Re: What happens to CPAN clients when TLS 1.2 is required?
[email protected] (David Golden) Wed, 25 Apr 2018 12:35:41 -0400
| Newsgroups | perl.cpan.workers |
|---|---|
| Message-ID | <CAOeq1c9Cf1zqf2-v_UiGJh3WTCNgZnVMNdsya+fwrYur=BivEg@mail.gmail.com> |
--f4f5e805de286ff6af056aaedec8 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable It's been an issue at work for darwin. Unless something uses SecureTransport (which the Perl TLS stack doesn't), older versions of OS X have openssl 0.9.x (though eventually no headers to build with). Hopefully Perl people building Net::SSLeay on OS X are using macports/homebrew to get something newer. On Wed, Apr 25, 2018 at 2:21 AM, Ask Bj=C3=B8rn Hansen <[email protected]> wrote= : > > > On Apr 24, 2018, at 18:11 , David Golden <[email protected]> wrote: > > But when they do opt into TLS, it's 1.2 required, right? > > > Sure, but =E2=80=A6 TLS 1.2 is almost ten years old. 1.1 is only barely o= lder. > What operating systems don=E2=80=99t support TLS 1.2, but are otherwise f= unctional > / reasonable enough that you=E2=80=99d be installing anything new? (And = if you are > running something that old, downloading over TLS shouldn=E2=80=99t be you= r top > priority problem). > > > Ask > --=20 David Golden <[email protected]> Twitter/IRC/GitHub: @xdg --f4f5e805de286ff6af056aaedec8 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr">It's been an issue at work for darwin.=C2=A0 Unless so= mething uses SecureTransport (which the Perl TLS stack doesn't), older = versions of OS X have openssl 0.9.x (though eventually no headers to build = with).=C2=A0 Hopefully Perl people building Net::SSLeay on OS X are using m= acports/homebrew to get something newer.<br></div><div class=3D"gmail_extra= "><br><div class=3D"gmail_quote">On Wed, Apr 25, 2018 at 2:21 AM, Ask Bj=C3= =B8rn Hansen <span dir=3D"ltr"><<a href=3D"mailto:[email protected]" target= =3D"_blank">[email protected]</a>></span> wrote:<br><blockquote class=3D"gmai= l_quote" style=3D"margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left= :1ex"><div style=3D"word-wrap:break-word;line-break:after-white-space"><spa= n class=3D""><br><div><br><blockquote type=3D"cite"><div>On Apr 24, 2018, a= t 18:11 , David Golden <<a href=3D"mailto:[email protected]" target=3D"_blank">= [email protected]</a>> wrote:</div><br class=3D"m_5117414198100274916Apple-inte= rchange-newline"><div><span style=3D"font-family:SourceSansPro-Regular;font= -size:14px;font-style:normal;font-variant-caps:normal;font-weight:normal;le= tter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;wh= ite-space:normal;word-spacing:0px;text-decoration:none;float:none;display:i= nline!important">But when they do opt into TLS, it's 1.2 required, righ= t?</span></div></blockquote></div><br></span><div>Sure, but =E2=80=A6 TLS 1= .2 is almost ten years old. 1.1 is only barely older.=C2=A0 What operating = systems don=E2=80=99t support TLS 1.2, but are otherwise functional / reaso= nable enough that you=E2=80=99d be installing anything new? =C2=A0(And if y= ou are running something that old, downloading over TLS shouldn=E2=80=99t b= e your top priority problem).</div><span class=3D"HOEnZb"><font color=3D"#8= 88888"><div><br></div><div><br></div><div>Ask</div></font></span></div></bl= ockquote></div><br><br clear=3D"all"><br>-- <br><div class=3D"gmail_signatu= re" data-smartmail=3D"gmail_signature"><div dir=3D"ltr"><div><div dir=3D"lt= r"><div>David Golden <<a href=3D"mailto:[email protected]" target=3D"_blank">xd= [email protected]</a>> Twitter/IRC/GitHub: @xdg</div></div></div></div></div> </div> --f4f5e805de286ff6af056aaedec8--