Free StartSSL certificate not trusted

2014-04-16 Thread ankbhdk
Hi all, I have installed an ubuntu server with dovecot and a free certificate from startssl, but I get: verify error:num=20:unable to get local issuer certificate and verify error:num=21:unable to verify the first certificate Any idea why? Tanks in advance, Allan My dovecot conf: ---

Free StartSSL certificate not trusted

2014-04-16 Thread Allan Nielsen
Hi all, I have installed an ubuntu server with dovecot and a free certificate from startssl, but I get: verify error:num=20:unable to get local issuer certificate and verify error:num=21:unable to verify the first certificate Any idea why? Tanks in advance, Allan My dovecot conf: ---

RE: SSL_ERROR_SYSCALL errno=0

2014-04-16 Thread hhachem
Thanks for the reply. I'll give the suggestions a try tomorrow. We've been thinking, that our kernel version (it is custom and does not support all system calls) is relatively old and missing some features that are required by OpenSSL. I'll post back tomorrow, if anything changes. Note: I've

Re: Help me for ECDHE algorithm

2014-04-16 Thread chetan
If this is only ECDH than how to perform ECDHE? what changes i have to made in this code? -- View this message in context: http://openssl.6102.n7.nabble.com/Help-me-for-ECDHE-algorithm-tp49168p49499.html Sent from the OpenSSL - User mailing list archive at Nabble.com.

Aw: Re: Re: Converting a root certificate from md5 to sha1

2014-04-16 Thread steffo76
Okay, thanks for all the information, here's what I did and what will go into testing: -Recreated a CSR from the root CA cert using openssl x509 -x509toreq -in cacert.crt -signkey cakey.key -sha1 -out newcert.csr Set the system date back to the startday of the old root cert Recreated the CA

RE: Free StartSSL certificate not trusted

2014-04-16 Thread Eisenacher, Patrick
-Original Message- From Allan Nielsen I have installed an ubuntu server with dovecot and a free certificate from startssl, but I get: verify error:num=20:unable to get local issuer certificate and verify error:num=21:unable to verify the first certificate Any idea why?

Getting bad record mac error

2014-04-16 Thread hiteshk
I have an application which was using openssl-0.9.8y. Now I have built fips enabled openssl1.0.1g and want to use the latest version that I have built for Linux x64. My application uses SslOpConnect. It works fine with 0.9.8y and when I use the new version I get SSL connection error (decryption

Re: Free StartSSL certificate not trusted

2014-04-16 Thread Allan Nielsen
Thanks you are right. I got it to work now adding the ca_bundle to it. BR. Allan 2014-04-16 10:28 GMT+02:00 Eisenacher, Patrick patrick.eisenac...@bdr.de: -Original Message- From Allan Nielsen I have installed an ubuntu server with dovecot and a free certificate from

Coverity Scan: Would/DId It Catch the Heartbleed Defect?

2014-04-16 Thread Tom Browder
Is OpenSSL participating in the Coverity free scanning program for open source software? If not, it might have caught the Heartbleed bug. If so, why did it miss it? See this link for the latest report on open source statistics:

Re: Coverity Scan: Would/DId It Catch the Heartbleed Defect?

2014-04-16 Thread Hanno Böck
On Wed, 16 Apr 2014 05:25:58 -0500 Tom Browder tom.brow...@gmail.com wrote: Is OpenSSL participating in the Coverity free scanning program for open source software? Don't know. If not, it might have caught the Heartbleed bug. No. http://blog.regehr.org/archives/1128 -- Hanno Böck

Re: Coverity Scan: Would/DId It Catch the Heartbleed Defect?

2014-04-16 Thread Tom Browder
On Wed, Apr 16, 2014 at 5:38 AM, Hanno Böck ha...@hboeck.de wrote: On Wed, 16 Apr 2014 05:25:58 -0500 Tom Browder tom.brow...@gmail.com wrote: Is OpenSSL participating in the Coverity free scanning program for open source software? ... Thanks for the link, Hanno! Regards, -Tom

Re: Help me for ECDHE algorithm

2014-04-16 Thread Matt Caswell
On 16 April 2014 05:48, chetan chet...@neominds.in wrote: If this is only ECDH than how to perform ECDHE? what changes i have to made in this code? Well the final E in ECHDE stands for ephemeral. It is not really a difference in the way the algorithm itself works, but more about how it is used.

1.0.1g Install warns: cms.pod (Error since May 1, 2013)

2014-04-16 Thread Iiiears Iiiears
I will try to leave a note with the developers at OpenSSL.org Used openssl-1.0.1g.tar.gz SHA1 b28b3bcb1dc3ee7b55024c9f795be60eb3183e3c several errors cms.pod around line 457: Expected text after =item, not a number cms.pod around line 461: Expected text after =item, not a number cms.pod around