Hi Michal! > Martin Uecker <[EMAIL PROTECTED]> wrote: > > > Upstream answered that it is okay too remove the seeding of the PRNG > > with uninitialized memory, but the concrete patch which additionally and > > erranously removed all seeding was never posted on openssl-dev. > > Are you sure? > http://thread.gmane.org/gmane.comp.encryption.openssl.devel/10917
I don't see a patch there. This might sound like nitpicking, but a real patch would have provided some context to the two lines. Nevertheless, the right thing in my opinion would have been to propose a patch, wait until it is accepted, and then to package the new upstream version. Regards, Martin
signature.asc
Description: Digital signature