From mboxrd@z Thu Jan 1 00:00:00 1970 X-Msuck: nntp://news.gmane.io/gmane.emacs.gnus.general/85610 Path: news.gmane.org!not-for-mail From: Lars Ingebrigtsen Newsgroups: gmane.emacs.gnus.general Subject: Re: Diffie-Hellman key exchange has been lowered to 256 bits Date: Wed, 28 Jan 2015 16:18:07 +1100 Message-ID: <87h9vbxz3k.fsf@building.gnus.org> References: NNTP-Posting-Host: plane.gmane.org Mime-Version: 1.0 Content-Type: text/plain X-Trace: ger.gmane.org 1422422465 21073 80.91.229.3 (28 Jan 2015 05:21:05 GMT) X-Complaints-To: usenet@ger.gmane.org NNTP-Posting-Date: Wed, 28 Jan 2015 05:21:05 +0000 (UTC) Cc: ding@gnus.org To: James Cloos Original-X-From: ding-owner+M33851@lists.math.uh.edu Wed Jan 28 06:21:00 2015 Return-path: Envelope-to: ding-account@gmane.org Original-Received: from util0.math.uh.edu ([129.7.128.18]) by plane.gmane.org with esmtp (Exim 4.69) (envelope-from ) id 1YGL3j-0000UY-0S for ding-account@gmane.org; Wed, 28 Jan 2015 06:20:59 +0100 Original-Received: from localhost ([127.0.0.1] helo=lists.math.uh.edu) by util0.math.uh.edu with smtp (Exim 4.63) (envelope-from ) id 1YGL3e-0008R2-Lc; Tue, 27 Jan 2015 23:20:54 -0600 Original-Received: from mx2.math.uh.edu ([129.7.128.33]) by util0.math.uh.edu with esmtps (TLSv1:AES128-SHA:128) (Exim 4.63) (envelope-from ) id 1YGL3d-0008Qn-GQ for ding@lists.math.uh.edu; Tue, 27 Jan 2015 23:20:53 -0600 Original-Received: from quimby.gnus.org ([80.91.231.51]) by mx2.math.uh.edu with esmtps (TLSv1.2:DHE-RSA-AES128-SHA:128) (Exim 4.84) (envelope-from ) id 1YGL3c-0005Ii-6N for ding@lists.math.uh.edu; Tue, 27 Jan 2015 23:20:53 -0600 Original-Received: from smtp.syd.comcen.com.au ([203.23.236.77]) by quimby.gnus.org with esmtp (Exim 4.80) (envelope-from ) id 1YGL3a-000347-2R for ding@gnus.org; Wed, 28 Jan 2015 06:20:50 +0100 Original-Received: from building.gnus.org ([27.96.197.126]) by smtp.syd.comcen.com.au (8.13.4/8.12.9) with ESMTP id t0S5ICv0025197; Wed, 28 Jan 2015 16:18:12 +1100 (EST) In-Reply-To: (James Cloos's message of "Sat, 21 Jun 2014 11:44:37 +0000") User-Agent: Gnus/5.130012 (Ma Gnus v0.12) Emacs/25.0.50 (gnu/linux) X-comcen-MailScanner-Information: Please contact the ISP for more information X-comcen-MailScanner: Found to be clean X-comcen-MailScanner-SpamCheck: not spam, SpamAssassin (not cached, score=0.102, required 4, AWL 0.00, BAYES_50 0.00, RDNS_NONE 0.10) X-comcen-MailScanner-From: larsi@gnus.org X-Spam-Score: -1.9 (-) List-ID: Precedence: bulk Xref: news.gmane.org gmane.emacs.gnus.general:85610 Archived-At: James Cloos writes: > I've been getting this message on my deb box for a few days now: > > ,---- > | gnutls.c: [1] Note that the security level of the Diffie-Hellman key > | exchange has been lowered to 256 bits and this may allow decryption of > | the session data > `---- > > It occurs for both nntp starttls and imaps connectins. > > That box runs sid and emacs24-nox, which uses libgnutls-deb0-28 > (currently 3.2.15-2). Is this a new warning libgnutls outputs now? If so, we should filter it out on the Emacs side. -- (domestic pets only, the antidote for overdose, milk.) bloggy blog http://lars.ingebrigtsen.no/