On Sun, Jul 22, 2001 at 01:05:32PM -0700, Tom Vaughan wrote:
> We've researched this[1] problem further and have found that "on occasion",
> in the Server Hello, in response to a request to resume a session, the MAC
> is bad. We've now seen this problem with both IE and Netscape. This appears
> to only happen when MD5 is used. When SHA-1 is used, this problem
> disappears. Would anyone happen to know if there is a problem in OpenSSL
> version 0.9.5a that would be causing this?
> 
> [1] http://marc.theaimsgroup.com/?l=openssl-dev&m=99542027232224&w=2

At least there is nothing in the CHANGES that would indicate that it is
fixed in later versions...
Reading this ethereal printout is a bit hard. Can you supply the dump
in tcpdump binary format so that it can be further processed e.g. with
ssldump?

Best regards,
        Lutz
-- 
Lutz Jaenicke                             [EMAIL PROTECTED]
BTU Cottbus               http://www.aet.TU-Cottbus.DE/personen/jaenicke/
Lehrstuhl Allgemeine Elektrotechnik                  Tel. +49 355 69-4129
Universitaetsplatz 3-4, D-03044 Cottbus              Fax. +49 355 69-4153
______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
Development Mailing List                       [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to