Re: [VOTE] TLS Peer Verification
| From: | Joe Watkins | Date: | Tue, 17 Dec 2013 16:23:08 +0000 |
| Subject: | Re: [VOTE] TLS Peer Verification | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70717@lists.php.net to get a copy of this message | ||
On 12/17/2013 04:06 PM, Andrea Faulds wrote:
On 17/12/13 11:51, Joe Watkins wrote:If the CA file is present with verification enabled the vast majority of requests will execute as they do now, but securely. Most of the time, no evident change. If the CA file is not present change is introduced, lots of it. Changing the behaviour of the language from an internals perspective does not and should not mean changing the behaviour of code unless that is the intention behind the change, obviously. Cheers JoeUnfortunately that's not true. To fix the security issue REQUIRES affecting behaviour. Otherwise it's not fixed.I'm saying that we should, definitely, accept the patch; in thisspecific case we can fix the implementation or security issue without affecting behaviour,