Updates to Gemini best practices

solderpunk solderpunk at SDF.ORG
Sat May 23 11:03:40 BST 2020


Hello again!

I have also just made changes to the official "best practices" document
at:

* gemini://gemini.circumlunar.space/docs/best-practices.txt
* gopher://gemini.circumlunar.space/0/docs/best-practices.txt
* https://gemini.circumlunar.space/docs/best-practices.txt

There is a new section on TLS cipher suites wherein it is recommended
that anybody who is supporting TLS 1.2 (which is optional according to
the spec, but more or less a practical requirement at this point in
order to be able to communicate with clients/servers using e.g. LibreSSL
or BearSSL) supports only a minimal subset of it to provide similar
security to TLS 1.3.

This might be a nice thing for server testing tools (like
gemini-diagnostics) to optionally test!

Cheers,
Solderpunk

PS: You can all guess what the next email will be...


More information about the Gemini mailing list