emacs-devel
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: Bug#766395: emacs/gnus: Uses s_client to for SSL.


From: Kurt Roeckx
Subject: Re: Bug#766395: emacs/gnus: Uses s_client to for SSL.
Date: Thu, 23 Oct 2014 21:11:57 +0200
User-agent: Mutt/1.5.23 (2014-03-12)

On Thu, Oct 23, 2014 at 08:59:56PM +0200, Florian Weimer wrote:
> * Perry E. Metzger:
> 
> > On Thu, 23 Oct 2014 20:43:32 +0200 Florian Weimer <address@hidden>
> >> Keep in mind that TLS 1.0 basically has the same problem as SSL 3.0,
> >> and support for protocols beyond TLS 1.0 is not actually widespread.
> >
> > Connections to most of the top sites are TLS 1.2 at this point.
> > Google is TLS 1.2. Facebook is TLS 1.2. Amazon is TLS 1.2. Apple is
> > TLS 1.2. I could go on and on.
> 
> Many IMAP servers running on free software still use OpenSSL 1.0.0 or
> even OpenSSL 0.9.8, which do not support TLS 1.2.  Interoperability
> with those should be our priority, not the proprietary services you
> listed.

TLS 1.1 and 1.2 support was added in OpenSSL 1.0.1.  It was
released in March 2012.  It's unfortunate that support wasn't
added much sooner.  But 1.0.X should be binary compatible with
1.0.0, and we recommend that you upgraded to either 1.0.1 or the
soon to be released 1.0.2.


Kurt




reply via email to

[Prev in Thread] Current Thread [Next in Thread]