outdated docs default tls version
- Dominant language
- Go
- Stars
- 6.1k
- Forks
- 327
- PR merge metrics
- No merged PRs in 30d
Description
heyjo :3
i think the docs are outdated on the minimum tls version.
honestly i am not comfy reading go and don't know enough about mail.
i was email rfc's and in 8997 it says that the minimum TLS version used by an MSP should be 1.2 or greater.
in the [docs](https://maddy.email/reference/tls/) it says that maddy uses tls 1.0 as its minimum version.
when running maddy without any tls options with curl and setting the tls protocol via `--tls-max` i get anything below 1.2 rejected.
i think the way i got the code is that in the default case the `tls.Config.MinVersion` and `tls.Config.MaxVersion` are set to O. honestly i didn't bother to spend more time reading the go lib for crypto much beyond their comment that the default tls version is 1.2 and found [this PR from a year back](https://github.com/golang/go/issues/62459) saying that they bumped it.
the docs weren't updated since then (`tls.md` at least).
that's why i guess everything is fine, it's just that the docs are outdated.
best regards
Contributor guide
Research direction
Start with tls.md and compare its stated minimum TLS version with the behavior described using curl and --tls-max, then check the linked Go TLS-default discussion for context. Done means the documentation accurately describes maddy's default minimum TLS version and no longer claims TLS 1.0 if the default rejects older versions.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- go
- Domain
- documentation
- Issue type
- Documentation
- Difficulty
- 1/5
- Estimated time
- Under an hour
- Activity status
- Stale
- Clarity
- Clearly specified
- Newbie friendliness
- 55/100