Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Drop RC4 from the cipher list #551

Merged
merged 1 commit into from
Feb 19, 2015
Merged

Drop RC4 from the cipher list #551

merged 1 commit into from
Feb 19, 2015

Conversation

alex
Copy link
Contributor

@alex alex commented Feb 19, 2015

In addition to having many security concerns, it is a violation of RFC 7465 to include RC4 cipher suites in a ClientHello.

In addition to having many security concerns, it is a violation of RFC 7465 to include RC4 cipher suites in a ClientHello.
@sigmavirus24
Copy link
Contributor

👍

shazow added a commit that referenced this pull request Feb 19, 2015
Drop RC4 from the cipher list.
@shazow shazow merged commit a8702be into urllib3:master Feb 19, 2015
@shazow
Copy link
Member

shazow commented Feb 19, 2015

Thank you, @alex! You should add yourself to the CONTRIBUTORS.txt file one of these days for keeping our cipher suites fresh. :P

@alex
Copy link
Contributor Author

alex commented Feb 19, 2015

✨ 🍰

I'll send a PR adding myself momentarily :-)

@alex alex deleted the patch-1 branch February 19, 2015 01:41
shazow added a commit that referenced this pull request Feb 19, 2015
jsonn pushed a commit to jsonn/pkgsrc that referenced this pull request Mar 10, 2015
Changes


2.5.3 (2015-02-24)

Bugfixes

    Revert changes to our vendored certificate bundle. For more context see (#2455, #2456, and http://bugs.python.org/issue23476)

2.5.2 (2015-02-23)

Features and Improvements

    Add sha256 fingerprint support. (urllib3/urllib3#540)
    Improve the performance of headers. (urllib3/urllib3#544)

Bugfixes

    Copy pip’s import machinery. When downstream redistributors remove requests.packages.urllib3 the import machinery will continue to let those same symbols work. Example usage in requests’ documentation and 3rd-party libraries relying on the vendored copies of urllib3 will work without having to fallback to the system urllib3.
    Attempt to quote parts of the URL on redirect if unquoting and then quoting fails. (#2356)
    Fix filename type check for multipart form-data uploads. (#2411)
    Properly handle the case where a server issuing digest authentication challenges provides both auth and auth-int qop-values. (#2408)
    Fix a socket leak. (urllib3/urllib3#549)
    Fix multiple Set-Cookie headers properly. (urllib3/urllib3#534)
    Disable the built-in hostname verification. (urllib3/urllib3#526)
    Fix the behaviour of decoding an exhausted stream. (urllib3/urllib3#535)

Security

    Pulled in an updated cacert.pem.
    Drop RC4 from the default cipher list. (urllib3/urllib3#551)
@urllib3 urllib3 deleted a comment from butogon Sep 17, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

4 participants