[389-devel] Re: Do we still need sslVersionMax/sslVersionMin?

2019-07-18 Thread Mark Reynolds
On 7/17/19 11:47 PM, William Brown wrote: On 17 Jul 2019, at 22:36, Mark Reynolds wrote: On 7/17/19 3:01 AM, Matus Honek wrote: I think we cannot remove it. Setting the MIN version is a workaround for *old clients* not even supporting current NSS' default min. Setting up MAX version is a w

[389-devel] Re: Do we still need sslVersionMax/sslVersionMin?

2019-07-17 Thread William Brown
> On 17 Jul 2019, at 22:36, Mark Reynolds wrote: > > > On 7/17/19 3:01 AM, Matus Honek wrote: >> I think we cannot remove it. Setting the MIN version is a workaround >> for *old clients* not even supporting current NSS' default min. >> Setting up MAX version is a workaround for *broken clients

[389-devel] Re: Do we still need sslVersionMax/sslVersionMin?

2019-07-17 Thread Mark Reynolds
On 7/17/19 3:01 AM, Matus Honek wrote: I think we cannot remove it. Setting the MIN version is a workaround for *old clients* not even supporting current NSS' default min. Setting up MAX version is a workaround for *broken clients* thinking they can support something they announced but for some

[389-devel] Re: Do we still need sslVersionMax/sslVersionMin?

2019-07-17 Thread Matus Honek
I think we cannot remove it. Setting the MIN version is a workaround for *old clients* not even supporting current NSS' default min. Setting up MAX version is a workaround for *broken clients* thinking they can support something they announced but for some reason fail to work with such a version. I