[Spice-devel] [PATCH spice-server] Use TLS version 1.0 or better

David Jaša djasa at redhat.com
Wed Nov 27 08:30:45 PST 2013


Before writing these patches against git, I wrote them as patches to rpm
packages on my system and I performed several tests. When both packages
had the patch included, the TLS version in use was 1.2. When only one of
them had the patch included, the TLS version falled back to 1.0 (same as
status quo). I did also tests using s_client:
openssl s_client -CAfile /path/to/ca.pem -connect hostname:port -VERSION

and the server rightfully accepted TLS 1.0 - TLS 1.2. Without the patch,
only TLS 1.0 was accepted.

David


-- 

David Jaša, RHCE

SPICE QE based in Brno
GPG Key:     22C33E24 
Fingerprint: 513A 060B D1B4 2A72 7F0D 0278 B125 CD00 22C3 3E24


-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/x-pkcs7-signature
Size: 5727 bytes
Desc: not available
URL: <http://lists.freedesktop.org/archives/spice-devel/attachments/20131127/66cf6544/attachment.bin>


More information about the Spice-devel mailing list