Unfortunately, I built with "openssl-0.9.6-stable-SNAP-20030324.tar.gz" and am now 
again seeing the intermittant problem of the dropping GIFs that I wrote about on 
3/21/2003.  My statements about the problem being gone in the "Stable 323" build were 
true if the "engine" snapshot was used (i.e., when 
"openssl-e-0.9.6-stable-SNAP-20030323.tar.gz" was used).  However, I believe that was 
because the 'engine' build did not pick up these latest timing fixes (I know that the 
Stable 323 engine build did NOT contain the "Klima-Pokorny-Rosa attack" patch whereas 
the non-engine Stable 323 build did).

The "openssl-0.9.6-stable-SNAP-20030324.tar.gz" does indeed contain the fixes for the 
RSA Blinding and Klima-Pokorny-Rosa Security Advisories, but unfortunately it also 
results in the "dropped GIF" problems.  I will dig in deeper tomorrow to see if I can 
see any server side OpenSSL error messages...

--- Pete Bobco ---


-----Original Message-----
From: Richard Levitte - VMS Whacker [mailto:[EMAIL PROTECTED]
Sent: Monday, March 24, 2003 2:21 PM
To: [EMAIL PROTECTED]; Bobco, Pete
Subject: Re: [openssl.org #541] Problem with the blinding patch 


In message <[EMAIL PROTECTED]> on Mon, 24 Mar 2003 13:24:08 -0600, "Bobco, Pete" 
<[EMAIL PROTECTED]> said:

Pete.Bobco> I am VERY interested in building with an official release
Pete.Bobco> and would greatly appreciate any info regarding when
Pete.Bobco> OpenSSL.org thinks it might release an official 0.9.6j.

We will release 0.9.6j as soon as possible.  There are a couple of
related bug reports to take care of first.

-- 
Richard Levitte   \ Spannv�gen 38, II \ [EMAIL PROTECTED]
[EMAIL PROTECTED]  \ S-168 35  BROMMA  \ T: +46-8-26 52 47
                    \      SWEDEN       \ or +46-708-26 53 44
Procurator Odiosus Ex Infernis                -- [EMAIL PROTECTED]
Member of the OpenSSL development team: http://www.openssl.org/

Unsolicited commercial email is subject to an archival fee of $400.
See <http://www.stacken.kth.se/~levitte/mail/> for more info.

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to