use of SSLv3 in Koji

Kevin Fenzi kevin at scrye.com
Thu Oct 16 22:44:31 UTC 2014


On Thu, 16 Oct 2014 16:58:48 -0500
Mátyás Selmeci <matyas at cs.wisc.edu> wrote:

> Hi,
> It looks like Koji is hardcoded to use SSLv3 (looking at 
> CreateSSLContext() in koji/SSLCommon.py) and does not work if SSLv3
> is disabled in the apache configs of koji-hub. Are there any plans to 
> change that, in light of the POODLE SSLv3 vulnerability?
> Thanks,

Yes, but it turns out there's no cause for undue haste... 

https://lists.fedoraproject.org/pipermail/infrastructure/2014-October/014992.html

kevin
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 819 bytes
Desc: not available
URL: <http://lists.fedoraproject.org/pipermail/buildsys/attachments/20141016/af567178/attachment.sig>


More information about the buildsys mailing list