stunnel 4.47 released

2011-11-21 Thread Michal Trojnara
Dear Users, I have released version 4.47 of stunnel. This version includes a number of important bugfixes. The ChangeLog entry: Version 4.47, 2011.11.21, urgency: MEDIUM: * Internal improvements - CVE-2010-3864 workaround improved to check runtime version of OpenSSL rather than

clarification about CVE-2011-3210 (TLS ephemeral ECDH) and OpenSSL 0.9.8 branch

2011-11-21 Thread Marco Molteni
Hi all, I would like to validate my understanding, please excuse my lack of familiarity with OpenSSL versioning :-) The OpenSSL security advisory of 2011-09-06 (http://www.mail-archive.com/openssl-announce@openssl.org/msg00108.html), regarding TLS ephemeral ECDH crashes in OpenSSL states that

Re: clarification about CVE-2011-3210 (TLS ephemeral ECDH) and OpenSSL 0.9.8 branch

2011-11-21 Thread Bodo Moeller
On Mon, Nov 21, 2011 at 10:51 AM, Marco Molteni mmolt...@cisco.com wrote: The OpenSSL security advisory of 2011-09-06 ( http://www.mail-archive.com/openssl-announce@openssl.org/msg00108.html), regarding TLS ephemeral ECDH crashes in OpenSSL states that the issue, for branch 0.9.8, applies to

certificates stored in ldap

2011-11-21 Thread prabhu kalyan rout
Hi, I am trying to store user certificates to ldap. But i dont know how to do it. Can anybody please tell me step by step procedure to do this or point me some link where it says how to do this. Thanks __ OpenSSL Project

Re: SSL_Connect call gives SSL_ERROR_WANT_READ for non blocking sockets

2011-11-21 Thread Arjun SM
Well yes, these are not errors. My bad for naming the variable as 'error'. ~Arjun On Thu, Nov 17, 2011 at 11:50 PM, Michael S. Zick open...@morethan.orgwrote: On Thu November 17 2011, Arjun SM wrote: Hi, Thanks for the reply. I have called the ssl_connect() function again after

Re: SSL_Connect call gives SSL_ERROR_WANT_READ for non blocking sockets

2011-11-21 Thread Michael S. Zick
On Mon November 21 2011, Arjun SM wrote: Well yes, these are not errors. My bad for naming the variable as 'error'. Not my point - Your logic shows that you think the connection has failed when it has simple not yet finished with its protocol. Not finished because you didn't respond to the

Re: understanding fipsld usage

2011-11-21 Thread Dr. Stephen Henson
On Fri, Nov 18, 2011, Kevin Fowler wrote: Let me first say I have read the User Guide and Security Policy repeatedly, as well as the Incore Tutorial, looked through this users group, and read anything else I could find - so I'm not being lazy, although my questions may be pedestrian... Please

Re: certificates stored in ldap

2011-11-21 Thread Erwin Himawan
Although, this doc is outdated, I find that this doc is helpful: http://vandervlies.xs4all.nl/~andre/Docs/pkildap.html On Mon, Nov 21, 2011 at 7:53 AM, prabhu kalyan rout pkr...@gmail.comwrote: Hi, I am trying to store user certificates to ldap. But i dont know how to do it. Can anybody

DH_check() claims that RFC 3526 groups have DH_NOT_SUITABLE_GENERATOR

2011-11-21 Thread Maxim Kammerer
Hello, MODP groups specified in RFC 3526 work fine once encoded as PKCS#3 DH parameters, e.g.: openssl genpkey -paramfile dh8192.pem -out private.pem openssl genpkey -paramfile dh8192.pem -out private2.pem openssl pkey -in private.pem -pubout -out public.pem openssl pkey -in private2.pem -pubout

CVE-2011-3210 clarification?

2011-11-21 Thread Charles Owens
I'm trying to make sure I completely understand the situation with respect to the TLS ephemeral ECDH crash issue (from http://openssl.org/news/secadv_20110906.txt). Is it true that with 0.9.8r by default the related ciphersuites (ECCdraft) are disabled? If they were enabled, would they show

Re: CVE-2011-3210 clarification?

2011-11-21 Thread Dr. Stephen Henson
On Mon, Nov 21, 2011, Charles Owens wrote: I'm trying to make sure I completely understand the situation with respect to the TLS ephemeral ECDH crash issue (from http://openssl.org/news/secadv_20110906.txt). Is it true that with 0.9.8r by default the related ciphersuites (ECCdraft) are

Re: CVE-2011-3210 clarification?

2011-11-21 Thread Charles Owens
On 11/21/11 3:16 PM, Dr. Stephen Henson wrote: On Mon, Nov 21, 2011, Charles Owens wrote: I'm trying to make sure I completely understand the situation with respect to the TLS ephemeral ECDH crash issue (from http://openssl.org/news/secadv_20110906.txt). Is it true that with 0.9.8r by default