>I think this level of checking was first introduced with OpenSSL
>1.1.1f and all applications will refuse to work if compiled with this
>or newer version (for example curl). If you don't mind sending your
>login information on an now unsecure channel, you can restore the
>previous behaviour. You need to edit /etc/ssl/openssl.cnf and set
>"CipherString = DEFAULT@SECLEVEL=2" to one instead. But then again,
>it's definitely NOT recommended for your security.

Thank you for the detailed info

-- 
Francesco Potortì (ricercatore)        Voice:  +39.050.621.3058
ISTI - Area della ricerca CNR          Mobile: +39.348.8283.107
via G. Moruzzi 1, I-56124 Pisa         Skype:  wnlabisti
(gate 20, 1st floor, room C71)         Web:    http://fly.isti.cnr.it

Reply via email to