Information wanted on OpenSSL cipher alias HIGH, MEDIUM and LOW.

2010-04-14 Thread Bhat, Jayalakshmi Manjunath
Hi All, I wanted to know when we use "ALL:!SSLv2:!EXPORT:!LOW:!MEDIUM:!DH" to select the ciphers how do OpenSSL understands what are ciphers are available under LOW and MEDIUM. Ssleay.txt documents names LOW,MEDIUM and HIGH as aliases. Please can someone provide me more information on this? Thank

RE: Information wanted on OpenSSL cipher alias HIGH, MEDIUM and LOW.

2010-04-15 Thread Bhat, Jayalakshmi Manjunath
:!LOW:!MEDIUM:!DH' AES256-SHA:AES128-SHA:DES-CBC3-SHA -Sandeep On Thu, Apr 15, 2010 at 10:45 AM, Bhat, Jayalakshmi Manjunath wrote: Hi All, I wanted to know when we use "ALL:!SSLv2:!EXPORT:!LOW:!MEDIUM:!DH" to select the ciphers how do OpenSSL understands what are ciphers are ava

Recall: Help needed on to compile OpenSSL with FIPS

2012-10-22 Thread Bhat, Jayalakshmi Manjunath
Bhat, Jayalakshmi Manjunath would like to recall the message, "Help needed on to compile OpenSSL with FIPS".__ OpenSSL Project http://www.openssl.org User Support Ma

How to uses FIPS 2.0.1 with OpenSSL 1.0.1

2012-10-22 Thread Bhat, Jayalakshmi Manjunath
Hi All, I wanted to know the procedure and steps for cross compiling OpenSSL on Linux along with FIPS? Regards Jaya

Help needed on to compile OpenSSL with FIPS

2012-10-22 Thread Bhat, Jayalakshmi Manjunath
Hi All, I wanted to know how to cross compile OpenSSL with FIPS enabled? Regards Jaya

Need inputs/suggestions on SSL/TLS protocol version fallback mechanism.

2012-10-29 Thread Bhat, Jayalakshmi Manjunath
Hi All, I have a client application that uses SSL23_client_method(). When the client is getting connected to server that supports TLS 1.0 there are no issues. When the client is getting connected to server that supports only SSLv3.0, connection is getting aborted with protocol number error. I

RE: Need inputs/suggestions on SSL/TLS protocol version fallback mechanism.

2012-10-29 Thread Bhat, Jayalakshmi Manjunath
proper forum for this sort of questions. Charles From: owner-openssl-us...@openssl.org<mailto:owner-openssl-us...@openssl.org> [mailto:owner-openssl-us...@openssl.org]<mailto:[mailto:owner-openssl-us...@openssl.org]> On Behalf Of Bhat, Jayalakshmi Manjunath Sent: Monday, October 29,

RE: Need inputs/suggestions on SSL/TLS protocol version fallback mechanism.

2012-10-29 Thread Bhat, Jayalakshmi Manjunath
ssl-us...@openssl.org]<mailto:[mailto:owner-openssl-us...@openssl.org]> On Behalf Of Bhat, Jayalakshmi Manjunath Sent: Monday, October 29, 2012 7:28 AM To: openssl-users@openssl.org<mailto:openssl-users@openssl.org> Subject: RE: Need inputs/suggestions on SSL/TLS protocol version fallback mech

RE: Need inputs/suggestions on SSL/TLS protocol version fallback mechanism.

2012-10-29 Thread Bhat, Jayalakshmi Manjunath
t a number of organizations will not want an SSL2/SSL3 clients accessing their corporate data. Differences Between SSLv2, SSLv3, and TLS, www.yaksman.org/~lweith/ssl.pdf Analysis of the SSL 3.0 Protocol, www.schneier.com/paper-ssl.html. Jeff On Mon, Oct 29, 2012 at 10:27 AM, Bhat, Jayalakshmi Manj

RE: Need inputs/suggestions on SSL/TLS protocol version fallback mechanism.

2012-10-29 Thread Bhat, Jayalakshmi Manjunath
t a number of organizations will not want an SSL2/SSL3 clients accessing their corporate data. Differences Between SSLv2, SSLv3, and TLS, www.yaksman.org/~lweith/ssl.pdf Analysis of the SSL 3.0 Protocol, www.schneier.com/paper-ssl.html. Jeff On Mon, Oct 29, 2012 at 10:27 AM, Bhat, Jayalakshmi Manjunath

How to check if the certificate is self signed

2006-10-25 Thread Bhat, Jayalakshmi Manjunath
Hi All, How do I check if the given certificate is self-signed? Thanks and Regards, Jaya __ OpenSSL Project http://www.openssl.org User Support Mailing Listopenssl-users@open

How to check if the certificate is self signed

2006-10-25 Thread Bhat, Jayalakshmi Manjunath
Hi All, How do I check if the given certificate is self-signed? Thanks and Regards, Jaya __ OpenSSL Project http://www.openssl.org User Support Mailing Listopenssl-users@open

How to create intermediate CA

2007-02-06 Thread Bhat, Jayalakshmi Manjunath
Hi All, Please can any one tell me what are the different methods to create an Intermediate ca certificate. Regards, Jaya __ OpenSSL Project http://www.openssl.org User Support Mailing List

CA certificate and signature algorithms

2007-02-07 Thread Bhat, Jayalakshmi Manjunath
Hi All, I have a CA certificate with Signature Algorithm md21RSA. Can I create a server certificate with Signature Algorithm sha1RSA and sign the server certificate using the above CA certificate. Will there be any problems. Thanks in advance. Jaya ___

EAP-FAST support

2007-02-20 Thread Bhat, Jayalakshmi Manjunath
Hi All, I was looking for EAP-FAST support in openssl library. In the mail list I found a patch. Patch was distributed for openssl-0.9.8. And I also found some mails stating EAP-FAST support will be added in openssl-0.9.9.I have 3 queries now. I. If EAP-FAST support will be added in openssl-0.9.9

Openssl 0.9.9 release

2007-03-02 Thread Bhat, Jayalakshmi Manjunath
Hi All, I was looking for EAP-FAST support in openssl library. In the mail list I found a patch. Patch was distributed for openssl-0.9.8. And I also found some mails stating EAP-FAST support will be added in openssl-0.9.9.I have few queries now. I. Will EAP-FAST support will be added in openssl-0

TLS extension support

2007-03-02 Thread Bhat, Jayalakshmi Manjunath
Hi All, Can any one tell me when "SessionTicket TLS Extension" support will be included in openssl library? Thanks in advance. Regards, Jaya. __ OpenSSL Project http://www.openssl.org User Support

Does openssl support TLS abbreviated handshake?

2007-03-21 Thread Bhat, Jayalakshmi Manjunath
Hi All, I wanted to know if openssl supports TLS abbreviated handshake? Thanks in advance. Regards, Jaya __ OpenSSL Project http://www.openssl.org User Support Mailing Listopens

Information about M_ASN1_I2D_len_IMP_opt and more

2007-04-04 Thread Bhat, Jayalakshmi Manjunath
Hi All, Where can I find more information about M_ASN1_I2D_len_IMP_opt M_ASN1_I2D_len_EXP_opt M_ASN1_D2I_get_IMP_opt M_ASN1_D2I_get_EXP_opt Functions. Regards, Jaya __ OpenSSL Project http://www

What is the difference netween SSL connection and session?

2007-04-04 Thread Bhat, Jayalakshmi Manjunath
Hi All, Please can any one tell me relationship between SSL_CTX,SSL,SSL_SESSION. And also the difference netween SSL connection and session? Regards, Jaya, __ OpenSSL Project http://www.openssl.org

do_cipher function

2007-05-01 Thread Bhat, Jayalakshmi Manjunath
Hi All, I am using EVP function for AES encryption/Decryption. Please can any one tell me how will know which function is invoked when do_cipher is called? Regards, Jaya __ OpenSSL Project http://w

do_cipher

2007-05-01 Thread Bhat, Jayalakshmi Manjunath
Hi All, I am using EVP functions for AES encryption/Decryption. Please can any one tell me how to find the exact AES encryption/decryption routines called when do_cipher is invoked? Regards, Jaya __ OpenSSL Project

Recall: do_cipher function

2007-05-01 Thread Bhat, Jayalakshmi Manjunath
Bhat, Jayalakshmi Manjunath would like to recall the message, "do_cipher function". __ OpenSSL Project http://www.openssl.org User Support Mailing Listopenssl-users@o

X509_STORE_CTX_set_time usage

2008-01-04 Thread Bhat, Jayalakshmi Manjunath
Hi All, I am facing a problem with "check_cert_time" function in OpenSSL library. I am trying to handle X509_V_ERR_CERT_NOT_YET_VALID and X509_V_ERR_CERT_NOT_YET_VALID errors.I am trying to simulate this errors with the expired certificate and certificate not yet valid. Problem here is I am always

Client authentication using Certificate chain.

2008-03-13 Thread Bhat, Jayalakshmi Manjunath
Hi All, If client authentication requested by the server, is it MUST to send the certificate chain along with client certificate? Does RFC mandates sending certificate chain? Regards Jaya __ OpenSSL Project

Use of Makefile.ssl

2006-04-18 Thread Bhat, Jayalakshmi Manjunath
Hi all, In openssl-0.9.8a I am not finding Makefile.ssl file. Please can you tell me How this is taken care. I need to edit my Makefile which invokes Makefile.ssl. So I am thinking of how to handle this. Regards, Jayalakshmi. ___

Hi..

2006-04-25 Thread Bhat, Jayalakshmi Manjunath
Hello All, Please can any one tell me when to use the progrms present in openssl-0.9.8a\apps. What is the use of these applications? Thanks and Regards, Jaya __ OpenSSL Project http://www.op

Hi..

2006-04-25 Thread Bhat, Jayalakshmi Manjunath
ECTED] Behalf Of Bhat, Jayalakshmi Manjunath Sent: Tuesday, April 25, 2006 4:19 PM To: openssl-users@openssl.org Subject: Hi.. Hello All, Please can any one tell me when to use the progrms present in openssl-0.9.8a\apps. What is the use of these applications? Thanks and Regards,

Object_mac.h,objects.txt

2006-06-23 Thread Bhat, Jayalakshmi Manjunath
Hi all, I am working on SSL from some time back. I don't understand the use of Object_mac.h,objects.txt, can any one explain me the use of this 2 files. Thanks in advance, Jaya. __ OpenSSL Project

Objects_mac.h,objects.txt

2006-06-23 Thread Bhat, Jayalakshmi Manjunath
Hi All, Please can any one tell me what is the use of objects_mac.h and objects.txt Regards, Jaya __ OpenSSL Project http://www.openssl.org User Support Mailing Listopen

obj_mac.num

2006-06-23 Thread Bhat, Jayalakshmi Manjunath
Hi All, I went through objects.README. But I did not understand the obj_mac.num and objects.txt files use clearly. Where do I get more info on this. Sorry in my prev mail I mentioned obj_mac.h instead of obj_mac.num. Thanks in advance, Jaya. _

RE: obj_mac.num

2006-06-23 Thread Bhat, Jayalakshmi Manjunath
, then i wud suggest you to first learn about OID (Object Identifiers) before mining this part. third - obj_mac.num stores NID ( a unique number) against each OID, openssl knows. this NID can be used to call any object associated with it. tanish On 6/23/06, Bhat, Jayalakshmi Manjunath <[EM

Hi..

2006-06-28 Thread Bhat, Jayalakshmi Manjunath
Hi all, I have a created a certificate certficate.cer, to which I have provided the Parameters Common name,Organization,Organizational Unit,City,State,Country. Now please can any one tell me how to use openssl to sign this certificate. I need to install certificate which will be P

GENERAL_NAME_free

2006-07-18 Thread Bhat, Jayalakshmi Manjunath
Hi All, Where do I find the definition for GENERAL_NAME_free? There are few files using this function. But I am not anle find the definition for this function. Please can any one help me. Thanks, Jaya. __ OpenSSL Project

Compilation broke with suffix or operands invalid for `bswap

2006-07-27 Thread Bhat, Jayalakshmi Manjunath
Can somebody please help me? I got this error while building openssl (openssl 9.8.a)for x86 . . . make[2]: Leaving directory `/usr/local/src/openssl-0.9.3a/crypto/md5' making all in crypto/sha... make[2]: Entering directory `/usr/local/src/openssl-0.9.3a/crypto/sha' gcc -I.. -I../../include -DTHRE

Compilation broke with suffix or operands invalid for `bswap

2006-07-27 Thread Bhat, Jayalakshmi Manjunath
Can somebody please help me? I got this error while building openssl (openssl 9.8.a)for x86 . . . make[2]: Leaving directory `/usr/local/src/openssl-0.9.3a/crypto/md5' making all in crypto/sha... make[2]: Entering directory `/usr/local/src/openssl-0.9.3a/crypto/sha' gcc -I.. -I../../include -DTH

Compilation broke with suffix or operands invalid for `bswap

2006-07-27 Thread Bhat, Jayalakshmi Manjunath
Can somebody please help me? I got this error while building openssl (openssl 9.8.a)for oz_x86 processor on HP-UX . . . make[2]: Leaving directory `/usr/local/src/openssl-0.9.3a/crypto/md5' making all in crypto/sha... make[2]: Entering directory `/usr/local/src/openssl-0.9.3a/crypto/sha' gcc -I..

Query on opensslconf.h in openssl

2006-07-31 Thread Bhat, Jayalakshmi Manjunath
Hi All, I have one query. In opensslconf.h there are some statements like #if defined(HEADER_BN_H) && !defined(CONFIG_HEADER_BN_H) #define CONFIG_HEADER_BN_H #undef BN_LLONG Many more statements are there for RC4,DES etc. I am not able to understand what these statements means. Pls can any one

RSAPublicKey causing compilation errors

2006-07-31 Thread Bhat, Jayalakshmi Manjunath
Hi All, I am trying to complie openssl.9.8a on HP-UX. I am getting errors ../../include/openssl/pem.h:610: parse error before `RSA' ../../include/openssl/pem.h:611: warning: return-type defaults to `int' pem_all.c: In function `DECLARE_PEM_write_fp_const': pem_all.c:133: storage class specified

RSAPublicKey causing compilation error

2006-07-31 Thread Bhat, Jayalakshmi Manjunath
Hi All, I am trying to complie openssl.9.8a on HP-UX. I am getting errors ../../include/openssl/pem.h:610: parse error before `RSA' ../../include/openssl/pem.h:611: warning: return-type defaults to `int' pem_all.c: In function `DECLARE_PEM_write_fp_const': pem_all.c:133: storage class specified

RE: RSAPublicKey causing compilation error

2006-07-31 Thread Bhat, Jayalakshmi Manjunath
--- "Bhat, Jayalakshmi Manjunath" <[EMAIL PROTECTED]> wrote: > Hi All, > > I am trying to complie openssl.9.8a on HP-UX. I am getting errors > > ../../include/openssl/pem.h:610: parse error before `RSA' > ../../include/openssl/pem.h:611: warning: > ret

RE: RSAPublicKey causing compilation error

2006-08-01 Thread Bhat, Jayalakshmi Manjunath
Venkatachalam Sent: Tuesday, August 01, 2006 12:24 PM To: openssl-users@openssl.org Subject: Re: RSAPublicKey causing compilation error --- "Bhat, Jayalakshmi Manjunath" <[EMAIL PROTECTED]> wrote: > Hi All, > > I am trying to complie openssl.9.8a on HP-UX. I am getting

Query on RSAPublicKeyy

2006-08-01 Thread Bhat, Jayalakshmi Manjunath
what could be wrong here. Regards, Jaya -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Girish Venkatachalam Sent: Tuesday, August 01, 2006 12:24 PM To: openssl-users@openssl.org Subject: Re: RSAPublicKey causing compilation error -

RE: Query on RSAPublicKeyy

2006-08-01 Thread Bhat, Jayalakshmi Manjunath
Hi, Thanks for the reply. I have ported openssl.9.8.a on HP-UX. Now I am trying to build the openssl source files which I have ported. I am using /hppa-hpux11/bin/make to build source. I am trying to build the library for ARM processor. Regards, Jaya. -Original Message- Fro

RE: Query on RSAPublicKeyy (Is this is a bug in pem.h)

2006-08-02 Thread Bhat, Jayalakshmi Manjunath
Hi All, In my previous post I had mailed these compilation error details. We have enabled OPENSSL_NO_FP_API Macro in our project. Compilation error: ../../include/openssl/pem.h:610: parse error before `RSA' ../../include/openssl/pem.h:611: warning: return-type defaults to `int' pem_all.c: In fun

Aes-256

2006-09-04 Thread Bhat, Jayalakshmi Manjunath
Hi All, I want to test AES-256 encryption and decryption. And also SH-512 hashing functionality in SSL. Pls can any one tell me how do I do it? Thanks in adnavce. Jaya. __ OpenSSL Project

RE: Aes-256

2006-09-04 Thread Bhat, Jayalakshmi Manjunath
Hi, Thanks a lot for the timely help. Regards, Jaya -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Marek Marcola Sent: Monday, September 04, 2006 4:51 PM To: openssl-users@openssl.org Subject: Re: Aes-256 Hello, > I want to test AES-256 encryp

RE: Aes-256 /testing of AES_cbc_encrypt

2006-09-06 Thread Bhat, Jayalakshmi Manjunath
Hi, I went through FIPS-197 for AES. Now if I want to test void AES_cbc_encrypt(const unsigned char *in, unsigned char *out, const unsigned long length, const AES_KEY *key, unsigned char *ivec, const int enc) function. How

RE: Query regarding AES support in Open SSL

2006-09-06 Thread Bhat, Jayalakshmi Manjunath
Yes OpenSSL supports AES.   Regards, Jaya   From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of V, Bharath (Bharath)Sent: Wednesday, September 06, 2006 3:08 PMTo: 'openssl-users@openssl.org'Subject: Query regarding AES support in Open SSL Hi,   I am using keytool command to ge

RE: Aes-256 /testing of AES_cbc_encrypt

2006-09-06 Thread Bhat, Jayalakshmi Manjunath
Thank you very much for the quick reply. Regards, Jaya. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Marek Marcola Sent: Wednesday, September 06, 2006 3:31 PM To: openssl-users@openssl.org Subject: RE: Aes-256 /testing of AES_cbc_encrypt Hello, > >

Warning in sha.h not able to use on HP-UX.

2006-09-14 Thread Bhat, Jayalakshmi Manjunath
Hi All, I have ported OPENSSL on VxWorks (host is HP-UX and target is VxWorks) I want to use SHA-512, When I compile I am getting the following warnings h/openssl/sha.h:179: warning: ANSI C does not support `long long' h/openssl/sha.h:180: warning: ANSI C does not support `long long' h/openssl/s

RE: Warning in sha.h not able to use on HP-UX.

2006-09-14 Thread Bhat, Jayalakshmi Manjunath
Hi All, First I would like to thank you very much. I just tested if I can use uint64_. I think I can use it. So Instead of unsigned long long can I use uint64_t? Regards, Jaya. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Marek Marcola Sent: Thursday

How do I remove padding during AES decryption

2006-09-16 Thread Bhat, Jayalakshmi Manjunath
Hi all Please can any one tell me how do I remove the pad bytes during AES decyrption using AES_cbc_encryption. Regards, Jaya. __ OpenSSL Project http://www.openssl.org User Support Mailing List

RE: How do I remove padding during AES decryption

2006-09-17 Thread Bhat, Jayalakshmi Manjunath
nssl-users@openssl.org Subject: RE: How do I remove padding during AES decryption Jaya, You would have to use the EVP api that would do it for you. see http://www.openssl.org/docs/crypto/EVP_EncryptInit.html -kbisla >From: "Bhat, Jayalakshmi Manjunath" <[EMAIL PROTECTED]

RE: How do I remove padding during AES decryption

2006-09-17 Thread Bhat, Jayalakshmi Manjunath
m: "Bhat, Jayalakshmi Manjunath" <[EMAIL PROTECTED]> >Reply-To: openssl-users@openssl.org >To: >Subject: How do I remove padding during AES decryption >Date: Sat, 16 Sep 2006 14:58:11 +0530 > >Hi all > >Please can any one tell me how do I remove the pad bytes

RE: How do I remove padding during AES encryption/ decryption

2006-09-18 Thread Bhat, Jayalakshmi Manjunath
Hi, Thanks for the reply. I have my sample test case like this. #define KEYSIZE 256 #define AES_BLOCK_SIZE 32 void test_main() { char key[KEYSIZE+1]; int I,keylen; char data[AES_BLOCK_SIZE] ; char cbuf[AES_BLOCK_SIZE]; char pbuf[AES_BLOCK_SIZE]; strcpy(key,"2ea24d27bc6e40