Alex Gaynor

Results 324 comments of Alex Gaynor

That's right. On Tue, Nov 30, 2021 at 6:43 PM Tony Homer ***@***.***> wrote: > > I think I get it. > > The current PKCS#1 v1.5 API in python-cryptography...

The status of this ticket has not changed. As we have expressed: this issue has been mitigated as well as is possible under our current APIs, and if someone is...

The cause of this is almost certainly our upgrade to OpenSSL 3.0, which has a new algorithm for checking the validity of RSA private keys, which is known to be...

Thanks for sharing your use case. I think we'd like to find a way to help address this. The wrinkle is that the implication of skipping these checks are... unclear....

autobahn is a very large package, and this report doesn't contain anything that helps us to debug or reproduce this. 37.0.4 contains only bumps in the openssl version versus 37.0.2...

Certainly possible. Are you able to provide a reproducer we can run?

In the absence of some way for us to reproduce, it will be very difficult for us to debug and remediate this. A Dockerfile for the server with a self-signed...

Hi folks, Now that we've established that this isn't a pyca/cryptography bug, I'm going to close this out since I think it'd be more appropriate to continue teh debugging elsewhere....

An honest assessment is that this issue isn't likely to make progress unless a contributor is particularly excited about figuring out a design and doing the implementation.

I'm a bit nervous about merging this -- it can't be shipped until aws-encryption-sdk is shipped and most users are updated.