RE: [ANNOUNCE] OpenSSL 0.9.6d beta 1 released

2002-04-30 Thread Lynn Gazis
Windows 2000 (MSVC 6.0) Did: perl Configure VC-WIN32 ms\do_ms nmake -f ms\ntdll.mak Got the error: cl /Fotmp32dll\s3_pkt.obj -Iinc32 -Itmp32dll /MD /W3 /WX /G5 /Ox /O2 /O b2 /Gs0 /GF /Gy /nologo -DWIN32 -DWIN32_LEAN_AND_MEAN -DL_ENDIAN -DDSO_WIN32 /Fd out32dll /GD -D_WINDLL -D_DLL -c

Re: strangeness in `x509 -noout -text` output

2002-04-30 Thread Dr. Stephen Henson
On Mon, Apr 29, 2002, Michael Bell wrote: > > I found a small problem with -nameopt RFC2253: > > The X509v3 Authority Key Identifier doesn't use -nameopt for DirName. Is > this DN stored as a string? > Yes it is and fixing this would need some non trivial changes to pass the nameopt flags to

OpenSSL 0.9.6 Session Cache

2002-04-30 Thread Tom Tang
Hello, Where in 9.6x is the session cache limit being imposed ? I have looked in the openssl/ssl directory, but all I could find is a reference to SSL_SESSION_CACHE_MAX which session_cache_size is set to when a new CTX is allocated. Hopefully I'm missing something ... - Tom Tom Tang Array

Re: 0.9.7 20020427 snapshot errors on Win32

2002-04-30 Thread Richard Levitte - VMS Whacker
In message <[EMAIL PROTECTED]> on Mon, 29 Apr 2002 7:32:18 EDT, Jeffrey Altman <[EMAIL PROTECTED]> said: jaltman> I would be happy to work on this with you if you give me some jaltman> direction on how you would like it to go. jaltman> jaltman> It seems to me that there is no reason that Conf

Re: 0.9.7 20020427 snapshot errors on Win32

2002-04-30 Thread Dr. Stephen Henson
On Mon, Apr 29, 2002, Jeffrey Altman wrote: > > I would be happy to work on this with you if you give me some > direction on how you would like it to go. > > It seems to me that there is no reason that Configure could not > actually do the work of the .bat files for the Windows platforms > pr

Re: "openssl dgst" ignores read errors

2002-04-30 Thread Solar Designer
On Mon, Apr 29, 2002 at 03:48:48PM +0100, Ben Laurie wrote: > Well, here's an even bigger and better patch. Thanks for the continued > feedback. Thank you for the patch. I'll test this one when I'm back from CanSecWest. Unfortunately, I don't have enough time left until my flight there. -- /s

Re: Adding cipher code

2002-04-30 Thread Stephen Sprunk
Thus spake Lutz Jaenicke: > On Fri, Apr 26, 2002 at 02:29:46PM +0700, Satria Bakti (13297096) wrote: > > I'm working on integrating new cipher suite in 0.9.7, > > and now I come to part where I have to put my block > > algorithm code in crypto/ directory. > > > > Is there any guidelines/hints on

Re: Memory Leaks

2002-04-30 Thread Nils Larsch
Hi Pratap, one possible reason for a memory leak is the way you use the BN_bn2hex() function. [...] > BN_CTX_free(ctx); > return; > } > strcpy((char *)A,(const char *)BN_bn2hex(d)); > [...] from the BN_bn2hex manpage : [...] BN_bn2he

Re: "openssl dgst" ignores read errors

2002-04-30 Thread Ben Laurie
Solar Designer wrote: > > On Wed, Apr 24, 2002 at 04:04:53PM +0100, Ben Laurie wrote: > > Solar Designer wrote: > > > Thank you for working on this! > > > > OK, try the attached patch... > > It's almost right, except: > > > - do_fp(out, buf,inp,separator, out_bin, sigkey, sigbuf, si

Re: 0.9.7 20020427 snapshot errors on Win32

2002-04-30 Thread Guillermo Maturana
Have you considered using "include" files in the Makefiles? This way one can place all the interesting variables in a single file and include that from all other Makefiles. This would also help those gnarly make calls with a million arguments to lower Makefiles. I am not sure if that would h

Re: strangeness in `x509 -noout -text` output

2002-04-30 Thread Lutz Jaenicke
On Mon, Apr 29, 2002 at 10:33:10AM +0200, Michael Bell wrote: > Lutz Jaenicke schrieb: > > > > On Sun, Apr 28, 2002 at 08:07:43PM +0100, Dr S N Henson wrote: > > > However a new FAQ entry might be in order or possibly changing the > > > default display options so that the old behaviour is no long

x509/req/crl -nameopt

2002-04-30 Thread Robert Joop
i've discovered that `req -nameopt` is implemented but undocumented. `req -subject` is implemented and documented in the usage, but not in the manual. `crl -nameopt` was not implemented, i quickly hacked it in (we want a sane output format for openca), patch is attached. documentation should be

Re: 0.9.7 20020427 snapshot errors on Win32

2002-04-30 Thread Richard Levitte - VMS Whacker
In message <[EMAIL PROTECTED]> on Mon, 29 Apr 2002 10:24:34 -0700, Guillermo Maturana <[EMAIL PROTECTED]> said: matute> Have you considered using "include" files in the Makefiles? matute> This way one can place all the interesting variables in a matute> single file and include that from all othe

Re: OpenSSL 0.9.6 Session Cache

2002-04-30 Thread Lutz Jaenicke
On Mon, Apr 29, 2002 at 10:49:51AM -0700, Tom Tang wrote: > Hello, > > Where in 9.6x is the session cache limit being imposed ? > I have looked in the openssl/ssl directory, but all I could > find is a reference to SSL_SESSION_CACHE_MAX which session_cache_size > is set to when a new CTX is a

Re: strangeness in `x509 -noout -text` output

2002-04-30 Thread Michael Bell
Lutz Jaenicke schrieb: > > On Mon, Apr 29, 2002 at 10:33:10AM +0200, Michael Bell wrote: > > > The only problem for the future is the support of this flag in all the > > other tools (especially ca and req have problems with their option > > -subj). > > Robert Joop sent a patch last week (not ap

Re: strangeness in `x509 -noout -text` output

2002-04-30 Thread Robert Joop
On 02-04-30 10:59:08 CEST, Michael Bell wrote: > Lutz Jaenicke schrieb: > > > > On Mon, Apr 29, 2002 at 10:33:10AM +0200, Michael Bell wrote: > > > > > The only problem for the future is the support of this flag in all the > > > other tools (especially ca and req have problems with their option

Virus infected mail, warning

2002-04-30 Thread Erwann ABALEA
I received a lot of virus alerts in my mailbox, and a mail appearing to be from me, with a Base64 content. I'd like to say that I'm not infected by any virus, and especially not by a Windows one (I only read/write my mails with Pine under Linux). I do have a Windows PC, but it has an antivirus in

Re: strangeness in `x509 -noout -text` output

2002-04-30 Thread Robert Joop
On 02-04-29 10:33:10 CEST, Michael Bell wrote: > I found a small problem with -nameopt RFC2253: > > The X509v3 Authority Key Identifier doesn't use -nameopt for DirName. Is > this DN stored as a string? it depends on what you mean by string. it is stored as an OCTET STRING that contains an ASN.1

Question on EVP encryption/decryption routines

2002-04-30 Thread Pavel Tsekov
Hello, I have a simple question: Currently EVP_Encrypt* interface doesnt support encryption of multiple data streams with a single symmetric key. Is there any chance patches to allow this to be accepted in the official OpenSSL codebase ? Currently I'm thinking to modify EVP_EncryptFinal so it le

Re: Question on EVP encryption/decryption routines

2002-04-30 Thread James Yonan
> I have a simple question: > > Currently EVP_Encrypt* interface doesnt support > encryption of multiple data streams with a single > symmetric key. Is there any chance patches to > allow this to be accepted in the official OpenSSL > codebase ? Currently I'm thinking to modify EVP_EncryptFinal > s