[Pkg-openssl-devel] Bug#732710: Bug#732710: openssl: rdrand should be disabled by default
Kurt Roeckx
kurt at roeckx.be
Fri Dec 20 18:18:31 UTC 2013
On Fri, Dec 20, 2013 at 09:38:19AM -0500, Marc Deslauriers wrote:
> Package: openssl
> Version: 1.0.1e-4
> Severity: normal
> Tags: patch
> User: ubuntu-devel at lists.ubuntu.com
> Usertags: origin-ubuntu trusty ubuntu-patch
>
> OpenSSL uses rdrand exclusively if it is available.
>
> http://seclists.org/fulldisclosure/2013/Dec/99
> http://wiki.openssl.org/index.php/Library_Initialization#ENGINEs_and_RDRAND
>
> Upstream has changed this behaviour.
Is this something you want to release a DSA for? Or should I
upload this to proposed-updates instead?
Kurt
More information about the Pkg-openssl-devel
mailing list