Re: Default https encryption wrapper
| From: | Adam Harvey | Date: | Thu, 19 Dec 2013 18:10:42 +0000 |
| Subject: | Re: Default https encryption wrapper | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70754@lists.php.net to get a copy of this message | ||
On 19 December 2013 06:39, Daniel Lowrey <rdlowrey@gmail.com> wrote:
> - SSL v2 is insecure and must not be used.
On the bright side, pretty much every browser no longer enables SSLv2
support, so that one's definitely safe to remove.
> To me, this change is a necessary one. Most users should not notice the
> change as TLSv1.0 is well established and supported by *virtually* all
> servers. Default to the more secure protocols here would dovetail nicely
> alongside the other security enhancements in 5.6.
I agree with all of the above, but wanted to track down some rough
numbers to figure out if we'd be causing significant pain by no longer
supporting SSLv3 by default in https:// URLs. I found a couple of
surveys:
1. http://blog.ivanristic.com/2011/09/ssl-survey-protocol-support.html
— from September 2011, surveying 298604 sites from Alexa's top
million. 5315 (1.8%) of those servers two years ago had no support for
TLS. That alone might have been enough to sway me, but then I found:
2. https://www.trustworthyinternet.org/ssl-pulse/
— from 2½ weeks ago,
indicating that 0.7% of the ~200k surveyed sites have no support for
TLS.
Every remotely supported Linux distro ships a version of OpenSSL that
supports at least TLS 1.0 (yes, even RHEL 4), so I don't see that as
an impediment.
> Thoughts?
I think we should do it. It will need to be documented clearly, and
hopefully we can put a good error message on top of this for users who
do run into problems with SSLv3-only servers, but I think the increase
in security is worthwhile, just as I did for the peer verification
work.
Great work, Daniel!
Thanks,
Adam