Hello again,

I've seen some discussion about the "dangers" of using the openssl
incorrectly but it has left me more confused than before. I'm using
openssl because I don't know much about ssl and I want a libary to take
care of the details. As I understand it the PRNG initializes itself
correctly under linux because of /dev/urandom. On other operating
systems we should take care of giving openssl some random data. If we
don't will the library complain or just operate unsafely? What is the
*current* behavior of openssl with respect to this?

Is there anything else that is not obvious and could reduce the security
of openssl?

Thanks in advance,

Vincent Levesque

______________________________________________________________________
OpenSSL Project                                 http://www.openssl.org
User Support Mailing List                    [EMAIL PROTECTED]
Automated List Manager                           [EMAIL PROTECTED]

Reply via email to