Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wonder if LibreSSL is affected


LibreSSL is a fork of 1.0.1, so you can read this security advisory and get a good guess.


Probably not affected since this bug was introduced after version 1.0.1 that is the version where the fork happened.

> Starting from OpenSSL version 1.1.1h a check to disallow certificates in the chain that have explicitly encoded elliptic curve parameters was added as an additional strict check.

> An error in the implementation of this check meant that the result of a previous check to confirm that certificates in the chain are valid CA certificates was overwritten. This effectively bypasses the check that non-CA certificates must not be able to issue other certificates.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: