[5443] in cryptography@c2.net mail archive
Re: [ANNOUNCE] PureTLS: Alpha 2 Release
daemon@ATHENA.MIT.EDU (EKR)
Sat Aug 21 23:03:47 1999
To: David Honig <honig@sprynet.com>
Cc: cryptix-users@cryptix.org, cryptography@c2.net, ietf-tls@consensus.com
From: EKR <ekr@rtfm.com>
Date: 21 Aug 1999 16:04:11 -0700
In-Reply-To: David Honig's message of "Sat, 21 Aug 1999 14:41:38 -0700"
David Honig <honig@sprynet.com> writes:
> At 09:26 PM 8/16/99 -0700, Eric Rescorla wrote:
>
> >A horribly embarrasing packaging oversight has been fixed. Alpha 1
> >included test-only code that always verified every signature
> >on a certificate as true.
>
> Well, at least some of your testing went remarkably smoothly :-)
Quite so. It really shows the importance of doing negative
controls as well as positive controls.
-Ekr
--
[Eric Rescorla ekr@rtfm.com]
PureTLS - free SSLv3/TLS software for Java
http://www.rtfm.com/puretls/