Tomas Mraz
55a3598cc7
fix DSA key generation in FIPS mode ( #833866 )
...
- allow duplicate FIPS_mode_set(1)
- enable build on ppc64 subarch (#834652 )
2012-07-12 21:59:56 +02:00
Tomas Mraz
5183d32904
Make it build with new Perl
2012-07-12 00:35:57 +02:00
Tomas Mraz
18ccae20f6
fix s_server with new glibc when no global IPv6 address ( #839031 )
2012-07-12 00:04:06 +02:00
Tomas Mraz
5e74bace82
new upstream version
2012-05-15 19:40:22 +02:00
Tomas Mraz
651215c12b
new upstream version
2012-05-15 19:37:55 +02:00
Tomas Mraz
5eb4589d83
new upstream version
2012-04-26 18:10:52 +02:00
Tomas Mraz
6a4bd67710
new upstream version fixing CVE-2012-2110
2012-04-20 12:30:37 +02:00
Tomas Mraz
e8c18345a4
new upstream version fixing CVE-2012-2110
2012-04-20 12:24:39 +02:00
Tomas Mraz
d46b44c249
add Kerberos 5 libraries to pkgconfig for static linking ( #807050 )
2012-04-11 16:33:03 +02:00
Tomas Mraz
d7587a26b6
backports from upstream CVS
...
fix segfault when /dev/urandom is not available (#809586 )
2012-04-05 19:56:49 +02:00
Tomas Mraz
0f0ab24176
new upstream release
2012-03-14 21:38:58 +01:00
Tomas Mraz
0aa7d61151
add obsoletes to assist multilib updates ( #799636 )
2012-03-05 10:51:13 +01:00
Tomas Mraz
00c4986d53
new upstream release from the 1.0.1 branch
...
- epoch bumped to 1 due to revert to 1.0.0g on Fedora 17
- fix s390x build (#798411 )
- versioning for the SSLeay symbol (#794950 )
- add -DPURIFY to build flags (#797323 )
- filter engine provides
- split the libraries to a separate -libs package
- add make to requires on the base package (#783446 )
2012-02-29 21:54:08 +01:00
Tomas Mraz
ad05b50537
New upstream release from the 1.0.1 branch, ABI compatible
...
- also add documentation for the -no_ign_eof option
2012-02-07 13:46:42 +01:00
Tomas Mraz
d91aea8890
new upstream release fixing CVE-2012-0050 - DoS regression in
...
DTLS support introduced by the previous release (#782795 )
2012-01-19 16:48:48 +01:00
Peter Robinson
48bba71e16
mktemp was long obsoleted by coreutils
2012-01-11 10:41:37 +00:00
Tomas Mraz
628d7e4989
new upstream release fixing multiple CVEs
2012-01-05 15:14:10 +01:00
Tomas Mraz
c28bd1cc5f
Make the non-upstream tarball comment more clear.
2011-11-25 16:32:43 +01:00
Tomas Mraz
497f2d674c
move the libraries needed for static linking to Libs.private
2011-11-22 11:53:40 +01:00
Tomas Mraz
6f65ffce68
do not use AVX instructions when osxsave bit not set
...
add direct known answer tests for SHA2 algorithms
2011-11-03 10:18:52 +01:00
Tomas Mraz
e4008f0b0e
fix missing initialization of variable in CHIL engine
2011-09-21 17:34:13 +02:00
Tomas Mraz
3447c41c99
new upstream release fixing CVE-2011-3207 ( #736088 )
2011-09-07 18:27:06 +02:00
Tomas Mraz
4c970c62c5
drop the separate engine for Intel acceleration improvements
...
and merge in the AES-NI, SHA1, and RC4 optimizations
add support for OPENSSL_DISABLE_AES_NI environment variable
that disables the AES-NI support
2011-08-24 13:12:33 +02:00
Tomas Mraz
0ed17c0652
correct openssl cms help output ( #636266 )
...
more tolerant starttls detection in XMPP protocol (#608239 )
2011-07-26 13:02:17 +02:00
Tomas Mraz
5c4fc08e4d
add support for newest Intel acceleration improvements backported
...
from upstream by Intel in form of a separate engine
2011-07-20 14:56:21 +02:00
Tomas Mraz
f4fb8490a9
allow the AES-NI engine in the FIPS mode
2011-06-09 16:22:08 +02:00
Tomas Mraz
19062db533
add API necessary for CAVS testing of the new DSA parameter generation
2011-05-24 14:57:29 +02:00
Tomas Mraz
0b4cee3bc2
Allow easier rebuilds on some multilib arches.
2011-05-19 10:34:38 +02:00
Tomas Mraz
138493a921
add support for VIA Padlock on 64bit arch from upstream ( #617539 )
...
do not return bogus values from load_certs (#652286 )
2011-04-28 21:58:56 +02:00
Tomas Mraz
8d20fec281
clarify apps help texts for available digest algorithms ( #693858 )
2011-04-05 21:24:01 +02:00
Tomas Mraz
1caf3ae072
- new upstream release fixing CVE-2011-0014 (OCSP stapling vulnerability)
2011-02-10 15:41:44 +01:00
Dennis Gilmore
ccc6e6f1c6
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
2011-02-08 21:34:08 -06:00
Tomas Mraz
65ebbaecc7
- add -x931 parameter to openssl genrsa command to use the ANSI X9.31
...
key generation method
- use FIPS-186-3 method for DSA parameter generation
- add OPENSSL_FIPS_NON_APPROVED_MD5_ALLOW environment variable
to allow using MD5 when the system is in the maintenance state
even if the /proc fips flag is on
- make openssl pkcs12 command work by default in the FIPS mode
2011-02-04 15:27:28 +01:00
Tomas Mraz
15fad7109b
- add -x931 parameter to openssl genrsa command to use the ANSI X9.31
...
key generation method
- use FIPS-186-3 method for DSA parameter generation
- add OPENSSL_FIPS_NON_APPROVED_MD5_ALLOW environment variable
to allow using MD5 when the system is in the maintenance state
even if the /proc fips flag is on
2011-02-04 15:14:18 +01:00
Tomas Mraz
09127ac54a
- listen on ipv6 wildcard in s_server so we accept connections
...
from both ipv4 and ipv6 (#601612 )
- fix openssl speed command so it can be used in the FIPS mode
with FIPS allowed ciphers
2011-01-24 17:41:43 +01:00
Tomas Mraz
154f82b97d
- new upstream version fixing CVE-2010-4180
2010-12-03 14:23:13 +01:00
Tomas Mraz
0a5657ab94
- replace the revert for the s390x bignum asm routines with
...
fix from upstream
2010-12-03 14:19:39 +01:00
Tomas Mraz
143a23a635
- bump release
2010-11-23 10:07:16 +01:00
Tomas Mraz
6e7d6d4dfd
- replace the revert for the s390x bignum asm routines with
...
fix from upstream
2010-11-23 09:51:17 +01:00
Tomas Mraz
23675ff78b
- revert upstream change in s390x bignum asm routines
2010-11-22 15:15:11 +01:00
Tomas Mraz
3ff2d49a83
- new upstream version fixing CVE-2010-3864 ( #649304 )
2010-11-16 18:21:39 +01:00
Tomas Mraz
17a6aec60b
- make SHLIB_VERSION reflect the library suffix
2010-09-07 21:41:52 +02:00
Tomáš Mráz
56642f75b1
- openssl man page fix ( #609484 )
2010-06-30 12:36:47 +00:00
Tomáš Mráz
1b4b1eaf63
- new upstream patch release, fixes CVE-2010-0742 ( #598738 ) and
...
CVE-2010-1633 (#598732 )
2010-06-04 12:23:14 +00:00
Tomáš Mráz
6adf85458c
- pkgconfig files now contain the correct libdir ( #593723 )
2010-05-19 15:39:13 +00:00
Tomáš Mráz
ae0beee7db
- make CA dir readable - the private keys are in private subdir ( #584810 )
2010-05-18 15:40:32 +00:00
Tomáš Mráz
290d51ec7f
- make CA dir readable - the private keys are in private subdir ( #584810 )
2010-05-18 15:34:17 +00:00
Tomáš Mráz
3bdf494b4f
- a few fixes from upstream CVS
...
- move libcrypto to /lib (#559953 )
2010-04-09 15:25:39 +00:00
Tomáš Mráz
7325c65a3e
- set UTC timezone on pod2man run ( #578842 )
...
- make X509_NAME_hash_old work in FIPS mode
2010-04-06 14:49:34 +00:00
Tomáš Mráz
c2fc1058b4
- set UTC timezone on pod2man run ( #578842 )
2010-04-06 14:35:57 +00:00
Tomáš Mráz
fa66cf4b52
- update to final 1.0.0 upstream release
2010-03-30 09:37:41 +00:00
Tomáš Mráz
7c4ab8ff8e
- make TLS work in the FIPS mode
2010-02-16 23:21:07 +00:00
Tomáš Mráz
bffe20438c
- gracefully handle zero length in assembler implementations of
...
OPENSSL_cleanse (#564029 )
- do not fail in s_server if client hostname not resolvable (#561260 )
2010-02-12 17:20:50 +00:00
Tomáš Mráz
ae5568515b
- new upstream release
2010-01-21 08:12:12 +00:00
Tomáš Mráz
79249339a7
- fix CVE-2009-4355 - leak in applications incorrectly calling
...
CRYPTO_free_all_ex_data() before application exit (#546707 )
- upstream fix for future TLS protocol version handling
2010-01-14 08:57:34 +00:00
Tomáš Mráz
7f0747ce73
- add support for Intel AES-NI
2010-01-13 09:21:02 +00:00
Tomáš Mráz
2d6ef07fa3
- upstream fix compression handling on session resumption
...
- various null checks and other small fixes from upstream
- upstream changes for the renegotiation info according to the latest draft
2010-01-07 22:43:57 +00:00
Tomáš Mráz
5845987ab4
- fix non-fips mingw build (patch by Kalev Lember)
...
- add IPV6 fix for DTLS
2009-11-23 07:54:08 +00:00
Tomáš Mráz
c9026def03
- add better error reporting for the unsafe renegotiation
2009-11-20 17:30:27 +00:00
Tomáš Mráz
359f84cd81
- fix build on s390x
2009-11-20 09:27:16 +00:00
Tomáš Mráz
5b761f5986
- disable enforcement of the renegotiation extension on the client
...
(#537962 )
- add fixes from the current upstream snapshot
2009-11-18 13:14:13 +00:00
Tomáš Mráz
982ac6e5f9
- keep the beta status in version number at 3 so we do not have to rebuild
...
openssh and possibly other dependencies with too strict version check
2009-11-13 12:11:41 +00:00
Tomáš Mráz
a9fcedd3fb
- keep the beta status in version number at 3 so we do not have to rebuild
...
openssh and possibly other dependencies with too strict version check
2009-11-13 11:45:07 +00:00
Tomáš Mráz
654ccf4a2f
- add fix to compile on new binutils
2009-11-12 16:27:52 +00:00
Tomáš Mráz
aabbc9ad89
- update to new upstream version, no soname bump needed
...
- fix CVE-2009-3555 - note that the fix is bypassed if SSL_OP_ALL is used
so the compatibility with unfixed clients is not broken. The protocol
extension is also not final.
2009-11-12 15:51:40 +00:00
Tomáš Mráz
e0fe963bd1
- fix use of freed memory if SSL_CTX_free() is called before SSL_free()
...
(#521342 )
2009-10-16 11:28:02 +00:00
Tomáš Mráz
1a303f4853
- fix typo in DTLS1 code ( #527015 )
...
- fix leak in error handling of d2i_SSL_SESSION()
2009-10-08 18:45:10 +00:00
Tomáš Mráz
75f7276f8b
- fix RSA and DSA FIPS selftests
...
- reenable fixed x86_64 camellia assembler code (#521127 )
2009-09-30 18:18:48 +00:00
Tomáš Mráz
2d8446ff1a
- temporarily disable x86_64 camellia assembler code ( #521127 )
2009-09-04 12:08:42 +00:00
Tomáš Mráz
c99976de43
- fix openssl dgst -dss1 ( #520152 )
2009-08-31 11:07:49 +00:00
Tomáš Mráz
9583cca278
- drop the compat symlink hacks
2009-08-26 15:50:36 +00:00
Tomáš Mráz
e1c2b406a8
- constify SSL_CIPHER_description()
2009-08-22 14:38:34 +00:00
Tomáš Mráz
4d132a5c14
- fix WWW:Curl:Easy reference in tsget
2009-08-21 13:42:11 +00:00
Tomáš Mráz
5ff2efa4d0
- enable MD-2
2009-08-21 13:08:15 +00:00
Tomáš Mráz
2ccfa6b48f
- update to new major upstream release
2009-08-20 14:20:57 +00:00
Tomáš Mráz
58b40a384a
- update to new major upstream release
2009-08-20 14:18:42 +00:00
Jesse Keating
72586e9d99
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
2009-07-25 20:54:16 +00:00
Bill Nottingham
d01d89f81d
- do not build special 'optimized' versions for i686, as that's the base
...
arch in Fedora now
2009-07-22 15:57:43 +00:00
Tomáš Mráz
44abf9d002
- abort if selftests failed and random number generator is polled
...
- mention EVP_aes and EVP_sha2xx routines in the manpages
- add README.FIPS
- make CA dir absolute path (#445344 )
- change default length for RSA key generation to 2048 (#484101 )
2009-06-30 11:17:45 +00:00
Tomáš Mráz
387d98c6e7
- fix CVE-2009-1377 CVE-2009-1378 CVE-2009-1379 (DTLS DoS problems)
...
(#501253 , #501254 , #501572 )
2009-05-21 16:30:42 +00:00
Tomáš Mráz
7723dd9040
- support compatibility DTLS mode for CISCO AnyConnect ( #464629 )
2009-04-21 10:05:11 +00:00
Tomáš Mráz
e1c42b9abd
- correct the SHLIB_VERSION define
2009-04-17 16:13:51 +00:00
Tomáš Mráz
bb917d493c
- add support for multiple CRLs with same subject
...
- load only dynamic engine support in FIPS mode
2009-04-15 14:36:54 +00:00
Tomáš Mráz
a9e5f01ef5
- update to new upstream release (minor bug fixes, security fixes and
...
machine code optimizations only)
2009-03-25 21:12:41 +00:00
Tomáš Mráz
a9567a4b21
- move only on 64bits
2009-03-19 11:03:16 +00:00
Tomáš Mráz
58f96a71e5
- move libraries to /usr/lib ( #239375 )
2009-03-19 10:31:41 +00:00
Tomáš Mráz
15d9ef2c72
- add a static subpackage
2009-03-13 13:10:33 +00:00
Jesse Keating
527ed75e65
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
2009-02-26 08:50:21 +00:00
Tomáš Mráz
07bd81ddaf
- must also verify checksum of libssl.so in the FIPS mode
...
- obtain the seed for FIPS rng directly from the kernel device
- drop the temporary symlinks
2009-02-02 16:46:33 +00:00
Tomáš Mráz
c7641abc30
- drop the temporary triggerpostun and symlinking in post
...
- fix the pkgconfig files and drop the unnecessary buildrequires on
pkgconfig as it is a rpmbuild dependency (#481419 )
2009-01-26 21:07:21 +00:00
Tomáš Mráz
919b2c6500
- add temporary triggerpostun to reinstate the symlinks
2009-01-17 20:49:48 +00:00
Tomáš Mráz
7e0fce6fea
- add temporary triggerpostun to reinstate the symlinks
2009-01-17 20:48:44 +00:00
Tomáš Mráz
105eb2ce8f
- no pairwise key tests in non-fips mode ( #479817 )
2009-01-17 19:31:29 +00:00
Tomáš Mráz
ebd2901e1d
- even more robust test for the temporary symlinks
2009-01-16 16:11:07 +00:00
Tomáš Mráz
b33a50c5b2
- try to ensure the temporary symlinks exist
2009-01-16 13:02:42 +00:00
Tomáš Mráz
1d20b5f238
- new upstream version with necessary soname bump ( #455753 )
...
- temporarily provide symlink to old soname to make it possible to rebuild
the dependent packages in rawhide
- add eap-fast support (#428181 )
- add possibility to disable zlib by setting
- add fips mode support for testing purposes
- do not null dereference on some invalid smime files
- add buildrequires pkgconfig (#479493 )
2009-01-15 09:10:25 +00:00
Tomáš Mráz
f1fb664cb6
- rediff for no fuzz
2008-08-10 20:36:12 +00:00
Tomáš Mráz
c59bdb11a0
- do not add tls extensions to server hello for SSLv3 either
2008-08-10 19:45:27 +00:00
jorton
acba378bc3
- restore the touch -r for openssl.cnf
2008-06-02 11:31:55 +00:00
jorton
50e76b460a
- remove reference to deleted source
2008-06-02 11:28:03 +00:00
jorton
bb2baacca9
- move root CA bundle to ca-certificates package
2008-06-02 11:06:57 +00:00
Tomáš Mráz
2c01b19843
- fix CVE-2008-0891 - server name extension crash ( #448492 )
...
- fix CVE-2008-1672 - server key exchange message omit crash (#448495 )
2008-05-28 15:52:21 +00:00
Tomáš Mráz
6e489d9c90
- release bump
2008-05-27 08:39:57 +00:00
Tomáš Mráz
cc7d549a79
- super-H arch support
...
- drop workaround for bug 199604 as it should be fixed in gcc-4.3
2008-05-27 08:38:06 +00:00
Tom Callaway
3bbf540789
sparc handling
2008-05-20 15:16:15 +00:00
jorton
dfabafc476
- update to new root CA bundle from mozilla.org (r1.45)
2008-03-10 10:45:36 +00:00
Jesse Keating
d08968bcfa
- Autorebuild for GCC 4.3
2008-02-20 05:36:13 +00:00
Tomáš Mráz
1181966c58
- rename required for build
2008-01-25 17:04:12 +00:00
Tomáš Mráz
5980c2800d
- merge review fixes ( #226220 )
...
- adjust the SHLIB_VERSION_NUMBER to reflect library name (#429846 )
2008-01-25 16:44:05 +00:00
Tomáš Mráz
d8cd5c45d8
- set default paths when no explicit paths are set ( #418771 )
...
- do not add tls extensions to client hello for SSLv3 (#422081 )
2007-12-13 17:16:43 +00:00
Tomáš Mráz
2a80bfda1d
- enable some new crypto algorithms and features
...
- add some more important bug fixes from openssl CVS
2007-12-03 19:57:11 +00:00
Tomáš Mráz
139aecb45e
- we have Dec now and not Nov
2007-12-03 15:26:28 +00:00
Tomáš Mráz
3849a1678a
- update to latest upstream release, SONAME bumped to 7
2007-12-03 14:24:08 +00:00
jorton
6427162702
- update to new CA bundle from mozilla.org
2007-10-15 15:20:47 +00:00
Tomáš Mráz
873b8d554b
- fix CVE-2007-5135 - off-by-one in SSL_get_shared_ciphers ( #309801 )
...
- fix CVE-2007-4995 - out of order DTLS fragments buffer overflow (#321191 )
- add alpha sub-archs (#296031 )
2007-10-12 12:17:08 +00:00
Tomáš Mráz
65e6d90529
- fix CVE-2007-5135 - off-by-one in SSL_get_shared_ciphers ( #309801 )
...
- fix CVE-2007-4995 - out of order DTLS fragments buffer overflow (#321191 )
- add alpha sub-archs (#296031 )
2007-10-12 12:16:00 +00:00
Tomáš Mráz
568fd16a03
- rebuild
2007-08-21 19:42:52 +00:00
Tomáš Mráz
aa64c417f5
- use localhost in testsuite, hopefully fixes slow build in koji
...
- CVE-2007-3108 - fix side channel attack on private keys (#250577 )
- make ssl session cache id matching strict (#233599 )
2007-08-03 12:16:54 +00:00
Tomáš Mráz
b191bc7a11
- allow building on ARM architectures ( #245417 )
...
- use reference timestamps to prevent multilib conflicts (#218064 )
- -devel package must require pkgconfig (#241031 )
2007-07-25 13:37:15 +00:00
Tomáš Mráz
fba756feb1
- detect duplicates in add_dir properly ( #206346 )
2006-12-11 19:46:13 +00:00
Tomáš Mráz
4ca06fa547
- the previous change still didn't make X509_NAME_cmp transitive
2006-11-30 23:10:43 +00:00
Tomáš Mráz
f0fb64db28
- make X509_NAME_cmp transitive otherwise certificate lookup is broken
...
(#216050 )
- Resolves: rhbz#216050
2006-11-23 20:38:24 +00:00
Tomáš Mráz
a99897e811
- aliasing bug in engine loading, patch by IBM ( #213216 )
2006-11-02 21:16:00 +00:00
Tomáš Mráz
98d8457650
- CVE-2006-2940 fix was incorrect ( #208744 )
2006-10-02 08:37:59 +00:00
Tomáš Mráz
6dc7017559
- fix CVE-2006-2937 - mishandled error on ASN.1 parsing ( #207276 )
...
- fix CVE-2006-2940 - parasitic public keys DoS (#207274 )
- fix CVE-2006-3738 - buffer overflow in SSL_get_shared_ciphers (#206940 )
- fix CVE-2006-4343 - sslv2 client DoS (#206940 )
2006-09-28 19:59:16 +00:00
Tomáš Mráz
cd294fcd2a
- fix CVE-2006-2937 - mishandled error on ASN.1 parsing ( #207276 )
...
- fix CVE-2006-2940 - parasitic public keys DoS (#207274 )
- fix CVE-2006-3738 - buffer overflow in SSL_get_shared_ciphers (#206940 )
- fix CVE-2006-4343 - sslv2 client DoS (#206940 )
2006-09-28 19:58:49 +00:00
Tomáš Mráz
ba40f6bb66
- fix CVE-2006-4339 - prevent attack on PKCS#1 v1.5 signatures ( #205180 )
2006-09-05 13:44:39 +00:00
Tomáš Mráz
2020821670
- set buffering to none on stdio/stdout FILE when bufsize is set ( #200580 )
...
patch by IBM
2006-08-02 18:18:43 +00:00
aoliva
c1d3bf9a12
- rebuild with new binutils ( #200330 )
2006-07-29 02:54:33 +00:00
Tomáš Mráz
e9887c37ef
- add a temporary workaround for sha512 test failure on s390 ( #199604 )
2006-07-21 08:28:43 +00:00
Tomáš Mráz
4d4d77e68c
- add ipv6 support to s_client and s_server (by Jan Pazdziora) ( #198737 )
...
- add patches for BN threadsafety, AES cache collision attack hazard fix
and pkcs7 code memleak fix from upstream CVS
2006-07-20 12:58:48 +00:00
Jesse Keating
a362beea0e
bumped for rebuild
2006-07-12 07:35:49 +00:00
Tomáš Mráz
6b8c7ea159
- dropped libica and ica engine from build
2006-06-21 21:14:05 +00:00
jorton
24c8087012
- update to new CA bundle from mozilla.org; adds CA certificates from
...
netlock.hu and startcom.org
2006-06-21 12:49:44 +00:00
Tomáš Mráz
810d3c4e49
- add export
2006-06-06 12:03:44 +00:00
Tomáš Mráz
50ec471f0f
- libica: add path to openssl headers for compilation in mock
2006-06-06 10:51:31 +00:00
Tomáš Mráz
499412dfe4
- fixed a few rpmlint warnings
...
- better fix for #173399 from upstream
- upstream fix for pkcs12
2006-06-05 13:55:51 +00:00
Tomáš Mráz
340dc6a41e
- there is no more linux/config.h (it was empty anyway)
2006-05-11 12:21:42 +00:00
Tomáš Mráz
bf80fa7d8e
- upgrade to new version, stays ABI compatible
2006-05-11 11:52:19 +00:00
Tomáš Mráz
6f11ea3f44
- fix stale open handles in libica ( #177155 )
...
- fix build if 'rand' or 'passwd' in buildroot path (#178782 )
- initialize VIA Padlock engine (#186857 )
2006-04-04 17:45:56 +00:00
Jesse Keating
8c34b0921c
bump for bug in double-long on ppc(64)
2006-02-11 04:53:59 +00:00
Jesse Keating
95579342d3
bump for new gcc/glibc
2006-02-07 13:22:17 +00:00
Tomáš Mráz
f1d9cb4f96
- don't include SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG in SSL_OP_ALL
...
(#175779 )
2005-12-15 10:45:33 +00:00
Jesse Keating
6a4a9c2005
gcc update bump
2005-12-09 22:42:35 +00:00
Tomáš Mráz
feb192463e
- fix build (-lcrypto was erroneusly dropped) of the updated libica
...
- updated ICA engine to 1.3.6-rc3
2005-11-29 11:52:11 +00:00
Tomáš Mráz
eba5bcbbc4
- disable builtin compression methods for now until they work properly
...
(#173399 )
2005-11-22 15:36:57 +00:00
Tomáš Mráz
20e19070fe
- don't set -rpath for openssl binary
2005-11-16 21:45:59 +00:00
Tomáš Mráz
e96bebc853
- new upstream version
...
- patches partially renumbered
2005-11-08 13:52:29 +00:00
Tomáš Mráz
2099136c66
- updated IBM ICA engine library and patch to latest upstream version
2005-10-21 13:48:38 +00:00
Tomáš Mráz
b073820eb5
- fix CAN-2005-2969 - remove SSL_OP_MSIE_SSLV2_RSA_PADDING which disables
...
the countermeasure against man in the middle attack in SSLv2 (#169863 )
- use sha1 as default for CA and cert requests - CAN-2005-2946 (#169803 )
2005-10-12 12:01:16 +00:00
Tomáš Mráz
86877cdfc8
- add *.so.soversion as symlinks in /lib ( #165264 )
...
- remove unpackaged symlinks (#159595 )
- fixes from upstream (constant time fixes for DSA, bn assembler div on ppc
arch, initialize memory on realloc)
2005-08-23 15:28:52 +00:00
Phil Knirsch
95f9154b19
- Updated ICA engine IBM patch to latest upstream version.
2005-08-11 10:16:19 +00:00
Karsten Hopp
655f2e498a
make it build with current rpm - remove symlinks
2005-08-03 13:30:46 +00:00
Tomáš Mráz
784dc22c4c
- fix CAN-2005-0109 - use constant time/memory access mod_exp so bits of
...
private key aren't leaked by cache eviction (#157631 )
- a few more fixes from upstream 0.9.7g
2005-05-19 09:17:54 +00:00
Tomáš Mráz
4e6a921995
- use poll instead of select in rand ( #128285 )
...
- fix Makefile.certificate to point to /etc/pki/tls
- change the default string mask in ASN1 to PrintableString+UTF8String
2005-04-27 10:48:43 +00:00
jorton
9c01f4a254
- update to revision 1.37 of Mozilla CA bundle
2005-04-25 09:06:16 +00:00
Tomáš Mráz
79f559a35a
- move certificates to _sysconfdir/pki/tls ( #143392 )
...
- move CA directories to _sysconfdir/pki/CA
- patch the CA script and the default config so it points to the CA
directories
2005-04-21 20:22:55 +00:00
Tomáš Mráz
1d982a09cd
- uninitialized variable mustn't be used as input in inline assembly
...
- reenable the x86_64 assembly again
2005-04-01 16:19:34 +00:00
Tomáš Mráz
d9b56b6f14
- add back RC4_CHAR on ia64 and x86_64 so the ABI isn't broken
...
- disable broken bignum assembly on x86_64
2005-03-31 19:41:28 +00:00
Tomáš Mráz
c9c6ff6b15
- added support for changing serial number to Makefile.certificate
...
(#151188 )
- make ca-bundle.crt a config file (#118903 )
2005-03-30 10:52:21 +00:00
Tomáš Mráz
632ff532b1
- reenable optimizations on ppc64
...
- enable assembly code on ia64
- upgrade to new upstream version (no soname bump needed)
- disable thread test - it was testing the backport of the RSA blinding -
no longer needed
2005-03-30 09:14:37 +00:00
Tomáš Mráz
d551f917f3
- libcrypto shouldn't depend on libkrb5 ( #135961 )
2005-03-02 00:41:20 +00:00
Tomáš Mráz
0448422a83
- rebuild
...
Mon Feb 28 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7e-1
- new upstream source, updated patches
- added patch so we are hopefully ABI compatible with upcoming
0.9.7f
2005-02-28 21:50:14 +00:00
Tomáš Mráz
50c4819563
- pkconfig file doesn't need to be executable
2005-02-10 10:03:14 +00:00
Tomáš Mráz
e809e73a39
- Support UTF-8 charset in the Makefile.certificate ( #134944 )
...
- Added cmp to BuildPrereq
2005-02-10 09:26:39 +00:00
jorton
125b1331bf
- generate new ca-bundle.crt from Mozilla certdata.txt (revision 1.32)
2005-01-27 09:35:36 +00:00
Phil Knirsch
7c24d1778f
- Fixed and updated libica-1.3.4-urandom.patch patch ( #122967 )
2004-12-23 14:30:10 +00:00
Nalin Dahyabhai
c07f22f83d
fix CAN-2004-0975 by removing der_chop
2004-11-19 20:14:52 +00:00
Phil Knirsch
33c00b2e3d
- Had to add a libtoolize --copy --force for libica...
2004-10-05 12:52:50 +00:00
Phil Knirsch
f577c55009
- Include latest libica version with important bugfixes.
2004-10-05 12:41:13 +00:00
cvsdist
acf96bd04c
auto-import changelog data from openssl-0.9.7a-39.src.rpm
...
Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
- rebuilt
2004-09-09 09:51:03 +00:00
cvsdist
3db75bb9db
auto-import changelog data from openssl-0.9.7a-38.src.rpm
...
Mon Jun 14 2004 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-38
- Updated ICA engine IBM patch to latest upstream version.
2004-09-09 09:50:54 +00:00
cvsdist
566a67e439
auto-import changelog data from openssl-0.9.7a-37.src.rpm
...
Mon Jun 07 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-37
- build for linux-alpha-gcc instead of alpha-gcc on alpha (Jeff Garzik)
2004-09-09 09:50:33 +00:00
cvsdist
c7b9ffb47e
auto-import changelog data from openssl-0.9.7a-36.src.rpm
...
Tue May 25 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-36
- handle %{_arch}=i486/i586/i686/athlon cases in the intermediate header
(#124303 )
2004-09-09 09:50:13 +00:00
cvsdist
80904fbc6f
auto-import changelog data from openssl-0.9.7a-35.src.rpm
...
Thu Mar 25 2004 Joe Orton <jorton@redhat.com> 0.9.7a-35
- add security fixes for CAN-2004-0079, CAN-2004-0112
2004-09-09 09:49:42 +00:00
cvsdist
b966cc9f0d
auto-import openssl-0.9.7a-34 from openssl-0.9.7a-34.src.rpm
2004-09-09 09:49:16 +00:00
cvsdist
c79d114687
auto-import openssl-0.9.7a-26 from openssl-0.9.7a-26.src.rpm
2004-09-09 09:47:19 +00:00
cvsdist
ee71aae33b
auto-import openssl-0.9.7a-23 from openssl-0.9.7a-23.src.rpm
2004-09-09 09:46:50 +00:00
cvsdist
7eff254795
auto-import changelog data from openssl-0.9.7a-20.2.src.rpm
...
Wed Mar 17 2004 Joe Orton <jorton@redhat.com> 0.9.7a-20.2
- pull in fix for libssl link line (Tim Waugh, #111154 )
2004-09-09 09:46:10 +00:00
cvsdist
b1b6b03b8a
auto-import changelog data from openssl-0.9.7a-20.1.src.rpm
...
Mon Mar 08 2004 Joe Orton <jorton@redhat.com> 0.9.7a-20.1
- add security fixes for CAN-2004-0079, CAN-2004-0112
- updated ca-bundle.crt: removed expired GeoTrust roots, added freessl.com
root, removed trustcenter.de Class 0 root
2004-09-09 09:46:04 +00:00
cvsdist
321fa67e1c
auto-import changelog data from openssl-0.9.7a-20.src.rpm
...
Wed Sep 24 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-20
- only parse a client cert if one was requested
- temporarily exclusivearch for %{ix86}
Tue Sep 23 2003 Nalin Dahyabhai <nalin@redhat.com>
- add security fixes for protocol parsing bugs (CAN-2003-0543,
CAN-2003-0544) and heap corruption (CAN-2003-0545)
- update RHNS-CA-CERT files
- ease back on the number of threads used in the threading test
Wed Sep 17 2003 Matt Wilson <msw@redhat.com> 0.9.7a-19
- rebuild to fix gzipped file md5sums (#91211 )
Mon Aug 25 2003 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-18
- Updated libica to version 1.3.4.
Thu Jul 17 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-17
- rebuild
Tue Jul 15 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-10.9
- free the kssl_ctx structure when we free an SSL structure (#99066 )
Thu Jul 10 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-16
- rebuild
Thu Jul 10 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-15
- lower thread test count on s390x
Tue Jul 08 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-14
- rebuild
Thu Jun 26 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-13
- disable assembly on arches where it seems to conflict with threading
Thu Jun 26 2003 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-12
- Updated libica to latest upstream version 1.3.0
2004-09-09 09:45:46 +00:00
cvsdist
5b50ae8c7b
auto-import openssl-0.9.7a-5 from openssl-0.9.7a-5.src.rpm
2004-09-09 09:45:40 +00:00
cvsdist
e32c11245f
auto-import openssl-0.9.7a-2 from openssl-0.9.7a-2.src.rpm
2004-09-09 09:45:17 +00:00
cvsdist
37242e4c03
auto-import openssl-0.9.6b-33 from openssl-0.9.6b-33.src.rpm
2004-09-09 09:44:16 +00:00
cvsdist
752071189c
auto-import openssl-0.9.6b-31 from openssl-0.9.6b-31.src.rpm
2004-09-09 09:43:14 +00:00
cvsdist
f61874de47
auto-import openssl-0.9.6b-29 from openssl-0.9.6b-29.src.rpm
2004-09-09 09:43:05 +00:00
cvsdist
ceaa16a863
auto-import openssl-0.9.6b-26 from openssl-0.9.6b-26.src.rpm
2004-09-09 09:42:18 +00:00
cvsdist
cc6067e931
auto-import openssl-0.9.6b-24 from openssl-0.9.6b-24.src.rpm
2004-09-09 09:42:01 +00:00
cvsdist
0cfdac5c04
auto-import openssl-0.9.6b-18 from openssl-0.9.6b-18.src.rpm
2004-09-09 09:41:24 +00:00
cvsdist
c7ee7e96b0
auto-import openssl-0.9.6b-16 from openssl-0.9.6b-16.src.rpm
2004-09-09 09:40:48 +00:00
cvsdist
4f250d3986
auto-import openssl-0.9.6b-15 from openssl-0.9.6b-15.src.rpm
2004-09-09 09:40:40 +00:00
cvsdist
90f01cc0d2
auto-import openssl-0.9.6b-8 from openssl-0.9.6b-8.src.rpm
2004-09-09 09:39:52 +00:00
cvsdist
90fa5b2444
auto-import openssl-0.9.6b-7 from openssl-0.9.6b-7.src.rpm
2004-09-09 09:39:48 +00:00
cvsdist
125a5b2f29
auto-import openssl-0.9.6b-6 from openssl-0.9.6b-6.src.rpm
2004-09-09 09:39:30 +00:00
cvsdist
8c3ec75004
auto-import openssl-0.9.6b-5 from openssl-0.9.6b-5.src.rpm
2004-09-09 09:39:26 +00:00
cvsdist
0d16b0bd39
auto-import openssl-0.9.6b-4 from openssl-0.9.6b-4.src.rpm
2004-09-09 09:39:14 +00:00
cvsdist
107c5de8ec
auto-import openssl-0.9.6b-3 from openssl-0.9.6b-3.src.rpm
2004-09-09 09:39:08 +00:00
cvsdist
c150e6469f
auto-import changelog data from openssl-0.9.6-16.0p.src.rpm
...
Thu Jun 19 2003 Guy Streeter <streeter@redhat.com> 0.9.6-16.0p
- build at -O1 for broken 7.1 ppc compiler
2004-09-09 09:38:46 +00:00
cvsdist
840a8b5bb7
auto-import changelog data from openssl-0.9.6-16.src.rpm
...
Wed Mar 19 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.6-16
- add backported patch to harden against Klima-Pokorny-Rosa extension of
Bleichenbacher's attack (CAN-2003-0131)
Mon Mar 17 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.6-15
- add patch to enable RSA blinding by default, closing a timing attack
(CAN-2003-0147)
Wed Feb 19 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.6-14
- add fix to guard against attempts to allocate negative amounts of memory
- add patch for CAN-2003-0078, fixing a timing attack
2004-09-09 09:38:38 +00:00
cvsdist
4d0009045f
auto-import changelog data from openssl-0.9.6-13.0p.src.rpm
...
Fri Aug 02 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6-13
- update asn patch to fix accidental reversal of a logic check
2004-09-09 09:37:51 +00:00
cvsdist
aa4a1b3eb5
auto-import changelog data from openssl-0.9.6-13.src.rpm
...
Thu Aug 01 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6-13
- update asn patch to fix accidental reversal of a logic check
Wed Jul 31 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6-12
- update asn patch to reduce chance that compiler optimization will remove
one of the added tests
Mon Jul 29 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6-11
- add patch to fix ASN.1 vulnerabilities
2004-09-09 09:37:25 +00:00
cvsdist
a3b5b01481
auto-import changelog data from openssl-0.9.6-10.src.rpm
...
Thu Jul 25 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6-10
- add backport of Ben Laurie's patches for OpenSSL 0.9.6d
2004-09-09 09:37:11 +00:00
cvsdist
4a904e2846
auto-import changelog data from openssl-0.9.6-9.71.0sx.src.rpm
...
Fri Jan 25 2002 David Sainty <dsainty@redhat.com>
- s390x support added in redhatx patch (renamed redhat patch) and spec.
2004-09-09 09:36:41 +00:00
cvsdist
9673719c43
auto-import changelog data from openssl-0.9.6-9.1ppc.src.rpm
...
Thu Jul 12 2001 Nalin Dahyabhai <nalin@redhat.com>
- add patches to fix PRNG flaws, supplied by Bodo Moeller and the OpenSSL
Group
2004-09-09 09:36:25 +00:00
cvsdist
00ff72af4a
auto-import changelog data from openssl-0.9.6-9.src.rpm
...
Wed Jul 11 2001 Nalin Dahyabhai <nalin@redhat.com>
- add patches to fix PRNG flaws, supplied by Bodo Moeller and the OpenSSL
Group
2004-09-09 09:36:18 +00:00
cvsdist
b1963909d4
auto-import changelog data from openssl-0.9.6-8.src.rpm
...
Fri Jun 01 2001 Nalin Dahyabhai <nalin@redhat.com>
- change two memcpy() calls to memmove()
Sun May 27 2001 Philip Copeland <bryce@redhat.com>
- Removed -DL_ENDIAN for the alpha builds as unsigned long = 8 not 4 which
both L_ENDIAN / B_ENDIAN require to work correctly
Tue May 15 2001 Nalin Dahyabhai <nalin@redhat.com>
- make subpackages depend on the main package
Thu Apr 26 2001 Nalin Dahyabhai <nalin@redhat.com>
- rebuild
Fri Apr 20 2001 Nalin Dahyabhai <nalin@redhat.com>
- use __libc_enable_secure in OPENSSL_setugid (suggested by
solar@openwall.com )
- make backported OPENSSL_setugid, BN_bntest_rand, and BN_rand_range static
functions, which keeps them away from client applications more cleanly
Tue Apr 17 2001 Nalin Dahyabhai <nalin@redhat.com>
- backport security fixes from 0.9.6a
2004-09-09 09:35:56 +00:00
cvsdist
821b825f3f
auto-import changelog data from openssl-0.9.6-3.src.rpm
...
Tue Mar 13 2001 Nalin Dahyabhai <nalin@redhat.com>
- use BN_LLONG on s390
Mon Mar 12 2001 Nalin Dahyabhai <nalin@redhat.com>
- fix the s390 changes for 0.9.6 (isn't supposed to be marked as 64-bit)
Sat Mar 03 2001 Nalin Dahyabhai <nalin@redhat.com>
- move c_rehash to the perl subpackage, because it's a perl script now
Fri Mar 02 2001 Nalin Dahyabhai <nalin@redhat.com>
- update to 0.9.6
- enable MD2
- use the libcrypto.so and libssl.so targets to build shared libs with
- bump the soversion to 1 because we're no longer compatible with any of
the various 0.9.5a packages circulating around, which provide lib*.so.0
Wed Feb 28 2001 Florian La Roche <Florian.LaRoche@redhat.de>
- change hobble-openssl for disabling MD2 again
Tue Feb 27 2001 Nalin Dahyabhai <nalin@redhat.com>
- re-disable MD2 -- the EVP_MD_CTX structure would grow from 100 to 152
bytes or so, causing EVP_DigestInit() to zero out stack variables in
apps built against a version of the library without it
Mon Feb 26 2001 Nalin Dahyabhai <nalin@redhat.com>
- disable some inline assembly, which on x86 is Pentium-specific
- re-enable MD2 (see http://www.ietf.org/ietf/IPR/RSA-MD-all )
Thu Feb 08 2001 Florian La Roche <Florian.LaRoche@redhat.de>
- fix s390 patch
Fri Dec 08 2000 Than Ngo <than@redhat.com>
- added support s390
Mon Nov 20 2000 Nalin Dahyabhai <nalin@redhat.com>
- remove -Wa,* and -m* compiler flags from the default Configure file
(#20656 )
- add the CA.pl man page to the perl subpackage
Thu Nov 02 2000 Nalin Dahyabhai <nalin@redhat.com>
- always build with -mcpu=ev5 on alpha
Tue Oct 31 2000 Nalin Dahyabhai <nalin@redhat.com>
- add a symlink from cert.pem to ca-bundle.crt
Wed Oct 25 2000 Nalin Dahyabhai <nalin@redhat.com>
- add a ca-bundle file for packages like Samba to reference for CA
certificates
Tue Oct 24 2000 Nalin Dahyabhai <nalin@redhat.com>
- remove libcrypto's crypt(), which doesn't handle md5crypt (#19295 )
Mon Oct 02 2000 Nalin Dahyabhai <nalin@redhat.com>
- add unzip as a buildprereq (#17662 )
- update m2crypto to 0.05-snap4
2004-09-09 09:35:41 +00:00
cvsdist
def39f16e5
auto-import changelog data from openssl-0.9.5a-17.src.rpm
...
Tue Sep 26 2000 Bill Nottingham <notting@redhat.com>
- fix some issues in building when it's not installed
2004-09-09 09:35:12 +00:00
cvsdist
e21e1846a7
auto-import changelog data from openssl-0.9.5a-14.src.rpm
...
Thu Sep 21 2000 Nalin Dahyabhai <nalin@redhat.com>
- tweak the makefile some more
- disable MD2 support
- disable MDC2 support
- tweak the makefile
- rework certificate makefile to have the right parts for Apache
- strip binaries and libraries
- enable actual RSA support
- use /usr/bin/perl instead of /usr/bin/perl
- move the passwd.1 man page out of the passwd package's way
- update to 0.9.5a, modified for U.S.
- add perl as a build-time requirement
- disable RC5, IDEA support
- break out python extensions
- byte-compile python extensions without the build-root
- adjust the makefile to not remove temporary files (like .key files when
building .csr files)
- fix the building of python modules without openssl-devel already
installed
Wed Mar 01 2000 Florian La Roche <Florian.LaRoche@redhat.de>
- Bero told me to move the Makefile into this package
Wed Mar 01 2000 Florian La Roche <Florian.LaRoche@redhat.de>
- add lib*.so symlinks to link dynamically against shared libs
Tue Feb 29 2000 Florian La Roche <Florian.LaRoche@redhat.de>
- update to 0.9.5
- run ldconfig directly in post/postun
- add FAQ
Sat Dec 18 1999 Bernhard Rosenkränzer <bero@redhat.de>
- Fix build on non-x86 platforms
Fri Nov 12 1999 Bernhard Rosenkränzer <bero@redhat.de>
- move /usr/share/ssl/* from -devel to main package
Tue Oct 26 1999 Bernhard Rosenkränzer <bero@redhat.de>
- inital packaging
- changes from base:
- Move /usr/local/ssl to /usr/share/ssl for FHS compliance
- handle RPM_OPT_FLAGS
2004-09-09 09:35:06 +00:00