Title: SSL module should not offer RC4 based cipher suites for clients by default
Author: Alex Gaynor (alex) * (Python committer) Date: 2015-02-19 00:54
In addition to the security concerns, it is now a violation of RFC7465 to offer a cipher suite with RC4 in a ClientHello:
Author: Ian Cordasco (icordasc) * Date: 2015-02-19 00:56
It's clearly no longer acceptable to include RC4 when the IETF has felt it necessary to publish an RFC prohibiting its usage.
Author: Antoine Pitrou (pitrou) * (Python committer) Date: 2015-02-19 22:22
Sounds fine to me. Should a test be added?
Author: Roundup Robot (python-dev) (Python triager) Date: 2015-02-19 22:58
New changeset c509e6f18d7d by Benjamin Peterson in branch '3.4':
remove rc4 from the default client ciphers (closes #23481)

New changeset 3596081cfb55 by Benjamin Peterson in branch '2.7':
remove rc4 from the default client ciphers (closes #23481)

New changeset 041a27298cf3 by Benjamin Peterson in branch 'default':
merge 3.4 (#23481)
