<rss version="2.0">
<channel>
<title>mailing.openssl.users</title>
<link>http://www.nnseek.com/e/mailing.openssl.users/</link>
<description>Posts for mailing.openssl.users</description>
<lastBuildDate>Thu, 04 Sep 2008 23:18:08 PDT</lastBuildDate>
  <image>
    <title>http://www.nnseek.com/</title>
    <link>http://www.nnseek.com/</link>
    <url>http://www.nnseek.com/img/64.png</url>
    <width>64</width>
    <height>64</height>
    <description>NNSeek</description>
  </image>
<item>
	<title><![CDATA[TechnoMarine TechnoSquare Chronograph Ladies Watch Recommendation  Discount Watches]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/technomarine_technosquare_chronograph_ladies_watch_160240555t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/technomarine_technosquare_chronograph_ladies_watch_160240555t.html</link>
	<description><![CDATA[TechnoMarine TechnoSquare Chronograph Ladies Watch Recommendation<br>Discount Watches<br><br>TechnoMarine TechnoSquare Chronograph Ladies Watch Site:<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7419.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7419.html</a><br><br>Thank you for choosing <a href="http://www.pxhelp.com" rel="nofollow" class="url" target="_blank">http://www.pxhelp.com</a>/<br><br>Quality Technomarine Watches: <a href="http://technomarine-watches.pxhelp.com" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com</a>/<br><br><br>TechnoMarine TechnoSquare Chronograph Ladies Watch AdditionalInfo :<br><br>Watches Brand :   Technomarine Watches ( <a href="http://technomarine-watches.pxhelp.com" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com</a>/<br>)<br>Gender :          Ladies<br>Model :           technomarine-technosquare-tsc99-1073<br>Also Called :<br>Case Material :   Stainless steel<br>Movement :        Quartz<br>Crystal :         Scratch Resistant Sapphire<br>Dial Color :       White<br>Clasp :           Blue leather<br>Bezel :           Stainless steel<br>Case Thickness :   32mm<br>Water Resistant : 100m/330ft<br><br>OUT OF STOCKTechnoMarine TechnoSquare Chronograph Ladies Watch This<br>TechnoMarine TechnoSquare Chronograph Ladies Watch watch case is made<br>out of Stainless steel. The White dial is covered in Sapphire. The<br>case diameter is 32 mm. This TechnoMarine TechnoSquare Chronograph<br>Ladies Watch is water resistant up to 100 m / 330 ft. TechnoMarine<br>TechnoSquare Chronograph Ladies Watch TechnoMarine TechnoSquare<br>Chronograph Ladies Watch Brand TechnomarineSeries Technomarine<br>TechnosquareGender LadiesCase Material Stainless steelCase Diameter<br>32mmDial Color WhiteBezel Stainless steelMovement QuartzClasp<br>TangBracelet Blue leatherWater Resistant 100m/330ftCrystal Scratch<br>Resistant SapphireWarranty 2 Year <a href="http://Pxhelp.com" rel="nofollow" class="url" target="_blank">Pxhelp.com</a> WarrantyTechnoMarine<br>TechnoSquare Chronograph Ladies Watch is brand new, join thousands of<br>satisfied customers and buy your TechnoMarine TechnoSquare Chronograph<br>Ladies Watch with total satisfaction . A <a href="http://Pxhelp.com" rel="nofollow" class="url" target="_blank">Pxhelp.com</a> 30 Day Money Back<br>Guarantee is included with every TechnoMarine TechnoSquare Chronograph<br>Ladies Watch for secure, risk-free online shopping. <a href="http://Pxhelp.com" rel="nofollow" class="url" target="_blank">Pxhelp.com</a> does<br>not charge sales tax for the TechnoMarine TechnoSquare Chronograph<br>Ladies Watch, unless shipped within New York State. <a href="http://Pxhelp.com" rel="nofollow" class="url" target="_blank">Pxhelp.com</a> is<br>rated 5 stars on the Yahoo! network.<br><br>Other Technomarine Watches You Might Like<br><br>TechnoMarine XS Magnum Leather Chronograph Men's Watch XSCM21<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7455.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7455.html</a><br>TechnoMarine TechnoSquare Chronograph Ladies Watch TSC99-1008<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7420.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7420.html</a><br>TechnoMarine Diamond Ladies Watch DXSL09<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7472.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7472.html</a><br>TechnoMarine Butterfly Ladies Watch LRBK04<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7308.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7308.html</a><br>Technomarine TMY Brown Chronograph Unisex Watch TMY26<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7446.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7446.html</a><br>Technomarine TMY Red Chronograph Unisex Watch TMY07<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7445.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7445.html</a><br>TechnoMarine TechnoSquare Chronograph Ladies Watch TSC99-1016<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7396.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7396.html</a><br>TechnoMarine TechnoSquare Chronograph Ladies Watch TSC99-1016<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7396.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7396.html</a><br>Technomarine Apnea X Black Unisex Watch TMAX02<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7297.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7297.html</a><br>Technomarine KRA Unisex Watch KRA05<br><a href="http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7329.html" rel="nofollow" class="url" target="_blank">http://technomarine-watches.pxhelp.com/Technomarine-wristwatch-7329.html</a><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/technomarine_technosquare_chronograph_ladies_watch_160240555t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/technomarine_technosquare_chronograph_ladies_watch_160240555m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 23:18:08 PDT</pubDate>
</item>
<item>
	<title><![CDATA[RE: Error when creating certificate in HPUX]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/error_when_creating_certificate_in_hpux_160080299t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/error_when_creating_certificate_in_hpux_160080299t.html</link>
	<description><![CDATA[Mike:<br>I appreciate the clarification on HPUX 11.11 RNG.  When I scanned HPUX documentation for RNG info a couple of months back, it was not totally clear to me what my OpenSSL-enabled app should do when installed on a 11.11 site host.  One take was to, upon installation on 11.11, ask installer if they were ok with having the app start RNG if needed, then figuring out if it was needed. <br><br>-----Original Message-----<br>From: owner-openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>[mailto:owner-openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a>]On Behalf Of Huey, Mike<br>Sent: Wednesday, September 03, 2008 3:58 PM<br>To: openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Subject: RE: Error when creating certificate in HPUX<br><br><br>If you are on 11.11 you need to see if you have random number generator installed.  You can get the rand gen product for 11.11 from:<br><a href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=KRNG11I" rel="nofollow" class="url" target="_blank">http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=KRN...</a><br><br>If you do not want to install a random number generator, then check to see if prngd is running.  If prngd is not running you can start it by<br><br>:/sbin/init.d/prngd.rc start<br><br>It would be useful to know what version of HP-UX and OpenSSL you are using.<br><br>You can get the latest openssl for HP-UX at:<br><a href="http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=OPENSSL11I" rel="nofollow" class="url" target="_blank">http://h20293.www2.hp.com/portal/swdepot/displayProductInfo.do?productNumber=OPE...</a><br><br>-Mike<br><br>-----Original Message-----<br>From: owner-openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a> [mailto:owner-openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a>] On Behalf Of Tan, Liao<br>Sent: Wednesday, September 03, 2008 5:52 AM<br>To: openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Subject: Error when creating certificate in HPUX<br><br>Folks,<br> Im trying to find solution for this issue. When running the command below<br><br>openssl genrsa -des3 -out <a href="http://mydomain.com.key" rel="nofollow" class="url" target="_blank">mydomain.com.key</a> 1024<br><br>to create the key pair certificate, it gives me the error:<br><br>=====================<br> warning, not much extra random data, consider using the -rand option<br>Generating RSA private key, 1024 bit long modulus<br>26995:error:24064064:random number generator:SSLEAY_RAND_BYTES:PRNG not seeded:md_rand.c:503:You need to read the OpenSSL FAQ, <a href="http://www.openssl.org/support/faq.html" rel="nofollow" class="url" target="_blank">http://www.openssl.org/support/faq.html</a><br>26995:error:04081003:rsa routines:RSA_BUILTIN_KEYGEN:BN lib:rsa_gen.c:183:<br>=====================<br><br>Please, any idea on wot´s going on? This is a production machine, Im in touch with the SA, I wont be able to perform tests, reallocate files, etc.<br><br>Please your prompt attention.<br>Thank you<br>Ingrid<br><br><br>______________________________________________________________________<br>OpenSSL Project                                 <a href="http://www.openssl.org" rel="nofollow" class="url" target="_blank">http://www.openssl.org</a><br>User Support Mailing List                    openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Automated List Manager                           majordomo@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>______________________________________________________________________<br>OpenSSL Project                                 <a href="http://www.openssl.org" rel="nofollow" class="url" target="_blank">http://www.openssl.org</a><br>User Support Mailing List                    openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Automated List Manager                           majordomo@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>______________________________________________________________________<br>OpenSSL Project                                 <a href="http://www.openssl.org" rel="nofollow" class="url" target="_blank">http://www.openssl.org</a><br>User Support Mailing List                    openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Automated List Manager                           majordomo@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/error_when_creating_certificate_in_hpux_160080299t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/error_when_creating_certificate_in_hpux_160080299m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 13:28:23 PDT</pubDate>
</item>
<item>
	<title><![CDATA[Need to upgrade openssl on my Solaris10 server]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/need_to_upgrade_openssl_on_my_solaris10_server_160249259t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/need_to_upgrade_openssl_on_my_solaris10_server_160249259t.html</link>
	<description><![CDATA[<br>Hello,<br><br>We have security holes that need to be fixed on our Solaris 10 server.<br>I have applied the Solaris 10  "Recommended and Security" patch bundle<br>that was updated on 09/02/08.   One of the security holes is will<br>openssl.   How do I upgrade it?   Currently we are running: OpenSSL<br><a href="http://0.9.7d" rel="nofollow" class="url" target="_blank">0.9.7d</a> 17 Mar 2004 (+ security patches to 2006-09-29).  I would like to<br>go to the lastest which I believe is: OpenSSL <a href="http://0.9.8h" rel="nofollow" class="url" target="_blank">0.9.8h</a>.    How do I get<br>the PKG for the latest version.   I  found a tar file located at<br><a href="http://www.openssl.org/source" rel="nofollow" class="url" target="_blank">http://www.openssl.org/source</a>/ , but don't know how I can apply it to my<br>system.<br><br>Thanks,<br>Randy Grode<br>Cargill, Inc<br><br><br><br><br><br><br><br>Need to upgrade openssl on my Solaris10 server<br><br><br><br><br>Hello,<br><br><br>We have security holes that need to be fixed on our Solaris 10 server.&nbsp; I have applied the Solaris 10&nbsp; "Recommended and Security" patch bundle that was updated on 09/02/08.&nbsp;&nbsp; One of the security holes is will openssl.&nbsp;&nbsp; How do I upgrade it?&nbsp;&nbsp; Currently we are running: OpenSSL <a href="http://0.9.7d" rel="nofollow" class="url" target="_blank">0.9.7d</a> 17 Mar 2004 (+ security patches to 2006-09-29).&nbsp; I would like to go to the lastest which I believe is: OpenSSL <a href="http://0.9.8h.&nbsp;&nbsp;&nbsp" rel="nofollow" class="url" target="_blank">0.9.8h.&nbsp;&nbsp;&nbsp</a>; How do I get the PKG for the latest version.&nbsp;&nbsp; I&nbsp; found a tar file located at <a href="http://www.openssl.org/source" rel="nofollow" class="url" target="_blank">http://www.openssl.org/source</a>/ , but don't know how I can apply it to my system.<br><br>Thanks,<br>Randy Grode<br><br>Cargill, Inc<br><br><br><br><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/need_to_upgrade_openssl_on_my_solaris10_server_160249259t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/need_to_upgrade_openssl_on_my_solaris10_server_160249259m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 12:07:56 PDT</pubDate>
</item>
<item>
	<title><![CDATA[Solaris x86 32-bit - OpenSSL Installation issue]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/solaris_x86_32_bit_openssl_installation_issue_160065963t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/solaris_x86_32_bit_openssl_installation_issue_160065963t.html</link>
	<description><![CDATA[<br>I am attempting to install OpenSSL <a href="http://0.9.8h" rel="nofollow" class="url" target="_blank">0.9.8h</a> on a Solaris x86 32 bit virtual<br>machine.<br> <br>I am able to ./config, make and make install but make test fails.<br> <br>Here is the error I am receiving:<br> <br># make test<br>testing...<br>making all in apps...<br>../util/shlib_wrap.sh ./destest<br>*** Signal 11 - core dumped<br>make: Fatal error: Command failed for target `test_des'<br>Current working directory /<a href="http://opt/src/openssl-0.9.8h/test" rel="nofollow" class="url" target="_blank">opt/src/openssl-0.9.8h/test</a><br>*** Error code 1<br>The following command caused the error:<br>(cd test && echo "testing..." && \<br>TOP= && unset TOP ${LIB+LIB} ${LIBS+LIBS}        ${INCLUDE+INCLUDE}<br>${INCLUDES+INCLUDES}         ${DIR+DIR} ${DIRS+DIRS} ${SRC+SRC}<br>${LIBSRC+LIBSRC} ${LIBOBJ+LIBOBJ} ${ALL+ALL}    ${EXHEADER+EXHEADER}<br>${HEADER+HEADER}           ${GENERAL+GENERAL} ${CFLAGS+CFLAGS}<br>${ASFLAGS+ASFLAGS} ${AFLAGS+AFLAGS}             ${LDCMD+LDCMD}<br>${LDFLAGS+LDFLAGS}               ${SHAREDCMD+SHAREDCMD}<br>${SHAREDFLAGS+SHAREDFLAGS}       ${SHARED_LIB+SHARED_LIB}<br>${LIBEXTRAS+LIBEXTRAS} && make -e PLATFORM='solaris-x86-gcc' PROCESSOR=''<br>CC='gcc' CFLAG='-fPIC -DOPENSSL_PIC -DOPENSSL_THREADS -D_REENTRANT<br>-DDSO_DLFCN -DHAVE_DLFCN_H -O3 -fomit-frame-pointer -march=pentium -Wall<br>-DL_ENDIAN -DOPENSSL_NO_INLINE_ASM -DOPENSSL_BN_ASM_PART_WORDS -DSHA1_ASM<br>-DMD5_ASM -DRMD160_ASM -DAES_ASM'                     AS='gcc' ASFLAG='-fPIC<br>-DOPENSSL_PIC -DOPENSSL_THREADS -D_REENTRANT -DDSO_DLFCN -DHAVE_DLFCN_H -O3<br>-fomit-frame-pointer -march=pentium -Wall -DL_ENDIAN -DOPENSSL_NO_INLINE_ASM<br>-DOPENSSL_BN_ASM_PART_WORDS -DSHA1_ASM -DMD5_ASM -DRMD160_ASM -DAES_ASM -c'<br>AR='ar  r' PERL='/usr/bin/perl' RANLIB='/usr/ccs/bin/ranlib'<br>SDIRS='objects  md2 md4 md5 sha hmac ripemd  des aes rc2 rc4 idea bf cast<br>bn ec rsa dsa ecdsa dh ecdh dso engine  buffer bio stack lhash rand err  evp<br>asn1 pem x509 x509v3 conf txt_db pkcs7 pkcs12 comp ocsp ui krb5  store<br>pqueue' LIBRPATH='/usr/local/ssl/lib'    INSTALL_PREFIX=''<br>INSTALLTOP='/usr/local/ssl' OPENSSLDIR='/usr/local/ssl'<br>MAKEDEPEND='$${TOP}/util/domd $${TOP} -MD gcc'<br>DEPFLAG='-DOPENSSL_NO_DEPRECATED -DOPENSSL_NO_CAMELLIA -DOPENSSL_NO_CMS<br>-DOPENSSL_NO_GMP -DOPENSSL_NO_MDC2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779<br>-DOPENSSL_NO_SEED -DOPENSSL_NO_TLSEXT'         MAKEDEPPROG='gcc'<br>SHARED_LDFLAGS='-shared'                KRB5_INCLUDES='' LIBKRB5=''<br>EXE_EXT='' SHARED_LIBS='<a href="http://libcrypto.so.0.9.8" rel="nofollow" class="url" target="_blank">libcrypto.so.0.9.8</a> <a href="http://libssl.so.0.9.8" rel="nofollow" class="url" target="_blank">libssl.so.0.9.8</a>'<br>SHLIB_EXT='.<a href="http://so.0.9.8" rel="nofollow" class="url" target="_blank">so.0.9.8</a>' SHLIB_TARGET='solaris-shared'     PEX_LIBS=''<br>EX_LIBS='-lsocket -lnsl -ldl'       CPUID_OBJ='x86cpuid-elf.o'<br>BN_ASM='bn86-elf.o co86-elf.o' DES_ENC='dx86-elf.o yx86-elf.o'<br>AES_ASM_OBJ='ax86-elf.o'                        BF_ENC='bx86-elf.o'<br>CAST_ENC='c_enc.o'  RC4_ENC='rx86-elf.o rc4_skey.o' RC5_ENC='r586-elf.o'<br>SHA1_ASM_OBJ='sx86-elf.o'                       MD5_ASM_OBJ='mx86-elf.o'<br>RMD160_ASM_OBJ='rm86-elf.o'             THIS=${THIS:-tests}<br>MAKEFILE=Makefile MAKEOVERRIDES= TOP=.. TESTS='alltests'<br>OPENSSL_DEBUG_MEMORY=on tests );<br>make: Fatal error: Command failed for target `tests'<br><br>Does anyone have any ideas how to resolve this?<br> <br>Thanks,<br>Matthew<br>--------------------------------------------------------<br>Matthew Maddox<br>IT Systems Developer and Coordinator<br>Webster University<br>470 East Lockwood Avenue <br>Saint Louis, MO 63119<br>314-246-8282 ofc<br>314-963-6134 fax<br>maddox@<a href="http://webster.edu" rel="nofollow" class="url" target="_blank">webster.edu</a><br> <br> <br> <br> <br> <br> <br><br><br><br><br><br><br><br>I am attempting to <br>install OpenSSL <a href="http://0.9.8h" rel="nofollow" class="url" target="_blank">0.9.8h</a> on a Solaris x86 32 bit virtual <br>machine.<br>&nbsp;<br>I am able to <br>./config, make and make install but make test fails.<br>&nbsp;<br>Here is the error I <br>am receiving:<br>&nbsp;<br># make <br>testtesting...making all in apps...../util/shlib_wrap.sh <br>./destest*** Signal 11 - core dumpedmake: Fatal error: Command failed <br>for target `test_des'Current working directory <br>/<a href="http://opt/src/openssl-0.9.8h/test" rel="nofollow" class="url" target="_blank">opt/src/openssl-0.9.8h/test</a>*** Error code 1The following command caused <br>the error:(cd test && echo "testing..." && \TOP= <br>&& unset TOP ${LIB+LIB} <br>${LIBS+LIBS}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ${INCLUDE+INCLUDE} <br>${INCLUDES+INCLUDES}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; ${DIR+DIR} <br>${DIRS+DIRS} <br>${SRC+SRC}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>${LIBSRC+LIBSRC} ${LIBOBJ+LIBOBJ} ${ALL+ALL}&nbsp;&nbsp;&nbsp; <br>${EXHEADER+EXHEADER} <br>${HEADER+HEADER}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>${GENERAL+GENERAL} <br>${CFLAGS+CFLAGS}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>${ASFLAGS+ASFLAGS} <br>${AFLAGS+AFLAGS}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>${LDCMD+LDCMD} <br>${LDFLAGS+LDFLAGS}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>${SHAREDCMD+SHAREDCMD} <br>${SHAREDFLAGS+SHAREDFLAGS}&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>${SHARED_LIB+SHARED_LIB} ${LIBEXTRAS+LIBEXTRAS} && make -e <br>PLATFORM='solaris-x86-gcc' PROCESSOR=''&nbsp; CC='gcc' CFLAG='-fPIC <br>-DOPENSSL_PIC -DOPENSSL_THREADS -D_REENTRANT -DDSO_DLFCN -DHAVE_DLFCN_H -O3 <br>-fomit-frame-pointer -march=pentium -Wall -DL_ENDIAN -DOPENSSL_NO_INLINE_ASM <br>-DOPENSSL_BN_ASM_PART_WORDS -DSHA1_ASM -DMD5_ASM -DRMD160_ASM <br>-DAES_ASM'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>AS='gcc' ASFLAG='-fPIC -DOPENSSL_PIC -DOPENSSL_THREADS -D_REENTRANT -DDSO_DLFCN <br>-DHAVE_DLFCN_H -O3 -fomit-frame-pointer -march=pentium -Wall -DL_ENDIAN <br>-DOPENSSL_NO_INLINE_ASM -DOPENSSL_BN_ASM_PART_WORDS -DSHA1_ASM -DMD5_ASM <br>-DRMD160_ASM -DAES_ASM <br>-c'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>AR='ar&nbsp; r' PERL='/usr/bin/perl' <br>RANLIB='/usr/ccs/bin/ranlib'&nbsp;&nbsp;&nbsp; SDIRS='objects&nbsp; md2 md4 md5 <br>sha hmac ripemd&nbsp; des aes rc2 rc4 idea bf cast&nbsp; bn ec rsa dsa ecdsa dh <br>ecdh dso engine&nbsp; buffer bio stack lhash rand err&nbsp; evp asn1 pem x509 <br>x509v3 conf txt_db pkcs7 pkcs12 comp ocsp ui krb5&nbsp; store pqueue' <br>LIBRPATH='/usr/local/ssl/lib'&nbsp;&nbsp;&nbsp; <br>INSTALL_PREFIX=''&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>INSTALLTOP='/usr/local/ssl' <br>OPENSSLDIR='/usr/local/ssl'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>MAKEDEPEND='$${TOP}/util/domd $${TOP} -MD gcc'&nbsp; <br>DEPFLAG='-DOPENSSL_NO_DEPRECATED -DOPENSSL_NO_CAMELLIA -DOPENSSL_NO_CMS <br>-DOPENSSL_NO_GMP -DOPENSSL_NO_MDC2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779 <br>-DOPENSSL_NO_SEED <br>-DOPENSSL_NO_TLSEXT'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>MAKEDEPPROG='gcc'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>SHARED_LDFLAGS='-shared'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>KRB5_INCLUDES='' LIBKRB5=''&nbsp;&nbsp;&nbsp;&nbsp; EXE_EXT='' <br>SHARED_LIBS='<a href="http://libcrypto.so.0.9.8" rel="nofollow" class="url" target="_blank">libcrypto.so.0.9.8</a> <a href="http://libssl.so.0.9.8'&nbsp;&nbsp;&nbsp;&nbsp" rel="nofollow" class="url" target="_blank">libssl.so.0.9.8'&nbsp;&nbsp;&nbsp;&nbsp</a>; <br>SHLIB_EXT='.<a href="http://so.0.9.8" rel="nofollow" class="url" target="_blank">so.0.9.8</a>' SHLIB_TARGET='solaris-shared'&nbsp;&nbsp;&nbsp;&nbsp; <br>PEX_LIBS='' EX_LIBS='-lsocket -lnsl -ldl'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>CPUID_OBJ='x86cpuid-elf.o'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>BN_ASM='bn86-elf.o co86-elf.o' DES_ENC='dx86-elf.o <br>yx86-elf.o'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>AES_ASM_OBJ='ax86-elf.o'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>BF_ENC='bx86-elf.o' CAST_ENC='c_enc.o'&nbsp; RC4_ENC='rx86-elf.o rc4_skey.o' <br>RC5_ENC='r586-elf.o'&nbsp;&nbsp;&nbsp; <br>SHA1_ASM_OBJ='sx86-elf.o'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>MD5_ASM_OBJ='mx86-elf.o'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>RMD160_ASM_OBJ='rm86-elf.o'&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; <br>THIS=${THIS:-tests} MAKEFILE=Makefile MAKEOVERRIDES= TOP=.. TESTS='alltests' <br>OPENSSL_DEBUG_MEMORY=on tests );make: Fatal error: Command failed for target <br>`tests'<br>Does anyone have any <br>ideas how to resolve this?<br>&nbsp;<br>Thanks,<br>Matthew<br>--------------------------------------------------------<br>Matthew Maddox<br>IT Systems Developer and <br>Coordinator<br>Webster University<br>470 East Lockwood Avenue <br>Saint Louis, MO 63119<br>314-246-8282 ofc<br>314-963-6134 fax<br>maddox@<a href="http://webster.edu" rel="nofollow" class="url" target="_blank">webster.edu</a><br>&nbsp;<br>&nbsp;<br>&nbsp;<br>&nbsp;<br>&nbsp;<br>&nbsp;<br><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/solaris_x86_32_bit_openssl_installation_issue_160065963t.html"><b>1</b> Comment</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/solaris_x86_32_bit_openssl_installation_issue_160065963m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 10:59:42 PDT</pubDate>
</item>
<item>
	<title><![CDATA[Problems making certificate request]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/problems_making_certificate_request_160051115t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/problems_making_certificate_request_160051115t.html</link>
	<description><![CDATA[<br>I've been trying to secure site with open ssl and have made a number of attempts and have gotten many errors. Any help with the following error would be very helpful. Thanks in advance:<br> <br>I get the following error upon issuing the following command:<br> <br>C:\Program Files\Apache Software Foundation\Apache2.2\bin>openssl req -config openssl.cnf -new -out my-server.csrLoading 'screen' into random state - doneGenerating a 1024 bit RSA private key...++++++.....++++++writing new private key to 'privkey.pem'Enter PEM pass phrase:Verifying - Enter PEM pass phrase:-----You are about to be asked to enter information that will be incorporatedinto your certificate request.What you are about to enter is what is called a Distinguished Name or a DN.There are quite a few fields but you can leave some blankFor some fields there will be a default value,If you enter '.', the field will be left blank.<br>.<br>.<br>A challenge password []:hutchError adding attribute5144:error:0D0BA041:asn1 encoding routines:ASN1_STRING_set:malloc failure:.\crypto\asn1\asn1_lib.c:381:5144:error:0B08A041:x509 certificate routines:X509_ATTRIBUTE_set1_data:malloc failure:.\crypto\x509\x509_att.c:317:<br> <br>I'm trying to create an SSL certificate for an svn repository. Thanks for any help. <br> <br>_________________________________________________________________<br>Want to do more with Windows Live? Learn “10 hidden secrets” from Jamie.<br><a href="http://windowslive.com/connect/post/jamiethomson.spaces.live.com-Blog-cns" rel="nofollow" class="url" target="_blank">http://windowslive.com/connect/post/jamiethomson.spaces.live.com-Blog-cns</a>!550F681DAD532637!5295.entry?ocid=TXT_TAGLM_WL_domore_092008<br><br><br><br><br>.hmmessage P<br>{<br>margin:0px;<br>padding:0px<br>}<br>body.hmmessage<br>{<br>FONT-SIZE: 10pt;<br>FONT-FAMILY:Tahoma<br>}<br><br><br>I've been trying to secure site with open ssl and have made a number of attempts and have gotten many errors. Any help with the following error would be very helpful. Thanks in advance:<br>&nbsp;<br>I get the following error upon issuing the following command:<br>&nbsp;<br>C:\Program Files\Apache Software Foundation\Apache2.2\bin>openssl req -config openssl.cnf -new -out my-server.csrLoading 'screen' into random state - doneGenerating a 1024 bit RSA private key...++++++.....++++++writing new private key to 'privkey.pem'Enter PEM pass phrase:Verifying - Enter PEM pass phrase:-----You are about to be asked to enter information that will be incorporatedinto your certificate request.What you are about to enter is what is called a Distinguished Name or a DN.There are quite a few fields but you can leave some blankFor some fields there will be a default value,If you enter '.', the field will be left blank.<br>.<br>.<br>A challenge password []:hutchError adding attribute5144:error:0D0BA041:asn1 encoding routines:ASN1_STRING_set:malloc failure:.\crypto\asn1\asn1_lib.c:381:5144:error:0B08A041:x509 certificate routines:X509_ATTRIBUTE_set1_data:malloc failure:.\crypto\x509\x509_att.c:317:<br>&nbsp;<br>I'm trying to create an SSL certificate for an svn repository.&nbsp;Thanks for any help.&nbsp;<br>&nbsp;Want to do more with Windows Live? Learn “10 hidden secrets” from Jamie. Learn Now<br><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/problems_making_certificate_request_160051115t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/problems_making_certificate_request_160051115m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 09:27:12 PDT</pubDate>
</item>
<item>
	<title><![CDATA[Creating private key]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/creating_private_key_160051627t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/creating_private_key_160051627t.html</link>
	<description><![CDATA[<br>Hi all,<br>I want generate a private key and certificate using openssl commands<br>Earlier I was generating both these files using <br>openssl req -config /usr/local/ssl/openssl.cnf -new -x509 -keyout private/cakey.pem -out cacert.pem -days 365<br>That time I was getting the error "asn1 encoding routines:ASN1_get_object:header too long:asn_lib.c"<br>Then I started creating private key using the command<br>openssl genrsa > cakey.pem<br>and I was using certificate file from the above command.<br><br>Now I get the errors<br>14478:error:0B080074:x509 certificate routines:X509_check_private_key:key values mismatch:x509_cmp.c:399:<br>14478:error:2107207F:PKCS7 routines:PKCS7_decrypt:private key does not match certificate:pk7_smime.c:465:<br><br>Both these errors indicate mismatch between private key and the certificate file<br>Please suggest me any method to generate both these files such that I get the error free response.<br><br>Thanks in advance to all of you <br>Please help me<br>Regards,<br>Abhishek<br><br>________________________________________<br>Public email at <a href="http://Nabble.com" rel="nofollow" class="url" target="_blank">Nabble.com</a><br>______________________________________________________________________<br>OpenSSL Project                                 <a href="http://www.openssl.org" rel="nofollow" class="url" target="_blank">http://www.openssl.org</a><br>User Support Mailing List                    openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Automated List Manager                           majordomo@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/creating_private_key_160051627t.html"><b>1</b> Comment</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/creating_private_key_160051627m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 07:39:48 PDT</pubDate>
</item>
<item>
	<title><![CDATA[perform a key exchange (key negotiation) using asymmetric keys (no certifications!)]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/perform_a_key_exchange_key_negotiation_using_asymmetric_160000683t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/perform_a_key_exchange_key_negotiation_using_asymmetric_160000683t.html</link>
	<description><![CDATA[<br>Hello,<br> <br>could anybody explain me how to modify this programm, to use only keys instead of certificates ?<br> <br>Thanks to all.<br> <br>-------------------------------------------------------------------------------------------------------------------------------------------------<br> <br>/* serv.cpp  -  Minimal ssleay server for Unix<br>   <a href="http://30.9.1996" rel="nofollow" class="url" target="_blank">30.9.1996</a>, Sampo Kellomaki <sampo@iki.fi> */<br> <br><br>/* mangled to work with <a href="http://SSLeay-0.9.0b" rel="nofollow" class="url" target="_blank">SSLeay-0.9.0b</a> and OpenSSL <a href="http://0.9.2b" rel="nofollow" class="url" target="_blank">0.9.2b</a><br>   Simplified to be even more minimal<br>   12/98 - 4/99 Wade Scholine <wades@<a href="http://mail.cybg.com" rel="nofollow" class="url" target="_blank">mail.cybg.com</a>> */<br> <br>#include <stdio.h><br>#include <unistd.h><br>#include <stdlib.h><br>#include <memory.h><br>#include <errno.h><br>#include <sys/types.h><br>#include <sys/socket.h><br>#include <netinet/in.h><br>#include <arpa/inet.h><br>#include <netdb.h><br> <br>#include <openssl/rsa.h>       /* SSLeay stuff */<br>#include <openssl/crypto.h><br>#include <openssl/x509.h><br>#include <openssl/pem.h><br>#include <openssl/ssl.h><br>#include <openssl/err.h><br> <br><br>/* define HOME to be dir for key and cert files... */<br>#define HOME "./"<br>/* Make these what you want for cert & key files */<br>#define CERTF  HOME "foo-cert.pem"<br>#define KEYF  HOME  "foo-cert.pem"<br> <br><br>#define CHK_NULL(x) if ((x)==NULL) exit (1)<br>#define CHK_ERR(err,s) if ((err)==-1) { perror(s); exit(1); }<br>#define CHK_SSL(err) if ((err)==-1) { ERR_print_errors_fp(stderr); exit(2); }<br> <br>void main ()<br>{<br>  int err;<br>  int listen_sd;<br>  int sd;<br>  struct sockaddr_in sa_serv;<br>  struct sockaddr_in sa_cli;<br>  size_t client_len;<br>  SSL_CTX* ctx;<br>  SSL*     ssl;<br>  X509*    client_cert;<br>  char*    str;<br>  char     buf [4096];<br>  SSL_METHOD *meth;<br>  <br>  /* SSL preliminaries. We keep the certificate and key with the context. */<br> <br>  SSL_load_error_strings();<br>  SSLeay_add_ssl_algorithms();<br>  meth = SSLv23_server_method();<br>  ctx = SSL_CTX_new (meth);<br>  if (!ctx) {<br>    ERR_print_errors_fp(stderr);<br>    exit(2);<br>  }<br>  <br>  if (SSL_CTX_use_certificate_file(ctx, CERTF, SSL_FILETYPE_PEM) <= 0) {<br>    ERR_print_errors_fp(stderr);<br>    exit(3);<br>  }<br>  if (SSL_CTX_use_PrivateKey_file(ctx, KEYF, SSL_FILETYPE_PEM) <= 0) {<br>    ERR_print_errors_fp(stderr);<br>    exit(4);<br>  }<br> <br>  if (!SSL_CTX_check_private_key(ctx)) {<br>    fprintf(stderr,"Private key does not match the certificate public key\n");<br>    exit(5);<br>  }<br> <br>  /* ----------------------------------------------- */<br>  /* Prepare TCP socket for receiving connections */<br> <br>  listen_sd = socket (AF_INET, SOCK_STREAM, 0);   CHK_ERR(listen_sd, "socket");<br>  <br>  memset (&sa_serv, '\0', sizeof(sa_serv));<br>  sa_serv.sin_family      = AF_INET;<br>  sa_serv.sin_addr.s_addr = INADDR_ANY;<br>  sa_serv.sin_port        = htons (1111);          /* Server Port number */<br>  <br>  err = bind(listen_sd, (struct sockaddr*) &sa_serv,<br>      sizeof (sa_serv));                   CHK_ERR(err, "bind");<br>      <br>  /* Receive a TCP connection. */<br>      <br>  err = listen (listen_sd, 5);                    CHK_ERR(err, "listen");<br>  <br>  client_len = sizeof(sa_cli);<br>  sd = accept (listen_sd, (struct sockaddr*) &sa_cli, &client_len);<br>  CHK_ERR(sd, "accept");<br>  close (listen_sd);<br> <br>  printf ("Connection from %%lx, port %%x\n",<br>   sa_cli.sin_addr.s_addr, sa_cli.sin_port);<br>  <br>  /* ----------------------------------------------- */<br>  /* TCP connection is ready. Do server side SSL. */<br> <br>  ssl = SSL_new (ctx);                           CHK_NULL(ssl);<br>  SSL_set_fd (ssl, sd);<br>  err = SSL_accept (ssl);                        CHK_SSL(err);<br>  <br>  /* Get the cipher - opt */<br>  <br>  printf ("SSL connection using %%s\n", SSL_get_cipher (ssl));<br>  <br>  /* Get client's certificate (note: beware of dynamic allocation) - opt */<br> <br>  client_cert = SSL_get_peer_certificate (ssl);<br>  if (client_cert != NULL) {<br>    printf ("Client certificate:\n");<br>    <br>    str = X509_NAME_oneline (X509_get_subject_name (client_cert), 0, 0);<br>    CHK_NULL(str);<br>    printf ("\t subject: %%s\n", str);<br>    OPENSSL_free (str);<br>    <br>    str = X509_NAME_oneline (X509_get_issuer_name  (client_cert), 0, 0);<br>    CHK_NULL(str);<br>    printf ("\t issuer: %%s\n", str);<br>    OPENSSL_free (str);<br>    <br>    /* We could do all sorts of certificate verification stuff here before<br>       deallocating the certificate. */<br>    <br>    X509_free (client_cert);<br>  } else<br>    printf ("Client does not have certificate.\n");<br> <br>  /* DATA EXCHANGE - Receive message and send reply. */<br> <br>  err = SSL_read (ssl, buf, sizeof(buf) - 1);                   CHK_SSL(err);<br>  buf[err] = '\0';<br>  printf ("Got %%d chars:'%%s'\n", err, buf);<br>  <br>  err = SSL_write (ssl, "I hear you.", strlen("I hear you."));  CHK_SSL(err);<br> <br>  /* Clean up. */<br> <br>  close (sd);<br>  SSL_free (ssl);<br>  SSL_CTX_free (ctx);<br>}<br>/* EOF - serv.cpp */<br><br><br><br><br><br><br>Hello,<br>&nbsp;<br>could anybody explain me how to modify this programm, to use only keys instead of certificates ?<br>&nbsp;<br>Thanks to all.<br>&nbsp;<br>-------------------------------------------------------------------------------------------------------------------------------------------------<br>&nbsp;<br>/* serv.cpp&nbsp; -&nbsp; Minimal ssleay server for Unix&nbsp;&nbsp; <a href="http://30.9.1996" rel="nofollow" class="url" target="_blank">30.9.1996</a>, Sampo Kellomaki  */<br>&nbsp;<br>/* mangled to work with <a href="http://SSLeay-0.9.0b" rel="nofollow" class="url" target="_blank">SSLeay-0.9.0b</a> and OpenSSL <a href="http://0.9.2b&nbsp;&nbsp" rel="nofollow" class="url" target="_blank">0.9.2b&nbsp;&nbsp</a>; Simplified to be even more minimal&nbsp;&nbsp; 12/98 - 4/99 Wade Scholine  */<br>&nbsp;<br>#include #include #include #include #include #include #include #include #include #include <br>&nbsp;<br>#include &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; /* SSLeay stuff */#include #include #include #include #include <br>&nbsp;<br>/* define HOME to be dir for key and cert files... */#define HOME "./"/* Make these what you want for cert & key files */#define CERTF&nbsp; HOME "foo-cert.pem"#define KEYF&nbsp; HOME&nbsp; "foo-cert.pem"<br>&nbsp;<br>#define CHK_NULL(x) if ((x)==NULL) exit (1)#define CHK_ERR(err,s) if ((err)==-1) { perror(s); exit(1); }#define CHK_SSL(err) if ((err)==-1) { ERR_print_errors_fp(stderr); exit(2); }<br>&nbsp;<br>void main (){&nbsp; int err;&nbsp; int listen_sd;&nbsp; int sd;&nbsp; struct sockaddr_in sa_serv;&nbsp; struct sockaddr_in sa_cli;&nbsp; size_t client_len;&nbsp; SSL_CTX* ctx;&nbsp; SSL*&nbsp;&nbsp;&nbsp;&nbsp; ssl;&nbsp; X509*&nbsp;&nbsp;&nbsp; client_cert;&nbsp; char*&nbsp;&nbsp;&nbsp; str;&nbsp; char&nbsp;&nbsp;&nbsp;&nbsp; buf [4096];&nbsp; SSL_METHOD *meth;&nbsp; &nbsp; /* SSL preliminaries. We keep the certificate and key with the context. */<br>&nbsp;<br>&nbsp; SSL_load_error_strings();&nbsp; SSLeay_add_ssl_algorithms();&nbsp; meth = SSLv23_server_method();&nbsp; ctx = SSL_CTX_new (meth);&nbsp; if (!ctx) {&nbsp;&nbsp;&nbsp; ERR_print_errors_fp(stderr);&nbsp;&nbsp;&nbsp; exit(2);&nbsp; }&nbsp; &nbsp; if (SSL_CTX_use_certificate_file(ctx, CERTF, SSL_FILETYPE_PEM) <br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/perform_a_key_exchange_key_negotiation_using_asymmetric_160000683t.html"><b>1</b> Comment</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/perform_a_key_exchange_key_negotiation_using_asymmetric_160000683m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 03:29:01 PDT</pubDate>
</item>
<item>
	<title><![CDATA[RSA_padding_check_PKCS1_type_1]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/rsa_padding_check_pkcs1_type_1_160006315t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/rsa_padding_check_pkcs1_type_1_160006315t.html</link>
	<description><![CDATA[<br>Hi all,<br><br>I am very new to openssl.<br>I am trying to create a certificate using scep. I am using <a href="http://opnessl-0.9.8h" rel="nofollow" class="url" target="_blank">opnessl-0.9.8h</a> for thsi implementation<br>I am using a private key generated using openssl genrsa > cakey.pem command.<br>for creating certificate I am using the following command.<br>openssl req -config /usr/local/ssl/openssl.cnf -new -x509 -keyout private/cakey.pem -out cacert.pem -days 365<br><br>I am getting the following error on the scep server side <br>24818:error:0407006A:rsa routines:RSA_padding_check_PKCS1_type_1:block type is not 01:rsa_pk1.c:100:<br>24818:error:04067072:rsa routines:RSA_EAY_PUBLIC_DECRYPT:padding check failed:rsa_eay.c:699:<br>24818:error:21071069:PKCS7 routines:PKCS7_signatureVerify:signature failure:pk7_doit.c:981:<br><br><br>also if use the cakey.pem genrates using <br>openssl req -config /usr/local/ssl/openssl.cnf -new -x509 -keyout private/cakey.pem -out cacert.pem -days 365<br>command I get following error<br>8848:error:0D07207B:asn1 encoding routines:ASN1_get_object:header too long:asn1_lib.c:150<br>So I have to use the private key generated using openssl genrsa > cakey.pem method.<br>Please help me, how to resolve this error<br><br>Thanks in advance.<br>Regards,<br>Abhishek<br><br>________________________________________<br>Public email at <a href="http://Nabble.com" rel="nofollow" class="url" target="_blank">Nabble.com</a><br>______________________________________________________________________<br>OpenSSL Project                                 <a href="http://www.openssl.org" rel="nofollow" class="url" target="_blank">http://www.openssl.org</a><br>User Support Mailing List                    openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Automated List Manager                           majordomo@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/rsa_padding_check_pkcs1_type_1_160006315t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/rsa_padding_check_pkcs1_type_1_160006315m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 02:56:42 PDT</pubDate>
</item>
<item>
	<title><![CDATA[rsa routines:RSA_padding_check_PKCS1_type_1:block type is not 01:rsa_pk1.c]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/rsa_routines_rsa_padding_check_pkcs1_type_1_block_type_159994539t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/rsa_routines_rsa_padding_check_pkcs1_type_1_block_type_159994539t.html</link>
	<description><![CDATA[<br>Hi all,<br>I am working with <a href="http://openssl-0.9.8h" rel="nofollow" class="url" target="_blank">openssl-0.9.8h</a> to generate SCEP certificates. I am getting<br>the following errors while the SCEP server is trying to verify the<br>signatures:<br><br>24293:error:0407006A:rsa routines:RSA_padding_check_PKCS1_type_1:block type<br>is not 01:rsa_pk1.c:100:<br>24293:error:04067072:rsa routines:RSA_EAY_PUBLIC_DECRYPT:padding check<br>failed:rsa_eay.c:699:<br>24293:error:21071069:PKCS7 routines:PKCS7_signatureVerify:signature<br>failure:pk7_doit.c:981:<br><br>I have generated my private key through openssl genrsa >cakey.pem  and<br>certificate using openssl req -config /usr/local/ssl/openssl.cnf -new -x509<br>-keyout private/cakey.pem -out cacert.pem -days 365.<br>Can anybody tell me how can I add padding to my certificate signing request.<br><br>Please help me.<br><br>Thanks in advance.<br>Regards,<br>Abhishek<br>-- <br>View this message in context: <a href="http://www.nabble.com/rsa-routines%%3ARSA_padding_check_PKCS1_type_1%%3Ablock-type-is-not-01%%3Arsa_pk1.c-tp19306475p19306475.html" rel="nofollow" class="url" target="_blank">http://www.nabble.com/rsa-routines%%3ARSA_padding_check_PKCS1_type_1%%3Ablock-type...</a><br>Sent from the OpenSSL - User mailing list archive at <a href="http://Nabble.com" rel="nofollow" class="url" target="_blank">Nabble.com</a>.<br>______________________________________________________________________<br>OpenSSL Project                                 <a href="http://www.openssl.org" rel="nofollow" class="url" target="_blank">http://www.openssl.org</a><br>User Support Mailing List                    openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Automated List Manager                           majordomo@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/rsa_routines_rsa_padding_check_pkcs1_type_1_block_type_159994539t.html"><b>2</b> Comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/rsa_routines_rsa_padding_check_pkcs1_type_1_block_type_159994539m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Thu, 04 Sep 2008 02:20:54 PDT</pubDate>
</item>
<item>
	<title><![CDATA[how to query out crl by using DirName in crl distribution field]]></title>
	<guid>http://www.nnseek.com/e/mailing.openssl.users/how_to_query_out_crl_by_using_dirname_in_crl_distribution_159983019t.html</guid>
	<link>http://www.nnseek.com/e/mailing.openssl.users/how_to_query_out_crl_by_using_dirname_in_crl_distribution_159983019t.html</link>
	<description><![CDATA[<br>Dear all:<br><br>I have a CA certificate. Its distributionPoint field contains a<br>directoryName(DirName). It's a DN in LDAP. So, if I get ldap server ip and<br>reserve whatever configured in DirName, can I do ldapsearch? If not, how can<br>I query out crl by using this DirName. And again, it points to an entry in<br>LDAP.<br><br>Many many thanks for any kind help.<br><br>Best Regards<br>Jean<br>-- <br>View this message in context: <a href="http://www.nabble.com/how-to-query-out-crl-by-using-DirName-in-crl-distribution-field-tp19303717p19303717.html" rel="nofollow" class="url" target="_blank">http://www.nabble.com/how-to-query-out-crl-by-using-DirName-in-crl-distribution-field...</a><br>Sent from the OpenSSL - User mailing list archive at <a href="http://Nabble.com" rel="nofollow" class="url" target="_blank">Nabble.com</a>.<br>______________________________________________________________________<br>OpenSSL Project                                 <a href="http://www.openssl.org" rel="nofollow" class="url" target="_blank">http://www.openssl.org</a><br>User Support Mailing List                    openssl-users@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br>Automated List Manager                           majordomo@<a href="http://openssl.org" rel="nofollow" class="url" target="_blank">openssl.org</a><br><br>
    <table border="0" cellspacing="0" cellpadding="0">
      <tr>
        <td width="30">&nbsp;</td>
        <td>Posted In: <a href="http://www.nnseek.com/e/mailing.openssl.users/">mailing.openssl.users</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/how_to_query_out_crl_by_using_dirname_in_crl_distribution_159983019t.html">no comments</a></td>
        <td width="20">&nbsp;</td>
        <td><a href="http://www.nnseek.com/e/mailing.openssl.users/how_to_query_out_crl_by_using_dirname_in_crl_distribution_159983019m.html">Reply</a></td>
      </tr></table><br>]]></description>
	<pubDate>Wed, 03 Sep 2008 22:43:33 PDT</pubDate>
</item>
</channel>
</rss>