Re: Question about the TLS extension vulnerability

2010-11-22 Thread r rubin
Thank you Victor for the detailed answer. I still don't understand: Does the vulnerability affect TLS *cliens*? Thanks. On Sun, Nov 21, 2010 at 04:40:09PM +0200, r rubin wrote: > Hello, > > In the vulnerability detail, it is mentioned that: > ?Any OpenSSL based TLS *serv

Question about the TLS extension vulnerability

2010-11-21 Thread r rubin
Hello, In the vulnerability detail, it is mentioned that: “Any OpenSSL based TLS *server* is vulnerable". Does this mean that OpenSSL-based TLS *client* applications aren't vulnerable at all? Sorry if this is an obvious question, but as a very OpenSSL beginner I can't count on my own knowledge..