[openssl-dev] [RFC 0/2] Proposal for seamless handling of TPM based RSA keys in openssl

Salz, Rich rsalz at akamai.com
Wed Nov 23 13:51:03 UTC 2016


> Why is it different if we do exactly that in libcrypto?

Because *we* are not guessing.  We are telling the application "we think it's a FOO" and then letting the application decide what to do.

Security libraries *should not guess.*


More information about the openssl-dev mailing list