On Tue, Sep 09, 2014 at 08:42:36AM -0400, Salz, Rich wrote:
> > Moving RC4 to "LOW" is also premature. It is already at the bottom of the
> > medium cipherlist, that should be enough.
>
> I am planning on doing it for master, not 1.0.2 That means it
> won't be in an official release until... what, at least six months.
Master has "security levels", which still need some work, but are
a less crude mechanism for such tweaks. Disabling RC4 at security
level 2 or some such, is better than incompatibly reclassifying it
as "LOW". We can discuss the details later.
--
Viktor.
______________________________________________________________________
OpenSSL Project http://www.openssl.org
User Support Mailing List [email protected]
Automated List Manager [email protected]