Re: [openssl-users] Call for testing TLS 1.3

2018-05-28 Thread Jouni Malinen
g similar or face possibility of breaking functionality if OpenSSL 1.1.1 does go out with TLS 1.3 enabled by default and both ends of the EAP connection have TLS 1.3 enabled. -- Jouni MalinenPGP id EFC895FA -- openssl-users mailing list To unsubscri

Re: Anyone implementing RFC 7030: Enrollment over Secure Transport (EST)?

2014-03-20 Thread Jouni Malinen
On Wed, Mar 12, 2014 at 7:10 PM, David von Oheimb david.von.ohe...@siemens.com wrote: is anyone out there developing or planning an implementation of EST (Enrollment over Secure Transport) in C/C++, making use of OpenSSL? There's one implementation here:

Re: Obtaining a TLS session key

2013-02-08 Thread Jouni Malinen
On Fri, Feb 8, 2013 at 12:11 AM, T J jordan.tre...@gmail.com wrote: TLS keying material exporter, i.e., SSL_export_keying_material(), will make your life much easier if you are just looking for a mechanism to derive suitable keys for other uses assuming you are using recent enough OpenSSL.

Re: Obtaining a TLS session key

2013-02-07 Thread Jouni Malinen
On Thu, Feb 7, 2013 at 9:00 AM, Trevor Jordan jordan.tre...@gmail.com wrote: From what I understand so far, the KeyBlock is the place to look for the key? It's just a matter of getting the sizes and order of the individual Keys and IV's so that I can extract the bits I need. Any pointers in

Key block size for key derivation

2012-08-17 Thread Jouni Malinen
not look exactly clean.. Is there a better way to figure out the MAC secret size (or even better, full key block size) with OpenSSL? -- Jouni MalinenPGP id EFC895FA __ OpenSSL Project

Re: Assertion failure (FIPS mode with wpa_supplicant)

2009-08-16 Thread Jouni Malinen
operations more gracefully. Should you have additional changes for FIPS mode operations, I would be interested in getting them merged into the development tree. -- Jouni MalinenPGP id EFC895FA

Re: Assertion failure

2009-07-23 Thread Jouni Malinen
if you could make the end pass whatever criteria FIPS has unless you do this. -- Jouni MalinenPGP id EFC895FA __ OpenSSL Project http://www.openssl.org User

Re: openssl-0.9.8d-tls-extensions.patch is not in the latest openssl-0.9.8k.tar.gz

2009-04-29 Thread Jouni Malinen
in the latest wpa_supplicant release (openssl-0.9.8i-tls-extensions.patch applies to OpenSSL 0.9.8k). -- Jouni MalinenPGP id EFC895FA __ OpenSSL Project