Re: Bug#772487: SSL 3.0 and older ciphers selected in applications

2014-12-08 Thread Adam D. Barratt
On Mon, 2014-12-08 at 09:16 +0100, Daniel Pocock wrote:
[...]
 If it will help the release team, is there anybody from the security
 team who could review the changes in my debdiff?

Note that debian-security@lists.debian.org is not a contact address for
the security team.

(Also I don't see anything in the nack mail that says it was related to
being unable to review the debdiff.)

Regards,

Adam


-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: https://lists.debian.org/1418030432.5790.11.ca...@adam-barratt.org.uk



Re: Bug#772487: SSL 3.0 and older ciphers selected in applications

2014-12-08 Thread Daniel Pocock
On 08/12/14 10:20, Adam D. Barratt wrote:
 On Mon, 2014-12-08 at 09:16 +0100, Daniel Pocock wrote:
 [...]
 If it will help the release team, is there anybody from the security
 team who could review the changes in my debdiff?
 Note that debian-security@lists.debian.org is not a contact address for
 the security team.

 (Also I don't see anything in the nack mail that says it was related to
 being unable to review the debdiff.)


I wasn't suggesting that was the cause for the nack email although I
remember some discussion around the wheezy release that the size of
diffs is considered a factor in unblock requests.

I understand that sometimes the security team have made decisions about
what should go through to stable, e.g. for the browser version updates
and the security team are also getting involved if some vulnerability is
found in future so I value their opinion on this particular case.

The WebSocket transport (which includes TLS support) in packages like
reSIProcate, Kamailio and Asterisk needs to remain interoperable with
the browsers and the server side also needs to remain secure throughout
the life of jessie so there are a range of reasons I'm asking about this.



-- 
To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org
with a subject of unsubscribe. Trouble? Contact listmas...@lists.debian.org
Archive: https://lists.debian.org/54856fa5.8020...@pocock.pro