Re: [openssl-dev] OpenSSL Security Advisory

2016-03-01 Thread Nounou Dadoun
Thanks for the test tool and making it available so quickly, we were able to close our DROWN bug ticket less than an hour after opening it! I'm interested in your tlsfuzzer tool (of which this appears to be a part), is there a larger test suite available? Is there any documentation out there?

Re: [openssl-dev] Failed TLSv1.2 handshake with error 67702888--bad signature

2016-02-26 Thread Nounou Dadoun
On Behalf Of Nounou Dadoun Sent: Friday, February 26, 2016 9:34 AM To: openssl-dev@openssl.org Subject: [openssl-dev] Failed TLSv1.2 handshake with error 67702888--bad signature Trying to upgrade from TLSv1 to TLSv1.1 and 1.2 has been more problematic than I might have suspected. I have a TLS se

[openssl-dev] Failed TLSv1.2 handshake with error 67702888--bad signature

2016-02-26 Thread Nounou Dadoun
On Behalf Of Nounou Dadoun Sent: Thursday, February 25, 2016 5:44 PM To: openssl-us...@openssl.org Subject: Re: [openssl-users] Failed TLSv1.2 handshake with error 67702888--bad signature Curiouser and curiouser - I have attached two minimal packet captures in which the only difference in the se

Re: [openssl-dev] Cannot verify self-signed certificates?

2015-12-15 Thread Nounou Dadoun
I have actually asked a variant on this question in the path, I would rephrase it as I have a certificate chain which doesn't go all the way back to a self-signed cert. But I "trust" the highest certificate in the chain that I have; is there a way of telling openssl that once it hits this