[#70257] [Ruby trunk - Feature #11420] [Open] Introduce ID key table into MRI — ko1@...

Issue #11420 has been reported by Koichi Sasada.

11 messages 2015/08/06

[ruby-core:70503] [Ruby trunk - Bug #11376] Stop using SSLv3 methods

From: kurt@...
Date: 2015-08-21 08:25:36 UTC
List: ruby-core #70503
Issue #11376 has been updated by Kurt Roeckx.


Is there any ETA of when I can expect this to be resolved?  Do you need some help or more info?

I would like to see this fixed in Debian as soon as possible, because I would like to drop support for that and ruby is really my biggest blocker at this point.

----------------------------------------
Bug #11376: Stop using SSLv3 methods
https://bugs.ruby-lang.org/issues/11376#change-53902

* Author: Kurt Roeckx
* Status: Assigned
* Priority: Normal
* Assignee: 
* ruby -v: 
* Backport: 2.0.0: UNKNOWN, 2.1: UNKNOWN, 2.2: UNKNOWN
----------------------------------------
If openssl is compiled using the OPENSSL_NO_SSL3_METHOD you can't compile ruby anymore since it will still try to use the SSLv3_*_method()s.

Please stop using those method at least when they're not available.

It would also be nice that you actually stopped version specific methods like TLSv1_1_*_method() and that you only use the SSLv23_*_method()s or TLS_*_methods (only available in development branch).  If you want to restrict the version that can be instead please use things like SSL_OP_NO_SSLv3.



-- 
https://bugs.ruby-lang.org/

In This Thread

Prev Next