vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
Mailing Listopenssl-users@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http
the one seem lagging behind now (as MSVC up
to and including 2008 isn't C99 compliant; I don't know about 2010 as I
haven't used that one yet).
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http
majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
Steve et al can apply my diffs without hickups, contrary to the last couple
of times.)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11
pair for testing
purposes (or you might have received directions how to roll your own keypair
in a way 100% compatible with theirs).
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http
-users@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile
regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
or copying of this communication is strictly prohibited. If you
have received this communication in error, please notify the sender
immediately by telephone and with a 'reply' message. Thank you for your
co-operation.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
dll.
Therefor, I am wondering if I run into problems it I build it as one DLL.
@ David Kirkby: I removed my phone number just in this case, and not by
accident ;)
Rob Deckers
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web
vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
at 9:13 PM, Jake Goulding gould...@vivisimo.com wrote:
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
content or some such
nastiness.]
It's not ideal, but it at least helps cover your tracks when you cut out the
offending source in OpenSSL itself.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com
__
OpenSSL Project http://www.openssl.org
User Support Mailing Listopenssl-users@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger
regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
faster
than mutexes.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
OCSP_RESPID_free() is defined?
Thanks
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
in the
ml archives should turn up a reference. I haven't looked at his work, but I
have seen other folks using his product. Don't know whether it comes with
project files like you'd expect, but I expect it does.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
, but it works
pretty well with my implementation of an FTP server.
regards,
Maik,
the modem-man
B.T.W.: what is preferred diff format here? I used diff -bw -u. Okay?
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http
http://www.openssl.org
User Support Mailing List openssl-us...@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
, but that's not something
that's within my capabilities or time limits right now.
For both parts, see above. (What's bad for one should not disappear
for everyone + analog audio noise)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web
no other
way, no need to add to that collection. ;-)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
must have missed that newsflash on
my MTV. ;-) )
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
is inside them:
your callbacks have to provide for that.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
'debug builds' like that to the sites that sometimes
exhibit the issue. Did you put assertions in your code to verify
run-time assumptions?)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http
,
I recompile ntdll with /MT swith and yes, output dlls now
little bigger:
libeay32.dll: 1 036 288 - 1 122 304
ssleay32.dll: 212 992 - 274 432
Looks like something linked...
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web
groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
List openssl-us...@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net
right.
How long should I keep my foot in my mouth this time? I can't
guarantee you I'll learn from the experience but at least it will be
one less unintelligent input for the duration.
Hm, now I should go and see how I can redeem myself... ...
--
Met vriendelijke groeten / Best regards,
Ger
where you can say things like
'literal:mykey' or 'file:keyfile' to the same command option is a nice
idea to have throughout. Hm, maybe a patch for that can appease my
lordship(s) ;-)
Sticking foot back in...
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
__
OpenSSL Project http://www.openssl.org
User Support Mailing List openssl-us...@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
in there.
Take care,
Ger
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
:
WSAEWOULDBLOCK
My question is why _using the same code_ Windows is returning WSAEWOULDBLOCK
instead of WSAECONNREFUSED when my server is down? while UNIX correctly
returns ECONNREFUSED...
Thanks
On Sun, Aug 23, 2009 at 5:04 PM, Ger Hobbelt g...@hobbelt.com wrote:
Since you use a nonblocking
are stored somewhat like sprintf(%f,
float_value) string output, just with the ASN.1 REAL type id before
it. (I haven't run into BER floats out there in the wild up to now,
btw.)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http
using application level protocol, such as in the case of
https:// based forums, where you log into a forum using
user+passphrase); /authorization/ is always handled in an overlay
(application layer), as SSL cannot not do this for you.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
2009/5/29 jazeltq jaze...@163.com:
在2009-05-28,Victor Duchovni victor.ducho...@morganstanley.com 写道:
On Thu, May 28, 2009 at 11:51:42AM +0200, Ger Hobbelt wrote:
Only if the data is text. Using strlen() on binary data is another
classic/basic 'C' programming mistake.
if it is binary data, what
://www.openssl.org
User Support Mailing List openssl-us...@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com
openSSL
produces it's libraries and the caveats regarding msvc and external
library usage.)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6
by the
receiving end node).
HTH
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
not happen due to any tricks with the
former. The only thing the attacker will 'gain' is temporal disability
to communicate. temporal = as long as the attacker is active in any
way.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web
majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
to
determine what part of the OpenSSL you wish to use in order to reduce
the amount of work.
I don't know of a readily-available solution for this (and haven't looked now).
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http
vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
in this is that everyone 'just assumes' everybody else
knows this and has their kit set up right. One of the unmentionable
trade secrets of software developers, I guess.)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com
vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
--- /home/ger/prj/1original/openssl
request to be plonked. (google = education)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
On Thu, Apr 9, 2009 at 2:42 PM, Ger Hobbelt g...@hobbelt.com wrote:
That last line what ADDED to Configure. Save, then invoke ./Configure
with any extras you want, specifying your freshly created debug
target, for example:
./Configure linux-x86_64
should read here (as it does further down
Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
though both
SSL_load_error_strings() and ERR_load_crypto_strings() have been called.
I'm stuck on this and any help would be greatly appreciated.
Thanks
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com
be generated using a
(secure) PRNG, such as RAND, included in OpenSSL.)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
was, and if it's not quite
as reusable as I am thinking about, is there a generic library available?
I've tried using asn1c, but this code seems to break when I feed it valid
BER...
Thanks!
Randy
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
.
--
--
José Hidalgo C.
Ingeniero de Software
Akzio Consultores - http://www.akzio.cl
Huérfanos 669 of. 609 - Santiago
Ofi:(+56)(2)6320567 - Cel:(+56)(9)88377088
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
outside the published code, i.e. check your context.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11
this longer
text has no mistakes lurking in it and explains sufficiently what is
important.)
Prodding at festering spots in the text is appreciated.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com
):
/*
saltlen == EVP_MD_CTX_FLAG_PSS_MDLEN ~ -1
saltlen == EVP_MD_CTX_FLAG_PSS_MREC ~ -2
*/
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
Macapuna
www.macapuna.com.br
macap...@{macapuna.com.br, dca.fee.unicamp.br}
Linux for human beings
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
, and thanks for the reply,
You're welcome!
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
),
and bioMem shows the correct number of bytes written in num_write.
Good catch - many thanks!
n8
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
of the core development team (or myself) as I'm sure
you'll find the tariffs very reasonable.
Always glad to help out a fellow software physician.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com
groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
OpenSSLDie().
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
http://www.openssl.org
User Support Mailing Listopenssl-users@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
right. Since you don't need anything more than just that, I think
that indeed is the smarter move now.
Good luck!
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g
concatenation'
a.k.a. ## (plus students reading language (grammar) specifications
instead of having to stumble forward by trial error as they receive
'practice-oriented' ed).
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http
and I'm sure they'll get answered,
time, knowledge and energy permitting.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
with
the others. I use it for all things crypto overhere.)
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
(Later on I redid a small part of this for my own purposes, where I
was (ahem) 'cross-compiling' from a Win32 host platform to embedded
i86. That code is not useful here
.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
);
BIO_write( b64, input, length);
BIO_flush( b64 );
BIO_get_mem_ptr( b64, bptr );
buff = malloc(bptr-length);
memcpy(buff, bptr-data, bptr-length);
buff[bptr-length-1]=0;
BIO_free_all(b64);
return buff;
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
://www.openssl.org
User Support Mailing Listopenssl-users@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com
.html
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
by this email.
www.wipro.com
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
, 2009 at 2:07 PM, Ajeet kumar.S
ajeetkuma...@jasmin-infotech.com wrote:
Dear Ger Hobbelt,
Thank you for your help and Time.
I want to validate only the signature of the server certificate.
For example in peer verification, ssl will check time of client
system(6:28PM 23 Jan 2009) to Ca root
to the network or disk.
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
be causing the shared cipher error?
Any help is appreciated.
-Dan
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
Hobbelt g...@hobbelt.com wrote:
Nothing glaring, except of course that this error is [almost] always
caused by the absence of a call to
OpenSSL_add_all_algorithms();
which is used to set up SSL with all the available ciphers, hashes, etc.
--
Met vriendelijke groeten / Best regards,
Ger
don't have key renegotiation
options in the protocol, how do you come by a key set to start with?
I call the above a 'hack' because you are basically looking at
reimplementing TCP. (Plus IPFIX, but that's just too obvious, right?
;-) )
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
--
#include stdio.h
#include openssl/err.h
#include openssl/bio.h
http://www.openssl.org
User Support Mailing Listopenssl-users@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http
pieces may have been disabled
(removed) at compile time: as they won't exist in the code, they will
not show up in the cipher/digest/... list.
But that would be far easier to diagnose indeed, when you list the
ciphers as you suggested yourself.
--
Met vriendelijke groeten / Best regards,
Ger
openssl-users@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g
groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
http://www.openssl.org
User Support Mailing Listopenssl-users@openssl.org
Automated List Manager majord...@openssl.org
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http
vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6-11 120 978
are talking to you RIGHT NOW? The one you are talking to, presents
itself as 'Ger Hobbelt', but how can you be sure? SSL only helps you
answer that question PARTLY. Wat is does not, and CANNOT answer is
this bit: It could be meat-me on machine A, but I could have a visitor
on machine C, who injected remote
Bastard
sitting in your (untrusted) box. For this occassion. ;-)
Did this help you?
--
Met vriendelijke groeten / Best regards,
Ger Hobbelt
--
web:http://www.hobbelt.com/
http://www.hebbut.net/
mail: g...@hobbelt.com
mobile: +31-6
1 - 100 of 164 matches
Mail list logo