Re: [openssl.org #3322] [PATCH] ccgost to use configured params for 28147-89 in CNT and IMIT mode

2014-04-22 Thread Dmitry Belyavsky
Hello Andrey, Thank you for your work, but I do not see the patch :-( I should say that in practice the CNT mode is used in TLS where usage of the Gost28147_CryptoProParamSetA is required. On Mon, Apr 21, 2014 at 7:40 PM, Andrey Kulikov via RT r...@openssl.orgwrote: Currently ccgost engine

Re: [openssl.org #3316] Wrong trust chain with new version of openssl

2014-04-22 Thread Tom Francis
It’s a lack of features in Apple’s code, and it’s very well-known among Apple developers. Search Apple’s developer forums (both iOS MacOS) as well as their public bug database (IIRC, you have to be a registered Apple developer to search those). Apple’s not going to change it, though, as the

Re: [openssl.org #3322] [PATCH] ccgost to use configured params for 28147-89 in CNT and IMIT mode

2014-04-22 Thread Andrey Kulikov via RT
Dmitriy, Thanks for noticing! I do not see it either - correcting myself. :-) You are right - according to http://tools.ietf.org/html/draft-chudov-cryptopro-cptls-04 CryptoProParamSetA is required in GOST TLS. But only for content encryption. Premaster secret encryption could use any other