[Pkg-haskell-maintainers] Bug#768164: Bug#768164: haskell-tls: SSLv3 support
Moritz Muehlenhoff
jmm at inutil.org
Wed Nov 5 16:12:02 UTC 2014
On Wed, Nov 05, 2014 at 05:07:15PM +0100, Joachim Breitner wrote:
> Hi,
>
>
> Am Mittwoch, den 05.11.2014, 16:45 +0100 schrieb Moritz Muehlenhoff:
> > Package: haskell-tls
> > Severity: important
> > Tags: security
> >
> > Hi,
> > openssl disabled SSLv3 for jessie since 1.0.1j-1. Shall we do the same for haskell-tls?
>
> good question. Probably yes. Did openssl disable SSLv3 completely, or
> did it just removed it from the default list of accepted settings?
openssl disabled it entirely; it features a dedicated build flag for it
(no-ssl3).
Could you approach haskell-tls upstream for their recommendation to disable it?
Cheers,
Moritz
More information about the Pkg-haskell-maintainers
mailing list