[Ach] Issue with OpenSSL >0.9.8l <1.0.0

Andy Wenk andy at nms.de
Fri Apr 25 11:52:00 CEST 2014


if one is using homebrew, the existing OS X openssl lib can be overwritten:

$ openssl version
OpenSSL 0.9.8y 5 Feb 2013

$ brew install openssl
$ brew link --force openssl

open a new terminal (tab)

$ openssl version
OpenSSL 1.0.1g 7 Apr 2014

For sure it should be fixed by Apple, but that can take time ...

Cheers

Andy




On 25 April 2014 11:15, Pepi Zawodsky <pepi.zawodsky at maclemon.at> wrote:

>
> On 25.04.2014, at 04:53, Aaron Zauner <azet at azet.org> wrote:
> > as well as older versions of Mac OS X.
>
> ALL versions of OS X up to and including the current Mavericks are
> affected by this.
> $ /usr/bin/openssl version
> OpenSSL 0.9.8y 5 Feb 2013
>
> Expanding Ciphersuite B results in:
>
> $ /usr/bin/openssl ciphers
> 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA'
>
> AES256-SHA:AES128-SHA
>
> Unexpectedly, DHE ciphers are missing.
>
>
> $ /opt/local/bin/openssl version
> OpenSSL 1.0.1g 7 Apr 2014
>
> $ /opt/local/bin/openssl ciphers
> 'EDH+CAMELLIA:EDH+aRSA:EECDH+aRSA+AESGCM:EECDH+aRSA+SHA384:EECDH+aRSA+SHA256:EECDH:+CAMELLIA256:+AES256:+CAMELLIA128:+AES128:+SSLv3:!aNULL:!eNULL:!LOW:!3DES:!MD5:!EXP:!PSK:!DSS:!RC4:!SEED:!ECDSA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA'
>
>
> DHE-RSA-AES256-GCM-SHA384:DHE-RSA-AES256-SHA256:ECDHE-RSA-AES256-GCM-SHA384:ECDHE-RSA-AES256-SHA384:DHE-RSA-AES128-GCM-SHA256:DHE-RSA-AES128-SHA256:ECDHE-RSA-AES128-GCM-SHA256:ECDHE-RSA-AES128-SHA256:DHE-RSA-CAMELLIA256-SHA:DHE-RSA-AES256-SHA:ECDHE-RSA-AES256-SHA:DHE-RSA-CAMELLIA128-SHA:DHE-RSA-AES128-SHA:ECDHE-RSA-AES128-SHA:CAMELLIA256-SHA:AES256-SHA:CAMELLIA128-SHA:AES128-SHA
>
> Best regards
> Pepi
>
> _______________________________________________
> Ach mailing list
> Ach at lists.cert.at
> http://lists.cert.at/cgi-bin/mailman/listinfo/ach
>
>


-- 
Andy Wenk
Hamburg - Germany
RockIt!

http://www.couchdb-buch.de
http://www.pg-praxisbuch.de

GPG fingerprint: C044 8322 9E12 1483 4FEC 9452 B65D 6BE3 9ED3 9588

https://people.apache.org/keys/committer/andywenk.asc
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.cert.at/pipermail/ach/attachments/20140425/513a17ef/attachment.html>


More information about the Ach mailing list