On Fri, Mar 28, 2014 at 07:44:53PM +0100, Dr. Stephen Henson wrote:
> What are your thoughts on level 1? Do you think those requirements are
> reasonable? Currently (subject to change!) level 1 is the default level.
I am not personally aware of any interoperability obstacles to the
proposed level 1 80-bit floor.
- I assume that the 80-bit floor allows RC4 and 3DES
- I assume that the 80-bit floor allows SHA1
- I assume that the 80-bit floor allows kRSA (non-PFS key exchange).
- I assume that the 80-bit floor allows RSA at 1024 bits or better.
- I assume that the 80-bit floor allows DHE at 1024 bits or better.
- I assume that the 80-bit floor allows ECDHE at 160 bits or better.
If so, I think we've successfully transitioned from SSLv2, MD5 and
export ciphers to the above as a new realistic floor for most
applications. Stronger settings will run into significant friction
for some time yet.
--
Viktor.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
Development Mailing List [email protected]
Automated List Manager [email protected]