| Summary: | curl doesn't work with RC4-SHA over SSL | ||
|---|---|---|---|
| Product: | Red Hat Enterprise Linux 6 | Reporter: | Strahinja Kustudic <kustodian> |
| Component: | curl | Assignee: | Kamil Dudka <kdudka> |
| Status: | CLOSED NOTABUG | QA Contact: | BaseOS QE Security Team <qe-baseos-security> |
| Severity: | medium | Docs Contact: | |
| Priority: | unspecified | ||
| Version: | 6.2 | CC: | prc |
| Target Milestone: | rc | ||
| Target Release: | --- | ||
| Hardware: | x86_64 | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | Bug Fix | |
| Doc Text: | Story Points: | --- | |
| Clone Of: | Environment: | ||
| Last Closed: | 2012-03-31 19:41:21 UTC | Type: | --- |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
|
Description
Strahinja Kustudic
2012-03-28 15:33:18 UTC
From the changes in https://rhn.redhat.com/errata/RHBA-2012-0430.html I was hoping this would be fixed, but it's not. The exact same result like before. (In reply to comment #0) > curl doesn't work with a SSL connection which are using RC4-SHA as the cypher. They are not enabled by default. You can override it by the --cipher option: curl --cipher rsa_rc4_128_sha https://api2.boku.com/billing/request That works, but why was this changed, since this wasn't needed in RHEL5? The default set of enabled cipher suites is configured to conform with current U.S. export regulations related to software products with encryption features. http://www.mozilla.org/projects/security/pki/nss/ref/ssl/sslfnc.html#1098841 |