[aklug] Re: SSL & TLS

From: Shane Spencer <shane@bogomip.com>
Date: Tue Sep 08 2009 - 20:19:11 AKDT

GnuTLS is a bit of a skunk right now.. I hope they get it right soon.

On Tue, Sep 8, 2009 at 6:20 PM, Michael Fowler<michael@shoebox.net> wrote:
> On Tue, Sep 08, 2009 at 03:45:35AM +0000, Damien Hull wrote:
>> I did some quick searching on SSL & TLS. I can't find an RFC for SSL.
>> I did find drafts for SSL but no actual RFC.
>
> SSL was never really formally standardized. =A0TLS is an attempt to
> standardize it, along with adding extra features.
>
> That being said, you can find specifications:
> =A0 =A0SSLv2: =A0http://www.mozilla.org/projects/security/pki/nss/ssl/dra=
ft02.html
> =A0 =A0SSLv3: =A0http://www.freesoft.org/CIE/Topics/ssl-draft/3-SPEC.HTM
>
> Wikipedia covers most of the salient points, along with the history.
>
> Beware of GnuTLS. =A0From everything I've read and experienced, it's far
> less robust than OpenSSL. =A0Unfortunately, the Debian OpenLDAP package i=
s
> compiled to use GnuTLS instead of OpenSSL, and I had no end of problems
> getting it working. =A0I ended up having to rebuild the packages to use
> OpenSSL.
>
> --
> Michael Fowler
> www.shoebox.net
> ---------
> To unsubscribe, send email to <aklug-request@aklug.org>
> with 'unsubscribe' in the message body.
>
>
---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Tue Sep 8 20:19:25 2009

This archive was generated by hypermail 2.1.8 : Tue Sep 08 2009 - 20:19:25 AKDT