[TLS] Prohibiting SSL 3.0

Yuhong Bao <yuhongbao_386@hotmail.com> Tue, 28 October 2014 02:05 UTC

Return-Path: <yuhongbao_386@hotmail.com>
X-Original-To: tls@ietfa.amsl.com
Delivered-To: tls@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 717BB1A6EF4 for <tls@ietfa.amsl.com>; Mon, 27 Oct 2014 19:05:46 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: 0.239
X-Spam-Level:
X-Spam-Status: No, score=0.239 tagged_above=-999 required=5 tests=[BAYES_20=-0.001, FREEMAIL_ENVFROM_END_DIGIT=0.25, FREEMAIL_FROM=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_PASS=-0.001, T_RP_MATCHES_RCVD=-0.01] autolearn=no
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id zuIFuux7Rnpx for <tls@ietfa.amsl.com>; Mon, 27 Oct 2014 19:05:44 -0700 (PDT)
Received: from BLU004-OMC3S19.hotmail.com (blu004-omc3s19.hotmail.com [65.55.116.94]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-SHA384 (256/256 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id B958A1A1B60 for <tls@ietf.org>; Mon, 27 Oct 2014 19:05:42 -0700 (PDT)
Received: from BLU177-W49 ([65.55.116.72]) by BLU004-OMC3S19.hotmail.com over TLS secured channel with Microsoft SMTPSVC(7.5.7601.22751); Mon, 27 Oct 2014 19:05:41 -0700
X-TMN: [jTgeQXVlYsETf7KLpSGks7llFJCDKBrI]
X-Originating-Email: [yuhongbao_386@hotmail.com]
Message-ID: <BLU177-W4981235CC3AA2325B8CC01C39F0@phx.gbl>
From: Yuhong Bao <yuhongbao_386@hotmail.com>
To: "tls@ietf.org" <tls@ietf.org>
Date: Mon, 27 Oct 2014 19:05:41 -0700
Importance: Normal
Content-Type: text/plain; charset="iso-8859-1"
Content-Transfer-Encoding: quoted-printable
MIME-Version: 1.0
X-OriginalArrivalTime: 28 Oct 2014 02:05:42.0084 (UTC) FILETIME=[AD4E7040:01CFF253]
Archived-At: http://mailarchive.ietf.org/arch/msg/tls/k0D3FuQZLMMafPiSCi8tEfkZUkw
Subject: [TLS] Prohibiting SSL 3.0
X-BeenThere: tls@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: "This is the mailing list for the Transport Layer Security working group of the IETF." <tls.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/tls>, <mailto:tls-request@ietf.org?subject=unsubscribe>
List-Archive: <http://www.ietf.org/mail-archive/web/tls/>
List-Post: <mailto:tls@ietf.org>
List-Help: <mailto:tls-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/tls>, <mailto:tls-request@ietf.org?subject=subscribe>
X-List-Received-Date: Tue, 28 Oct 2014 02:05:48 -0000

I hope that a Internet-Draft prohibiting SSL 3.0 will be next. Maybe make an exception for things like browser download sites (it is easy to enable TLS 1.0 in IE6 but for these kind of sites it is probably not worth the effort).

Yuhong Bao