foxcpp / foxcpp/maddy

outdated docs default tls version

オープン
#702 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug
主要言語
Go
スター
6.1k
フォーク
327
PR マージ指標
30日以内にマージされた PR はありません

説明

heyjo :3

i think the docs are outdated on the minimum tls version.
honestly i am not comfy reading go and don't know enough about mail.
i was email rfc's and in 8997 it says that the minimum TLS version used by an MSP should be 1.2 or greater.
in the [docs](https://maddy.email/reference/tls/) it says that maddy uses tls 1.0 as its minimum version.
when running maddy without any tls options with curl and setting the tls protocol via `--tls-max` i get anything below 1.2 rejected.
i think the way i got the code is that in the default case the `tls.Config.MinVersion` and `tls.Config.MaxVersion` are set to O. honestly i didn't bother to spend more time reading the go lib for crypto much beyond their comment that the default tls version is 1.2 and found [this PR from a year back](https://github.com/golang/go/issues/62459) saying that they bumped it.
the docs weren't updated since then (`tls.md` at least).
that's why i guess everything is fine, it's just that the docs are outdated.

best regards

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。