Annotate

AUTHORS @ 10721:3a1b1d3084fb 0.11

core.certmanager: Move EECDH ciphers before EDH in default cipherstring (fixes #1513) Backport of 94e341dee51c The original intent of having kEDH before kEECDH was that if a `dhparam` file was specified, this would be interpreted as a preference by the admin for old and well-tested Diffie-Hellman key agreement over newer elliptic curve ones. Otherwise the faster elliptic curve ciphersuites would be preferred. This didn't really work as intended since this affects the ClientHello on outgoing s2s connections, leading to some servers using poorly configured kEDH. With Debian shipping OpenSSL settings that enforce a higher security level, this caused interoperability problems with servers that use DH params smaller than 2048 bits. E.g. jabber.org at the time of this writing has 1024 bit DH params. MattJ says > Curves have won, and OpenSSL is less weird about them now
author Kim Alvefur <zash@zash.se>
date Sun, 25 Aug 2019 20:22:35 +0200
parent 5403:d7ecf6cd584e
Ignore whitespace changes - Everywhere: Within whitespace: At end of lines:
rev   line source
5403
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
1
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
2 The Prosody project is open to contributions (see HACKERS file), but is
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
3 maintained daily by:
94
57d2f1c98124 Add AUTHORS file
Matthew Wild <mwild1@gmail.com>
parents:
diff changeset
4
5403
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
5 - Matthew Wild (mail: matthew [at] prosody.im)
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
6 - Waqas Hussain (mail: waqas [at] prosody.im)
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
7 - Kim Alvefur (mail: zash [at] prosody.im)
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
8
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
9 You can reach us collectively by email: developers [at] prosody.im
d7ecf6cd584e AUTHORS: A small update...
Matthew Wild <mwild1@gmail.com>
parents: 792
diff changeset
10 or in realtime in the Prosody chatroom: prosody@conference.prosody.im