Upgrading openssl to version 1.0.0g and removing the old openssl from /usr/bin

2012-02-09 Thread Christopher Johnson
Hello, I am trying to upgrade to openssl version 1..0.0.g from 0.9.8e. I have 1.0.0g install but when I try to remove the older version because it has library dependencies. What is the best way to remove it without breaking the linux OS? I just want to have 10.0.0g on the system. Thanks, Chri

Re: [openssl.org #2709] AutoReply: Exporter return value confusion

2012-02-09 Thread Eric Rescorla via RT
this is a problem in s_server as well, btw. On Thu, Feb 9, 2012 at 12:26 PM, The default queue via RT wrote: > > Greetings, > > This message has been automatically generated in response to the > creation of a trouble ticket regarding: >        "Exporter return value confusion", > a summary of whi

[openssl.org #2709] Exporter return value confusion

2012-02-09 Thread Eric Rescorla via RT
Checkin 1.57.2.3.2.18 changes the return value of SSL_export_keying_material to return 1 on success rather than the length of the returned string. Unfortunately, s_client.c still depends on the previous semantics and so reports an error. I don't care which one of these it is, but we should harmon

Re: Openssl-1.0.1-beta2 with openssl-fips-2.0 compile errors in windows

2012-02-09 Thread Jacob White
Whether I set the FIPSDIR environment variable or use the -with-fipsdir= option, I still get the same error. It still wants the fips header files. On Thu, Feb 9, 2012 at 5:31 AM, Dr. Stephen Henson wrote: > On Wed, Feb 08, 2012, Jacob White wrote: > > > After downloading and unpacking > > *openss

Re: [openssl.org #2702] TLS bad_mac_record with IIS 7 and client authentication

2012-02-09 Thread Andy Polyakov via RT
>> Results using prexit are attached. >> Openssl v1.0.1 beta 2 compiled on >> powerppc/linux >> Vs >> Win2008 R2 64bit IIS7 set to require client auth >> Command issued: >> openssl s_client -connect stk-tms.a51.lab:443 -cert >> /config/lighttpd/ssl.pem -CAfile /user/http_calist.pem -prexit -state >

[openssl.org #2702] TLS bad_mac_record with IIS 7 and client authentication

2012-02-09 Thread Stephen Henson via RT
> [stkap...@cisco.com - Wed Feb 08 00:12:25 2012]: > > Results using prexit are attached. > Openssl v1.0.1 beta 2 compiled on > powerppc/linux > Vs > Win2008 R2 64bit IIS7 set to require client auth > Command issued: > openssl s_client -connect stk-tms.a51.lab:443 -cert > /config/lighttpd/ssl.pem

[openssl.org #2708] 1.0.1beta2 fipsdir is changed incorrectly in util/mk1mf.pl

2012-02-09 Thread Bruce Stephens via RT
At line 62: $fipsdir =~ tr/\//${o}/; But that's before the platform file has been loaded, so $o hasn't been set. And tr doesn't do variable expansion, so this won't work anyway. Using s rather than tr and moving it down the file (after the platform file has been loaded, so line 236 or so

Re: Openssl-1.0.1-beta2 with openssl-fips-2.0 compile errors in windows

2012-02-09 Thread Dr. Stephen Henson
On Wed, Feb 08, 2012, Jacob White wrote: > After downloading and unpacking > *openssl-1.0.1-beta2.tar.gz > * and > openssl-fips-2.0rc3.tar.gzI > was able to build the fip