From owner-freebsd-security@FreeBSD.ORG Thu May 14 10:41:07 2015 Return-Path: Delivered-To: freebsd-security@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [8.8.178.115]) (using TLSv1.2 with cipher AECDH-AES256-SHA (256/256 bits)) (No client certificate requested) by hub.freebsd.org (Postfix) with ESMTPS id A093D81E for ; Thu, 14 May 2015 10:41:07 +0000 (UTC) Received: from thor.freshdata.pl (thor.freshdata.pl [148.251.122.55]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (Client did not present a certificate) by mx1.freebsd.org (Postfix) with ESMTPS id 634841100 for ; Thu, 14 May 2015 10:41:06 +0000 (UTC) Received: from dhcp46-187-149-223.eaw.com.pl ([46.187.149.223] helo=[192.168.2.100]) by thor.freshdata.pl with esmtpa (Exim 4.82_1-5b7a7c0-XX (FreeBSD)) (envelope-from ) id 1YsqEw-000CS3-JO for freebsd-security@freebsd.org; Thu, 14 May 2015 12:19:42 +0200 Message-ID: <555476CB.2010005@ivpro.net> Date: Thu, 14 May 2015 12:19:55 +0200 From: Adam Major User-Agent: Mozilla/5.0 (Windows NT 5.1; rv:31.0) Gecko/20100101 Thunderbird/31.6.0 MIME-Version: 1.0 To: freebsd-security@freebsd.org Subject: Re: Forums.FreeBSD.org - SSL Issue? References: <2857899F-802E-4086-AD41-DD76FACD44FB@modirum.com> <05636D22-BBC3-4A15-AC44-0F39FB265CDF@patpro.net> <20150514193706.V69409@sola.nimnet.asn.au> In-Reply-To: <20150514193706.V69409@sola.nimnet.asn.au> Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 7bit X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.20 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Thu, 14 May 2015 10:41:07 -0000 Hello I checked now by sslLabs.com: https://www.ssllabs.com/ssltest/analyze.html?d=forums.freebsd.org and score is A+ But I don't think disable TLS 1.0 is ok. In test result paragraph: Handshake Simulation is informations that page will not work on: - Android 4.3 (and older) - IE 6,7,8 on XP/Vista - IE 8-10 on Win7 (TLS > 1.0 is disabled in default browser config) - old Java Very nice Web browser Secure protocols table: https://en.wikipedia.org/wiki/Transport_Layer_Security#Web_browsers Best Regards.