Re: What happens to CPAN clients when TLS 1.2 is required?
[email protected] (David Golden) Wed, 25 Apr 2018 01:11:03 +0000
| Newsgroups | perl.cpan.workers |
|---|---|
| Message-ID | <CAOeq1c9vVngz+D8+CHYF1fbD70wn40Fc5_YHTfKAvmF_2Q1-LA@mail.gmail.com> |
--f4f5e805de288be225056aa1f259 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable Thanks! But when they do opt into TLS, it's 1.2 required, right? On Tue, Apr 24, 2018, 8:45 PM Ask Bj=C3=B8rn Hansen <[email protected]> wrote: > www.cpan.org only forces TLS on modern browsers and the =E2=80=9Cuser vis= ible=E2=80=9D > pages. The index and distributions are TLS optional. > > -- > http://askask.com/ > > On Apr 24, 2018, at 11:52, David Golden <[email protected]> wrote: > > A colleague wrote this article about Python, which also uses Fastly: > https://pyfound.blogspot.com/2017/01/time-to-upgrade-your-python-tls-v12.= html > > I realize that a lot of clients may not even use TLS for CPAN downloads, > but for those that do, will they be in for a surprise when our cpan.org > and metacpan.org Fastly-backed CPAN mirrors stop serving insecure TLS > traffic? > > David > > -- > David Golden <[email protected]> Twitter/IRC/GitHub: @xdg > > --f4f5e805de288be225056aa1f259 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"auto">Thanks!<div dir=3D"auto"><br></div><div dir=3D"auto">But = when they do opt into TLS, it's 1.2 required, right?</div></div><br><di= v class=3D"gmail_quote"><div dir=3D"ltr">On Tue, Apr 24, 2018, 8:45 PM Ask = Bj=C3=B8rn Hansen <<a href=3D"mailto:[email protected]">[email protected]</a>> = wrote:<br></div><blockquote class=3D"gmail_quote" style=3D"margin:0 0 0 .8e= x;border-left:1px #ccc solid;padding-left:1ex"><div dir=3D"auto"><a href=3D= "http://www.cpan.org" target=3D"_blank" rel=3D"noreferrer">www.cpan.org</a>= only forces TLS on modern browsers and the =E2=80=9Cuser visible=E2=80=9D = pages. The index and distributions are TLS optional.<div><br><div id=3D"m_4= 29605438407786101AppleMailSignature">--=C2=A0<div><a href=3D"http://askask"= target=3D"_blank" rel=3D"noreferrer">http://askask</a><span class=3D"m_429= 605438407786101Apple-style-span">.com/</span></div></div><div><br>On Apr 24= , 2018, at 11:52, David Golden <<a href=3D"mailto:[email protected]" target=3D"= _blank" rel=3D"noreferrer">[email protected]</a>> wrote:<br><br></div><blockquo= te type=3D"cite"><div><div dir=3D"ltr"><div><div>A colleague wrote this art= icle about Python, which also uses Fastly: <a href=3D"https://pyfound.blogs= pot.com/2017/01/time-to-upgrade-your-python-tls-v12.html" target=3D"_blank"= rel=3D"noreferrer">https://pyfound.blogspot.com/2017/01/time-to-upgrade-yo= ur-python-tls-v12.html</a><br><br></div>I realize that a lot of clients may= not even use TLS for CPAN downloads, but for those that do, will they be i= n for a surprise when our <a href=3D"http://cpan.org" target=3D"_blank" rel= =3D"noreferrer">cpan.org</a> and <a href=3D"http://metacpan.org" target=3D"= _blank" rel=3D"noreferrer">metacpan.org</a> Fastly-backed CPAN mirrors stop= serving insecure TLS traffic?<br><br></div>David<br clear=3D"all"><div><di= v><div><div><br>-- <br><div class=3D"m_429605438407786101gmail_signature"><= div dir=3D"ltr"><div><div dir=3D"ltr"><div>David Golden <<a href=3D"mail= to:[email protected]" target=3D"_blank" rel=3D"noreferrer">[email protected]</a>> Twit= ter/IRC/GitHub: @xdg</div></div></div></div></div> </div></div></div></div></div> </div></blockquote></div></div></blockquote></div> --f4f5e805de288be225056aa1f259--