Information about the security levels can be found in the SSL_CTX_set_security_level(3ssl) manpage.

The default security level for TLS connections has also been increased from level 1 to level 2.Sometimes, changes introduced in a new release have side-effects we cannot reasonably avoid, or they expose bugs somewhere else. Please also read the errata, the relevant packages' documentation, bug reports, and other information mentioned in Section 6.1, “Further reading”. These now specify signature algorithms that are accepted for their respective authentication mechanism, where previously they specified accepted key types.This distinction matters when using the RSA/SHA2 signature algorithms and their certificate counterparts.A fix for the installer is being planned (see bug #931373) and will be uploaded to debian-security.In the meantime users of full disk encryption should apply the above workaround.

