[Pkg-openssl-devel] Bug#732710: Bug#732710: openssl: rdrand should be disabled by default

Kurt Roeckx kurt at roeckx.be
Fri Dec 20 18:18:31 UTC 2013


On Fri, Dec 20, 2013 at 09:38:19AM -0500, Marc Deslauriers wrote:
> Package: openssl
> Version: 1.0.1e-4
> Severity: normal
> Tags: patch
> User: ubuntu-devel at lists.ubuntu.com
> Usertags: origin-ubuntu trusty ubuntu-patch
> 
> OpenSSL uses rdrand exclusively if it is available.
> 
> http://seclists.org/fulldisclosure/2013/Dec/99
> http://wiki.openssl.org/index.php/Library_Initialization#ENGINEs_and_RDRAND
> 
> Upstream has changed this behaviour.

Is this something you want to release a DSA for?  Or should I
upload this to proposed-updates instead?


Kurt



More information about the Pkg-openssl-devel mailing list