Tim Hudson

Results 26 comments of Tim Hudson

This is a feature addition - this is not in the fips provider and it is being added. It is not a simple addition of a "test". As such it...

I think the issue here is that it should be kept in the tree *and* there should be a CI target that actually uses it. Uncompiled code isn't all that...

The mistake of dereferencing what could be a NULL pointer return occurs in more than this place in the CMS code. **Every** call to CMS_get0_RecipientInfos or ossl_cms_get0_env_enc_content needs to be...

> Agreed - except for cases where the context already prevents an unsuitable content type, which may be non-trivial to determine at places. Which is why checking in **all** places...

FYI https://csrc.nist.gov/projects/pki-testing is the web page from which the test data is located.

https://openssl-library.org/source/index.html notes the EOL date for 3.3 ~~The older (defunct) release strategy page is no more.~~