Tim Hudson

Results 41 comments of Tim Hudson

This is a feature addition - this is not in the fips provider and it is being added. It is not a simple addition of a "test". As such it...

I think the issue here is that it should be kept in the tree *and* there should be a CI target that actually uses it. Uncompiled code isn't all that...

The mistake of dereferencing what could be a NULL pointer return occurs in more than this place in the CMS code. **Every** call to CMS_get0_RecipientInfos or ossl_cms_get0_env_enc_content needs to be...

> Agreed - except for cases where the context already prevents an unsuitable content type, which may be non-trivial to determine at places. Which is why checking in **all** places...

FYI https://csrc.nist.gov/projects/pki-testing is the web page from which the test data is located.

https://openssl-library.org/source/index.html notes the EOL date for 3.3 ~~The older (defunct) release strategy page is no more.~~

Vote: +1 But I would select the '@' rather than '\\' indicator as it is much more "readable" and common.

No - the main reason we stick to earlier versions is so that OpenSSL can go across the widest range of platforms and that is not just on Windows. People...

This issue has both technical and business implications (in terms of what platforms can be supported) It would IMHO require an OMC decision to move forward on this (on the...

I'm not against the concept of adding this - I think we are a general purpose library - and BIGNUM is very much part of that. It is absolutely not...