On Sun, Aug 2, 2026 at 4:54 AM Oleg Kalnichevski <[email protected]> wrote: > > On Sat, 2026-08-01 at 21:14 -0400, Gary Gregory wrote: > > Hi All, > > > > Is there anything that we can do in our code to facilitate RFC 10015 > > and > > further secure users of HttpClient? > > > > https://www.rfc-editor.org/rfc/rfc10015.html > > > > Ty, > > Gary > > Hi Gary > > We already have weak cipher exclusion logic, for instance, used to > exclude cipher blacklisted by the HTTP/2 spec. > > https://github.com/apache/httpcomponents-core/blob/master/httpcore5/src/main/java/org/apache/hc/core5/http/ssl/TlsCiphers.java#L348 > > One would have to review the existing implementation and make sure it > conforms to RFC 10015.
I'll create a PR... Gary > > Oleg > > --------------------------------------------------------------------- > To unsubscribe, e-mail: [email protected] > For additional commands, e-mail: [email protected] > --------------------------------------------------------------------- To unsubscribe, e-mail: [email protected] For additional commands, e-mail: [email protected]
