Bug#982745: nginx-common: don't enable TLSv1 or TLSv1.1 in default configuration

2021-04-23 Thread Chris Hofstaedtler
* didi.deb...@cknow.org [210423 21:23]: > TLSv1.2 was defined in 2008, so I don't think it's to 'wild' to use that > as a default for security in the default configuration of nginx for Bullseye. You seem to neglect to mention that SSL/TLS is disabled in the default configuration. I agree that sug

Bug#982745: nginx-common: don't enable TLSv1 or TLSv1.1 in default configuration)

2021-04-20 Thread Diederik de Haas
Control: severity -1 grave Control: notforwarded -1 I did not get any response to my bug report which I tagged with 'security', so I'm upping the severity and believe the Debian documentation justifies it. https://www.debian.org/Bugs/Developer#severities says: "Most security bugs should also be s

Bug#982745: nginx-common: don't enable TLSv1 or TLSv1.1 in default configuration

2021-02-13 Thread didi . debian
Package: nginx-common Version: 1.18.0-6 Severity: normal Tags: security, patch Forwarded: https://salsa.debian.org/nginx-team/nginx/-/merge_requests/7 X-Debbugs-Cc: Debian Security Team TLSv1.2 was defined in 2008, so I don't think it's to 'wild' to use that as a default for security in the defau