Re: breaking TLS (Was: Re: multiplexing -- don't do it)

In message <20120406211424.GB4336@1wt.eu>, Willy Tarreau writes:

>In my opinion we should let the user decide between GET https:// and
>CONNECT. That solves all issues because admins can let just a short
>whitelist run on CONNECT, with the rest being analyzed.

For reasons of backwards compat, I don't think we'll get rid of
CONNECT any time soon, and since it is also widely used for getting
VPN out through corp perimeters, it will have to be supported by
proxies still.

-- 
Poul-Henning Kamp       | UNIX since Zilog Zeus 3.20
phk@FreeBSD.ORG         | TCP/IP since RFC 956
FreeBSD committer       | BSD since 4.3-tahoe    
Never attribute to malice what can adequately be explained by incompetence.

Received on Friday, 6 April 2012 21:26:33 UTC