Bug#766957: Patch / update for znc to disable weak ciphers and SSLv2/SSLv3 protocols

2014-12-12 Thread Patrick Matthäi
Am 22.11.2014 um 17:47 schrieb Thijs Kinkhorst: > Hi, > >> sid/jessie will be fixed, soon. But I can not take the responsibility >> for backporting this patch to znc=0.206. > > I've not seen movement in sid yet on this issue. Is it still on your > radar? Anything I can help with? > > > Cheers,

Bug#766957: Patch / update for znc to disable weak ciphers and SSLv2/SSLv3 protocols

2014-11-22 Thread Thijs Kinkhorst
Hi, > sid/jessie will be fixed, soon. But I can not take the responsibility > for backporting this patch to znc=0.206. I've not seen movement in sid yet on this issue. Is it still on your radar? Anything I can help with? Cheers, Thijs -- To UNSUBSCRIBE, email to debian-bugs-dist-requ...@list

Bug#766957:

2014-11-04 Thread Thomas Ward (Dark-Net)
I can maybe take a stab at backporting to 0.206, as it's on my radar to do anyways. Note this though: I don't think we should outright disable SSLv3 in a stable release. There is a code commit in the pull requests queue waiting for inclusion that allows the specification of SSLv3 being disabled -

Bug#766957: Patch / update for znc to disable weak ciphers and SSLv2/SSLv3 protocols

2014-10-27 Thread Patrick Matthäi
Am 27.10.2014 um 09:31 schrieb Chris: > Package: znc > Version: 0.206-2 > Tags: security > > Hi, > > the ZNC IRC Bouncer (https://packages.debian.org/wheezy/znc) finally allows > to choose own ciphers and to disable SSLv2/SSLv3 protocols with this pull > requests: > > https://github.com/znc/zn

Bug#766957: Patch / update for znc to disable weak ciphers and SSLv2/SSLv3 protocols

2014-10-27 Thread Chris
Package: znc Version: 0.206-2 Tags: security Hi, the ZNC IRC Bouncer (https://packages.debian.org/wheezy/znc) finally allows to choose own ciphers and to disable SSLv2/SSLv3 protocols with this pull requests: https://github.com/znc/znc/pull/716 https://github.com/znc/znc/pull/717 Not sure if t