[UPDATE] [VOTE] TLS Peer Verification
| From: | Daniel Lowrey | Date: | Wed, 18 Dec 2013 03:14:59 +0000 |
| Subject: | [UPDATE] [VOTE] TLS Peer Verification | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-70725@lists.php.net to get a copy of this message | ||
After some discussion in #php.pecl, the efforts of php.net's crack research
team (a.k.a. Joe Watkins) and a suggestion by Rasmus it was determined that
the original peer verification vote should be discarded in favor of
clarification.
The patch has been improved to obviate any need for manual CA management by
PHP itself. The new implementation takes advantage of OS and distro-managed
CA stores. As a result, users with a distro-packaged PHP version will see
most existing code work without any modifications while retaining control
of the implementation on a case-by-case basis.
This is an ideal solution as it preserves BC for many (likely most)
scenarios while simultaneously improving security. The changes are clearly
marked and summarized in the updated RFC. The original vote has been closed
and the new vote consists of only two options: Yes or No.
Thanks for your time and apologies to those tasked with duplicating their
original voting efforts.