> Maybe just a co-incidence, but the sect571r1 curve is the only binary curve > in your list- the others are all prime curves. Maybe it doesn't like binary > curves?
Yes, if any binary curve (sect571r1, sect571k1, sect409k1, sect409r1, sect283k1, sect283r1, sect239k1, sect233k1, sect233r1, sect193r1, sect193r2, sect163k1, sect163r1, sect163r2) comes before a prime curve in the list it results in failure. > Just realised that in your original post you said you were using the fips > build of openssl. Yes, but ruled out FIPS as the problem early on. Much of the s_client testing has been with non-fips 1.0.1e and 1.0.2 I've built myself. -Andrew ______________________________________________________________________ OpenSSL Project http://www.openssl.org User Support Mailing List [email protected] Automated List Manager [email protected]
