Rocksolid Light

Welcome to RetroBBS

mail  files  register  newsreader  groups  login

Message-ID:  

You can do more with a kind word and a gun than with just a kind word. -- Al Capone


computers / comp.sys.tandem / Re: Question for Everyone Regarding ITUGLIB

SubjectAuthor
* Question for Everyone Regarding ITUGLIBRandall
`* Re: Question for Everyone Regarding ITUGLIBred floyd
 `* Re: Question for Everyone Regarding ITUGLIBRandall
  `- Re: Question for Everyone Regarding ITUGLIBRandall

1
Question for Everyone Regarding ITUGLIB

<75544fd9-8386-4ab3-bb4a-61145f788eefn@googlegroups.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=309&group=comp.sys.tandem#309

  copy link   Newsgroups: comp.sys.tandem
X-Received: by 2002:a05:620a:95c:: with SMTP id w28mr5516964qkw.229.1640372519629;
Fri, 24 Dec 2021 11:01:59 -0800 (PST)
X-Received: by 2002:a25:c00c:: with SMTP id c12mr7051883ybf.99.1640372519442;
Fri, 24 Dec 2021 11:01:59 -0800 (PST)
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!border2.nntp.dca1.giganews.com!nntp.giganews.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.sys.tandem
Date: Fri, 24 Dec 2021 11:01:59 -0800 (PST)
Injection-Info: google-groups.googlegroups.com; posting-host=2607:fea8:3ddf:f2b0:1d92:5b76:a185:3f41;
posting-account=6VebZwoAAAAgrpUtsowyjrKRLNlqxnXo
NNTP-Posting-Host: 2607:fea8:3ddf:f2b0:1d92:5b76:a185:3f41
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <75544fd9-8386-4ab3-bb4a-61145f788eefn@googlegroups.com>
Subject: Question for Everyone Regarding ITUGLIB
From: rsbecker@nexbridge.com (Randall)
Injection-Date: Fri, 24 Dec 2021 19:01:59 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Lines: 8
 by: Randall - Fri, 24 Dec 2021 19:01 UTC

Hi Everyone,

I noticed that most of the OpenSSL downloads are still from the 1.0.2 series or older - there was recently even a 1.0.1 download. Is anyone having difficulty with the more recent versions of builds done by ITUGLIB? Are the builds on too recent RVUs? Is there something we can do better?

Thanks,
Randall

Re: Question for Everyone Regarding ITUGLIB

<sq59gb$983$1@redfloyd.dont-email.me>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=310&group=comp.sys.tandem#310

  copy link   Newsgroups: comp.sys.tandem
X-Received: by 2002:a05:620a:95c:: with SMTP id w28mr5516964qkw.229.1640372519629;
Fri, 24 Dec 2021 11:01:59 -0800 (PST)
X-Received: by 2002:a25:c00c:: with SMTP id c12mr7051883ybf.99.1640372519442;
Fri, 24 Dec 2021 11:01:59 -0800 (PST)
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!border2.nntp.dca1.giganews.com!nntp.giganews.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.sys.tandem
Date: Fri, 24 Dec 2021 11:01:59 -0800 (PST)
Injection-Info: google-groups.googlegroups.com; posting-host=2607:fea8:3ddf:f2b0:1d92:5b76:a185:3f41;
posting-account=6VebZwoAAAAgrpUtsowyjrKRLNlqxnXo
NNTP-Posting-Host: 2607:fea8:3ddf:f2b0:1d92:5b76:a185:3f41
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <75544fd9-8386-4ab3-bb4a-61145f788eefn@googlegroups.com>
Subject: Question for Everyone Regarding ITUGLIB
From: no.spam.here@its.invalid (red floyd)
Injection-Date: Fri, 24 Dec 2021 19:01:59 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Lines: 8
 by: red floyd - Fri, 24 Dec 2021 20:10 UTC

On 12/24/2021 11:01 AM, Randall wrote:
> Hi Everyone,
>
> I noticed that most of the OpenSSL downloads are still from the 1.0.2 series or older - there was recently even a 1.0.1 download. Is anyone having difficulty with the more recent versions of builds done by ITUGLIB? Are the builds on too recent RVUs? Is there something we can do better?
>

Hi Randall, I haven't downloaded in a while, but I'm wondering if it's
the API change in 1.1.x? Nothing to do with your awesome efforts
at all?

Re: Question for Everyone Regarding ITUGLIB

<df1cd3dc-9fa9-4783-9799-50f02f37a988n@googlegroups.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=311&group=comp.sys.tandem#311

  copy link   Newsgroups: comp.sys.tandem
X-Received: by 2002:a05:620a:95c:: with SMTP id w28mr5516964qkw.229.1640372519629;
Fri, 24 Dec 2021 11:01:59 -0800 (PST)
X-Received: by 2002:a25:c00c:: with SMTP id c12mr7051883ybf.99.1640372519442;
Fri, 24 Dec 2021 11:01:59 -0800 (PST)
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!border2.nntp.dca1.giganews.com!nntp.giganews.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.sys.tandem
Date: Fri, 24 Dec 2021 11:01:59 -0800 (PST)
Injection-Info: google-groups.googlegroups.com; posting-host=2607:fea8:3ddf:f2b0:1d92:5b76:a185:3f41;
posting-account=6VebZwoAAAAgrpUtsowyjrKRLNlqxnXo
NNTP-Posting-Host: 2607:fea8:3ddf:f2b0:1d92:5b76:a185:3f41
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <75544fd9-8386-4ab3-bb4a-61145f788eefn@googlegroups.com>
Subject: Question for Everyone Regarding ITUGLIB
From: rsbecker@nexbridge.com (Randall)
Injection-Date: Fri, 24 Dec 2021 19:01:59 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Lines: 8
 by: Randall - Sun, 26 Dec 2021 01:54 UTC

On Friday, December 24, 2021 at 3:10:52 p.m. UTC-5, red floyd wrote:
> On 12/24/2021 11:01 AM, Randall wrote:
> > Hi Everyone,
> >
> > I noticed that most of the OpenSSL downloads are still from the 1.0.2 series or older - there was recently even a 1.0.1 download. Is anyone having difficulty with the more recent versions of builds done by ITUGLIB? Are the builds on too recent RVUs? Is there something we can do better?
> >
> Hi Randall, I haven't downloaded in a while, but I'm wondering if it's
> the API change in 1.1.x? Nothing to do with your awesome efforts
> at all?

The API had a fairly minimal set of changes at 1.1.x compared to 1.0.2. Most programs should not see a significant change, AFAIK - if any at all. There are some method signature changes but if you use the recommended #define macros, you should be insulated. The 3.0 change dealt with new cyphers and changes to DLL handling of engines (moved to "providers"). We rebuilt curl using 1.0.2 and 1.1.1 with no changes that we could see. 3.0.x has a small initialization change, I think. Remember that 1.0.2 does not receive any fixes, so you could be vulnerable to CVE fixes that have been applied to 1.1.1 and 3.0.1. The biggest difference is that 1.1.x has new cyphers that 1.0.2 does not know, so if you are talking to a more up-to-date server (or client), you *can* vs. might not be able to. The most important change at 3.0 is that the OpenSSL code on NonStop is identical to standard code; and that PRNGD is no longer used on L-series (replaced by the x86 hardware randomizer, so FIPS certification is now possible). There have been certificate format changes but those were done after 1.0.2 was deprecated. Check the release notes at openssl.org.

Re: Question for Everyone Regarding ITUGLIB

<01214c27-b71f-4421-80c9-599b6dfdd857n@googlegroups.com>

  copy mid

https://www.rocksolidbbs.com/computers/article-flat.php?id=318&group=comp.sys.tandem#318

  copy link   Newsgroups: comp.sys.tandem
X-Received: by 2002:a05:620a:95c:: with SMTP id w28mr5516964qkw.229.1640372519629;
Fri, 24 Dec 2021 11:01:59 -0800 (PST)
X-Received: by 2002:a25:c00c:: with SMTP id c12mr7051883ybf.99.1640372519442;
Fri, 24 Dec 2021 11:01:59 -0800 (PST)
Path: i2pn2.org!i2pn.org!weretis.net!feeder6.news.weretis.net!news.misty.com!border2.nntp.dca1.giganews.com!nntp.giganews.com!news-out.google.com!nntp.google.com!postnews.google.com!google-groups.googlegroups.com!not-for-mail
Newsgroups: comp.sys.tandem
Date: Fri, 24 Dec 2021 11:01:59 -0800 (PST)
Injection-Info: google-groups.googlegroups.com; posting-host=2607:fea8:3ddf:f2b0:1d92:5b76:a185:3f41;
posting-account=6VebZwoAAAAgrpUtsowyjrKRLNlqxnXo
NNTP-Posting-Host: 2607:fea8:3ddf:f2b0:1d92:5b76:a185:3f41
User-Agent: G2/1.0
MIME-Version: 1.0
Message-ID: <75544fd9-8386-4ab3-bb4a-61145f788eefn@googlegroups.com>
Subject: Question for Everyone Regarding ITUGLIB
From: rsbecker@nexbridge.com (Randall)
Injection-Date: Fri, 24 Dec 2021 19:01:59 +0000
Content-Type: text/plain; charset="UTF-8"
Content-Transfer-Encoding: quoted-printable
Lines: 8
 by: Randall - Thu, 30 Dec 2021 23:57 UTC

On Saturday, December 25, 2021 at 8:55:00 p.m. UTC-5, Randall wrote:
> On Friday, December 24, 2021 at 3:10:52 p.m. UTC-5, red floyd wrote:
> > On 12/24/2021 11:01 AM, Randall wrote:
> > > Hi Everyone,
> > >
> > > I noticed that most of the OpenSSL downloads are still from the 1.0.2 series or older - there was recently even a 1.0.1 download. Is anyone having difficulty with the more recent versions of builds done by ITUGLIB? Are the builds on too recent RVUs? Is there something we can do better?
> > >
> > Hi Randall, I haven't downloaded in a while, but I'm wondering if it's
> > the API change in 1.1.x? Nothing to do with your awesome efforts
> > at all?
> The API had a fairly minimal set of changes at 1.1.x compared to 1.0.2. Most programs should not see a significant change, AFAIK - if any at all. There are some method signature changes but if you use the recommended #define macros, you should be insulated. The 3.0 change dealt with new cyphers and changes to DLL handling of engines (moved to "providers"). We rebuilt curl using 1.0.2 and 1.1.1 with no changes that we could see. 3.0.x has a small initialization change, I think. Remember that 1.0.2 does not receive any fixes, so you could be vulnerable to CVE fixes that have been applied to 1.1.1 and 3.0.1. The biggest difference is that 1.1.x has new cyphers that 1.0.2 does not know, so if you are talking to a more up-to-date server (or client), you *can* vs. might not be able to. The most important change at 3.0 is that the OpenSSL code on NonStop is identical to standard code; and that PRNGD is no longer used on L-series (replaced by the x86 hardware randomizer, so FIPS certification is now possible). There have been certificate format changes but those were done after 1.0.2 was deprecated. Check the release notes at openssl.org.

In case anyone is wondering about compatibility of OpenSSL 1.1.1 and NonStop SSL, the SPR that comes with L21.06 is 1.1.1k. Although slightly older than the ITUGLIB build, NonStop SSL has the new protocols, cyphers, and certificates that are also in the ITUGLIB OpenSSL build. 1.0.2 is starting to show come cracks in terms of compatibiity, so please think about upgrading. Staying on unsupported versions is not a good plan.

Although, some of the CVEs applicable to 1.0.2 have fixes, but they are only available on a fee basis - it costs real (not cheap!) money to get the fixes from the OpenSSL team beyond 1.0.2u - and if you want help with that, please reach out to me and we can work something out. The more people who do, the less expensive it will be.


computers / comp.sys.tandem / Re: Question for Everyone Regarding ITUGLIB

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor