On Fri, 24 Oct 2014, Kamil Dudka wrote:
Is the plan to disable SSL 3.0 by default still valid?
Are we going to make the change before the upcoming release?
Yes I think we should, if possible.
Should I unimplement the fallback to SSL 3.0 in the NSS backend now, or wait
till Ray's patch appears upstream?
I'm digging up Ray's patch just now and I've pushed it!
--
/ daniel.haxx.se
-------------------------------------------------------------------
List admin: http://cool.haxx.se/list/listinfo/curl-library
Etiquette: http://curl.haxx.se/mail/etiquette.html