I don't have time to write for you a new entropy source to replace the heap walking.
I've patched my local rand_win.c to time-limit the inner loop in the same manner as the outer, and do not plan to spend any more time on this issue. James P.S. I am surprised that no one else uses OpenSSL on Windows enough to notice this bug? The test code attached to this ticket performs the same on every physical/VM Win7 box I can get my hands on. I went and searched for responses, the only thing I found was this response to the dev list, which I am not on: -----Original Message----- James Baker via RT wrote: [SNIP] James, you post is interesting to me but I would like to ask you to post unified diff format with changes (please search internet for "unified diff"). It you environment is limited please use some public available/free sites for code review. ROumen ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [email protected] ______________________________________________________________________ OpenSSL Project http://www.openssl.org Development Mailing List [email protected] Automated List Manager [email protected]
