<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:www.nabble.com,2006:forum-978</id>
	<title>Nabble - OpenSSL</title>
	<updated>2008-07-06T06:29:51Z</updated>
	<link rel="self" type="application/atom+xml" href="http://www.nabble.com/OpenSSL-f978.xml" />
	<link rel="alternate" type="text/html" href="http://www.nabble.com/OpenSSL-f978.html" />
	<subtitle type="html">The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, full-featured, and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library. OpenSSL home is &lt;a href=&quot;http://www.openssl.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;here&lt;/a&gt;.</subtitle>
	
<entry>
	<id>tag:www.nabble.com,2006:post-18302206</id>
	<title>Re: PKI Application</title>
	<published>2008-07-06T06:29:51Z</published>
	<updated>2008-07-06T06:29:51Z</updated>
	<author>
		<name>Michael S. Zick-4</name>
	</author>
	<content type="html">On Sun July 6 2008 08:13, Mounir IDRASSI wrote:
&lt;br&gt;&amp;gt; You must also check for RootKits which are harder to detect and always run
&lt;br&gt;&amp;gt; under an account with no privilege.
&lt;br&gt;&amp;gt; As far as I am concerned, I will use Wine under Linux to try this executable.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;Wine inside a Linux-VServer context is even better.
&lt;br&gt;Test and then just rm -fr the entire instance.
&lt;br&gt;&lt;br&gt;Mike
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18302206&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18302206&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/OpenSSL-FIPS-Object-Module-v1.2-status-tp18297734p18302206.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18302002</id>
	<title>Re: PKI Application</title>
	<published>2008-07-06T06:13:56Z</published>
	<updated>2008-07-06T06:13:56Z</updated>
	<author>
		<name>Mounir IDRASSI</name>
	</author>
	<content type="html">You must also check for RootKits which are harder to detect and always run
&lt;br&gt;under an account with no privilege.
&lt;br&gt;As far as I am concerned, I will use Wine under Linux to try this executable.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Mounir IDRASSI
&lt;br&gt;IDRIX
&lt;br&gt;&lt;a href=&quot;http://www.idrix.fr&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.idrix.fr&lt;/a&gt;&lt;br&gt;&lt;br&gt;On Sun, July 6, 2008 2:54 pm, Jim Lynch wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Open an XP Vmware client, use it to test. When you're through run a decent
&lt;br&gt;&amp;gt; malware/virus detector to see if anything got infected. &amp;nbsp;If not, then you
&lt;br&gt;&amp;gt; may be OK.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Jim.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Sun, Jul 6, 2008 at 8:32 AM, Vishal Rao &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18302002&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;vishalrao@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Sun, Jul 6, 2008 at 4:48 PM, Hacker SF &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18302002&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sfhacker@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; You can download the soft from here:
&lt;br&gt;&amp;gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://www.limina.com.ar/Downloads/RosPKI-EN-Demo.exe&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.limina.com.ar/Downloads/RosPKI-EN-Demo.exe&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; LOL, asking users in a *security* list to download and run a random
&lt;br&gt;&amp;gt;&amp;gt; executable from the Internet and without source code, I wonder how
&lt;br&gt;&amp;gt;&amp;gt; many actually will go ahead with that...
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I've downloaded the EXE, is there any way/place I can get this
&lt;br&gt;&amp;gt;&amp;gt; analysed for malicious code, other than just scanning it with my
&lt;br&gt;&amp;gt;&amp;gt; installed anti-virus/anti-malware?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt; &amp;quot;Thou shalt not follow the null pointer for at its end madness and chaos
&lt;br&gt;&amp;gt;&amp;gt; lie.&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt; ______________________________________________________________________
&lt;br&gt;&amp;gt;&amp;gt; OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt; User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18302002&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18302002&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18302002&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18302002&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/OpenSSL-FIPS-Object-Module-v1.2-status-tp18297734p18302002.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18301847</id>
	<title>Re: PKI Application</title>
	<published>2008-07-06T05:54:55Z</published>
	<updated>2008-07-06T05:54:55Z</updated>
	<author>
		<name>AverageGuy</name>
	</author>
	<content type="html">Open an XP Vmware client, use it to test. When you&amp;#39;re through run a decent malware/virus detector to see if anything got infected.&amp;nbsp; If not, then you may be OK.&lt;br&gt;&lt;br&gt;Jim.&lt;br&gt;&lt;br&gt;&lt;div class=&quot;gmail_quote&quot;&gt;On Sun, Jul 6, 2008 at 8:32 AM, Vishal Rao &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18301847&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;vishalrao@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;
&lt;blockquote class=&quot;gmail_quote&quot; style=&quot;border-left: 1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;&quot;&gt;&lt;div class=&quot;Ih2E3d&quot;&gt;On Sun, Jul 6, 2008 at 4:48 PM, Hacker SF &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18301847&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sfhacker@...&lt;/a&gt;&amp;gt; wrote:&lt;br&gt;

&amp;gt; You can download the soft from here:&lt;br&gt;
&amp;gt; &lt;a href=&quot;http://www.limina.com.ar/Downloads/RosPKI-EN-Demo.exe&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.limina.com.ar/Downloads/RosPKI-EN-Demo.exe&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
&lt;/div&gt;LOL, asking users in a *security* list to download and run a random&lt;br&gt;
executable from the Internet and without source code, I wonder how&lt;br&gt;
many actually will go ahead with that...&lt;br&gt;
&lt;br&gt;
I&amp;#39;ve downloaded the EXE, is there any way/place I can get this&lt;br&gt;
analysed for malicious code, other than just scanning it with my&lt;br&gt;
installed anti-virus/anti-malware?&lt;br&gt;
&lt;font color=&quot;#888888&quot;&gt;&lt;br&gt;
--&lt;br&gt;
&amp;quot;Thou shalt not follow the null pointer for at its end madness and chaos lie.&amp;quot;&lt;br&gt;
______________________________________________________________________&lt;br&gt;
OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_blank&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;
User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18301847&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;&lt;br&gt;
Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18301847&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;&lt;br&gt;
&lt;/font&gt;&lt;/blockquote&gt;&lt;/div&gt;&lt;br&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/OpenSSL-FIPS-Object-Module-v1.2-status-tp18297734p18301847.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18301680</id>
	<title>Re: PKI Application</title>
	<published>2008-07-06T05:32:16Z</published>
	<updated>2008-07-06T05:32:16Z</updated>
	<author>
		<name>Vishal Rao</name>
	</author>
	<content type="html">On Sun, Jul 6, 2008 at 4:48 PM, Hacker SF &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18301680&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;sfhacker@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; You can download the soft from here:
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://www.limina.com.ar/Downloads/RosPKI-EN-Demo.exe&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.limina.com.ar/Downloads/RosPKI-EN-Demo.exe&lt;/a&gt;&lt;br&gt;&lt;br&gt;LOL, asking users in a *security* list to download and run a random
&lt;br&gt;executable from the Internet and without source code, I wonder how
&lt;br&gt;many actually will go ahead with that...
&lt;br&gt;&lt;br&gt;I've downloaded the EXE, is there any way/place I can get this
&lt;br&gt;analysed for malicious code, other than just scanning it with my
&lt;br&gt;installed anti-virus/anti-malware?
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&amp;quot;Thou shalt not follow the null pointer for at its end madness and chaos lie.&amp;quot;
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18301680&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18301680&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/OpenSSL-FIPS-Object-Module-v1.2-status-tp18297734p18301680.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18301129</id>
	<title>PKI Application</title>
	<published>2008-07-06T04:18:16Z</published>
	<updated>2008-07-06T04:18:16Z</updated>
	<author>
		<name>SFHacker</name>
	</author>
	<content type="html">&lt;html&gt;
&lt;head&gt;

&lt;/head&gt;
&lt;body class='hmmessage'&gt;
Hi All,&lt;BR&gt;&lt;BR&gt;I'm working on a GUI software application to OpenSSL for the Windows platform I'd like to share with you. It's not yet finished and I'd like your feedback on it regarding interface, functionality, etc. It supports OpenLDAP to store the certificates. I'd like to know if there is any other similar application I can download and test.&lt;BR&gt;&lt;BR&gt;
You can download the soft from here: &lt;A href=&quot;http://www.limina.com.ar/Downloads/RosPKI-EN-Demo.exe&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.limina.com.ar/Downloads/RosPKI-EN-Demo.exe&lt;/A&gt;&lt;BR&gt;
Thanks in advance.&lt;BR&gt;&lt;BR&gt;&lt;BR&gt;Sergio.&lt;BR&gt;&lt;BR&gt;&lt;br /&gt;&lt;hr /&gt;Sell your car for just $40 at CarPoint.com.au &lt;a href='http://a.ninemsn.com.au/b.aspx?URL=http%3A%2F%2Fsecure%2Dau%2Eimrworldwide%2Ecom%2Fcgi%2Dbin%2Fa%2Fci%5F450304%2Fet%5F2%2Fcg%5F801459%2Fpi%5F1004813%2Fai%5F859641&amp;_t=762955845&amp;_r=tig_OCT07&amp;_m=EXT' target='_new' rel=&quot;nofollow&quot;&gt;It's simple! &lt;/a&gt;&lt;/body&gt;
&lt;/html&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/OpenSSL-FIPS-Object-Module-v1.2-status-tp18297734p18301129.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18298414</id>
	<title>simple command line client</title>
	<published>2008-07-05T20:04:06Z</published>
	<updated>2008-07-05T20:04:06Z</updated>
	<author>
		<name>Lucito07</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I would like to know if any one knows of a simple command line client that can connect to a secure server using ssl, send a string of text, wait for a response and returns with that response. I know that with OpenSSL you can connect to the server using 'openssl s_client -connect remote.host:remote.port', but I would need to send the data and return with the response from a single command. Is that possible with OpenSSL directly, or is there a simple client that can do that?
&lt;br&gt;&lt;br&gt;Kindest regargs,
&lt;br&gt;&lt;br&gt;JLP&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---Dev-f980.html&quot; embed=&quot;fixTarget[980]&quot; target=&quot;_top&quot; &gt;OpenSSL - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/simple-command-line-client-tp18298414p18298414.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18297734</id>
	<title>OpenSSL FIPS Object Module v1.2 status</title>
	<published>2008-07-05T16:45:18Z</published>
	<updated>2008-07-05T16:45:18Z</updated>
	<author>
		<name>Steve Marquess</name>
	</author>
	<content type="html">I've received several requests for minor editorial changes to the draft 
&lt;br&gt;security policy for the v1.2 OpenSSL FIPS Object Module validation that 
&lt;br&gt;has been in process for a number of months now. &amp;nbsp;Based on past 
&lt;br&gt;experience those requests mean that the validation is now undergoing 
&lt;br&gt;active review and that the validation will *probably* be awarded in a 
&lt;br&gt;couple of weeks or so. &amp;nbsp;Emphasis on the &amp;quot;probably&amp;quot; -- I have been wrong 
&lt;br&gt;before.
&lt;br&gt;&lt;br&gt;-Steve M.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Steve Marquess
&lt;br&gt;Open Source Software institute
&lt;br&gt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18297734&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;marquess@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18297734&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18297734&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/OpenSSL-FIPS-Object-Module-v1.2-status-tp18297734p18297734.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18291710</id>
	<title>EC-Elgamal not work fine</title>
	<published>2008-07-05T03:06:56Z</published>
	<updated>2008-07-05T03:06:56Z</updated>
	<author>
		<name>Pietro Albano</name>
	</author>
	<content type="html">Hi all,
&lt;br&gt;I developed EC-Elgamal crypto schema, work fine till I use NIST
&lt;br&gt;Prime-Curve, but when I try to work on NIST Binary-Curve crypted point
&lt;br&gt;is egual to decrypted poit.
&lt;br&gt;&lt;br&gt;This is source code, pls help me :(
&lt;br&gt;&lt;br&gt;&lt;br&gt;#include &amp;lt;stdio.h&amp;gt;
&lt;br&gt;#include &amp;lt;stdlib.h&amp;gt;
&lt;br&gt;#include &amp;lt;string.h&amp;gt;
&lt;br&gt;&lt;br&gt;#include &amp;quot;../e_os.h&amp;quot;
&lt;br&gt;&lt;br&gt;#include &amp;lt;openssl/opensslconf.h&amp;gt;	/* for OPENSSL_NO_ECDH */
&lt;br&gt;#include &amp;lt;openssl/crypto.h&amp;gt;
&lt;br&gt;#include &amp;lt;openssl/bio.h&amp;gt;
&lt;br&gt;#include &amp;lt;openssl/bn.h&amp;gt;
&lt;br&gt;#include &amp;lt;openssl/objects.h&amp;gt;
&lt;br&gt;#include &amp;lt;openssl/rand.h&amp;gt;
&lt;br&gt;#include &amp;lt;openssl/sha.h&amp;gt;
&lt;br&gt;#include &amp;lt;openssl/err.h&amp;gt;
&lt;br&gt;&lt;br&gt;#ifdef OPENSSL_NO_ECDH
&lt;br&gt;&lt;br&gt;int main(int argc, char *argv[]) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; printf(&amp;quot;No ECDH support\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; return(0);
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;#else
&lt;br&gt;&lt;br&gt;#include &amp;lt;openssl/ec.h&amp;gt;
&lt;br&gt;#include &amp;lt;openssl/ecdh.h&amp;gt;
&lt;br&gt;&lt;br&gt;static const char rnd_seed[] = &amp;quot;21o4h32rfon4d3ornou53gnwqpegbnng&amp;quot;;
&lt;br&gt;&lt;br&gt;&lt;br&gt;static int test_ecdh_curve(int nid, const char *text, BN_CTX *ctx, BIO
&lt;br&gt;*out) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_KEY *a=NULL;
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_KEY *b=NULL;
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIGNUM *x_a=NULL, *y_a=NULL,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; *x_b=NULL, *y_b=NULL;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; int ret=0;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; const EC_GROUP *group;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT *M = NULL, *P = NULL, *R = NULL, *Q = NULL, *A = NULL, *B =
&lt;br&gt;NULL;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; a = EC_KEY_new_by_curve_name(nid);
&lt;br&gt;&amp;nbsp; &amp;nbsp; b = EC_KEY_new_by_curve_name(nid);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (a == NULL || b == NULL)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; group = EC_KEY_get0_group(a);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; if ((x_a=BN_new()) == NULL) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if ((y_a=BN_new()) == NULL) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if ((x_b=BN_new()) == NULL) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if ((y_b=BN_new()) == NULL) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_puts(out, &amp;quot;Testing key generation with &amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_puts(out, text);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_puts(out, &amp;quot;\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!EC_KEY_generate_key(a)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!EC_KEY_generate_key(b)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; P = EC_POINT_new(group);
&lt;br&gt;&amp;nbsp; &amp;nbsp; Q = EC_POINT_new(group);
&lt;br&gt;&amp;nbsp; &amp;nbsp; R = EC_POINT_new(group);
&lt;br&gt;&amp;nbsp; &amp;nbsp; A = EC_POINT_new(group);
&lt;br&gt;&amp;nbsp; &amp;nbsp; B = EC_POINT_new(group);
&lt;br&gt;&amp;nbsp; &amp;nbsp; M = EC_POINT_new(group);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_copy(P, EC_KEY_get0_public_key(a));
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_copy(Q, EC_KEY_get0_public_key(a));
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_copy(R, EC_KEY_get0_public_key(a));
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_copy(A, EC_KEY_get0_public_key(a));
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_copy(B, EC_KEY_get0_public_key(a));
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_copy(M, EC_KEY_get0_public_key(a));
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; /*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;* Q = a * P
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;*/
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_mul(group, Q, NULL, P, EC_KEY_get0_private_key(a), ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (EC_METHOD_get_field_type(EC_GROUP_method_of(group)) ==
&lt;br&gt;NID_X9_62_prime_field) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (!EC_POINT_get_affine_coordinates_GFp(group, P, x_a, y_a,
&lt;br&gt;ctx)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; }else {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (!EC_POINT_get_affine_coordinates_GF2m(group, P, x_a, y_a,
&lt;br&gt;ctx)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; }
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;Point P (x,y): &amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_print(out, x_a);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;,&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_print(out, y_a);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;\nkey a:\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;private key: &amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_print(out, EC_KEY_get0_private_key(a));
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;\nkey b:\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;private key: &amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_print(out, EC_KEY_get0_private_key(b));
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; /*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;* Encrypting message P because message must be in E
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;*/
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; /*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;* R = b * P
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;*/
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_mul(group, R, NULL, P, EC_KEY_get0_private_key(b), ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; /*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;* B = [b * a] * P
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;*/
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_mul(group, B, NULL, Q, EC_KEY_get0_private_key(b), ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; /*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;* B = P + [b * a] * P
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;*/
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_add(group, B, P, B, ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (EC_METHOD_get_field_type(EC_GROUP_method_of(group)) ==
&lt;br&gt;NID_X9_62_prime_field) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (!EC_POINT_get_affine_coordinates_GFp(group, B, x_a, y_a,
&lt;br&gt;ctx)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; }else {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (!EC_POINT_get_affine_coordinates_GF2m(group, B, x_a, y_a,
&lt;br&gt;ctx)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; }
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;Encrypted Point P (x,y): &amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_print(out, x_a);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;,&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_print(out, y_a);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; /*
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;* Decrypting message B = (bP, P + abP)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;*/
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_mul(group, R, NULL, R, EC_KEY_get0_private_key(a), ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_invert(group, R, ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; EC_POINT_add(group, B, B, R, ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (EC_METHOD_get_field_type(EC_GROUP_method_of(group)) ==
&lt;br&gt;NID_X9_62_prime_field) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (!EC_POINT_get_affine_coordinates_GFp(group, B, x_b, y_b,
&lt;br&gt;ctx)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; }else {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (!EC_POINT_get_affine_coordinates_GF2m(group, B, x_b, y_b,
&lt;br&gt;ctx)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; }
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;Decrypted point P (x,y): &amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_print(out, x_b);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;,&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_print(out, y_b);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_printf(out, &amp;quot;\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; ret=1;
&lt;br&gt;&amp;nbsp; &amp;nbsp; err:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ERR_print_errors_fp(stderr);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (y_a) BN_free(y_a);
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (x_b) BN_free(x_b);
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (y_b) BN_free(y_b);
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (b) EC_KEY_free(b);
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (a) EC_KEY_free(a);
&lt;br&gt;&amp;nbsp; &amp;nbsp; return(ret);
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;int main(int argc, char *argv[]) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; BN_CTX *ctx=NULL;
&lt;br&gt;&amp;nbsp; &amp;nbsp; int ret=1;
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO *out;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; RAND_seed(rnd_seed, sizeof rnd_seed);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; out=BIO_new(BIO_s_file());
&lt;br&gt;&amp;nbsp; &amp;nbsp; FILE* fp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if((fp=fopen(&amp;quot;keys&amp;quot;, &amp;quot;w&amp;quot;))==NULL) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; printf(&amp;quot;Error in fopen!\n&amp;quot;);
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; return 0;
&lt;br&gt;&amp;nbsp; &amp;nbsp; }
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (out == NULL) EXIT(1);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_set_fp(out, fp, BIO_NOCLOSE);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; if ((ctx=BN_CTX_new()) == NULL) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; /* NIST PRIME CURVES TESTS */
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_X9_62_prime192v1, &amp;quot;NIST Prime-Curve P-192&amp;quot;,
&lt;br&gt;ctx, out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_secp224r1, &amp;quot;NIST Prime-Curve P-224&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_X9_62_prime256v1, &amp;quot;NIST Prime-Curve P-256&amp;quot;,
&lt;br&gt;ctx, out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_secp384r1, &amp;quot;NIST Prime-Curve P-384&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_secp521r1, &amp;quot;NIST Prime-Curve P-521&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; /* NIST BINARY CURVES TESTS */
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect163k1, &amp;quot;NIST Binary-Curve K-163&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect163r2, &amp;quot;NIST Binary-Curve B-163&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect233k1, &amp;quot;NIST Binary-Curve K-233&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect233r1, &amp;quot;NIST Binary-Curve B-233&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect283k1, &amp;quot;NIST Binary-Curve K-283&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect283r1, &amp;quot;NIST Binary-Curve B-283&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect409k1, &amp;quot;NIST Binary-Curve K-409&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect409r1, &amp;quot;NIST Binary-Curve B-409&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect571k1, &amp;quot;NIST Binary-Curve K-571&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (!test_ecdh_curve(NID_sect571r1, &amp;quot;NIST Binary-Curve B-571&amp;quot;, ctx,
&lt;br&gt;out)) goto err;
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; ret = 0;
&lt;br&gt;&amp;nbsp; &amp;nbsp; fclose(fp);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;&amp;nbsp; &amp;nbsp; err:
&lt;br&gt;&amp;nbsp; &amp;nbsp; ERR_print_errors_fp(stderr);
&lt;br&gt;&amp;nbsp; &amp;nbsp; if (ctx) BN_CTX_free(ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; BIO_free(out);
&lt;br&gt;&amp;nbsp; &amp;nbsp; CRYPTO_cleanup_all_ex_data();
&lt;br&gt;&amp;nbsp; &amp;nbsp; ERR_remove_state(0);
&lt;br&gt;&amp;nbsp; &amp;nbsp; CRYPTO_mem_leaks_fp(stderr);
&lt;br&gt;&amp;nbsp; &amp;nbsp; EXIT(ret);
&lt;br&gt;&amp;nbsp; &amp;nbsp; return(ret);
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;#endif
&lt;br&gt;&lt;br&gt;&lt;br&gt;output :
&lt;br&gt;&lt;br&gt;Testing key generation with NIST Binary-Curve K-163
&lt;br&gt;&lt;br&gt;Point P (x,y):
&lt;br&gt;2DC0A8BAAE6199F6603FA504361685B4255C6D03F,6BD43B113FCFFD7B18CF9EA4A696AB81E217E955F
&lt;br&gt;&lt;br&gt;key a:
&lt;br&gt;&lt;br&gt;private key: B0DB552C7D8B09776B9669F4524BAA10F08A46BA
&lt;br&gt;&lt;br&gt;key b:
&lt;br&gt;&lt;br&gt;private key: 3D2AF43E0B858AC1F97D5224FE1C446F610F907DE
&lt;br&gt;&lt;br&gt;Encrypted Point P (x,y):
&lt;br&gt;38DE7188633292F192689530F9890F26629C7217B,7E7270D2AE583D5CEFAA4A1CB09770CF830BE3213
&lt;br&gt;&lt;br&gt;Decrypted point P (x,y):
&lt;br&gt;38DE7188633292F192689530F9890F26629C7217B,7E7270D2AE583D5CEFAA4A1CB09770CF830BE3213
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18291710&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18291710&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/EC-Elgamal-not-work-fine-tp18291710p18291710.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18289569</id>
	<title>How to generate bilinear map</title>
	<published>2008-07-04T21:58:14Z</published>
	<updated>2008-07-04T21:58:14Z</updated>
	<author>
		<name>Pietro Albano</name>
	</author>
	<content type="html">Hi all,
&lt;br&gt;Who can help me to generate bilinear map? 
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18289569&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18289569&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/How-to-generate-bilinear-map-tp18289569p18289569.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18286235</id>
	<title>Re: [openssl.org #1709] DTLS BUG: retransmition of handshake messages does not work</title>
	<published>2008-07-04T13:25:51Z</published>
	<updated>2008-07-04T13:25:51Z</updated>
	<author>
		<name>Ariel Salomon via RT</name>
	</author>
	<content type="html">&lt;br&gt;The DTLS code makes some assumptions that it is using a UDP socket BIO 
&lt;br&gt;to detect the timeout condition for resend.
&lt;br&gt;&lt;br&gt;When using another BIO type (e.g. BIO pair) on read, this does not work 
&lt;br&gt;properly.
&lt;br&gt;&lt;br&gt;&amp;nbsp; - Ariel
&lt;br&gt;&lt;br&gt;Pavel via RT wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; This problem was described by Martin Vladic, but i cant find it in RT.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Here is description:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;quot;Let's suppose that handshake between client and server comes to the
&lt;br&gt;&amp;gt; point where client sends this message flight to the server:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Certificate
&lt;br&gt;&amp;gt; ClientKeyExchange
&lt;br&gt;&amp;gt; CertificateVerify
&lt;br&gt;&amp;gt; ChangeCipherSpec
&lt;br&gt;&amp;gt; Finished [this message is protected]
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; So, client comes to the stage when all subsequent messages shall be
&lt;br&gt;&amp;gt; protected. In above message flight only last message (Finished) is
&lt;br&gt;&amp;gt; protected. First four messages are unprotected. That's all OK.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; To continue, client needs following response from the server:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ChangeCipherSpec
&lt;br&gt;&amp;gt; Finished [this message is encrypted]
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; What happens if such message doesn't arrive? Retransmission timer
&lt;br&gt;&amp;gt; expires and client must send last flight again.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; But, OpenSSL DTLS implementation doesn't handle this situation very
&lt;br&gt;&amp;gt; well. It sends the last flight of messages, but all messages are
&lt;br&gt;&amp;gt; protected because implementation thinks that CipherSpec and keys are
&lt;br&gt;&amp;gt; negotiated. I think that only last message must be protected, and
&lt;br&gt;&amp;gt; first four must not (like it was in first transmission of the same
&lt;br&gt;&amp;gt; flight).&amp;quot;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Also, when client retransmits his last flight (5 messages), message
&lt;br&gt;&amp;gt; &amp;quot;retransmit: &amp;nbsp;message 4 non-existant&amp;quot; is printed to stderr.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Even if client resends correct last flight (encrypting only Finished
&lt;br&gt;&amp;gt; message),
&lt;br&gt;&amp;gt; server will not retransmit his last flight (2 messages).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Pavel
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ______________________________________________________________________
&lt;br&gt;&amp;gt; OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;&amp;gt; Development Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18286235&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-dev@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18286235&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&amp;nbsp;- Ariel Salomon / Senior Software Engineer
&lt;br&gt;Real-Time Innovations (RTI) / www.rti.com
&lt;br&gt;408 990-7439 / &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18286235&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ariel@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;RTI - The Real-Time Middleware Experts
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;Development Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18286235&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-dev@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18286235&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---Dev-f980.html&quot; embed=&quot;fixTarget[980]&quot; target=&quot;_top&quot; &gt;OpenSSL - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/-openssl.org--1709--DTLS-BUG%3A-retransmition-of-handshake-messages-does-not-work-tp18274187p18286235.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18283852</id>
	<title>RE: Subtract betwen two EC_POINT</title>
	<published>2008-07-04T10:56:57Z</published>
	<updated>2008-07-04T10:56:57Z</updated>
	<author>
		<name>Bill Colvin</name>
	</author>
	<content type="html">Pietro: &amp;nbsp;OpenSSL seems to provide add, double, invert and multiply
&lt;br&gt;routines for EC points. &amp;nbsp;There does not seem to be an explicit routine
&lt;br&gt;for subtract in the include files.
&lt;br&gt;&lt;br&gt;The book &amp;quot;Implementing Eliptic Curve Cryptography&amp;quot; by Michael Rosing has
&lt;br&gt;routines esub and poly_esub for doing a subtraction of two EC points
&lt;br&gt;depending on the type of underlying curve. &amp;nbsp;Essentially these routines
&lt;br&gt;first perform a negation of the subtrahend followed by an addition.
&lt;br&gt;&lt;br&gt;Bill
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18283852&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;owner-openssl-users@...&lt;/a&gt;
&lt;br&gt;[mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18283852&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;owner-openssl-users@...&lt;/a&gt;] On Behalf Of Pietro Albano
&lt;br&gt;Sent: July 4, 2008 10:17 AM
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18283852&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Subject: Subtract betwen two EC_POINT
&lt;br&gt;&lt;br&gt;Hi all,
&lt;br&gt;I'm newby on openssl coding, I developing Elgamal chiper , i need
&lt;br&gt;subtract two EC_POINT who can help me?
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18283852&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18283852&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18283852&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18283852&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Subtract-betwen-two-EC_POINT-tp18282460p18283852.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18284275</id>
	<title>RE: Subtract betwen two EC_POINT</title>
	<published>2008-07-04T09:31:06Z</published>
	<updated>2008-07-04T09:31:06Z</updated>
	<author>
		<name>Pietro Albano</name>
	</author>
	<content type="html">Thanks for the interest, i resolved with EC_POINT_invert().
&lt;br&gt;&lt;br&gt;EC-Elgamal work fine :)
&lt;br&gt;&lt;br&gt;Il giorno ven, 04/07/2008 alle 11.56 -0600, Bill Colvin ha scritto:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Pietro: &amp;nbsp;OpenSSL seems to provide add, double, invert and multiply
&lt;br&gt;&amp;gt; routines for EC points. &amp;nbsp;There does not seem to be an explicit routine
&lt;br&gt;&amp;gt; for subtract in the include files.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The book &amp;quot;Implementing Eliptic Curve Cryptography&amp;quot; by Michael Rosing has
&lt;br&gt;&amp;gt; routines esub and poly_esub for doing a subtraction of two EC points
&lt;br&gt;&amp;gt; depending on the type of underlying curve. &amp;nbsp;Essentially these routines
&lt;br&gt;&amp;gt; first perform a negation of the subtrahend followed by an addition.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Bill
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; -----Original Message-----
&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;owner-openssl-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt; [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;owner-openssl-users@...&lt;/a&gt;] On Behalf Of Pietro Albano
&lt;br&gt;&amp;gt; Sent: July 4, 2008 10:17 AM
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Subtract betwen two EC_POINT
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt; I'm newby on openssl coding, I developing Elgamal chiper , i need
&lt;br&gt;&amp;gt; subtract two EC_POINT who can help me?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ______________________________________________________________________
&lt;br&gt;&amp;gt; OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;&amp;gt; User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&amp;gt; ______________________________________________________________________
&lt;br&gt;&amp;gt; OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;&amp;gt; User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;/div&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18284275&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Subtract-betwen-two-EC_POINT-tp18282460p18284275.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18282460</id>
	<title>Subtract betwen two EC_POINT</title>
	<published>2008-07-04T07:16:56Z</published>
	<updated>2008-07-04T07:16:56Z</updated>
	<author>
		<name>Pietro Albano</name>
	</author>
	<content type="html">Hi all,
&lt;br&gt;I'm newby on openssl coding, I developing Elgamal chiper , i need
&lt;br&gt;subtract two EC_POINT who can help me?
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18282460&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18282460&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Subtract-betwen-two-EC_POINT-tp18282460p18282460.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18292988</id>
	<title>Modifying the cipher in OpenSSL for TLS</title>
	<published>2008-07-04T03:20:32Z</published>
	<updated>2008-07-04T03:20:32Z</updated>
	<author>
		<name>Shridhar</name>
	</author>
	<content type="html">Hi All,
&lt;br&gt;&lt;br&gt;I want to use TLS_RSA_WITH_AES_128_CBC_SHA cipher for
encrypting the application data in TLS. &amp;nbsp;But, OpenSSL negotiates this
encryption algorithm to be used(selected cipher in ServerHello) based
on the first common algorithm presented by the client in ClientHello
message. &amp;nbsp;Since I want to test the TLS_RSA_WITH_AES_128_CBC_SHA
algorithm, could anyone please let me know how to make
TLS_RSA_WITH_AES_128_CBC_SHA as the default(force to use)?
&lt;br&gt;&lt;br&gt;Thanks a lot in advance,
&lt;br&gt;&lt;br&gt;Shridhar.
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Modifying-the-cipher-in-OpenSSL-for-TLS-tp18292988p18292988.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18276721</id>
	<title>Modifying the cipher in OpenSSL for TLS</title>
	<published>2008-07-04T03:16:10Z</published>
	<updated>2008-07-04T03:16:10Z</updated>
	<author>
		<name>Shridhar</name>
	</author>
	<content type="html">Hi All,
&lt;br&gt;&lt;br&gt;I want to use TLS_RSA_WITH_AES_128_CBC_SHA cipher for encrypting the application data in TLS. &amp;nbsp;But, OpenSSL negotiates this encryption algorithm to be used(selected cipher in ServerHello) based on the first common algorithm presented by the client in ClientHello message. &amp;nbsp;Since I want to test the TLS_RSA_WITH_AES_128_CBC_SHA algorithm, could anyone please let me know how to make TLS_RSA_WITH_AES_128_CBC_SHA as the default(force to use)?
&lt;br&gt;&lt;br&gt;Thanks a lot in advance,
&lt;br&gt;&lt;br&gt;Shridhar.&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Modifying-the-cipher-in-OpenSSL-for-TLS-tp18276721p18276721.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18274601</id>
	<title>Re: [FWD] Not able to use openssl</title>
	<published>2008-07-04T00:37:54Z</published>
	<updated>2008-07-04T00:37:54Z</updated>
	<author>
		<name>Thomas J. Hruska</name>
	</author>
	<content type="html">Lutz Jaenicke wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Forwareded to openssl-users for public discussion
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Best regards,
&lt;br&gt;&amp;gt; 	Lutz
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; ----- Forwarded message from Satya Narayan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274601&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;satya.tailor@...&lt;/a&gt;&amp;gt; -----
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
&lt;br&gt;&amp;gt; 	d=gmail.com; s=gamma;
&lt;br&gt;&amp;gt; 	h=domainkey-signature:received:received:message-id:date:from:to
&lt;br&gt;&amp;gt; 	:subject:mime-version:content-type;
&lt;br&gt;&amp;gt; 	bh=Yvc6CBMi1XB9hiQM+9Mo/A9oXYcu+HfjaMI3XLLMLt0=;
&lt;br&gt;&amp;gt; 	b=IDKXR2yk6MKxDtLZugwdLbjbPehvOx9UycmLMUvKvJAuW8qCdHmWCW8/D9pm+sKt/P
&lt;br&gt;&amp;gt; 	MsoEE5qLLVL/WTiTnj1GurBR+F2eiri4YyMpWDyCC4xUaVgnRpkSXWHF3JpBSp4CF7Hn
&lt;br&gt;&amp;gt; 	Xp0GPfsW1Ffrmk9ISDK31J9dD89brhWJy/22s=
&lt;br&gt;&amp;gt; DomainKey-Signature: a=rsa-sha1; c=nofws;
&lt;br&gt;&amp;gt; 	d=gmail.com; s=gamma;
&lt;br&gt;&amp;gt; 	h=message-id:date:from:to:subject:mime-version:content-type;
&lt;br&gt;&amp;gt; 	b=mqQZ2rjxCTMOHUeMuJgq+31i9cbgx2ZRpuFBi/JDl7BaFBHyxl/HFI8JnWhSi4QTGu
&lt;br&gt;&amp;gt; 	8QczVwLhs4XNJuX7vFeuiFm/JermjMD76A8wci4Q25zWUtL4Gz1zYFdc3eb7LtNxWw6O
&lt;br&gt;&amp;gt; 	BtUv+aetnf0WOrrUT9bdaLDBasvVoDq5fb8DI=
&lt;br&gt;&amp;gt; Date: Tue, 1 Jul 2008 17:12:41 +0200
&lt;br&gt;&amp;gt; From: Satya Narayan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274601&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;satya.tailor@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274601&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-bugs@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Not able to use openssl
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; i have downloaded OpenSSL'Win32 OpenSSL
&lt;br&gt;&amp;gt; v0.9.8h&amp;lt;&lt;a href=&quot;http://www.slproweb.com/download/Win32OpenSSL-0_9_8h.exe&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.slproweb.com/download/Win32OpenSSL-0_9_8h.exe&lt;/a&gt;&amp;gt;'
&lt;br&gt;&amp;gt; for windows(XP) and installed on my local machine, now i am trying to open
&lt;br&gt;&amp;gt; 'openSSL.exe' &amp;nbsp;from command prompt it is giving the error like: the
&lt;br&gt;&amp;gt; application has failed to start, the application configuration is incorrect.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Is there any system requirement VC++ ?
&lt;br&gt;&amp;gt; or
&lt;br&gt;&amp;gt; any extra thingy i need to perform? Please help me out
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks &amp; Regards
&lt;br&gt;&amp;gt; Satya N Tailor
&lt;/div&gt;&lt;br&gt;Install the VC++ 2008 Redistributable. &amp;nbsp;There happens to be a link right 
&lt;br&gt;below the link you used to download 0.9.8h.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Thomas Hruska
&lt;br&gt;Shining Light Productions
&lt;br&gt;&lt;br&gt;Home of BMP2AVI, Nuclear Vision, ProtoNova, and Win32 OpenSSL.
&lt;br&gt;&lt;a href=&quot;http://www.slproweb.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.slproweb.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274601&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274601&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/-FWD--Not-able-to-use-openssl-tp18274221p18274601.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18274580</id>
	<title>Re: [FWD] openssl command propt</title>
	<published>2008-07-04T00:35:53Z</published>
	<updated>2008-07-04T00:35:53Z</updated>
	<author>
		<name>Thomas J. Hruska</name>
	</author>
	<content type="html">Lutz Jaenicke wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Forwarded to openssl-users for public discussion
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Best regards,
&lt;br&gt;&amp;gt; 	Lutz
&lt;br&gt;&amp;gt; ----- Forwarded message from richard jonik &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274580&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gybe_again@...&lt;/a&gt;&amp;gt; -----
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
&lt;br&gt;&amp;gt; 	s=s1024; d=yahoo.com;
&lt;br&gt;&amp;gt; 	h=Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type:Conte
&lt;br&gt;&amp;gt; 	nt-Transfer-Encoding:Message-ID;
&lt;br&gt;&amp;gt; 	b=vBBzEPZaiZTIah8JHRbzeAxZJVAr0wUKpTQtpm8NPuq2kS5PXMll/twaYA909NIud5TxJV
&lt;br&gt;&amp;gt; 	mTNcygBfqD9MEbJv6OukLsdWu0RbxiYewUoRFEWWR+ASvYbdvhiu8Hrdsua5VEY7SH9sL3eZ
&lt;br&gt;&amp;gt; 	AcQPtdnpq08UmGxyvkpDyDkSLSzxY=;
&lt;br&gt;&amp;gt; Date: Tue, 1 Jul 2008 13:19:07 -0700 (PDT)
&lt;br&gt;&amp;gt; From: richard jonik &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274580&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gybe_again@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Subject: openssl command propt
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274580&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-bugs@...&lt;/a&gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; i am trying to use the a sandbox account with paypal.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; my command propt wont allow me to enter a password at all !
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; for:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; openssl pkcs12 -export -in cert_key_pem.txt -out fileout.p12
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; when asked for the password my keyboard is completely frozen.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; this also happens for
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; passwd -1
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; i have tried all versions and cannot get this to work?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; how frustrating.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; any ideas.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; version 0.9.8g 19 oct 2007.
&lt;/div&gt;&lt;br&gt;Your keyboard probably isn't frozen. &amp;nbsp;There is no visual feedback when 
&lt;br&gt;entering a password. &amp;nbsp;Type in a password and press enter.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Thomas Hruska
&lt;br&gt;Shining Light Productions
&lt;br&gt;&lt;br&gt;Home of BMP2AVI, Nuclear Vision, ProtoNova, and Win32 OpenSSL.
&lt;br&gt;&lt;a href=&quot;http://www.slproweb.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.slproweb.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274580&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274580&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/-FWD--openssl-command-propt-tp18274239p18274580.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18274367</id>
	<title>Re: [FWD] openssl command propt</title>
	<published>2008-07-04T00:29:19Z</published>
	<updated>2008-07-04T00:29:19Z</updated>
	<author>
		<name>wolfoftheair</name>
	</author>
	<content type="html">Need information on the environment (NT, or which version of *nix).
&lt;br&gt;&lt;br&gt;For *nix, try running 'stty sane', and then also try hitting ctrl+j
&lt;br&gt;and ctrl+m as alternatives to your 'enter' key.
&lt;br&gt;&lt;br&gt;Also, openssl allows you to put the passphrase into an environment
&lt;br&gt;variable if necessary.
&lt;br&gt;&lt;br&gt;The fact that passwd gives the same result makes me think that it is
&lt;br&gt;simply terminal misconfiguration.
&lt;br&gt;&lt;br&gt;-Kyle H
&lt;br&gt;&lt;br&gt;On Thu, Jul 3, 2008 at 11:15 PM, Lutz Jaenicke &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jaenicke@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Forwarded to openssl-users for public discussion
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Best regards,
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Lutz
&lt;br&gt;&amp;gt; ----- Forwarded message from richard jonik &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gybe_again@...&lt;/a&gt;&amp;gt; -----
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;s=s1024; d=yahoo.com;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;h=Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type:Conte
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;nt-Transfer-Encoding:Message-ID;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;b=vBBzEPZaiZTIah8JHRbzeAxZJVAr0wUKpTQtpm8NPuq2kS5PXMll/twaYA909NIud5TxJV
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;mTNcygBfqD9MEbJv6OukLsdWu0RbxiYewUoRFEWWR+ASvYbdvhiu8Hrdsua5VEY7SH9sL3eZ
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AcQPtdnpq08UmGxyvkpDyDkSLSzxY=;
&lt;br&gt;&amp;gt; Date: Tue, 1 Jul 2008 13:19:07 -0700 (PDT)
&lt;br&gt;&amp;gt; From: richard jonik &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gybe_again@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Subject: openssl command propt
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-bugs@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; i am trying to use the a sandbox account with paypal.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; my command propt wont allow me to enter a password at all !
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; for:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; openssl pkcs12 -export -in cert_key_pem.txt -out fileout.p12
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; when asked for the password my keyboard is completely frozen.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; this also happens for
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; passwd -1
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; i have tried all versions and cannot get this to work?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; how frustrating.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; any ideas.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; version 0.9.8g 19 oct 2007.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp;__________________________________________________________
&lt;br&gt;&amp;gt; Not happy with your email address?.
&lt;br&gt;&amp;gt; Get the one you really want - millions of new email addresses available now at Yahoo! &lt;a href=&quot;http://uk.docs.yahoo.com/ymail/new.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://uk.docs.yahoo.com/ymail/new.html&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ----- End forwarded message -----
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Lutz Jaenicke &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jaenicke@...&lt;/a&gt;
&lt;br&gt;&amp;gt; OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org/~jaenicke/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org/~jaenicke/&lt;/a&gt;&lt;br&gt;&amp;gt; ______________________________________________________________________
&lt;br&gt;&amp;gt; OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;&amp;gt; User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&amp;gt;
&lt;/div&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274367&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/-FWD--openssl-command-propt-tp18274239p18274367.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18274168</id>
	<title>command smime and RFC 3851</title>
	<published>2008-07-04T00:03:41Z</published>
	<updated>2008-07-04T00:03:41Z</updated>
	<author>
		<name>Gabor Kiss-3</name>
	</author>
	<content type="html">Dear folks,
&lt;br&gt;&lt;br&gt;I created X.509 signed mail by an application then I tried to verify
&lt;br&gt;signature by 'openssl smime -verify ...' command.
&lt;br&gt;&lt;br&gt;It did not work first time.
&lt;br&gt;&lt;br&gt;S/MIME standard RFC 3851 and predecessors show a sample
&lt;br&gt;multipart/signed message in section 3.4.3.3.:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Type: multipart/signed;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; protocol=&amp;quot;application/pkcs7-signature&amp;quot;;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; micalg=sha1; boundary=boundary42
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;--boundary42
&lt;br&gt;--&amp;gt; &amp;nbsp; &amp;nbsp;Content-Type: text/plain
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;This is a clear-signed message.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;--boundary42
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Type: application/pkcs7-signature; name=smime.p7s
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Transfer-Encoding: base64
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Disposition: attachment; filename=smime.p7s
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;ghyHhHUujhJhjH77n8HHGTrfvbnj756tbB9HG4VQpfyF467GhIGfHfYT6
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4VQpfyF467GhIGfHfYT6jH77n8HHGghyHhHUujhJh756tbB9HGTrfvbnj
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;n8HHGTrfvhJhjH776tbB9HG4VQbnj7567GhIGfHfYT6ghyHhHUujpfyF4
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7GhIGfHfYT64VQbnj756
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;--boundary42--
&lt;br&gt;&lt;br&gt;See the marked MIME sub-header in part2. My application that uses
&lt;br&gt;MIME::Tools PERL library produces similar format:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Type: multipart/signed;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; protocol=&amp;quot;application/pkcs7-signature&amp;quot;;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; micalg=sha1;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; boundary=&amp;quot;----------=_1215093708-16004-0&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Transfer-Encoding: binary
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;MIME-Version: 1.0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;X-Mailer: MIME-tools 5.420 (Entity 5.420)
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;From: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274168&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;me@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274168&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;you@...&lt;/a&gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Subject: Hello, nurse!
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;This is an S/MIME signed message
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;------------=_1215093708-16004-0
&lt;br&gt;--&amp;gt; &amp;nbsp; &amp;nbsp;Content-Type: text/plain
&lt;br&gt;--&amp;gt; &amp;nbsp; &amp;nbsp;Content-Disposition: inline
&lt;br&gt;--&amp;gt; &amp;nbsp; &amp;nbsp;Content-Transfer-Encoding: binary
&lt;br&gt;--&amp;gt;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;This is a message
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;------------=_1215093708-16004-0
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Type: application/pkcs7-signature; name=&amp;quot;signature-cr.p7s&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Disposition: attachment; filename=&amp;quot;signature-cr.p7s&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;Content-Transfer-Encoding: base64
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;MIAGCSqGSIb3DQEHAqCAMIACAQExCzAJBgUrDgMCGgUAMIAGCSqGSIb3DQEH
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;AQAAoIIFbjCCBWowggRSoAMCAQICAgNWMA0GCSqGSIb3DQEBBQUAMFUxCzAJ
&lt;br&gt;...
&lt;br&gt;&lt;br&gt;I found that 'openssl smime' refuses to verify signature until I
&lt;br&gt;delete the marked lines. Probably it computes hash not only the
&lt;br&gt;cleartext but on header and separator too.
&lt;br&gt;&lt;br&gt;Is this normal?
&lt;br&gt;Why openssl could not figure out where the cleartext begins?
&lt;br&gt;&lt;br&gt;Gabor
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274168&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274168&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/command-smime-and-RFC-3851-tp18274168p18274168.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18274187</id>
	<title>[openssl.org #1709] DTLS BUG: retransmition of handshake messages does not work</title>
	<published>2008-07-03T23:18:46Z</published>
	<updated>2008-07-03T23:18:46Z</updated>
	<author>
		<name>Ariel Salomon via RT</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;This problem was described by Martin Vladic, but i cant find it in RT.
&lt;br&gt;&lt;br&gt;Here is description:
&lt;br&gt;&lt;br&gt;&amp;quot;Let's suppose that handshake between client and server comes to the
&lt;br&gt;point where client sends this message flight to the server:
&lt;br&gt;&lt;br&gt;Certificate
&lt;br&gt;ClientKeyExchange
&lt;br&gt;CertificateVerify
&lt;br&gt;ChangeCipherSpec
&lt;br&gt;Finished [this message is protected]
&lt;br&gt;&lt;br&gt;So, client comes to the stage when all subsequent messages shall be
&lt;br&gt;protected. In above message flight only last message (Finished) is
&lt;br&gt;protected. First four messages are unprotected. That's all OK.
&lt;br&gt;&lt;br&gt;To continue, client needs following response from the server:
&lt;br&gt;&lt;br&gt;ChangeCipherSpec
&lt;br&gt;Finished [this message is encrypted]
&lt;br&gt;&lt;br&gt;What happens if such message doesn't arrive? Retransmission timer
&lt;br&gt;expires and client must send last flight again.
&lt;br&gt;&lt;br&gt;But, OpenSSL DTLS implementation doesn't handle this situation very
&lt;br&gt;well. It sends the last flight of messages, but all messages are
&lt;br&gt;protected because implementation thinks that CipherSpec and keys are
&lt;br&gt;negotiated. I think that only last message must be protected, and
&lt;br&gt;first four must not (like it was in first transmission of the same
&lt;br&gt;flight).&amp;quot;
&lt;br&gt;&lt;br&gt;Also, when client retransmits his last flight (5 messages), message
&lt;br&gt;&amp;quot;retransmit: &amp;nbsp;message 4 non-existant&amp;quot; is printed to stderr.
&lt;br&gt;&lt;br&gt;Even if client resends correct last flight (encrypting only Finished 
&lt;br&gt;message),
&lt;br&gt;server will not retransmit his last flight (2 messages).
&lt;br&gt;&lt;br&gt;Pavel
&lt;br&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;Development Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274187&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-dev@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274187&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---Dev-f980.html&quot; embed=&quot;fixTarget[980]&quot; target=&quot;_top&quot; &gt;OpenSSL - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/-openssl.org--1709--DTLS-BUG%3A-retransmition-of-handshake-messages-does-not-work-tp18274187p18274187.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18274239</id>
	<title>[FWD] openssl command propt</title>
	<published>2008-07-03T23:15:53Z</published>
	<updated>2008-07-03T23:15:53Z</updated>
	<author>
		<name>Lutz Jaenicke-3</name>
	</author>
	<content type="html">Forwarded to openssl-users for public discussion
&lt;br&gt;&lt;br&gt;Best regards,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Lutz
&lt;br&gt;----- Forwarded message from richard jonik &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274239&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gybe_again@...&lt;/a&gt;&amp;gt; -----
&lt;br&gt;&lt;br&gt;DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; s=s1024; d=yahoo.com;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; h=Received:X-Mailer:Date:From:Subject:To:MIME-Version:Content-Type:Conte
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; nt-Transfer-Encoding:Message-ID;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; b=vBBzEPZaiZTIah8JHRbzeAxZJVAr0wUKpTQtpm8NPuq2kS5PXMll/twaYA909NIud5TxJV
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; mTNcygBfqD9MEbJv6OukLsdWu0RbxiYewUoRFEWWR+ASvYbdvhiu8Hrdsua5VEY7SH9sL3eZ
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; AcQPtdnpq08UmGxyvkpDyDkSLSzxY=;
&lt;br&gt;Date: Tue, 1 Jul 2008 13:19:07 -0700 (PDT)
&lt;br&gt;From: richard jonik &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274239&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;gybe_again@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Subject: openssl command propt
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274239&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-bugs@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;i am trying to use the a sandbox account with paypal.
&lt;br&gt;&lt;br&gt;my command propt wont allow me to enter a password at all !
&lt;br&gt;&lt;br&gt;for:
&lt;br&gt;&lt;br&gt;openssl pkcs12 -export -in cert_key_pem.txt -out fileout.p12
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;when asked for the password my keyboard is completely frozen.
&lt;br&gt;&lt;br&gt;this also happens for
&lt;br&gt;&lt;br&gt;passwd -1
&lt;br&gt;&lt;br&gt;&lt;br&gt;i have tried all versions and cannot get this to work?
&lt;br&gt;&lt;br&gt;how frustrating.
&lt;br&gt;&lt;br&gt;any ideas.
&lt;br&gt;&lt;br&gt;version 0.9.8g 19 oct 2007.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; __________________________________________________________
&lt;br&gt;Not happy with your email address?.
&lt;br&gt;Get the one you really want - millions of new email addresses available now at Yahoo! &lt;a href=&quot;http://uk.docs.yahoo.com/ymail/new.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://uk.docs.yahoo.com/ymail/new.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;----- End forwarded message -----
&lt;br&gt;--
&lt;br&gt;Lutz Jaenicke &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274239&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jaenicke@...&lt;/a&gt;
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org/~jaenicke/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org/~jaenicke/&lt;/a&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274239&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274239&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/-FWD--openssl-command-propt-tp18274239p18274239.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18274221</id>
	<title>[FWD] Not able to use openssl</title>
	<published>2008-07-03T23:15:01Z</published>
	<updated>2008-07-03T23:15:01Z</updated>
	<author>
		<name>Lutz Jaenicke-3</name>
	</author>
	<content type="html">Forwareded to openssl-users for public discussion
&lt;br&gt;&lt;br&gt;Best regards,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Lutz
&lt;br&gt;&lt;br&gt;----- Forwarded message from Satya Narayan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274221&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;satya.tailor@...&lt;/a&gt;&amp;gt; -----
&lt;br&gt;&lt;br&gt;DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; d=gmail.com; s=gamma;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; h=domainkey-signature:received:received:message-id:date:from:to
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; :subject:mime-version:content-type;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; bh=Yvc6CBMi1XB9hiQM+9Mo/A9oXYcu+HfjaMI3XLLMLt0=;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; b=IDKXR2yk6MKxDtLZugwdLbjbPehvOx9UycmLMUvKvJAuW8qCdHmWCW8/D9pm+sKt/P
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; MsoEE5qLLVL/WTiTnj1GurBR+F2eiri4YyMpWDyCC4xUaVgnRpkSXWHF3JpBSp4CF7Hn
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Xp0GPfsW1Ffrmk9ISDK31J9dD89brhWJy/22s=
&lt;br&gt;DomainKey-Signature: a=rsa-sha1; c=nofws;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; d=gmail.com; s=gamma;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; h=message-id:date:from:to:subject:mime-version:content-type;
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; b=mqQZ2rjxCTMOHUeMuJgq+31i9cbgx2ZRpuFBi/JDl7BaFBHyxl/HFI8JnWhSi4QTGu
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 8QczVwLhs4XNJuX7vFeuiFm/JermjMD76A8wci4Q25zWUtL4Gz1zYFdc3eb7LtNxWw6O
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; BtUv+aetnf0WOrrUT9bdaLDBasvVoDq5fb8DI=
&lt;br&gt;Date: Tue, 1 Jul 2008 17:12:41 +0200
&lt;br&gt;From: Satya Narayan &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274221&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;satya.tailor@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274221&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-bugs@...&lt;/a&gt;
&lt;br&gt;Subject: Not able to use openssl
&lt;br&gt;&lt;br&gt;Hi
&lt;br&gt;&lt;br&gt;i have downloaded OpenSSL'Win32 OpenSSL
&lt;br&gt;v0.9.8h&amp;lt;&lt;a href=&quot;http://www.slproweb.com/download/Win32OpenSSL-0_9_8h.exe&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.slproweb.com/download/Win32OpenSSL-0_9_8h.exe&lt;/a&gt;&amp;gt;'
&lt;br&gt;for windows(XP) and installed on my local machine, now i am trying to open
&lt;br&gt;'openSSL.exe' &amp;nbsp;from command prompt it is giving the error like: the
&lt;br&gt;application has failed to start, the application configuration is incorrect.
&lt;br&gt;&lt;br&gt;Is there any system requirement VC++ ?
&lt;br&gt;or
&lt;br&gt;any extra thingy i need to perform? Please help me out
&lt;br&gt;&lt;br&gt;Thanks &amp; Regards
&lt;br&gt;Satya N Tailor
&lt;br&gt;&lt;br&gt;----- End forwarded message -----
&lt;br&gt;--
&lt;br&gt;Lutz Jaenicke &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274221&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jaenicke@...&lt;/a&gt;
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org/~jaenicke/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org/~jaenicke/&lt;/a&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274221&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274221&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/-FWD--Not-able-to-use-openssl-tp18274221p18274221.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18292965</id>
	<title>ECDH</title>
	<published>2008-07-03T23:06:18Z</published>
	<updated>2008-07-03T23:06:18Z</updated>
	<author>
		<name>Pietro Albano</name>
	</author>
	<content type="html">Hi all,
&lt;br&gt;I must develop a simple program to do ECDH. This is an example of what i
&lt;br&gt;think:
&lt;br&gt;&lt;br&gt;&lt;br&gt;EC_POINT_mul(group,Q,NULL,EC_KEY_get0_public_key(a),EC_KEY_get0_private_key(a),ctx);
&lt;br&gt;&lt;br&gt;EC_POINT_mul(group,R,NULL,EC_KEY_get0_public_key(a),EC_KEY_get0_private_key(b),ctx);
&lt;br&gt;&lt;br&gt;EC_POINT_mul(group,A,NULL,Q,EC_KEY_get0_private_key(b),ctx);
&lt;br&gt;&amp;nbsp; &amp;nbsp; 
&lt;br&gt;EC_POINT_mul(group,B,NULL,R,EC_KEY_get0_private_key(a),ctx);
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18292965&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18292965&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/ECDH-tp18292965p18292965.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18273017</id>
	<title>IPv6 Support</title>
	<published>2008-07-03T21:59:22Z</published>
	<updated>2008-07-03T21:59:22Z</updated>
	<author>
		<name>kamakshi.krish</name>
	</author>
	<content type="html">&lt;!DOCTYPE HTML PUBLIC &quot;-//W3C//DTD HTML 4.0 Transitional//EN&quot;&gt;
&lt;HTML&gt;&lt;HEAD&gt;
&lt;META http-equiv=Content-Type content=&quot;text/html; charset=us-ascii&quot;&gt;
&lt;META content=&quot;MSHTML 6.00.2900.3354&quot; name=GENERATOR&gt;&lt;/HEAD&gt;
&lt;BODY&gt;
&lt;DIV&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=296195704-04072008&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;Hi,&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=296195704-04072008&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&amp;nbsp;I am new to openSSL. I would like to know if openSSL supports IPv6
at the socket level. If yes, which version of openSSL supports this feature
?&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=296195704-04072008&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=296195704-04072008&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;thanks
and regards,&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;
&lt;DIV&gt;&lt;SPAN class=296195704-04072008&gt;&lt;FONT face=Arial color=#0000ff size=2&gt;Kamakshi&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/DIV&gt;&lt;P&gt;&lt;strong&gt;&lt;span style='font-size:10.0pt;font-family:
&quot;Palatino Linotype&quot;,&quot;serif&quot;;color:green'&gt; Please do not print this email unless it is absolutely necessary. &lt;/span&gt;&lt;/strong&gt;&lt;span style='font-family:&quot;Arial&quot;,&quot;sans-serif&quot;'&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;


&lt;p&gt; The information contained in this electronic message and any attachments to this message are intended for the exclusive use of the addressee(s) and may contain proprietary, confidential or privileged information. If you are not the intended recipient, you should not disseminate, distribute or copy this e-mail. Please notify the sender immediately and destroy all copies of this message and any attachments. &lt;/p&gt;

&lt;p&gt;WARNING: Computer viruses can be transmitted via email. The recipient should check this email and any attachments for the presence of viruses. The company accepts no liability for any damage caused by any virus transmitted by this email. &lt;/p&gt;
&lt;p&gt;
www.wipro.com
&lt;/p&gt;
&lt;/BODY&gt;&lt;/HTML&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SSL_connect-returns--1-tp18262630p18273017.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18274209</id>
	<title>RE: [FWD] request UP UX  openssl A.00.09.07l</title>
	<published>2008-07-03T17:07:53Z</published>
	<updated>2008-07-03T17:07:53Z</updated>
	<author>
		<name>Huey, Mike</name>
	</author>
	<content type="html">You could update to the latest OpenSSL from HP-UX: &lt;a href=&quot;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=OPENSSL11I&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=OPENSSL11I&lt;/a&gt;&lt;br&gt;&lt;br&gt;This contains FIPS 1.1.2 OpenSSL
&lt;br&gt;&lt;br&gt;FIPS OpenSSL, used in FIPS mode, does restrict the algorithms used to a subset of the normal list of OpenSSL algorithms.
&lt;br&gt;&lt;br&gt;See: &lt;a href=&quot;http://oss-institute.org/fips-faq.html#a6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://oss-institute.org/fips-faq.html#a6&lt;/a&gt;&amp;nbsp;for a list of algorithms supported in FIPS mode.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;-Mike
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;owner-openssl-users@...&lt;/a&gt; [mailto:&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;owner-openssl-users@...&lt;/a&gt;] On Behalf Of Lutz Jaenicke
&lt;br&gt;Sent: Monday, June 30, 2008 12:04 AM
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Cc: Soverini Luca
&lt;br&gt;Subject: [FWD] request UP UX openssl A.00.09.07l
&lt;br&gt;&lt;br&gt;Forwarded to openssl-users for public discussion.
&lt;br&gt;&lt;br&gt;Best regards,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Lutz
&lt;br&gt;&lt;br&gt;----- Forwarded message from Soverini Luca &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;luca.soverini@...&lt;/a&gt;&amp;gt; -----
&lt;br&gt;&lt;br&gt;Importance: normal
&lt;br&gt;Priority: normal
&lt;br&gt;From: Soverini Luca &amp;lt;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;luca.soverini@...&lt;/a&gt;&amp;gt;
&lt;br&gt;To: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;rt@...&lt;/a&gt;
&lt;br&gt;Date: Fri, 27 Jun 2008 15:46:56 +0200
&lt;br&gt;Subject: request UP UX &amp;nbsp;openssl A.00.09.07l
&lt;br&gt;Thread-Topic: request UP UX &amp;nbsp;openssl A.00.09.07l
&lt;br&gt;thread-index: AcjYXEOhcfCnezkxSVmEAjNRSa5lIQ==
&lt;br&gt;Accept-Language: it-IT, en-US
&lt;br&gt;acceptlanguage: it-IT, en-US
&lt;br&gt;&lt;br&gt;Can i have a help? How I can disable in openssl, HPUX platform &amp;nbsp;SSV2 and weak cipher in favour of large encryption keys?
&lt;br&gt;&lt;br&gt;Cordiali saluti
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; Luca Soverini
&lt;br&gt;&lt;br&gt;T.IO.DC.NE
&lt;br&gt;Delivery &amp; Operations/Server Unix
&lt;br&gt;&lt;br&gt;____________________________________________________________________________________
&lt;br&gt;Le informazioni contenute o allegate alla mail sono classificate :TELECOM S.p.A. - Uso interno - e sono dirette unicamente al destinatario in indirizzo che si impegna a mantenere riservate le informazioni relative alla presente. Chiunque riceva questa mail per errore è tenuto ad informare immediatamente il mittente ed a distruggere le informazioni in essa contenute.
&lt;br&gt;Si ringrazia per la collaborazione.
&lt;br&gt;&lt;br&gt;&lt;br&gt;--------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;CONFIDENTIALITY NOTICE
&lt;br&gt;&lt;br&gt;This message and its attachments are addressed solely to the persons above and may contain confidential information. If you have received the message in error, be informed that any use of the content hereof is prohibited. Please return it immediately to the sender and delete the message. Should you have any questions, please contact us by replying to &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;webmaster@...&lt;/a&gt;.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Thank you
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; www.telecomitalia.it
&lt;br&gt;&lt;br&gt;--------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;----- End forwarded message -----
&lt;br&gt;--
&lt;br&gt;Lutz Jaenicke &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jaenicke@...&lt;/a&gt;
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org/~jaenicke/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org/~jaenicke/&lt;/a&gt;&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18274209&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/-FWD--request-UP-UX--openssl-A.00.09.07l-tp18190697p18274209.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18265020</id>
	<title>where to get SSL_CTX_set_psk_client_callback??</title>
	<published>2008-07-03T10:54:13Z</published>
	<updated>2008-07-03T10:54:13Z</updated>
	<author>
		<name>yozhang</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;Where to get functions related to PSK? Does it need a special patch? I
&lt;br&gt;downloaded 0.9.8a/g/h openssl,
&lt;br&gt;but I can not find it. But I can see its man page in the openssl docs site.
&lt;br&gt;&lt;br&gt;Thanks!
&lt;br&gt;&lt;br&gt;Yong
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://www.openssl.org/docs/ssl/SSL_CTX_set_psk_client_callback.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org/docs/ssl/SSL_CTX_set_psk_client_callback.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;#include &amp;lt;openssl/ssl.h&amp;gt;
&lt;br&gt;&lt;br&gt;&amp;nbsp;void SSL_CTX_set_psk_client_callback(SSL_CTX *ctx,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; unsigned int (*callback)(SSL *ssl, const char *hint,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; char *identity, unsigned int max_identity_len,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; unsigned char *psk, unsigned int max_psk_len));
&lt;br&gt;&amp;nbsp;void SSL_set_psk_client_callback(SSL *ssl,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; unsigned int (*callback)(SSL *ssl, const char *hint,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; char *identity, unsigned int max_identity_len,
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; unsigned char *psk, unsigned int max_psk_len));
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;User Support Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18265020&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-users@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18265020&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/where-to-get-SSL_CTX_set_psk_client_callback---tp18265020p18265020.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18262852</id>
	<title>Re: query</title>
	<published>2008-07-03T09:09:28Z</published>
	<updated>2008-07-03T09:09:28Z</updated>
	<author>
		<name>Brad House</name>
	</author>
	<content type="html">&amp;gt; 2) If I've to add crypto accelerator support in openssl for linux then which is better approach 
&lt;br&gt;&amp;gt; 	a) I directly write an engine
&lt;br&gt;&amp;gt; 	b) I use engine written for OCF and I just write my module for OCF in kernel
&lt;br&gt;&lt;br&gt;&amp;nbsp;From my limited experience with OCF I remember a _significant_
&lt;br&gt;performance penalty for each call, assumed because of the
&lt;br&gt;penalty for transferring data to/from kernel-land. &amp;nbsp;The only
&lt;br&gt;time I saw a benefit was for the larger block sizes...
&lt;br&gt;&lt;br&gt;Here is a post I made a while back, it has some performance
&lt;br&gt;statistics for OCF vs software on a Geode...
&lt;br&gt;&lt;a href=&quot;http://busybox.net/lists/buildroot/2007-August/004810.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://busybox.net/lists/buildroot/2007-August/004810.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;Basically, if you can do it by writing a real OpenSSL engine, my guess
&lt;br&gt;is that it will probably be faster and a better course of action. &amp;nbsp;That
&lt;br&gt;said, I haven't run any tests on hardware supported by both OCF and
&lt;br&gt;directly as an OpenSSL engine to provide any real knowledge there,
&lt;br&gt;perhaps someone else could better answer your question.
&lt;br&gt;&lt;br&gt;-Brad
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;Development Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18262852&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-dev@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18262852&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---Dev-f980.html&quot; embed=&quot;fixTarget[980]&quot; target=&quot;_top&quot; &gt;OpenSSL - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/query-tp18262656p18262852.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18262566</id>
	<title>Re: Verification of X509 certificate</title>
	<published>2008-07-03T08:23:43Z</published>
	<updated>2008-07-03T08:23:43Z</updated>
	<author>
		<name>Patrick Patterson-3</name>
	</author>
	<content type="html">Hi Konrad:
&lt;br&gt;&lt;br&gt;Konrad Kleine wrote:
&lt;br&gt;&amp;gt; I also posted this question on the users mailing list.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; we are writing an client/server-application in C/C++ using OpenSSL.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;lt;SNIP&amp;gt;
&lt;br&gt;&lt;br&gt;&amp;gt; That's fine, but is it possible to verify the server's certificate on
&lt;br&gt;&amp;gt; client side by specifying a whole directory or a perhaps the copy of the
&lt;br&gt;&amp;gt; server's certificate file directly?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; In our examples, verification fails if we don't specify a file that
&lt;br&gt;&amp;gt; contains the CA certificate among others.
&lt;br&gt;&amp;gt; 
&lt;br&gt;This is actually correct behaviour - in order to check a certificates
&lt;br&gt;validity, you need to check:
&lt;br&gt;&lt;br&gt;1: That it was signed by a &amp;quot;trusted&amp;quot; CA
&lt;br&gt;2: That it is in it's validity period
&lt;br&gt;3: That it isn't revoked.
&lt;br&gt;4: That it is being used according to any critical extensions.
&lt;br&gt;5: You SHOULD check and make sure that non-critical extensions are
&lt;br&gt;obeyed as well.
&lt;br&gt;6: That it was issued according to a Certificate Policy that you have
&lt;br&gt;chosen.
&lt;br&gt;&lt;br&gt;&lt;br&gt;The OpenSSL verification routines do a fairly good job of handling
&lt;br&gt;1,2,3,and 4, &amp;nbsp;although you have to supply your own code to handle CRL
&lt;br&gt;Distribution Points and the actual downloading of the CRL, you have to
&lt;br&gt;provide an already built trust path, since AIA chasing isn't possible
&lt;br&gt;directly from within the OpenSSL Verification routines (which is
&lt;br&gt;probably a good thing :), and there are only a small number of critical
&lt;br&gt;fields that OpenSSL can handle by default. To handle the full set of
&lt;br&gt;requirements, including 5 and 6, you have to implement custom routines
&lt;br&gt;yourself, or use something like Pathfinder
&lt;br&gt;(&lt;a href=&quot;http://pathfinder-pki.googlecode.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://pathfinder-pki.googlecode.com&lt;/a&gt;).
&lt;br&gt;&lt;br&gt;So, you should be providing the CA that signed the Server cert to the
&lt;br&gt;client (or else, how do you know and trust the signature in the server
&lt;br&gt;certificate ??). Just checking the server certificate doesn't actually
&lt;br&gt;get you anything (if you are just going to do that, don't use
&lt;br&gt;certificates, and just use some form of shared secret).
&lt;br&gt;&lt;br&gt;Have fun.
&lt;br&gt;&lt;br&gt;Patrick.
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;Development Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18262566&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-dev@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18262566&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---Dev-f980.html&quot; embed=&quot;fixTarget[980]&quot; target=&quot;_top&quot; &gt;OpenSSL - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/Verification-of-X509-certificate-tp18254600p18262566.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18261166</id>
	<title>pkcs12 friendly name segfault in 0.9.8h</title>
	<published>2008-07-03T07:48:47Z</published>
	<updated>2008-07-03T07:48:47Z</updated>
	<author>
		<name>Bruce Stephens-4</name>
	</author>
	<content type="html">In 0.9.8g (the Debian package of it, anyway), this works:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;openssl &amp;nbsp;pkcs12 -export -name &amp;quot;name&amp;quot; -inkey 1215091299.pem -in certs.pem -out p12.p12
&lt;br&gt;&lt;br&gt;(where those files have appropriate types, and certs.pem contains a
&lt;br&gt;user certificate and a CA certificate.)
&lt;br&gt;&lt;br&gt;In 0.9.8h which I just built, it segfaults. &amp;nbsp;-caname seems to be fine.
&lt;br&gt;&lt;br&gt;(The test suite completes apparently without an error, so I guess
&lt;br&gt;there's no test for this.)
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;Development Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18261166&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-dev@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18261166&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---Dev-f980.html&quot; embed=&quot;fixTarget[980]&quot; target=&quot;_top&quot; &gt;OpenSSL - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/pkcs12-friendly-name-segfault-in-0.9.8h-tp18261166p18261166.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18262656</id>
	<title>query</title>
	<published>2008-07-03T04:08:05Z</published>
	<updated>2008-07-03T04:08:05Z</updated>
	<author>
		<name>Manish RATHI</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;Can any one tell me 
&lt;br&gt;1) when I call SSL_write() in application then which layer/code 
&lt;br&gt;actually does encryption of data?
&lt;br&gt;As per my understanding, SSL_write() calls write callback of SSL object.
&lt;br&gt;2) If I've to add crypto accelerator support in openssl for linux then which is better approach 
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; a) I directly write an engine
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; b) I use engine written for OCF and I just write my module for OCF in kernel
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks
&lt;br&gt;Regards
&lt;br&gt;Manish
&lt;br&gt;______________________________________________________________________
&lt;br&gt;OpenSSL Project &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.openssl.org&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.openssl.org&lt;/a&gt;&lt;br&gt;Development Mailing List &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18262656&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;openssl-dev@...&lt;/a&gt;
&lt;br&gt;Automated List Manager &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18262656&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;majordomo@...&lt;/a&gt;
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---Dev-f980.html&quot; embed=&quot;fixTarget[980]&quot; target=&quot;_top&quot; &gt;OpenSSL - Dev&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/query-tp18262656p18262656.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18262630</id>
	<title>SSL_connect returns -1</title>
	<published>2008-07-03T03:42:59Z</published>
	<updated>2008-07-03T03:42:59Z</updated>
	<author>
		<name>Tejesh Vijayakumar</name>
	</author>
	<content type="html">
&lt;br&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;Hi&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;I have ported Xsupplicant(EAP) code
on Vxworks platform for a wireless modem.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;I am testing TLS authentication. Currently
i am able to receive &amp;quot;server certificate, server key exchange, server
hello done&amp;quot; messages from&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;the server. But I am unable to send
&amp;quot;client certificate, client key exchange, client change cipher spec&amp;quot;messages.&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;SSL_connect returns -1 and ERR_get_error(..)
returns 0. and the error is &lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;SYS_ERROR_SYSCALL. errno is also 0.
&lt;/font&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;could someone tell me why is this
happening?&lt;/font&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;
&lt;br&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;Regards,&lt;br&gt;
Tejesh Vijayakumar&lt;br&gt;
Software Engineer,&lt;br&gt;
Product Engineering Services[PES] Group,&lt;br&gt;
&lt;br&gt;
Contact Details&lt;br&gt;
---------------------------------------------------------------&lt;br&gt;
e-mail: &lt;a href=&quot;http://www.nabble.com/user/SendEmail.jtp?type=post&amp;post=18262630&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tejesh.vijayakumar@...&lt;/a&gt;&lt;br&gt;
L&amp;amp;T Infotech,&lt;br&gt;
Plot 25-31, EPIP Phase II,&lt;br&gt;
KIADB Industrial Area,&lt;br&gt;
Whitefield, Bangalore 66. &lt;br&gt;
India GMT +5 30 Hours&lt;br&gt;
----------------------------------------------------------------&lt;br&gt;
Telephone(office): +91 80 66242424 Extn 2429&lt;br&gt;
 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;
&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;+91 80 66242429 (Direct)&lt;br&gt;
&lt;b&gt;&lt;br&gt;
Larsen &amp;amp; Toubro Infotech Ltd.&lt;/b&gt;&lt;/font&gt;&lt;font size=2 color=blue face=&quot;Trebuchet MS&quot;&gt;&lt;u&gt;&lt;br&gt;
&lt;/u&gt;&lt;/font&gt;&lt;a href=http://www.lntinfotech.com target=&quot;_top&quot; rel=&quot;nofollow&quot; /&gt;&lt;font size=2 color=blue face=&quot;Trebuchet MS&quot;&gt;&lt;u&gt;www.Lntinfotech.com&lt;/u&gt;&lt;/font&gt;&lt;/a&gt;&lt;font size=2 face=&quot;Trebuchet MS&quot;&gt;&lt;br&gt;
&lt;br&gt;
This Document is classified as: &lt;br&gt;
&lt;br&gt;
L&amp;amp;T Infotech Proprietary &amp;nbsp; L&amp;amp;T Infotech Confidential &amp;nbsp;
L&amp;amp;T Infotech Internal Use Only &amp;nbsp; L&amp;amp;T Infotech General Business
&amp;nbsp; &lt;br&gt;
&lt;br&gt;
This Email may contain confidential or privileged information for the intended
recipient (s) If you are not the intended recipient, please do not use
or disseminate the information, notify the sender and delete it from your
system. &lt;/font&gt;

&lt;BR&gt;
______________________________________________________________________&lt;BR&gt;
&lt;p&gt;From forum: &lt;a href=&quot;http://www.nabble.com/OpenSSL---User-f981.html&quot; embed=&quot;fixTarget[981]&quot; target=&quot;_top&quot; &gt;OpenSSL - User&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://www.nabble.com/SSL_connect-returns--1-tp18262630p18262630.html" />
</entry>

<entry>
	<id>tag:www.nabble.com,2006:post-18255334</id>
	<title>Re: Verification of X509 certificate</title>
	<published>2008-07-03T02:23:30Z</published>
	<updated>2008-07-03T02:23:30Z</updated>
	<author>
		<name>wolfoftheair</name>
	</author>
	<content type="html">The CA is the point of trust -- the &amp;quot;trust anchor&amp;quot;. &amp;nbsp;Since the server
&lt;br&gt;certificate is issued by the anchor, the client needs the anchor's
&lt;br&gt;certificate to be able to verify it.
&lt;br&gt;&lt;br&gt;If you want to bypass this, look at the definition of
&lt;br&gt;SSL_set_verify(). &amp;nbsp;If your verification callback returns 0, the
&lt;br&gt;certificate is considered unverified. &amp;nbsp;If it returns 1, the
&lt;br&gt;certificate is considered verified. &amp;nbsp;It is YOUR code that must make
&lt;br&gt;this determination; usually this includes checking a local certificate
&lt;br&gt;store for a certificate with a CN= the FQDN of the server, and then
&lt;br&gt;seeing if the key used for the connection matches the one in that
&lt;br&gt;certificate. &amp;nbsp;OpenSSL won't do this for you automatically if you don't
&lt;br&gt;have the se