Re: [openssl.org #3314] BUG - CMS Decrypt returns wrong error message on mismatching private key after Bleichenbachers FIX

2014-04-16 Thread Harakiri via RT
On Tue, 4/15/14, Stephen Henson via RT wrote: >> decrypting messages. Otherwise update the documentation - that > > under no circumenstances the CMS_R_NO_MATCHING_RECIPIENT is ever > > returned - you might as well remove it from any header file. >

[openssl.org #3314] BUG - CMS Decrypt returns wrong error message on mismatching private key after Bleichenbachers FIX

2014-04-15 Thread Harakiri via RT
This commit: http://git.openssl.org/gitweb/?p=openssl.git;a=commit;h=146b52edd122f55e2b2bfeb486dae8dbe96f739e   Introduced an error/new behavior, specifically this file http://git.openssl.org/gitweb/?p=openssl.git;a=blobdiff;f=crypto/cms/cms_smime.c;h=8c56e3a8520d73802c7ea00f81e81c1d574bc49b;hp

Re: OpenSSL Security Advisory

2009-01-08 Thread Harakiri
--- On Wed, 1/7/09, Dr. Stephen Henson wrote: > Incorrect checks for malformed signatures > - --- It is not perfectly clear to me if regular certificate validiations and smime signature validiation is also affected by this. Could you please elaborate if