OpenSSL bug(s)

Cantor, Scott cantor.2 at osu.edu
Tue Feb 7 16:41:53 UTC 2023


There are enough semi-ugly bugs in the OpenSSL advisory today that I'm going to push out a Windows package update for the SP to pick up 3.0.8.

The most serious one involves CRLs and to the extent there's a risk, it would be limited to use of PKIX, so part of the eventual announcement I'll put out will be a strong recommendation to turn it off. I strongly suspect nobody is still using that TrustEngine feature, and if they are they need to stop, so it's time. I should have changed the V3 default to leave it out, but I didn't.

If there's ever a new SP release, I'll update the default config to carry the one TrustEngine again instead of omitting it.

-- Scott 




More information about the users mailing list