On Tue, Sep 09, 2014 at 08:42:36AM -0400, Salz, Rich wrote: > > Moving RC4 to "LOW" is also premature. It is already at the bottom of the > > medium cipherlist, that should be enough. > > I am planning on doing it for master, not 1.0.2 That means it > won't be in an official release until... what, at least six months.
Master has "security levels", which still need some work, but are a less crude mechanism for such tweaks. Disabling RC4 at security level 2 or some such, is better than incompatibly reclassifying it as "LOW". We can discuss the details later. -- Viktor. ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List openssl-users@openssl.org Automated List Manager majord...@openssl.org