Re: How to know which curve to use for which cipher

2012-07-10 Thread Dr. Stephen Henson
On Tue, Jul 10, 2012, Wim Lewis wrote: > > (I think this is more appropriate for openssl-users than -dev, so I'm > responding to that list.) > > On 10 Jul 2012, at 8:59 AM, Sirshendu Rakshit wrote: > > My questions are: > > 1) Is this a good way to know the EC_KEY using the curve-name Or there

Re: How to know which curve to use for which cipher

2012-07-10 Thread Wim Lewis
(I think this is more appropriate for openssl-users than -dev, so I'm responding to that list.) On 10 Jul 2012, at 8:59 AM, Sirshendu Rakshit wrote: > My questions are: > 1) Is this a good way to know the EC_KEY using the curve-name Or there is > some better way to know it? If you're hardcoding

Re: FIPS Mode

2012-07-10 Thread Alexander Sack
On Mon, Jul 9, 2012 at 10:01 AM, Mike Hoy wrote: > I've googled around for that and for a layman like myself I didn't find > anything that 'held my hand' through the process. If you know how to do > this could you elaborate on how to disable Diffie-Hellman key exchanges? > > http://old.nabble.com

Re: Openssl s_client connection closes within few seconds

2012-07-10 Thread Sebastian Raymond
Dear Dave Thomson, Thank you for your reply. I checked Apache log and it does not give much information about the connection closure. 0. Yes, as you said, -debug and state did not give me much information about the problem. The only thing understood is server sends close notify. 1. The error is

Re: TS verify: how to fix "Verify error:self signed certificate in certificate chain" ?

2012-07-10 Thread Sandro Tosi
Thanks Peter & Dave for your replies! On 07/10/2012 08:15 AM, Peter Sylvester wrote: On 07/10/2012 02:38 AM, Dave Thompson wrote: From: owner-openssl-us...@openssl.org On Behalf Of Sandro Tosi Sent: Monday, 09 July, 2012 10:15 /usr/bin/openssl ts -verify -sha256 -untrusted -CAfile -data -in