Re: [Openvpn-devel] [PATCH] Add option to disable Diffie Hellman key exchange by setting "--dh none"

2014-10-18 Thread Steffan Karger
Anyone willing to review / comment? On 23-08-14 18:21, Steffan Karger wrote: > As requested on the mailing list and in trac ticket #410, add an option to > disable 'traditional' Diffie Hellman key exchange. People want to be able > to create ecdh-only configurations. > > Also update the manpage t

Re: [Openvpn-devel] New OpenVPN bundles for Windows platform that incorporate OpenSSL 1.0.1j

2014-10-18 Thread Steffan Karger
Hi, On 18-10-14 05:40, Илья Шипицин wrote: > how does that affect OpenVPN? > > суббота, 18 октября 2014 г. пользователь Lisa Minogue написал: > > SRTP Memory Leak (CVE-2014-3513) > Session Ticket Memory Leak (CVE-2014-3567) Denial-of-service only (no integrity or confidentiality breach)

Re: [Openvpn-devel] New OpenVPN bundles for Windows platform that incorporate OpenSSL 1.0.1j

2014-10-18 Thread Илья Шипицин
how does that affect OpenVPN? суббота, 18 октября 2014 г. пользователь Lisa Minogue написал: > OpenSSL Security Advisory [15 Oct 2014] > === > > SRTP Memory Leak (CVE-2014-3513) > > > Severity: High > > A flaw in the DTLS SRTP e

Re: [Openvpn-devel] New OpenVPN bundles for Windows platform that incorporate OpenSSL 1.0.1j

2014-10-18 Thread Lisa Minogue
OpenSSL Security Advisory [15 Oct 2014] === SRTP Memory Leak (CVE-2014-3513) Severity: High A flaw in the DTLS SRTP extension parsing code allows an attacker, who sends a carefully crafted handshake message, to cause OpenSSL to