Re: Default https encryption wrapper

From: Date: Thu, 19 Dec 2013 18:10:42 +0000
Subject: Re: Default https encryption wrapper
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-70754@lists.php.net to get a copy of this message
On 19 December 2013 06:39, Daniel Lowrey <rdlowrey@gmail.com> wrote: > - SSL v2 is insecure and must not be used. On the bright side, pretty much every browser no longer enables SSLv2 support, so that one's definitely safe to remove. > To me, this change is a necessary one. Most users should not notice the > change as TLSv1.0 is well established and supported by *virtually* all > servers. Default to the more secure protocols here would dovetail nicely > alongside the other security enhancements in 5.6. I agree with all of the above, but wanted to track down some rough numbers to figure out if we'd be causing significant pain by no longer supporting SSLv3 by default in https:// URLs. I found a couple of surveys: 1. http://blog.ivanristic.com/2011/09/ssl-survey-protocol-support.html — from September 2011, surveying 298604 sites from Alexa's top million. 5315 (1.8%) of those servers two years ago had no support for TLS. That alone might have been enough to sway me, but then I found: 2. https://www.trustworthyinternet.org/ssl-pulse/ — from 2½ weeks ago, indicating that 0.7% of the ~200k surveyed sites have no support for TLS. Every remotely supported Linux distro ships a version of OpenSSL that supports at least TLS 1.0 (yes, even RHEL 4), so I don't see that as an impediment. > Thoughts? I think we should do it. It will need to be documented clearly, and hopefully we can put a good error message on top of this for users who do run into problems with SSLv3-only servers, but I think the increase in security is worthwhile, just as I did for the peer verification work. Great work, Daniel! Thanks, Adam

« previous php.internals (#70754) next »