Bug#787505: also affects browsers

2015-06-12 Thread Christophe Deleuze
Daniel Kahn Gillmor  wrote:
> 
> which web sites are you visiting that do FFDHE with weak groups?  It is

The authentication portal for my university intranet (!)

> a good thing that the browser does not treat these connections as secure
> connections.

Indeed.  But then there's no obvious way to access the site if really
needed.

Possible work-arounds:
 - downgrading to 3.19,
 - setting about:config security.ssl3.*.dhe* to false as suggested by Ben
   Caradoc-Davies above.

Both do work.

Maybe a word on the issue and possible work-arounds should appear in
README.Debian.  Also, it could be nice to display a warning about that
when upgrading from 3.19 since it's probably not obvious for
everybody to go look to libnss3 if the browser or mailer fails.

(assuming that complies with the policy about displaying such warnings,
which I don't know).

--
Christophe Deleuze


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#787505: also affects browsers

2015-06-09 Thread Christophe Deleuze
Just to note that this also affects browsers (experienced with conkeror
and iceweasel).

--
Christophe Deleuze


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org



Bug#773151: simply uninstall mh-e

2015-03-03 Thread Christophe Deleuze
emacs24.4 contains mh-e 8.6

uninstalling package mh-e (wich is currently version 8.5) makes you use
the 8.6 version bundled with emacs, which fixes the problem.

isn't this silly?


-- 
To UNSUBSCRIBE, email to debian-bugs-dist-requ...@lists.debian.org
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org