Re: [openssl-dev] [openssl.org #3133] minor make install improvement for Windows/Visual Studio in ms\nt.mak

2016-02-02 Thread Kees Dekker via RT
No matter. As soon as we have to perform a new build (will be done on Visual Studio 2015 later this year) and I discover the same issue, I will report it. Kees -Original Message- From: Rich Salz via RT [mailto:r...@openssl.org] Sent: Tuesday, February 02, 2016 22:16 To: Kees Dekker Cc:

[openssl-dev] Rgd. CVE-2015-3197 fix test verification !!

2016-02-02 Thread Hareesh D
Can someone please tell me how to verify the fix done for CVE-2015-3197. I want to test 1.0.1r version for this issue. >From the issue description I'm not able to understand what exactly client and server doing. Please tell me what packet client has to send or else please provide me the packet c

[openssl-dev] [openssl.org #2937] Handshake performance degradation in 1.0.1 and up.

2016-02-02 Thread Rich Salz via RT
The patches were large and added new features and API's which isn't appropriate for bugfix releases. In the master branch, branch the PRF functionality has been redirected to libcrypto so it's possible it can be optimised by using a more efficient implementation in crypto/kdf or in an engine. Ther

[openssl-dev] [openssl.org #3713] Bug: openssl-1.0.1l, FIPS, HP-UX ia64, Duplicate Symbol "AES_Te" and "AES_Td"

2016-02-02 Thread Stephen Henson via RT
On Tue Feb 02 23:38:51 2016, stuart.k...@microfocus.com wrote: > The SecurityPolicy.pdf claims that HP-UX 11i IA64 is a Supported > Configuration; how can this claim be made when the code does nto even > compile correctly? The FIPS module compiles correctly but there is the duplicated symbol issue

[openssl-dev] [openssl.org #3641] [PATCH] EC_KEY_generate always overwrites private key All OS 1.0.1j

2016-02-02 Thread Stephen Henson via RT
The existing functionality reuses an EC_KEY structure and generates a new key. We can't really change this because any application relying on that would end up getting the same key back instead of a new one. However I think a separate function which calculates the public key based on the set priva

Re: [openssl-dev] OpenSSL Security Advisory

2016-02-02 Thread Rainer Jung
Am 03.02.2016 um 00:30 schrieb Kurt Roeckx: On Tue, Feb 02, 2016 at 10:34:32PM +0100, Rainer Jung wrote: Hi there, reading the last advisory again, I noticed, that there's one logical inconsistency. First: OpenSSL before 1.0.2f will reuse the key if: ... - Static DH ciphersuites are used. The

[openssl-dev] [openssl.org #3699] openssl-1.0.2, fips sparc multiply defined _sparcv9_vis1_instrument_bus, _sparcv9_vis1_instrument_bus2

2016-02-02 Thread Stephen Henson via RT
On Tue Feb 02 21:46:59 2016, rsalz wrote: > Sorry, we can't touch the FIPS code any more without sponsorship. Though if this is still a problem a workaround is to rename the symbols on the OpenSSL side outside the FIPS code. Steve. -- Dr Stephen N. Henson. OpenSSL project core developer. Commerci

Re: [openssl-dev] [openssl.org #3713] Bug: openssl-1.0.1l, FIPS, HP-UX ia64, Duplicate Symbol "AES_Te" and "AES_Td"

2016-02-02 Thread Stuart Kemp via RT
The SecurityPolicy.pdf claims that HP-UX 11i IA64 is a Supported Configuration; how can this claim be made when the code does nto even compile correctly? From: Rich Salz via RT [r...@openssl.org] Sent: Tuesday, February 02, 2016 4:23 PM To: Stuart Kemp Cc:

Re: [openssl-dev] OpenSSL Security Advisory

2016-02-02 Thread Kurt Roeckx
On Tue, Feb 02, 2016 at 10:34:32PM +0100, Rainer Jung wrote: > Hi there, > > reading the last advisory again, I noticed, that there's one logical > inconsistency. > > First: > > OpenSSL before 1.0.2f will reuse the key if: > ... > - Static DH ciphersuites are used. The key is part of the certifi

Re: [openssl-dev] OpenSSL Security Advisory

2016-02-02 Thread Matt Caswell
On 02/02/16 21:34, Rainer Jung wrote: > Hi there, > > reading the last advisory again, I noticed, that there's one logical > inconsistency. > > First: > > OpenSSL before 1.0.2f will reuse the key if: > ... > - Static DH ciphersuites are used. The key is part of the certificate > and so it will

[openssl-dev] [openssl.org #3713] Bug: openssl-1.0.1l, FIPS, HP-UX ia64, Duplicate Symbol "AES_Te" and "AES_Td"

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #4000] Bug in Branch OpenSSL-fips-2_0-stable; file rsa_x931g.c

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #4001] Bug in branch OpenSSL-fips-2_0-stable, file fips_rsa_sign.c

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #3805] Re: Error while building FIPS capable OpenSSL

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #3531] [PATCH] fix a crash in dsa_do_sign() from openssl-fips-2.0.7

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #3089] Building OpenSSL 1.0.1e with FIPS on Win64A

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #3150] Bug Report (with trivial fix): fips module segfault

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #3081] openssl-fips-2.0.N

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

Re: [openssl-dev] [openssl.org #3739] regression: syswrite payloads >90kb can trigger EFAULT "Bad address" error on 1.0.2

2016-02-02 Thread Kent Fredric via RT
On 3 February 2016 at 10:50, Rich Salz via RT wrote: > sorry, we can't do anything about this without more detail. > inter-language bindings are tough Fortunately, I haven't seen this issue since 1.0.2a, so I suspect it was some other bug being exposed in a strange way, that has since been resol

[openssl-dev] [openssl.org #3079] FIPS Capable 1.0.1e with no-shared and -no-comp fails to compile

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #2399] Request: Allow "-no-xxx" options in ./config for FIPS build

2016-02-02 Thread Rich Salz via RT
If you sneeze on the FIPS code, you need a new CMVP change letter. Setting realistic expectations, there are no plans at this time for any FIPS work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #4270] OpenSSL 1.0.1 Installation bug

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #4261] BUG unable to connect to Mysql via ssl connection.

2016-02-02 Thread Rich Salz via RT
not an openssl issue, closing ticket. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #4225] OpenSSL 1.1-pre2 EC_KEY_ex_data regression of functionality from 1.0.2 to 1.1

2016-02-02 Thread Rich Salz via RT
Believed all in now :) -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #4143] bug: fips_premain_dso.exe does not include applink.c on dll fips builds

2016-02-02 Thread Rich Salz via RT
We're not maintaining FIPS stuff right now. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #4034] mkstack.pl does generate new safestack.h until release 1.0.1m

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Fixed in master. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list

[openssl-dev] [openssl.org #4014] RE: bug /fix to INSTALL_W64

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Also this is fixed in master. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev

[openssl-dev] [openssl.org #4008] Building statically OpenSSL 1.0.1p with MSVC2015 fails

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3987] Bug report about crash related to ASN1_primitive_free

2016-02-02 Thread Rich Salz via RT
Not enough information to reproduce the bug. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3929] Crash in EVP_PKEY_CTX_free in the client code ..

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. We cannot reproduce the error. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev

[openssl-dev] [openssl.org #3916] [PATCH] Fix Uninitialized Values

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Believe fixed in current releases. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl

[openssl-dev] [openssl.org #3770] Bug

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3766] OS/400 port of OpenSSL 1.0.1m

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3739] regression: syswrite payloads >90kb can trigger EFAULT "Bad address" error on 1.0.2

2016-02-02 Thread Rich Salz via RT
sorry, we can't do anything about this without more detail. inter-language bindings are tough. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3747] Bug Report - Segmentation fault thrown from engine_unlocked_finish()

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3733] ZOS 1.0.1k bug report with fix.

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3699] openssl-1.0.2, fips sparc multiply defined _sparcv9_vis1_instrument_bus, _sparcv9_vis1_instrument_bus2

2016-02-02 Thread Rich Salz via RT
Sorry, we can't touch the FIPS code any more without sponsorship. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3696] openssl 1.0.1k s_client app bug?

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. fixed in master and perhaps 1.0.2 -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-

[openssl-dev] [openssl.org #3685] crash in 32-bit OpenSSL (1.0.1j-fips) when external .so dynamically loads libcrypto.so

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. Also, we're not touching FIPS stuff right now. Also also, pascal inter-language calling stuff? :) -- Rich Salz, OpenSSL dev team; rs...@opens

[openssl-dev] [openssl.org #3677] bug report - open ssl interactive command interface

2016-02-02 Thread Rich Salz via RT
this sounds like a windows display issue, not an openssl issue. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3642] Bug in OpenSSL 1.0.1j version: Decode error in TLS 1.2 handshake failure from client

2016-02-02 Thread Rich Salz via RT
No reply, cannot reproduce it, closing the ticket. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3640] Bug report: PKCS7_decrypt memory leak

2016-02-02 Thread Rich Salz via RT
No reply, cannot reproduce the bug, closing the ticket. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3630] BUG - Building OpenSSL on Windows with zlib and fips object module fails. Possible fix included.

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3573] Building win64 openssl static library with no-ssl3 option fails on 1.0.1j

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. Also fixed in master, and probably 1.0.2 -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ o

[openssl-dev] [openssl.org #3587] openssl-1.0.1j configuration for solaris-x86/x64 should be changed

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3566] openssl-1.0.1j make depend failes

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. Also, fixed in master (and maybe 1.0.2) -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ op

Re: [openssl-dev] OpenSSL Security Advisory

2016-02-02 Thread Rainer Jung
Hi there, reading the last advisory again, I noticed, that there's one logical inconsistency. First: OpenSSL before 1.0.2f will reuse the key if: ... - Static DH ciphersuites are used. The key is part of the certificate and so it will always reuse it. This is only supported in 1.0.2. and

[openssl-dev] [openssl.org #3522] [PATCH] 1.0.1e: Configure: Allow the apps, test and tools directories to be configured out of DIRS.

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. Also fixed in 1.1 -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list

[openssl-dev] [openssl.org #3521] [PATCH] 1.0.1e: Configure: Correctly Handle GCC --sysroot Option

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. also the new build process handles this correctl. -- Rich Salz, OpenSSL dev team; rs...@openssl.org

[openssl-dev] [openssl.org #3520] [PATCH] 1.0.1e: Configure: Correctly Handle GCC/clang/LLVM -arch and -isysroot Options

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. Also, the new build process should handle this more cleanly. -- Rich Salz, OpenSSL dev team; rs...@openssl.org _

[openssl-dev] [openssl.org #3455] Compile error on Tandem NonStop (including patch)

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Also, Tandem isn't much supported... Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ opens

[openssl-dev] [openssl.org #3358] openssl should create private keys with stricter permissions

2016-02-02 Thread Rich Salz via RT
this is fixed in master (openssl 1.1 release) -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3322] [PATCH] ccgost to use configured params for 28147-89 in CNT and IMIT mode

2016-02-02 Thread Rich Salz via RT
GOST is now a separately-maintained engine. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3252] OpenSSL v1.0.1f issue: decryption failed or bad record mac:s3_pkt.c:484

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Is this still an issue? (Hubert?) -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/

[openssl-dev] [openssl.org #3233] 'make depend' emits warnings on OSX wth 1.0.1f

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. This is already fixed in master, as well. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___

[openssl-dev] [openssl.org #3217] [PATCH] changes in 1.0.0l and 1.0.1f required for OpenVMS

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. VMS gets a major uplift in 1.1 -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-de

[openssl-dev] [openssl.org #3204] J-PAKE test fails

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3182] Bug in OpenSSL 1.0.1e 586 assembly optimized AES_cbc_encrypt

2016-02-02 Thread Rich Salz via RT
The public interface is EVP_xxx which does the right thing. ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3165] tru64-alpha-cc compatibility fixes

2016-02-02 Thread Rich Salz via RT
Many of these are probably fixed now. Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ open

[openssl-dev] [openssl.org #3158] [bug] bad output for 'openssl ciphers -ssl2' built with 'no-ssl2'

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. also, sslv2 is gone. :) Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailin

[openssl-dev] [openssl.org #3157] PATCH Win32/64 openssl 1.0.1e fixes

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3137] The behavior of CRYPTO_set_mem_functions() in FIPS mode

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now and not doing any FIPS stuff for now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ opens

[openssl-dev] [openssl.org #3133] minor make install improvement for Windows/Visual Studio in ms\nt.mak

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. Also the build system in changed in master. -- Rich Salz, OpenSSL dev team; rs...@openssl.org _

[openssl-dev] [openssl.org #3048] [Bug] openssl-1.0.1e-fips-2.0.3 Illegal instruction

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. But we're not doing FIPS work now, either. Sorry. -- Rich Salz, OpenSSL dev team; rs...@openssl.org

[openssl-dev] [openssl.org #3035] Patch to properly detect and default to 64bit on OSX

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. We believe this works now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mai

[openssl-dev] [openssl.org #3007] BUG: OpenSSL 1.0.1e VC-WIN64A build fails when configured with 'no-ec'

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #3009] test failure, x64 openssl 1.0.1.e on OS X

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #2997] Problems with build because of compiler warnings, etc.

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #2998] Linking libgost.so

2016-02-02 Thread Rich Salz via RT
GOST is now a separately-maintained engine. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2986] aix building of openssl-1.0.1e

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #2945] bug: linking static OpenSSL 1.0.1c on EL6 seems to cause breakage

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe:

[openssl-dev] [openssl.org #2928] openSSL 1.0.1c serious bug in Win32 makefiles, easy to fix: linker binary variable name LINK collides with buildsystem variable LINK . please rename

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #2920] Problems building openssl-1.0.1c on 64bit PA-RISC HPUX

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner. We're only taking security fixes for 1.0.1 now. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: h

[openssl-dev] [openssl.org #2915] [PATCH] Add an option to Configure to set the include directory for FIPS enabled builds

2016-02-02 Thread Rich Salz via RT
sorry, we're not doing any FIPS changes at this time. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2912] Error in SSLv23 connection to some servers

2016-02-02 Thread Rich Salz via RT
Old release, Tried to reproduce the problem and could not do so. Please open a new ticket if this is still an issue with current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.

[openssl-dev] [openssl.org #2891] deadlock in X509_PUBKEY_get without recursive mutexes

2016-02-02 Thread Rich Salz via RT
for 1.0.1 we're only doing security fixes now. for threads stuff, please see https://github.com/openssl/openssl/pull/451 -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listin

[openssl-dev] [openssl.org #2865] Shared build broken in 1.0.1c

2016-02-02 Thread Rich Salz via RT
Sorry we didn't get to this sooner, we are only taking security fixes for 1.0.1 now. If still an issue on current releases, please open a new ticket. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://m

[openssl-dev] [openssl.org #2856] cryptlib.c: dynlock destroy call during (un)locking

2016-02-02 Thread Rich Salz via RT
Please see https://github.com/openssl/openssl/pull/451 -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2840] [PATCH] Restore alg_section to 1.0.1c

2016-02-02 Thread Rich Salz via RT
sorry we diddn't get to this sooner. we're only taking 1.0.1 security fixes now. and if you so much as *sneeze* on source code, you need a FIPS change letter :) -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe

[openssl-dev] [openssl.org #2831] patches for openssl 1.0.1c digest stuff

2016-02-02 Thread Rich Salz via RT
Too late for 1.0.1 and too much work for 1.0.2 :) We fixed it in master (1.1) by saying "any supported digest" which isn't ideal, admittedly. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.opens

[openssl-dev] [openssl.org #2835] question/proposal for openssl 1.0.1c to make do_ms.bat and do_win64a.bat somewhat more consisent + solve build errors for WIN64a.

2016-02-02 Thread Rich Salz via RT
We're only doing security fixes in 1.0.1 now; sorry we didn't get to this sooner. Fixed in current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-

[openssl-dev] [openssl.org #2812] BUG: infinite loop when using s_client's xmpp starttls operation

2016-02-02 Thread Rich Salz via RT
Is this still an issue in 1.0.2 or master? If so, please re-open this ticket. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2805] uplink-x86_64-pl-script error when running "ms\do_win64a" on windows 7-64bit command line

2016-02-02 Thread Rich Salz via RT
We're only doing security fixes in 1.0.1 now, sorry we didn't get to this sooner. Believed fixed in 1.0.2 Definitely fixed in master. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/m

[openssl-dev] [openssl.org #2779] OpenSSL 1.0.1 doesn't compile with NO_STDIO/NO_FP_API

2016-02-02 Thread Rich Salz via RT
fixed in master. too invasive to fix in earlier releases -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2774] OpenSSL 1.0.1 doesn't compile when configured with "no-tls1"

2016-02-02 Thread Rich Salz via RT
We're only taking security fixes for 1.0.1 now. Sorry we didn't get to look at this sooner. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2767] test/testssl script does not exercise TLS 1.2

2016-02-02 Thread Rich Salz via RT
fixed in current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2763] Possible bug - TLS 1.2 compliance

2016-02-02 Thread Rich Salz via RT
Since everyone disagrees with the RFC about sending "sigalg-agreeing" certs, we're not going to change this. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-d

[openssl-dev] [openssl.org #2747] valgrind suppressions file to suppress warnings from Python/openssl

2016-02-02 Thread Rich Salz via RT
Are these issues still present in the current releases(s)? If so, please open a new ticket. The 1.0.1 release only gets security fixes now. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl

[openssl-dev] [openssl.org #2741] [PATCH] 1.0.1-beta3 fails to build on Windows if --with-fipsdir is used

2016-02-02 Thread Rich Salz via RT
believed fixed; 1.0.1 only gets security fixes now. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2720] can't build with no-tlsext

2016-02-02 Thread Rich Salz via RT
we no longer support building without all tls extensions. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2688] OpenSSL 1.0.1 beta 2 report on Cygwin 1.5.25

2016-02-02 Thread Rich Salz via RT
fixed in later versions; 1.0.1 only gets security fixes now. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2670] [BUG] OpenSSL 1.0.1 beta 1 released (on VMS FAILED)

2016-02-02 Thread Rich Salz via RT
1.0.1 is only getting security fixes now. we think current releases work. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2640] [PATCH] support xmpp servers in starttls

2016-02-02 Thread Rich Salz via RT
this feature is in openssl 1.1 -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2993] Openssl manual pages

2016-02-02 Thread Rich Salz via RT
not a bug. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2906] enhancement: test suite won't work when parent directories have spaces

2016-02-02 Thread Rich Salz via RT
1.0.1 only gets security fixes now. might be fixed in 1.0.2 definitely fixed in 1.1 -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2949] OpenSSL bug

2016-02-02 Thread Rich Salz via RT
0.9.8 not supported, please re-test and re-open if still an issue on current releases. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #2901] no-rsa build bug in 1.0.1c

2016-02-02 Thread Rich Salz via RT
Sorry it took so long to get to this. We're only doing security fixes for 1.0.1 now. Closing. -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3957] BUG:Double free in int_thread_del_item in crypto/err/err.c

2016-02-02 Thread Rich Salz via RT
Believed fixed. Also see https://github.com/openssl/openssl/pull/451 ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev

[openssl-dev] [openssl.org #3196] Default CRYPTO_THREADID for Mac OS X with Posix Threads

2016-02-02 Thread Rich Salz via RT
Please see https://github.com/openssl/openssl/pull/451 which is what we'll be doing for threads moving forward -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl

[openssl-dev] [openssl.org #3806] change request - cleanup thread ERR state

2016-02-02 Thread Rich Salz via RT
Please see https://github.com/openssl/openssl/pull/451 which is what we'll be doing for threads moving forward -- Rich Salz, OpenSSL dev team; rs...@openssl.org ___ openssl-dev mailing list To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl

  1   2   >