RE: Problems installing OpenSSL on Linux

2004-07-12 Thread John . Airey
es mean that version numbers differ from the latest version, which is frankly a minor inconvenience. Details of all of this and how to build openssl without patent restrictions on your systems is in the openssl FAQ. -- John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Ro

RE: [98] Address in use.. Could not bind to 443

2004-04-28 Thread John . Airey
with "Include conf.d/*.conf" in httpd.conf), but the configuration will have to go in the httpd.conf file. Can you send me more details off list? I've not come across this before and I've not had to change this ssl.conf file at all. I suspect that you may be trying to run

RE: Encrypted attachments

2004-03-31 Thread John . Airey
ess you are testing with > Outlook 97 which i think has its problems with S/MIME > > Thorsten > Don't use Outlook 97, not even for a joke. It's seriously broken in many other ways too. 98 is passible but 2000 is fairly reliable. YMMV of course. - John Airey, BSc (Jt Hons),

RE: Openssl upgrade on Red Hat 7.3 question

2004-03-12 Thread John . Airey
hen support ceased. However, if you wish to use a different version of openssl with apache, you would be best advised to recompile both openssl and apache. Details of how to do this are in the openssl documentation. www.redhat.com and https://rhn.redhat.com are a good place to start. - John Airey, BSc

RE: Virus Scanner

2004-03-02 Thread John . Airey
faking addresses, and in some cases send viruses back to someone who hadn't even sent it! Given all these difficulties, a virus scanner would probably create more problems than it solves. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the

RE: Using OpenSSL and smartcards with pkcs#11

2004-01-15 Thread John . Airey
ve the security updates. "rpm -q --changelog openssl | more" shows that the security fixes were added on Sep 23 2003. Before suggesting they upgrade, find out what version of Linux they are running please. Otherwise they may come back with more problems that what they started with. Thank yo

RE: OpenSSL file destinations

2004-01-14 Thread John . Airey
s openssl already installed is so that you don't have issues where your programs are executing the wrong version. It's surprising how many times that happens. You might also find that the distro version is sufficient for your needs too, especially now the engine code is included. (I reme

RE: OpenSSL file destinations

2004-01-13 Thread John . Airey
ry rpm -q openssl To see if it is. If it is then try rpm -e openssl --test You'll probably see a list of packages that depend on it. If you don't, then you are free to stick with the defaults. If you do, then follow the build instructions in the openssl FAQ that refer to Red Hat. - John A

RE: un-tar'ing not working for me

2004-01-13 Thread John . Airey
ntents: tar -zxvf openssl-0.9.7c.tar.gz.tar To be really sure, use this first: tar -ztvf openssl-0.9.7c.tar.gz.tar To ensure there are no errors with the tar file. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road

RE: Sign PIX certificate using OpenSSL CA

2003-12-16 Thread John . Airey
wall version 6.3.x. I don't think there is a way to get a certificate onto a Pix, as the "ca" commands can only create certificates. Have a look at the version 6.3 command reference at http://www.cisco.com/en/US/products/sw/secursw/ps2120/products_command_refer ence_book09186a008017284e.

RE: Signing a CSR from JetDirect

2003-07-25 Thread John . Airey
or them in IE, they can be more trouble than they are worth. Most of these problems can be overcome however. I keep meaning to write a book including all this, as I don't think anyone has yet. Maybe this year I will... Getting back to the posters original point, is it at all possible that

RE: Upgrading to the lastest version, what happends with my Apach e-Mod_SSL?

2003-06-16 Thread John . Airey
enssl. However, your time might be better spent upgrading to a newer version of Linux. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [

RE: Upgrading to the lastest version, what happends with my Apach e-Mod_SSL?

2003-06-12 Thread John . Airey
f date the last time I tried. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] Evolution isn't true just because

RE: Upgrading to the lastest version, what happends with my Apache-Mod_SSL?

2003-06-12 Thread John . Airey
need to use patent restricted code there'll be no need. If you haven't built against one of these versions, you'll either need to recompile or use the Red Hat supplied mod_ssl package. Whichever you choose is up to you. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support

RE: Minimum RSA Key length ?

2003-06-06 Thread John . Airey
about which I am completely clueless as I currently have no business reason to use them). Anyway, the proof of the pudding is in the eating. Can you point me to a secure site that uses a key size >1024 bits? I can't find one for love nor money. - John Airey, BSc (Jt Hons), CNA, RHCE Inter

RE: Anyone where to get a signed SSL certificate cheap?

2003-02-14 Thread John . Airey
Try globalsign www.globalsign.com, 175 Euro ($189 or £116.91 in proper money). - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL

RE: Anyone where to get a signed SSL certificate cheap?

2003-02-14 Thread John . Airey
You are right about the price Jo. They've hiked their prices a lot (must be to pay for Mark Shuttleworth's space trip...). If you are representing a charity you may be able to negotiate a lower price. We did that last year and received a wildcard certificate at a discount. - John Aire

RE: Problems building 0.9.7 on RedHat 7.3

2003-01-20 Thread John . Airey
What are you using to build it with? I've managed to build 0.9.7 fine on RedHat 7.3 with "./config" and "./config shared" - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE

RE: OpenSSL Project Environment Migration on 10-Dec-2002 11:00 am CET

2002-12-12 Thread John . Airey
Can you give us more details about the move, like where, who, and whether it has bigger bandwidth please Ralf? Sorry for being late in replying, but I've been unwell. Thanks. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the

RE: regenerate a host-specific ?

2002-11-15 Thread John . Airey
If you don't give a passphrase, you can copy the contents of the id_dsa.pub to $HOME/.ssh/authorized_keys on the remote server, chmod this file to 600, chmod the .ssh directory to 700 and then ssh should let you in with this key from that host rather than via a password. - John Airey,

RE: Building 0.9.6g --RH8.0

2002-11-08 Thread John . Airey
he packages have changed. (I really like rpm -V, it helps me to check whether anything has been tampered with). I hope that helps. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1

RE: Building 0.9.6g --RH8.0

2002-10-31 Thread John . Airey
only there because of US patent restrictions. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] Theories of evolutio

RE: openssl 9.6g Redhat 7.3 Seg Fault

2002-10-10 Thread John . Airey
!! as I > think their RPM packages are rubbish and buggy also. > [snip] Link to aforementioned post: http://www.mail-archive.com/openssl-users@openssl.org/msg28006.html - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell

RE: openssl 9.6g Redhat 7.3 Seg Fault

2002-10-10 Thread John . Airey
gt; think their RPM packages are rubbish and buggy also. > [snip] I should have mentioned that someone did recently post a method to this list detailing how to remove openssl from Red Hat and build it. A search of the archives should bring it up. - John Airey, BSc (Jt Hons), CNA, RHCE Inter

RE: openssl 9.6g Redhat 7.3 Seg Fault

2002-10-10 Thread John . Airey
that much differently to how you are building them. I'm also a big fan of Red Hat Network now as I'm able to see that my systems are up to date with all the released patches at a glance. I should also add that I'm not on any commission from Red Hat to say this (sadly ;-) ). - John Airey

RE: apache and that whole "bugbear" thing

2002-10-09 Thread John . Airey
ll in memory. Could you give some more details about your other problems please? eg, version of apache and mod_ssl? You may need to upgrade these. For example, there is a recent update to apache (1.3.27) that contains several "new" security fixes. - John Airey, BSc (Jt Hons), CNA,

RE: Validity period of certificates

2002-09-27 Thread John . Airey
In addition, that was your key and certificate that you sent, not just . So I'd hope you have a pass-phrase on your key or the key and certificate that you sent aren't ones that you intend to use. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Roya

RE: upgrading

2002-09-19 Thread John . Airey
ate of release of openssl-0.9.6e, which according to CERT is the version that will fix it. I can't get into the openssl site at the moment to check anything else. Mornings aren't my best time of day... - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Ro

RE: upgrading

2002-09-19 Thread John . Airey
dea to leave compilers on public web servers, but there are occasions where you might need to. - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848

RE: Pls. suggest some books on security

2002-09-18 Thread John . Airey
Maximum Linux Security - ISBN 0-672-31670-6 is also very useful. Despite the title, it covers UNIX based security fairly well. John > -Original Message- > From: Matthew Hannigan [mailto:[EMAIL PROTECTED]] > Sent: 18 September 2002 14:10 > To: [EMAIL PROTECTED] > Subject: Re: Pls. suggest

RE: RH 7.3 hosed up

2002-09-18 Thread John . Airey
Just in case you've got the wrong end of the stick, I'm not suggesting that you shouldn't compile stuff yourself rather than use pre-packaged software. I'm simply saying that there may be more broken by forcibly removing packages that have dependencies than is at first realised. Personally I'd nev

RE: RH 7.3 hosed up

2002-09-18 Thread John . Airey
ght > > ahead. > > > > Otherwise, following the directions in the openssl FAQ: > > http://www.openssl.org/support/faq.cgi#BUILD8 > > > > - > > John Airey, BSc (Jt Hons), CNA, RHCE > > Internet systems support officer, ITCSD, Royal National > Insti

RE: RH 7.3 hosed up

2002-09-18 Thread John . Airey
://www.openssl.org/support/faq.cgi#BUILD8 - John Airey, BSc (Jt Hons), CNA, RHCE Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] Reality TV - the ultimate oxymoron

RE: FIPS-140 certification

2002-07-25 Thread John . Airey
that > > software version, the fix for the bug would invalidate the > > certification. > > > > Which all boils down to a question of choice, do you prefer a > > certificate that says your software is safe even if it isn't > > to uncertified software wh

Submission for the openssl FAQ

2002-07-01 Thread John . Airey
ource packages). - John Airey Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] - NOTICE: The information contained in this email and any attachments is confide

RE: OpenSSL, IIS 5.0 and Installing certificate trouble

2002-06-27 Thread John . Airey
he certificates straight onto IIS5. Contact me off the list for more details. I have a task for myself to test keys of greater than 1024 bits before the end of next week. I'll be running through the whole IIS procedure to do this. - John Airey Internet systems support officer, ITCSD, Royal Natio

RE: REMOVE

2002-06-06 Thread John . Airey
Can't you read the headers of your email? There should be a line something like Received: from mmx.engelschall.com (mmx.engelschall.com [195.27.130.252]) by maggotts.rnib.org.uk (8.11.6/8.11.6) with ESMTP id g56Bp6r03903 for <[EMAIL PROTECTED]>; Thu, 6 Jun 2002 12:51:11 +0100 My

RE: Key strength confusion

2002-04-29 Thread John . Airey
/cryptolaw/ Finally, their support for servers mentions Apache-SSL with no mention at all of openssl. Without a little more information about which browsers are causing trouble, there's not a lot more we can do. - John Airey Internet systems support officer, ITCSD, Royal National Institute of

RE: Key strength confusion

2002-04-26 Thread John . Airey
let me know the address of the site in question, I can have a look and see what I can ascertain from that also. - John Airey Internet systems support officer, ITCSD, Royal National Institute of the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL P

RE: smime segfault on redhat 7.2

2002-02-25 Thread John . Airey
ed openssl has files in /lib, these have different filenames from the libraries that are created with the source compilation (for reasons beyond the scope of your problem). On that basis, which openssl are you executing? - John Airey Internet systems support officer, ITCSD, Royal National Institu

RE: RedHat Linux 7.1 ssh connection refused

2002-01-21 Thread John . Airey
the server (ie telnet localhost 22) does that give a response? If it does, I would imagine that your firewall configuration on the server disallows connections to port 22 from remote machines. - John Airey Internet systems support officer, ITCSD, Royal National Institute for the Blind, Bak

RE: linux/openssl/apache problem solved

2002-01-21 Thread John . Airey
gt;Alaska Internetworks Not entirely correct. If you select normal or high and then customise, you can "trust" certain interfaces, eg eth0. Whilst this has the effect of disabling firewalling for that interface, it still allows you to add firewalling later. - John Airey Internet syste

RE: ./openssl speed -multi 1000 -engine aep ?

2002-01-14 Thread John . Airey
uation is. My guess (and that's all it is) is that the manufacturer may not have released any code or information about how it works. - John Airey Internet systems support officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 3752

RE: ./openssl speed -multi 1000 -engine aep ?

2002-01-14 Thread John . Airey
The openssl-engine versions also support "openssl speed". - John Airey Internet systems support officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] Agnostic (Greek) = Ignora

RE: Why DNS/IP in certificate?

2002-01-14 Thread John . Airey
machine and the client machine without worrying about the firewall. - John Airey Internet systems support officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] Agnostic (Greek) = Ignoramus

RE: I got 4 or more emails identical....

2001-12-20 Thread John . Airey
Title: RE: I got 4 or more emails identical The exact configuration line in a Pix firewall for "smtp security" is   fixup protocol smtp 25 However, I would doubt this is causing this. There is an old bug with Pix firewall's that might cause this, but the same version of IOS has more ser

RE: Help needed with getting SSL installed

2001-12-11 Thread John . Airey
ontact details. The change log there indicates the last change to Teraterm SSL was over three years ago. Not encouraging. All these pages are linked from the Teraterm Home Page at http://hp.vector.co.jp/authors/VA002416/teraterm.html. Also, as it is only a matter of time before Red Hat drop s

RE: Large File Support

2001-11-28 Thread John . Airey
The best advice is to rebuild the rpm packages so that these options are in the makefile. You can then upgrade your openssl packages to your new version without (hopefully) breaking other packages. Mail me off the list and I'll send you instructions. - John Airey Internet systems su

RE: RPM & Source code version

2001-11-21 Thread John . Airey
aking a non-US package available, but the sticking point with that is how to integrate it with their "up2date" tool. Unless we have US and non-US versions of RedHat I think we'll be stuck with that one. Incidentally, the hack of using a symlink doesn't work for all package

RE: RPM & Source code version

2001-11-20 Thread John . Airey
d out what is in them, and one RPM install on one machine is the same on another. (I know that you can create a custom configuration file and use that to compile and install on every machine, but frankly all that compiling and copying is a lot more work for multiple servers. If I build an RPM I do it f

RE: porting openssl to linux kernel

2001-11-02 Thread John . Airey
er all the time, the length of time required for a context switch is also becoming shorter and shorter. If that's the only reason to do it, it's really not worth it, IMNSHO. Now if the linux kernel had accessibility built in, eg keyboard control of voice synthesisers like a dectalk, that

RE: Two versions of openssl on one system

2001-10-30 Thread John . Airey
ter option to upgrade to that. Make sure you have plenty of backups before you start, though. - John Airey Internet systems support officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL

RE: Decrypting encrypted e-mail in OE 5

2001-10-16 Thread John . Airey
Specifically, IE5.01SP2 has 128bit support. This is the oldest version of IE that MS currently supports. A trip to http://windowsupdate.microsoft.com/ will allow you to upgrade to this. - John Airey Internet systems support officer, ITCSD, Royal National Institute for the Blind, Bakewell Road

RE: About libssl.so.2 and libcrypto.so.2

2001-10-09 Thread John . Airey
t; tarball with the RPM has had some things >stripped. That's > part of the hobbling.) > > 2) Edit the spec file and remove the "-usa" from "Source". > > 2) Down in %prep, kill off %{SOURCE1} by commenting it >out

RE: About libssl.so.2 and libcrypto.so.2

2001-10-08 Thread John . Airey
indeed another version of Linux, but it is not supported, might destroy all your data, etc. However, I have taken packages from it (apache-mod_ssl 1.3.20-2.8.4 for example) and they've worked for me. Details are at ftp://ftp.redhat.com/pub/redhat/linux/rawhide/README - John Airey Internet s

RE: About libssl.so.2 and libcrypto.so.2

2001-10-08 Thread John . Airey
es (details at www.redhat.com/errata/) runs the risk of breaking a lot of code. Also, the version of openssl with RedHat 7.1 is "hobbled" and does not include all the cipher support. I've asked an employee of RedHat who has OK'd the making available of a package that contains all the

RE: Major OpenSSL/mod_ssl install problems.

2001-09-30 Thread John . Airey
Your statement "I'm using RH 7.1" is the critical one for me. RedHat 7.1 (Which I assume you mean) includes openssl by default. If you build openssl from source and replace that which comes with it, you will break about 24 packages, including sendmail (I can send you a list if you want). Specifi

RE: openssl-0.9.6b.tar.gz.asc

2001-09-25 Thread John . Airey
gnature is 2.6.3ia. - John Airey Internet systems support officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] >-Original Message- >From: Victor S. [mailto:[EMAIL PROTE

RE: Export laws

2001-09-14 Thread John . Airey
RC4 violates the RC4 trademark is as daft as stating that the name Christina Saunders violates the right to the initials NASA. I believe someone with a name like this was once refused the right to register a domain name. Closer to home, Does NASDAQ violate the trademark name ASDA? I don't

RE: Time Diff?

2001-09-14 Thread John . Airey
gt; >Any ideas? > There isn't a time difference. These are the same time! 9:58:32 GMT (or more correctly UTC) is 10:58:32 BST, although only between (at present) 1:00AM UTC on the last Sunday in March and 1:00AM UTC on the last Sunday in October. This is the same across the whole of the E

RE: WIN32 binaries anyone??

2001-09-13 Thread John . Airey
Have you checked out http://curl.haxx.se/download.html? - John Airey Internet systems support officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] >-Original Message- >From

RE: libssl.so & libcrypto.so, again.

2001-09-10 Thread John . Airey
e now. When you have numerous RedHat boxes to administer, building RPMS on one to install on the others makes perfect sense. However, like I said it would help if the packages were made available. If not, does RedHat have any objections to me making them available? - John Airey Internet systems sup

RE: libssl.so & libcrypto.so, again.

2001-09-10 Thread John . Airey
nd others) who aren't restricted by RC5 and IDEA patents... > ># rpm --erase openssl-devel ># rpm -Uvh openssl-devel-0.9.6-3.rpm ### from the CD, or wherever > >if you wish to get back under the RPM management. You may need >a --force >too. > >Hope some of that mak

RE: Wasn't someone joking about the virus being posted by an autoresponder

2001-08-23 Thread John . Airey
ors (including myself). We already get grief from our users because Out of Office messages don't go the Internet! Mind you, if a mischievious sysadmin in the UK has done this deliberately as a result of my "suggestion", I'd like to chase him/her under the Computer Misuse Ac

RE: W2k wiazrd

2001-08-23 Thread John . Airey
our breath if this is a "self-signed" certificate. No doubt someone else will correct me if I'm wrong, but I've never been able to get self-signed certificate working on any version of IIS. (I'm assuming this is a server cert. If it's a client cert then I'm pr

RE: Please reconfigure majordomo to not set Reply-To (was: Failed to clean virus file Emanuel.exe)

2001-08-20 Thread John . Airey
rs. > >What we do is send the notice to the envelope sender, which >typically is set to the list owner. (Sorry list owner.) At least >that way it doesn't flood the entire list time and time again > If you think this is bad, imagine what would happen if the anti-virus checke

RE: Linux and EVP_rc5_32_12_16_ofb

2001-07-30 Thread John . Airey
tallation at the moment, so I have >no clue why >> this is so. >> > >RC5 is probably omitted for patent reasons. > You are spot on. The pre-packaged openssl with RedHat 7.1 has a file called "hobble-openssl". It removes RC5, IDEA and MDC2. Of course, it is possible to

RE: Web Site Alert: Not Responding

2001-07-27 Thread John . Airey
Title: Web Site Alert: Not Responding It worked just now! I've just pulled 0.9.6b again to test it (again).   - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0)

Expired certificates

2001-07-25 Thread John . Airey
the last 24 hours of the certificate is reached. As far as I am aware this is not documented anywhere. (No doubt some clever person will point me to the RFC where this is). I believe I'll have some accurate information about self-signed starred certificates with IIS fairly soon also. - Jo

RE: OpenSSL and IIS4 - problem

2001-07-23 Thread John . Airey
bit security cleared it. (I would recommend anyone who can to upgrade IE to 128bit). But like you say, it looks like a firewall or router configuration that is preventing connections. - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute

RE: OpenSSL and IIS4 - problem

2001-07-20 Thread John . Airey
first error, IIS will refuse you access to that directory as you requested a secure channel. It usually says something about requiring a secure connection though. - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE

RE: OpenSSL and IIS4

2001-07-19 Thread John . Airey
IIS4 can use 1024 RSA keys. We have several machines that are doing this already. - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED

RE: ROOKIE Question

2001-04-12 Thread John . Airey
it's money well spent - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] > -Original Message- > From: Web boy [mailto:[EMAIL PR

RE: a question about install

2001-04-09 Thread John . Airey
You can also use the DOS "SHELL" command to increase environment space. Details can be gathered from a DOS 6.0-6.22 machine. Windoze doesn't have any information on it, AFAIK. - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind

RE: OpenSSL or Engine

2001-03-29 Thread John . Airey
The openssl-engine code contains "experimental" support for hardware crypto devices. If you don't have one, or don't even know what one is, then just use the vanilla "openssl" code. I read somewhere that the two code branches will be merged in 0.9.7. Can't

RE: Batching E-Mails

2001-03-14 Thread John . Airey
My $0.02 worth. It is perfectly possible for there to be two versions of this list, a normal list and a "digest" or batched list as the original poster calls it. Majordomo supports it, but it will involve more work for someone to set it up. - John Airey Internet Systems Support Offi

RE: Can't compile openssl-0.9.6

2001-03-12 Thread John . Airey
Just to muddy the waters a little, the latest kernel (2.2.17) from RedHat put the "kernel-headers" package in with the "kernel-source" package. A really stupid idea which has caused a number of people a lot of grief, including me! - John Airey Internet Systems Support O

RE: ????????--???

2001-02-01 Thread John . Airey
is the case. One of them I actually approve messages before they go out, because most of the people on that list reply to the list rather than send messages to me, which is a real pain in the neck! - Happy new Millennium - http://www.rog.nmm.ac.uk/mill/index.htm John Airey Internet Systems Suppor

RE: Certificates with many Virtual host

2001-01-25 Thread John . Airey
It appears that you are not using one IP address for each virtual host. Once you've configured those correctly the error should go away. - Happy new Millennium - http://www.rog.nmm.ac.uk/mill/index.htm John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the

RE: Certificates with many Virtual host

2001-01-25 Thread John . Airey
Correction, it does work with IE, we have a wildcard certificate that works with IE 5.01. It works with IE 4 fine. As for IE 3.02 and before, well, they have problems with their root certs anyway. - Happy new Millennium - http://www.rog.nmm.ac.uk/mill/index.htm John Airey Internet Systems

RE: URGENT : SSL Handshake failed

2001-01-25 Thread John . Airey
I hope you are kidding about using mod_ssl 2.2.7. The latest version is 2.7.1, which is what you should be running. - Happy new Millennium - http://www.rog.nmm.ac.uk/mill/index.htm John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road

RE: Rainbow Cryptoswift cards

2001-01-19 Thread John . Airey
t; > There's a list of supported cards in the openssl changelog at http://www.openssl.org/news/changelog.html Don't know anything else though. - Happy new Millennium - http://www.rog.nmm.ac.uk/mill/index.htm John Airey Internet Systems Support Officer, ITCSD, Royal National Instit

Rainbow Cryptoswift cards

2001-01-19 Thread John . Airey
y post. The documentation available on the Rainbow site is scant as well) Thank you. If no-one can help, I'll battle on and post my results later. - Happy new Millennium - http://www.rog.nmm.ac.uk/mill/index.htm John Airey Internet Systems Support Officer, ITCSD, Royal National Institut

RE: Can IMagesh and RShyamsundar be unsubscribed from the list?

2001-01-11 Thread John . Airey
mail-abuse.org site tests didn't check for this one! - Happy new Millennium - http://www.rog.nmm.ac.uk/mill/index.htm John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 173

RE: Re(2): Problem compilig under RH Linux 6.2

2001-01-09 Thread John . Airey
d for openssl if you want. They are at www.modssl.org/contrib/. Use the versions with "fixed" in the title as there are installation problems with the other versions. I prefer them myself as it makes it easier to know what you have installed. - Happy new Millennium - http://www.rog.nmm

RE: Re(2): Problem compilig under RH Linux 6.2

2001-01-09 Thread John . Airey
Support for elf binaries comes with the out of the box installation, AFAIK. - Happy new Millennium - http://www.rog.nmm.ac.uk/mill/index.htm John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1

RE: what is ISO 9796?

2000-12-12 Thread John . Airey
ften ISO 3166-1 gets changed. It's about every three years, even though country names often change more regularly than that. It was last updated in 1997. I would imagine that either OpenSSL already supports it, or the standard is so dated as to have been superseded by other developments. - Jo

RE: what is ISO 9796?

2000-12-11 Thread John . Airey
lready seen the description on the ISO site. I don't believe that ISO make the full standards available on the 'net. Although I appreciate that this standard covers data encryption, I don't think it's that relevant to this list. Anyone care to differ? - John Airey Internet Systems Sup

RE: what is ISO 9796?

2000-12-11 Thread John . Airey
The International Standards Organisation have a description of this and all their standards at http://www.iso.ch/ Totally off-topic question though. - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0

RE: Corrected openssl.spec file

2000-11-22 Thread John . Airey
trib page and "fixed" versions of the existing rpms. I hope that Steve, who recently posted to this list, will find these useful as they install without errors (again, on my system). - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell R

RE: Openssl RPMs

2000-11-20 Thread John . Airey
view it's easier to show someone how to install and uninstall RPMs rather than explaining how to compile code from scratch. I'm not aversed to compiling programs with configure/make/etc , but my colleagues wouldn't even know where to start. They don't even understand what inetd

RE: Openssl RPMs

2000-11-20 Thread John . Airey
achines at my disposal to create and test these on. - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] > -Original Message- > F

RE:

2000-11-10 Thread John . Airey
those is the server session key that changes automatically every hour. This makes it more difficult to break ssh via brute force than ssl. However, I'm not foolish enough to state that it is impossible to break, just very difficult. - John Airey Internet Systems Support Officer, ITCSD,

RE:

2000-11-10 Thread John . Airey
ot;stunnel" which uses openssl to encrypt data over a standard port. Some protocols can't use this (eg ftp) as they don't use a single port. I think you'll need some more information though! - John Airey Internet Systems Support Officer, ITCSD, Royal National Institut

RE: Error Message : IP address does not match the server name

2000-10-30 Thread John . Airey
ed to Openssl at all. - John Airey Internet Systems Support Officer, ITCSD, Royal National Institute for the Blind, Bakewell Road, Peterborough PE2 6XU, Tel.: +44 (0) 1733 375299 Fax: +44 (0) 1733 370848 [EMAIL PROTECTED] -Original Message- From: Sze Yee [mailto:[EMAIL PROTECTED]] Sent: 29 O