Open SSL 1.1.1 (General questions)
Is there some kind of a deadline when WeOnlyDo ActiveX components start supporting OpenSSL 1.1.1
(interested in SFTP, SSH components)?
Is there some kind of a deadline when WeOnlyDo ActiveX components start supporting OpenSSL 1.1.1
(interested in SFTP, SSH components)?
by Jasmine, (1450 days ago) @ Mykola Melnyk
Hi.
I'm not really sure why you need OpenSSL 1.1.1 for SSH/SFTP, since those protocols have nothing to do with SSL, so TLS1.3 which is major feature of 1.1.1 doesn't apply to SSH protocol. Can you please elaborate why you need OpenSSL 1.1.1?
As for when it will be supported - as soon as FIPS is available as 'drop in' DLL, as it is now with 1.0.2.
Hope this helps!
Jasmine
by Mykola Melnyk , (1450 days ago) @ Jasmine
Thank you for your quick response.
Our concern originates from the known list of vulnerabilities in OpenSSL 1.0.x. Numerous customers of our company prefer to consume products based on OpenSSL 1.1.1 even before FIPS support is provided. Though the best solution is still both OpenSSL 1.1.1 and FIPS in one bucket.
As far as we access OpenSSL functionalities mainly through WeOnlyDo libraries that's the reason why I raise the issue.
Thank you
by Jasmine, (1450 days ago) @ Mykola Melnyk
Mykola,
hi. Can you point to the list of vulnerability that concern crypto algorithms that are used, not the SSL/TLS layer itself which we don't use? If it's something to be fixed ASAP we'll be happy to know about it.
We'lre also for 1.1.1 (in other products mainly) but FIPS is more important at this time.
Jasmine
by Mykola Melnyk , (1449 days ago) @ Jasmine
The first one I have handy:
https://nvd.nist.gov/vuln/detail/CVE-2019-1552
by Jasmine, (1449 days ago) @ Mykola Melnyk
Hi.
But, that is for TLS protocol. We don't implement or use SSL/TLS in SSH protocol. We use only OpenSSL's crypto libraries. This doesn't apply in any way to SSH protocol.
Jasmine
Not only wodSFTPdll is excellent, the service you have provided is outstanding and second to none!
The wodCrypt product is great and we appreciate your effort to add support for UNIX Crypt.
Just thought you'd like to know that my gateway app with your SMTP Server component held the line against a DDOS attack today...
I can only hope I will have the pleasure to work with other products by "We Only Do" in the future.
I can only hope I will have the pleasure to work with other products by "We Only Do" in the future.
Your customer service was excellent, and I will look at your products in the future for precisely that reason.
Thank you very much for the rapid responses. I was a little nervous about dealing with a company that is on a different continent from me. You have proven my concerns to be unfounded.
Fantastic product by the way, it has helped us tremendously on a daily basis. Keep up the good work.
Count us as a satisfied WeOnlyDo customer. We appreciate your terrific support to get the secure Telnet working properly.
Just thought you'd like to know that my gateway app with your SMTP Server component held the line against a DDOS attack today...