Attention is currently required from: flichtenheld.

plaisthos has posted comments on this change. ( 
http://gerrit.openvpn.net/c/openvpn/+/457?usp=email )

Change subject: Implement generating TLS 1.0 PRF using new OpenSSL 3.0 APIs
......................................................................


Patch Set 5:

(3 comments)

Commit Message:

http://gerrit.openvpn.net/c/openvpn/+/457/comment/ae29b807_47365dcf :
PS5, Line 13: using OpenSSL 3.0, it gives the same error as with the older API 
but
> missing "in FIPS mode"? My understanding is that this still works with 
> "normal" OpenSSL 3?
Done


Patchset:

PS5:
> I have my doubts whether this change is worth it if it doesn't actually fixes 
> anything? […]
One advantage is that we at least are now compatible with compiling against an 
OpenSSL that has been compiled with OPENSSL_NO_MD5. Otherwise we fail at the 
EVP_md5_sha1 function call.


File src/openvpn/crypto_openssl.c:

http://gerrit.openvpn.net/c/openvpn/+/457/comment/fd9542a8_f818ca77 :
PS5, Line 1404:                                                   secret, 
(size_t) secret_len);
> ../../../src/openvpn/crypto_openssl. […]
Done



--
To view, visit http://gerrit.openvpn.net/c/openvpn/+/457?usp=email
To unsubscribe, or for help writing mail filters, visit 
http://gerrit.openvpn.net/settings

Gerrit-Project: openvpn
Gerrit-Branch: master
Gerrit-Change-Id: Ic74195a4ed340547c5e862dc2438f95be318c286
Gerrit-Change-Number: 457
Gerrit-PatchSet: 5
Gerrit-Owner: plaisthos <arne-open...@rfc2549.org>
Gerrit-Reviewer: flichtenheld <fr...@lichtenheld.com>
Gerrit-CC: openvpn-devel <openvpn-devel@lists.sourceforge.net>
Gerrit-Attention: flichtenheld <fr...@lichtenheld.com>
Gerrit-Comment-Date: Wed, 29 Nov 2023 12:15:50 +0000
Gerrit-HasComments: Yes
Gerrit-Has-Labels: No
Comment-In-Reply-To: flichtenheld <fr...@lichtenheld.com>
Gerrit-MessageType: comment
_______________________________________________
Openvpn-devel mailing list
Openvpn-devel@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/openvpn-devel

Reply via email to