Static Analysis Results for OpenSSL Available

2011-10-14 Thread Lynn Gayowski
Klocwork's open source program analyzed OpenSSL using its static analysis product, Klocwork Insight, to give a report on bugs and potential security vulnerabilities in the project. We hope these results will be of value to project contributors. The results are hosted on a secure web portal tha

Re: Truststore

2011-10-14 Thread Hopkins, Nathan
Hi, what is a trustore please and how could I read one?

Re: Padding schemes [was Differences between RSA and ECDSA - Conceptual and Practical]

2011-10-14 Thread Dirk Menstermann
Thanks, On 14.10.2011 13:16, Jakob Bohm wrote: >> > Unfortunately not, I am a security engineer, not a fully trained > cryptographer/cryptanalyst. > > As an engineer I am aware that attacking an algorithm such as RSA is easier > the > more the > attacker knows or can control about the input, an

Re: Padding schemes [was Differences between RSA and ECDSA - Conceptual and Practical]

2011-10-14 Thread Jakob Bohm
On 10/13/2011 7:17 PM, Dirk Menstermann wrote: Hello Jakob, On 12.10.2011 22:21, Jakob Bohm wrote: I know that to sign, i have to take a hash of some document or message but, theoretically, i could encrypt any document? The padding scheme would shrink the message and them could reveal the same