[Pkg-openssl-devel] Bug#469554: openssl: Overflow bug in SSL key generation

John Goerzen jgoerzen at complete.org
Wed Mar 5 21:07:49 UTC 2008


Package: openssl
Version: 0.9.8g-3
Severity: normal

I generated an SSL key with req -x509 -days 20000

The resulting key expired in 1926, but was valid starting today.

Something ought to warn about that!

-- System Information:
Debian Release: lenny/sid
  APT prefers unstable
  APT policy: (500, 'unstable'), (99, 'experimental')
Architecture: i386 (i686)

Kernel: Linux 2.6.22-3-686 (SMP w/2 CPU cores)
Locale: LANG=C, LC_CTYPE=en_US (charmap=ISO-8859-1)
Shell: /bin/sh linked to /bin/bash

Versions of packages openssl depends on:
ii  libc6                   2.7-5            GNU C Library: Shared libraries
ii  libssl0.9.8             0.9.8g-3         SSL shared libraries
ii  zlib1g                  1:1.2.3.3.dfsg-8 compression library - runtime

openssl recommends no packages.

-- no debconf information





More information about the Pkg-openssl-devel mailing list