[openssl.org #2616] Missing initialization in the CHIL engine

2011-09-27 Thread Tomas Mraz via RT
There is a missing initialization of a variable in the CHIL engine. In case the uninitialized value of the variable answer is 'C' and there is no prompt, the engine startup will erroneously fail. The attached patch fixes this. -- Tomas Mraz No matter how far down the wrong road you've gone, turn

RE: [openssl.org #2594] Problem with X509 path loop detection - PATCH

2011-09-27 Thread Nick Lewis via RT
With update version i confirm that regression test of a software now pass with OpenSSL HEAD version. I still have problem with HEAD regarding check if is for self signed. This case is not in openssl regression tests ans cannot be reproduced with openssl command line. Case is when callback

Re: openssl 1.0.1 and rumors about TLS 1.0 attacks

2011-09-27 Thread Hanno Böck
To sum up what I've learned until now: - There are workarounds that openssl implements, but major applications (including apache) disable them, so they're mostly worthless - All workarounds on AES-CBC have problems, chrome and firefox discuss how to handle it, the only real fix is TLS 1.1/1.2

Re: [openssl.org #2343] Resolved: randfile.c compilation failure on OpenBSD

2011-09-27 Thread Ingo Schwarze via RT
on OpenBSD -current with ftp://ftp.openssl.org/snapshot/openssl-SNAP-20110927.tar.gz Yours, Ingo __ OpenSSL Project http://www.openssl.org Development Mailing List openssl