[openssl.org #2828] TLS 1.1 and 1.2 client - invalid Client Hello during renegotiation

2012-06-03 Thread Marsh Ray via RT
Greetings, The Tor project has uncovered an issue with the new support for TLS 1.1 and 1.2 in OpenSSL 1.0.1. It is reproducible with the s_client utility. There does not appear to be any obvious security impact, but it does represent a failure to interoperate. The bug relates to the

[openssl.org #2829] OpenSSL port in FreeBSD: DTLS networking problem

2012-06-03 Thread Oleg Moskalenko via RT
Hi Formal bug description: OpenSSL version: all versions with DTLS support. OS name: FreeBSD 7.x, 8.x, 9.x Compiler: any Application: any DTLS application Problem description: The DTLS packets do not have Don't fragment IP flag set (DF bit). According to DTLS specs, it must always be set. In

[openssl.org #2828] TLS 1.1 and 1.2 client - invalid Client Hello during renegotiation

2012-06-03 Thread Stephen Henson via RT
[ma...@extendedsubset.com - Mon Jun 04 00:23:30 2012]: Greetings, The Tor project has uncovered an issue with the new support for TLS 1.1 and 1.2 in OpenSSL 1.0.1. It is reproducible with the s_client utility. There does not appear to be any obvious security impact, but it does