On Mon, Jul 29, 2013 at 2:03 PM, Thomas Gries <m...@tgries.de> wrote:
> Am 29.07.2013 21:31, schrieb Ryan Lane: > > > >> That ssllabs link also shows that wikimedia has RC4 encryption enabled > >> on SSL connections, which offers no real security. This is apparently > >> related to the TLS 1.0 -vs- TLS 1.1/1.2 issue: > >> > >> > https://community.qualys.com/blogs/securitylabs/2013/03/19/rc4-in-tls-is-broken-now-what > >> --scott > >> > > Ryan: > > check with https://www.ssllabs.com/ssltest/ > > Example for https://en.wikipedia.org > https://www.ssllabs.com/ssltest/analyze.html?d=en.wikipedia.org > > I did. I also offered an explanation as to why we're using RC4. I'm going to add a proper block cipher to the config for TLS1.2 soon, but the rest need to use RC4. - Ryan _______________________________________________ Wikitech-l mailing list Wikitech-l@lists.wikimedia.org https://lists.wikimedia.org/mailman/listinfo/wikitech-l