Skip to content

Conversation

3rd-Eden
Copy link
Member

I found out that we're not providing any sane HTTPS default options by default. While this would affect IE6 users because SSLv2 will no longer be supported by it, it will create a more secure connection for the rest of the world. As this is a major breaking change, Primus and this module should receive a major bump.

@lpinca
Copy link
Member

lpinca commented Aug 24, 2015

I'm not an expert of security defaults but using a config that prevents heartbleed and the like, seems a good idea. The refactor LGTM.

3rd-Eden added a commit that referenced this pull request Aug 24, 2015
@3rd-Eden 3rd-Eden merged commit 9c4b8e2 into master Aug 24, 2015
@3rd-Eden 3rd-Eden deleted the sane-https branch August 24, 2015 18:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants