[openssl-users] While ssl handshake happens, getting error Operation not allowed in fips mode

2016-05-03 Thread mani kanta
Hello, While the SSL handshake is happening,I am getting the error as below SSL_connect error:0408E09E:rsa routines:PKEY_RSA_SIGN:operation not allowed in fips mode. ssl handshake went well up to client sending key exchange to server and failing in the process of send client verify. Why this er

[openssl-users] stunnel 5.32 released

2016-05-03 Thread Michał Trojnara
Dear Users, I have released version 5.32 of stunnel. The ChangeLog entry: Version 5.32, 2016.05.03, urgency: HIGH * Security bugfixes - OpenSSL DLLs updated to version 1.0.2h. https://www.openssl.org/news/secadv_20160503.txt * New features - New "socket = a:IPV6_V6ONLY=yes" option to onl

[openssl-users] OpenSSL Security Advisory

2016-05-03 Thread OpenSSL
Security Advisory: https://www.openssl.org/news/secadv/20160503.txt Note: the online version of the advisory may be updated with additional details over time. For details of OpenSSL severity classifications please see: https://www.openssl.org/policies/secpolicy.html -BEGIN PGP SIGNATU

[openssl-users] OpenSSL version 1.0.2h published

2016-05-03 Thread OpenSSL
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 OpenSSL version 1.0.2h released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.0.2h of our open source

[openssl-users] OpenSSL version 1.0.1t published

2016-05-03 Thread OpenSSL
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 OpenSSL version 1.0.1t released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.0.1t of our open source

Re: [openssl-users] openssl verify reporting errors where there are none

2016-05-03 Thread Dr. Stephen Henson
On Tue, May 03, 2016, Graham Leggett wrote: > Hi all, > > I am trying to use ???openssl verify??? as a sanity check to determine > whether a set of certificates are sane and valid in a script that issues (or > reissues) the certificates, and I???m struggling with the output of the > ???openssl

[openssl-users] openssl verify reporting errors where there are none

2016-05-03 Thread Graham Leggett
Hi all, I am trying to use “openssl verify” as a sanity check to determine whether a set of certificates are sane and valid in a script that issues (or reissues) the certificates, and I’m struggling with the output of the “openssl verify” command. This is output I get while verifying three cer