Re: Default https encryption wrapper
| From: | Daniel Lowrey | Date: | Thu, 19 Dec 2013 19:36:57 +0000 |
| Subject: | Re: Default https encryption wrapper | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-70760@lists.php.net to get a copy of this message | ||
On Thu, Dec 19, 2013 at 2:29 PM, Martin Jansen <martin@divbyzero.net> wrote:
> On Thu Dec 19, 2013 at 10:1042AM -0800, Adam Harvey wrote:
> > On 19 December 2013 06:39, Daniel Lowrey <rdlowrey@gmail.com> wrote:
> > > To me, this change is a necessary one. Most users should not notice the
> > > change as TLSv1.0 is well established and supported by *virtually* all
> > > servers. Default to the more secure protocols here would dovetail
> nicely
> > > alongside the other security enhancements in 5.6.
> >
> > I think we should do it. It will need to be documented clearly, and
> > hopefully we can put a good error message on top of this for users who
> > do run into problems with SSLv3-only servers, but I think the increase
>
> I agree with that. Part of the reasoning for my change to
> stream_context_set_option() that Daniel mentions was to make it
> possible to swap the default transport in the future while giving
> people a way to go back to the old SSLv23 behaviour if they really
> need it.
>
> - Martin
>
Yes, the in-context crypto method assignment is an extremely helpful
addition. I failed to fully appreciate its importance at first but for what
we're doing now (gently nudging people into the more secure protocols) it
makes it possible to significantly improve security without breaking
everything for the few stragglers still stuck with SSLv3. Kudos!