Re: OpenSSL 1.1.1e New EOF detection breaks session resumption

2020-03-27 Thread Steffen
Thanks Rainer and Rüdiger, When 2.4.43 is GA, I ship it with 1.1.1e. When 1.1.1f is available : test and wait a week to ship it with 2.4.43. Regards, Steffen > Op 27 mrt. 2020 om 20:33 heeft Rainer Jung het > volgende geschreven: > > Am 27.03.2020 um 19:24 schrieb Steffen: >> A

Re: OpenSSL 1.1.1e New EOF detection breaks session resumption

2020-03-27 Thread Ruediger Pluem
On 3/27/20 7:24 PM, Steffen wrote: > > A discussion started on Apachelounge about an possible issue with OpenSSL > 1.1.1e > ( https://www.apachelounge.com/viewtopic.php?p=38941#38941 ) > > This is the introduced new EOF in 1.1.1e :  >

Re: OpenSSL 1.1.1e New EOF detection breaks session resumption

2020-03-27 Thread Rainer Jung
Am 27.03.2020 um 19:24 schrieb Steffen: A discussion started on Apachelounge about an possible issue with OpenSSL 1.1.1e ( https://www.apachelounge.com/viewtopic.php?p=38941#38941 ) This is the introduced new EOF in 1.1.1e :

Re: OpenSSL 1.1.1e New EOF detection breaks session resumption

2020-03-27 Thread Steffen
I know. > Op 27 mrt. 2020 om 20:18 heeft William A Rowe Jr het > volgende geschreven: > >  > If you want to beat up your server in unusual ways, a good way to do this is > to > run it against https://www.ssllabs.com/ssltest/ from Qualsys with debug > logging > level throughout. I think

Re: OpenSSL 1.1.1e New EOF detection breaks session resumption

2020-03-27 Thread William A Rowe Jr
If you want to beat up your server in unusual ways, a good way to do this is to run it against https://www.ssllabs.com/ssltest/ from Qualsys with debug logging level throughout. I think you'll find we already sanitize all error results. On Fri, Mar 27, 2020 at 1:24 PM Steffen wrote: > > A

OpenSSL 1.1.1e New EOF detection breaks session resumption

2020-03-27 Thread Steffen