[asterisk-bugs] [JIRA] (ASTERISK-25294) srtp's crypto_get_random deprecated

Alexander Traud (JIRA) noreply at issues.asterisk.org
Wed Jul 13 06:08:56 CDT 2016


    [ https://issues.asterisk.org/jira/browse/ASTERISK-25294?page=com.atlassian.jira.plugin.system.issuetabpanels:comment-tabpanel&focusedCommentId=231399#comment-231399 ] 

Alexander Traud commented on ASTERISK-25294:
--------------------------------------------

Not an duplicate per-se, but the issue of this report here was resolved with an updated change to ASTERISK-24436. Tzafrir, is that conditional OpenSSL switch sufficient to close this issue here?

> srtp's crypto_get_random deprecated
> -----------------------------------
>
>                 Key: ASTERISK-25294
>                 URL: https://issues.asterisk.org/jira/browse/ASTERISK-25294
>             Project: Asterisk
>          Issue Type: Bug
>      Security Level: None
>          Components: Resources/res_srtp
>    Affects Versions: 13.4.0
>            Reporter: Tzafrir Cohen
>            Severity: Minor
>
> Upcoming version of SRTP will drop crypto_get_random. Its developers don't consider it a good random number generator and recommend using alternatives.
> See https://github.com/cisco/libsrtp/commit/339b61d



--
This message was sent by Atlassian JIRA
(v6.2#6252)



More information about the asterisk-bugs mailing list