Re: GnuTLS/TLS proposals for after the release

From: Ted Zlatanov
Subject: Re: GnuTLS/TLS proposals for after the release
Date: Wed, 06 Jul 2016 08:21:44 -0400
User-agent: Gnus/5.13 (Gnus v5.13) Emacs/25.1.50 (gnu/linux)

On Tue, 05 Jul 2016 17:32:59 -0700 John Wiegley <address@hidden> wrote: 

>>>>>> Ted Zlatanov <address@hidden> writes:
>> Here are some thoughts about the near future of gnutls.el and friends (none
>> urgently needed for the release):

JW> Ted, can you, or someone with more experience in this area, help me to
JW> understand these alternatives? If we are all generally agreed on one over 
JW> others, I'm willing to go with the wisdom of consensus.

These are three separate proposals, not alternatives of each other.

They have different purposes: (1) is to make tls.el, which uses
command-line tunnels, more noisy by default, so users are led to the C
bindings to GnuTLS (gnutls.el). (2) is to disable SSLv3 in tls.el. (3)
is to change the variables in gnutls.el a bit to make customization and
future work easier. (3) is the only risky one because it affects user
customizations, but I think we have to bite that buller sooner or later.

There are several people who have worked in this area besides me, mainly
Lars and Paul Eggert I think. I asked Lars about (3) already but haven't
heard back. Any comments are welcome, of course.


