Skip to content
This repository has been archived by the owner on Feb 16, 2021. It is now read-only.

Include reasoning why certain ciphers should be removed #80

Open
claudijd opened this issue Jun 19, 2017 · 5 comments
Open

Include reasoning why certain ciphers should be removed #80

claudijd opened this issue Jun 19, 2017 · 5 comments

Comments

@claudijd
Copy link
Contributor

Source: https://twitter.com/fugueish/status/876891820134813696

Currently, we suggest removal for cases where a cipher is not in the policy. Perhaps we need to be more specific about why a cipher is not part of a given policy.

@claudijd
Copy link
Contributor Author

claudijd commented Jun 19, 2017

We should also revisit the Modern policy for SSH and provide justifications for each and maybe even get some community vetting of the list. This could be a good discussion point for next week in SFO over beverages_of_choice.

@claudijd
Copy link
Contributor Author

/cc @gdestuynder you game?

@floatingatoll
Copy link

Don't block this on that, but Modern's already been under review for some time now in a bug open on their side.

@claudijd
Copy link
Contributor Author

/cc @jvehent interested?

@gdestuynder
Copy link

Yeah i think we have a similar "issue" with TLS guidelines, where we basically make an opinionated choice on what list you need to be following the standard we set.
It can be improved for expectations setting though, which can be by including rationales in the output of recommendations

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants