On Fri, May 02, 2014 at 04:12:33PM +0200, Kurt Roeckx wrote: > As I understand things, RC4 needs to be before 3DES because some > exchange servers have broken 3DES and don't support anything else.
No, that's a misreading of my posts. It suffices for RC4-SHA to be in the 64 ciphersuites in the client SSL HELLO. The servers in question will choose RC4-SHA if offered in the first 64 regardless of client preference. -- Viktor. ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@openssl.org