Re: Question About OpenSSL 3.0, FIPS and Solaris Support

2021-12-07 Thread Dr Paul Dale
The "unadopted" category is not the same as "unsupported".  We'll make an effort but if access to a physical machine is required, we will have to stop.  Whoever reports a problem will like have to assist with fixing it.  Be that by doing builds or writing code. The platform policy page

Re: Enumerating TLS protocol versions and ciphers supported by the peer

2021-12-07 Thread Mark Hack
Look at https://testssl.sh/ That is an openssl wrapper which enumerates ciphers and protocols ( and a whole lot more) Hexcode Cipher Suite Name (OpenSSL) KeyExch. Encryption Bits Cipher Suite Name (IANA/RFC)-

Forthcoming OpenSSL Releases

2021-12-07 Thread Matt Caswell
The OpenSSL project team would like to announce the forthcoming release of OpenSSL versions 1.1.1m and 3.0.1. These releases will be made available on Tuesday 14th December 2021 between 1300-1700 UTC. OpenSSL 3.0.1 is a security and bug fix release. The highest severity issue fixed in this

Question About OpenSSL 3.0, FIPS and Solaris Support

2021-12-07 Thread David Dillard via openssl-users
Hi, I'm hoping someone can shed some light on something that's confusing me. In the blog post about the FIPS submission it states that one of the platforms that's being tested is "Oracle Solaris 11.4 on Oracle SPARC

Re: Enumerating TLS protocol versions and ciphers supported by the peer

2021-12-07 Thread Hubert Kario
On Monday, 6 December 2021 15:52:30 CET, Dr. Matthias St. Pierre wrote: "Comparable elegant" is underspecified. (I guess, "Comparably elegant" would have been grammatically more correct.) Perhaps try testssl.sh (https://testssl.sh/)? It has various options for reducing the number and types

Re: OpenSSL 1.1 on OSX

2021-12-07 Thread Grahame Grieve
So I did end up statically binding openSSL into my application - thanks for the suggestion. Still, it seems to me that a note in the install/build instructions under macos saying that the default dylibs are not compatible with the rules for hardened applications would be a nice thing for