On Mon, Jul 29, 2013 at 2:03 PM, Thomas Gries <m...@tgries.de> wrote:

> Am 29.07.2013 21:31, schrieb Ryan Lane:
> >
> >> That ssllabs link also shows that wikimedia has RC4 encryption enabled
> >> on SSL connections, which offers no real security.  This is apparently
> >> related to the TLS 1.0 -vs- TLS 1.1/1.2 issue:
> >>
> >>
> https://community.qualys.com/blogs/securitylabs/2013/03/19/rc4-in-tls-is-broken-now-what
> >>  --scott
> >>
>
> Ryan:
>
> check with https://www.ssllabs.com/ssltest/
>
> Example for https://en.wikipedia.org
> https://www.ssllabs.com/ssltest/analyze.html?d=en.wikipedia.org
>
>
I did. I also offered an explanation as to why we're using RC4. I'm going
to add a proper block cipher to the config for TLS1.2 soon, but the rest
need to use RC4.

- Ryan
_______________________________________________
Wikitech-l mailing list
Wikitech-l@lists.wikimedia.org
https://lists.wikimedia.org/mailman/listinfo/wikitech-l

Reply via email to