Skip to content

Comment on OpenSSL in Debian Unstable drops TLS 1.0/1.1 supportparent

Comments

At a previous job they finally deprecated RC4-MD5, long after almost everyone had stopped using it.

About a week later they had to re-enable it, because it turned out a few major customers had some old SPARC (IIRC?) boxes that used the service. The extra overhead of non RC4-MD5 ciphers was crippling them. There was some seriously frantic back and forth with the customer to get the situation resolved and figure out a timeline to finally, finally, finally deprecate RC4-MD5.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.