On Wed, Nov 05, 2014 at 05:07:15PM +0100, Joachim Breitner wrote:
> Hi,
>
>
> Am Mittwoch, den 05.11.2014, 16:45 +0100 schrieb Moritz Muehlenhoff:
> > Package: haskell-tls
> > Severity: important
> > Tags: security
> >
> > Hi,
> > openssl disabled SSLv3 for jessie since 1.0.1j-1. Shall we do the same for
> > haskell-tls?
>
> good question. Probably yes. Did openssl disable SSLv3 completely, or
> did it just removed it from the default list of accepted settings?
openssl disabled it entirely; it features a dedicated build flag for it
(no-ssl3).
Could you approach haskell-tls upstream for their recommendation to disable it?
Cheers,
Moritz
--
To UNSUBSCRIBE, email to [email protected]
with a subject of "unsubscribe". Trouble? Contact [email protected]