Tom Callaway
|
1f19ac14f9
|
resolve bugzilla 319901 (phew! only took 6 years & 9 days)
|
2013-10-15 02:08:35 +01:00 |
|
Tomas Mraz
|
7ae1dc1df9
|
Bump release
|
2013-09-27 15:46:03 +02:00 |
|
Tomas Mraz
|
4e423c3c50
|
make DTLS1 work in FIPS mode
- avoid RSA and DSA 512 bits and Whirlpool in 'openssl speed' in FIPS mode
|
2013-09-27 15:43:51 +02:00 |
|
Tomas Mraz
|
df94661da5
|
avoid dlopening libssl.so from libcrypto (#1010357)
|
2013-09-23 18:30:01 +02:00 |
|
Tomas Mraz
|
372f3ac997
|
fix small memory leak in FIPS aes selftest
|
2013-09-20 16:04:50 +02:00 |
|
Tomas Mraz
|
8c28623e94
|
fix segfault in openssl speed hmac in the FIPS mode
|
2013-09-19 15:16:50 +02:00 |
|
Tomas Mraz
|
d907abae39
|
Merge branch 'f20' of ssh://pkgs.fedoraproject.org/openssl into f20
Conflicts:
openssl.spec
|
2013-09-13 15:33:34 +02:00 |
|
Tomas Mraz
|
fa93b626ad
|
Add documentation of -attime to verify manpage
|
2013-09-12 11:26:07 +02:00 |
|
Tomas Mraz
|
30ebb4d732
|
document the nextprotoneg option in manual pages
original patch by Hubert Kario
|
2013-09-12 10:39:33 +02:00 |
|
Tomas Mraz
|
ae08b15c89
|
document the nextprotoneg option in manual pages
original patch by Hubert Kario
|
2013-09-12 10:23:34 +02:00 |
|
Kyle McMartin
|
cb069618e7
|
arm: use auxv to figure out armcap.c instead of using signals (#1006474)
|
2013-09-11 10:36:42 -04:00 |
|
Kyle McMartin
|
f6aa3c2ddd
|
arm: use auxv to figure out armcap.c instead of using signals (#1006474)
|
2013-09-11 09:52:25 -04:00 |
|
Tomas Mraz
|
eb63cc63df
|
try to avoid some races when updating the -fips subpackage
|
2013-09-04 13:53:38 +02:00 |
|
Tomas Mraz
|
850ca72b9a
|
use version-release in .hmac suffix to avoid overwrite during upgrade
|
2013-09-02 15:02:18 +02:00 |
|
Tomas Mraz
|
b5d2711ab6
|
allow deinitialization of the FIPS mode
|
2013-08-29 16:41:24 +02:00 |
|
Tomas Mraz
|
1465572e17
|
always perform the FIPS selftests in library constructor
if FIPS module is installed
|
2013-08-29 11:45:04 +02:00 |
|
Tomas Mraz
|
bb2f3882f2
|
add -fips subpackage that contains the FIPS module files
|
2013-08-27 16:03:43 +02:00 |
|
Tomas Mraz
|
9c324da28e
|
fix use of rdrand if available
- more commits cherry picked from upstream
- documentation fixes
|
2013-08-16 16:06:51 +02:00 |
|
Petr Písař
|
a254940dd1
|
Perl 5.18 rebuild
|
2013-08-03 12:05:42 +02:00 |
|
Tomas Mraz
|
acdf8a62f6
|
use symbol versioning also for the textual version
- additional manual page fix
|
2013-07-26 13:16:10 +02:00 |
|
Tomas Mraz
|
9b36f08da8
|
additional manual page fixes
|
2013-07-25 15:14:25 +02:00 |
|
Tomas Mraz
|
653e1efa34
|
use _prefix macro
|
2013-07-19 11:46:56 +02:00 |
|
Petr Písař
|
49a1fc761b
|
Perl 5.18 rebuild
|
2013-07-17 16:32:50 +02:00 |
|
Tomas Mraz
|
7ccde74773
|
add openssl.cnf.5 manpage symlink to config.5
|
2013-07-11 10:44:55 +02:00 |
|
Tomas Mraz
|
9555809e80
|
add relro linking flag
|
2013-07-10 17:54:24 +02:00 |
|
Tomas Mraz
|
6a0a35eb5f
|
Add missing fix of renamed manpages.
|
2013-07-10 16:43:07 +02:00 |
|
Tomas Mraz
|
30aa9303c7
|
add support for the -trusted_first option for certificate chain verification
|
2013-07-10 11:02:41 +02:00 |
|
Tomas Mraz
|
dad6e3ee78
|
fix build of manual pages with current pod2man (#959439)
|
2013-05-03 18:38:28 +02:00 |
|
Peter Robinson
|
6705192b85
|
Enable ARM optimised build
|
2013-04-21 14:33:34 +01:00 |
|
Tomas Mraz
|
64e30c5369
|
fix random bad record mac errors (#918981)
|
2013-03-18 21:34:18 +01:00 |
|
Tomas Mraz
|
9cf55df55b
|
fix up the SHLIB_VERSION_NUMBER
|
2013-02-19 20:35:16 +01:00 |
|
Tomas Mraz
|
169c3a0ddb
|
disable ZLIB loading by default (due to CRIME attack)
|
2013-02-19 16:41:14 +01:00 |
|
Tomas Mraz
|
dc696fdac4
|
new upstream version
|
2013-02-19 13:57:39 +01:00 |
|
Tomas Mraz
|
0fd0958b75
|
more fixes from upstream
- fix errors in manual causing build failure (#904777)
|
2013-01-30 18:32:56 +01:00 |
|
Tomas Mraz
|
2ca16b9a24
|
Add the renew-dummy-cert script to file list
|
2012-12-21 17:38:32 +01:00 |
|
Tomas Mraz
|
c67ea975b9
|
add script for renewal of a self-signed cert by Philip Prindeville (#871566)
- allow X509_issuer_and_serial_hash() produce correct result in
the FIPS mode (#881336)
|
2012-12-21 17:21:50 +01:00 |
|
Tomas Mraz
|
07ac3d216e
|
Fix bogus dates in changelog.
|
2012-12-07 12:37:49 +01:00 |
|
Tomas Mraz
|
728b1133e0
|
s_time uses tm_ctx.
|
2012-12-07 10:01:17 +01:00 |
|
Tomas Mraz
|
650873ff0e
|
do not load default verify paths if CApath or CAfile specified (#884305)
|
2012-12-06 18:30:15 +01:00 |
|
Tomas Mraz
|
12aab15a03
|
more fixes from upstream CVS
- fix DSA key pairwise check (#878597)
|
2012-11-20 22:33:42 +01:00 |
|
Tomas Mraz
|
d8e7bfc73b
|
Add the marker for required patch.
|
2012-11-19 17:43:07 +01:00 |
|
Tomas Mraz
|
b7eb6f4a5f
|
use 1024 bit DH parameters in s_server as 512 bit is not allowed
in FIPS mode and it is quite weak anyway
|
2012-11-15 21:11:36 +01:00 |
|
Tomas Mraz
|
79971bf194
|
Use secure_getenv() with new glibc.
|
2012-09-10 20:25:19 +02:00 |
|
Tomas Mraz
|
c015bd1b1e
|
add missing initialization of str in aes_ccm_init_key (#853963)
- add important patches from upstream CVS
|
2012-09-07 10:48:56 +02:00 |
|
Dennis Gilmore
|
eaa5561c35
|
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
|
2012-07-20 02:06:56 -05:00 |
|
Tomas Mraz
|
af044b4037
|
use __getenv_secure() instead of __libc_enable_secure
|
2012-07-13 22:21:05 +02:00 |
|
Tomas Mraz
|
72a1bddddc
|
do not move libcrypto to /lib
- do not use environment variables if __libc_enable_secure is on
- fix strict aliasing problems in modes
|
2012-07-13 14:30:31 +02:00 |
|
Tomas Mraz
|
c2e3151786
|
do not move libcrypto to /lib
- do not use environment variables if __libc_enable_secure is on
- fix strict aliasing problems in modes
|
2012-07-13 14:23:34 +02:00 |
|
Tomas Mraz
|
55a3598cc7
|
fix DSA key generation in FIPS mode (#833866)
- allow duplicate FIPS_mode_set(1)
- enable build on ppc64 subarch (#834652)
|
2012-07-12 21:59:56 +02:00 |
|
Tomas Mraz
|
5183d32904
|
Make it build with new Perl
|
2012-07-12 00:35:57 +02:00 |
|