Re: [libgadu-devel] How to Report a Security Bug in libgadu

2013-06-12 Thread Radhesh Krishnan K
Hi Bartosz, I was wondering if there is any update on this ? On Fri, Jun 7, 2013 at 12:24 PM, Radhesh Krishnan K < radheshkrishn...@gmail.com> wrote: > Hi Bartosz, > > Adding Equifax Secure CA one to the list of trusted CA's sounds like a > good idea to me. > > > > On Fri, Jun 7, 2013 at 5:25

Re: [libgadu-devel] How to Report a Security Bug in libgadu

2013-06-12 Thread Wojtek Kaniewski
Dnia 2013-06-12, śro o godzinie 12:42 +0530, Radhesh Krishnan K pisze: > I was wondering if there is any update on this ? I commited the verification code for OpenSSL version. As Bartosz wrote the code for GnuTLS will be more complicated, so it may take some time. Regards, Wojtek _

Re: [libgadu-devel] How to Report a Security Bug in libgadu

2013-06-12 Thread Bartosz Brachaczek
2013/6/12 Wojtek Kaniewski : > As Bartosz wrote > the code for GnuTLS will be more complicated, so it may take some time. Do you have any plan for it? I have performed some research and the options seem to be to: 1) Have a build-time option to explicitly specify a CA trust store file to use, and

Re: [libgadu-devel] How to Report a Security Bug in libgadu

2013-06-12 Thread Radhesh Krishnan K
I think first option is better than the second one as it covers both possibilities. It gives the user an option to specify a CA trust store file to use and if not mentioned we can use the default. On Thu, Jun 13, 2013 at 4:08 AM, Bartosz Brachaczek wrote: > 2013/6/12 Wojtek Kaniewski : > > As Ba