How can I improve OpenSSL performance without guessing?
A performance change should improve the measured workload without sacrificing correctness or wasting capacity. Which measurements and bottlenecks should be considered first?
ReadMeFeed / Community knowledge
Real questions. Useful conversations. Find the people who know your stack.
A performance change should improve the measured workload without sacrificing correctness or wasting capacity. Which measurements and bottlenecks should be considered first?
When generating a Certificate Signing Request (CSR) using the openssl req command, standard subject fields are handled via interactive prompts or a basic configuration file. However, modern browser requirements necessitate the inclusion of Subject Alternative Names (SANs) to ensure certificate validity across multiple DNS entries or IP addresses. The goal is
Configuration must be available to the application without exposing credentials in source control, logs or browser code. What belongs in the runtime and which access controls matter?
Goal Ensure that OpenSSL’s ASN.1 TIME parsing consistently translates timezone offsets into a predictable representation for applications that convert the returned time to local civil time. Constraints and uncertainty OpenSSL currently returns the time as a time_t value interpreted as UTC, discarding any timezone offset present in the ASN.1 TIME field. Some
A failure needs to be narrowed down before settings are changed or operations retried. Which evidence best separates application errors from environment and dependency problems?
Certificate Revocation List (CRL) Validation OpenSSL provides the -crl_checks flag within the X509 verification store to ensure that certificates are checked against revocation lists during the chain validation process. A primary constraint is that OpenSSL does not natively perform network requests to fetch CRLs from Distribution Points (CDPs) defined in the
I've just updated to Ubuntu 22.04 LTS and my libs using OpenSSL just stopped working. Looks like Ubuntu switched to the version 3.0 of OpenSSL. For example, poetry stopped working: Traceback (most recent call last): File "/home/robz/.local/bin/poetry", line 5, in <module> from poetry.console import main File "/home/robz/.local/share/pypoetry/venv/lib/p
The same project needs to behave consistently on developer machines, in CI and after deployment. Which versions, dependencies and configuration should be recorded?
An upgrade needs a compatibility check, a tested release and a recovery path. Which changes deserve particular attention before the new version reaches production?