• TLS 1.0 and 1.1 are still enabled by default in apache2

    From Vincent Lefevre@21:1/5 to All on Thu Jul 17 03:30:01 2025
    The following bug

    https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=943415

    was submitted in 2019 to request that TLS 1.0 and 1.1 be disabled by
    default, as already done for OpenSSL. But there is still no reaction
    from the Apache maintainers.

    Note also that TLS 1.0 and 1.1 were deprecated in RFC 8996 4 years
    ago.

    Shouldn't they be disabled for trixie?

    --
    Vincent Lefèvre <vincent@vinc17.net> - Web: <https://www.vinc17.net/>
    100% accessible validated (X)HTML - Blog: <https://www.vinc17.net/blog/>
    Work: CR INRIA - computer arithmetic / Pascaline project (LIP, ENS-Lyon)

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)
  • From Marco d'Itri@21:1/5 to Vincent Lefevre on Thu Jul 17 05:10:01 2025
    On Jul 17, Vincent Lefevre <vincent@vinc17.net> wrote:

    Shouldn't they be disabled for trixie?
    Yes!

    --
    ciao,
    Marco

    -----BEGIN PGP SIGNATURE-----

    iHUEABYKAB0WIQQnKUXNg20437dCfobLPsM64d7XgQUCaHhoXQAKCRDLPsM64d7X gUS1AP9rFEmeVOErWQW4E2Nbedmh7oK08vjrF8n/6F0wNocG+QEA7vAiZePLCyEM 9pAOa692Ca55QrYQmZYTtRzfZXqBkwU=
    =qKv3
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)