Return-Path: X-Original-To: archive-asf-public-internal@cust-asf2.ponee.io Delivered-To: archive-asf-public-internal@cust-asf2.ponee.io Received: from cust-asf.ponee.io (cust-asf.ponee.io [163.172.22.183]) by cust-asf2.ponee.io (Postfix) with ESMTP id 66776200C68 for ; Wed, 3 May 2017 14:25:45 +0200 (CEST) Received: by cust-asf.ponee.io (Postfix) id 6516B160BB5; Wed, 3 May 2017 12:25:45 +0000 (UTC) Delivered-To: archive-asf-public@cust-asf.ponee.io Received: from mail.apache.org (hermes.apache.org [140.211.11.3]) by cust-asf.ponee.io (Postfix) with SMTP id 83BD5160BAA for ; Wed, 3 May 2017 14:25:44 +0200 (CEST) Received: (qmail 96560 invoked by uid 500); 3 May 2017 12:25:43 -0000 Mailing-List: contact dev-help@httpd.apache.org; run by ezmlm Precedence: bulk Reply-To: dev@httpd.apache.org list-help: list-unsubscribe: List-Post: List-Id: Delivered-To: mailing list dev@httpd.apache.org Received: (qmail 96550 invoked by uid 99); 3 May 2017 12:25:43 -0000 Received: from pnap-us-west-generic-nat.apache.org (HELO spamd3-us-west.apache.org) (209.188.14.142) by apache.org (qpsmtpd/0.29) with ESMTP; Wed, 03 May 2017 12:25:43 +0000 Received: from localhost (localhost [127.0.0.1]) by spamd3-us-west.apache.org (ASF Mail Server at spamd3-us-west.apache.org) with ESMTP id 18F96191FAD for ; Wed, 3 May 2017 12:25:43 +0000 (UTC) X-Virus-Scanned: Debian amavisd-new at spamd3-us-west.apache.org X-Spam-Flag: NO X-Spam-Score: 1.999 X-Spam-Level: * X-Spam-Status: No, score=1.999 tagged_above=-999 required=6.31 tests=[HTML_MESSAGE=2, RP_MATCHES_RCVD=-0.001, SPF_PASS=-0.001, URIBL_BLOCKED=0.001] autolearn=disabled Received: from mx1-lw-us.apache.org ([10.40.0.8]) by localhost (spamd3-us-west.apache.org [10.40.0.10]) (amavisd-new, port 10024) with ESMTP id Ej4cU4vikswK for ; Wed, 3 May 2017 12:25:41 +0000 (UTC) Received: from weser.webweaving.org (weser.webweaving.org [148.251.234.232]) by mx1-lw-us.apache.org (ASF Mail Server at mx1-lw-us.apache.org) with ESMTPS id 8815B5FE00 for ; Wed, 3 May 2017 12:25:40 +0000 (UTC) Received: from [10.11.0.158] (5ED29A06.cm-7-3c.dynamic.ziggo.nl [94.210.154.6]) (authenticated bits=0) by weser.webweaving.org (8.15.2/8.15.2) with ESMTPSA id v43CP7YT040163 (version=TLSv1.2 cipher=ECDHE-RSA-AES256-GCM-SHA384 bits=256 verify=NO) for ; Wed, 3 May 2017 14:25:38 +0200 (CEST) (envelope-from dirkx@webweaving.org) X-Authentication-Warning: weser.webweaving.org: Host 5ED29A06.cm-7-3c.dynamic.ziggo.nl [94.210.154.6] claimed to be [10.11.0.158] From: Dirk-Willem van Gulik Content-Type: multipart/signed; boundary="Apple-Mail=_88F0D75F-E9F2-4A18-A090-EADA9C5343B6"; protocol="application/pgp-signature"; micalg=pgp-sha256 Mime-Version: 1.0 (Mac OS X Mail 10.3 \(3273\)) Subject: Re: SSL Policy Definitions Date: Wed, 3 May 2017 14:25:01 +0200 References: <95C9DA3A-CF68-413F-B620-4EE35B957A60@greenbytes.de> To: dev@httpd.apache.org In-Reply-To: Message-Id: X-Mailer: Apple Mail (2.3273) X-Greylist: Sender succeeded SMTP AUTH, not delayed by milter-greylist-4.6.1 (weser.webweaving.org [148.251.234.232]); Wed, 03 May 2017 14:25:38 +0200 (CEST) archived-at: Wed, 03 May 2017 12:25:45 -0000 --Apple-Mail=_88F0D75F-E9F2-4A18-A090-EADA9C5343B6 Content-Type: multipart/alternative; boundary="Apple-Mail=_FE18D173-F299-4C15-9E95-3C7AC7DD61B0" --Apple-Mail=_FE18D173-F299-4C15-9E95-3C7AC7DD61B0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset=utf-8 > On 3 May 2017, at 14:09, Graham Leggett wrote: >=20 > On 03 May 2017, at 2:01 PM, Stefan Eissing = wrote: >=20 >> We seem to all agree that a definition in code alone will not be good = enough. People need to be able to see what is actually in effect. >=20 > I think we=E2=80=99re overthinking this. >=20 > We only need to document the settings that SSLSecurityLevel has = clearly in our docs, and make sure that "httpd -L=E2=80=9D prints out = the exact details so no user need ever get confused. >=20 >> If we let users define their own classes, it could look like this: >=20 > Immediately we=E2=80=99ve jumped into functionality that is beyond = Mr/Mrs Normal. Agreed. If our default is simply =E2=80=98industry best practice=E2=80=99 = (i.e. what we say it is*) =E2=80=94 then Normal will be the new black. And everyone else is still in the same boat - i.e. having to specify it = just like they do today. All that requires it to make the defaults sane. Dw. *: exceed NIST and https://www.keylength.com/ = for 5+ years, PFS, A or better at SSLLabs. = https://github.com/ssllabs/research/wiki/SSL-and-TLS-Deployment-Best-Pract= ices = --Apple-Mail=_FE18D173-F299-4C15-9E95-3C7AC7DD61B0 Content-Transfer-Encoding: quoted-printable Content-Type: text/html; charset=utf-8
On 3 May 2017, at 14:09, Graham Leggett <minfrin@sharp.fm> = wrote:

On 03 May 2017, at 2:01 PM, Stefan Eissing <stefan.eissing@greenbytes.de> wrote:

We seem to all agree = that a definition in code alone will not be good enough. People need to = be able to see what is actually in effect.

I think we=E2=80=99re overthinking this.

We only need to document the settings that SSLSecurityLevel = has clearly in our docs, and make sure that "httpd -L=E2=80=9D prints = out the exact details so no user need ever get confused.
If we let users define = their own classes, it could look like this:
Immediately we=E2=80=99ve jumped into functionality that is = beyond Mr/Mrs Normal.

Agreed. If our default is simply =E2=80=98indus= try best practice=E2=80=99 (i.e. what we say it is*) =E2=80=94 then = Normal will be the new black.

And everyone else is still in the same = boat - i.e. having to specify it just like they do today.

All that requires it to = make the defaults sane.

Dw.


= --Apple-Mail=_FE18D173-F299-4C15-9E95-3C7AC7DD61B0-- --Apple-Mail=_88F0D75F-E9F2-4A18-A090-EADA9C5343B6 Content-Transfer-Encoding: 7bit Content-Disposition: attachment; filename=signature.asc Content-Type: application/pgp-signature; name=signature.asc Content-Description: Message signed with OpenPGP -----BEGIN PGP SIGNATURE----- Version: GnuPG/MacGPG2 v2.0.30 iQCVAwUBWQnMITGmPZbsFAuBAQiCXwP9FfKGc8nZrer9dhAdTs+qjD9RydcCp9XC uXj+Rb/fm0cjAioL3w9LEMUOk1yHMU93x4hlTShi/3mqHVZijzjhKbjxqdmffu81 7Cw8Zu9Rl7AFdV69hhPJaBun5pqXYmfn/tVR4Ww4L+OXcoJGPsrsiyufoDRq6h0l RSic4IKczx8= =4zRW -----END PGP SIGNATURE----- --Apple-Mail=_88F0D75F-E9F2-4A18-A090-EADA9C5343B6--