# openssl

OpenSSL is an open-source toolkit and software library for TLS, cryptography, and secure communication, including a command-line tool for cryptographic tasks.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## Security updates for Wednesday

DevFeed: [Security updates for Wednesday](<https://devfeed.tech/articles/security-updates-for-wednesday-31515.md>)

Original publisher: [Read original article](<https://lwn.net/Articles/1094720/>)

Author: corbet

Published: 2026-09-16T13:40:53Z

Content type: news

Language: en

Sources: [LWN.net](<https://devfeed.tech/sources/lwn-net.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [nginx](<https://devfeed.tech/topics/nginx.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Python](<https://devfeed.tech/topics/python.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>)

Tags: [debian](<https://devfeed.tech/tags/debian.md>), [linux](<https://devfeed.tech/tags/linux.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [openssh](<https://devfeed.tech/tags/openssh.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [python](<https://devfeed.tech/tags/python.md>), [security](<https://devfeed.tech/tags/security.md>), [updates](<https://devfeed.tech/tags/updates.md>)

### AI overview

Security updates were issued by AlmaLinux, Debian, Fedora, Oracle, Red Hat, SUSE, and Ubuntu for packages including kernels, nginx, OpenSSL, Python, Perl, Git, Docker, OpenSSH, and other software.

### Source excerpt

Security updates have been issued by AlmaLinux (kernel, kernel-rt, libkcapi, nginx, nginx:1.24, openssl, osbuild-composer, perl, perl:5.32, python-tornado, rsync, and rust), Debian (cjose and nginx), Fedora (environment-modules, erlang, GitPython, knot, perl-Authen-SASL, python-configargparse, ruby, rubygems, and sblim-sfcb), Oracle (firefox, git-lfs, gstreamer1-plugins-base, kernel, libkcapi, nginx, nginx:1.26, openssl, osbuild-composer, perl, perl-YAML-Syck, postgresql18, python-tornado, and rust), Red Hat (fence-agents, git-lfs, microcode_ctl, osbuild-composer, podman, python-pyasn1, and resource-agents), SUSE (389-ds, ant, bson-devel, chirp-20260911, docker, gimp, google-cloud-sap-agent, hauler, kernel, kimi-code, libpcap, python-GitPython, python310, syncthing, yast2-samba-client, and zstd-jni), and Ubuntu (aom, imagemagick, kitty, openssh, phpseclib, policykit-1, python-sql, python-webob, shibboleth-sp, simplesamlphp, snapcast, srt, and suricata-update).

## curl 8.22.0

DevFeed: [curl 8.22.0](<https://devfeed.tech/articles/curl-8-22-0-18904.md>)

Original publisher: [Read original article](<https://daniel.haxx.se/blog/2026/09/02/curl-8-22-0/>)

Author: Daniel Stenberg

Published: 2026-09-02T05:52:46Z

Content type: release

Language: en

Sources: [Daniel Stenberg](<https://devfeed.tech/sources/daniel-stenberg.md>)

Topics: [cURL](<https://devfeed.tech/topics/curl.md>), [Security](<https://devfeed.tech/topics/security.md>), [HTTP](<https://devfeed.tech/topics/http.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [API](<https://devfeed.tech/topics/api.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [bugfixes](<https://devfeed.tech/tags/bugfixes.md>), [command-line](<https://devfeed.tech/tags/command-line.md>), [curl](<https://devfeed.tech/tags/curl.md>), [curl-and-libcurl](<https://devfeed.tech/tags/curl-and-libcurl.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [http](<https://devfeed.tech/tags/http.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [tls](<https://devfeed.tech/tags/tls.md>)

### AI overview

The curl 8.22.0 release includes six changes, 302 bug fixes, and nine curl/libcurl security fixes plus one wcurl fix. It adds Apple GSS Framework support, API guards, experimental HTTP Message Signatures support, and Apple fast UDP, while blocking NTLM fallback in SPNEGO and dropping TLS-SRP support.

### Source excerpt

Welcome to this new release. Get it as always from https://curl.se. If you rather want a security-patched older release branch, stay tuned for the follow-up Rock-solid curl announcement within a few days. Release presentation Numbers the 276th release6 changes70 days (total: 10,887)302 bugfixes (total: 14,489)525 commits (total: 39,608)0 new public libcurl function (total: 100)4 new ... Continue reading curl 8.22.0 ->

## Announcing Oracle Jipher 10.37: FIPS 140-3 Cryptography for Java

DevFeed: [Announcing Oracle Jipher 10.37: FIPS 140-3 Cryptography for Java](<https://devfeed.tech/articles/announcing-oracle-jipher-10-37-fips-140-3-cryptography-for-java-15127.md>)

Original publisher: [Read original article](<https://inside.java/2026/08/25/jipher-cryptography-for-java/>)

Author: Poonam Parhar

Published: 2026-08-25T00:00:00Z

Content type: release

Language: en

Sources: [Inside Java](<https://devfeed.tech/sources/inside-java.md>)

Topics: [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [fips 140-3](<https://devfeed.tech/topics/fips-140-3.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Java](<https://devfeed.tech/topics/java.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Security, Privacy and Abuse Prevention](<https://devfeed.tech/topics/security-privacy-and-abuse-prevention.md>)

Tags: [cryptographic](<https://devfeed.tech/tags/cryptographic.md>), [cryptography](<https://devfeed.tech/tags/cryptography.md>), [fips](<https://devfeed.tech/tags/fips.md>), [fips-140-3](<https://devfeed.tech/tags/fips-140-3.md>), [java](<https://devfeed.tech/tags/java.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [oracle](<https://devfeed.tech/tags/oracle.md>), [security](<https://devfeed.tech/tags/security.md>), [standard](<https://devfeed.tech/tags/standard.md>)

### AI overview

Oracle Jipher 10 packages a FIPS 140-3 validated OpenSSL cryptographic module and exposes cryptographic services through Java Cryptography Architecture (JCA).

### Source excerpt

Oracle Jipher 10 packages a FIPS 140-3 validated OpenSSL cryptographic module, making cryptographic services available through the standard Java Cryptography Architecture (JCA) framework.

## TLS Certificate Cheat Sheet - OpenSSL & Curl

DevFeed: [TLS Certificate Cheat Sheet - OpenSSL & Curl](<https://devfeed.tech/articles/tls-certificate-cheat-sheet-openssl-curl-31866.md>)

Original publisher: [Read original article](<https://www.metachris.dev/2025/09/tls-certificate-cheat-sheet-openssl-curl/>)

Author: Chris Hager

Published: 2025-09-22T00:00:00Z

Content type: tutorial

Language: en

Sources: [Chris Hager](<https://devfeed.tech/sources/chris-hager.md>)

Topics: [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [Cheat sheet](<https://devfeed.tech/topics/cheatsheet.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [cURL](<https://devfeed.tech/topics/curl.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cheat-sheet](<https://devfeed.tech/tags/cheat-sheet.md>), [curl](<https://devfeed.tech/tags/curl.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [tls](<https://devfeed.tech/tags/tls.md>), [tools](<https://devfeed.tech/tags/tools.md>)

### AI overview

A cheat sheet for creating, inspecting, signing, validating, and testing TLS certificates and related keys and CSRs using OpenSSL and cURL.

### Source excerpt

https://collective.flashbots.net/t/tls-certificates-know-how-quick-reference/5292

## FuzzSlice: Separating real CVEs from fakes through fuzzing

DevFeed: [FuzzSlice: Separating real CVEs from fakes through fuzzing](<https://devfeed.tech/articles/fuzzslice-separating-real-cves-from-fakes-through-fuzzing-13055.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/fuzzslice-separating-real-cves-from-fakes-through-fuzzing>)

Published: 2024-09-19T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [Fuzzing/Fuzz testing](<https://devfeed.tech/topics/fuzzing.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Security](<https://devfeed.tech/topics/security.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [supply-chain-security](<https://devfeed.tech/topics/supply-chain-security.md>)

Tags: [cves](<https://devfeed.tech/tags/cves.md>), [false-positives](<https://devfeed.tech/tags/false-positives.md>), [fuzzing](<https://devfeed.tech/tags/fuzzing.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>), [software-supply-chain](<https://devfeed.tech/tags/software-supply-chain.md>)

### AI overview

Chainguard Labs presents FuzzSlice, a fuzzing technique for determining whether CVEs are exploitable within an application context. In an evaluation of 18 OpenSSL CVEs, it classified 12 as exploitable and six as unreachable or false positives.

### Source excerpt

Chainguard Labs explores FuzzSlice, a novel fuzzing technique, to improve vulnerability remediation by distinguishing exploitable CVEs from false positives.

## Blog: Falco Weekly 46 - 2023

DevFeed: [Blog: Falco Weekly 46 - 2023](<https://devfeed.tech/articles/blog-falco-weekly-46-2023-32509.md>)

Original publisher: [Read original article](<https://falco.org/blog/falco-w-46-2023-weekly-recap/>)

Published: 2023-11-17T00:00:00Z

Content type: article

Language: en

Sources: [Falco - Falco](<https://devfeed.tech/sources/falco-falco.md>), [Falco - The Falco blog](<https://devfeed.tech/sources/falco-the-falco-blog.md>)

Topics: [Falco](<https://devfeed.tech/topics/falco.md>), [Development](<https://devfeed.tech/topics/development.md>), [ci](<https://devfeed.tech/topics/ci.md>), [CMake](<https://devfeed.tech/topics/cmake.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [osx](<https://devfeed.tech/topics/osx.md>), [win32](<https://devfeed.tech/topics/win32.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [changes](<https://devfeed.tech/tags/changes.md>), [ci](<https://devfeed.tech/tags/ci.md>), [cmake](<https://devfeed.tech/tags/cmake.md>), [falco](<https://devfeed.tech/tags/falco.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [osx](<https://devfeed.tech/tags/osx.md>), [weekly](<https://devfeed.tech/tags/weekly.md>), [win32](<https://devfeed.tech/tags/win32.md>)

### AI overview

Falco Weekly 46 reviews development changes across Falco-related repositories, including library cleanups, fixes, new features, experimental ppc64le support, an OpenSSL upgrade, CI support for win32 and osx, and Kubernetes metadata work involving gRPC.

### Source excerpt

This is the first of a series of weekly blog post whose aim is to give a quick overview about the development of Falco and its related projects. What happened in Falco this week? Let's go through the major changes that happened in various repositories under the falcosecurity organization. Libs Lots of cleanups happened in the libs repo; the most outstanding ones being: udig engine removal (https://github.com/falcosecurity/libs/pull/1485) dropped legacy metadata clients for k8s and mesos (https://github.com/falcosecurity/libs/pull/1478) cleaned up proc callback handling code (https://github.com/falcosecurity/libs/pull/1471) Please, note that the removal of the legacy k8s client is part of a bigger effort to entirely rewrite it as a plugin, with a more future proof architecture and language. See the tracking issue: https://github.com/falcosecurity/libs/issues/987. All of these cleanups account for ~26k loc removed!! :rocket: Moreover, some fixes landed: removed some more Undefined Behavior warnings from integer copies (https://github.com/falcosecurity/libs/pull/1481) solved win32 linking issues with zlib (https://github.com/falcosecurity/libs/pull/1484) prevent libbpf stats from being collected with no bpf stats (https://github.com/falcosecurity/libs/pull/1487) Finally, some new features were merged: libraries will now be properly installed under CMAKE_INSTALL_LIBDIR (https://github.com/falcosecurity/libs/pull/1101) added ppc64le experimental support for modern bpf driver (https://github.com/falcosecurity/libs/pull/1475) upgraded openssl to 3.1.4 (https://github.com/falcosecurity/libs/pull/1488) Also, we now have a target release date and a tracking issue for libs 0.14 and next driver release: https://github.com/falcosecurity/libs/issues/1482. Falco Now Falco builds and runs on win32 and osx too! https://github.com/falcosecurity/falco/pull/2889 While Falco won't ship for these platforms, we will now have proper CI for them. Following the huge round of cleanups in libs

## Using WSL and Let's Encrypt to create Azure App Service SSL Wildcard Certificates

DevFeed: [Using WSL and Let's Encrypt to create Azure App Service SSL Wildcard Certificates](<https://devfeed.tech/articles/using-wsl-and-let-s-encrypt-to-create-azure-app-service-ssl-wildcard-certificates-21859.md>)

Original publisher: [Read original article](<https://www.hanselman.com/blog/using-wsl-and-lets-encrypt-to-create-azure-app-service-ssl-wildcard-certificates>)

Author: Scott Hanselman

Published: 2023-06-27T17:17:25Z

Content type: tutorial

Language: en

Sources: [Scott Hanselman](<https://devfeed.tech/sources/scott-hanselman.md>)

Topics: [Azure](<https://devfeed.tech/topics/azure.md>), [Windows Subsystem for Linux](<https://devfeed.tech/topics/wsl.md>), [SSL](<https://devfeed.tech/topics/ssl.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [apt](<https://devfeed.tech/topics/apt.md>), [pip](<https://devfeed.tech/topics/pip.md>)

Tags: [apt](<https://devfeed.tech/tags/apt.md>), [azure](<https://devfeed.tech/tags/azure.md>), [certificates](<https://devfeed.tech/tags/certificates.md>), [dns](<https://devfeed.tech/tags/dns.md>), [install](<https://devfeed.tech/tags/install.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [password](<https://devfeed.tech/tags/password.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [windows](<https://devfeed.tech/tags/windows.md>), [wsl](<https://devfeed.tech/tags/wsl.md>)

### AI overview

This tutorial explains how to use Certbot in Windows Subsystem for Linux with Let's Encrypt to create a wildcard certificate, convert it to a password-protected PFX containing the certificate chain, and upload it to Azure App Service. It also describes importing and exporting the certificate in Windows before updating the App Service binding.

### Source excerpt

There are many let's encrypt automatic tools for azure but I also wanted to see if I could use certbot in wsl to generate a wildcard certificate for the azure Friday website and then upload the resulting certificates to azure app service. Azure app service ultimately needs a specific format called dot PFX that includes the full certificate path and all intermediates. Per the docs, App Service private certificates must meet the following requirements: Exported as a password-protected PFX file, encrypted using triple DES. Contains private key at least 2048 bits long Contains all intermediate certificates and the root certificate in the certificate chain. If you have a PFX that doesn't meet all these requirements you can have Windows reencrypt the file. I use WSL and certbot to create the cert, then I import/export in Windows and upload the resulting PFX. Within WSL, install certbot: sudo apt update sudo apt install python3 python3-venv libaugeas0 sudo python3 -m venv /opt/certbot/ sudo /opt/certbot/bin/pip install --upgrade pip sudo /opt/certbot/bin/pip install certbot Then I generate the cert. You'll get a nice text UI from certbot and update your DNS as a verification challenge. Change this to make sure it's two lines, and your domains and subdomains are correct and your paths are correct. sudo certbot certonly --manual --preferred-challenges=dns --email YOUR@EMAIL.COM --server https://acme-v02.api.letsencrypt.org/directory --agree-tos --manual-public-ip-logging-ok -d "azurefriday.com" -d "*.azurefriday.com" sudo openssl pkcs12 -export -out AzureFriday2023.pfx -inkey /etc/letsencrypt/live/azurefriday.com/privkey.pem -in /etc/letsencrypt/live/azurefriday.com/fullchain.pem I then copy the resulting file to my desktop (check your desktop path) so it's now in the Windows world. sudo cp AzureFriday2023.pfx /mnt/c/Users/Scott/OneDrive/Desktop Now from Windows, import the PFX, note the thumbprint and export that cert. Import-PfxCertificate -FilePath "AzureFriday2023.pfx" -

## Removing Calendar Invites using PowerShell + Azure CLI

DevFeed: [Removing Calendar Invites using PowerShell + Azure CLI](<https://devfeed.tech/articles/removing-calendar-invites-using-powershell-azure-cli-32350.md>)

Original publisher: [Read original article](<https://dustn.dev/post/2021-12-20-removing-calendar-invites-using-azure-cli/>)

Author: dustin@dustn.dev (Dustin Summers)

Published: 2021-12-20T10:26:38Z

Content type: tutorial

Language: en

Sources: [Dustin Summers](<https://devfeed.tech/sources/dustin-summers.md>)

Topics: [PowerShell](<https://devfeed.tech/topics/powershell.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [active directory](<https://devfeed.tech/topics/active-directory.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>)

Tags: [active-directory](<https://devfeed.tech/tags/active-directory.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cli](<https://devfeed.tech/tags/cli.md>), [commands](<https://devfeed.tech/tags/commands.md>), [it-management-services-powershell-microsoft-azure-azure-active-directory](<https://devfeed.tech/tags/it-management-services-powershell-microsoft-azure-azure-active-directory.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [powershell](<https://devfeed.tech/tags/powershell.md>)

### AI overview

The article describes removing calendar invitations created by a departing employee while retaining the employee's account temporarily. It discusses PowerShell access problems on updated Macs caused by differing OpenSSL versions and presents Azure CLI as an alternative for managing the Azure environment.

### Source excerpt

Apart from my day job, I moonlight helping small-to-medium size companies' install and manage secure IT infrastructures, along with building and creating applications for them. I offer these services (and more) through my company, Attica, LLC. It is a passion of mine to help companies that are starting out have a solid IT/Cyber infrastructure that can scale with their company as these businesses are vulnerable and common targets of ransomware and phishing attacks.

## Node.js 12.22.8 (LTS)

DevFeed: [Node.js 12.22.8 (LTS)](<https://devfeed.tech/articles/node-js-12-22-8-lts-2506.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v12.22.8>)

Published: 2021-12-16T23:42:46Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [certificates](<https://devfeed.tech/topics/certificates.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [libuv](<https://devfeed.tech/topics/libuv.md>)

Tags: [certificates](<https://devfeed.tech/tags/certificates.md>), [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [js](<https://devfeed.tech/tags/js.md>), [libuv](<https://devfeed.tech/tags/libuv.md>), [mozilla](<https://devfeed.tech/tags/mozilla.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [release](<https://devfeed.tech/tags/release.md>)

### AI overview

Node.js 12.22.8 is an LTS release that updates c-ares to fix a regression resolving CNAME records containing underscores and updates root certificates from Mozilla's Network Security Services 3.71. It also includes dependency, platform, documentation, runtime, test, and worker-process fixes.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Node.js 15.0.1 (Current)

DevFeed: [Node.js 15.0.1 (Current)](<https://devfeed.tech/articles/node-js-15-0-1-current-2582.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/release/v15.0.1>)

Published: 2020-10-21T20:26:35Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>), [cross-platform](<https://devfeed.tech/topics/cross-platform.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [npm](<https://devfeed.tech/topics/npm.md>), [V8](<https://devfeed.tech/topics/v8.md>), [openssl](<https://devfeed.tech/topics/openssl.md>)

Tags: [cross-platform](<https://devfeed.tech/tags/cross-platform.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [npm](<https://devfeed.tech/tags/npm.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [release](<https://devfeed.tech/tags/release.md>), [v8](<https://devfeed.tech/tags/v8.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Node.js 15.0.1 (Current) is a release update that fixes a crypto regression in randomFillSync, upgrades npm to 7.0.3, updates the V8 version patch number, and includes documentation, build, source, and test changes.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Analyzing a simple encryption scheme using GitHub SSH keys

DevFeed: [Analyzing a simple encryption scheme using GitHub SSH keys](<https://devfeed.tech/articles/analyzing-a-simple-encryption-scheme-using-github-ssh-keys-29170.md>)

Original publisher: [Read original article](<https://www.latacora.com/blog/2018/09/30/analyzing-github-ssh-key-encryption/>)

Published: 2018-09-30T17:54:00Z

Content type: opinion

Language: en

Sources: [Latacora](<https://devfeed.tech/sources/latacora.md>)

Topics: [Encryption](<https://devfeed.tech/topics/encryption.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>), [GitHub](<https://devfeed.tech/topics/github.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [OpenSSH](<https://devfeed.tech/topics/openssh.md>), [SSL](<https://devfeed.tech/topics/ssl.md>), [Command-line interface](<https://devfeed.tech/topics/cli.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [channel](<https://devfeed.tech/tags/channel.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [github](<https://devfeed.tech/tags/github.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [padding](<https://devfeed.tech/tags/padding.md>), [public-key](<https://devfeed.tech/tags/public-key.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [ssl](<https://devfeed.tech/tags/ssl.md>)

### AI overview

This introductory analysis examines encrypting secrets for recipients using their GitHub SSH public keys and an OpenSSL RSA command. It explains that the scheme's PKCS#1 v1.5 and SSLv2 padding variants are vulnerable to Bleichenbacher's oracle attack, while noting that the described offline threat model does not provide access to a decryption oracle.

### Source excerpt

(This is an introductory level analysis of a scheme involving RSA. If you're already comfortable with Bleichenbacher oracles you should skip it.) Someone pointed me at the following suggestion on the Internet for encrypting secrets to people based on their GitHub SSH keys. I like the idea of making it easier for people to leverage key material and tools they already have. The encryption instructions are: echo "my secret" > message.txt curl -q "https://github.com/${USER}.keys" \ | head -n 1 \ > recipient.pub ssh-keygen -e -m pkcs8 -f recipient.pub > recipient.pem openssl rsautl \ -encrypt \ -pubin \ -inkey recipient.pem \ -ssl \ -in message.txt \ -out encrypted.txt Anything using an openssl command line tool makes me a little uncomfortable. Let's poke at it a little.

## Accessing Yahoo and AOL Mail Features Through IMAP

DevFeed: [Accessing Yahoo and AOL Mail Features Through IMAP](<https://devfeed.tech/articles/a-peek-behind-the-mail-curtain-20486.md>)

Original publisher: [Read original article](<https://yahooeng.tumblr.com/post/174023151641>)

Author: marcelatoath

Published: 2018-05-18T16:19:38Z

Content type: tutorial

Language: en

Sources: [Yahoo](<https://devfeed.tech/sources/yahoo.md>)

Topics: [Protocol (disambiguation)](<https://devfeed.tech/topics/protocol.md>), [servers](<https://devfeed.tech/topics/servers.md>), [client](<https://devfeed.tech/topics/client.md>), [openssl](<https://devfeed.tech/topics/openssl.md>)

Tags: [aol](<https://devfeed.tech/tags/aol.md>), [developers](<https://devfeed.tech/tags/developers.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [protocol](<https://devfeed.tech/tags/protocol.md>), [server](<https://devfeed.tech/tags/server.md>), [yahoo](<https://devfeed.tech/tags/yahoo.md>), [yahoo-engineering](<https://devfeed.tech/tags/yahoo-engineering.md>)

### AI overview

This tutorial explains how developers can access Yahoo and AOL Mail metadata such as DECOS and THREADID through IMAP. It demonstrates an IMAP command sequence using openssl to connect, authenticate, list folders, select the inbox, and search for message UIDs.

### Source excerpt

USE IMAP TO ACCESS SOME UNIQUE FEATURES By Libby Lin, Principal Product Manager Well, we actually won't show you how we create the magic in our big OATH consumer mail factory. But nevertheless we wanted to share how interested developers could leverage some of our unique features we offer for our Yahoo and AOL Mail customers. To drive experiences like our travel and shopping smart views or message threading, we tag qualified mails with something we call DECOS and THREADID. While we will not indulge in explaining how exactly we use them internally, we wanted to share how they can be used and accessed through IMAP. So let's just look at a sample IMAP command chain. We'll just assume that you are familiar with the IMAP protocol at this point and you know how to properly talk to an IMAP server. So here's how you would retrieve DECO and THREADIDs for specific messages: 1. CONNECT openssl s_client -crlf -connect imap.mail.yahoo.com:993 2. LOGIN a login username password a OK LOGIN completed 3. LIST FOLDERS a list "" "*" * LIST (\Junk \HasNoChildren) "/" "Bulk Mail" * LIST (\Archive \HasNoChildren) "/" "Archive" * LIST (\Drafts \HasNoChildren) "/" "Draft" * LIST (\HasNoChildren) "/" "Inbox" * LIST (\HasNoChildren) "/" "Notes" * LIST (\Sent \HasNoChildren) "/" "Sent" * LIST (\Trash \HasChildren) "/" "Trash" * LIST (\HasNoChildren) "/" "Trash/l2" * LIST (\HasChildren) "/" "test level 1" * LIST (\HasNoChildren) "/" "test level 1/nestedfolder" * LIST (\HasNoChildren) "/" "test level 1/test level 2" * LIST (\HasNoChildren) "/" "&T2BZfXso-" * LIST (\HasNoChildren) "/" "&gQKAqk7WWr12hA-" a OK LIST completed 4.SELECT FOLDER a select inbox * 94 EXISTS * 0 RECENT * OK [UIDVALIDITY 1453335194] UIDs valid * OK [UIDNEXT 40213] Predicted next UID * FLAGS (\Answered \Deleted \Draft \Flagged \Seen $Forwarded $Junk $NotJunk) * OK [PERMANENTFLAGS (\Answered \Deleted \Draft \Flagged \Seen $Forwarded $Junk $NotJunk)] Permanent flags * OK [HIGHESTMODSEQ 205] a OK [READ-WRITE] SELECT completed;

## Setup up HTTPS for your e-commerce site with Let's Encrypt and Google App Engine.

DevFeed: [Setup up HTTPS for your e-commerce site with Let's Encrypt and Google App Engine.](<https://devfeed.tech/articles/setup-up-https-for-your-e-commerce-site-with-let-s-encrypt-and-google-app-engine-15846.md>)

Original publisher: [Read original article](<https://developer.squareup.com/blog/setting-up-https-for-your-e-commerce-website-with-lets-encrypt-and-google-app-engine>)

Author: Tristan Sokol

Published: 2017-05-09T00:37:36Z

Content type: tutorial

Language: en

Sources: [Square Corner Blog RSS Feed](<https://devfeed.tech/sources/square-corner-blog-rss-feed.md>)

Topics: [Tutorial](<https://devfeed.tech/topics/tutorial.md>), [Security](<https://devfeed.tech/topics/security.md>), [Google](<https://devfeed.tech/topics/google.md>), [Web](<https://devfeed.tech/topics/web.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [openssl](<https://devfeed.tech/topics/openssl.md>)

Tags: [apis](<https://devfeed.tech/tags/apis.md>), [e-commerce](<https://devfeed.tech/tags/e-commerce.md>), [google](<https://devfeed.tech/tags/google.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [security](<https://devfeed.tech/tags/security.md>), [web-hosting](<https://devfeed.tech/tags/web-hosting.md>)

### AI overview

A tutorial explaining how to set up HTTPS for an e-commerce website hosted on Google App Engine using Let's Encrypt. It covers the prerequisites and begins the process of generating a private key and certificate signing request with OpenSSL.

### Source excerpt

HTTPS is an important part of keeping your customer's information secure on the web--here's a quick tutorial on how to set up HTTPS on your App Engine website to use our e-commerce APIs.

## Encrypt your data with MessageEncryptor

DevFeed: [Encrypt your data with MessageEncryptor](<https://devfeed.tech/articles/encrypt-your-data-with-messageencryptor-20070.md>)

Original publisher: [Read original article](<http://jollygoodcode.com/blog/2015/11/17/encrypt-your-data-with-messageencryptor.html>)

Published: 2015-11-17T07:44:55Z

Content type: tutorial

Language: en

Sources: [Jolly Good Code](<https://devfeed.tech/sources/jolly-good-code.md>)

Topics: [Rails](<https://devfeed.tech/topics/rails.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Cryptography](<https://devfeed.tech/topics/cryptography.md>)

Tags: [built-in](<https://devfeed.tech/tags/built-in.md>), [encryption](<https://devfeed.tech/tags/encryption.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [rails](<https://devfeed.tech/tags/rails.md>)

### AI overview

This tutorial explains that Rails' built-in MessageEncryptor uses OpenSSL::Cipher to encrypt data and is easy to use.

### Source excerpt

Rails has a built-in class MessageEncryptor which uses OpenSSL::Cipher to perform encryption, and it's easy to use that to encrypt your data.

## Using Heartbleed as a starting point

DevFeed: [Using Heartbleed as a starting point](<https://devfeed.tech/articles/using-heartbleed-as-a-starting-point-20667.md>)

Original publisher: [Read original article](<http://antirez.com/news/76>)

Published: 2014-04-10T09:06:18Z

Content type: opinion

Language: en

Sources: [Antirez](<https://devfeed.tech/sources/antirez.md>)

Topics: [openssl](<https://devfeed.tech/topics/openssl.md>), [Security](<https://devfeed.tech/topics/security.md>), [code security](<https://devfeed.tech/topics/code-security.md>), [Static code analysis](<https://devfeed.tech/topics/static-code-analysis.md>), [C](<https://devfeed.tech/topics/c.md>)

Tags: [c](<https://devfeed.tech/tags/c.md>), [code-analysis](<https://devfeed.tech/tags/code-analysis.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

The article uses the Heartbleed vulnerability in OpenSSL as a starting point for discussing how to improve system software security. It argues for greater investment in security audits, open-source software development, and static and dynamic checks, while noting that changing languages or specifications is unlikely in the near term.

### Source excerpt

The strong reactions about the recent OpenSSL bug are understandable: it is not fun when suddenly all the internet needs to be patched. Moreover for me personally how trivial the bug is, is disturbing. I don't want to point the finger to the OpenSSL developers, but you just usually think at those class of issues as a bit more subtle, in the case of a software like OpenSSL. Usually you fail to do sanity checks *correctly*, as opposed to this bug where there is a total *lack* of bound checks in the memcpy() call. However sometimes in the morning I read the code I wrote the night before and I'm deeply embarrassed. Programmers sometimes fail, I for sure do often, so my guess is that what is needed is a different process, and not a different OpenSSL team. There is who proposes a different language safer than C, and who proposes that the specification is broken because it is too complex. Probably there is some truth in both arguments, however it is unlikely that we move to a different specification or system language soon, so the real question is, what we can do now to improve system software security? 1) Throw money at it. Making system code safer is simple if there are investments. If different companies hire security experts to do code auditings in the OpenSSL code base, what happens is that the probability of discovering a bug like heartbleed is greater. I've seen very complex bugs that are triggered by a set of non-trivial conditions being discovered by serious code auditing efforts. A memcpy() without bound checks is something that if you analyze the code security-wise, will stand out in the first read. And guess how heartbleed was discovered? Via security auditings performed at Google. Probably the time to consider open source something that mostly we take from is over. Many companies should follow the example of Google and other companies, using workforce for OSS software development and security. 2) Static and dynamic checks. Static code analysis is, as a side ef

## Heartbleed: What the OpenSSL Bug Means for Internet Users

DevFeed: [Heartbleed: What the OpenSSL Bug Means for Internet Users](<https://devfeed.tech/articles/heartbleed-and-you-30057.md>)

Original publisher: [Read original article](<http://www.netmeister.org/blog/heartbleed-and-you.html>)

Published: 2014-04-09T21:44:27Z

Content type: article

Language: en

Sources: [Signs of Triviality](<https://devfeed.tech/sources/signs-of-triviality.md>)

Topics: [openssl](<https://devfeed.tech/topics/openssl.md>), [bug](<https://devfeed.tech/topics/bug.md>), [Library](<https://devfeed.tech/topics/library.md>), [Internet](<https://devfeed.tech/topics/internet.md>)

Tags: [bug](<https://devfeed.tech/tags/bug.md>), [internet](<https://devfeed.tech/tags/internet.md>), [library](<https://devfeed.tech/tags/library.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [technical](<https://devfeed.tech/tags/technical.md>)

### AI overview

The article explains that Heartbleed is a bug in the widely used OpenSSL library affecting almost all internet users, with an explanation intended for non-technical readers.

### Source excerpt

A bug in the widely used OpenSSL library named 'heartbleed' affects almost all users on the internet. Here's what it means for non-technical users.

## Security issue on the ReactOS infrastructure

DevFeed: [Security issue on the ReactOS infrastructure](<https://devfeed.tech/articles/security-issue-on-the-reactos-infrastructure-33234.md>)

Original publisher: [Read original article](<https://reactos.org/project-news/security-issue-reactos-infrastructure-2014/>)

Published: 2014-04-09T00:00:00Z

Content type: news

Language: en

Sources: [Front Page on ReactOS Website](<https://devfeed.tech/sources/front-page-on-reactos-website.md>)

Topics: [ReactOS](<https://devfeed.tech/topics/reactos.md>), [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [SSL](<https://devfeed.tech/topics/ssl.md>), [TLS (Transport Layer Security)](<https://devfeed.tech/topics/tls.md>)

Tags: [cve](<https://devfeed.tech/tags/cve.md>), [free](<https://devfeed.tech/tags/free.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [os](<https://devfeed.tech/tags/os.md>), [react](<https://devfeed.tech/tags/react.md>), [reactos](<https://devfeed.tech/tags/reactos.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [tls](<https://devfeed.tech/tags/tls.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [win32](<https://devfeed.tech/tags/win32.md>), [winapi](<https://devfeed.tech/tags/winapi.md>)

### AI overview

ReactOS reports that its infrastructure was affected by the Heartbleed vulnerability in OpenSSL. The project applied the fix, renewed its SSL certificates and private keys, and warned that account information and sessions might have been compromised. Users were advised to change their passwords and review their accounts.

### Source excerpt

Dear all, In case you don't use SSL/TLS on our infrastructure (web sites - drupal, jira, fisheye), skip reading (and reconsider your choices about such non-usage). As you may (should?) have heard recently, OpenSSL has suffered a critical security vulnerability (CVE-2014-0160), known as Heartbleed Bug (http://heartbleed.com/). Most of our services were using an affected release of OpenSSL, with heartbeat feature activated. Be it, mails services, web services (Drupal, Jira).

## Generate ECDSA key with OpenSSL

DevFeed: [Generate ECDSA key with OpenSSL](<https://devfeed.tech/articles/generate-ecdsa-key-with-openssl-27598.md>)

Original publisher: [Read original article](<https://gagor.pro/2013/12/generate-ecdsa-key-with-openssl/>)

Author: Tom

Published: 2013-12-17T00:00:00Z

Content type: tutorial

Language: en

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [ECDSA](<https://devfeed.tech/topics/ecdsa.md>), [openssl](<https://devfeed.tech/topics/openssl.md>), [private key](<https://devfeed.tech/topics/private-key.md>)

Tags: [ecdsa](<https://devfeed.tech/tags/ecdsa.md>), [generate](<https://devfeed.tech/tags/generate.md>), [linux](<https://devfeed.tech/tags/linux.md>), [openssl](<https://devfeed.tech/tags/openssl.md>), [private-key](<https://devfeed.tech/tags/private-key.md>), [security](<https://devfeed.tech/tags/security.md>)

### AI overview

This tutorial explains how to generate an ECDSA private key with OpenSSL, including selecting a curve and using a 256-bit key, followed by creating a self-signed certificate.

### Source excerpt

After the last NSA scandal I've found some time to read some texts about PFS and ECDSA keys lately. I always used RSA keys but wanted to give a try to ECDSA so I wanted to give it a try (test performance, etc). Here is how I've done it. Firstly find your favorite curve. A short tip about bit length and complexity could be found here. From it you will now that using 256 bit ECDSA key should be enough for next 10-20 years.

## Konwersja formatu certyfikatu dla telefonów Nokia

DevFeed: [Konwersja formatu certyfikatu dla telefonów Nokia](<https://devfeed.tech/articles/konwersja-formatu-certyfikatu-dla-telefonow-nokia-27524.md>)

Original publisher: [Read original article](<https://gagor.pro/2012/04/konwersja-formatu-certyfikatu-dla-telefonow-nokia/>)

Author: Tom

Published: 2012-04-11T00:00:00Z

Content type: tutorial

Language: pl

Sources: [Tomasz Gągor](<https://devfeed.tech/sources/tomasz-gagor.md>)

Topics: [openssl](<https://devfeed.tech/topics/openssl.md>)

Tags: [openssl](<https://devfeed.tech/tags/openssl.md>), [rsa](<https://devfeed.tech/tags/rsa.md>), [x509](<https://devfeed.tech/tags/x509.md>)

### AI overview

A practical guide to converting self-signed certificates and private keys between PEM and DER formats with OpenSSL, so a certificate can be installed on a Nokia E72.

### Source excerpt

Chciałem zaimportować mój certyfikat self-signed do Nokii E72 by nie krzyczała przy sprawdzaniu poczty. Potrzebowałem certyfikatu w formacie DER, a miałem w PEM - chwilę szukałem jak dokonać konwersji, więc ku pamięci zapisuję kilka gotowych poleceń: Konwersja certyfikatu z PEM na DER openssl x509 -in in.crt -inform PEM -out out.crt -outform DER Konwersja certyfikatu z DER na PEM openssl x509 -in in.crt -inform DER -out out.crt -outform DER Konwersja klucza z formatu PEM na DER openssl rsa -in in.crt -inform PEM -out out.crt -outform DER Konwersja klucza z formatu DER na PEM openssl rsa -in in.crt -inform DER -out out.crt -outform PEM Po konwersji certyfikat w formacie DER wystarczy wrzucić na kartę i otworzyć z menadżera plików, zainstalować.