Re: OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542)

2012-03-01 Thread Jakob Bohm
On 2/29/2012 11:43 PM, Dr. Stephen Henson wrote: On Wed, Feb 29, 2012, Tammany, Curtis wrote: I had brought this issue up earlier (Windows 7/IE8 CAC enabled sites). With SSL 3.0 only checked on IE8 (in windows 7), I could make a connection to my site that had OpenSSL 1.0.0g. With both SSL 3.0

Re: OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542)

2012-03-01 Thread Dr. Stephen Henson
On Thu, Mar 01, 2012, Jakob Bohm wrote: On 2/29/2012 11:43 PM, Dr. Stephen Henson wrote: On Wed, Feb 29, 2012, Tammany, Curtis wrote: I had brought this issue up earlier (Windows 7/IE8 CAC enabled sites). With SSL 3.0 only checked on IE8 (in windows 7), I could make a connection to my site

RE: OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542)

2012-03-01 Thread Dave Thompson
From: owner-openssl-us...@openssl.org On Behalf Of Jakob Bohm Sent: Wednesday, 29 February, 2012 15:51 I do not know why MS KB2643584 does not mention changing TLS 1.1 and/or TLS 1.2 behavior, maybe someone familiar with the attack described in CVE2011-3389 knows a reason. Well, at least

Re: OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542)

2012-02-29 Thread Jakob Bohm
On 2/29/2012 12:22 AM, Michael D wrote: Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542) http://www.microsoft.com/download/en/details.aspx?displaylang=enid=28629 That page only instructs how to download the update file for that particular build of Windows. The real meat of

RE: OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542)

2012-02-29 Thread Tammany, Curtis
Update for Windows Server 2008 R2 x 64 Edition (KB2585542) On 2/29/2012 12:22 AM, Michael D wrote: Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542) http://www.microsoft.com/download/en/details.aspx?displaylang=enid=28629 That page only instructs how to download the update file

Re: OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542)

2012-02-29 Thread Jakob Bohm
540.663.9507 -Original Message- From: owner-openssl-us...@openssl.org [mailto:owner-openssl-us...@openssl.org] On Behalf Of Jakob Bohm Sent: Wednesday, February 29, 2012 08:44 To: openssl-users@openssl.org Subject: Re: OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542

Re: OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542)

2012-02-29 Thread Dr. Stephen Henson
On Wed, Feb 29, 2012, Tammany, Curtis wrote: I had brought this issue up earlier (Windows 7/IE8 CAC enabled sites). With SSL 3.0 only checked on IE8 (in windows 7), I could make a connection to my site that had OpenSSL 1.0.0g. With both SSL 3.0 AND TLS 1.0 checked, I could not make a

OpenSSL Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542)

2012-02-28 Thread Michael D
Security Update for Windows Server 2008 R2 x 64 Edition (KB2585542) http://www.microsoft.com/download/en/details.aspx?displaylang=enid=28629  Does anybody have any experience with this security patch? It seems to affect older versions of openssl (0.9.7 or so)... does anybody have experience