Re: CVE-2011-3210 clarification?

2011-11-21 Thread Charles Owens
On 11/21/11 3:16 PM, Dr. Stephen Henson wrote: On Mon, Nov 21, 2011, Charles Owens wrote: I'm trying to make sure I completely understand the situation with respect to the "TLS ephemeral ECDH crash" issue (from http://openssl.org/news/secadv_20110906.txt). Is it true that with 0.9.8r by defaul

Re: CVE-2011-3210 clarification?

2011-11-21 Thread Dr. Stephen Henson
On Mon, Nov 21, 2011, Charles Owens wrote: > I'm trying to make sure I completely understand the situation with > respect to the "TLS ephemeral ECDH crash" issue (from > http://openssl.org/news/secadv_20110906.txt). > > Is it true that with 0.9.8r by default the related ciphersuites > (ECCdraft)

CVE-2011-3210 clarification?

2011-11-21 Thread Charles Owens
I'm trying to make sure I completely understand the situation with respect to the "TLS ephemeral ECDH crash" issue (from http://openssl.org/news/secadv_20110906.txt). Is it true that with 0.9.8r by default the related ciphersuites (ECCdraft) are disabled? If they were enabled, would they show