[openssl.org #111] Cross compilation assumption

2014-06-27 Thread Rich Salz via RT
unsupported release, unsupported platform, very old defect, resolving as reject. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Auto

[openssl.org #111] Cross compilation assumption

2014-06-27 Thread Rich Salz via RT
unsupported release, unsupported platform, very old defect, resolving as reject. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Auto

[openssl.org #2746] Bugfix for ASN.1 parser in OpenSSL 0.9.8 and 1.0

2014-06-27 Thread Rich Salz via RT
As discussed, the "failed" encoding is BER, not DER, and we only do DER. (And if you know what that means, and the difference between the two, you have my sympathies.) __ OpenSSL Project http://www.

[openssl.org #2746] Bugfix for ASN.1 parser in OpenSSL 0.9.8 and 1.0

2014-06-27 Thread Rich Salz via RT
As discussed, the "failed" encoding is BER, not DER, and we only do DER. (And if you know what that means, and the difference between the two, you have my sympathies.) __ OpenSSL Project http://www.

[openssl.org #2264] Backwards-compatibility problem in 1.0.0 evp.h

2014-06-27 Thread Rich Salz via RT
As described by Stephen, not a bug. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #1572] Info required: OpenSSL 9.8.e

2014-06-27 Thread Rich Salz via RT
This isn't a defect report, it's an RFI :) __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #688] openssl+QNX6.2.1 - HELP PLEASE

2014-06-27 Thread Rich Salz via RT
No response in a decade, unsupported platform, closing this. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #776] Feature Request: static OpenSSL library project for CodeWarrior

2014-06-27 Thread Rich Salz via RT
Not a supported platform for this old release. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #776] Feature Request: static OpenSSL library project for CodeWarrior

2014-06-27 Thread Rich Salz via RT
Not a supported platform for this old release. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #861] [PATCH] add Interix configuration

2014-06-27 Thread Rich Salz via RT
Release too old, patch incomplete, and platform not supported. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #861] [PATCH] add Interix configuration

2014-06-27 Thread Rich Salz via RT
Release too old, patch incomplete, and platform not supported. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #554] Fw: FreeBSD Problem

2014-06-27 Thread Rich Salz via RT
Seems to be pilot error. If not, please re-open. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #554] Fw: FreeBSD Problem

2014-06-27 Thread Rich Salz via RT
Seems to be pilot error. If not, please re-open. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #835] Openssl 0.9.7c bug

2014-06-27 Thread Rich Salz via RT
Some local environment issue, not an OpenSSL issue. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #835] Openssl 0.9.7c bug

2014-06-27 Thread Rich Salz via RT
Some local environment issue, not an OpenSSL issue. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #675] Error 140890B2:SSL

2014-06-27 Thread Rich Salz via RT
This isn't a defect. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@opens

[openssl.org #675] Error 140890B2:SSL

2014-06-27 Thread Rich Salz via RT
This isn't a defect. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@opens

[openssl.org #670] -fPIC flag missing for asm/des_enc-sparc.

2014-06-27 Thread Rich Salz via RT
Never heard back about the .S file mentioned in the report, so resolving this. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automa

[openssl.org #670] -fPIC flag missing for asm/des_enc-sparc.

2014-06-27 Thread Rich Salz via RT
Never heard back about the .S file mentioned in the report, so resolving this. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automa

[openssl.org #641] Problem with include file !!!

2014-06-27 Thread Rich Salz via RT
Way too old. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@openssl.org

[openssl.org #641] Problem with include file !!!

2014-06-27 Thread Rich Salz via RT
Way too old. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager majord...@openssl.org

[openssl.org #533] small OpenSSL

2014-06-27 Thread Rich Salz via RT
Not a goal of the project. But a cool effort. On the other hand, openssl fits on telephones now :) __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-de

[openssl.org #533] small OpenSSL

2014-06-27 Thread Rich Salz via RT
Not a goal of the project. But a cool effort. On the other hand, openssl fits on telephones now :) __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-de

[openssl.org #3295] UNKWN can be returned for SSL_state_string when in some SSL23 states

2014-06-27 Thread Stephen Henson via RT
Fixed now, thanks for the report. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.ope

[openssl.org #3229] Fwd: Issue with key length

2014-06-27 Thread Stephen Henson via RT
No updates and not reproducible with standard OpenSSL. Marking as resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

[openssl.org #997] FW: Tarring failure

2014-06-27 Thread Stephen Henson via RT
Very old report, not happened since. Marking as resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

[openssl.org #3208] Planned removal of SSL_OP_MSIE_SSLV2_RSA_PADDING breaks dependent software

2014-06-27 Thread Stephen Henson via RT
Fixed: SSL_OP_MSIE_SSLV2_RSA_PADDING was restored but with value of 0x0. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

[openssl.org #3175] ideatest.c typo.

2014-06-27 Thread Stephen Henson via RT
Fixed now, thanks for the report. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.ope

[openssl.org #1004] dgst: unknown option "-md5" ...

2014-06-27 Thread Stephen Henson via RT
Old ticket. Problem no longer present, resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

[openssl.org #3218] Typo in .../demos/cms_dec.c

2014-06-27 Thread Stephen Henson via RT
Fixed, thanks for the report. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openssl

[openssl.org #3174] Redundant check for non-zero type parameter in ssl3_read_bytes

2014-06-27 Thread Stephen Henson via RT
Fixed now, thanks for the report. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.ope

[openssl.org #3179] Feature Request: Set Preference List for EC Curves in Client

2014-06-27 Thread Stephen Henson via RT
As indicate feature already present in OpenSSL 1.0.2, ticket resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

[openssl.org #3242] Patch Request for OpenSSL 0.9.8

2014-06-27 Thread Stephen Henson via RT
As indicated the patch is not relevant for OpenSSL 0.9.8. Ticket resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

RE: [openssl.org #1531] typo: 'rouines' should read 'routines' in all Copyright sections

2014-06-27 Thread Salz, Rich
It is perhaps appropriate that my comment had a typo. We "can't" change it. -- Principal Security Engineer Akamai Technologies, Cambridge, MA IM: rs...@jabber.me; Twitter: RichSalz

[openssl.org #1531] typo: 'rouines' should read 'routines' in all Copyright sections

2014-06-27 Thread Rich Salz via RT
This is the license we got and we got change it. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #1531] typo: 'rouines' should read 'routines' in all Copyright sections

2014-06-27 Thread Rich Salz via RT
This is the license we got and we got change it. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated List Manager

[openssl.org #871] Bug & Patch: PEM_write_SSL_SESSION and other macros cause GCC warnings

2014-06-27 Thread Stephen Henson via RT
Fixed long ago. PEM_write_SSL_SESSION is no longer a macro. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

[openssl.org #687] expired cert on www.openssl.org

2014-06-27 Thread Stephen Henson via RT
Fixed long ago... Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openssl.org Develop

[openssl.org #9] Re: [patch] Sign certs that aren't self signed for x509 -CA

2014-06-27 Thread Rich Salz via RT
Original requestor is willing to let it drop, and nobody else has asked about this so closing it. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev

[openssl.org #9] Re: [patch] Sign certs that aren't self signed for x509 -CA

2014-06-27 Thread Rich Salz via RT
Original requestor is willing to let it drop, and nobody else has asked about this so closing it. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev

[openssl.org #378] building without md5

2014-06-27 Thread Rich Salz via RT
You can't build ssl3 without MD5. Removing MD5 isn't supported. In theory it might be possible to build the crypto library and then not build libssl, but that's also not supported -- edit the makefile by hand to not build ssl if you need that. __

[openssl.org #378] building without md5

2014-06-27 Thread Rich Salz via RT
You can't build ssl3 without MD5. Removing MD5 isn't supported. In theory it might be possible to build the crypto library and then not build libssl, but that's also not supported -- edit the makefile by hand to not build ssl if you need that. __

[openssl.org #565] include error (RT ticket 565)

2014-06-27 Thread Rich Salz via RT
Believed to be config error, no response after 10 years so closing this. __ OpenSSL Project http://www.openssl.org Development Mailing List openssl-dev@openssl.org Automated Li

RE: [openssl.org #3359] Expired certificates bug.

2014-06-27 Thread Jaan Murumets via RT
Thanks for update. Our development process takes longer to validate your suggested fix. Probably takes 2-4 months due the summer holidays. I will keep posted if we have results. -Original Message- From: Stephen Henson via RT [mailto:r...@openssl.org] Sent: Friday, June 27, 2014 6:57 PM T

[openssl.org #1574] Session Ticket in OpenSSL 0.9.9 and EAP-FAST

2014-06-27 Thread Stephen Henson via RT
Resolved long ago. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openssl.org Develo

[openssl.org #3014] bug report: 1.0.1e - Linux/OSX/Windows/All? - CRL validation fails with unknown CRL critical extension

2014-06-27 Thread Stephen Henson via RT
Fixed now, thanks for the report. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.ope

[openssl.org #2909] Resolved: Wildcard support for certificate matching (plus fixes)

2014-06-27 Thread Stephen Henson via RT
According to our records, your request has been resolved. If you have any further questions or concerns, please respond to this message. __ OpenSSL Project http://www.openssl.org Development Mailing

[openssl.org #2269] ENGINE_register_complete() seems to ignore OPENSSL_NO_RAND

2014-06-27 Thread Stephen Henson via RT
Old ticket, no update from requestor. Marking as resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

[openssl.org #767] Openssl time bugs

2014-06-27 Thread Stephen Henson via RT
Old ticket, resolved long ago. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openss

[openssl.org #2803] bug report: OCSP_basic_verify may return incorrect value

2014-06-27 Thread Stephen Henson via RT
Resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openssl.org Development Mai

[openssl.org #2765] openssl negotiates ECC ciphersuites in SSL 3.0

2014-06-27 Thread Stephen Henson via RT
Resolved long ago. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openssl.org Develo

[openssl.org #2708] 1.0.1beta2 fipsdir is changed incorrectly in util/mk1mf.pl

2014-06-27 Thread Stephen Henson via RT
Resolved long ago. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openssl.org Develo

[openssl.org #2800] [PATCH] Add Camellia SHA256 ciphersuites from RFC5932

2014-06-27 Thread Stephen Henson via RT
Applied, thanks for the contribution. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www

[openssl.org #2783] OCSP_parse_url() does not parse URLs containing IPv6 addresses correctly

2014-06-27 Thread Stephen Henson via RT
Applied, ticket resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openssl.org

[openssl.org #2828] TLS 1.1 and 1.2 client - invalid Client Hello during renegotiation

2014-06-27 Thread Stephen Henson via RT
No further reports, marking as resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://

[openssl.org #2806] [PATCH] key exchange cipherlist labels for 8 ciphersuites (3e, 68, a4, a5, c029, c02a, c031, c032)

2014-06-27 Thread Stephen Henson via RT
Fixed long ago, ticket resolved. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.open

[openssl.org #2556] 3 bugs for OID encoding/decoding

2014-06-27 Thread Stephen Henson via RT
All issues resolved now. For now fix for case #1 only applied to master and 1.0.2 branches until it is tested more thoroughly: the fix has to rewrite the OID table and is only a minor bug. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: ht

[openssl.org #3359] Expired certificates bug.

2014-06-27 Thread Stephen Henson via RT
Awaiting response, marking as stalled for now. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project h

[openssl.org #3409] PATCH: Update SSL_CTX_add_extra_chain_cert doc

2014-06-27 Thread Stephen Henson via RT
Applied, thanks for the report. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.opens

[openssl.org #3374] Do not advertise ECC ciphersuites in SSLv2 client hello

2014-06-27 Thread Stephen Henson via RT
Applied, thanks for the report. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.opens

[openssl.org #3403] Null dereference and memory leak reports for openssl-1.0.1h from Facebook's Infer static analyzer

2014-06-27 Thread Stephen Henson via RT
These should all be addressed now. Thanks for the report. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project

[openssl.org #2742] Problems with cms -resign

2014-06-27 Thread Stephen Henson via RT
Resolved a long time ago. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commercial tech support now available see: http://www.openssl.org __ OpenSSL Project http://www.openssl.org

Re: [openssl.org #3412] [PATCH] Add 3072, 7680 and 15360 bit RSA tests to openssl speed

2014-06-27 Thread Matt Caswell
On 27 June 2014 06:38, Oscar Jacobsson via RT wrote: > Cheers! > > In general, should I be looking to submit patches against master? Assuming > the latest stable branch was the place to go may have been presumptuous of > me. :) > Unless a patch is only applicable to one of the branches, in genera