Commit Graph

  • a577400ed8 drop RSA X9.31 from RSA FIPS selftests Tomas Mraz 2014-08-13 20:03:17 +0200
  • ffdfc30aac Multiple moderate security issues fixes Tomas Mraz 2014-08-08 13:16:26 +0200
  • 638098da51 Merge branch 'master' into f21 Tomas Mraz 2014-08-07 16:16:19 +0200
  • a78828f786 new upstream release fixing multiple moderate security issues Tomas Mraz 2014-08-07 16:00:47 +0200
  • a751492d12 fix license handling Tom Callaway 2014-07-18 19:31:40 -0400
  • 6c0bfa087d fix license handling Tom Callaway 2014-07-18 19:31:16 -0400
  • c66230af31 Sign the test string in the pairwise check instead of empty data. Tomas Mraz 2014-07-04 17:08:44 +0200
  • 6466466115 disable SSLv2 and SSLv3 protocols by default Tomas Mraz 2014-06-30 14:21:11 +0200
  • 873dc4a466 And never call fclose with NULL parameter. Tomas Mraz 2014-06-11 16:21:37 +0200
  • 9c4f375672 Cannot use malloc with OPENSSL_free. Tomas Mraz 2014-06-11 15:30:49 +0200
  • f550490681 use system profile for default cipher list Tomas Mraz 2014-06-11 15:07:06 +0200
  • a98d99a503 fix CVE-2014-0224 fix that broke EAP-FAST session resumption support Tomas Mraz 2014-06-10 16:38:56 +0200
  • 0a491cd9f2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild Dennis Gilmore 2014-06-07 12:02:05 -0500
  • 360a4bb67c new upstream release 1.0.1h Tomas Mraz 2014-06-05 15:05:17 +0200
  • 6b9a0a89db Add missing patch. Tomas Mraz 2014-06-05 13:42:19 +0200
  • 0fca960006 Multiple security vulnerabilities fixes. Tomas Mraz 2014-06-05 10:54:23 +0200
  • b5f54ff916 Drop obsolete and irrelevant docs, Move devel docs to appropriate package, they're all rather large and of little use for all but historical reference Peter Robinson 2014-05-31 22:49:33 +0100
  • 0376d8368c new upstream release 1.0.1g Tomas Mraz 2014-05-07 11:42:32 +0200
  • 237512dfb7 pull in upstream patch for CVE-2014-0160 Dennis Gilmore 2014-04-07 19:23:35 -0500
  • e55cd2c0e4 pull in upstream patch for CVE-2014-0160 Dennis Gilmore 2014-04-07 19:20:31 -0500
  • 239d122765 add support for ppc64le architecture (#1072633) Tomas Mraz 2014-04-03 16:24:35 +0200
  • 477d4a1758 properly detect encryption failure in BIO Tomas Mraz 2014-03-17 17:22:08 +0100
  • 423ab177c8 use the key length from configuration file if req -newkey rsa is invoked Tomas Mraz 2014-02-14 16:24:31 +0100
  • 3f8863c3cd Avoid unnecessary reseeding in BN_rand in FIPS mode. Tomas Mraz 2014-02-13 16:54:43 +0100
  • 165cee17b3 Remove obsolete sentence. Tomas Mraz 2014-02-13 16:17:58 +0100
  • a9591c7f1f Add macro for performance build on certain arches. Tomas Mraz 2014-02-12 16:58:49 +0100
  • 24632bb1db print ephemeral key size negotiated in TLS handshake (#1057715) Tomas Mraz 2014-02-12 16:20:03 +0100
  • abe62302b2 make expiration and key length changeable by DAYS and KEYLEN Tomas Mraz 2014-02-06 18:07:59 +0100
  • 40825564d8 make 3des strength to be 128 bits instead of 168 (#1056616) Tomas Mraz 2014-01-22 17:57:22 +0100
  • 1d0cabc003 Merge branch 'f19' into f18 f18 Tomas Mraz 2014-01-08 17:27:07 +0100
  • 6fb56a9054 Merge branch 'master' into f20 Tomas Mraz 2014-01-07 15:38:39 +0100
  • 519fe2cc24 Two security fixes Tomas Mraz 2014-01-07 15:09:40 +0100
  • c5b74d70a3 dh->q might be NULL. Tomas Mraz 2014-01-07 11:57:56 +0100
  • 8d26a664b6 Merge branch 'f20' into f18 Tomas Mraz 2013-12-20 14:53:22 +0100
  • 62d89f393f do not apply the no-md5-verify patch in released Fedora branches Tomas Mraz 2013-12-20 14:47:41 +0100
  • 8978637f3b fix CVE-2013-6449 - crash when version in SSL structure is incorrect Tomas Mraz 2013-12-20 14:14:15 +0100
  • 5713696953 Additional FIPS requirements changes. Tomas Mraz 2013-12-19 17:42:43 +0100
  • dc728e2d8b drop weak ciphers from the default TLS ciphersuite list Tomas Mraz 2013-12-18 15:55:26 +0100
  • 86c6006dcc add back support for secp521r1 EC curve Tomas Mraz 2013-11-08 18:23:00 +0100
  • 07f114b0d0 add back support for secp521r1 EC curve Tomas Mraz 2013-11-08 18:16:49 +0100
  • ad237d19e6 fix locking and reseeding problems with FIPS drbg Tomas Mraz 2013-11-19 14:52:30 +0100
  • c9a46cb3ac Fix typos. Tomas Mraz 2013-11-15 16:57:33 +0100
  • e64d4ea7bb additional changes required for FIPS validation Tomas Mraz 2013-11-15 16:13:44 +0100
  • 9caf868063 disable verification of certificate, CRL, and OCSP signatures using MD5 Tomas Mraz 2013-11-13 20:06:28 +0100
  • dcd0fb1ec9 disable verification of certificate, CRL, and OCSP signatures using MD5 Tomas Mraz 2013-11-13 19:42:54 +0100
  • 1e5b73a151 add back support for secp521r1 EC curve Tomas Mraz 2013-11-08 18:23:00 +0100
  • 83d99a68af add back support for secp521r1 EC curve Tomas Mraz 2013-11-08 18:16:49 +0100
  • 4e5355e47f fix misdetection of RDRAND support on Cyrix CPUS (from upstream) (#1022346) Tomas Mraz 2013-10-29 16:24:08 +0100
  • 5714047e75 fix misdetection of RDRAND support on Cyrix CPUS (from upstream) (#1022346) Tomas Mraz 2013-10-29 16:24:08 +0100
  • d561e3fcd1 do not advertise ECC curves we do not support (#1022493) Tomas Mraz 2013-10-24 13:23:24 +0200
  • eca676db7a do not advertise ECC curves we do not support (#1022493) Tomas Mraz 2013-10-24 10:40:18 +0200
  • 0b29901824 Sync with rawhide. Tomas Mraz 2013-10-16 17:30:28 +0200
  • a8799e01c4 Merge remote-tracking branch 'origin/f19' into f19 Tomas Mraz 2013-10-16 16:52:19 +0200
  • e241743946 Merge remote-tracking branch 'origin/f20' into f20 Tomas Mraz 2013-10-16 16:00:01 +0200
  • b3551463ca only ECC NIST Suite B curves support Tomas Mraz 2013-10-16 14:37:51 +0200
  • 3178316eea resolve bugzilla 319901 (phew! only took 6 years & 9 days) Tom Callaway 2013-10-15 02:15:39 +0100
  • 4d56d16496 resolve bugzilla 319901 (phew! only took 6 years & 9 days) Tom Callaway 2013-10-15 02:14:11 +0100
  • 9a59868619 resolve bugzilla 319901 (phew! only took 6 years & 9 days) Tom Callaway 2013-10-15 02:13:38 +0100
  • 1f19ac14f9 resolve bugzilla 319901 (phew! only took 6 years & 9 days) Tom Callaway 2013-10-15 02:08:35 +0100
  • 7ae1dc1df9 Bump release Tomas Mraz 2013-09-27 15:46:03 +0200
  • 4e423c3c50 make DTLS1 work in FIPS mode Tomas Mraz 2013-09-27 15:43:51 +0200
  • df94661da5 avoid dlopening libssl.so from libcrypto (#1010357) Tomas Mraz 2013-09-23 18:30:01 +0200
  • 372f3ac997 fix small memory leak in FIPS aes selftest Tomas Mraz 2013-09-20 16:04:50 +0200
  • 8c28623e94 fix segfault in openssl speed hmac in the FIPS mode Tomas Mraz 2013-09-19 15:16:50 +0200
  • d907abae39 Merge branch 'f20' of ssh://pkgs.fedoraproject.org/openssl into f20 Tomas Mraz 2013-09-13 15:33:34 +0200
  • fa93b626ad Add documentation of -attime to verify manpage Tomas Mraz 2013-09-12 11:26:07 +0200
  • 30ebb4d732 document the nextprotoneg option in manual pages Tomas Mraz 2013-09-12 10:39:33 +0200
  • ae08b15c89 document the nextprotoneg option in manual pages Tomas Mraz 2013-09-12 10:23:34 +0200
  • cb069618e7 arm: use auxv to figure out armcap.c instead of using signals (#1006474) Kyle McMartin 2013-09-11 09:52:25 -0400
  • f6aa3c2ddd arm: use auxv to figure out armcap.c instead of using signals (#1006474) Kyle McMartin 2013-09-11 09:52:25 -0400
  • eb63cc63df try to avoid some races when updating the -fips subpackage Tomas Mraz 2013-09-04 13:53:38 +0200
  • 850ca72b9a use version-release in .hmac suffix to avoid overwrite during upgrade Tomas Mraz 2013-09-02 15:02:18 +0200
  • b5d2711ab6 allow deinitialization of the FIPS mode Tomas Mraz 2013-08-29 16:41:24 +0200
  • 1465572e17 always perform the FIPS selftests in library constructor Tomas Mraz 2013-08-29 11:45:04 +0200
  • bb2f3882f2 add -fips subpackage that contains the FIPS module files Tomas Mraz 2013-08-27 16:03:43 +0200
  • 9c324da28e fix use of rdrand if available Tomas Mraz 2013-08-16 16:06:51 +0200
  • a254940dd1 Perl 5.18 rebuild Petr Písař 2013-08-03 12:05:42 +0200
  • acdf8a62f6 use symbol versioning also for the textual version Tomas Mraz 2013-07-26 13:16:10 +0200
  • 9b36f08da8 additional manual page fixes Tomas Mraz 2013-07-25 15:14:25 +0200
  • 653e1efa34 use _prefix macro Tomas Mraz 2013-07-19 11:36:23 +0200
  • 49a1fc761b Perl 5.18 rebuild Petr Písař 2013-07-17 16:32:50 +0200
  • 7ccde74773 add openssl.cnf.5 manpage symlink to config.5 Tomas Mraz 2013-07-11 10:44:55 +0200
  • 9555809e80 add relro linking flag Tomas Mraz 2013-07-10 17:54:24 +0200
  • 6a0a35eb5f Add missing fix of renamed manpages. Tomas Mraz 2013-07-10 16:43:07 +0200
  • 30aa9303c7 add support for the -trusted_first option for certificate chain verification Tomas Mraz 2013-07-10 11:02:41 +0200
  • dad6e3ee78 fix build of manual pages with current pod2man (#959439) Tomas Mraz 2013-05-03 18:38:28 +0200
  • 6705192b85 Enable ARM optimised build Peter Robinson 2013-04-21 14:33:34 +0100
  • 59c61e18e3 fix random bad record mac errors (#918981) Tomas Mraz 2013-03-18 21:34:18 +0100
  • 64e30c5369 fix random bad record mac errors (#918981) Tomas Mraz 2013-03-18 21:34:18 +0100
  • 36472b541d new upstream release fixing multiple CVEs f17 Tomas Mraz 2013-02-19 21:57:05 +0100
  • 780e333d18 fix up the SHLIB_VERSION_NUMBER Tomas Mraz 2013-02-19 20:35:16 +0100
  • 9cf55df55b fix up the SHLIB_VERSION_NUMBER Tomas Mraz 2013-02-19 20:35:16 +0100
  • 04b41a91f2 __secure_getenv() must be used on F18 Tomas Mraz 2013-02-19 19:39:53 +0100
  • 169c3a0ddb disable ZLIB loading by default (due to CRIME attack) Tomas Mraz 2013-02-19 16:41:14 +0100
  • dc696fdac4 new upstream version Tomas Mraz 2013-02-19 13:57:39 +0100
  • 0fd0958b75 more fixes from upstream Tomas Mraz 2013-01-30 18:32:56 +0100
  • 2ca16b9a24 Add the renew-dummy-cert script to file list Tomas Mraz 2012-12-21 17:38:32 +0100
  • c67ea975b9 add script for renewal of a self-signed cert by Philip Prindeville (#871566) Tomas Mraz 2012-12-21 17:21:50 +0100
  • 07ac3d216e Fix bogus dates in changelog. Tomas Mraz 2012-12-07 12:37:49 +0100
  • 728b1133e0 s_time uses tm_ctx. Tomas Mraz 2012-12-07 10:01:17 +0100