[#70843] Re: [ruby-cvs:58952] hsbt:r51801 (trunk): * lib/rubygems: Update to RubyGems HEAD(fe61e4c112). — Eric Wong <normalperson@...>
hsbt@ruby-lang.org wrote:
3 messages
2015/09/17
[ruby-core:70728] [Ruby trunk - Feature #11524] [Open] Use TLS 1.2 to default version of OpenSSL
From:
shibata.hiroshi@...
Date:
2015-09-12 08:35:56 UTC
List:
ruby-core #70728
Issue #11524 has been reported by Hiroshi SHIBATA. ---------------------------------------- Feature #11524: Use TLS 1.2 to default version of OpenSSL https://bugs.ruby-lang.org/issues/11524 * Author: Hiroshi SHIBATA * Status: Open * Priority: Normal * Assignee: Hiroshi SHIBATA ---------------------------------------- OpenSSL on trunk still use SSL version 3 with default option. but SSLv3 have some vulnerability. I propose to use TLS 1.2 with default on OpenSSL library. see original proposal: https://github.com/ruby/ruby/pull/873 In other side, HTTP/2 must be required TLS 1.2 protocol. We should change it before http client author put ```ctx.ssl_version = :TLSv1_2``` every their code. ref. https://http2.github.io/http2-spec/#TLSUsage -- https://bugs.ruby-lang.org/