[openssl-users] Help with OpenSSL running on OSX

2015-07-08 Thread Matthew Donald
One of Imapfilter's users is having problems verifying certificates. They are running Imapfilter on OSX, which I don't have access to. In addition, I understand that OSX runs a custom version of OpenSSL, which has changes to the way certificates are verified. Could someone help me debug the issu

Re: [openssl-users] Old "RSA_NET" key format

2015-07-08 Thread Salz, Rich
> That's an overly general criteria, and may be the source of your mysterious > marauding of the APIs. Well there was no intent to be mysterious although I like the alliteration. We did mention it in the roadmap (https://openssl.org/about/roadmap.html) . Things are evaluated on a case-by-case

Re: [openssl-users] Old "RSA_NET" key format

2015-07-08 Thread Jakob Bohm
On 08/07/2015 20:23, Salz, Rich wrote: 1. Is there any good reason to remove this code? Yes. If it's not tested, reviewed, or in general use, then it's more likely to be harmful (source of bugs) than useful. That's an overly general criteria, and may be the source of your mysterious marauding

Re: [openssl-users] Old "RSA_NET" key format

2015-07-08 Thread Dr. Stephen Henson
On Wed, Jul 08, 2015, Jakob Bohm wrote: > > 2. Is this the OpenSSL name for the private key format > used by older Microsoft Authenticate tools (and thus > sometimes converted to/from PKCS#12 when switching > tool chains)? > AFAIK they only use "PVK" format. Steve. -- Dr Stephen N. Henso

Re: [openssl-users] Old "RSA_NET" key format

2015-07-08 Thread Salz, Rich
> 1. Is there any good reason to remove this code? Yes. If it's not tested, reviewed, or in general use, then it's more likely to be harmful (source of bugs) than useful. > 2. Is this the OpenSSL name for the private key format >used by older Microsoft Authenticate tools (and thus >some

Re: [openssl-users] Old "RSA_NET" key format

2015-07-08 Thread Jakob Bohm
On 02/07/2015 14:35, Salz, Rich wrote: We are thinking about removing the old “RSA_NET” format for private keys. This is used by very old Netscape and IIS. This would remove the d2i/i2d RSA_NET API’s, and the “nss” format flag from the openssl program. It would not remove the SPKI stuff.

Re: [openssl-users] RC4-MD5

2015-07-08 Thread Jeffrey Walton
On Wed, Jul 8, 2015 at 1:24 PM, Rajeswari K wrote: > Hello Openssl team, > > We are currently facing an issue with RC4-MD5 cipher suite after upgrading > from openssl0.9.8q to openssl1.0.1j. > > We see that on few platforms, RC4-MD5 cipher negotiation is returning bad > mac record error after rece

[openssl-users] RC4-MD5

2015-07-08 Thread Rajeswari K
Hello Openssl team, We are currently facing an issue with RC4-MD5 cipher suite after upgrading from openssl0.9.8q to openssl1.0.1j. We see that on few platforms, RC4-MD5 cipher negotiation is returning bad mac record error after receiving "Client Key Exchange" message. Currently we are using pro

[openssl-users] FIPS 140-2 casualty list -- Ubuntu 10.4 still MIA

2015-07-08 Thread Steve Marquess
If you don't know or care what FIPS 140-2 is then dance a little jig of joy and move on. The "hostage issue" has resulted in the forced removal[*] of a number of platforms from the #1747 validation. That removal was done by editing the "Big Blob o' Text" in the rightmost cell of the entry for the