Re: [openssl-users] OpenSSL Behaviour under low bandwidth

2015-05-15 Thread Martin Beynon
Hi Kurt, I send OpenSSL blocks of 512 bytes...but as fast as it will consume them (since I want rid of the data as fast as possible). Blocking. Martin On 15 May 2015 at 21:21, Kurt Roeckx wrote: > On Fri, May 15, 2015 at 12:44:03PM +0100, Martin Beynon wrote: > > > > That is right from 100Mbps

Re: [openssl-users] OpenSSL Behaviour under low bandwidth

2015-05-15 Thread Kurt Roeckx
On Fri, May 15, 2015 at 12:44:03PM +0100, Martin Beynon wrote: > > That is right from 100Mbps down to 150 kpbs everything works as expected. > As I continue tuning down the bandwidth below 150kbps openssl starts to > stop sending data. It becomes very bursty and there are whole periods of > second

Re: [openssl-users] [openssl-dev] Replacing RFC2712 (was Re: Kerberos)

2015-05-15 Thread Jakob Bohm
On 13/05/2015 21:17, Nico Williams wrote: We're closer. On Wed, May 13, 2015 at 07:10:10PM +0200, Jakob Bohm wrote: On 13/05/2015 17:46, Nico Williams wrote: On Wed, May 13, 2015 at 12:03:33PM +0200, Jakob Bohm wrote: On 12/05/2015 21:45, Nico Williams wrote: On Tue, May 12, 2015 at 08:23:34

Re: [openssl-users] [openssl-dev] Replacing RFC2712 (was Re: Kerberos)

2015-05-15 Thread Jakob Bohm
On 13/05/2015 21:37, Jeffrey Altman wrote: On 5/13/2015 3:17 PM, Nico Williams wrote: Kerberos in particular supports PROT_READY. There is no Kerberos IV GSS mechanism, FYI. I'd never heard of GSS-SRP-6a; do you have a reference? Nico, Look for draft-burdis-cat-srp-sasl. It was never standa

Re: [openssl-users] OpenSSL Behaviour under low bandwidth

2015-05-15 Thread Martin Beynon
Sorry Rich, It does - as in; look like a network issue. But I fail to see how. If I try to push 10MB/s into openssl and everything works as expected until the available network bandwidth drops below 150 kpbs, this points at openssl - I think. That is right from 100Mbps down to 150 kpbs everythin

Re: [openssl-users] OpenSSL Behaviour under low bandwidth

2015-05-15 Thread Salz, Rich
“It does” Does that mean you have the same behavior? If so, it is possible that your simulator is, well, not great. But this doesn’t seem an openssl issue. Not sure where to suggest you go for help. ___ openssl-users mailing list To unsubscribe: htt

Re: [openssl-users] OpenSSL Behaviour under low bandwidth

2015-05-15 Thread Martin Beynon
Hi Rich, Thanks for your quick response. It does...and I do wonder if it has something to do with the bandwidth limiting / traffic shaping feature on the DrayTek router that I'm using to simulate low bandwidth. The reason I am looking at this now is because I'm experiencing some customer issues

Re: [openssl-users] OpenSSL Behaviour under low bandwidth

2015-05-15 Thread Salz, Rich
>I've tested with s_client between my PC and an AWS EC2 instance. I've also >tried using s_tunnel and nmap/ncat. The results appear the same. Using >wireshark I see a lot of TCP retransmissions. That sounds like a network issue. Try testing using something like netcat and see if you also get T

[openssl-users] OpenSSL Behaviour under low bandwidth

2015-05-15 Thread Martin Beynon
Hi all, I have discovered some strange behaviour with OpenSSL under low bandwidth conditions. I've found that with the bandwidth < about 150 kpbs that the throughput drops heavily and doesn't appear to be anywhere near the available bandwidth, spending a lot of time doing nothing. I've tested va

[openssl-users] Fwd: X9.31 RSA key generation for FIPS validation (180-4)

2015-05-15 Thread SecInterlocutor
Hello, Our product was FIPS-certified a few years ago. We are now about to start the re-certification process. The test for RSA X9.31 key generation have somewhat changed, or so it looks like to me anyway. A few years ago, we received test vectors with the following parameters: modulus size,