RE: Question in regards to early warning about new openssl versions

2014-08-13 Thread Salz, Rich
Thanks for your kind words. We do post a notice that we're putting out a security update. Not sure how you missed it... -- Principal Security Engineer Akamai Technologies, Cambridge MA IM: rs...@jabber.me Twitter: RichSalz

Re: Question in regards to early warning about new openssl versions

2014-08-13 Thread Kurt Roeckx
On Wed, Aug 13, 2014 at 01:12:12PM -0400, Henning Horst wrote: Dear OpenSSL-Team, First of all, thank you for your great work! I hope openssl-dev is the right list for the following request: Many projects rely on OpenSSL of course and whenever a new version is published fixing security

Re: Question in regards to early warning about new openssl versions

2014-08-13 Thread Steef
Hi Henning, So my question is - would it be reasonable to send an early warning (without any details) to one of the OpenSSL lists a few days before publishing a version containing fixes for security vulnerabilities? Just saying something along the lines of we plan to release a new openssl

Re: Question in regards to early warning about new openssl versions

2014-08-13 Thread Steef389
Hi Henning, So my question is - would it be reasonable to send an early warning (without any details) to one of the OpenSSL lists a few days before publishing a version containing fixes for security vulnerabilities? Just saying something along the lines of we plan to release a new openssl

Re: Question in regards to early warning about new openssl versions

2014-08-13 Thread Henning Horst
Duh - thank you Steef, Kurt and Rich - not sure how I could miss that either... So please only take the key message - your team does a great job with OpenSSL, thank you all! Regards, Henning On 08/13/2014 01:35 PM, Steef wrote: Hi Henning, So my question is - would it be reasonable to send