Re: PHP 7.2.0 Released
| From: | Sara Golemon | Date: | Fri, 01 Dec 2017 21:49:25 +0000 |
| Subject: | Re: PHP 7.2.0 Released | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-101214@lists.php.net to get a copy of this message | ||
On Fri, Dec 1, 2017 at 11:52 AM, lists@rhsoft.net <lists@rhsoft.net> wrote:
> yes and since nobody ever sould override the defaults in application code
> for obvious reasons that's the problem, you shouldn't mangle with openssl
> defaults in general and let openssl do the handshake which will end in the
> server side perferred cipher and so in the most secure
>
> what PHP does is making encryption weaker as it hsould be
>
Um. Did you look at the diff in question?
The old default was tls 1.0 only, the new default is tls 1.0, 1.1, or 1.2.
The new default allows OpenSSL to negotiate for a preferred method
where it couldn't before.
The change literally does the opposite of what you're talking about.
-Sara