Re: What happens to CPAN clients when TLS 1.2 is required?

[email protected] (David Golden) Wed, 25 Apr 2018 12:35:41 -0400
Newsgroups perl.cpan.workers
Message-ID <CAOeq1c9Cf1zqf2-v_UiGJh3WTCNgZnVMNdsya+fwrYur=BivEg@mail.gmail.com>
--f4f5e805de286ff6af056aaedec8
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

It's been an issue at work for darwin.  Unless something uses
SecureTransport (which the Perl TLS stack doesn't), older versions of OS X
have openssl 0.9.x (though eventually no headers to build with).  Hopefully
Perl people building Net::SSLeay on OS X are using macports/homebrew to get
something newer.

On Wed, Apr 25, 2018 at 2:21 AM, Ask Bj=C3=B8rn Hansen <[email protected]> wrote=
:

>
>
> On Apr 24, 2018, at 18:11 , David Golden <[email protected]> wrote:
>
> But when they do opt into TLS, it's 1.2 required, right?
>
>
> Sure, but =E2=80=A6 TLS 1.2 is almost ten years old. 1.1 is only barely o=
lder.
> What operating systems don=E2=80=99t support TLS 1.2, but are otherwise f=
unctional
> / reasonable enough that you=E2=80=99d be installing anything new?  (And =
if you are
> running something that old, downloading over TLS shouldn=E2=80=99t be you=
r top
> priority problem).
>
>
> Ask
>



--=20
David Golden <[email protected]> Twitter/IRC/GitHub: @xdg

--f4f5e805de286ff6af056aaedec8
Content-Type: text/html; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable

<div dir=3D"ltr">It&#39;s been an issue at work for darwin.=C2=A0 Unless so=
mething uses SecureTransport (which the Perl TLS stack doesn&#39;t), older =
versions of OS X have openssl 0.9.x (though eventually no headers to build =
with).=C2=A0 Hopefully Perl people building Net::SSLeay on OS X are using m=
acports/homebrew to get something newer.<br></div><div class=3D"gmail_extra=
"><br><div class=3D"gmail_quote">On Wed, Apr 25, 2018 at 2:21 AM, Ask Bj=C3=
=B8rn Hansen <span dir=3D"ltr">&lt;<a href=3D"mailto:[email protected]" target=
=3D"_blank">[email protected]</a>&gt;</span> wrote:<br><blockquote class=3D"gmai=
l_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left=
:1ex"><div style=3D"word-wrap:break-word;line-break:after-white-space"><spa=
n class=3D""><br><div><br><blockquote type=3D"cite"><div>On Apr 24, 2018, a=
t 18:11 , David Golden &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">=
[email protected]</a>&gt; wrote:</div><br class=3D"m_5117414198100274916Apple-inte=
rchange-newline"><div><span style=3D"font-family:SourceSansPro-Regular;font=
-size:14px;font-style:normal;font-variant-caps:normal;font-weight:normal;le=
tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh=
ite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:i=
nline!important">But when they do opt into TLS, it&#39;s 1.2 required, righ=
t?</span></div></blockquote></div><br></span><div>Sure, but =E2=80=A6 TLS 1=
.2 is almost ten years old. 1.1 is only barely older.=C2=A0 What operating =
systems don=E2=80=99t support TLS 1.2, but are otherwise functional / reaso=
nable enough that you=E2=80=99d be installing anything new? =C2=A0(And if y=
ou are running something that old, downloading over TLS shouldn=E2=80=99t b=
e your top priority problem).</div><span class=3D"HOEnZb"><font color=3D"#8=
88888"><div><br></div><div><br></div><div>Ask</div></font></span></div></bl=
ockquote></div><br><br clear=3D"all"><br>-- <br><div class=3D"gmail_signatu=
re" data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div><div dir=3D"lt=
r"><div>David Golden &lt;<a href=3D"mailto:[email protected]" target=3D"_blank">xd=
[email protected]</a>&gt; Twitter/IRC/GitHub: @xdg</div></div></div></div></div>
</div>

--f4f5e805de286ff6af056aaedec8--