[Pkg-haskell-maintainers] Bug#768164: Bug#768164: haskell-tls: SSLv3 support

Moritz Muehlenhoff jmm at inutil.org
Wed Nov 5 16:12:02 UTC 2014


On Wed, Nov 05, 2014 at 05:07:15PM +0100, Joachim Breitner wrote:
> Hi,
> 
> 
> Am Mittwoch, den 05.11.2014, 16:45 +0100 schrieb Moritz Muehlenhoff:
> > Package: haskell-tls
> > Severity: important
> > Tags: security
> > 
> > Hi,
> > openssl disabled SSLv3 for jessie since 1.0.1j-1. Shall we do the same for haskell-tls?
> 
> good question. Probably yes.  Did openssl disable SSLv3 completely, or
> did it just removed it from the default list of accepted settings?

openssl disabled it entirely; it features a dedicated build flag for it
(no-ssl3). 

Could you approach haskell-tls upstream for their recommendation to disable it?

Cheers,
        Moritz



More information about the Pkg-haskell-maintainers mailing list