Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Gert Doering
Hi, On Thu, Dec 02, 2010 at 11:50:47AM +0100, David Sommerseth wrote: > Wow, I mean WOW!! This is quite some work you've done! [..] What he said :-) I'm not so pessimistic regarding inclusion in 2.3, though - yes, 2.3 brings large changes, but not yet in the SSL arena. So why not break that as

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Farkas Levente
On 12/02/2010 12:10 PM, Matthias Andree wrote: > Am 02.12.2010 10:46, schrieb Farkas Levente: >> On 12/02/2010 10:05 AM, Adriaan de Jong wrote: >>> Hi List, >>> >>> We've been working on OpenVPN in preparation for a security evaluation. >>> This entailed documenting OpenVPN at a relatively high l

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Adriaan de Jong
mber 2010 11:51 > To: Adriaan de Jong > Cc: openvpn-devel@lists.sourceforge.net > Subject: Re: [Openvpn-devel] Documentation and alternative SSL backend > patches > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 02/12/10 10:05, Adriaan de Jong wrote: > >

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Davide Brini
On Thu, 02 Dec 2010 12:10:29 +0100 Matthias Andree wrote: > > most distro switch from openssl to nss. is there any reason you switch > > to polarssl in stead of nss? > > > > What do you base the "most distro" assessment on? > > Are you aware of any website discussing the advantages of the "big

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Matthias Andree
Am 02.12.2010 10:46, schrieb Farkas Levente: > On 12/02/2010 10:05 AM, Adriaan de Jong wrote: >> Hi List, >> >> We've been working on OpenVPN in preparation for a security evaluation. This >> entailed documenting OpenVPN at a relatively high level, removing the >> dependencies on OpenSSL, and a

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread David Sommerseth
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/12/10 10:05, Adriaan de Jong wrote: > Hi List, > > We've been working on OpenVPN in preparation for a security evaluation. This > entailed documenting OpenVPN at a relatively high level, removing the > dependencies on OpenSSL, and adding supp

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Adriaan de Jong
...@debuntu.org] Sent: donderdag 2 december 2010 11:20 To: Adriaan de Jong Cc: Farkas Levente; openvpn-devel@lists.sourceforge.net Subject: Re: [Openvpn-devel] Documentation and alternative SSL backend patches PolarSSL was a personal choice for us, mostly due to its simplicity and multi-platform

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread chantra
donderdag 2 december 2010 10:47 > > To: Adriaan de Jong > > Cc: openvpn-devel@lists.sourceforge.net > > Subject: Re: [Openvpn-devel] Documentation and alternative SSL backend > > patches > > > > On 12/02/2010 10:05 AM, Adriaan de Jong wrote: > > &

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Adriaan de Jong
Farkas Levente [mailto:lfar...@lfarkas.org] > Sent: donderdag 2 december 2010 10:47 > To: Adriaan de Jong > Cc: openvpn-devel@lists.sourceforge.net > Subject: Re: [Openvpn-devel] Documentation and alternative SSL backend > patches > > On 12/02/2010 10:05 AM, Adriaan de Jong wrote:

Re: [Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Farkas Levente
On 12/02/2010 10:05 AM, Adriaan de Jong wrote: > Hi List, > > We've been working on OpenVPN in preparation for a security evaluation. This > entailed documenting OpenVPN at a relatively high level, removing the > dependencies on OpenSSL, and adding support for a simpler, easier to evaluate > l

[Openvpn-devel] Documentation and alternative SSL backend patches

2010-12-02 Thread Adriaan de Jong
Hi List, We've been working on OpenVPN in preparation for a security evaluation. This entailed documenting OpenVPN at a relatively high level, removing the dependencies on OpenSSL, and adding support for a simpler, easier to evaluate library (PolarSSL). This was done in a series of patches: -