Re: PHP 7.2.0 Released
| From: | lists@rhsoft.net | Date: | Fri, 01 Dec 2017 16:52:15 +0000 |
| Subject: | Re: PHP 7.2.0 Released | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-101213@lists.php.net to get a copy of this message | ||
Am 01.12.2017 um 17:44 schrieb Niklas Keller:
lists@rhsoft.net <mailto:lists@rhsoft.net> <lists@rhsoft.net <mailto:lists@rhsoft.net>> schrieb am Fr., 1. Dez. 2017, 17:13:This worries me a lot. Last time someone thought it was a goodAm 30.11.2017 um 17:41 schrieb Hannes Magnusson:- Improve TLS constants to sane values
idea theyintroduced security vulnerability for all apps that used them.
that PHP now instead of ECDHE-RSA-AES128-SHA uses
ECDHE-RSA-AES128-GCM-SHA256 for TLS connections (and before 7.1 with
openssl 1.1 it was not able to use ECHDE at all) or that PHP don't let
the crypto library alone at all?
at least it got better with 7.2We only changed the defaults in 7.2, it was possible to use the same features before, except for the security level yes and since nobody ever sould override the defaults in application code for obvious reasons that's the problem, you shouldn't mangle with openssl defaults in general and let openssl do the handshake which will end in the server side perferred cipher and so in the most secure what PHP does is making encryption weaker as it hsould be above i talk about encrypted connection to mysqld and *no* if our only cipher on the server is ECDHE-RSA-AES128-GCM-SHA256 anything before PHP 7.2 won't connect at all