curl-library
weak cipher suites with OpenSSL, SecureTransport and... ?
From: Daniel Stenberg <daniel_at_haxx.se>
Date: Thu, 9 Jan 2014 23:34:19 +0100 (CET)
Date: Thu, 9 Jan 2014 23:34:19 +0100 (CET)
Howdy,
Here are two fresh (and annoying) issues we need to fix:
#1323 - remove export cipher suites from OpenSSL preference list
https://sourceforge.net/p/curl/bugs/1323/
#1324 - curl built with SecureTransport includes support for NULL ciphersuites
in ClientHello
https://sourceforge.net/p/curl/bugs/1324/
Left to do is then to build curl with other TLS backends and try it against
https://www.howsmyssl.com/a/check to see if there are more flaws in this
style.
-- / daniel.haxx.se ------------------------------------------------------------------- List admin: http://cool.haxx.se/list/listinfo/curl-library Etiquette: http://curl.haxx.se/mail/etiquette.htmlReceived on 2014-01-09