Open SSL 1.1.1 (General questions)
Is there some kind of a deadline when WeOnlyDo ActiveX components start supporting OpenSSL 1.1.1
(interested in SFTP, SSH components)?
Is there some kind of a deadline when WeOnlyDo ActiveX components start supporting OpenSSL 1.1.1
(interested in SFTP, SSH components)?
by Jasmine, (1851 days ago) @ Mykola Melnyk
Hi.
I'm not really sure why you need OpenSSL 1.1.1 for SSH/SFTP, since those protocols have nothing to do with SSL, so TLS1.3 which is major feature of 1.1.1 doesn't apply to SSH protocol. Can you please elaborate why you need OpenSSL 1.1.1?
As for when it will be supported - as soon as FIPS is available as 'drop in' DLL, as it is now with 1.0.2.
Hope this helps!
Jasmine
by Mykola Melnyk
, (1851 days ago) @ Jasmine
Thank you for your quick response.
Our concern originates from the known list of vulnerabilities in OpenSSL 1.0.x. Numerous customers of our company prefer to consume products based on OpenSSL 1.1.1 even before FIPS support is provided. Though the best solution is still both OpenSSL 1.1.1 and FIPS in one bucket.
As far as we access OpenSSL functionalities mainly through WeOnlyDo libraries that's the reason why I raise the issue.
Thank you
by Jasmine, (1851 days ago) @ Mykola Melnyk
Mykola,
hi. Can you point to the list of vulnerability that concern crypto algorithms that are used, not the SSL/TLS layer itself which we don't use? If it's something to be fixed ASAP we'll be happy to know about it.
We'lre also for 1.1.1 (in other products mainly) but FIPS is more important at this time.
Jasmine
by Mykola Melnyk
, (1850 days ago) @ Jasmine
The first one I have handy:
https://nvd.nist.gov/vuln/detail/CVE-2019-1552
by Jasmine, (1850 days ago) @ Mykola Melnyk
Hi.
But, that is for TLS protocol. We don't implement or use SSL/TLS in SSH protocol. We use only OpenSSL's crypto libraries. This doesn't apply in any way to SSH protocol.
Jasmine

The SFTP ocx is one of the finest pieces of programming I have seen. It worked out of the box...

...not only that you provide these components at very reasonable cost, your responsiveness to emailed technical questions is simply outstanding...

...with WOD's excellent support I was able to bypass Winsock and focus on the task at hand...

You made it so simple for us to integrate SFTP - a technology we had little experience with...

Brilliant, even works on the mobile phone...

I've heard that you are amazing with your replies coming back so quickly - and now I've seen the speed in which you reply first hand.

Your .NET components allow us to blend .NET technology seamlessly with secure communication, and with excellent technical support.

...with the SFTP interface you produced, everything was so simple to understand, we were able to start coding almost immediately!

WeOnlyDo!COM will be the first stop I make should I require any further off-the-shelf components.

Thank you very much for the rapid responses. I was a little nervous about dealing with a company that is on a different continent from me. You have proven my concerns to be unfounded.

