Re: Crypto overhaul

2017-10-31 Thread Eric McCorkle
On 10/31/2017 08:23, Wall, Stephen wrote: >> At least as about its first year and a half, LibreSSL had a markedly >> better track record than OpenSSL (zero high-severity CVEs vs 5 from >> OpenSSL, about half as many mid- and low-security CVEs). > > Are any of these relevant to the crypto module?

RE: Crypto overhaul

2017-10-31 Thread Wall, Stephen
> At least as about its first year and a half, LibreSSL had a markedly > better track record than OpenSSL (zero high-severity CVEs vs 5 from > OpenSSL, about half as many mid- and low-security CVEs). Are any of these relevant to the crypto module? Or are they all only applicable to the SSL proto

Re: Crypto overhaul

2017-10-31 Thread Ben Laurie
On 31 October 2017 at 11:48, Eric McCorkle wrote: > On 10/30/2017 04:05, Julian Elischer wrote: >> On 29/10/17 8:36 am, Eric McCorkle wrote: >>> On 10/28/2017 09:15, Poul-Henning Kamp wrote: In message <20171028123132.gf96...@kduck.kaduk.org>, Benjamin Kaduk writes: >>

Re: Crypto overhaul

2017-10-31 Thread Eric McCorkle
On 10/30/2017 04:05, Julian Elischer wrote: > On 29/10/17 8:36 am, Eric McCorkle wrote: >> On 10/28/2017 09:15, Poul-Henning Kamp wrote: >>> >>> In message <20171028123132.gf96...@kduck.kaduk.org>, Benjamin Kaduk >>> writes: >>> I would say that the 1.1.x series is less bad, especiall