From: Dr S N Henson <[EMAIL PROTECTED]>

drh> > I'm not sure if it's a good idea to activate these ciphersuites by
drh> > default (i.e., include them in 'ALL') before they are official;
drh> > especially at such a prominent position of the ciphersuite list.
drh> > 
drh> 
drh> Yes OK. There's several ways we could go:
drh> 
drh> 1. Have a #define such as "EXPERIMENTAL_AES_CIPHERSUITES which would go
drh> away when they become official.
drh> 
drh> 2. Remove them from DEFAULT (add -AES or !AES in there) so they only
drh> appear in custom cipher lists, like ADH currently.
drh> 
drh> 3. Remove them from ALL so they need to be added to any existing
drh> cipherlist (like eNULL currently).

I'd vote for 1.

-- 
Richard Levitte   \ Spannvägen 38, II \ [EMAIL PROTECTED]
Chairman@Stacken   \ S-168 35  BROMMA  \ T: +46-8-26 52 47
Redakteur@Stacken   \      SWEDEN       \ or +46-709-50 36 10
Procurator Odiosus Ex Infernis                -- [EMAIL PROTECTED]
Member of the OpenSSL development team: http://www.openssl.org/
Software Engineer, Celo Communications: http://www.celocom.com/

Unsolicited commercial email is subject to an archival fee of $400.
See <http://www.stacken.kth.se/~levitte/mail/> for more info.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to