From owner-freebsd-ports@FreeBSD.ORG Thu May 21 00:05:25 2015 Return-Path: Delivered-To: ports@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:1900:2254:206a::19:1]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id 91D7F2D6; Thu, 21 May 2015 00:05:25 +0000 (UTC) Received: from slim.berklix.org (slim.berklix.org [94.185.90.68]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 23B4D1ADF; Thu, 21 May 2015 00:05:24 +0000 (UTC) Received: from mart.js.berklix.net (p5DCBF7DA.dip0.t-ipconnect.de [93.203.247.218]) (authenticated bits=128) by slim.berklix.org (8.14.5/8.14.5) with ESMTP id t4L06Hlg022812; Thu, 21 May 2015 02:06:18 +0200 (CEST) (envelope-from jhs@berklix.com) Received: from fire.js.berklix.net (fire.js.berklix.net [192.168.91.41]) by mart.js.berklix.net (8.14.3/8.14.3) with ESMTP id t4L0563H099025; Thu, 21 May 2015 02:05:06 +0200 (CEST) (envelope-from jhs@berklix.com) Received: from fire.js.berklix.net (localhost [127.0.0.1]) by fire.js.berklix.net (8.14.7/8.14.7) with ESMTP id t4L04eIq082662; Thu, 21 May 2015 02:04:59 +0200 (CEST) (envelope-from jhs@berklix.com) Message-Id: <201505210004.t4L04eIq082662@fire.js.berklix.net> To: d@delphij.net cc: "freebsd-security@freebsd.org" , ports@freebsd.org Subject: Re: LogJam exploit can force TLS down to 512 bytes, does it affect us? ? From: "Julian H. Stacey" Organization: http://berklix.com BSD Unix Linux Consultants, Munich Germany User-agent: EXMH on FreeBSD http://berklix.com/free/ X-URL: http://www.berklix.com In-reply-to: Your message "Wed, 20 May 2015 15:48:23 -0700." <555D0F37.8040605@delphij.net> Date: Thu, 21 May 2015 02:04:40 +0200 X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 21 May 2015 00:05:25 -0000 Xin Li wrote: > On 05/20/15 14:40, Julian H. Stacey wrote: > > Hi security@freebsd.org > > Please note that security@freebsd.org = secteam@freebsd.org. Since > this is posted to ports@ which is public, I'm assuming it's not > intended to be in private. Yes, correct, thanks Xin Li, (Sorry I forgot that lack of naming alias, different to other [freebsd-](hackers|current|ports)@freebsd.org lists). Thanks for the quick response :-) PS I checked some finance sites (random, OS unknown) from a FreeBSD client, all failed with 'EXPORT', just 2 responded OK with 'ECDH' Cheers, Julian -- Julian Stacey, BSD Linux Unix C Sys Eng Consultant Munich http://berklix.com Indent previous with "> ". Reply Below as a play script. Send plain text, Not quoted-printable, HTML, or base64.