Web lists-archives.com

Re: OpenSSL disables TLS 1.0 and 1.1




Hi,

On Sat, 12 Aug 2017 14:16:25 +0200
Tollef Fog Heen <tfheen@xxxxxx> wrote:
> While I think we might want to ship buster with TLS 1.0 available, I
> think running with it disabled for parts of the development cycle is
> very useful, since it exposes bugs we have in packages that will use
> that version out of the box (isync being referred to elsethread).
> Finding and fixing those bugs is good.

Seconded in Tollef's opinion.

- This affects *only* testing and unstable, not stable release (yet).
  So, most of users are not influenced.
- We *can* revert it before Buster release if it would be too much
  wrong impact for us.
- This is done in early timing for Buster Cycle. We have enough time
  to see what is going on.

So, please file bugs with real world precise examples against affected
packages, and let's fix it first.


And, if it will not be reverted, maybe we can provide alternatives
such as openssh-client-ssh1 does.

> Package: openssh-client-ssh1
> (snip)
> Description: secure shell (SSH) client for legacy SSH1 protocol
> (snip)
>  This package provides the ssh1 and scp1 clients and the ssh-keygen1
>  utility, all built with support for the legacy SSH1 protocol. This
>  protocol is obsolete and should not normally be used, but in some cases
>  there may be no alternative way to connect to outdated servers.
>  .
>  In some countries it may be illegal to use any encryption at all
>  without a special permit.
> ...


-- 
Regards,

 Hideki Yamane     henrich @ debian.or.jp/org
 http://wiki.debian.org/HidekiYamane