CVE-2014-0076 and OpenSSL 0.9.8

2014-03-26 Thread Geoff_Lowe
It looks as though CVE-2014-0076 affects OpenSSL 0.9.8-based distributions as well, correct? It doesn't appear that the fix has been applied to the OpenSSL_0_9_8-stable branch yet though. I suppose it might need a few tweaks to apply there cleanly... Thanks.

signature_algorithms in client hello in FIPS mode

2013-06-16 Thread Geoff_Lowe
OpenSSL removes the RSA/MD5 combination from the tls12_sigalgs[] table in the tls12_get_req_sig_algs() function when FIPS mode is in effect. (This reduced set of signature/hash algorithm pairs is used to fill in the supported_signature_algorithms field in the TLS 1.2 Certificate Request

diffs for changes to fix CVEs

2013-02-05 Thread Geoff_Lowe
How does one find the diffs corresponding to the fixes (on the 0.9.8 line) for today's CVEs using the git web interface? Thanks. __ OpenSSL Project http://www.openssl.org Development Mailing List