SSL_use_psk_identity_hint() broken ?

2014-08-25 Thread Leif Thuresson
Don't know if I'm missing something or if this is a bug. It don't seem to be possible to set the PSK identity-hint per session. If I set the identity-hint in a newly created SSL connection object it is rejected because there is no session associated connection yet (but the SSL_use_psk_identity_h

CVE 2009-3245 effects

2010-03-10 Thread Leif Thuresson
I'm trying to figure out if my openssl based applications are vulnerable to CVE 2009-3245 From: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-3245 > OpenSSL before 0.9.8m does not check for a NULL return value from > bn_wexpand function calls in (1) crypto/bn/bn_div.c, (2) > crypto/bn/b

Re: aes128 code??

2007-11-27 Thread Leif Thuresson
e there some utility for use aes128 into another code more easy?? PD: Sorry for my English...i know that is not good -- Leif Thuresson Email: [EMAIL PROTECTED] Fox TechnologiesPhone: +46 18 160046 Kungsangsv. 19 Cell:

Re: Build problem on HP Itanium 64 bit machine

2006-09-04 Thread Leif Thuresson
atal error. + rm -f lib4758cca.exp chmod: can't access lib4758cca.sl *** Error exit code 1 Stop. *** Error exit code 1 Stop. *** Error exit code 1 === Leif, could you please throw some more light on the changes made from 0.9.7 to 0.9.8 and what changes you think cause this pr

Re: Build problem on HP Itanium 64 bit machine

2006-08-29 Thread Leif Thuresson
Hi, I have also had problems building shared version of openssl-0.9.8b on hpux-11.00 parisc using the hp ansi-c compiler. It looks like the openssl shared-library building part is completely re-implemented in 0.9.8 (compared to 0.9.7 which worked out of the box) In 0.9.7 shared libraries where lin

Memory handling bug in 0.9.8a AES assembler code for x86 ?

2006-04-10 Thread Leif Thuresson
performed on a RedHat Enterprise Linux 3.0 x86 32-bit system Code compiled with gcc version 3.2.3 Test results attached. /Leif Thuresson rh3:~/src/openssl-0.9.8a/test:45> ./evp_test evptests.txt Purify or PureCoverage slave: Warning: Can't open display "", using tty

Is it possible to serialize a SSL connection object ?

2002-01-16 Thread Leif Thuresson
hin a process. So I'm starting to wonder what is the SSL_dup() function supposed to do ? Have anyone tryed something similar ? /Leif -- Leif Thuresson Email: [EMAIL PROTECTED] RSA SecurityPhone: +46-18-160046 Kungsangsv. 19 S-753 23 Upps