4 ms·
> TLS v1.2 should be your main protocol. This version is superior because it offers important features that are unavailable in earlier protocol versions. If you
by devicenull 13y ago
> TLS v1.2 should be your main protocol. This version is superior because it offers important features that
are unavailable in earlier protocol versions. If your server platform (or any intermediary device) does
not support TLS v1.2, make plans to upgrade at an accelerated pace. If your service providers do not
support TLS v1.2, require that they upgrade.
Too bad CentOS is still stuck on TLS 1.0 and apparently will be for quite some time.
- McGlockenshire 13y agoGiven that Redhat is beginning to backport a larger number of newer platforms [1], I'd expect them to eventually include newer Apache & mod_ssl editions. Hopefully the CentOS folks will be able to pick this stuff up, or duplicate the functionality if RH isn't open-sourcing the bits that make it work. 1: http://developerblog.redhat.com/2013/09/17/shared-dev-rhscl/ http://developerblog.redhat.com/2013/09/17/shared-dev-rhscl/
- jlgaddis 13y agoI don't expect we'll expect elliptic curve support until RHEL 7.
- baudehlo 13y agoAlso you need to support SSL as well as TLS if you want to support IE6, and surprisingly - Stripe webhooks (see my blog for details).
- jlgaddis 13y agoIt's easy to dismiss IE6 -- and even IE6 on XP -- assuming that no one uses them anymore. I work at an ISP and am converting a number of Windows servers to Linux servers and adding SSL/TLS support as I go along. I've done some analysis on our own log files and was amazed at the astounding number of users still running IE6 and/or XP. :/
- regecks 13y ago> Too bad CentOS is still stuck on TLS 1.0 and apparently will be for quite some time Perhaps on a vanilla install, but it is not impossible or even difficult to build OpenSSL 1.0.1e+ for RHEL(s). Either build yourself or use Avixo[1]. Granted it's a pain in the ass/maybe not permitted in some environments, but doable. [1] http://rpm.axivo.com/ http://rpm.axivo.com/
- ivanr 13y agoThe bigger problem with CentOS (Red Hat) is that they do not support Elliptic Curves, which are necessary for Forward Secrecy. If you're using Apache, you can compile your own from source, using static linking against OpenSSL. That way, you can have the latest versions of both. I have a blog post that describes the process: http://blog.ivanristic.com/2013/08/compiling-apache-with-static-openssl.html http://blog.ivanristic.com/2013/08/compiling-apache-with-sta... While you're there, you might also want to patch Apache to support configurable DH parameters: http://blog.ivanristic.com/2013/08/increasing-dhe-strength-on-apache.html http://blog.ivanristic.com/2013/08/increasing-dhe-strength-o...