LinuxQuestions.org
Go Job Hunting at the LQ Job Marketplace
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Distributions > Slackware
User Name
Password
Slackware This Forum is for the discussion of Slackware Linux.

Notices

Reply
 
Search this Thread
Old 02-10-2013, 05:31 PM   #1
Cesare
LQ Newbie
 
Registered: Jun 2010
Posts: 27

Rep: Reputation: 31
OpenSSL 1.0.1d + AES-NI


After today's OpenSSL update I was a bit surprised when alpine stopped working and random characters were appearing in the dialogue when I tested IMAP manually with OpenSSL's s_client. Interestingly it affected only one of my machines.

Apparently there's a regression in the current OpenSSL 1.0.1d that corrupts the data
stream on CPUs with AES-NI, see http://article.gmane.org/gmane.comp....sl.devel/22137 and follow-ups.

If you've got a CPU with AES-NI (i5, i7, ...) consider rebuilding the 1.0.1d package with the patch from http://git.openssl.org/gitweb/?p=ope...diff;h=32cc247 before upgrading. In my case the patch solved the problem.
 
Old 02-10-2013, 07:40 PM   #2
TommyC7
Member
 
Registered: Mar 2012
Distribution: Slackware, CentOS, OpenBSD, FreeBSD
Posts: 436

Rep: Reputation: Disabled
Thank you Cesare!

I had the same exact problem with irssi when connecting securely since my CPU does have AES-NI:
Code:
/connect -ssl_verify -ssl_capath /etc/ssl/certs chat.freenode.net 7070 # this generated similar random characters you speak of
# whereas:
/connect irc.freenode.net 6667 # did not generate said random characters and worked fine
Hopefully openssl gets rebuilt soon by the Slackware team.
 
  


Reply


Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
OpenSSL, aes.h, AES_cbc_encrypt(): length parameter? Brandon9000 Programming 5 12-06-2012 04:42 PM
OPENSSL AES-128-CBC Encoding Format AbdulKabani Linux - Newbie 0 05-20-2012 10:29 AM
OpenSSL Encryption with AES kaplan71 Linux - Software 3 11-26-2008 12:46 PM
Openssl Certificate Generation Question AES richinsc Linux - Security 11 09-18-2008 10:48 AM
AES for openssh and openssl powah Linux - Software 1 04-21-2008 08:59 AM


All times are GMT -5. The time now is 08:16 AM.

Main Menu
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
identi.ca: @linuxquestions
Facebook: linuxquestions Google+: linuxquestions
Open Source Consulting | Domain Registration