Re: [openssl-users] rsaOAEP OID in X509 certificate

2018-08-14 Thread Viktor Dukhovni
> On Aug 14, 2018, at 4:55 PM, Stephane van Hardeveld > wrote: > > If I would try this endeavour, what would be the best interface to set this? > For creation, use the EVP_PKEY type with the EVP_PKEY_CTX, and set > attributes there? You'll need a new EVP_PKEY type that is mostly like RSA, bu

Re: [openssl-users] rsaOAEP OID in X509 certificate

2018-08-14 Thread Stephane van Hardeveld
> > > On Aug 9, 2018, at 3:21 PM, Stephane van Hardeveld > wrote: > > > > The certificate is signed with PSS. However, I try to indicate that the > > public key enclosed IN the certificate should be used with the OAEP > padding > > mode while decrypting a separate message > > Keys in X.509 certi

[openssl-users] the whole internet gets real small real fast on TLS 1.3

2018-08-14 Thread Dennis Clarke
Seems google.com supports TLS 1.3 as well as very very few others. There is also https://beta.tls13.net/ running apache-trunk where that site is based on OpenSSL 1.1.1-pre8 and supports TLS 1.3 and a fallback to TLS 1.2 however I think browsers will *not* perform tls version fallback from TLS 1.

Re: [openssl-users] About 1.0.2p version release !!

2018-08-14 Thread Dennis Clarke
On 08/14/2018 04:06 AM, Wouter Verhelst wrote: It does (and that's the whole point of it) On 13-08-18 05:31, Short, Todd via openssl-users wrote: That site can’t be reached… (at least by me, unless it requires TLSv1.3…) -- -Todd Short // tsh...@akamai.com // "One if by land, two if by sea

Re: [openssl-users] The new BN_num_bits_word in 1.0.2o triggers bug in MS C 14.00.60131 for ARM

2018-08-14 Thread Jakob Bohm
On 09/08/2018 23:23, Kurt Roeckx wrote: On Mon, Aug 06, 2018 at 04:30:54PM +0200, Jakob Bohm wrote: The patch below works around this, porting this to OpenSSL 1.1.x is left as an exercise for the reader: Can you please open a pull request on github for that? Kurt This may be some extra work

Re: [openssl-users] OpenSSL version 1.1.0i published

2018-08-14 Thread Thomas J. Hruska
I notice the release distribution for 1.1.0i includes a preconfigured makefile whereas 1.1.0h and earlier do not. -- Thomas Hruska Shining Light Productions Home of BMP2AVI and Win32 OpenSSL. http://www.slproweb.com/ -- openssl-users mailing list To unsubscribe: https://mta.openssl.org/mailman/

[openssl-users] Compile Failure 1.0.2p AIX 7.1 using GCC

2018-08-14 Thread Jerry L
This error message was transcribed from an air-gap network and not copied. I believe the error message has been correctly transcribed. This is the error we are getting when attempting to compile 1.0.2p for AIX 7.1 using GCC 4.3.5 making all in crypto. /usr/bin/perl ../util/mkbuildinf.pl

[openssl-users] OpenSSL version 1.1.0i published

2018-08-14 Thread OpenSSL
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 OpenSSL version 1.1.0i released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.1.0i of our open sour

[openssl-users] OpenSSL version 1.0.2p published

2018-08-14 Thread OpenSSL
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 OpenSSL version 1.0.2p released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.0.2p of our open sour

Re: [openssl-users] About 1.0.2p version release !!

2018-08-14 Thread Wouter Verhelst
It does (and that's the whole point of it) On 13-08-18 05:31, Short, Todd via openssl-users wrote: > > That site can’t be reached… (at least by me, unless it requires TLSv1.3…) > >   > > -- > > -Todd Short > > // tsh...@akamai.com > > // "One if by land, two if by sea, three if by the Internet."