> Maybe just a co-incidence, but the sect571r1 curve is the only binary curve
> in your list- the others are all prime curves. Maybe it doesn't like binary 
> curves?

Yes, if any binary curve (sect571r1, sect571k1, sect409k1, sect409r1, 
sect283k1, sect283r1, sect239k1, sect233k1, sect233r1, sect193r1, sect193r2,  
sect163k1, sect163r1, sect163r2) comes before a prime curve in the list it 
results in failure.

> Just realised that in your original post you said you were using the fips 
> build of openssl.

Yes, but ruled out FIPS as the problem early on. Much of the s_client testing 
has been with non-fips 1.0.1e and 1.0.2 I've built myself.

-Andrew

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [email protected]
Automated List Manager                           [email protected]

Reply via email to