Re: [Operators] ECDSA certs score F

2014-08-06 Thread Kim Alvefur
On 2014-08-06 10:14, Dave Cridland wrote: > Without an RSA cert at all, can a remote server with only RSA negotiate TLS? Sure they can. But here the only non-ECDSA-ciphers offered are DHE ones, so for another server to support incoming connections from mqas.net they need to have DH parameters set

Re: [Operators] ECDSA certs score F

2014-08-06 Thread Thijs Alkemade
On 26 jul. 2014, at 05:18, shm...@riseup.net wrote: > > hi, > > i was testing an xmpp server and i believe its wrong to reduce the > score because of the cert which is reported < 1024 bits > > i think the testing backend only assumes an RSA cert, is that right ? > > the server i tested is usi

Re: [Operators] ECDSA certs score F

2014-08-06 Thread Dave Cridland
Without an RSA cert at all, can a remote server with only RSA negotiate TLS? On 5 August 2014 19:30, shm...@riseup.net wrote: > ? > > shm...@riseup.net wrote: > > > > hi, > > > > i was testing an xmpp server and i believe its wrong to reduce the > > score because of the cert which is reported <