Apps shouldn't let users enter OpenSSL cipher-suite strings

2 jedisct1 1 6/6/2025, 8:06:28 AM 00f.net ↗

Comments (1)

stop50 · 1d ago
Clientside apps: definitly not on Server side: i usually set an minimum tls version, The ciphers baseline of HIGH and removing some ciphers like sha1, CBC and any NULL Containing cipher