From: Dr. Stephen Henson Date: Thu, 20 Sep 2007 11:32:09 +0000 (+0000) Subject: Clarify wording a little. X-Git-Tag: OpenSSL_0_9_8f~22 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=015052cf7b353ee6a7be0318f48d871979dac902;p=oweals%2Fopenssl.git Clarify wording a little. --- diff --git a/FAQ b/FAQ index e00651e9c5..e2e1c2f92e 100644 --- a/FAQ +++ b/FAQ @@ -897,16 +897,14 @@ thread-safe): * Why does Valgrind complain about the use of uninitialized data? -OpenSSL does internally call its own PRNG routines to retrieve random -numbers. It so does with uninitialed buffer contents. The buffer -contents is mixed into the entropy pool so that it technically does -not matter whether the buffer is initialized at this point or not. -Valgrind (and other test tools) will complain whatsoever. When -using Valgrind, make sure to use an OpenSSL library that has been -compiled with the PEDANTIC macro being defined (-DPEDANTIC) to -get rid of these warnings. Compling with -DPURIFY will help as well. - -The PEDANTIC macro was added in OpenSSL 0.9.8f. +When OpenSSL's PRNG routines are called to generate random numbers the supplied +buffer contents are mixed into the entropy pool: so it technically does not +matter whether the buffer is initialized at this point or not. Valgrind (and +other test tools) will complain about this. When using Valgrind, make sure the +OpenSSL library has been compiled with the PEDANTIC macro defined (-DPEDANTIC) +to get rid of these warnings. Compling with -DPURIFY will help as well. + +The use of PEDANTIC with the PRNG was added in OpenSSL 0.9.8f. ===============================================================================