Skip to content

Plan for updating technical configuration/best practices #81

@znewman01

Description

@znewman01

I think it's great that this proposal is so specific about e.g. encouraging ECDHE, discouraging RC4, etc. But I worry that for many agencies this will be set-and-forget: if someone comes up with an attack on TLS1.0 or AES 128 is no longer considered sufficient in 2016, what would the plan be to upgrade any agencies that already implemented TLS1.0? My suspicion is that they wouldn't do it on their own accord.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions