4 ms·
Title is misleading -- this appears to be an issue with a tool called socat, not with OpenSSL. That's a world of a difference in the severity of the issue.
by oxguy3 11y ago
Title is misleading -- this appears to be an issue with a tool called socat, not with OpenSSL. That's a world of a difference in the severity of the issue.
- mrb 11y agoThanks, I fixed the title. (For the record it was "OpenSSL: the hard coded 1024 bit DH p parameter was not prime").
- yeukhon 11y agoI think the first line is confusing and misleading until I read yours. > In the OpenSSL address implementation the hard coded 1024 bit DH p parameter was not prime. It should have been worded "In Socat, the DH p parameter used by OpenSSL implementation was hardcoded and was not a prime."
- LukeShu 11y agoThe original phrasing is correct, but confusing if you aren't familiar with socat. Socat fundamentally works by giving it a pair of addresses; they are referring to socat's implementation of addresses starting with "OPENSSL:" (caps-insensitive), AKA "OpenSSL addresses".
- yeukhon 11y agoI see. You are right, and yes I may have jumped to the gun too quickly.