Stitched vs non-Stitched Ciphersuites

Short, Todd tshort at akamai.com
Tue Feb 26 15:03:41 UTC 2019


The latest security advisory:

https://www.openssl.org/news/secadv/20190226.txt

mentions stitched vs. non-stitched ciphersuites, but doesn’t really elaborate on which ciphersuites are stitched and non-stitched.

"In order for this to be exploitable "non-stitched" ciphersuites must be in use. Stitched ciphersuites are optimised implementations of certain commonly used ciphersuites."

Can someone give some examples of both?

--
-Todd Short
// tshort at akamai.com<mailto:tshort at akamai.com>
// "One if by land, two if by sea, three if by the Internet."

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-users/attachments/20190226/ce907982/attachment-0001.html>


More information about the openssl-users mailing list