
oss-sec mailing list archives
Re: feedback requested regarding deprecation of TLS 1.0/1.1
From: Duncan Grisby <duncan () grisby org>
Date: Wed, 07 Aug 2024 23:58:40 +0100
On Tue, 2024-08-06 at 05:02 -0400, Neil Horman wrote:
The current proposal under consideration is to explicitly disable TLS 1.0/1.1 at build time, in our 4.0 release (tentatively scheduled to release in the next 12-18 months), with an eye to completely remove the impacted code in a future major release. The default configuration could be overridden to re-enable TLS 1.0/1.1 at build time. Questions to the community are: 1) Are distributions/users comfortable with this approach in the time frame proposed?
I lead a quite unusual application (BMC Discovery), which is an IT discovery tool. Its purpose is to connect to everything it can in an IT environment and interrogate it, to find out what it is, and what it is doing. We would all agree that everything ought to be using modern TLS versions and encryption algorithms, but the reality is that we encounter many ancient systems that are using old protocols. It is important to us that we can connect to things even if they are now considered insecure, not least because that way we can report that they _are_ old and insecure. Obviously this is quite an unusual use of OpenSSL, but I think it is a good use case for retaining these old algorithms for as long as possible, even if they are disabled by default. If new OpenSSL versions drop support for older protocols, we will have to start using multiple versions, so we can use old OpenSSL versions for old discovery targets. Regards, Duncan Grisby. -- Duncan Grisby <duncan () grisby org>
Current thread:
- Re: feedback requested regarding deprecation of TLS 1.0/1.1, (continued)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Demi Marie Obenour (Aug 08)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Clemens Lang (Aug 08)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jacob Bachmeyer (Aug 09)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jens Timmerman (Aug 09)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Marco Moock (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Clemens Lang (Aug 06)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Demi Marie Obenour (Aug 06)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Alex Gaynor (Aug 06)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Neil Horman (Aug 07)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jan Engelhardt (Aug 06)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Duncan Grisby (Aug 08)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Mike O'Connor (Aug 14)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Pat Gunn (Aug 14)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jacob Bachmeyer (Aug 15)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Pat Gunn (Aug 14)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Hanno Böck (Aug 15)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Peter Gutmann (Aug 15)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jacob Bachmeyer (Aug 16)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jeffrey Walton (Aug 16)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jacob Bachmeyer (Aug 17)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Peter Gutmann (Aug 18)
- Re: feedback requested regarding deprecation of TLS 1.0/1.1 Jacob Bachmeyer (Aug 19)