[openssl-dev] [openssl.org #4201] Feature Request: Support dumping session keys in NSS key log format

Judson Wilson wilson.judson at gmail.com
Mon Jan 11 11:34:00 UTC 2016


Here is an OpenSSL port of a patch in BoringSSL. It requires a call from
the application to set a file BIO.  You could probably do this from within
SSL_CTX_new or something like that if you want a solution that doesn't
change the application.

https://github.com/JudsonWilson/openssl/commit/20e035a293756976b519ce028d5bcfe95544794b



On Mon, Jan 11, 2016 at 2:08 AM, Matt Caswell via RT <rt at openssl.org> wrote:

> On Mon Dec 28 23:53:02 2015, matt wrote:
> > On Mon Dec 28 22:01:04 2015, rsalz at akamai.com wrote:
> > > Yes we would be interested in this but someone would almost
> > > definitely
> > > have to be provided as a complete patch because it seems unlikely
> > > anyone on the team will get around to doing it by 1.1 release.
> > >
> >
> > Actually I think this capability is already in 1.1.0...or rather it
> > *was* but
> > now seems to be broken.
> >
> > See commit 189ae368d91 and RT ticket 3352.
> >
> > I suspect the big apps cleanup broke it.
>
> This is now fixed. Keeping this ticket open for now because of the request
> for
> support beyond just the apps.
>
> Matt
>
> _______________________________________________
> openssl-dev mailing list
> To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-dev
>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20160111/59d8cb31/attachment.html>


More information about the openssl-dev mailing list