[ruby-core:70728] [Ruby trunk - Feature #11524] [Open] Use TLS 1.2 to default version of OpenSSL

From: shibata.hiroshi@...
Date: 2015-09-12 08:35:56 UTC
List: ruby-core #70728
Issue #11524 has been reported by Hiroshi SHIBATA.

----------------------------------------
Feature #11524: Use TLS 1.2 to default version of OpenSSL
https://bugs.ruby-lang.org/issues/11524

* Author: Hiroshi SHIBATA
* Status: Open
* Priority: Normal
* Assignee: Hiroshi SHIBATA
----------------------------------------
OpenSSL on trunk still use SSL version 3 with default option. but SSLv3 have some vulnerability.

I propose to use TLS 1.2 with default on OpenSSL library.

see original proposal: https://github.com/ruby/ruby/pull/873

In other side, HTTP/2 must be required TLS 1.2 protocol. We should change it before http client 
author put ```ctx.ssl_version = :TLSv1_2``` every their code.

ref. https://http2.github.io/http2-spec/#TLSUsage



-- 
https://bugs.ruby-lang.org/

In This Thread

Prev Next