[Bug 1797440] Re: lxd is too restrictive about ciphers when it comes to proxies

2018-10-15 Thread Stéphane Graber
The stable snap now contains this code. ** Changed in: lxd (Ubuntu) Status: Fix Committed => Fix Released -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1797440 Title: lxd is too restrictive

[Bug 1797440] Re: lxd is too restrictive about ciphers when it comes to proxies

2018-10-15 Thread Stéphane Graber
** Changed in: lxd (Ubuntu) Status: In Progress => Fix Committed -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/1797440 Title: lxd is too restrictive about ciphers when it comes to proxies

[Bug 1797440] Re: lxd is too restrictive about ciphers when it comes to proxies

2018-10-15 Thread Stéphane Graber
Well, so most proxies do not intercept TLS and instead let you send "CONNECT" through and connect to the target server, in which case there's no reason for us to compromise on ciphers and allow for a potential downgrade and breaking of PFS. Since we can't really detect a company proxy which does