OpenSSL STATUS Last modified at
- ______________ $Date: 2002/02/28 22:07:50 $
+ ______________ $Date: 2002/05/09 23:53:01 $
DEVELOPMENT STATE
o OpenSSL 0.9.7: Under development...
+ o OpenSSL 0.9.6d: Released on May 9th, 2002
o OpenSSL 0.9.6c: Released on December 21st, 2001
o OpenSSL 0.9.6b: Released on July 9th, 2001
o OpenSSL 0.9.6a: Released on April 5th, 2001
RELEASE SHOWSTOPPERS
- o BIGNUM library failures on 64-bit platforms (0.9.7-dev):
- - BN_mod_mul verificiation (bc) fails for solaris64-sparcv9-cc
-
- Checked on Result
- alpha-cc (Tru64 version 4.0) works
- linux-alpha+bwx-gcc doesn't work. Reported by
- Sean O'Riordain <seanpor@acm.org>
-
- Needs checked on
- [add platforms here]
-
AVAILABLE PATCHES
o
NEEDS PATCH
- o An (optional) countermeasure against the predictable-IV CBC
- weakness in SSL/TLS should be added; see
- http://www.openssl.org/~bodo/tls-cbc.txt
-
o apps/ca.c: "Sign the certificate?" - "n" creates empty certificate file
+ o Whenever strncpy is used, make sure the resulting string is NULL-terminated
+ or an error is reported
+
o "OpenSSL STATUS" is never up-to-date.
OPEN ISSUES
which apparently is not flexible enough to generate
libcrypto)
- WISHES
- o Add variants of DH_generate_parameters() and BN_generate_prime() [etc?]
- where the callback function can request that the function be aborted.
- [Gregory Stark <ghstark@pobox.com>, <rayyang2000@yahoo.com>]
+ o The perl/ stuff needs a major overhaul. Currently it's
+ totally obsolete. Either we clean it up and enhance it to be up-to-date
+ with the C code or we also could replace it with the really nice
+ Net::SSLeay package we can find under
+ http://www.neuronio.pt/SSLeay.pm.html. Ralf uses this package for a
+ longer time and it works fine and is a nice Perl module. Best would be
+ to convince the author to work for the OpenSSL project and create a
+ Net::OpenSSL or Crypt::OpenSSL package out of it and maintains it for
+ us.
+
+ Status: Ralf thinks we should both contact the author of Net::SSLeay
+ and look how much effort it is to bring Eric's perl/ stuff up
+ to date.
+ Paul +1
+
+ WISHES
o SRP in TLS.
[wished by: