NTS client configuration support has landed

Richard Laager rlaager at wiktel.com
Sat Feb 2 03:24:06 UTC 2019


On 2/1/19 9:07 PM, Richard Laager wrote:
> On 2/1/19 7:56 PM, Gary E. Miller via devel wrote:
>> "tlsver [1.2 1.3]*
> If forcing a maximum version (e.g. for testing) is important, tlsver
> seems like a good approach.

Another approach would be to allow specifying a minimum and maximum
version. That's what Firefox recently did, citing "We need policies for
min/max TLS to be consistent Chrome and for the DOD STIG."

https://bugzilla.mozilla.org/show_bug.cgi?id=1522182

So maybe that's a better way.

I'm not familiar with DOD security policies, so I'm not able to find a
reference either way as to whether a _maximum_ TLS version setting is
required.

-- 
Richard

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 488 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ntpsec.org/pipermail/devel/attachments/20190201/edb96233/attachment.bin>


More information about the devel mailing list