Subject: Re: openssl and IDEA
To: Sverre Froyen <sverre@viewmark.com>
From: Jaromir Dolecek <jdolecek@netbsd.org>
List: current-users
Date: 06/07/2002 16:58:18
Doing what you propose would make it impossible to hook in IDEA at all.

BTW, AFAIK IDEA patent is noncommercial only. If the site below
is using IDEA, they break law (unless they bought commercial licence,
that is).

Jaromir


Sverre Froyen wrote:
[ Charset ISO-8859-1 unsupported, converting... ]
> Hi,
> 
> The version of openssl in the source tree has dummy routines for the IDEA 
> cipher and possibly others.  This causes a problem when the result of an SSL 
> negotiation is to use IDEA. For instance, using the package source p5-libwww 
> and P5-SSLeay, the command
> 
> 	lwp-request https://epayhipvar.paymentech.net
> 
> results in
> 
> 	IDEA is a patented algorithm; link against libcrypto_idea.a. Aborting...
> 
> The openssl library appears to present IDEA as a valid cipher during the SSL 
> negotiation and then turn around and exit with the above error message when 
> IDEA is chosen.  Since IDEA is encumbered with a patent, the solution 
> suggested in the error message is not viable.  Instead, IDEA should not be 
> presented as a valid option in the first place.
> 
> Sverre
> 


-- 
Jaromir Dolecek <jdolecek@NetBSD.org> http://www.NetBSD.org/Ports/i386/ps2.html
-=- We should be mindful of the potential goal, but as the tantric    -=-
-=- Buddhist masters say, ``You may notice during meditation that you -=-
-=- sometimes levitate or glow.   Do not let this distract you.''     -=-