[openssl.org #2570] Timing related bug in openssl pkcs

2014-09-09 Thread Rich Salz via RT
sorry, you can't use stdin twice. we have no control over system buffering, among other things. closing file. -- Rich Salz, OpenSSL dev team; rs...@openssl.org __ OpenSSL Project

[openssl.org #2570] Timing related bug in openssl pkcs

2011-07-23 Thread Ron Garret via RT
I have found a reliably reproducible timing-related bug in openssl pkcs when both the key to be processed and the passphrase to use in encryption are passed through stdin. The problem can be reliably reproduced thusly: [ron@mighty:~]$ cat foo password -BEGIN RSA PRIVATE KEY-