cURL / Mailing Lists / curl-library / Single Mail

curl-library

Re: weak randomness with some TLS backends

From: Dan Fandrich <dan_at_coneharvesters.com>
Date: Wed, 4 Jun 2014 22:29:00 +0200

On Wed, Jun 04, 2014 at 12:29:05PM -0700, Chris Ghormley wrote:
> Here is a patch for axTLS. I don't submit patches very often, so I
> apologize if I'm doing it wrong.

The patch format looks fine, but since you're using git, creating a patch with
git format-patch would be even better.

> This backend doesn't seem to do anything spectacular for
> randomness...I'm not an expert.
> But if it does/did I think this is the right way to call it.
>
> I performed limited testing to make sure my product talks to my servers
> (nginx and lighttpd with OpenSSL).

Unfortunately, I get a core dump on test 304 with this patch, and a failure on
test 560.

>>> Dan
-------------------------------------------------------------------
List admin: http://cool.haxx.se/list/listinfo/curl-library
Etiquette: http://curl.haxx.se/mail/etiquette.html
Received on 2014-06-04