Re: SSL: better default ciphersuite - Mailing list pgsql-hackers

From Peter Eisentraut
Subject Re: SSL: better default ciphersuite
Date
Msg-id 1386815383.28197.2.camel@vanquo.pezone.net
Whole thread Raw
In response to Re: SSL: better default ciphersuite  (Marko Kreen <markokr@gmail.com>)
Responses Re: SSL: better default ciphersuite
Re: SSL: better default ciphersuite
List pgsql-hackers
On Fri, 2013-11-29 at 18:43 +0200, Marko Kreen wrote:
> Well, we should - the DEFAULT is clearly a client-side default
> for compatibility only.  No server should ever run with it.

Any other opinions on this out there?  All instances of other
SSL-enabled servers out there, except nginx, default to some variant of
DEFAULT:!LOW:... or HIGH:MEDIUM:....  The proposal here is essentially
to disable MEDIUM ciphers by default, which is explicitly advised
against in the Postfix and Dovecot documentation, for example.




pgsql-hackers by date:

Previous
From: Kyotaro HORIGUCHI
Date:
Subject: [BUG] Archive recovery failure on 9.3+.
Next
From: Tatsuo Ishii
Date:
Subject: pgbench with large scale factor