Re: [pkg-lighttpd] [SECURITY] [DSA 2368-1] lighttpd security update

2011-12-22 Thread Vincent Bernat
OoO Peu avant le début de l'après-midi du jeudi 22 décembre 2011, vers 13:38, Arno Töll disait : > I'm sorry you're right. I was indeed misleading as I just copied the > NEWS entry I wrote for Unstable where things are slightly different. I > admit I shouldn't have copied it for Stable and Unst

Re: [pkg-lighttpd] [SECURITY] [DSA 2368-1] lighttpd security update

2011-12-22 Thread Arno Töll
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 FYI, forwarding to Vincent: On 21.12.2011 11:39, Olaf van der Spek wrote: > On Wed, Dec 21, 2011 at 8:40 AM, Vincent Bernat wrote: >> More important, lighttp uses OpenSSL which is not compatible with TLS >> 1.2. Therefore, the above cipher list is

Re: [pkg-lighttpd] [SECURITY] [DSA 2368-1] lighttpd security update

2011-12-21 Thread Nico Golde
Hi, * Olaf van der Spek [2011-12-21 12:01]: > On Wed, Dec 21, 2011 at 8:40 AM, Vincent Bernat wrote: > > More important,  lighttp uses OpenSSL  which is not compatible  with TLS > > 1.2. Therefore, the above cipher list is the same as: > >  RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM > > > > (you can check

Re: [pkg-lighttpd] [SECURITY] [DSA 2368-1] lighttpd security update

2011-12-21 Thread Olaf van der Spek
On Wed, Dec 21, 2011 at 8:40 AM, Vincent Bernat wrote: > More important,  lighttp uses OpenSSL  which is not compatible  with TLS > 1.2. Therefore, the above cipher list is the same as: >  RC4:HIGH:!MD5:!aNULL:!EDH:!AESGCM > > (you can check the output of "openssl ciphers") Isn't aNULL disabled b