Closed Bug 1473987 Opened 6 years ago Closed 6 years ago

Gradual roll-out of TLS fallback-limit to 1.3 on release channel (61)

Categories

(Core :: Security: PSM, enhancement)

enhancement
Not set
normal

Tracking

()

RESOLVED FIXED
Tracking Status
firefox61 + fixed

People

(Reporter: rhelmer, Assigned: rhelmer)

Details

We'd like to now do a gradual roll-out of the TLS fallback-limit pref. This is controlled by the "security.tls.version.fallback-limit" pref, which is currently set to 3 (TLS 1.2) on Beta. The value we wish to roll out is 4 (TLS 1.3) We tested this roll-out on Beta in bug 1462164. Initial roll-out should be to 25%
(In reply to Robert Helmer [:rhelmer] from comment #0) > Initial roll-out should be to 25% After discussion, we'd like to go to 10% ASAP and ramp up further Monday after looking at data from the weekend.
I didn't want to come into this cold on late Friday afternoon so I asked to delay till Monday. We're going ahead with 25% rollout from the email discussion. Telemetry results come in quickly so ekr and team will be watching to let us know whether to halt rollout or increase it by Wednesday.
After talking with rhelmer, this recipe has been published at 10%, with plans to ramp it up further over the next few days.
We're at 95% now I believe?
Flags: needinfo?(rhelmer)
(In reply to Ryan VanderMeulen [:RyanVM][PTO Until August 6] from comment #4) > We're at 95% now I believe? This is correct. I'll find out if we want to stay here or go to 100%.
Flags: needinfo?(rhelmer)
(In reply to Robert Helmer [:rhelmer] from comment #5) > (In reply to Ryan VanderMeulen [:RyanVM][PTO Until August 6] from comment #4) > > We're at 95% now I believe? > > This is correct. I'll find out if we want to stay here or go to 100%. Just spoke to ekr, we might as well stay at 95% and just bump the default for the next release (62)
Do we have a bug about bump the default?
(In reply to Masatoshi Kimura [:emk] from comment #7) > Do we have a bug about bump the default? I don't see any from a quick search, I'll file momentarily.
(In reply to Robert Helmer [:rhelmer] from comment #8) > (In reply to Masatoshi Kimura [:emk] from comment #7) > > Do we have a bug about bump the default? > > I don't see any from a quick search, I'll file momentarily. Bug 1479501.
Based on comment 6, I'm resolving this bug as fixed since no further work is planned for 61.
Status: NEW → RESOLVED
Closed: 6 years ago
Resolution: --- → FIXED

Hi Robert,

Mythmon and I review Normandy feature-rollout recipes once a month to see which ones can be disabled. This recipe now has a low enrollment (weekly and 4-week) number. I would like to disable it. Do you have any concerns?

Flags: needinfo?(rhelmer)

(In reply to Ritu Kothari (:ritu) from comment #11)

Hi Robert,

Mythmon and I review Normandy feature-rollout recipes once a month to see which ones can be disabled. This recipe now has a low enrollment (weekly and 4-week) number. I would like to disable it. Do you have any concerns?

No concerns from me, if enrollment has dropped below the threshold that it's useful. This pref has been the default for many releases now.

Flags: needinfo?(rhelmer)
You need to log in before you can comment on or make changes to this bug.