<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Marketgrid Consulting Blog &#187; OpenSSL</title>
	<atom:link href="http://www.marketgrid.com/blog/tag/openssl/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.marketgrid.com/blog</link>
	<description>MySQL, website development and performance news</description>
	<lastBuildDate>Wed, 01 Sep 2010 11:00:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0.1</generator>
		<item>
		<title>OpenSSL version 1.0.0a</title>
		<link>http://www.marketgrid.com/blog/2010/06/openssl-version-1-0-0a/</link>
		<comments>http://www.marketgrid.com/blog/2010/06/openssl-version-1-0-0a/#comments</comments>
		<pubDate>Sat, 05 Jun 2010 15:24:16 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[OpenSSL]]></category>
		<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=195</guid>
		<description><![CDATA[The OpenSSL project team has released version 1.0.0a of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bugfix release which addresses CVE-2010-1633 and CVE-2010-0742. For a complete list of changes, please see http://www.openssl.org/source/exp/CHANGES. OpenSSL 1.0.0a is considered to be the best version of OpenSSL available and we strongly recommend [...]]]></description>
			<content:encoded><![CDATA[<p>The OpenSSL project team has released version 1.0.0a of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bugfix release which addresses CVE-2010-1633 and CVE-2010-0742. For a complete list of changes, please see <a href="http://www.openssl.org/source/exp/CHANGES">http://www.openssl.org/source/exp/CHANGES</a>.</p>
<p>OpenSSL 1.0.0a is considered to be the best version of OpenSSL available and we strongly recommend that users of older versions upgrade as soon as possible. OpenSSL 1.0.0a is available for</p>
<p>download via HTTP and FTP from the following master locations (you can find the various FTP mirrors under <a href="http://www.openssl.org/source/mirror.html">http://www.openssl.org/source/mirror.html</a>):</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/06/openssl-version-1-0-0a/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL version 0.9.8o</title>
		<link>http://www.marketgrid.com/blog/2010/06/openssl-version-0-9-8o/</link>
		<comments>http://www.marketgrid.com/blog/2010/06/openssl-version-0-9-8o/#comments</comments>
		<pubDate>Sat, 05 Jun 2010 15:22:57 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[OpenSSL]]></category>
		<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=193</guid>
		<description><![CDATA[The OpenSSL project team has released version 0.9.8o of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bugfix release which addresses CVE-2010-0742. For a complete list of changes, please see http://www.openssl.org/source/exp/CHANGES. OpenSSL 1.0.0a is available for download via HTTP and FTP from the following master locations (you can find [...]]]></description>
			<content:encoded><![CDATA[<p>The OpenSSL project team has released version 0.9.8o of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bugfix release which addresses CVE-2010-0742. For a complete list of changes, please see <a href="http://www.openssl.org/source/exp/CHANGES">http://www.openssl.org/source/exp/CHANGES</a>.</p>
<p>OpenSSL 1.0.0a is available for download via HTTP and FTP from the following master locations (you can find the various FTP mirrors under <a href="http://www.openssl.org/source/mirror.html">http://www.openssl.org/source/mirror.html</a>):</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/06/openssl-version-0-9-8o/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL version 1.0.0 released</title>
		<link>http://www.marketgrid.com/blog/2010/03/openssl-version-1-0-0-released/</link>
		<comments>http://www.marketgrid.com/blog/2010/03/openssl-version-1-0-0-released/#comments</comments>
		<pubDate>Wed, 31 Mar 2010 20:24:56 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[OpenSSL]]></category>
		<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=169</guid>
		<description><![CDATA[OpenSSL &#8211; The Open Source toolkit for SSL/TLS http://www.openssl.org/ The OpenSSL project team had announced the release of version 1.0.0 of the open source toolkit for SSL/TLS. This new OpenSSL version is a major release and incorporates many new features as well as major fixes compared to 0.9.8n.  For a complete list of changes, please [...]]]></description>
			<content:encoded><![CDATA[<p>OpenSSL &#8211; The Open Source toolkit for SSL/TLS</p>
<p><a href="http://www.openssl.org/">http://www.openssl.org/</a></p>
<p>The OpenSSL project team had announced the release of version 1.0.0 of the open source toolkit for SSL/TLS.</p>
<p>This new OpenSSL version is a major release and incorporates many new features as well as major fixes compared to 0.9.8n.  For a complete list of changes, please see <a href="http://www.openssl.org/source/exp/CHANGES">http://www.openssl.org/source/exp/CHANGES</a> .</p>
<p>The most significant changes are:</p>
<p>o RFC3280 path validation: sufficient to process PKITS tests.</p>
<p>o Integrated support for PVK files and keyblobs.</p>
<p>o Change default private key format to PKCS#8.</p>
<p>o CMS support: able to process all examples in RFC4134</p>
<p>o Streaming ASN1 encode support for PKCS#7 and CMS.</p>
<p>o Multiple signer and signer add support for PKCS#7 and CMS.</p>
<p>o ASN1 printing support.</p>
<p>o Whirlpool hash algorithm added.</p>
<p>o RFC3161 time stamp support.</p>
<p>o New generalised public key API supporting ENGINE based algorithms.</p>
<p>o New generalised public key API utilities.</p>
<p>o New ENGINE supporting GOST algorithms.</p>
<p>o SSL/TLS GOST ciphersuite support.</p>
<p>o PKCS#7 and CMS GOST support.</p>
<p>o RFC4279 PSK ciphersuite support.</p>
<p>o Supported points format extension for ECC ciphersuites.</p>
<p>o ecdsa-with-SHA224/256/384/512 signature types.</p>
<p>o dsa-with-SHA224 and dsa-with-SHA256 signature types.</p>
<p>o Opaque PRF Input TLS extension support.</p>
<p>o Updated time routines to avoid OS limitations.</p>
<p>We consider OpenSSL 1.0.0 to be the best version of OpenSSL available and we strongly recommend that users of older versions upgrade as soon as possible.  OpenSSL 1.0.0 is available for download via HTTP and FTP from the following master locations (you can find the various FTP mirrors under <a href="http://www.openssl.org/source/mirror.html">http://www.openssl.org/source/mirror.html</a>):</p>
<p>* <a href="http://www.openssl.org/source/">http://www.openssl.org/source/</a></p>
<p>* <a href="ftp://ftp.openssl.org/source/">ftp://ftp.openssl.org/source/</a></p>
<p>The distribution file name is:</p>
<p>o openssl-1.0.0.tar.gz</p>
<p>Size: 4010166</p>
<p>MD5 checksum: 89eaa86e25b2845f920ec00ae4c864ed</p>
<p>SHA1 checksum: 3f800ea9fa3da1c0f576d689be7dca3d55a4cb62</p>
<p>The checksums were calculated using the following commands:</p>
<p>openssl md5 openssl-1.0.0.tar.gz</p>
<p>openssl sha1 openssl-1.0.0.tar.gz</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/03/openssl-version-1-0-0-released/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL version 0.9.8n</title>
		<link>http://www.marketgrid.com/blog/2010/03/openssl-version-0-9-8n/</link>
		<comments>http://www.marketgrid.com/blog/2010/03/openssl-version-0-9-8n/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 23:19:07 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[OpenSSL]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=167</guid>
		<description><![CDATA[OpenSSL &#8211; The Open Source toolkit for SSL/TLS http://www.openssl.org/ The OpenSSL project team has announced the release of version 0.9.8n of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bugfix release which addresses CVE-2010-0740. For a complete list of changes, please see http://www.openssl.org/source/exp/CHANGES.]]></description>
			<content:encoded><![CDATA[<p>OpenSSL &#8211; The Open Source toolkit for SSL/TLS <a href="http://www.openssl.org/">http://www.openssl.org/</a></p>
<p>The OpenSSL project team has announced the release of version 0.9.8n of the open source toolkit for SSL/TLS.</p>
<p>This new OpenSSL version is a security and bugfix release which addresses CVE-2010-0740.</p>
<p>For a complete list of changes, please see <a href="http://www.openssl.org/source/exp/CHANGES">http://www.openssl.org/source/exp/CHANGES</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/03/openssl-version-0-9-8n/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL Security Advisory</title>
		<link>http://www.marketgrid.com/blog/2010/03/openssl-security-advisory/</link>
		<comments>http://www.marketgrid.com/blog/2010/03/openssl-security-advisory/#comments</comments>
		<pubDate>Wed, 24 Mar 2010 23:13:13 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[OpenSSL]]></category>
		<category><![CDATA[Releases]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=164</guid>
		<description><![CDATA[&#8220;Record of death&#8221; vulnerability in OpenSSL 0.9.8f through 0.9.8m ================================================================ In TLS connections, certain incorrectly formatted records can cause an OpenSSL client or server to crash due to a read attempt at NULL. Affected versions depend on the C compiler used with OpenSSL: - &#8211; If &#8216;short&#8217; is a 16-bit integer, this issue applies only [...]]]></description>
			<content:encoded><![CDATA[<p>&#8220;Record of death&#8221; vulnerability in OpenSSL 0.9.8f through 0.9.8m</p>
<p>================================================================</p>
<p>In TLS connections, certain incorrectly formatted records can cause an OpenSSL</p>
<p>client or server to crash due to a read attempt at NULL.</p>
<p>Affected versions depend on the C compiler used with OpenSSL:</p>
<p>- &#8211; If &#8216;short&#8217; is a 16-bit integer, this issue applies only to OpenSSL 0.9.8m.</p>
<p>- &#8211; Otherwise, this issue applies to OpenSSL 0.9.8f through 0.9.8m.</p>
<p>Users of OpenSSL should update to the OpenSSL 0.9.8n release, which contains a</p>
<p>patch to correct this issue.  If upgrading is not immediately possible, the</p>
<p>source code patch provided in this advisory should be applied.</p>
<p>Bodo Moeller and Adam Langley (Google) have identified the vulnerability</p>
<p>and prepared the fix.</p>
<p>Patch</p>
<p>- &#8212;&#8211;</p>
<pre>- --- ssl/s3_pkt.c      24 Jan 2010 13:52:38 -0000    1.57.2.9</pre>
<pre>+++ ssl/s3_pkt.c  24 Mar 2010 00:00:00 -0000</pre>
<pre>@@ -291,9 +291,9 @@</pre>
<pre>if (version != s-&gt;version)</pre>
<pre>{</pre>
<pre>SSLerr(SSL_F_SSL3_GET_RECORD,SSL_R_WRONG_VERSION_NUMBER);</pre>
<pre>- -                     /* Send back error using their</pre>
<pre>- -                      * version number <img src='http://www.marketgrid.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  */</pre>
<pre>- -                     s-&gt;version=version;</pre>
<pre>+                                if ((s-&gt;version &amp; 0xFF00) == (version &amp; 0xFF00))</pre>
<pre>+                                   /* Send back error using their minor version number <img src='http://www.marketgrid.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':-)' class='wp-smiley' />  */</pre>
<pre>+                             s-&gt;version = (unsigned short)version;</pre>
<pre>al=SSL_AD_PROTOCOL_VERSION;</pre>
<pre>goto f_err;</pre>
<pre>}</pre>
<p>References</p>
<p>- &#8212;&#8212;&#8212;-</p>
<p>This vulnerability is tracked as CVE-2010-0740.</p>
<p>URL for this Security Advisory:</p>
<p><a href="http://www.openssl.org/news/secadv_20100324.txt">http://www.openssl.org/news/secadv_20100324.txt</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/03/openssl-security-advisory/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL 0.9.8m</title>
		<link>http://www.marketgrid.com/blog/2010/02/openssl-0-9-8m/</link>
		<comments>http://www.marketgrid.com/blog/2010/02/openssl-0-9-8m/#comments</comments>
		<pubDate>Fri, 26 Feb 2010 01:20:20 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Releases]]></category>
		<category><![CDATA[OpenSSL]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=116</guid>
		<description><![CDATA[The OpenSSL project team has announced the release of version 0.9.8m of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bugfix release which implements RFC5746 to address renegotiation vulnerabilities mentioned in CVE-2009-3555.]]></description>
			<content:encoded><![CDATA[<p>The OpenSSL project team has announced the release of version 0.9.8m of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bugfix release which implements RFC5746 to address renegotiation vulnerabilities mentioned in CVE-2009-3555.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/02/openssl-0-9-8m/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL 0.9.8m-beta1</title>
		<link>http://www.marketgrid.com/blog/2010/01/openssl-0-9-8m-beta1/</link>
		<comments>http://www.marketgrid.com/blog/2010/01/openssl-0-9-8m-beta1/#comments</comments>
		<pubDate>Thu, 21 Jan 2010 13:26:46 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Releases]]></category>
		<category><![CDATA[OpenSSL]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=81</guid>
		<description><![CDATA[OpenSSL &#8211; The Open Source toolkit for SSL/TLS http://www.openssl.org/ The OpenSSL project team has announced the release of version 0.9.8m-beta1 of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bug fix beta release which implements draft-ietf-tls-renegotiation-03.txt to address CVE-2009-3555. For a complete list of changes, please see http://www.openssl.org/source/exp/CHANGES. They [...]]]></description>
			<content:encoded><![CDATA[<p><span><span style="font-size: x-small;">OpenSSL &#8211; The Open Source toolkit for SSL/TLS<br />
<a href="https://exchange.simplyms.com/owa/redir.aspx?C=26991df35ae94d76bec8b75fd596a863&amp;URL=http%3a%2f%2fwww.openssl.org%2f" target="_blank">http://www.openssl.org/</a></p>
<p>The OpenSSL project team has announced the release of version 0.9.8m-beta1 of the open source toolkit for SSL/TLS. This new OpenSSL version is a security and bug fix beta release which implements draft-ietf-tls-renegotiation-03.txt to address CVE-2009-3555. For a complete list of changes, please see <a href="https://exchange.simplyms.com/owa/redir.aspx?C=26991df35ae94d76bec8b75fd596a863&amp;URL=http%3a%2f%2fwww.openssl.org%2fsource%2fexp%2fCHANGES" target="_blank">http://www.openssl.org/source/exp/CHANGES</a>.</p>
<p>They have taken the unusual step of releasing a beta from the stable branch of OpenSSL for two reasons. </span></span></p>
<p><span><span style="font-size: x-small;">Firstly the renegotiation specification may change before they are finalised. </span></span></p>
<p><span><span style="font-size: x-small;">Secondly a large number of changes in OpenSSL 0.9.8 have been made since the last release and a beta release<br />
should encourage testing and help resolve any issues before the final release.</p>
<p>It is expected that this will be the only beta release of OpenSSL 0.9.8m.</span></span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/01/openssl-0-9-8m-beta1/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>OpenSSL version 1.0.0 Beta 5</title>
		<link>http://www.marketgrid.com/blog/2010/01/openssl-version-1-0-0-beta-5/</link>
		<comments>http://www.marketgrid.com/blog/2010/01/openssl-version-1-0-0-beta-5/#comments</comments>
		<pubDate>Wed, 20 Jan 2010 19:16:02 +0000</pubDate>
		<dc:creator>Phil Smith</dc:creator>
				<category><![CDATA[Releases]]></category>
		<category><![CDATA[OpenSSL]]></category>

		<guid isPermaLink="false">http://www.marketgrid.com/blog/?p=77</guid>
		<description><![CDATA[OpenSSL &#8211; The Open Source toolkit for SSL/TLS http://www.openssl.org/ OpenSSL is currently in a release cycle. The fifth beta is now released. This is expected be the final beta depending on the number of bugs reported. The beta release is available for download via HTTP and FTP from the following master locations (the various FTP [...]]]></description>
			<content:encoded><![CDATA[<p>OpenSSL &#8211; The Open Source toolkit for SSL/TLS</p>
<p><a href="http://www.openssl.org/">http://www.openssl.org/</a></p>
<p>OpenSSL is currently in a release cycle. The fifth beta is now released. This is expected be the final beta depending on the number of bugs reported.</p>
<p>The beta release is available for download via HTTP and FTP from the following master locations (the various FTP mirrors you can find under <a href="http://www.openssl.org/source/mirror.html">http://www.openssl.org/source/mirror.html</a>):</p>
<p>o <a href="http://www.openssl.org/source/">http://www.openssl.org/source/</a></p>
<p>o <a href="ftp://ftp.openssl.org/source/">ftp://ftp.openssl.org/source/</a></p>
<p>This new OpenSSL version incorporates 122 documented changes and bugfixes to the toolkit (for a complete list see <a href="http://www.openssl.org/source/exp/CHANGES">http://www.openssl.org/source/exp/CHANGES</a>).</p>
]]></content:encoded>
			<wfw:commentRss>http://www.marketgrid.com/blog/2010/01/openssl-version-1-0-0-beta-5/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
