Apparently that's a list for people developing apps *with* openssl, and
the openssl devs don't all read it.
(If so, well done openssl: not only is your code an uncommented
stylistically awful dog's dinner, your mailing lists also have
ridiculously misleading names. There's a reason I encourage GnuTLS use
over OpenSSL wherever possible, and it's not the license...)
Discussions on development of the OpenSSL library. Not for application development questions!
So it would seem like a reasonable place to ask questions of that nature.
jake
Cryptographic weakness on Debian systems
Posted May 13, 2008 20:16 UTC (Tue) by dark (✭ supporter ✭, #8483)
[Link]
The README distributed with openssl also says to submit patches to
openssl-dev. And the FAQ on openssl.org ("How can I contact the OpenSSL
developers?") says to look in the README.
Cryptographic weakness on Debian systems
Posted May 14, 2008 0:42 UTC (Wed) by nix (subscriber, #2304)
[Link]
OK, I'll go and be quiet in the corner for not fact-checking before
burbling. Apologies.
Cryptographic weakness on Debian systems
Posted May 14, 2008 23:54 UTC (Wed) by cortana (subscriber, #24596)
[Link]
Well, don't feel so bad. The OpenSSL developers also didn't bother fact-checking either. ;)
Cryptographic weakness on Debian systems
Posted May 15, 2008 4:20 UTC (Thu) by ajf (subscriber, #10844)
[Link]
If a member of the OpenSSL team got it wrong, you can hardly blame yourself for believing him.