[13261] in cryptography@c2.net mail archive

home help back first fref pref prev next nref lref last post

Re: ANNOUNCE: PureTLS 0.9b4

daemon@ATHENA.MIT.EDU (Eric Rescorla)
Tue May 13 14:19:57 2003

X-Original-To: cryptography@metzdowd.com
X-Original-To: cryptography@metzdowd.com
To: Vlastimil.Klima@i.cz
Cc: <ietf-tls@lists.certicom.com>, <cryptography@metzdowd.com>
Reply-To: EKR <ekr@rtfm.com>
From: Eric Rescorla <ekr@rtfm.com>
In-Reply-To: <DDAF169EF755BB46B62D2BD2FCEA8A840D9780@dcb01.decros.cz>
Date: 13 May 2003 08:03:19 -0700

Vlastimil Klíma <Vlastimil.Klima@i.cz> writes:

> Does it contain a protection against Klima-Pokorny-Rosa attack ?
That protection has been there since PureTLS 0.9b3.

-Ekr

> 
> -----Original Message-----
> From: Eric Rescorla [mailto:ekr@rtfm.com] 
> Sent: Sunday, May 04, 2003 5:17 PM
> To: ietf-tls@lists.certicom.com; cryptography@metzdowd.com; puretls-users@rtfm.com
> Subject: ANNOUNCE: PureTLS 0.9b4
> 
> ANNOUNCE: PureTLS version 0.9b4
> Copyright (C) 1999-2002 Claymore Systems, Inc.
> 
> http://www.rtfm.com/puretls
> 
> DESCRIPTION
> PureTLS is a free Java-only implementation of the SSLv3 and TLSv1
> (RFC2246) protocols. PureTLS was developed by Eric Rescorla for
> Claymore Systems, Inc, but is being distributed for free because we
> believe that basic network security is a public good and should be a
> commodity. PureTLS is licensed under a Berkeley-style license, which
> basically means that you can do anything you want with it, provided
> that you give us credit.
> 
> This is a beta release of PureTLS. Although it has undergone a fair
> amount of testing and is believed to operate correctly, it no doubt contains 
> significant bugs, which this release is intended to shake out. Please
> send any bug reports to the author at <ekr@rtfm.com>.
> 
> 0.9b4 is a bugfix release which includes protection against timing
> attacks on RSA (Boneh-Brumley/Kocher) and CBC padding (Vaudenay).
> Server users and clients who do client authentication should upgrade.
> Client-only users may not need to.
> 
> 
> WEB SITE
> http://www.rtfm.com/puretls
> 
> 
> ---------------------------------------------------------------------
> The Cryptography Mailing List
> Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com
> 

-- 
[Eric Rescorla                                   ekr@rtfm.com]
                http://www.rtfm.com/

---------------------------------------------------------------------
The Cryptography Mailing List
Unsubscribe by sending "unsubscribe cryptography" to majordomo@metzdowd.com

home help back first fref pref prev next nref lref last post