aboutsummaryrefslogtreecommitdiffstats
path: root/NEWS
diff options
context:
space:
mode:
authorMatthias Andree <matthias.andree@gmx.de>2016-05-26 11:18:53 +0200
committerMatthias Andree <matthias.andree@gmx.de>2016-05-26 11:18:53 +0200
commitffbe69a5caa0cd3738e93d0a195c12f03dd452a0 (patch)
treee84407f7f5f0ad6a1fe9ec436660afa35b5bb726 /NEWS
parent37c389b762451f645c2732e057fa4f24b4cfba4d (diff)
downloadfetchmail-ffbe69a5caa0cd3738e93d0a195c12f03dd452a0.tar.gz
fetchmail-ffbe69a5caa0cd3738e93d0a195c12f03dd452a0.tar.bz2
fetchmail-ffbe69a5caa0cd3738e93d0a195c12f03dd452a0.zip
Fix a few inconsistencies.
Diffstat (limited to 'NEWS')
-rw-r--r--NEWS11
1 files changed, 6 insertions, 5 deletions
diff --git a/NEWS b/NEWS
index 44e02b21..e02a7f0c 100644
--- a/NEWS
+++ b/NEWS
@@ -69,17 +69,18 @@ fetchmail-6.4.0 (not yet released):
TLS version, with STLS/STARTTLS (it would previously force TLSv1.0 with
STARTTLS). If the OpenSSL version used at build and run-time supports these
versions, --sslproto ssl3 and --sslproto ssl3+ can be used to re-enable SSLv3.
- Doing so is discouraged because these SSLv3 protocol is broken.
+ Doing so is discouraged because the SSLv3 protocol is broken.
Along the lines suggested - as patch - by Kurt Roeckx, Debian Bug #768843.
While this change is supposed to be compatible with common configurations,
- users are advised to change all explicit --sslproto ssl2, --sslproto
- ssl3, --sslproto tls1 to --sslproto auto, so that they can enable TLSv1.1 and
- TLSv1.2 on systems with OpenSSL 1.0.1 or newer.
+ users may have to and are advised to change all explicit --sslproto ssl2
+ (change to newer protocols required), --sslproto ssl3, --sslproto tls1 to
+ --sslproto auto, so that they can benefit from TLSv1.1 and TLSv1.2 where
+ supported by the server.
The --sslproto option now understands the values auto, ssl3+, tls1+, tls1.1,
- tls1.1+, tls1.2, tls1.2+ (case insensitively).
+ tls1.1+, tls1.2, tls1.2+ (case insensitively), see CHANGES below for details.
* Fetchmail defaults to --sslcertck behaviour. A new option --nosslcertck to
override this has been added, but may be removed in future fetchmail versions