Re: PHP 7.2.0 Released
| From: | lists@rhsoft.net | Date: | Fri, 01 Dec 2017 16:13:04 +0000 |
| Subject: | Re: PHP 7.2.0 Released | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-101211@lists.php.net to get a copy of this message | ||
Am 30.11.2017 um 17:41 schrieb Hannes Magnusson:
that PHP now instead of ECDHE-RSA-AES128-SHA uses ECDHE-RSA-AES128-GCM-SHA256 for TLS connections (and before 7.1 with openssl 1.1 it was not able to use ECHDE at all) or that PHP don't let the crypto library alone at all? at least it got better with 7.2- Improve TLS constants to sane valuesThis worries me a lot. Last time someone thought it was a good idea they introduced security vulnerability for all apps that used them.