11
General / Re: Sizes and SizeInt
« Last post by LemonParty on Today at 02:06:45 pm »Mixing singned and unsigned variables is bad.
Uderstood.
Uderstood.
It's not simply enough to use a LTS but you must also keep up-to-date with the most recent version of the OpenSSL library. When you check the release notes you will often find that each version fixes a number of security vulnerabilities.
If you are going to go back to 3.5 then you should use 3.5.7 - released yesterday.
Hi Everyone, thanks for your input,It could easily be an issue for OpenSSL given the error message has been reported elsewhere and IndySecOpenSSL relies on OpenSSL to establish communication and should not send any application data before ssl_connect has completed.
The Indy TCP Server with TLS is running on a Debian 13 box which when queried says the OpenSSL version is 3.5.6.
I will log the status call backs and see what light they may shed.
One thing I have just tested is my dev box has openssl v 3.6.2 and I havent seen that issue maybe it is a OpenSSL bug? In which case I am going to either have to upgrade Debians version or ignore the error?
It's not simply enough to use a LTS but you must also keep up-to-date with the most recent version of the OpenSSL library. When you check the release notes you will often find that each version fixes a number of security vulnerabilities.Currently, your only reason to switch to the 3.5 branch of IndySecOpenSSL is that you want to enforce the use of OpenSSL 3.5 or later.
Let's say that using 3.5 is practically mandatory given the "expiration" of the older versions in just over three months.
If you're providing a commercial product, obviously the application vision is long-term, so using a "long-term" LTS is essential.
I use TaurusTLS, but I also keep the sources updated with IndySecOpenSSL releases. It's been a while since I tested IndySecOpenSSL, however.
I was currently using OpenSSL version 4, but with this in mind, I rightly think I'll go back to 3.5.
(I assume that any developer has at least two monitors for serious programming. If you can't because of financial issues I am happy to donate two monitors (new, I have to order them), just send a private message and we work that out only considering shipping, same as with the Raspberry Pi's, usually that is also free as some of you know. Note I am affluent but not rich: 2 monitors for two different people)I have 3 monitors: 2 144Hz monitors for gaming and 1 wacom cintiq 16 for drawing. I also have a VR headset, which itself counts as a monitor as well