Re: [RFC] Improved TLS Defaults
| From: | Daniel Lowrey | Date: | Tue, 28 Jan 2014 22:05:23 +0000 |
| Subject: | Re: [RFC] Improved TLS Defaults | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71706@lists.php.net to get a copy of this message | ||
Great! The default cipher list is really the main thing I want to flesh out
during the discussion process. You also won't hear me claim to be an
"expert" (whatever that entails).
I think having the community as a whole decide what's right for PHP is the
best course of action here. Any feedback on these points is appreciated
(especially feedback that comes with concrete references).
On Tue, Jan 28, 2014 at 5:00 PM, Robert Stoll <php@tutteli.ch> wrote:
> Hey Daniel
>
> > -----Original Message-----
> > From: Daniel Lowrey [mailto:rdlowrey@gmail.com]
> > Sent: Tuesday, January 28, 2014 10:51 PM
> > To: internals@lists.php.net
> > Subject: [PHP-DEV] [RFC] Improved TLS Defaults
> >
> > Hello, internals!
> >
> > I've created a new RFC to discuss improving default TLS encryption
> settings:
> >
> > https://wiki.php.net/rfc/improved-tls-defaults
> >
> > This RFC complements the previously accepted TLS Peer Verification RFC.
> >
> > I've proposed these (relatively straight-forward) changes in RFC form
> > because there does exist the potential for minimal BC breakage. I see
> this
> > breakage as a good thing because it enhances security, however everyone
> may
> > not share this view.
> >
> > Thanks in advance for your participation.
>
> I am not a security expert but I read (somewhere, don't ask me where
> please) that further ciphers should be excluded.
> Maybe they are already covered in !LOW but just in case:
>
> !DES:!3DES:!EXP:!SRP:!PSK
>
> Cheers,
> Robert
>
>
>