From owner-freebsd-ports@FreeBSD.ORG Mon Jun 4 02:52:37 2012 Return-Path: Delivered-To: freebsd-ports@freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2001:4f8:fff6::34]) by hub.freebsd.org (Postfix) with ESMTP id C2D7B1065678; Mon, 4 Jun 2012 02:52:37 +0000 (UTC) (envelope-from swhetzel@gmail.com) Received: from mail-ob0-f182.google.com (mail-ob0-f182.google.com [209.85.214.182]) by mx1.freebsd.org (Postfix) with ESMTP id 799298FC0C; Mon, 4 Jun 2012 02:52:37 +0000 (UTC) Received: by obcni5 with SMTP id ni5so8531158obc.13 for ; Sun, 03 Jun 2012 19:52:37 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:date:message-id:subject:from:to :cc:content-type; bh=t1OE7cRTPZuE6u73Y+79RBHgq0VTfepvo3qOaeQJh5k=; b=aqdU0ZVPDceq/Rks0v20lTLB6+WRGL69b8FSdnjH8FV+GeULuQB34eR/TPaL/kb+uE bMZxHHs+TsGUzx8wT/c5ptB01ncQD2zBuDW3WGSoGIoT2/91hs0EZEnxbWwWbCLBcvC3 vTOF25QiDMcKt4NQuU7xB5jMp983hzLVkSRtHN/mk0QAPoqwl7TOXhyq+6NW4TdUCrra tfXkexMwLQiIWWk+BO2clJIHN7Ng9rkpL6AJP25D15S3neupNHp+dVp92gsvFk+aMfo6 vDxXjFXDyXowPMrJh7MRh1fngdj453jE2gbKQoIj5YKt0oJf7AlijOvyDZwtUR0DZ+I9 L/Jg== MIME-Version: 1.0 Received: by 10.60.20.198 with SMTP id p6mr10168024oee.60.1338778356868; Sun, 03 Jun 2012 19:52:36 -0700 (PDT) Received: by 10.60.116.38 with HTTP; Sun, 3 Jun 2012 19:52:36 -0700 (PDT) In-Reply-To: <031222CBCF33214AB2EB4ABA279428A3011A2D0170BB@SJCPMAILBOX01.citrite.net> References: <031222CBCF33214AB2EB4ABA279428A3011A2D0170B9@SJCPMAILBOX01.citrite.net> <031222CBCF33214AB2EB4ABA279428A3011A2D0170BB@SJCPMAILBOX01.citrite.net> Date: Sun, 3 Jun 2012 21:52:36 -0500 Message-ID: From: Scot Hetzel To: Oleg Moskalenko Content-Type: text/plain; charset=ISO-8859-1 Cc: "mm@freebsd.org" , "freebsd-ports@freebsd.org" Subject: Re: Libevent2 port is not passing SSL regression tests X-BeenThere: freebsd-ports@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Porting software to FreeBSD List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 04 Jun 2012 02:52:37 -0000 On Sun, Jun 3, 2012 at 5:29 PM, Oleg Moskalenko wrote: > I got reply from libevent guys: > > ====================================== > This is actually an openssl bug that prevents OpenSSL 1.0.1 from > renegotiating with itself successfully when it has negotiated TLS 1.1 or > TLS 1.2. > > It doesn't seem to have an OpenSSL ticket yet; we only figured it out > yesterday on the Tor bugtracker. See > https://trac.torproject.org/projects/tor/ticket/6033 for what we learned > there. With any luck, this should be fixed in openssl 1.0.1d or 1.0.1e. > It is nothing to worry about, unless you're using renegotiation with > OpenSSL and TLS 1.1 or TLS 1.2. > Looks like OpenSSL has a fix for this: http://cvs.openssl.org/chngview?cn=22567 We might want to add a patch to the OpenSSL port to fix this before 1.01d is released. Scot