sufficient engine configuration i openssl.cnf for signing with smartcard/xmlsec1

2011-10-07 Thread SiSt
-openssl version 0.9.8a- OS:SuSE Linux Enterprise (SLED_10_SP3) CardMan 3021 OmneyKey BuyPass smartcard, http://buypass.no I am trying to have a --crypto switch with xmlsec1 working for a necessary signature The setup for a key-file is like this: xmlsec1 sign --privkey key.pem --output

TLS false start support on Openssl

2011-10-07 Thread Ritesh Rekhi
Hi All, Does openssl support TLS false start http://tools.ietf.org/html/draft-bmoeller-tls-falsestart-00 ? If Openssl supports TLS false start how can I use it with s_client ? Thanks Ritesh

Re: TLS false start support on Openssl

2011-10-07 Thread Richard Könning
Am 06.10.2011 23:28, schrieb Ritesh Rekhi: Does openssl support TLS false start http://tools.ietf.org/html/draft-bmoeller-tls-falsestart-00 ? I cite the last section of this draft: At the time of writing, the authors are not aware of any deployed TLS implementation that is not False

strong TLS connections

2011-10-07 Thread Kristen J. Webb
Hi All, I'm exploring the security of TLS for TCP/IP connections. I would like to establish TLS connections using server certificates (managing client certs via external or internal PKI is painful). My understanding is that a TLS connection with a server cert only identifies the server to the