[#70257] [Ruby trunk - Feature #11420] [Open] Introduce ID key table into MRI — ko1@...

Issue #11420 has been reported by Koichi Sasada.

11 messages 2015/08/06

[ruby-core:70621] [Ruby trunk - Bug #11376] Stop using SSLv3 methods

From: kili@...
Date: 2015-08-28 13:29:11 UTC
List: ruby-core #70621
Issue #11376 has been updated by Matthias Kilian.

File ruby-sslv3.diff added

Kurt Roeckx wrote:
> Is there any ETA of when I can expect this to be resolved?  Do you need some help or more info?

Since OpenBSD removed SSLv3 from libressl a few days ago, I've committed patches similar to the attached one to all ruby ports in the OpenBSD ports tree.

----------------------------------------
Bug #11376: Stop using SSLv3 methods
https://bugs.ruby-lang.org/issues/11376#change-54027

* Author: Kurt Roeckx
* Status: Assigned
* Priority: Normal
* Assignee: 
* ruby -v: 
* Backport: 2.0.0: UNKNOWN, 2.1: UNKNOWN, 2.2: UNKNOWN
----------------------------------------
If openssl is compiled using the OPENSSL_NO_SSL3_METHOD you can't compile ruby anymore since it will still try to use the SSLv3_*_method()s.

Please stop using those method at least when they're not available.

It would also be nice that you actually stopped version specific methods like TLSv1_1_*_method() and that you only use the SSLv23_*_method()s or TLS_*_methods (only available in development branch).  If you want to restrict the version that can be instead please use things like SSL_OP_NO_SSLv3.

---Files--------------------------------
ruby-sslv3.diff (1.13 KB)


-- 
https://bugs.ruby-lang.org/

In This Thread

Prev Next