Lucky Green wrote: > > OpenSSL is a library. It should support whatever the standard supports and > whatever users and/or authors of the lib desire to be in the lib. That may > include broken or null-ciphers. But the user should have to take positive > action to get at the broken ciphers. I believe by default, OpenSSL should > ship with the weak ciphers disabled. And there should be a clear warning: > "Not secure, don't fool yourself, do not use, etc]". Its funny you should say that, because I was just working around to the same conclusion myself. I anticipate resistance from both users and some of the other developers, because it will break almost every out-of-the-box installation, and it will be argued that the "user experience" is far more important that this piffling security stuff. Sigh. Ah well, here goes. Cheers, Ben. -- http://www.apache-ssl.org/ben.html "My grandfather once told me that there are two kinds of people: those who work and those who take the credit. He told me to try to be in the first group; there was less competition there." - Indira Gandhi
- Re: so why is IETF stilling adding DES to p... Ben Laurie
- Re: so why is IETF stilling adding DES to p... David Honig
- Re: so why is IETF stilling adding DES to proto... Lucky Green
- Re: so why is IETF stilling adding DES to p... William H. Geiger III
- DES vs RC4 -- A correction (Re: so why is IETF ... Arnold G. Reinhold
- Re: so why is IETF stilling adding DES to protocols?... Ben Laurie
- Re: so why is IETF stilling adding DES to proto... Jeffrey I. Schiller
- Re: so why is IETF stilling adding DES to p... Anonymous
- Re: so why is IETF stilling adding DES to p... Lucky Green
- Re: so why is IETF stilling adding DES ... Ben Laurie
- Re: so why is IETF stilling adding DES ... Russell Nelson
- Re: so why is IETF stilling adding DES to proto... William H. Geiger III
- Re: so why is IETF stilling adding DES to p... Tom Weinstein
- Re: so why is IETF stilling adding DES ... James A. Donald
- Re: so why is IETF stilling adding ... Adam Shostack
- write code outside US (Re: so why is IE... Adam Back
- Re: write code outside US (Re: so w... Tom Weinstein
- Re: write code outside US (Re: so w... Sameer Parekh
- Re: so why is IETF stilling adding DES ... Eivind Eklund
- Re: so why is IETF stilling adding DES ... Bodo Moeller
