Skip to content

Conversation

@smortex
Copy link
Member

@smortex smortex commented Dec 23, 2025

SSLv3 is long gone, we could also probably also disable TLS 1.0 and 1.1,
but recent changes in the openssl gem freeze the default parameters, and
the default configuration seems to have the correct behavior on the
systems I tested, refusing to connect to hosts with anything older than
TLS 1.2.

Drop this monkey patching to unbreak with version 4.0.0 of the openssl
gem.

Fixes OpenVoxProject/openbolt#169

SSLv3 is long gone, we could also probably also disable TLS 1.0 and 1.1,
but [recent changes in the openssl gem freeze the default parameters](ruby/openssl#925), and
the default configuration seems to have the correct behavior on the
systems I tested, refusing to connect to hosts with anything older than
TLS 1.2.

Drop this monkey patching to unbreak with version 4.0.0 of the openssl
gem.

Fixes OpenVoxProject/openbolt#169
@smortex smortex force-pushed the remove-sslv3-monkey-patch branch from 6e2d29f to e79be53 Compare December 23, 2025 00:14
@bastelfreak bastelfreak added the enhancement New feature or request label Dec 23, 2025
@bastelfreak bastelfreak merged commit 9336df1 into main Dec 23, 2025
15 checks passed
@bastelfreak bastelfreak deleted the remove-sslv3-monkey-patch branch December 23, 2025 08:41
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Upcoming issue with openssl 4.0.0 gem

4 participants