@Andrew G: did you manage to find some time to have a look at the POODLE implications for this release?

@Chris: you mentioned that you were seeing more live test failures than usual, and were going to investigate before voting. Have you had a chance to do that?

Based on this discussion in this thread on POODLE so far, I'm inclined to not cancel the release since it seems that exploiting the SSL downgrade would require additional vulnerabilities in jclouds (see [1]). Of course, we should document this and fix JCLOUDS-753 asap.

I'd like to close this vote tomorrow, if at all possible, so if either of you have any input at this point, that would be much appreciated.

Regards

ap

[1] http://markmail.org/message/25na5y3gamyacszp

Reply via email to