On Fri, Mar 28, 2014, Viktor Dukhovni wrote: > On Fri, Mar 28, 2014 at 06:57:34PM +0100, Dr. Stephen Henson wrote: > > > Well what goes in each security level is up for discussion and can be > > changed. > > So perhaps session tickets can be allowed at somewhat higher levels? >
Certainly. Nothing is set in stone at this stage. It's only part of the master branch and wont appear in a release for a while yet. > > As you note level 2 and higher general will have problems with "today's > > internet". Not just the RC4-SHA1 issue but also the fact that SHA1 for > > digital > > signatures only offers 80 bits of equivalent security. > > I am concerned that too many naive users will be tempted by the > "sexiness" of "my system security level is higher than yours". > > Raising the ceiling on crypto strength is well and good, and tuning > of the cipher-suite order to put adequately stronger stuff ahead > of weaker stuff is all fine, but raising the floor should be done > with great care! The interoperability consequences of floor-raising > can easily defeat the feel-good gains. > Yes I'm aware of some of the problems here. I do want OpenSSL to reject attempts to do silly things by default (e.g. ridiculously small key sizes). > Therefore, at the very least the security levels should be documented > with strong warnings about the usability of the resulting configuration > and the potential for *reduced* security overall (connections that > work are more secure, but more and more connections fail entirely). > Yes I agree. Big warnings in the documentation are in order. What are your thoughts on level 1? Do you think those requirements are reasonable? Currently (subject to change!) level 1 is the default level. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [email protected]
