openssl 1.0.1 and rumors about TLS 1.0 attacks

2011-09-20 Thread Hanno Böck
Hi, It seems some rumors are spreading about an attack presented later this week against sslv3/tlsv1.0: http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/ Whatever this attack looks like in detail, all news one can find at the moment suggest that only sslv3/tls 1.0 is affected

Engines memory-management problems

2011-09-20 Thread Dmitry Belyavsky
Greetings! During the 1.x version the current scheme of algorithms providing through engines was implemented. Debugging our (Cryptocom LTD) engines, I’ve found some troubles in the way it works, please tell me where I’m mistaken. Openssl is configured with shared zlib enable-rfc3779 options.

Re: openssl 1.0.1 and rumors about TLS 1.0 attacks

2011-09-20 Thread Richard Könning
Am 20.09.2011 13:19, schrieb Hanno Böck: It seems some rumors are spreading about an attack presented later this week against sslv3/tlsv1.0: http://www.theregister.co.uk/2011/09/19/beast_exploits_paypal_ssl/ Whatever this attack looks like in detail, all news one can find at the moment suggest