User.js: Test whether the world is ready for security.ssl.require_safe_negotiation -> true

Created on 13 Mar 2017  路  10Comments  路  Source: pyllyukko/user.js

crypto website breakage

All 10 comments

Seems like one of the many implementations that web admins tend to ignore:
https://forum.palemoon.org/viewtopic.php?t=14549#p104106

It's not a matter of configuration, but upgrading the underlying TLS library to a version that supports RFC5746.

At least www.vmware.com is not ready :frowning_face:

New, TLSv1/SSLv3, Cipher is ECDHE-RSA-AES256-GCM-SHA384
Server public key is 2048 bit
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated

World doesn't seem ready yet, as RFC is actually supported by OpenSSL and others, but it's rarely implemented on the mail and webservers?

On Thunderbird: security.ssl.warn_missing_rfc5746;1

I know this is ancient but just adding that this broke Hulu login (auth.hulu.com) for me. 馃槥

Blame Hulu admins.

@Atavic oh yes, to be clear I'm definitely not blaming you guys! I'm just sad that some of the biggest websites are still way behind on implementing this almost two years later.

identify.nordea.com not ready :(

nordea

tools.cisco.com not ready.

caterpillar.com

Was this page helpful?
0 / 5 - 0 ratings

Related issues

nodiscc picture nodiscc  路  6Comments

gerroon picture gerroon  路  3Comments

brakenow picture brakenow  路  7Comments

thefleebs picture thefleebs  路  4Comments

brakenow picture brakenow  路  3Comments