On Fri, Mar 28, 2014, Viktor Dukhovni wrote:

> On Fri, Mar 28, 2014 at 06:57:34PM +0100, Dr. Stephen Henson wrote:
> 
> > Well what goes in each security level is up for discussion and can be 
> > changed.
> 
> So perhaps session tickets can be allowed at somewhat higher levels?
> 

Certainly. Nothing is set in stone at this stage. It's only part of the master
branch and wont appear in a release for a while yet.

> > As you note level 2 and higher general will have problems with "today's
> > internet". Not just the RC4-SHA1 issue but also the fact that SHA1 for 
> > digital
> > signatures only offers 80 bits of equivalent security.
> 
> I am concerned that too many naive users will be tempted by the
> "sexiness" of "my system security level is higher than yours".
> 
> Raising the ceiling on crypto strength is well and good, and tuning
> of the cipher-suite order to put adequately stronger stuff ahead
> of weaker stuff is all fine, but raising the floor should be done
> with great care!  The interoperability consequences of floor-raising
> can easily defeat the feel-good gains.
> 

Yes I'm aware of some of the problems here. I do want OpenSSL to reject
attempts to do silly things by default (e.g. ridiculously small key sizes).

> Therefore, at the very least the security levels should be documented
> with strong warnings about the usability of the resulting configuration
> and the potential for *reduced* security overall (connections that
> work are more secure, but more and more connections fail entirely).
> 

Yes I agree. Big warnings in the documentation are in order.

What are your thoughts on level 1? Do you think those requirements are
reasonable? Currently (subject to change!) level 1 is the default level.

Steve.
--
Dr Stephen N. Henson. OpenSSL project core developer.
Commercial tech support now available see: http://www.openssl.org
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [email protected]

Reply via email to