[ 
https://issues.apache.org/jira/browse/PROTON-2021?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Andrew Stitcher updated PROTON-2021:
------------------------------------
    Description: 
There are some aspects of using TLS with proton-c that are awkward and by 
default less secure than they could be.

A good example of this is that it is tricky to set up to verify peer names 
against the system default ca certificate list. Even though this is carefully 
set up under many (most?) modern OS distributions.

Another example is that for a client on the internet verifying peer names is 
the only safe way to use TLS, but this is not the default.

  was:
There are some aspects of using TLS with proton-c that are awkward and by 
default less secure than thye could be.

A good example of this is that it is tricky to set up to verify peer names 
against the system default ca certificate list. Even though this is carefully 
set up under many (most?) modern OS distributions.

Another example is that for a client on the internet verifying peer names is 
the only safe way to use TLS, but this is not the default.


> [c] Make SSL/TLS usage more secure by default
> ---------------------------------------------
>
>                 Key: PROTON-2021
>                 URL: https://issues.apache.org/jira/browse/PROTON-2021
>             Project: Qpid Proton
>          Issue Type: Improvement
>          Components: proton-c
>            Reporter: Andrew Stitcher
>            Assignee: Andrew Stitcher
>            Priority: Major
>
> There are some aspects of using TLS with proton-c that are awkward and by 
> default less secure than they could be.
> A good example of this is that it is tricky to set up to verify peer names 
> against the system default ca certificate list. Even though this is carefully 
> set up under many (most?) modern OS distributions.
> Another example is that for a client on the internet verifying peer names is 
> the only safe way to use TLS, but this is not the default.



--
This message was sent by Atlassian JIRA
(v7.6.3#76005)

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to