OpenSSL-compat patches or contributions

2020-09-21 Thread CODERE Carl-Eric
Greetings, On the OpenSSL 1.1.0 Changes wiki there is at the bottom of the page, there is an OpenSSL-compat source code package to help migrating to OpenSSL 1.1.X and keep compatibility with 1.0.2, how can we contribute to this, as we see there seems to be missing code...

RE: OpenSSL 3.0.0 security concerns using dynamic providers

2020-09-01 Thread CODERE Carl-Eric
> -Original Message- > From: Matt Caswell [mailto:m...@openssl.org] > Sent: mardi 1 septembre 2020 18:57 > To: CODERE Carl-Eric ; openssl- > us...@openssl.org > Subject: Re: OpenSSL 3.0.0 security concerns using dynamic providers > > > > On 01/09/2020

OpenSSL 3.0.0 security concerns using dynamic providers

2020-08-31 Thread CODERE Carl-Eric
Greetings, We are currently investigating the usage of OpenSSL 3.0.0 on our side, especially for FIPS usage, but it seems that for OpenSSL 3.0.0 the providers, especially the FIPS provider, will be loaded dynamically, my main worry is that this will easily permit some kind of