On Sun, Aug 2, 2026 at 4:54 AM Oleg Kalnichevski <[email protected]> wrote:
>
> On Sat, 2026-08-01 at 21:14 -0400, Gary Gregory wrote:
> > Hi All,
> >
> > Is there anything that we can do in our code to facilitate RFC 10015
> > and
> > further secure users of HttpClient?
> >
> > https://www.rfc-editor.org/rfc/rfc10015.html
> >
> > Ty,
> > Gary
>
> Hi Gary
>
> We already have weak cipher exclusion logic, for instance, used to
> exclude cipher blacklisted by the HTTP/2 spec.
>
> https://github.com/apache/httpcomponents-core/blob/master/httpcore5/src/main/java/org/apache/hc/core5/http/ssl/TlsCiphers.java#L348
>
> One would have to review the existing implementation and make sure it
> conforms to RFC 10015.

I'll create a PR...

Gary

>
> Oleg
>
> ---------------------------------------------------------------------
> To unsubscribe, e-mail: [email protected]
> For additional commands, e-mail: [email protected]
>

---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to