Currently each and every shipped application in distributions enforces its own policy on the allowed cryptographic algorithms/protocols. While for some this is a desirable property, for most unmanaged applications like wget, curl, and similar, it prevents enforcing a consistent security level. The purpose of this talk is to describe the approach we've taken in Fedora to counter the issue, and enforce a system-wide policies, discuss the current outcome, lessons learned, and invite Debian maintainers to participate.