure TLS traffic?<br><br></div>David<br clear=3D"all"><div><di=
v><div><div><br>-- <br><div class=3D"m_429605438407786101gmail_signature"><=
div dir=3D"ltr"><div><div dir=3D"ltr"><div>David Golden &lt;<a href=3D"mail=
to:[email protected]" target=3D"_blank" rel=3D"noreferrer">[email protected]</a>&gt; Twit=
ter/IRC/GitHub: @xdg</div></div></div></div></div>
</div></div></div></div></div>
</div></blockquote></div></div></blockquote></div>

--f4f5e805de288be225056aa1f259--