Re: [openssl-users] [openssl-dev] Kerberos

2015-05-14 Thread Jeffrey Altman
On 5/13/2015 10:19 AM, Matt Caswell wrote: On 08/05/15 09:40, Matt Caswell wrote: On 08/05/15 02:28, Jeffrey Altman wrote: Regardless, the inability to improve the support in this area has left the those organizations that rely upon 2712 with the choice of use insecure protocols or re

Re: [openssl-users] [openssl-dev] Replacing RFC2712 (was Re: Kerberos)

2015-05-13 Thread Jeffrey Altman
there is an implementation in Cyrus/SASL. This is the most recent version I could find http://www.opensource.apple.com/source/passwordserver_sasl/passwordserver_sasl-159/cyrus_sasl/doc/draft-burdis-cat-srp-sasl-xx.txt Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature

Re: [openssl-users] Kerberos

2015-05-08 Thread Jeffrey Altman
. Or perhaps hold an IETF BOF first to explore the interest. The last time I was involved the work product was https://tools.ietf.org/html/draft-santesson-tls-gssapi-03 I still believe that is a reasonable approach. Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature

Re: [openssl-users] Kerberos

2015-05-07 Thread Jeffrey Altman
that any sane OS or application vendor can with a straight face continue to ship 2712 support. As such it should be removed from OpenSSL master. Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature ___ openssl-users mailing list

Re: Post-2010 future of the OpenSSL FIPS Object Module?

2010-02-19 Thread Jeffrey Altman
Foundation is *NOT* a 501(c)3. This is described at http://www.openssl.org/support/donations.html Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature

Re: win32 openssl w/o requiring the dreaded msvcr71.dll?

2008-03-27 Thread Jeffrey Altman
Bobby Krupczak wrote: Hi! I'm trying to build a multi-platform application using openssl. I'm using the win32 ssl libs built by Shining Path. However, those libs require msvcr71.dll whilst the rest of my apps are compiled such that they only require msvcr.dll Since I want my app to run

Re: What is an OpenSSL issue (was Re[2]: Vista 64 bit)

2008-01-03 Thread Jeffrey Altman
costs money. Where do you think the user will go first? The best you can do is try to give end users a message to send back to the application developer and at the same time attempt to answer their question or point them at the official distributors and let Thomas deal with the fallout. Jeffrey

Re: Vista 64 bit

2008-01-01 Thread Jeffrey Altman
Thomas J. Hruska wrote: I'm holding back from a 64-bit build of the Win32(?) OpenSSL installer for another couple weeks because I need to purchase Visual Studio Professional 2008 (i.e. I can't use VC++ Express) for various reasons and my development computer gets unhappy when I install new

Re: Vista 64 bit

2008-01-01 Thread Jeffrey Altman
Thomas J. Hruska wrote: I know about the 90 day trial. The VS 2008 install is going to hose my existing dev. environment. So, I'd rather just hose it once (install the full thing) than hose it twice (install the trial and then install the full thing). I have VS.2003, VS.2005, and VS.2008 all

Re: Authenticode in Vista

2006-04-25 Thread Jeffrey Altman
service. The problem appears to be that only the Verisign Code Signing CA is now a trust anchor for validating Authenticode signatures. It looks like I will have to buy a cert from Verisign when the current one expires. Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature

Re: Licenses...

2006-04-10 Thread Jeffrey Altman
the GPL's rules, but how the postgresql client library was compiled isn't neccessarily under freeradius's control. Maybe the problem is the GPL rules. Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature

Re: Compilation of OpenSSL-fips-1.0 under Windows

2006-04-06 Thread Jeffrey Altman
Tools? Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature

Peter Runestig has passed away

2005-07-23 Thread Jeffrey Altman
Last month, Peter Runestig [EMAIL PROTECTED] passed away from a heart attack. Peter was an active participant in the openssl community. He will be dearly missed by all that knew him. Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature

Re: question -- should SSL server send certs for all CAs?

2005-01-10 Thread Jeffrey Altman
. Jeffrey Altman Jason Keltz wrote: Hi. I have a question with respect to SSL protocol. Is it part of the protocol that the SSL server send to the client the public keys for the CAs making up the certificate chain? or is it acceptable to send just the server public key and expect the client

Re: openssl, c-kermit and IBM information exchange

2004-04-27 Thread Jeffrey Altman
between you and IBM which does not permitted secure FTP sessions. Jeffrey Altman Kermit 95 Author Secure Endpoints Inc Vasseur, Peter wrote: Hello. I am trying to make a secure FTP connection to IBM Information Exchange from my UNIX machine. I am using C-Kermit 8.0.211, which I compiled for use

Re: Unorthodox SSL Questions

2004-02-18 Thread Jeffrey Altman
Marton Anka wrote: Message Hello, I am trying to solve a verypeculiar problem. In my application, there are three players: 1. Client - runs a regular web browser. 2. Proxy - runs my proxy application with OpenSSL 0.9.7c 3. Host - runs my host application with

Re: Unorthodox SSL Questions

2004-02-18 Thread Jeffrey Altman
if they were to fail. Jeffrey Altman smime.p7s Description: S/MIME Cryptographic Signature

Re: ASN.1 overflows

2004-02-10 Thread Jeffrey Altman
It doesn't. OpenSSL does not use the Microsoft ASN.1 Library. Mark Foster wrote: http://www.us-cert.gov/cas/techalerts/TA04-041A.html Does this affect openssl running on Window'splatforms? __ OpenSSL Project

Re: openssl+zlib /MD problem

2003-07-23 Thread Jeffrey Altman
I have been linking applications with both OpenSSL and ZLIB for many years now without difficulties. My guess is that either your app is not using the MSVCRT.DLL or that your are linking to some other library which is using an alternative C Runtime library. Jeffrey Altman Andrew Marlow wrote

Re: [ADVISORY] Timing Attack on OpenSSL

2003-03-17 Thread Jeffrey Altman
This is a different vulnerability. The one you patched two weeks ago was caused by a failure to decrypt messages when the MAC comparison failed. This vulnerability is a timing attack against the RSA algorithms. The Slashdot discussion is here:

Re: ftp implicit ssl connection

2003-03-15 Thread Jeffrey Altman
PBSZ is used when you are negotiating the size of the buffer to be encrypted. If you are using FTP over SSL, the FTP protocol is not performing any authentication or encryption. Therefore, you do not use PBSZ. gomess wrote: It is very unclear to me what type of help you are looking

Re: ftp implicit ssl connection

2003-03-13 Thread Jeffrey Altman
It is very unclear to me what type of help you are looking for. There are many SSL/TLS FTP client and server implementations available as open source in addition to the specifications for the protocol which are available as an Internet-Draft. What do you need? gomess wrote:

Re: Openssl and Kerberos

2003-03-11 Thread Jeffrey Altman
C-Kermit 8.0 http://www.kermit-project.org/ckermit.html implements it for both client and server sides. - Jeff Markus Moeller wrote: Are there any example programs documentations of how to use Openssl with Kerberos for authentication/encryption (rfc2712) ? Thank you Markus

Re: Openssl and Kerberos

2003-03-11 Thread Jeffrey Altman
or they do not. - Jeff Markus Moeller wrote: On Tuesday 11 Mar 2003 12:12, Jeffrey Altman wrote: Jeff, thanks for the link. The only problem I have now is how to filter out of the hundred of options the ones related to openssl/kerberos? Also I was wondering, what you would need to do if you

Re: openssl not thread-safe: any alternatives?

2003-02-24 Thread Jeffrey Altman
Are you using the mutex locks with blocking or non-blocking sockets? Using mutex locks with non-blocking sockets most definitely works. Folkert van Heusden wrote: So, my questions are: - am I doing something and IS openssl threadsafe? - is there an alternative for openssl doing which

Re: OpenSSL 0.9.7a and versioning issues

2003-02-20 Thread Jeffrey Altman
OpenSSH and C-Kermit both perform checks of the version string of the library versus the version string of the headers the program was compiled with. This is done to ensure that the OpenSSL header constants and APIs used to build the program match those in the library. Both products must be

Re: OpenSSL 0.9.7a and versioning issues

2003-02-20 Thread Jeffrey Altman
That is how current versions of the software work. You can of course hack the code and remove the checks on your system if you would like. I do not predict what the future may hold. Phil Howard wrote: On Thu, Feb 20, 2003 at 06:17:02PM -0500, Jeffrey Altman wrote: | OpenSSH and C-Kermit

Re: Kerberos/PKINIT compliant subjectAltName?

2003-02-11 Thread Jeffrey Altman
Dr. Stephen Henson wrote: On Tue, Feb 11, 2003, Thomas Anders wrote: Hello, the Kerberos/PKINIT Internet draft (http://www.ietf.org/internet-drafts/draft-ietf-cat-kerberos-pk-init-16.txt, chapter 3.2.2.2) requires the KDC certificates to specify Kerberos realm and principal name

Re: SSL_accept hang

2003-02-04 Thread Jeffrey Altman
As long as you are on a Windows system that implements WinSock2 all you need to do is specify int timeout = 15; setsockopt(socket, SOL_SOCKET, SO_RCVTIMEO, timeout, sizeof(int)); This will result in the following behaviors as described in

Re: SSL_accept hang

2003-02-04 Thread Jeffrey Altman
Can you please elaborate on the algorithm you are using to accept connections? The SSL_accept() does not take a server socket (the socket on which the accept() call is performed.) Therefore, I do not know why the SSL_accept() should block accept() calls unless you are calling them in sequence

Re: explicit linking question (6)

2003-02-03 Thread Jeffrey Altman
You can use LoadLibrary() to load the DLLs at runtime instead of linking to them at compile time. However, if you do this you will need to load each function pointer programatically. dan demers wrote: in the windows environment, is it possible to use the explicitly

Re: Socket call fails with OpenSSL 0.9.6h on Win32

2002-12-29 Thread Jeffrey Altman
WSAStartup() is required for Winsock 1.x as well. You should be calling this in your application. It would be inappropriate for this to be called from OpenSSL. Peter Aben wrote: I have used OpenSSL 0.9.6c in our application successfully on various platforms. After upgrading to 0.9.6h, on the

Re: Slapper denial-of-service problem - why isn't this fixed?

2002-12-21 Thread Jeffrey Altman
Geoff: Since absolutely no one that is experiencing this problem has looked at a suffering process in a debugger it is impossible to know what is the cause of the problem. As far as I can tell all the theories that have been put forward as to what this is or is not are simply best guesses

Re: PROBLEM

2002-11-26 Thread Jeffrey Altman
Manager [EMAIL PROTECTED] Jeffrey Altman * Volunteer Developer Kermit 95 2.1 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org/Secured with MIT Kerberos, SRP

Re: IMPORTANT: The release of 0.9.6h is postponed

2002-11-25 Thread Jeffrey Altman
that is not entirely predictable that ensures the function cannot be optimized out. Jeffrey Altman * Volunteer Developer Kermit 95 2.1 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org/Secured with MIT

Re: IMPORTANT: The release of 0.9.6h is postponed

2002-11-24 Thread Jeffrey Altman
loop = len; while(loop--) { *(p++) = foo++; foo += (17 + (unsigned char)(p 0xF)) } if(memchr(ptr, foo, len)) foo += 63; return(foo); } Jeffrey Altman * Volunteer Developer Kermit 95 2.1 GUI available now!!! The Kermit Project @ Columbia University SSH

Re: IMPORTANT: The release of 0.9.6h is postponed

2002-11-23 Thread Jeffrey Altman
[EMAIL PROTECTED] Jeffrey Altman * Volunteer Developer Kermit 95 2.1 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org/Secured with MIT Kerberos, SRP, and [EMAIL PROTECTED

Re: IMPORTANT: The release of 0.9.6h is postponed

2002-11-22 Thread Jeffrey Altman
. Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org/Secured with MIT Kerberos, SRP, and [EMAIL PROTECTED] OpenSSL

Re: IMPORTANT: The release of 0.9.6h is postponed

2002-11-22 Thread Jeffrey Altman
with the first two is that they do have significant performance impacts. The problem with the last is that we do not want to need to know the command line options for each and every compiler. Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit

Re: OpenSSL on WIN2K

2002-11-06 Thread Jeffrey Altman
the applications I know of that have export approval, which use OpenSSL, is in fact static linked to the OpenSSL library. It would be interesting to know if any US based application, which has export approval, does use the OpenSSL dll's. Ken Jeffrey Altman * Sr.Software Designer Kermit

RE: Question about auth with client certificates

2002-09-24 Thread Jeffrey Altman
to do the job. Thanks a lot for your help. Gastón Christen Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org/Secured with MIT Kerberos, SRP

RE: openssl Newbie ( PRNG seed )

2002-09-11 Thread Jeffrey Altman
There is no need to call RAND_screen() more than once. 0.9.4 is vulnerable to attacks because the random number generator is not seeded with sufficient entropy. 0.9.6e takes more time in order to generate the necessary entropy. Using a hardcoded seed value with make your connections

Re: [ANNOUNCE] OpenSSL 0.9.6g released

2002-08-11 Thread Jeffrey Altman
already have done it a long time ago (that's my guess at least...). This is correct. Simply shipping a binary with an implemented algorithm (even when not used) opens the distributor to patent infringement claims. Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now

Re: patches for security advisory of 30th July [URGENT]

2002-08-11 Thread Jeffrey Altman
port the resulting subsequent fixes yourself. Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org/Secured with MIT Kerberos, SRP, and [EMAIL

RE: [ANNOUNCE] OpenSSL 0.9.6g released

2002-08-09 Thread Jeffrey Altman
be suspicious of the quality and will simply wait to see how things shake out. --- Jeffrey Altman [EMAIL PROTECTED] wrote: At 09:40 AM 8/9/2002 -0400, Gregg Andrew writeth: OK so is version 0.9.6e that I just compiled with Apache-2.0.39 any good? It was my understanding that all known

Re: 0.9.7-beta3 : build problem on Win32 (FIXED ?)

2002-08-04 Thread Jeffrey Altman
of the win32 build maintenance to double-check this for me and update the build procedure before next beta or release. Thank you very much, Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http

Re: Web Browsers and SSL Support

2002-07-31 Thread Jeffrey Altman
such as C-Kermit 8.0 http://www.kermit-project.org/ckermit.html Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org/Secured with MIT Kerberos

Re: Web Browsers and SSL Support

2002-07-31 Thread Jeffrey Altman
. http://www.kermit-project.org/k95.html For web browsers I am unaware of a single one that supports FTP AUTH SSL. You could probably take the code that Peter Runestig wrote for the FTP clients that he supports on Unix and integrate it into Mozilla. Jeffrey Altman * Sr.Software Designer

RE: OpenSSL Security Altert - Remote Buffer Overflows

2002-07-30 Thread Jeffrey Altman
OpenSSL Security Advisory [30 July 2002] Does this affect Apache Web Servers? If they are compiled with OpenSSL support then 'yes'. Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP

Re: backwards connection

2002-07-29 Thread Jeffrey Altman
), ssl_verify_callback ); SSL_CTX_set_verify_depth( ctx, 4 ); SSL_CTX_set_options( ctx, SSL_OP_ALL ); ...bind to port... SSL_new() SSL_accept( ) /* returns 0 */ This should be SSL_connect(); Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available

Re: starting TLS Telnet server

2002-07-03 Thread Jeffrey Altman
files that Peter provides in his distribution. Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org/Secured with MIT Kerberos, SRP, and [EMAIL

Re: starting TLS Telnet server

2002-07-03 Thread Jeffrey Altman
.) and no one here has ever implemented SSL before and our Unix guy is across the country so unless if I want to wait 2 more weeks, I have to set the Linux box up myself. Thanks, Michael - Original Message - From: Jeffrey Altman [EMAIL PROTECTED] To: [EMAIL PROTECTED] Cc: [EMAIL

[no subject]

2002-07-01 Thread Jeffrey Altman
. See http://www.kermit-project.org/telnetd.html for a list of servers that support START_TLS Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet, Secure FTP, HTTP http://www.kermit-project.org

Re: (forgot to add subj. last time) SSL Telnet servers

2002-07-01 Thread Jeffrey Altman
. Mike - Original Message - From: Jeffrey Altman [EMAIL PROTECTED] To: [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Sent: Monday, July 01, 2002 11:57 AM I am new to the whole SSL thing and I want to set up an SSL Telnet = server (not SSH). Is there a package that does this or do

Re: Problem RAND_Status

2002-06-13 Thread Jeffrey Altman
__ OpenSSL Project http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI

RE: telnetd-ssl

2002-06-07 Thread Jeffrey Altman
://www.kermit-project.org/security.html -Mensaje original- De: Jeffrey Altman [mailto:[EMAIL PROTECTED]] Enviado el: jueves, 06 de junio de 2002 19:58 Para: [EMAIL PROTECTED] CC: [EMAIL PROTECTED] Asunto: Re: telnetd-ssl That depends on whose Telnetd you are using and how you want

Re: telnetd-ssl

2002-06-06 Thread Jeffrey Altman
linux ? S:-( =20 Zanx. =20 Manuel Guerrero Martos IN3 S.A.L. C/ Prim, 16 A - Bajo 12003 Castell=F3n 964723680 [EMAIL PROTECTED] www.in3.es =20 Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet

Re: telnetd-ssl

2002-06-06 Thread Jeffrey Altman
http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer Kermit 95 2.0 GUI available now!!! The Kermit Project @ Columbia University SSH, Secure Telnet

Re: Securing Telnet

2002-05-14 Thread Jeffrey Altman
http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer Kermit 95 1.1.21 available now!!! The Kermit Project @ Columbia University SSH plus Telnet

Re: Prevent apache from giving out server cert?

2002-04-18 Thread Jeffrey Altman
http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer Kermit 95 1.1.21 available now!!! The Kermit Project @ Columbia University SSH plus

Re: using X.509 certificates in Ckermit 8.0

2002-04-11 Thread Jeffrey Altman
/security.html SET AUTH TLS DSA-CERT-FILE SET AUTH TLS DSA-CERT-KEY SET AUTH TLS RSA-CERT-FILE SET AUTH TLS RSA-CERT-KEY Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 available now!!! The Kermit Project @ Columbia University includes Telnet, FTP and HTTP http://www.kermit

Re: Is OpenSSL Production Ready?

2002-04-06 Thread Jeffrey Altman
stated above. Best regards, Lutz There is an answer to this of course. It is do not link against OpenSSL but instead load the libraries and functions manually as OpenSSL does with the DSO interface. Then the two programs are separate with separate licenses. Jeffrey Altman

Re: Is OpenSSL Production Ready?

2002-04-06 Thread Jeffrey Altman
. This includes such things as CRL location not specified in certificate errors when CRL verification is turned on. There are any number of reasons why this message may be generated. - Jeff Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 available now!!! The Kermit Project @ Columbia

Re: FTP with SSL

2002-04-04 Thread Jeffrey Altman
http://www.kermit-project.org/ftpd.html for one list. Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 available now!!! The Kermit Project @ Columbia University includes Telnet, FTP and HTTP http://www.kermit-project.org/ secured with Kerberos, SRP, and [EMAIL

RE: OpenSSL 0.9.7-stable-SNAP-20020310

2002-03-12 Thread Jeffrey Altman
: the #ifdef / #endif is unnecessary and clutters the source. As of at least C90 #undef with a name that is not currently defined is ignored. See ISO 9899-1990 6.8.3.5. If only this were true. OpenSSL compiles with strict checking and all warnings are considered errors. Jeffrey Altman

Re: Help! SSL Telnet client-server deadlock problem.

2002-03-10 Thread Jeffrey Altman
technical reason why telnet+stunnel cannot work (at least to the extent of avoiding the client-server deadlock problem I observe)? Jeffrey Altman [EMAIL PROTECTED] Sent by: [EMAIL PROTECTED] 08/03/2002 23:19 Please respond to openssl-users To: [EMAIL PROTECTED

Re: Using SSL_clear to reuse SSL object

2002-02-26 Thread Jeffrey Altman
SSL_clear(ssl); SSL_set_session(ssl,NULL); SSL_set_accept_state(ssl); I believe I got this code from some very old ssleay applications. However, this has not worked with OpenSSL since at least 0.9.5. Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 available now!!! The Kermit

RE: RAND_poll hangs on WINNT 4.0

2002-02-22 Thread Jeffrey Altman
:-) /Stefan -Original Message- From: Jeffrey Altman [mailto:[EMAIL PROTECTED]] Sent: den 20 februari 2002 18:25 To: [EMAIL PROTECTED] Cc: '[EMAIL PROTECTED]' Subject: RE: RAND_poll hangs on WINNT 4.0 Stefan: This is helpful information. So the problem

Re: Win 2000 Services and SSL

2002-01-30 Thread Jeffrey Altman
] Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 available now!!! The Kermit Project @ Columbia University includes Telnet, FTP and HTTP http://www.kermit-project.org/ secured with Kerberos, SRP, and [EMAIL PROTECTED]OpenSSL. Interfaces with OpenSSH

RE: OpenSSL Key Generation GUI for Windows

2002-01-28 Thread Jeffrey Altman
; walking the memory allocation tables; reading screen data; and including data from the Windows crypto apis. Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 available now!!! The Kermit Project @ Columbia University includes Telnet, FTP and HTTP http://www.kermit-project.org

Re: Why DNS/IP in certificate?

2002-01-11 Thread Jeffrey Altman
within the certificate. And since the private key is needed for signing and decryption, is this not security enough for data transfer? /Jan Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 available now!!! The Kermit Project @ Columbia University includes Telnet, FTP and HTTP

RE: Problem with openssl.exe

2002-01-09 Thread Jeffrey Altman
it. -Original Message- From: Jeffrey Altman [mailto:[EMAIL PROTECTED]] Sent: mercredi 9 janvier 2002 06:13 To: [EMAIL PROTECTED] Cc: '[EMAIL PROTECTED]' Subject: Re: Problem with openssl.exe How does openssl.exe knows the SSLEAY environment variable under WNT4? When I type openssl, I

Re: RSA keys auth.

2002-01-06 Thread Jeffrey Altman
) __ OpenSSL Project http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 available now!!! The Kermit

Re: Echo is openssl

2001-12-12 Thread Jeffrey Altman
] __ OpenSSL Project http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 Beta available

Re: FTP over OpenSSL

2001-10-10 Thread Jeffrey Altman
__ OpenSSL Project http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software

Re: SSL for telnet

2001-09-10 Thread Jeffrey Altman
Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 Beta available The Kermit Project @ Columbia University includes Secure Telnet and FTP http://www.kermit-project.org/ using Kerberos, SRP, and [EMAIL PROTECTED] OpenSSL. SSH soon to follow

Re: telnet 993 asks for PEM passphrase

2001-08-23 Thread Jeffrey Altman
PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 Beta available The Kermit Project @ Columbia University includes Secure Telnet and FTP http://www.kermit-project.org/ using Kerberos, SRP

Re: SSL vs SSH

2001-08-13 Thread Jeffrey Altman
All, From a client application perspective, is SSL/TLS the same as SSH. If = not then what is the difference? Cheers Mike They are completely different and incompatible protocols. Jeffrey Altman * Sr.Software Designer C-Kermit 8.0 Beta available The Kermit Project @ Columbia

Re: Feature or bug in 96b ?

2001-08-07 Thread Jeffrey Altman
Did you recompile your application for 0.9.6b? 0.9.5a is not binary compatible with the newer release. Hello openssl-users, I use openssl pretty long time, but only in simple mode. Recently , installed version 96b (major release) and found that my application become to crash. I checked it

Re: FTP over SSH2

2001-07-25 Thread Jeffrey Altman
] __ OpenSSL Project http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer C-Kermit 8.0

RE: Weakness in Openssl PRNG

2001-07-13 Thread Jeffrey Altman
. In that case porting the crypto/rand directory should be fine. But check the announcement, it has details of what needs to be changed if you are doing a partial port. Another question I had Is openssl PRNG ANSI X9.17 compatible ?. I have no idea. Jeffrey Altman * Sr.Software Designer C-Kermit 7.1

Re: Browser Support for TLS/HTTP Upgrade?

2000-12-20 Thread Jeffrey Altman
in HTTP do so by using the TLS Kerberos cipher suites. Jeffrey Altman * Sr.Software Designer C-Kermit 7.1 Alpha available The Kermit Project @ Columbia University includes Secure Telnet and FTP http://www.kermit-project.org/ using Kerberos, SRP, and [EMAIL PROTECTED

Re: Kurt Seifred's article on securityportal

2000-12-19 Thread Jeffrey Altman
ol problem. This is a user training issue. There is only so much that software can do. Jeffrey Altman * Sr.Software Designer C-Kermit 7.1 Alpha available The Kermit Project @ Columbia University includes Secure Telnet and FTP http://www.kermit-project.org/ using Ker

Re: Kurt Seifred's article on securityportal

2000-12-19 Thread Jeffrey Altman
. Again, not an SSL problem since SSL does not require the use of PKI ciphers. Feel free to use a non-PKI cipher in your SSL implementation. This is a problem with the implementations found in Netscape and Microsoft browsers. Jeffrey Altman * Sr.Software Designer C-Kermit 7.1 Alpha available

Re: Sending data on a socket before SSL_Accept

2000-11-19 Thread Jeffrey Altman
. You absolutely should not use the contents of the plaintext data to determine if you should negotiate SSL/TLS. Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University 612 West 115th St * New York, NY * 10025 * USA http

Re: There will be a third beta...

2000-09-20 Thread Jeffrey Altman
that flag is static. Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University 612 West 115th St * New York, NY * 10025 * USA http://www.kermit-project.org/ * [EMAIL PROTECTED

Re: There will be a third beta...

2000-09-20 Thread Jeffrey Altman
so frequently with an 'add_entropy' value of 0 in RAND_poll()? I would assume the 'add_entropy' value is supposed to indictate the relative strength of the entropy being passed in, but I doubt that it should be 0.8 in most cases. Jeffrey Altman * Sr.Software Designer

RE: Apps over SSL

2000-09-20 Thread Jeffrey Altman
Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University 612 West 115th St * New York, NY * 10025 * USA http://www.kermit-project.org/ * [EMAIL PROTECTED

Re: OpenSSL version 0.9.6 Beta 2 (problems with Win 98)

2000-09-18 Thread Jeffrey Altman
Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University 612 West 115th St * New York, NY * 10025 * USA http://www.kermit-project.org/ * [EMAIL PROTECTED

Re: Problem compiling openssl engine beta2 on NT

2000-09-18 Thread Jeffrey Altman
http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University

Re: Import Export Restrictions

2000-09-14 Thread Jeffrey Altman
es could tell us. Protocols are not considered "retail", "mass market", or otherwise. Only applications can be considered "retail", "mass market", ... Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia Un

Re: windows client needed

2000-09-13 Thread Jeffrey Altman
://www.kermit-project.org/k95.html Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University 612 West 115th St * New York, NY * 10025 * USA http://www.kermit-project.org/ * [EMAIL PROTECTED

Re: Windows 2000

2000-09-13 Thread Jeffrey Altman
. Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University 612 West 115th St * New York, NY * 10025 * USA http://www.kermit-project.org/ * [EMAIL PROTECTED] __ OpenSSL Project

Re: Serious Bug in ssl3_get_record

2000-09-13 Thread Jeffrey Altman
PROTECTED] __ OpenSSL Project http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * S

RE: client certificate

2000-08-22 Thread Jeffrey Altman
in the middle. If the proxy is on a Trusted OS, that is great. But it doesn't change the security model one bit. The proxy should not be interfering with the end to end properties of SSL. Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia

RE: client certificate

2000-08-21 Thread Jeffrey Altman
[EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University 612 West 115th St * New York, NY * 10025 * USA http://www.kermit-project.org

Re: transport layer question

2000-08-11 Thread Jeffrey Altman
for this. alas, I don't know if OpenSSL works on top of other protocols, but it shoukd: you might want to use BIO's to fake 'normal' sockets. Jeffrey Altman * Sr.Software Designer The Kermit Project * Columbia University 612 West 115th St * New

Re: Legality - just heated up

2000-06-28 Thread Jeffrey Altman
http://www.openssl.org User Support Mailing List[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer * Kermit-95 for Win32 and OS/2 The Kermit Project

RE: FTP SSL

2000-06-16 Thread Jeffrey Altman
[EMAIL PROTECTED] Automated List Manager [EMAIL PROTECTED] Jeffrey Altman * Sr.Software Designer * Kermit-95 for Win32 and OS/2 The Kermit Project * Columbia University 612 West 115th St #716 * New York, NY * 10025

Re: FTP SSL

2000-06-16 Thread Jeffrey Altman
of patches implementing the current FTP over TLS Internet-Draft at ftp://ftp.runestig.com/ Jeffrey Altman * Sr.Software Designer * Kermit-95 for Win32 and OS/2 The Kermit Project * Columbia University 612 West 115th St #716 * New York, NY * 10025 http

  1   2   >