AFAIK it is valid to call BN_sub() in this way, and looking at the code I can't see any problem with doing so. There is no reproducer of an actual issue in this report, so closing. Matt -- Ticket here: http://rt.openssl.org/Ticket/Display.html?id=1639 Please log in as guest with password guest if prompted