summaryrefslogtreecommitdiff
path: root/usr.bin/mg
diff options
context:
space:
mode:
authorJoel Sing <jsing@cvs.openbsd.org>2014-10-15 17:39:35 +0000
committerJoel Sing <jsing@cvs.openbsd.org>2014-10-15 17:39:35 +0000
commita99bb57b30617d9470fb7eb57d94361711e144ba (patch)
tree689b922f49f71a54fa70562020b69162d5611cf6 /usr.bin/mg
parent3a44d34da4930822d32cd89ef0f36b0ec6030a6e (diff)
Disable SSLv3 by default.
SSLv3 has been long known to have weaknesses and the POODLE attack has once again shown that it is effectively broken/insecure. As such, it is time to stop enabling a protocol was deprecated almost 15 years ago. If an application really wants to provide backwards compatibility, at the cost of security, for now SSL_CTX_clear_option(ctx, SSL_OP_NO_SSLv3) can be used to re-enable it on a per-application basis. General agreement from many. ok miod@
Diffstat (limited to 'usr.bin/mg')
0 files changed, 0 insertions, 0 deletions