On Fri, Mar 28, 2014 at 07:44:53PM +0100, Dr. Stephen Henson wrote:

> What are your thoughts on level 1? Do you think those requirements are
> reasonable? Currently (subject to change!) level 1 is the default level.

I am not personally aware of any interoperability obstacles to the
proposed level 1 80-bit floor.

    - I assume that the 80-bit floor allows RC4 and 3DES
    - I assume that the 80-bit floor allows SHA1
    - I assume that the 80-bit floor allows kRSA (non-PFS key exchange).
    - I assume that the 80-bit floor allows RSA at 1024 bits or better.
    - I assume that the 80-bit floor allows DHE at 1024 bits or better.
    - I assume that the 80-bit floor allows ECDHE at 160 bits or better.

If so, I think we've successfully transitioned from SSLv2, MD5 and
export ciphers to the above as a new realistic floor for most
applications.  Stronger settings will run into significant friction
for some time yet.

-- 
        Viktor.
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [email protected]
Automated List Manager                           [email protected]

Reply via email to