RE: [EXTERNAL] Re: Need Help for Code Changes to Upgrade from OpenSSL 1.0.2 to 3.0

2021-10-27 Thread Paramashivaiah, Sunil
Hi Matt, Thanks for the help. I need get SSL members (ssl->session , ssl->ctx , ssl->references) and set SSL member (ssl->tlsext_ocsp_resp). Please let me know the Openssl 3.0 API's for the same. Thanks and Regards, Sunil -Original Message- From: Matt Caswell S

Refactring FIPS_escda_sign() for OpenSSL 3.0.0

2021-10-27 Thread Kory Hamzeh
Hi, I am upgrading some 3RD party code which performs FIPS ECDSA AVS testing for FIPS 140-2 certification. The code uses FIPS_escda_sign(), which in Openssl-fips-2.0.5 is define as: ECDSA_SIG * FIPS_ecdsa_sign(EC_KEY *key, const unsigned char *msg, size_t msglen ,

v1.1.1: “Secure Renegotiation IS NOT supported”

2021-10-27 Thread Felipe Gasper
Hello, I’m using OpenSSL 1.1.1l to connect via s_client to a service on an AlmaLinux 8 box running OpenSSL 1.1.1g, and s_client is reporting that secure renegotiation isn’t supported: > Secure Renegotiation IS NOT supported Curiously, when I connect to a 1.0.2 server (CentOS 7), it rep

Re: OpenSSL 3.0 FIPS questions

2021-10-27 Thread Jason Schultz
Sorry, I meant to include the config information in my previous email. I should probably go back to the beginning, I've been trying a lot of different combinations without success, so unwinding to the beginning and taking one step at a time is probably appropriate. Since I want the FIPS changes

Re: OpenSSL 3.0 FIPS questions

2021-10-27 Thread Matt Caswell
On 26/10/2021 20:17, Jason Schultz wrote: Thanks for all of the help so far. Unfortunately, I'm still struggling with this. There could be a number of issues, starting with the installation of OpenSSL. I basically followed the documentation and did the following: ./Configure enable-fips m

Fw: openssl s_client privatekey engine pkcs11 - no SSL_connect:SSLv3/TLS write certificate verify

2021-10-27 Thread Zlatko Vrastic via openssl-users
- Forwarded Message - From: Zlatko Vrastic To: "openssl-users@openssl.org" Sent: Friday, October 22, 2021, 03:25:10 PM GMT+2Subject: openssl s_client privatekey engine pkcs11 - no SSL_connect:SSLv3/TLS write certificate verify When using openssl s_client .. -keyform engine -e