acdedc
# For the curious:
acdedc
# 0.9.5a soversion = 0
acdedc
# 0.9.6  soversion = 1
acdedc
# 0.9.6a soversion = 2
acdedc
# 0.9.6c soversion = 3
acdedc
# 0.9.7a soversion = 4
acdedc
# 0.9.7ef soversion = 5
acdedc
# 0.9.8ab soversion = 6
acdedc
# 0.9.8g soversion = 7
acdedc
# 0.9.8jk + EAP-FAST soversion = 8
acdedc
# 1.0.0 soversion = 10
acdedc
# 1.1.0 soversion = 1.1 (same as upstream although presence of some symbols
acdedc
#                        depends on build configuration options)
acdedc
%define soversion 1.1
acdedc
acdedc
# Arches on which we need to prevent arch conflicts on opensslconf.h, must
acdedc
# also be handled in opensslconf-new.h.
acdedc
%define multilib_arches %{ix86} ia64 %{mips} ppc ppc64 s390 s390x sparcv9 sparc64 x86_64
acdedc
acdedc
%global _performance_build 1
acdedc
acdedc
Summary: Utilities from the general purpose cryptography library with TLS implementation
acdedc
Name: openssl
b3353e
Version: 1.1.1k
877dfe
Release: 9%{?dist}
acdedc
Epoch: 1
acdedc
# We have to remove certain patented algorithms from the openssl source
acdedc
# tarball with the hobble-openssl script which is included below.
acdedc
# The original openssl upstream tarball cannot be shipped in the .src.rpm.
acdedc
Source: openssl-%{version}-hobbled.tar.xz
acdedc
Source1: hobble-openssl
acdedc
Source2: Makefile.certificate
acdedc
Source6: make-dummy-cert
acdedc
Source7: renew-dummy-cert
acdedc
Source9: opensslconf-new.h
acdedc
Source10: opensslconf-new-warning.h
acdedc
Source11: README.FIPS
acdedc
Source12: ec_curve.c
acdedc
Source13: ectest.c
acdedc
# Build changes
acdedc
Patch1: openssl-1.1.1-build.patch
acdedc
Patch2: openssl-1.1.1-defaults.patch
7d1228
Patch3: openssl-1.1.1-no-html.patch
acdedc
Patch4: openssl-1.1.1-man-rename.patch
b3353e
acdedc
# Functionality changes
acdedc
Patch31: openssl-1.1.1-conf-paths.patch
acdedc
Patch32: openssl-1.1.1-version-add-engines.patch
acdedc
Patch33: openssl-1.1.1-apps-dgst.patch
acdedc
Patch36: openssl-1.1.1-no-brainpool.patch
acdedc
Patch37: openssl-1.1.1-ec-curves.patch
acdedc
Patch38: openssl-1.1.1-no-weak-verify.patch
acdedc
Patch40: openssl-1.1.1-sslv3-keep-abi.patch
acdedc
Patch41: openssl-1.1.1-system-cipherlist.patch
acdedc
Patch42: openssl-1.1.1-fips.patch
acdedc
Patch44: openssl-1.1.1-version-override.patch
acdedc
Patch45: openssl-1.1.1-weak-ciphers.patch
acdedc
Patch46: openssl-1.1.1-seclevel.patch
acdedc
Patch47: openssl-1.1.1-ts-sha256-default.patch
acdedc
Patch48: openssl-1.1.1-fips-post-rand.patch
acdedc
Patch49: openssl-1.1.1-evp-kdf.patch
acdedc
Patch50: openssl-1.1.1-ssh-kdf.patch
7d1228
Patch51: openssl-1.1.1-intel-cet.patch
067bfb
Patch60: openssl-1.1.1-krb5-kdf.patch
067bfb
Patch61: openssl-1.1.1-edk2-build.patch
067bfb
Patch62: openssl-1.1.1-fips-curves.patch
7d1228
Patch65: openssl-1.1.1-fips-drbg-selftest.patch
7d1228
Patch66: openssl-1.1.1-fips-dh.patch
7d1228
Patch67: openssl-1.1.1-kdf-selftest.patch
7d1228
Patch69: openssl-1.1.1-alpn-cb.patch
7d1228
Patch70: openssl-1.1.1-rewire-fips-drbg.patch
b3353e
Patch76: openssl-1.1.1-cleanup-peer-point-reneg.patch
b3353e
Patch77: openssl-1.1.1-s390x-aes.patch
b3353e
Patch78: openssl-1.1.1-detected-addr-ipv6.patch
b3353e
Patch79: openssl-1.1.1-servername-cb.patch
b3353e
Patch80: openssl-1.1.1-s390x-aes-tests.patch
acdedc
# Backported fixes including security fixes
acdedc
Patch52: openssl-1.1.1-s390x-update.patch
acdedc
Patch53: openssl-1.1.1-fips-crng-test.patch
067bfb
Patch55: openssl-1.1.1-arm-update.patch
067bfb
Patch56: openssl-1.1.1-s390x-ecc.patch
b3353e
Patch74: openssl-1.1.1-addrconfig.patch
b3353e
Patch75: openssl-1.1.1-tls13-curves.patch
434deb
Patch81: openssl-1.1.1-read-buff.patch
6e1574
Patch82: openssl-1.1.1-cve-2022-0778.patch
6e1574
Patch83: openssl-1.1.1-replace-expired-certs.patch
6e1574
Patch84: openssl-1.1.1-cve-2022-1292.patch
6e1574
Patch85: openssl-1.1.1-cve-2022-2068.patch
6e1574
Patch86: openssl-1.1.1-cve-2022-2097.patch
877dfe
#OpenSSL 1.1.1t CVEs
877dfe
Patch101: openssl-1.1.1-cve-2022-4304-RSA-oracle.patch
877dfe
Patch102: openssl-1.1.1-cve-2022-4450-PEM-bio.patch
877dfe
Patch103: openssl-1.1.1-cve-2023-0215-BIO-UAF.patch
877dfe
Patch104: openssl-1.1.1-cve-2023-0286-X400.patch
acdedc
7d1228
License: OpenSSL and ASL 2.0
acdedc
URL: http://www.openssl.org/
acdedc
BuildRequires: gcc
acdedc
BuildRequires: coreutils, perl-interpreter, sed, zlib-devel, /usr/bin/cmp
acdedc
BuildRequires: lksctp-tools-devel
acdedc
BuildRequires: /usr/bin/rename
acdedc
BuildRequires: /usr/bin/pod2man
acdedc
BuildRequires: /usr/sbin/sysctl
acdedc
BuildRequires: perl(Test::Harness), perl(Test::More), perl(Math::BigInt)
acdedc
BuildRequires: perl(Module::Load::Conditional), perl(File::Temp)
acdedc
BuildRequires: perl(Time::HiRes)
7d1228
BuildRequires: perl(FindBin), perl(lib), perl(File::Compare), perl(File::Copy)
acdedc
Requires: coreutils
acdedc
Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release}
acdedc
acdedc
%description
acdedc
The OpenSSL toolkit provides support for secure communications between
acdedc
machines. OpenSSL includes a certificate management tool and shared
acdedc
libraries which provide various cryptographic algorithms and
acdedc
protocols.
acdedc
acdedc
%package libs
acdedc
Summary: A general purpose cryptography library with TLS implementation
acdedc
Requires: ca-certificates >= 2008-5
acdedc
Requires: crypto-policies >= 20180730
acdedc
Recommends: openssl-pkcs11%{?_isa}
acdedc
# Needed obsoletes due to the base/lib subpackage split
acdedc
Obsoletes: openssl < 1:1.0.1-0.3.beta3
acdedc
Obsoletes: openssl-fips < 1:1.0.1e-28
acdedc
Provides: openssl-fips = %{epoch}:%{version}-%{release}
acdedc
acdedc
%description libs
acdedc
OpenSSL is a toolkit for supporting cryptography. The openssl-libs
acdedc
package contains the libraries that are used by various applications which
acdedc
support cryptographic algorithms and protocols.
acdedc
acdedc
%package devel
acdedc
Summary: Files for development of applications which will use OpenSSL
acdedc
Requires: %{name}-libs%{?_isa} = %{epoch}:%{version}-%{release}
acdedc
Requires: krb5-devel%{?_isa}, zlib-devel%{?_isa}
acdedc
Requires: pkgconfig
acdedc
acdedc
%description devel
acdedc
OpenSSL is a toolkit for supporting cryptography. The openssl-devel
acdedc
package contains include files needed to develop applications which
acdedc
support various cryptographic algorithms and protocols.
acdedc
acdedc
%package static
acdedc
Summary:  Libraries for static linking of applications which will use OpenSSL
acdedc
Requires: %{name}-devel%{?_isa} = %{epoch}:%{version}-%{release}
acdedc
acdedc
%description static
acdedc
OpenSSL is a toolkit for supporting cryptography. The openssl-static
acdedc
package contains static libraries needed for static linking of
acdedc
applications which support various cryptographic algorithms and
acdedc
protocols.
acdedc
acdedc
%package perl
acdedc
Summary: Perl scripts provided with OpenSSL
acdedc
Requires: perl-interpreter
acdedc
Requires: %{name}%{?_isa} = %{epoch}:%{version}-%{release}
acdedc
acdedc
%description perl
acdedc
OpenSSL is a toolkit for supporting cryptography. The openssl-perl
acdedc
package provides Perl scripts for converting certificates and keys
acdedc
from other formats to the formats used by the OpenSSL toolkit.
acdedc
acdedc
%prep
acdedc
%setup -q -n %{name}-%{version}
acdedc
acdedc
# The hobble_openssl is called here redundantly, just to be sure.
acdedc
# The tarball has already the sources removed.
acdedc
%{SOURCE1} > /dev/null
acdedc
acdedc
cp %{SOURCE12} crypto/ec/
acdedc
cp %{SOURCE13} test/
acdedc
acdedc
%patch1 -p1 -b .build   %{?_rawbuild}
acdedc
%patch2 -p1 -b .defaults
acdedc
%patch3 -p1 -b .no-html  %{?_rawbuild}
acdedc
%patch4 -p1 -b .man-rename
acdedc
acdedc
%patch31 -p1 -b .conf-paths
acdedc
%patch32 -p1 -b .version-add-engines
acdedc
%patch33 -p1 -b .dgst
acdedc
%patch36 -p1 -b .no-brainpool
acdedc
%patch37 -p1 -b .curves
acdedc
%patch38 -p1 -b .no-weak-verify
acdedc
%patch40 -p1 -b .sslv3-abi
acdedc
%patch41 -p1 -b .system-cipherlist
acdedc
%patch42 -p1 -b .fips
acdedc
%patch44 -p1 -b .version-override
acdedc
%patch45 -p1 -b .weak-ciphers
acdedc
%patch46 -p1 -b .seclevel
acdedc
%patch47 -p1 -b .ts-sha256-default
acdedc
%patch48 -p1 -b .fips-post-rand
acdedc
%patch49 -p1 -b .evp-kdf
acdedc
%patch50 -p1 -b .ssh-kdf
7d1228
%patch51 -p1 -b .intel-cet
acdedc
%patch52 -p1 -b .s390x-update
acdedc
%patch53 -p1 -b .crng-test
067bfb
%patch55 -p1 -b .arm-update
067bfb
%patch56 -p1 -b .s390x-ecc
067bfb
%patch60 -p1 -b .krb5-kdf
067bfb
%patch61 -p1 -b .edk2-build
067bfb
%patch62 -p1 -b .fips-curves
7d1228
%patch65 -p1 -b .drbg-selftest
7d1228
%patch66 -p1 -b .fips-dh
7d1228
%patch67 -p1 -b .kdf-selftest
7d1228
%patch69 -p1 -b .alpn-cb
7d1228
%patch70 -p1 -b .rewire-fips-drbg
b3353e
%patch74 -p1 -b .addrconfig
b3353e
%patch75 -p1 -b .tls13-curves
b3353e
%patch76 -p1 -b .cleanup-reneg
b3353e
%patch77 -p1 -b .s390x-aes
b3353e
%patch78 -p1 -b .addr-ipv6
b3353e
%patch79 -p1 -b .servername-cb
b3353e
%patch80 -p1 -b .s390x-test-aes
434deb
%patch81 -p1 -b .read-buff
6e1574
%patch82 -p1 -b .cve-2022-0778
6e1574
%patch83 -p1 -b .replace-expired-certs
6e1574
%patch84 -p1 -b .cve-2022-1292
6e1574
%patch85 -p1 -b .cve-2022-2068
6e1574
%patch86 -p1 -b .cve-2022-2097
877dfe
%patch101 -p1 -b .cve-2022-4304
877dfe
%patch102 -p1 -b .cve-2022-4450
877dfe
%patch103 -p1 -b .cve-2023-0215
877dfe
%patch104 -p1 -b .cve-2023-0286
acdedc
acdedc
%build
acdedc
# Figure out which flags we want to use.
acdedc
# default
acdedc
sslarch=%{_os}-%{_target_cpu}
acdedc
%ifarch %ix86
acdedc
sslarch=linux-elf
acdedc
if ! echo %{_target} | grep -q i686 ; then
acdedc
	sslflags="no-asm 386"
acdedc
fi
acdedc
%endif
acdedc
%ifarch x86_64
acdedc
sslflags=enable-ec_nistp_64_gcc_128
acdedc
%endif
acdedc
%ifarch sparcv9
acdedc
sslarch=linux-sparcv9
acdedc
sslflags=no-asm
acdedc
%endif
acdedc
%ifarch sparc64
acdedc
sslarch=linux64-sparcv9
acdedc
sslflags=no-asm
acdedc
%endif
acdedc
%ifarch alpha alphaev56 alphaev6 alphaev67
acdedc
sslarch=linux-alpha-gcc
acdedc
%endif
acdedc
%ifarch s390 sh3eb sh4eb
acdedc
sslarch="linux-generic32 -DB_ENDIAN"
acdedc
%endif
acdedc
%ifarch s390x
acdedc
sslarch="linux64-s390x"
acdedc
%endif
acdedc
%ifarch %{arm}
acdedc
sslarch=linux-armv4
acdedc
%endif
acdedc
%ifarch aarch64
acdedc
sslarch=linux-aarch64
acdedc
sslflags=enable-ec_nistp_64_gcc_128
acdedc
%endif
acdedc
%ifarch sh3 sh4
acdedc
sslarch=linux-generic32
acdedc
%endif
acdedc
%ifarch ppc64 ppc64p7
acdedc
sslarch=linux-ppc64
acdedc
%endif
acdedc
%ifarch ppc64le
acdedc
sslarch="linux-ppc64le"
acdedc
sslflags=enable-ec_nistp_64_gcc_128
acdedc
%endif
acdedc
%ifarch mips mipsel
acdedc
sslarch="linux-mips32 -mips32r2"
acdedc
%endif
acdedc
%ifarch mips64 mips64el
acdedc
sslarch="linux64-mips64 -mips64r2"
acdedc
%endif
acdedc
%ifarch mips64el
acdedc
sslflags=enable-ec_nistp_64_gcc_128
acdedc
%endif
acdedc
%ifarch riscv64
acdedc
sslarch=linux-generic64
acdedc
%endif
acdedc
acdedc
# Add -Wa,--noexecstack here so that libcrypto's assembler modules will be
acdedc
# marked as not requiring an executable stack.
acdedc
# Also add -DPURIFY to make using valgrind with openssl easier as we do not
acdedc
# want to depend on the uninitialized memory as a source of entropy anyway.
acdedc
RPM_OPT_FLAGS="$RPM_OPT_FLAGS -Wa,--noexecstack -Wa,--generate-missing-build-notes=yes -DPURIFY $RPM_LD_FLAGS"
acdedc
acdedc
export HASHBANGPERL=/usr/bin/perl
acdedc
acdedc
# ia64, x86_64, ppc are OK by default
acdedc
# Configure the build tree.  Override OpenSSL defaults with known-good defaults
acdedc
# usable on all platforms.  The Configure script already knows to use -fPIC and
acdedc
# RPM_OPT_FLAGS, so we can skip specifiying them here.
acdedc
./Configure \
acdedc
	--prefix=%{_prefix} --openssldir=%{_sysconfdir}/pki/tls ${sslflags} \
acdedc
	--system-ciphers-file=%{_sysconfdir}/crypto-policies/back-ends/openssl.config \
acdedc
	zlib enable-camellia enable-seed enable-rfc3779 enable-sctp \
acdedc
	enable-cms enable-md2 enable-rc5\
acdedc
	enable-weak-ssl-ciphers \
acdedc
	no-mdc2 no-ec2m no-sm2 no-sm4 \
acdedc
	shared  ${sslarch} $RPM_OPT_FLAGS '-DDEVRANDOM="\"/dev/urandom\""'
acdedc
acdedc
# Do not run this in a production package the FIPS symbols must be patched-in
acdedc
#util/mkdef.pl crypto update
acdedc
acdedc
make all
acdedc
acdedc
# Overwrite FIPS README
acdedc
cp -f %{SOURCE11} .
acdedc
acdedc
# Clean up the .pc files
acdedc
for i in libcrypto.pc libssl.pc openssl.pc ; do
acdedc
  sed -i '/^Libs.private:/{s/-L[^ ]* //;s/-Wl[^ ]* //}' $i
acdedc
done
acdedc
acdedc
%check
acdedc
# Verify that what was compiled actually works.
acdedc
acdedc
# Hack - either enable SCTP AUTH chunks in kernel or disable sctp for check
acdedc
(sysctl net.sctp.addip_enable=1 && sysctl net.sctp.auth_enable=1) || \
acdedc
(echo 'Failed to enable SCTP AUTH chunks, disabling SCTP for tests...' &&
acdedc
 sed '/"zlib-dynamic" => "default",/a\ \ "sctp" => "default",' configdata.pm > configdata.pm.new && \
acdedc
 touch -r configdata.pm configdata.pm.new && \
acdedc
 mv -f configdata.pm.new configdata.pm)
acdedc
acdedc
# We must revert patch31 before tests otherwise they will fail
acdedc
patch -p1 -R < %{PATCH31}
acdedc
acdedc
LD_LIBRARY_PATH=`pwd`${LD_LIBRARY_PATH:+:${LD_LIBRARY_PATH}}
acdedc
export LD_LIBRARY_PATH
acdedc
crypto/fips/fips_standalone_hmac libcrypto.so.%{soversion} >.libcrypto.so.%{soversion}.hmac
acdedc
ln -s .libcrypto.so.%{soversion}.hmac .libcrypto.so.hmac
acdedc
crypto/fips/fips_standalone_hmac libssl.so.%{soversion} >.libssl.so.%{soversion}.hmac
acdedc
ln -s .libssl.so.%{soversion}.hmac .libssl.so.hmac
acdedc
OPENSSL_ENABLE_MD5_VERIFY=
acdedc
export OPENSSL_ENABLE_MD5_VERIFY
acdedc
OPENSSL_SYSTEM_CIPHERS_OVERRIDE=xyz_nonexistent_file
acdedc
export OPENSSL_SYSTEM_CIPHERS_OVERRIDE
acdedc
make test
acdedc
acdedc
# Add generation of HMAC checksum of the final stripped library
acdedc
%define __spec_install_post \
acdedc
    %{?__debug_package:%{__debug_install_post}} \
acdedc
    %{__arch_install_post} \
acdedc
    %{__os_install_post} \
acdedc
    crypto/fips/fips_standalone_hmac $RPM_BUILD_ROOT%{_libdir}/libcrypto.so.%{version} >$RPM_BUILD_ROOT%{_libdir}/.libcrypto.so.%{version}.hmac \
acdedc
    ln -sf .libcrypto.so.%{version}.hmac $RPM_BUILD_ROOT%{_libdir}/.libcrypto.so.%{soversion}.hmac \
acdedc
    crypto/fips/fips_standalone_hmac $RPM_BUILD_ROOT%{_libdir}/libssl.so.%{version} >$RPM_BUILD_ROOT%{_libdir}/.libssl.so.%{version}.hmac \
acdedc
    ln -sf .libssl.so.%{version}.hmac $RPM_BUILD_ROOT%{_libdir}/.libssl.so.%{soversion}.hmac \
acdedc
%{nil}
acdedc
acdedc
%define __provides_exclude_from %{_libdir}/openssl
acdedc
acdedc
%install
acdedc
[ "$RPM_BUILD_ROOT" != "/" ] && rm -rf $RPM_BUILD_ROOT
acdedc
# Install OpenSSL.
acdedc
install -d $RPM_BUILD_ROOT{%{_bindir},%{_includedir},%{_libdir},%{_mandir},%{_libdir}/openssl,%{_pkgdocdir}}
acdedc
make DESTDIR=$RPM_BUILD_ROOT install
acdedc
rename so.%{soversion} so.%{version} $RPM_BUILD_ROOT%{_libdir}/*.so.%{soversion}
acdedc
for lib in $RPM_BUILD_ROOT%{_libdir}/*.so.%{version} ; do
acdedc
	chmod 755 ${lib}
acdedc
	ln -s -f `basename ${lib}` $RPM_BUILD_ROOT%{_libdir}/`basename ${lib} .%{version}`
acdedc
	ln -s -f `basename ${lib}` $RPM_BUILD_ROOT%{_libdir}/`basename ${lib} .%{version}`.%{soversion}
acdedc
done
acdedc
acdedc
# Install a makefile for generating keys and self-signed certs, and a script
acdedc
# for generating them on the fly.
acdedc
mkdir -p $RPM_BUILD_ROOT%{_sysconfdir}/pki/tls/certs
acdedc
install -m644 %{SOURCE2} $RPM_BUILD_ROOT%{_pkgdocdir}/Makefile.certificate
acdedc
install -m755 %{SOURCE6} $RPM_BUILD_ROOT%{_bindir}/make-dummy-cert
acdedc
install -m755 %{SOURCE7} $RPM_BUILD_ROOT%{_bindir}/renew-dummy-cert
acdedc
acdedc
# Move runable perl scripts to bindir
acdedc
mv $RPM_BUILD_ROOT%{_sysconfdir}/pki/tls/misc/*.pl $RPM_BUILD_ROOT%{_bindir}
acdedc
mv $RPM_BUILD_ROOT%{_sysconfdir}/pki/tls/misc/tsget $RPM_BUILD_ROOT%{_bindir}
acdedc
acdedc
# Drop the SSLv3 methods from includes
acdedc
sed -i '/ifndef OPENSSL_NO_SSL3_METHOD/,+4d' $RPM_BUILD_ROOT%{_includedir}/openssl/ssl.h
acdedc
acdedc
# Rename man pages so that they don't conflict with other system man pages.
acdedc
pushd $RPM_BUILD_ROOT%{_mandir}
acdedc
ln -s -f config.5 man5/openssl.cnf.5
acdedc
for manpage in man*/* ; do
acdedc
	if [ -L ${manpage} ]; then
acdedc
		TARGET=`ls -l ${manpage} | awk '{ print $NF }'`
acdedc
		ln -snf ${TARGET}ssl ${manpage}ssl
acdedc
		rm -f ${manpage}
acdedc
	else
acdedc
		mv ${manpage} ${manpage}ssl
acdedc
	fi
acdedc
done
acdedc
for conflict in passwd rand ; do
acdedc
	rename ${conflict} ssl${conflict} man*/${conflict}*
acdedc
# Fix dangling symlinks
acdedc
	manpage=man1/openssl-${conflict}.*
acdedc
	if [ -L ${manpage} ] ; then
acdedc
		ln -snf ssl${conflict}.1ssl ${manpage}
acdedc
	fi
acdedc
done
acdedc
popd
acdedc
acdedc
mkdir -m755 $RPM_BUILD_ROOT%{_sysconfdir}/pki/CA
acdedc
mkdir -m700 $RPM_BUILD_ROOT%{_sysconfdir}/pki/CA/private
acdedc
mkdir -m755 $RPM_BUILD_ROOT%{_sysconfdir}/pki/CA/certs
acdedc
mkdir -m755 $RPM_BUILD_ROOT%{_sysconfdir}/pki/CA/crl
acdedc
mkdir -m755 $RPM_BUILD_ROOT%{_sysconfdir}/pki/CA/newcerts
acdedc
acdedc
# Ensure the config file timestamps are identical across builds to avoid
acdedc
# mulitlib conflicts and unnecessary renames on upgrade
acdedc
touch -r %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/pki/tls/openssl.cnf
acdedc
touch -r %{SOURCE2} $RPM_BUILD_ROOT%{_sysconfdir}/pki/tls/ct_log_list.cnf
acdedc
acdedc
rm -f $RPM_BUILD_ROOT%{_sysconfdir}/pki/tls/openssl.cnf.dist
acdedc
rm -f $RPM_BUILD_ROOT%{_sysconfdir}/pki/tls/ct_log_list.cnf.dist
acdedc
acdedc
# Determine which arch opensslconf.h is going to try to #include.
acdedc
basearch=%{_arch}
acdedc
%ifarch %{ix86}
acdedc
basearch=i386
acdedc
%endif
acdedc
%ifarch sparcv9
acdedc
basearch=sparc
acdedc
%endif
acdedc
%ifarch sparc64
acdedc
basearch=sparc64
acdedc
%endif
acdedc
acdedc
%ifarch %{multilib_arches}
acdedc
# Do an opensslconf.h switcheroo to avoid file conflicts on systems where you
acdedc
# can have both a 32- and 64-bit version of the library, and they each need
acdedc
# their own correct-but-different versions of opensslconf.h to be usable.
acdedc
install -m644 %{SOURCE10} \
acdedc
	$RPM_BUILD_ROOT/%{_prefix}/include/openssl/opensslconf-${basearch}.h
acdedc
cat $RPM_BUILD_ROOT/%{_prefix}/include/openssl/opensslconf.h >> \
acdedc
	$RPM_BUILD_ROOT/%{_prefix}/include/openssl/opensslconf-${basearch}.h
acdedc
install -m644 %{SOURCE9} \
acdedc
	$RPM_BUILD_ROOT/%{_prefix}/include/openssl/opensslconf.h
acdedc
%endif
acdedc
LD_LIBRARY_PATH=`pwd`${LD_LIBRARY_PATH:+:${LD_LIBRARY_PATH}}
acdedc
export LD_LIBRARY_PATH
acdedc
acdedc
%files
acdedc
%{!?_licensedir:%global license %%doc}
acdedc
%license LICENSE
acdedc
%doc FAQ NEWS README README.FIPS
acdedc
%{_bindir}/make-dummy-cert
acdedc
%{_bindir}/renew-dummy-cert
acdedc
%{_bindir}/openssl
acdedc
%{_mandir}/man1*/*
acdedc
%{_mandir}/man5*/*
acdedc
%{_mandir}/man7*/*
acdedc
%{_pkgdocdir}/Makefile.certificate
acdedc
%exclude %{_mandir}/man1*/*.pl*
acdedc
%exclude %{_mandir}/man1*/c_rehash*
acdedc
%exclude %{_mandir}/man1*/tsget*
acdedc
%exclude %{_mandir}/man1*/openssl-tsget*
acdedc
acdedc
%files libs
acdedc
%{!?_licensedir:%global license %%doc}
acdedc
%license LICENSE
acdedc
%dir %{_sysconfdir}/pki/tls
acdedc
%dir %{_sysconfdir}/pki/tls/certs
acdedc
%dir %{_sysconfdir}/pki/tls/misc
acdedc
%dir %{_sysconfdir}/pki/tls/private
acdedc
%config(noreplace) %{_sysconfdir}/pki/tls/openssl.cnf
acdedc
%config(noreplace) %{_sysconfdir}/pki/tls/ct_log_list.cnf
acdedc
%attr(0755,root,root) %{_libdir}/libcrypto.so.%{version}
acdedc
%attr(0755,root,root) %{_libdir}/libcrypto.so.%{soversion}
acdedc
%attr(0755,root,root) %{_libdir}/libssl.so.%{version}
acdedc
%attr(0755,root,root) %{_libdir}/libssl.so.%{soversion}
acdedc
%attr(0644,root,root) %{_libdir}/.libcrypto.so.*.hmac
acdedc
%attr(0644,root,root) %{_libdir}/.libssl.so.*.hmac
acdedc
%attr(0755,root,root) %{_libdir}/engines-%{soversion}
acdedc
acdedc
%files devel
acdedc
%doc CHANGES doc/dir-locals.example.el doc/openssl-c-indent.el
acdedc
%{_prefix}/include/openssl
acdedc
%{_libdir}/*.so
acdedc
%{_mandir}/man3*/*
acdedc
%{_libdir}/pkgconfig/*.pc
acdedc
acdedc
%files static
acdedc
%{_libdir}/*.a
acdedc
acdedc
%files perl
acdedc
%{_bindir}/c_rehash
acdedc
%{_bindir}/*.pl
acdedc
%{_bindir}/tsget
acdedc
%{_mandir}/man1*/*.pl*
acdedc
%{_mandir}/man1*/c_rehash*
acdedc
%{_mandir}/man1*/tsget*
acdedc
%{_mandir}/man1*/openssl-tsget*
acdedc
%dir %{_sysconfdir}/pki/CA
acdedc
%dir %{_sysconfdir}/pki/CA/private
acdedc
%dir %{_sysconfdir}/pki/CA/certs
acdedc
%dir %{_sysconfdir}/pki/CA/crl
acdedc
%dir %{_sysconfdir}/pki/CA/newcerts
acdedc
acdedc
%post libs -p /sbin/ldconfig
acdedc
acdedc
%postun libs -p /sbin/ldconfig
acdedc
acdedc
%changelog
877dfe
* Wed Feb 08 2023 Dmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.1.1k-9
877dfe
- Fixed Timing Oracle in RSA Decryption
877dfe
  Resolves: CVE-2022-4304
877dfe
- Fixed Double free after calling PEM_read_bio_ex
877dfe
  Resolves: CVE-2022-4450
877dfe
- Fixed Use-after-free following BIO_new_NDEF
877dfe
  Resolves: CVE-2023-0215
877dfe
- Fixed X.400 address type confusion in X.509 GeneralName
877dfe
  Resolves: CVE-2023-0286
877dfe
877dfe
* Thu Jul 21 2022 Dmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.1.1k-8
877dfe
- Fix no-ec build
877dfe
  Resolves: rhbz#2071020
877dfe
6e1574
* Tue Jul 05 2022 Clemens Lang <cllang@redhat.com> - 1:1.1.1k-7
6e1574
- Fix CVE-2022-2097: AES OCB fails to encrypt some bytes on 32-bit x86
6e1574
  Resolves: CVE-2022-2097
6e1574
- Update expired certificates used in the testsuite
877dfe
  Resolves: rhbz#2092462
6e1574
- Fix CVE-2022-1292: openssl: c_rehash script allows command injection
877dfe
  Resolves: rhbz#2090372
6e1574
- Fix CVE-2022-2068: the c_rehash script allows command injection
877dfe
  Resolves: rhbz#2098279
6e1574
6e1574
* Wed Mar 23 2022 Clemens Lang <cllang@redhat.com> - 1:1.1.1k-6
6e1574
- Fixes CVE-2022-0778 openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates
877dfe
- Resolves: rhbz#2067146
6e1574
6e1574
* Tue Nov 16 2021 Sahana Prasad <sahana@redhat.com> - 1:1.1.1k-5
6e1574
- Fixes CVE-2021-3712 openssl: Read buffer overruns processing ASN.1 strings
6e1574
- Resolves: rhbz#2005402
434deb
b3353e
* Fri Jul 16 2021 Sahana Prasad <sahana@redhat.com> - 1:1.1.1k-4
b3353e
- Fixes bugs in s390x AES code.
b3353e
- Uses the first detected address family if IPv6 is not available
b3353e
- Reverts the changes in https://github.com/openssl/openssl/pull/13305
b3353e
  as it introduces a regression if server has a DSA key pair, the handshake fails
b3353e
  when the protocol is not explicitly set to TLS 1.2. However, if the patch is reverted,
b3353e
  it has an effect on the "ssl_reject_handshake" feature in nginx. Although, this feature
b3353e
  will continue to work, TLS 1.3 protocol becomes unavailable/disabled. This is already
b3353e
  known - https://trac.nginx.org/nginx/ticket/2071#comment:1
b3353e
  As per https://github.com/openssl/openssl/issues/16075#issuecomment-879939938, nginx
b3353e
  could early callback instead of servername callback.
b3353e
- Resolves: rhbz#1978214
b3353e
- Related: rhbz#1934534
b3353e
b3353e
* Thu Jun 24 2021 Sahana Prasad <sahana@redhat.com> - 1:1.1.1k-3
b3353e
- Cleansup the peer point formats on renegotiation
b3353e
- Resolves rhbz#1965362
b3353e
b3353e
* Wed Jun 23 2021 Dmitry Belyavskiy <dbelyavs@redhat.com> - 1:1.1.1k-2
b3353e
- Fixes FIPS_selftest to work in FIPS mode. Resolves: rhbz#1940085
b3353e
- Using safe primes for FIPS DH self-test
b3353e
b3353e
* Mon May 24 2021 Sahana Prasad <sahana@redhat.com> 1.1.1k-1
b3353e
- Update to version 1.1.1k
b3353e
b3353e
* Mon Apr 26 2021 Daiki Ueno <dueno@redhat.com> 1.1.1g-16
b3353e
- Use AI_ADDRCONFIG only when explicit host name is given
b3353e
- Allow only curves defined in RFC 8446 in TLS 1.3
b3353e
b3353e
* Fri Apr 16 2021 Dmitry Belyavski <dbelyavs@redhat.com> 1.1.1g-15
b3353e
- Remove 2-key 3DES test from FIPS_selftest
b3353e
b3353e
* Mon Mar 29 2021 Sahana Prasad <sahana@redhat.com> 1.1.1g-14
b3353e
- Fix CVE-2021-3450 openssl: CA certificate check bypass with
b3353e
  X509_V_FLAG_X509_STRICT
b3353e
- Fix CVE-2021-3449 NULL pointer deref in signature_algorithms processing
b3353e
b3353e
* Fri Dec  4 2020 Sahana Prasad <sahana@redhat.com> 1.1.1g-13
ec892a
- Fix CVE-2020-1971 ediparty null pointer dereference
ec892a
b3353e
* Fri Oct 23 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1g-12
ec892a
- Implemented new FIPS requirements in regards to KDF and DH selftests
ec892a
- Disallow certificates with explicit EC parameters
ec892a
ec892a
* Mon Jul 20 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1g-11
ec892a
- Further changes for SP 800-56A rev3 requirements
ec892a
7d1228
* Tue Jun 23 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1g-9
7d1228
- Rewire FIPS_drbg API to use the RAND_DRBG
7d1228
- Use the well known DH groups in TLS even for 2048 and 1024 bit parameters
7d1228
7d1228
* Mon Jun  8 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1g-7
7d1228
- Disallow dropping Extended Master Secret extension
7d1228
  on renegotiation
7d1228
- Return alert from s_server if ALPN protocol does not match
7d1228
- SHA1 is allowed in @SECLEVEL=2 only if allowed by
7d1228
  TLS SigAlgs configuration
7d1228
7d1228
* Wed Jun  3 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1g-6
7d1228
- Add FIPS selftest for PBKDF2 and KBKDF
7d1228
7d1228
* Wed May 27 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1g-5
7d1228
- Allow only well known DH groups in the FIPS mode
7d1228
7d1228
* Mon May 18 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1g-1
7d1228
- update to the 1.1.1g release
7d1228
- FIPS module installed state definition is modified
7d1228
7d1228
* Thu Mar  5 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-15
7d1228
- add selftest of the RAND_DRBG implementation
7d1228
7d1228
* Wed Feb 19 2020 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-14
7d1228
- fix incorrect error return value from FIPS_selftest_dsa
7d1228
- S390x: properly restore SIGILL signal handler
7d1228
067bfb
* Wed Dec  4 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-12
067bfb
- additional fix for the edk2 build
067bfb
067bfb
* Tue Nov 26 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-9
067bfb
- disallow use of SHA-1 signatures in TLS in FIPS mode
067bfb
067bfb
* Mon Nov 25 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-8
067bfb
- fix CVE-2019-1547 - side-channel weak encryption vulnerability
067bfb
- fix CVE-2019-1563 - padding oracle in CMS API
067bfb
- fix CVE-2019-1549 - ensure fork safety of the DRBG
067bfb
- fix handling of non-FIPS allowed EC curves in FIPS mode
067bfb
- fix TLS compliance issues
067bfb
067bfb
* Thu Nov 21 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-7
067bfb
- backported ARM performance fixes from master
067bfb
067bfb
* Wed Nov 20 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-6
067bfb
- backport of S390x ECC CPACF enhancements from master
067bfb
- FIPS mode: properly disable 1024 bit DSA key generation
067bfb
- FIPS mode: skip ED25519 and ED448 algorithms in openssl speed
067bfb
- FIPS mode: allow AES-CCM ciphersuites
067bfb
067bfb
* Tue Nov 19 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-5
067bfb
- make the code suitable for edk2 build
067bfb
067bfb
* Thu Nov 14 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-4
067bfb
- backport of SSKDF from master
067bfb
067bfb
* Wed Nov 13 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-3
067bfb
- backport of KBKDF and KRB5KDF from master
067bfb
067bfb
* Mon Jun 24 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-2
067bfb
- do not try to use EC groups disallowed in FIPS mode
067bfb
  in TLS
067bfb
- fix Valgrind regression with constant-time code
067bfb
acdedc
* Mon Jun  3 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1c-1
acdedc
- update to the 1.1.1c release
acdedc
acdedc
* Fri May 24 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1b-6
acdedc
- adjust the default cert pbe algorithm for pkcs12 -export
acdedc
  in the FIPS mode
acdedc
acdedc
* Fri May 10 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1b-5
acdedc
- Fix small regressions related to the rebase
acdedc
acdedc
* Tue May  7 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1b-3
acdedc
- FIPS compliance fixes
acdedc
acdedc
* Tue May  7 2019 Tomáš Mráz <tmraz@redhat.com> 1.1.1b-1
acdedc
- update to the 1.1.1b release
acdedc
- EVP_KDF API backport from master
acdedc
- SSH KDF implementation for EVP_KDF API backport from master
acdedc
- add S390x chacha20-poly1305 assembler support from master branch
acdedc
acdedc
* Fri Dec 14 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-8
acdedc
- make openssl ts default to using SHA256 digest
acdedc
acdedc
* Wed Nov 14 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-7
acdedc
- use /dev/urandom for seeding the RNG in FIPS POST
acdedc
acdedc
* Mon Oct 15 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-6
acdedc
- make SECLEVEL=3 work
acdedc
acdedc
* Tue Oct  9 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-5
acdedc
- fix defects found in Coverity scan
acdedc
acdedc
* Mon Oct  1 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-4
acdedc
- drop SSLv3 support
acdedc
acdedc
* Tue Sep 25 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-3
acdedc
- drop the TLS-1.3 version revert
acdedc
acdedc
* Mon Sep 17 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-2
acdedc
- disable RC4-MD5 ciphersuites completely
acdedc
acdedc
* Fri Sep 14 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-1
acdedc
- update to the final 1.1.1 version
acdedc
- for consistent support of security policies we build
acdedc
  RC4 support in TLS (not default) and allow SHA1 in SECLEVEL 2
acdedc
- use only /dev/urandom if getrandom() is not available
acdedc
- disable SM4
acdedc
acdedc
* Thu Aug 23 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-0.pre9.1
acdedc
- update to the latest 1.1.1 beta version
acdedc
- temporarily revert TLS-1.3 to draft 28 version
acdedc
acdedc
* Mon Aug 13 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-0.pre8.4
acdedc
- bidirectional shutdown fixes from upstream
acdedc
acdedc
* Mon Aug 13 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-0.pre8.3
acdedc
- do not put error on stack when using fixed protocol version
acdedc
  with the default config (#1615098)
acdedc
acdedc
* Fri Jul 27 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-0.pre8.2
acdedc
- load crypto policy config file from the default config
acdedc
acdedc
* Wed Jul 25 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.1-0.pre8
acdedc
- update to the latest 1.1.1 beta version
acdedc
acdedc
* Fri Jul 13 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1:1.1.0h-6
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_29_Mass_Rebuild
acdedc
acdedc
* Tue Jun 19 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.0h-5
acdedc
- fix FIPS RSA key generation failure
acdedc
acdedc
* Mon Jun  4 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.0h-4
acdedc
- ppc64le is not multilib arch (#1584994)
acdedc
acdedc
* Tue Apr  3 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.0h-3
acdedc
- fix regression of c_rehash (#1562953)
acdedc
acdedc
* Thu Mar 29 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.0h-2
acdedc
- fix FIPS symbol versions
acdedc
acdedc
* Thu Mar 29 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.0h-1
acdedc
- update to upstream version 1.1.0h
acdedc
- add Recommends for openssl-pkcs11
acdedc
acdedc
* Fri Feb 23 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.0g-6
acdedc
- one more try to apply RPM_LD_FLAGS properly (#1541033)
acdedc
- dropped unneeded starttls xmpp patch (#1417017)
acdedc
acdedc
* Thu Feb 08 2018 Fedora Release Engineering <releng@fedoraproject.org> - 1:1.1.0g-5
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_28_Mass_Rebuild
acdedc
acdedc
* Thu Feb  1 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.0g-4
acdedc
- apply RPM_LD_FLAGS properly (#1541033)
acdedc
acdedc
* Thu Jan 11 2018 Tomáš Mráz <tmraz@redhat.com> 1.1.0g-3
acdedc
- silence the .rnd write failure as that is auxiliary functionality (#1524833)
acdedc
acdedc
* Thu Dec 14 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0g-2
acdedc
- put the Makefile.certificate in pkgdocdir and drop the requirement on make
acdedc
acdedc
* Fri Nov  3 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0g-1
acdedc
- update to upstream version 1.1.0g
acdedc
acdedc
* Thu Aug 03 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1:1.1.0f-9
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Binutils_Mass_Rebuild
acdedc
acdedc
* Thu Jul 27 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1:1.1.0f-8
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_27_Mass_Rebuild
acdedc
acdedc
* Mon Jul 17 2017 Tomáš Mráz <tmraz@redhat.com> 1:1.1.0f-7
acdedc
- make s_client and s_server work with -ssl3 option (#1471783)
acdedc
acdedc
* Thu Jul 13 2017 Petr Pisar <ppisar@redhat.com> - 1:1.1.0f-6
acdedc
- perl dependency renamed to perl-interpreter
acdedc
  <https://fedoraproject.org/wiki/Changes/perl_Package_to_Install_Core_Modules>
acdedc
acdedc
* Mon Jun 26 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0f-5
acdedc
- disable verification of all insecure hashes
acdedc
acdedc
* Fri Jun 23 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0f-4
acdedc
- make DTLS work (#1462541)
acdedc
acdedc
* Thu Jun 15 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0f-3
acdedc
- enable 3DES SSL ciphersuites, RC4 is kept disabled (#1453066)
acdedc
acdedc
* Mon Jun  5 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0f-2
acdedc
- only release thread-local key if we created it (from upstream) (#1458775)
acdedc
acdedc
* Fri Jun  2 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0f-1
acdedc
- update to upstream version 1.1.0f
acdedc
- SRP and GOST is now allowed, note that GOST support requires
acdedc
  adding GOST engine which is not part of openssl anymore
acdedc
acdedc
* Thu Feb 16 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0e-1
acdedc
- update to upstream version 1.1.0e
acdedc
- add documentation of the PROFILE=SYSTEM special cipher string (#1420232)
acdedc
acdedc
* Sat Feb 11 2017 Fedora Release Engineering <releng@fedoraproject.org> - 1:1.1.0d-3
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_26_Mass_Rebuild
acdedc
acdedc
* Wed Feb  1 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0d-2
acdedc
- applied upstream fixes (fix regression in X509_CRL_digest)
acdedc
acdedc
* Thu Jan 26 2017 Tomáš Mráz <tmraz@redhat.com> 1.1.0d-1
acdedc
- update to upstream version 1.1.0d
acdedc
acdedc
* Thu Dec 22 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0c-5
acdedc
- preserve new line in fd BIO BIO_gets() as other BIOs do
acdedc
acdedc
* Fri Dec  2 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0c-4
acdedc
- FIPS mode fixes for TLS
acdedc
acdedc
* Wed Nov 30 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0c-3
acdedc
- revert SSL_read() behavior change - patch from upstream (#1394677)
acdedc
- fix behavior on client certificate request in renegotiation (#1393579)
acdedc
acdedc
* Tue Nov 22 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0c-2
acdedc
- EC curve NIST P-224 is now allowed, still kept disabled in TLS due
acdedc
  to less than optimal security
acdedc
acdedc
* Fri Nov 11 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0c-1
acdedc
- update to upstream version 1.1.0c
acdedc
acdedc
* Fri Nov  4 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0b-4
acdedc
- use a random seed if the supplied one did not generate valid
acdedc
  parameters in dsa_builtin_paramgen2()
acdedc
acdedc
* Wed Oct 12 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0b-3
acdedc
- do not break contract on return value when using dsa_builtin_paramgen2()
acdedc
acdedc
* Wed Oct 12 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0b-2
acdedc
- fix afalg failure on big endian
acdedc
acdedc
* Tue Oct 11 2016 Tomáš Mráz <tmraz@redhat.com> 1.1.0b-1
acdedc
- update to upstream version 1.1.0b
acdedc
acdedc
* Fri Oct 07 2016 Richard W.M. Jones <rjones@redhat.com> - 1:1.0.2j-2
acdedc
- Add flags for riscv64.
acdedc
acdedc
* Mon Sep 26 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2j-1
acdedc
- minor upstream release 1.0.2j fixing regression from previous release
acdedc
acdedc
* Sat Sep 24 2016 David Woodhouse <dwmw2@infradead.org> 1.0.2i-2
acdedc
- Fix enginesdir in libcrypto.c (#1375361)
acdedc
acdedc
* Thu Sep 22 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2i-1
acdedc
- minor upstream release 1.0.2i fixing security issues
acdedc
- move man pages for perl based scripts to perl subpackage (#1377617)
acdedc
acdedc
* Wed Aug 10 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2h-3
acdedc
- fix regression in Cisco AnyConnect VPN support (#1354588)
acdedc
acdedc
* Mon Jun 27 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2h-2
acdedc
- require libcrypto in libssl.pc (#1301301)
acdedc
acdedc
* Tue May  3 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2h-1
acdedc
- minor upstream release 1.0.2h fixing security issues
acdedc
acdedc
* Tue Mar 29 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2g-4
acdedc
- disable SSLv2 support altogether (without ABI break)
acdedc
acdedc
* Mon Mar  7 2016 Tom Callaway <spot@fedoraproject.org> - 1.0.2g-3
acdedc
- enable RC5
acdedc
acdedc
* Wed Mar  2 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2g-2
acdedc
- reenable SSL2 in the build to avoid ABI break (it does not
acdedc
  make the openssl vulnerable to DROWN attack)
acdedc
acdedc
* Tue Mar  1 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2g-1
acdedc
- minor upstream release 1.0.2g fixing security issues
acdedc
acdedc
* Thu Feb 04 2016 Fedora Release Engineering <releng@fedoraproject.org> - 1:1.0.2f-2
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_24_Mass_Rebuild
acdedc
acdedc
* Thu Jan 28 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2f-1
acdedc
- minor upstream release 1.0.2f fixing security issues
acdedc
- add support for MIPS secondary architecture
acdedc
acdedc
* Fri Jan 15 2016 Tomáš Mráz <tmraz@redhat.com> 1.0.2e-5
acdedc
- document some options of openssl speed command
acdedc
acdedc
* Fri Dec 18 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2e-4
acdedc
- enable sctp support in DTLS
acdedc
acdedc
* Tue Dec  8 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2e-3
acdedc
- remove unimplemented EC method from header (#1289599)
acdedc
acdedc
* Mon Dec  7 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2e-2
acdedc
- the fast nistp implementation works only on little endian architectures
acdedc
acdedc
* Fri Dec  4 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2e-1
acdedc
- minor upstream release 1.0.2e fixing moderate severity security issues
acdedc
- enable fast assembler implementation for NIST P-256 and P-521
acdedc
  elliptic curves (#1164210)
acdedc
- filter out unwanted link options from the .pc files (#1257836)
acdedc
- do not set serial to 0 in Makefile.certificate (#1135719)
acdedc
acdedc
* Mon Nov 16 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2d-3
acdedc
- fix sigill on some AMD CPUs (#1278194)
acdedc
acdedc
* Wed Aug 12 2015 Tom Callaway <spot@fedoraproject.org> 1.0.2d-2
acdedc
- re-enable secp256k1 (bz1021898)
acdedc
acdedc
* Thu Jul  9 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2d-1
acdedc
- minor upstream release 1.0.2d fixing a high severity security issue
acdedc
acdedc
* Tue Jul  7 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2c-3
acdedc
- fix the aarch64 build
acdedc
acdedc
* Thu Jun 18 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.0.2c-2
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
acdedc
acdedc
* Mon Jun 15 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2c-1
acdedc
- minor upstream release 1.0.2c fixing multiple security issues
acdedc
acdedc
* Thu May  7 2015 Peter Robinson <pbrobinson@fedoraproject.org> 1.0.2a-4
acdedc
- Add aarch64 sslarch details
acdedc
acdedc
* Thu May  7 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2a-3
acdedc
- fix some 64 bit build targets
acdedc
acdedc
* Tue Apr 28 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2a-2
acdedc
- add alternative certificate chain discovery support from upstream
acdedc
acdedc
* Thu Apr 23 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.2a-1
acdedc
- rebase to 1.0.2 branch
acdedc
acdedc
* Thu Apr  9 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.1k-7
acdedc
- drop the AES-GCM restriction of 2^32 operations because the IV is
acdedc
  always 96 bits (32 bit fixed field + 64 bit invocation field)
acdedc
acdedc
* Thu Mar 19 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.1k-6
acdedc
- fix CVE-2015-0209 - potential use after free in d2i_ECPrivateKey()
acdedc
- fix CVE-2015-0286 - improper handling of ASN.1 boolean comparison
acdedc
- fix CVE-2015-0287 - ASN.1 structure reuse decoding memory corruption
acdedc
- fix CVE-2015-0289 - NULL dereference decoding invalid PKCS#7 data
acdedc
- fix CVE-2015-0293 - triggerable assert in SSLv2 server
acdedc
acdedc
* Mon Mar 16 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.1k-5
acdedc
- fix bug in the CRYPTO_128_unwrap()
acdedc
acdedc
* Fri Feb 27 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.1k-4
acdedc
- fix bug in the RFC 5649 support (#1185878)
acdedc
acdedc
* Sat Feb 21 2015 Till Maas <opensource@till.name> - 1:1.0.1k-3
acdedc
- Rebuilt for Fedora 23 Change
acdedc
  https://fedoraproject.org/wiki/Changes/Harden_all_packages_with_position-independent_code
acdedc
acdedc
* Thu Jan 15 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.1k-2
acdedc
- test in the non-FIPS RSA keygen for minimal distance of p and q
acdedc
  similarly to the FIPS RSA keygen
acdedc
acdedc
* Fri Jan  9 2015 Tomáš Mráz <tmraz@redhat.com> 1.0.1k-1
acdedc
- new upstream release fixing multiple security issues
acdedc
acdedc
* Thu Nov 20 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1j-3
acdedc
- disable SSLv3 by default again (mail servers and possibly
acdedc
  LDAP servers should probably allow it explicitly for legacy
acdedc
  clients)
acdedc
acdedc
* Tue Oct 21 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1j-2
acdedc
- update the FIPS RSA keygen to be FIPS 186-4 compliant
acdedc
acdedc
* Thu Oct 16 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1j-1
acdedc
- new upstream release fixing multiple security issues
acdedc
acdedc
* Fri Oct 10 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1i-5
acdedc
- copy negotiated digests when switching certs by SNI (#1150032)
acdedc
acdedc
* Mon Sep  8 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1i-4
acdedc
- add support for RFC 5649
acdedc
acdedc
* Sun Aug 17 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.0.1i-3
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild
acdedc
acdedc
* Wed Aug 13 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1i-2
acdedc
- drop RSA X9.31 from RSA FIPS selftests
acdedc
- add Power 8 optimalizations
acdedc
acdedc
* Thu Aug  7 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1i-1
acdedc
- new upstream release fixing multiple moderate security issues
acdedc
- for now disable only SSLv2 by default
acdedc
acdedc
* Fri Jul 18 2014 Tom Callaway <spot@fedoraproject.org> 1.0.1h-6
acdedc
- fix license handling
acdedc
acdedc
* Mon Jun 30 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1h-5
acdedc
- disable SSLv2 and SSLv3 protocols by default (can be enabled
acdedc
  via appropriate SSL_CTX_clear_options() call)
acdedc
acdedc
* Wed Jun 11 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1h-4
acdedc
- use system profile for default cipher list
acdedc
acdedc
* Tue Jun 10 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1h-3
acdedc
- make FIPS mode keygen bit length restriction enforced only when
acdedc
  OPENSSL_ENFORCE_MODULUS_BITS is set
acdedc
- fix CVE-2014-0224 fix that broke EAP-FAST session resumption support
acdedc
acdedc
* Sat Jun 07 2014 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.0.1h-2
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild
acdedc
acdedc
* Thu Jun  5 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1h-1
acdedc
- new upstream release 1.0.1h
acdedc
acdedc
* Sat May 31 2014 Peter Robinson <pbrobinson@fedoraproject.org> 1.0.1g-2
acdedc
- Drop obsolete and irrelevant docs
acdedc
- Move devel docs to appropriate package
acdedc
acdedc
* Wed May  7 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1g-1
acdedc
- new upstream release 1.0.1g
acdedc
- do not include ECC ciphersuites in SSLv2 client hello (#1090952)
acdedc
- fail on hmac integrity check if the .hmac file is empty
acdedc
acdedc
* Mon Apr 07 2014 Dennis Gilmore <dennis@ausil.us> - 1.0.1e-44
acdedc
- pull in upstream patch for CVE-2014-0160
acdedc
- removed CHANGES file portion from patch for expediency
acdedc
acdedc
* Thu Apr  3 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-43
acdedc
- add support for ppc64le architecture (#1072633)
acdedc
acdedc
* Mon Mar 17 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-42
acdedc
- properly detect encryption failure in BIO
acdedc
- use 2048 bit RSA key in FIPS selftests
acdedc
acdedc
* Fri Feb 14 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-41
acdedc
- use the key length from configuration file if req -newkey rsa is invoked
acdedc
acdedc
* Thu Feb 13 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-40
acdedc
- print ephemeral key size negotiated in TLS handshake (#1057715)
acdedc
- add DH_compute_key_padded needed for FIPS CAVS testing
acdedc
acdedc
* Thu Feb  6 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-39
acdedc
- make expiration and key length changeable by DAYS and KEYLEN
acdedc
  variables in the certificate Makefile (#1058108)
acdedc
- change default hash to sha256 (#1062325)
acdedc
acdedc
* Wed Jan 22 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-38
acdedc
- make 3des strength to be 128 bits instead of 168 (#1056616)
acdedc
acdedc
* Tue Jan  7 2014 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-37
acdedc
- fix CVE-2013-4353 - Invalid TLS handshake crash
acdedc
- fix CVE-2013-6450 - possible MiTM attack on DTLS1
acdedc
acdedc
* Fri Dec 20 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-36
acdedc
- fix CVE-2013-6449 - crash when version in SSL structure is incorrect
acdedc
- more FIPS validation requirement changes
acdedc
acdedc
* Wed Dec 18 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-35
acdedc
- drop weak ciphers from the default TLS ciphersuite list
acdedc
- add back some symbols that were dropped with update to 1.0.1 branch
acdedc
- more FIPS validation requirement changes
acdedc
acdedc
* Tue Nov 19 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-34
acdedc
- fix locking and reseeding problems with FIPS drbg
acdedc
acdedc
* Fri Nov 15 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-33
acdedc
- additional changes required for FIPS validation
acdedc
acdedc
* Wed Nov 13 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-32
acdedc
- disable verification of certificate, CRL, and OCSP signatures
acdedc
  using MD5 if OPENSSL_ENABLE_MD5_VERIFY environment variable
acdedc
  is not set
acdedc
acdedc
* Fri Nov  8 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-31
acdedc
- add back support for secp521r1 EC curve
acdedc
- add aarch64 to Configure (#969692)
acdedc
acdedc
* Tue Oct 29 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-30
acdedc
- fix misdetection of RDRAND support on Cyrix CPUS (from upstream) (#1022346)
acdedc
acdedc
* Thu Oct 24 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-29
acdedc
- do not advertise ECC curves we do not support (#1022493)
acdedc
acdedc
* Wed Oct 16 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-28
acdedc
- only ECC NIST Suite B curves support
acdedc
- drop -fips subpackage
acdedc
acdedc
* Mon Oct 14 2013 Tom Callaway <spot@fedoraproject.org> - 1.0.1e-27
acdedc
- resolve bugzilla 319901 (phew! only took 6 years & 9 days)
acdedc
acdedc
* Fri Sep 27 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-26
acdedc
- make DTLS1 work in FIPS mode
acdedc
- avoid RSA and DSA 512 bits and Whirlpool in 'openssl speed' in FIPS mode
acdedc
acdedc
* Mon Sep 23 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-25
acdedc
- avoid dlopening libssl.so from libcrypto (#1010357)
acdedc
acdedc
* Fri Sep 20 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-24
acdedc
- fix small memory leak in FIPS aes selftest
acdedc
acdedc
* Thu Sep 19 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-23
acdedc
- fix segfault in openssl speed hmac in the FIPS mode
acdedc
acdedc
* Thu Sep 12 2013 Tomáš Mráz <tmraz@redhat.com> 1.0.1e-22
acdedc
- document the nextprotoneg option in manual pages
acdedc
  original patch by Hubert Kario
acdedc
acdedc
* Tue Sep 10 2013 Kyle McMartin <kyle@redhat.com> 1.0.1e-21
acdedc
- [arm] use elf auxv to figure out armcap.c instead of playing silly
acdedc
  games with SIGILL handlers. (#1006474)
acdedc
acdedc
* Wed Sep  4 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-20
acdedc
- try to avoid some races when updating the -fips subpackage
acdedc
acdedc
* Mon Sep  2 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-19
acdedc
- use version-release in .hmac suffix to avoid overwrite
acdedc
  during upgrade
acdedc
acdedc
* Thu Aug 29 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-18
acdedc
- allow deinitialization of the FIPS mode
acdedc
acdedc
* Thu Aug 29 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-17
acdedc
- always perform the FIPS selftests in library constructor
acdedc
  if FIPS module is installed
acdedc
acdedc
* Tue Aug 27 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-16
acdedc
- add -fips subpackage that contains the FIPS module files
acdedc
acdedc
* Fri Aug 16 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-15
acdedc
- fix use of rdrand if available
acdedc
- more commits cherry picked from upstream
acdedc
- documentation fixes
acdedc
acdedc
* Sat Aug 03 2013 Petr Pisar <ppisar@redhat.com> - 1:1.0.1e-14
acdedc
- Perl 5.18 rebuild
acdedc
acdedc
* Fri Jul 26 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-13
acdedc
- additional manual page fix
acdedc
- use symbol versioning also for the textual version
acdedc
acdedc
* Thu Jul 25 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-12
acdedc
- additional manual page fixes
acdedc
acdedc
* Fri Jul 19 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-11
acdedc
- use _prefix macro
acdedc
acdedc
* Wed Jul 17 2013 Petr Pisar <ppisar@redhat.com> - 1:1.0.1e-10
acdedc
- Perl 5.18 rebuild
acdedc
acdedc
* Thu Jul 11 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-9
acdedc
- add openssl.cnf.5 manpage symlink to config.5
acdedc
acdedc
* Wed Jul 10 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-8
acdedc
- add relro linking flag
acdedc
acdedc
* Wed Jul 10 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-7
acdedc
- add support for the -trusted_first option for certificate chain verification
acdedc
acdedc
* Fri May  3 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-6
acdedc
- fix build of manual pages with current pod2man (#959439)
acdedc
acdedc
* Sun Apr 21 2013 Peter Robinson <pbrobinson@fedoraproject.org> 1.0.1e-5
acdedc
- Enable ARM optimised build
acdedc
acdedc
* Mon Mar 18 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-4
acdedc
- fix random bad record mac errors (#918981)
acdedc
acdedc
* Tue Feb 19 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-3
acdedc
- fix up the SHLIB_VERSION_NUMBER
acdedc
acdedc
* Tue Feb 19 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-2
acdedc
- disable ZLIB loading by default (due to CRIME attack)
acdedc
acdedc
* Tue Feb 19 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1e-1
acdedc
- new upstream version
acdedc
acdedc
* Wed Jan 30 2013 Tomas Mraz <tmraz@redhat.com> 1.0.1c-12
acdedc
- more fixes from upstream
acdedc
- fix errors in manual causing build failure (#904777)
acdedc
acdedc
* Fri Dec 21 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-11
acdedc
- add script for renewal of a self-signed cert by Philip Prindeville (#871566)
acdedc
- allow X509_issuer_and_serial_hash() produce correct result in
acdedc
  the FIPS mode (#881336)
acdedc
acdedc
* Thu Dec  6 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-10
acdedc
- do not load default verify paths if CApath or CAfile specified (#884305)
acdedc
acdedc
* Tue Nov 20 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-9
acdedc
- more fixes from upstream CVS
acdedc
- fix DSA key pairwise check (#878597)
acdedc
acdedc
* Thu Nov 15 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-8
acdedc
- use 1024 bit DH parameters in s_server as 512 bit is not allowed
acdedc
  in FIPS mode and it is quite weak anyway
acdedc
acdedc
* Mon Sep 10 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-7
acdedc
- add missing initialization of str in aes_ccm_init_key (#853963)
acdedc
- add important patches from upstream CVS
acdedc
- use the secure_getenv() with new glibc
acdedc
acdedc
* Fri Jul 20 2012 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1:1.0.1c-6
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild
acdedc
acdedc
* Fri Jul 13 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-5
acdedc
- use __getenv_secure() instead of __libc_enable_secure
acdedc
acdedc
* Fri Jul 13 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-4
acdedc
- do not move libcrypto to /lib
acdedc
- do not use environment variables if __libc_enable_secure is on
acdedc
- fix strict aliasing problems in modes
acdedc
acdedc
* Thu Jul 12 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-3
acdedc
- fix DSA key generation in FIPS mode (#833866)
acdedc
- allow duplicate FIPS_mode_set(1)
acdedc
- enable build on ppc64 subarch (#834652)
acdedc
acdedc
* Wed Jul 11 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-2
acdedc
- fix s_server with new glibc when no global IPv6 address (#839031)
acdedc
- make it build with new Perl
acdedc
acdedc
* Tue May 15 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1c-1
acdedc
- new upstream version
acdedc
acdedc
* Thu Apr 26 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1b-1
acdedc
- new upstream version
acdedc
acdedc
* Fri Apr 20 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1a-1
acdedc
- new upstream version fixing CVE-2012-2110
acdedc
acdedc
* Wed Apr 11 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1-3
acdedc
- add Kerberos 5 libraries to pkgconfig for static linking (#807050)
acdedc
acdedc
* Thu Apr  5 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1-2
acdedc
- backports from upstream CVS
acdedc
- fix segfault when /dev/urandom is not available (#809586)
acdedc
acdedc
* Wed Mar 14 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1-1
acdedc
- new upstream release
acdedc
acdedc
* Mon Mar  5 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1-0.3.beta3
acdedc
- add obsoletes to assist multilib updates (#799636)
acdedc
acdedc
* Wed Feb 29 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1-0.2.beta3
acdedc
- epoch bumped to 1 due to revert to 1.0.0g on Fedora 17
acdedc
- new upstream release from the 1.0.1 branch
acdedc
- fix s390x build (#798411)
acdedc
- versioning for the SSLeay symbol (#794950)
acdedc
- add -DPURIFY to build flags (#797323)
acdedc
- filter engine provides
acdedc
- split the libraries to a separate -libs package
acdedc
- add make to requires on the base package (#783446)
acdedc
acdedc
* Tue Feb  7 2012 Tomas Mraz <tmraz@redhat.com> 1.0.1-0.1.beta2
acdedc
- new upstream release from the 1.0.1 branch, ABI compatible
acdedc
- add documentation for the -no_ign_eof option
acdedc
acdedc
* Thu Jan 19 2012 Tomas Mraz <tmraz@redhat.com> 1.0.0g-1
acdedc
- new upstream release fixing CVE-2012-0050 - DoS regression in
acdedc
  DTLS support introduced by the previous release (#782795)
acdedc
acdedc
* Thu Jan  5 2012 Tomas Mraz <tmraz@redhat.com> 1.0.0f-1
acdedc
- new upstream release fixing multiple CVEs
acdedc
acdedc
* Tue Nov 22 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0e-4
acdedc
- move the libraries needed for static linking to Libs.private
acdedc
acdedc
* Thu Nov  3 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0e-3
acdedc
- do not use AVX instructions when osxsave bit not set
acdedc
- add direct known answer tests for SHA2 algorithms
acdedc
acdedc
* Wed Sep 21 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0e-2
acdedc
- fix missing initialization of variable in CHIL engine
acdedc
acdedc
* Wed Sep  7 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0e-1
acdedc
- new upstream release fixing CVE-2011-3207 (#736088)
acdedc
acdedc
* Wed Aug 24 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0d-8
acdedc
- drop the separate engine for Intel acceleration improvements
acdedc
  and merge in the AES-NI, SHA1, and RC4 optimizations
acdedc
- add support for OPENSSL_DISABLE_AES_NI environment variable
acdedc
  that disables the AES-NI support
acdedc
acdedc
* Tue Jul 26 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0d-7
acdedc
- correct openssl cms help output (#636266)
acdedc
- more tolerant starttls detection in XMPP protocol (#608239)
acdedc
acdedc
* Wed Jul 20 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0d-6
acdedc
- add support for newest Intel acceleration improvements backported
acdedc
  from upstream by Intel in form of a separate engine
acdedc
acdedc
* Thu Jun  9 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0d-5
acdedc
- allow the AES-NI engine in the FIPS mode
acdedc
acdedc
* Tue May 24 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0d-4
acdedc
- add API necessary for CAVS testing of the new DSA parameter generation
acdedc
acdedc
* Thu Apr 28 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0d-3
acdedc
- add support for VIA Padlock on 64bit arch from upstream (#617539)
acdedc
- do not return bogus values from load_certs (#652286)
acdedc
acdedc
* Tue Apr  5 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0d-2
acdedc
- clarify apps help texts for available digest algorithms (#693858)
acdedc
acdedc
* Thu Feb 10 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0d-1
acdedc
- new upstream release fixing CVE-2011-0014 (OCSP stapling vulnerability)
acdedc
acdedc
* Tue Feb 08 2011 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 1.0.0c-4
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_15_Mass_Rebuild
acdedc
acdedc
* Fri Feb  4 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0c-3
acdedc
- add -x931 parameter to openssl genrsa command to use the ANSI X9.31
acdedc
  key generation method
acdedc
- use FIPS-186-3 method for DSA parameter generation
acdedc
- add OPENSSL_FIPS_NON_APPROVED_MD5_ALLOW environment variable
acdedc
  to allow using MD5 when the system is in the maintenance state
acdedc
  even if the /proc fips flag is on
acdedc
- make openssl pkcs12 command work by default in the FIPS mode
acdedc
acdedc
* Mon Jan 24 2011 Tomas Mraz <tmraz@redhat.com> 1.0.0c-2
acdedc
- listen on ipv6 wildcard in s_server so we accept connections
acdedc
  from both ipv4 and ipv6 (#601612)
acdedc
- fix openssl speed command so it can be used in the FIPS mode
acdedc
  with FIPS allowed ciphers
acdedc
acdedc
* Fri Dec  3 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0c-1
acdedc
- new upstream version fixing CVE-2010-4180
acdedc
acdedc
* Tue Nov 23 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0b-3
acdedc
- replace the revert for the s390x bignum asm routines with
acdedc
  fix from upstream
acdedc
acdedc
* Mon Nov 22 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0b-2
acdedc
- revert upstream change in s390x bignum asm routines
acdedc
acdedc
* Tue Nov 16 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0b-1
acdedc
- new upstream version fixing CVE-2010-3864 (#649304)
acdedc
acdedc
* Tue Sep  7 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0a-3
acdedc
- make SHLIB_VERSION reflect the library suffix
acdedc
acdedc
* Wed Jun 30 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0a-2
acdedc
- openssl man page fix (#609484)
acdedc
acdedc
* Fri Jun  4 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0a-1
acdedc
- new upstream patch release, fixes CVE-2010-0742 (#598738)
acdedc
  and CVE-2010-1633 (#598732)
acdedc
acdedc
* Wed May 19 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-5
acdedc
- pkgconfig files now contain the correct libdir (#593723)
acdedc
acdedc
* Tue May 18 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-4
acdedc
- make CA dir readable - the private keys are in private subdir (#584810)
acdedc
acdedc
* Fri Apr  9 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-3
acdedc
- a few fixes from upstream CVS
acdedc
- move libcrypto to /lib (#559953)
acdedc
acdedc
* Tue Apr  6 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-2
acdedc
- set UTC timezone on pod2man run (#578842)
acdedc
- make X509_NAME_hash_old work in FIPS mode
acdedc
acdedc
* Tue Mar 30 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-1
acdedc
- update to final 1.0.0 upstream release
acdedc
acdedc
* Tue Feb 16 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.22.beta5
acdedc
- make TLS work in the FIPS mode
acdedc
acdedc
* Fri Feb 12 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.21.beta5
acdedc
- gracefully handle zero length in assembler implementations of
acdedc
  OPENSSL_cleanse (#564029)
acdedc
- do not fail in s_server if client hostname not resolvable (#561260)
acdedc
acdedc
* Wed Jan 20 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.20.beta5
acdedc
- new upstream release
acdedc
acdedc
* Thu Jan 14 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.19.beta4
acdedc
- fix CVE-2009-4355 - leak in applications incorrectly calling
acdedc
  CRYPTO_free_all_ex_data() before application exit (#546707)
acdedc
- upstream fix for future TLS protocol version handling
acdedc
acdedc
* Wed Jan 13 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.18.beta4
acdedc
- add support for Intel AES-NI
acdedc
acdedc
* Thu Jan  7 2010 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.17.beta4
acdedc
- upstream fix compression handling on session resumption
acdedc
- various null checks and other small fixes from upstream
acdedc
- upstream changes for the renegotiation info according to the latest draft
acdedc
acdedc
* Mon Nov 23 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.16.beta4
acdedc
- fix non-fips mingw build (patch by Kalev Lember)
acdedc
- add IPV6 fix for DTLS
acdedc
acdedc
* Fri Nov 20 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.15.beta4
acdedc
- add better error reporting for the unsafe renegotiation
acdedc
acdedc
* Fri Nov 20 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.14.beta4
acdedc
- fix build on s390x
acdedc
acdedc
* Wed Nov 18 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.13.beta4
acdedc
- disable enforcement of the renegotiation extension on the client (#537962)
acdedc
- add fixes from the current upstream snapshot
acdedc
acdedc
* Fri Nov 13 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.12.beta4
acdedc
- keep the beta status in version number at 3 so we do not have to rebuild
acdedc
  openssh and possibly other dependencies with too strict version check
acdedc
acdedc
* Thu Nov 12 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.11.beta4
acdedc
- update to new upstream version, no soname bump needed
acdedc
- fix CVE-2009-3555 - note that the fix is bypassed if SSL_OP_ALL is used
acdedc
  so the compatibility with unfixed clients is not broken. The
acdedc
  protocol extension is also not final.
acdedc
acdedc
* Fri Oct 16 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.10.beta3
acdedc
- fix use of freed memory if SSL_CTX_free() is called before
acdedc
  SSL_free() (#521342)
acdedc
acdedc
* Thu Oct  8 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.9.beta3
acdedc
- fix typo in DTLS1 code (#527015)
acdedc
- fix leak in error handling of d2i_SSL_SESSION()
acdedc
acdedc
* Wed Sep 30 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.8.beta3
acdedc
- fix RSA and DSA FIPS selftests
acdedc
- reenable fixed x86_64 camellia assembler code (#521127)
acdedc
acdedc
* Fri Sep  4 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.7.beta3
acdedc
- temporarily disable x86_64 camellia assembler code (#521127)
acdedc
acdedc
* Mon Aug 31 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.6.beta3
acdedc
- fix openssl dgst -dss1 (#520152)
acdedc
acdedc
* Wed Aug 26 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.5.beta3
acdedc
- drop the compat symlink hacks
acdedc
acdedc
* Sat Aug 22 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.4.beta3
acdedc
- constify SSL_CIPHER_description()
acdedc
acdedc
* Fri Aug 21 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.3.beta3
acdedc
- fix WWW:Curl:Easy reference in tsget
acdedc
acdedc
* Fri Aug 21 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.2.beta3
acdedc
- enable MD-2
acdedc
acdedc
* Thu Aug 20 2009 Tomas Mraz <tmraz@redhat.com> 1.0.0-0.1.beta3
acdedc
- update to new major upstream release
acdedc
acdedc
* Sat Jul 25 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.9.8k-7
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild
acdedc
acdedc
* Wed Jul 22 2009 Bill Nottingham <notting@redhat.com>
acdedc
- do not build special 'optimized' versions for i686, as that's the base
acdedc
  arch in Fedora now
acdedc
acdedc
* Tue Jun 30 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8k-6
acdedc
- abort if selftests failed and random number generator is polled
acdedc
- mention EVP_aes and EVP_sha2xx routines in the manpages
acdedc
- add README.FIPS
acdedc
- make CA dir absolute path (#445344)
acdedc
- change default length for RSA key generation to 2048 (#484101)
acdedc
acdedc
* Thu May 21 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8k-5
acdedc
- fix CVE-2009-1377 CVE-2009-1378 CVE-2009-1379
acdedc
  (DTLS DoS problems) (#501253, #501254, #501572)
acdedc
acdedc
* Tue Apr 21 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8k-4
acdedc
- support compatibility DTLS mode for CISCO AnyConnect (#464629)
acdedc
acdedc
* Fri Apr 17 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8k-3
acdedc
- correct the SHLIB_VERSION define
acdedc
acdedc
* Wed Apr 15 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8k-2
acdedc
- add support for multiple CRLs with same subject
acdedc
- load only dynamic engine support in FIPS mode
acdedc
acdedc
* Wed Mar 25 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8k-1
acdedc
- update to new upstream release (minor bug fixes, security
acdedc
  fixes and machine code optimizations only)
acdedc
acdedc
* Thu Mar 19 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-10
acdedc
- move libraries to /usr/lib (#239375)
acdedc
acdedc
* Fri Mar 13 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-9
acdedc
- add a static subpackage
acdedc
acdedc
* Thu Feb 26 2009 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 0.9.8j-8
acdedc
- Rebuilt for https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild
acdedc
acdedc
* Mon Feb  2 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-7
acdedc
- must also verify checksum of libssl.so in the FIPS mode
acdedc
- obtain the seed for FIPS rng directly from the kernel device
acdedc
- drop the temporary symlinks
acdedc
acdedc
* Mon Jan 26 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-6
acdedc
- drop the temporary triggerpostun and symlinking in post
acdedc
- fix the pkgconfig files and drop the unnecessary buildrequires
acdedc
  on pkgconfig as it is a rpmbuild dependency (#481419)
acdedc
acdedc
* Sat Jan 17 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-5
acdedc
- add temporary triggerpostun to reinstate the symlinks
acdedc
acdedc
* Sat Jan 17 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-4
acdedc
- no pairwise key tests in non-fips mode (#479817)
acdedc
acdedc
* Fri Jan 16 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-3
acdedc
- even more robust test for the temporary symlinks
acdedc
acdedc
* Fri Jan 16 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-2
acdedc
- try to ensure the temporary symlinks exist
acdedc
acdedc
* Thu Jan 15 2009 Tomas Mraz <tmraz@redhat.com> 0.9.8j-1
acdedc
- new upstream version with necessary soname bump (#455753)
acdedc
- temporarily provide symlink to old soname to make it possible to rebuild
acdedc
  the dependent packages in rawhide
acdedc
- add eap-fast support (#428181)
acdedc
- add possibility to disable zlib by setting
acdedc
- add fips mode support for testing purposes
acdedc
- do not null dereference on some invalid smime files
acdedc
- add buildrequires pkgconfig (#479493)
acdedc
acdedc
* Sun Aug 10 2008 Tomas Mraz <tmraz@redhat.com> 0.9.8g-11
acdedc
- do not add tls extensions to server hello for SSLv3 either
acdedc
acdedc
* Mon Jun  2 2008 Joe Orton <jorton@redhat.com> 0.9.8g-10
acdedc
- move root CA bundle to ca-certificates package
acdedc
acdedc
* Wed May 28 2008 Tomas Mraz <tmraz@redhat.com> 0.9.8g-9
acdedc
- fix CVE-2008-0891 - server name extension crash (#448492)
acdedc
- fix CVE-2008-1672 - server key exchange message omit crash (#448495)
acdedc
acdedc
* Tue May 27 2008 Tomas Mraz <tmraz@redhat.com> 0.9.8g-8
acdedc
- super-H arch support
acdedc
- drop workaround for bug 199604 as it should be fixed in gcc-4.3
acdedc
acdedc
* Mon May 19 2008 Tom "spot" Callaway <tcallawa@redhat.com> 0.9.8g-7
acdedc
- sparc handling
acdedc
acdedc
* Mon Mar 10 2008 Joe Orton <jorton@redhat.com> 0.9.8g-6
acdedc
- update to new root CA bundle from mozilla.org (r1.45)
acdedc
acdedc
* Wed Feb 20 2008 Fedora Release Engineering <rel-eng@fedoraproject.org> - 0.9.8g-5
acdedc
- Autorebuild for GCC 4.3
acdedc
acdedc
* Thu Jan 24 2008 Tomas Mraz <tmraz@redhat.com> 0.9.8g-4
acdedc
- merge review fixes (#226220)
acdedc
- adjust the SHLIB_VERSION_NUMBER to reflect library name (#429846)
acdedc
acdedc
* Thu Dec 13 2007 Tomas Mraz <tmraz@redhat.com> 0.9.8g-3
acdedc
- set default paths when no explicit paths are set (#418771)
acdedc
- do not add tls extensions to client hello for SSLv3 (#422081)
acdedc
acdedc
* Tue Dec  4 2007 Tomas Mraz <tmraz@redhat.com> 0.9.8g-2
acdedc
- enable some new crypto algorithms and features
acdedc
- add some more important bug fixes from openssl CVS
acdedc
acdedc
* Mon Dec  3 2007 Tomas Mraz <tmraz@redhat.com> 0.9.8g-1
acdedc
- update to latest upstream release, SONAME bumped to 7
acdedc
acdedc
* Mon Oct 15 2007 Joe Orton <jorton@redhat.com> 0.9.8b-17
acdedc
- update to new CA bundle from mozilla.org
acdedc
acdedc
* Fri Oct 12 2007 Tomas Mraz <tmraz@redhat.com> 0.9.8b-16
acdedc
- fix CVE-2007-5135 - off-by-one in SSL_get_shared_ciphers (#309801)
acdedc
- fix CVE-2007-4995 - out of order DTLS fragments buffer overflow (#321191)
acdedc
- add alpha sub-archs (#296031)
acdedc
acdedc
* Tue Aug 21 2007 Tomas Mraz <tmraz@redhat.com> 0.9.8b-15
acdedc
- rebuild
acdedc
acdedc
* Fri Aug  3 2007 Tomas Mraz <tmraz@redhat.com> 0.9.8b-14
acdedc
- use localhost in testsuite, hopefully fixes slow build in koji
acdedc
- CVE-2007-3108 - fix side channel attack on private keys (#250577)
acdedc
- make ssl session cache id matching strict (#233599)
acdedc
acdedc
* Wed Jul 25 2007 Tomas Mraz <tmraz@redhat.com> 0.9.8b-13
acdedc
- allow building on ARM architectures (#245417)
acdedc
- use reference timestamps to prevent multilib conflicts (#218064)
acdedc
- -devel package must require pkgconfig (#241031)
acdedc
acdedc
* Mon Dec 11 2006 Tomas Mraz <tmraz@redhat.com> 0.9.8b-12
acdedc
- detect duplicates in add_dir properly (#206346)
acdedc
acdedc
* Thu Nov 30 2006 Tomas Mraz <tmraz@redhat.com> 0.9.8b-11
acdedc
- the previous change still didn't make X509_NAME_cmp transitive
acdedc
acdedc
* Thu Nov 23 2006 Tomas Mraz <tmraz@redhat.com> 0.9.8b-10
acdedc
- make X509_NAME_cmp transitive otherwise certificate lookup
acdedc
  is broken (#216050)
acdedc
acdedc
* Thu Nov  2 2006 Tomas Mraz <tmraz@redhat.com> 0.9.8b-9
acdedc
- aliasing bug in engine loading, patch by IBM (#213216)
acdedc
acdedc
* Mon Oct  2 2006 Tomas Mraz <tmraz@redhat.com> 0.9.8b-8
acdedc
- CVE-2006-2940 fix was incorrect (#208744)
acdedc
acdedc
* Mon Sep 25 2006 Tomas Mraz <tmraz@redhat.com> 0.9.8b-7
acdedc
- fix CVE-2006-2937 - mishandled error on ASN.1 parsing (#207276)
acdedc
- fix CVE-2006-2940 - parasitic public keys DoS (#207274)
acdedc
- fix CVE-2006-3738 - buffer overflow in SSL_get_shared_ciphers (#206940)
acdedc
- fix CVE-2006-4343 - sslv2 client DoS (#206940)
acdedc
acdedc
* Tue Sep  5 2006 Tomas Mraz <tmraz@redhat.com> 0.9.8b-6
acdedc
- fix CVE-2006-4339 - prevent attack on PKCS#1 v1.5 signatures (#205180)
acdedc
acdedc
* Wed Aug  2 2006 Tomas Mraz <tmraz@redhat.com> - 0.9.8b-5
acdedc
- set buffering to none on stdio/stdout FILE when bufsize is set (#200580)
acdedc
  patch by IBM
acdedc
acdedc
* Fri Jul 28 2006 Alexandre Oliva <aoliva@redhat.com> - 0.9.8b-4.1
acdedc
- rebuild with new binutils (#200330)
acdedc
acdedc
* Fri Jul 21 2006 Tomas Mraz <tmraz@redhat.com> - 0.9.8b-4
acdedc
- add a temporary workaround for sha512 test failure on s390 (#199604)
acdedc
acdedc
* Thu Jul 20 2006 Tomas Mraz <tmraz@redhat.com>
acdedc
- add ipv6 support to s_client and s_server (by Jan Pazdziora) (#198737)
acdedc
- add patches for BN threadsafety, AES cache collision attack hazard fix and
acdedc
  pkcs7 code memleak fix from upstream CVS
acdedc
acdedc
* Wed Jul 12 2006 Jesse Keating <jkeating@redhat.com> - 0.9.8b-3.1
acdedc
- rebuild
acdedc
acdedc
* Wed Jun 21 2006 Tomas Mraz <tmraz@redhat.com> - 0.9.8b-3
acdedc
- dropped libica and ica engine from build
acdedc
acdedc
* Wed Jun 21 2006 Joe Orton <jorton@redhat.com>
acdedc
- update to new CA bundle from mozilla.org; adds CA certificates
acdedc
  from netlock.hu and startcom.org
acdedc
acdedc
* Mon Jun  5 2006 Tomas Mraz <tmraz@redhat.com> - 0.9.8b-2
acdedc
- fixed a few rpmlint warnings
acdedc
- better fix for #173399 from upstream
acdedc
- upstream fix for pkcs12
acdedc
acdedc
* Thu May 11 2006 Tomas Mraz <tmraz@redhat.com> - 0.9.8b-1
acdedc
- upgrade to new version, stays ABI compatible
acdedc
- there is no more linux/config.h (it was empty anyway)
acdedc
acdedc
* Tue Apr  4 2006 Tomas Mraz <tmraz@redhat.com> - 0.9.8a-6
acdedc
- fix stale open handles in libica (#177155)
acdedc
- fix build if 'rand' or 'passwd' in buildroot path (#178782)
acdedc
- initialize VIA Padlock engine (#186857)
acdedc
acdedc
* Fri Feb 10 2006 Jesse Keating <jkeating@redhat.com> - 0.9.8a-5.2
acdedc
- bump again for double-long bug on ppc(64)
acdedc
acdedc
* Tue Feb 07 2006 Jesse Keating <jkeating@redhat.com> - 0.9.8a-5.1
acdedc
- rebuilt for new gcc4.1 snapshot and glibc changes
acdedc
acdedc
* Thu Dec 15 2005 Tomas Mraz <tmraz@redhat.com> 0.9.8a-5
acdedc
- don't include SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG
acdedc
  in SSL_OP_ALL (#175779)
acdedc
acdedc
* Fri Dec 09 2005 Jesse Keating <jkeating@redhat.com>
acdedc
- rebuilt
acdedc
acdedc
* Tue Nov 29 2005 Tomas Mraz <tmraz@redhat.com> 0.9.8a-4
acdedc
- fix build (-lcrypto was erroneusly dropped) of the updated libica
acdedc
- updated ICA engine to 1.3.6-rc3
acdedc
acdedc
* Tue Nov 22 2005 Tomas Mraz <tmraz@redhat.com> 0.9.8a-3
acdedc
- disable builtin compression methods for now until they work
acdedc
  properly (#173399)
acdedc
acdedc
* Wed Nov 16 2005 Tomas Mraz <tmraz@redhat.com> 0.9.8a-2
acdedc
- don't set -rpath for openssl binary
acdedc
acdedc
* Tue Nov  8 2005 Tomas Mraz <tmraz@redhat.com> 0.9.8a-1
acdedc
- new upstream version
acdedc
- patches partially renumbered
acdedc
acdedc
* Fri Oct 21 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-11
acdedc
- updated IBM ICA engine library and patch to latest upstream version
acdedc
acdedc
* Wed Oct 12 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-10
acdedc
- fix CAN-2005-2969 - remove SSL_OP_MSIE_SSLV2_RSA_PADDING which
acdedc
  disables the countermeasure against man in the middle attack in SSLv2
acdedc
  (#169863)
acdedc
- use sha1 as default for CA and cert requests - CAN-2005-2946 (#169803)
acdedc
acdedc
* Tue Aug 23 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-9
acdedc
- add *.so.soversion as symlinks in /lib (#165264)
acdedc
- remove unpackaged symlinks (#159595)
acdedc
- fixes from upstream (constant time fixes for DSA,
acdedc
  bn assembler div on ppc arch, initialize memory on realloc)
acdedc
acdedc
* Thu Aug 11 2005 Phil Knirsch <pknirsch@redhat.com> 0.9.7f-8
acdedc
- Updated ICA engine IBM patch to latest upstream version.
acdedc
acdedc
* Thu May 19 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-7
acdedc
- fix CAN-2005-0109 - use constant time/memory access mod_exp
acdedc
  so bits of private key aren't leaked by cache eviction (#157631)
acdedc
- a few more fixes from upstream 0.9.7g
acdedc
acdedc
* Wed Apr 27 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-6
acdedc
- use poll instead of select in rand (#128285)
acdedc
- fix Makefile.certificate to point to /etc/pki/tls
acdedc
- change the default string mask in ASN1 to PrintableString+UTF8String
acdedc
acdedc
* Mon Apr 25 2005 Joe Orton <jorton@redhat.com> 0.9.7f-5
acdedc
- update to revision 1.37 of Mozilla CA bundle
acdedc
acdedc
* Thu Apr 21 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-4
acdedc
- move certificates to _sysconfdir/pki/tls (#143392)
acdedc
- move CA directories to _sysconfdir/pki/CA
acdedc
- patch the CA script and the default config so it points to the
acdedc
  CA directories
acdedc
acdedc
* Fri Apr  1 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-3
acdedc
- uninitialized variable mustn't be used as input in inline
acdedc
  assembly
acdedc
- reenable the x86_64 assembly again
acdedc
acdedc
* Thu Mar 31 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-2
acdedc
- add back RC4_CHAR on ia64 and x86_64 so the ABI isn't broken
acdedc
- disable broken bignum assembly on x86_64
acdedc
acdedc
* Wed Mar 30 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7f-1
acdedc
- reenable optimizations on ppc64 and assembly code on ia64
acdedc
- upgrade to new upstream version (no soname bump needed)
acdedc
- disable thread test - it was testing the backport of the
acdedc
  RSA blinding - no longer needed
acdedc
- added support for changing serial number to
acdedc
  Makefile.certificate (#151188)
acdedc
- make ca-bundle.crt a config file (#118903)
acdedc
acdedc
* Tue Mar  1 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7e-3
acdedc
- libcrypto shouldn't depend on libkrb5 (#135961)
acdedc
acdedc
* Mon Feb 28 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7e-2
acdedc
- rebuild
acdedc
acdedc
* Mon Feb 28 2005 Tomas Mraz <tmraz@redhat.com> 0.9.7e-1
acdedc
- new upstream source, updated patches
acdedc
- added patch so we are hopefully ABI compatible with upcoming
acdedc
  0.9.7f
acdedc
acdedc
* Thu Feb 10 2005 Tomas Mraz <tmraz@redhat.com>
acdedc
- Support UTF-8 charset in the Makefile.certificate (#134944)
acdedc
- Added cmp to BuildPrereq
acdedc
acdedc
* Thu Jan 27 2005 Joe Orton <jorton@redhat.com> 0.9.7a-46
acdedc
- generate new ca-bundle.crt from Mozilla certdata.txt (revision 1.32)
acdedc
acdedc
* Thu Dec 23 2004 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-45
acdedc
- Fixed and updated libica-1.3.4-urandom.patch patch (#122967)
acdedc
acdedc
* Fri Nov 19 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-44
acdedc
- rebuild
acdedc
acdedc
* Fri Nov 19 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-43
acdedc
- rebuild
acdedc
acdedc
* Fri Nov 19 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-42
acdedc
- rebuild
acdedc
acdedc
* Fri Nov 19 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-41
acdedc
- remove der_chop, as upstream cvs has done (CAN-2004-0975, #140040)
acdedc
acdedc
* Tue Oct 05 2004 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-40
acdedc
- Include latest libica version with important bugfixes
acdedc
acdedc
* Tue Jun 15 2004 Elliot Lee <sopwith@redhat.com>
acdedc
- rebuilt
acdedc
acdedc
* Mon Jun 14 2004 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-38
acdedc
- Updated ICA engine IBM patch to latest upstream version.
acdedc
acdedc
* Mon Jun  7 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-37
acdedc
- build for linux-alpha-gcc instead of alpha-gcc on alpha (Jeff Garzik)
acdedc
acdedc
* Tue May 25 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-36
acdedc
- handle %%{_arch}=i486/i586/i686/athlon cases in the intermediate
acdedc
  header (#124303)
acdedc
acdedc
* Thu Mar 25 2004 Joe Orton <jorton@redhat.com> 0.9.7a-35
acdedc
- add security fixes for CAN-2004-0079, CAN-2004-0112
acdedc
acdedc
* Tue Mar 16 2004 Phil Knirsch <pknirsch@redhat.com>
acdedc
- Fixed libica filespec.
acdedc
acdedc
* Thu Mar 11 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-34
acdedc
- ppc/ppc64 define __powerpc__/__powerpc64__, not __ppc__/__ppc64__, fix
acdedc
  the intermediate header
acdedc
acdedc
* Wed Mar 10 2004 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-33
acdedc
- add an intermediate <openssl/opensslconf.h> which points to the right
acdedc
  arch-specific opensslconf.h on multilib arches
acdedc
acdedc
* Tue Mar 02 2004 Elliot Lee <sopwith@redhat.com>
acdedc
- rebuilt
acdedc
acdedc
* Thu Feb 26 2004 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-32
acdedc
- Updated libica to latest upstream version 1.3.5.
acdedc
acdedc
* Tue Feb 17 2004 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-31
acdedc
- Update ICA crypto engine patch from IBM to latest version.
acdedc
acdedc
* Fri Feb 13 2004 Elliot Lee <sopwith@redhat.com>
acdedc
- rebuilt
acdedc
acdedc
* Fri Feb 13 2004 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-29
acdedc
- rebuilt
acdedc
acdedc
* Wed Feb 11 2004 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-28
acdedc
- Fixed libica build.
acdedc
acdedc
* Wed Feb  4 2004 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add "-ldl" to link flags added for Linux-on-ARM (#99313)
acdedc
acdedc
* Wed Feb  4 2004 Joe Orton <jorton@redhat.com> 0.9.7a-27
acdedc
- updated ca-bundle.crt: removed expired GeoTrust roots, added
acdedc
  freessl.com root, removed trustcenter.de Class 0 root
acdedc
acdedc
* Sun Nov 30 2003 Tim Waugh <twaugh@redhat.com> 0.9.7a-26
acdedc
- Fix link line for libssl (bug #111154).
acdedc
acdedc
* Fri Oct 24 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-25
acdedc
- add dependency on zlib-devel for the -devel package, which depends on zlib
acdedc
  symbols because we enable zlib for libssl (#102962)
acdedc
acdedc
* Fri Oct 24 2003 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-24
acdedc
- Use /dev/urandom instead of PRNG for libica.
acdedc
- Apply libica-1.3.5 fix for /dev/urandom in icalinux.c
acdedc
- Use latest ICA engine patch from IBM.
acdedc
acdedc
* Sat Oct  4 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-22.1
acdedc
- rebuild
acdedc
acdedc
* Wed Oct  1 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-22
acdedc
- rebuild (22 wasn't actually built, fun eh?)
acdedc
acdedc
* Tue Sep 30 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-23
acdedc
- re-disable optimizations on ppc64
acdedc
acdedc
* Tue Sep 30 2003 Joe Orton <jorton@redhat.com>
acdedc
- add a_mbstr.c fix for 64-bit platforms from CVS
acdedc
acdedc
* Tue Sep 30 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-22
acdedc
- add -Wa,--noexecstack to RPM_OPT_FLAGS so that assembled modules get tagged
acdedc
  as not needing executable stacks
acdedc
acdedc
* Mon Sep 29 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-21
acdedc
- rebuild
acdedc
acdedc
* Thu Sep 25 2003 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- re-enable optimizations on ppc64
acdedc
acdedc
* Thu Sep 25 2003 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- remove exclusivearch
acdedc
acdedc
* Wed Sep 24 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-20
acdedc
- only parse a client cert if one was requested
acdedc
- temporarily exclusivearch for %%{ix86}
acdedc
acdedc
* Tue Sep 23 2003 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add security fixes for protocol parsing bugs (CAN-2003-0543, CAN-2003-0544)
acdedc
  and heap corruption (CAN-2003-0545)
acdedc
- update RHNS-CA-CERT files
acdedc
- ease back on the number of threads used in the threading test
acdedc
acdedc
* Wed Sep 17 2003 Matt Wilson <msw@redhat.com> 0.9.7a-19
acdedc
- rebuild to fix gzipped file md5sums (#91211)
acdedc
acdedc
* Mon Aug 25 2003 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-18
acdedc
- Updated libica to version 1.3.4.
acdedc
acdedc
* Thu Jul 17 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-17
acdedc
- rebuild
acdedc
acdedc
* Tue Jul 15 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-10.9
acdedc
- free the kssl_ctx structure when we free an SSL structure (#99066)
acdedc
acdedc
* Fri Jul 11 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-16
acdedc
- rebuild
acdedc
acdedc
* Thu Jul 10 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-15
acdedc
- lower thread test count on s390x
acdedc
acdedc
* Tue Jul  8 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-14
acdedc
- rebuild
acdedc
acdedc
* Thu Jun 26 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-13
acdedc
- disable assembly on arches where it seems to conflict with threading
acdedc
acdedc
* Thu Jun 26 2003 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-12
acdedc
- Updated libica to latest upstream version 1.3.0
acdedc
acdedc
* Wed Jun 11 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-9.9
acdedc
- rebuild
acdedc
acdedc
* Wed Jun 11 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-11
acdedc
- rebuild
acdedc
acdedc
* Tue Jun 10 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-10
acdedc
- ubsec: don't stomp on output data which might also be input data
acdedc
acdedc
* Tue Jun 10 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-9
acdedc
- temporarily disable optimizations on ppc64
acdedc
acdedc
* Mon Jun  9 2003 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- backport fix for engine-used-for-everything from 0.9.7b
acdedc
- backport fix for prng not being seeded causing problems, also from 0.9.7b
acdedc
- add a check at build-time to ensure that RSA is thread-safe
acdedc
- keep perlpath from stomping on the libica configure scripts
acdedc
acdedc
* Fri Jun  6 2003 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- thread-safety fix for RSA blinding
acdedc
acdedc
* Wed Jun 04 2003 Elliot Lee <sopwith@redhat.com> 0.9.7a-8
acdedc
- rebuilt
acdedc
acdedc
* Fri May 30 2003 Phil Knirsch <pknirsch@redhat.com> 0.9.7a-7
acdedc
- Added libica-1.2 to openssl (featurerequest).
acdedc
acdedc
* Wed Apr 16 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-6
acdedc
- fix building with incorrect flags on ppc64
acdedc
acdedc
* Wed Mar 19 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-5
acdedc
- add patch to harden against Klima-Pokorny-Rosa extension of Bleichenbacher's
acdedc
  attack (CAN-2003-0131)
acdedc
acdedc
* Mon Mar 17 2003 Nalin Dahyabhai <nalin@redhat.com>  0.9.7a-4
acdedc
- add patch to enable RSA blinding by default, closing a timing attack
acdedc
  (CAN-2003-0147)
acdedc
acdedc
* Wed Mar  5 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-3
acdedc
- disable use of BN assembly module on x86_64, but continue to allow inline
acdedc
  assembly (#83403)
acdedc
acdedc
* Thu Feb 27 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-2
acdedc
- disable EC algorithms
acdedc
acdedc
* Wed Feb 19 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7a-1
acdedc
- update to 0.9.7a
acdedc
acdedc
* Wed Feb 19 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7-8
acdedc
- add fix to guard against attempts to allocate negative amounts of memory
acdedc
- add patch for CAN-2003-0078, fixing a timing attack
acdedc
acdedc
* Thu Feb 13 2003 Elliot Lee <sopwith@redhat.com> 0.9.7-7
acdedc
- Add openssl-ppc64.patch
acdedc
acdedc
* Mon Feb 10 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7-6
acdedc
- EVP_DecryptInit should call EVP_CipherInit() instead of EVP_CipherInit_ex(),
acdedc
  to get the right behavior when passed uninitialized context structures
acdedc
  (#83766)
acdedc
- build with -mcpu=ev5 on alpha family (#83828)
acdedc
acdedc
* Wed Jan 22 2003 Tim Powers <timp@redhat.com>
acdedc
- rebuilt
acdedc
acdedc
* Fri Jan 17 2003 Phil Knirsch <pknirsch@redhat.com> 0.9.7-4
acdedc
- Added IBM hw crypto support patch.
acdedc
acdedc
* Wed Jan 15 2003 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add missing builddep on sed
acdedc
acdedc
* Thu Jan  9 2003 Bill Nottingham <notting@redhat.com> 0.9.7-3
acdedc
- debloat
acdedc
- fix broken manpage symlinks
acdedc
acdedc
* Wed Jan  8 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7-2
acdedc
- fix double-free in 'openssl ca'
acdedc
acdedc
* Fri Jan  3 2003 Nalin Dahyabhai <nalin@redhat.com> 0.9.7-1
acdedc
- update to 0.9.7 final
acdedc
acdedc
* Tue Dec 17 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.7-0
acdedc
- update to 0.9.7 beta6 (DO NOT USE UNTIL UPDATED TO FINAL 0.9.7)
acdedc
acdedc
* Wed Dec 11 2002 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- update to 0.9.7 beta5 (DO NOT USE UNTIL UPDATED TO FINAL 0.9.7)
acdedc
acdedc
* Tue Oct 22 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-30
acdedc
- add configuration stanza for x86_64 and use it on x86_64
acdedc
- build for linux-ppc on ppc
acdedc
- start running the self-tests again
acdedc
acdedc
* Wed Oct 02 2002 Elliot Lee <sopwith@redhat.com> 0.9.6b-29hammer.3
acdedc
- Merge fixes from previous hammer packages, including general x86-64 and
acdedc
  multilib
acdedc
acdedc
* Tue Aug  6 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-29
acdedc
- rebuild
acdedc
acdedc
* Thu Aug  1 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-28
acdedc
- update asn patch to fix accidental reversal of a logic check
acdedc
acdedc
* Wed Jul 31 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-27
acdedc
- update asn patch to reduce chance that compiler optimization will remove
acdedc
  one of the added tests
acdedc
acdedc
* Wed Jul 31 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-26
acdedc
- rebuild
acdedc
acdedc
* Mon Jul 29 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-25
acdedc
- add patch to fix ASN.1 vulnerabilities
acdedc
acdedc
* Thu Jul 25 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-24
acdedc
- add backport of Ben Laurie's patches for OpenSSL 0.9.6d
acdedc
acdedc
* Wed Jul 17 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-23
acdedc
- own {_datadir}/ssl/misc
acdedc
acdedc
* Fri Jun 21 2002 Tim Powers <timp@redhat.com>
acdedc
- automated rebuild
acdedc
acdedc
* Sun May 26 2002 Tim Powers <timp@redhat.com>
acdedc
- automated rebuild
acdedc
acdedc
* Fri May 17 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-20
acdedc
- free ride through the build system (whee!)
acdedc
acdedc
* Thu May 16 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-19
acdedc
- rebuild in new environment
acdedc
acdedc
* Thu Apr  4 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-17, 0.9.6b-18
acdedc
- merge RHL-specific bits into stronghold package, rename
acdedc
acdedc
* Tue Apr 02 2002 Gary Benson <gbenson@redhat.com> stronghold-0.9.6c-2
acdedc
- add support for Chrysalis Luna token
acdedc
acdedc
* Tue Mar 26 2002 Gary Benson <gbenson@redhat.com>
acdedc
- disable AEP random number generation, other AEP fixes
acdedc
acdedc
* Fri Mar 15 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-15
acdedc
- only build subpackages on primary arches
acdedc
acdedc
* Thu Mar 14 2002 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-13
acdedc
- on ia32, only disable use of assembler on i386
acdedc
- enable assembly on ia64
acdedc
acdedc
* Mon Jan  7 2002 Florian La Roche <Florian.LaRoche@redhat.de> 0.9.6b-11
acdedc
- fix sparcv9 entry
acdedc
acdedc
* Mon Jan  7 2002 Gary Benson <gbenson@redhat.com> stronghold-0.9.6c-1
acdedc
- upgrade to 0.9.6c
acdedc
- bump BuildArch to i686 and enable assembler on all platforms
acdedc
- synchronise with shrimpy and rawhide
acdedc
- bump soversion to 3
acdedc
acdedc
* Wed Oct 10 2001 Florian La Roche <Florian.LaRoche@redhat.de>
acdedc
- delete BN_LLONG for s390x, patch from Oliver Paukstadt
acdedc
acdedc
* Mon Sep 17 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-9
acdedc
- update AEP driver patch
acdedc
acdedc
* Mon Sep 10 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- adjust RNG disabling patch to match version of patch from Broadcom
acdedc
acdedc
* Fri Sep  7 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-8
acdedc
- disable the RNG in the ubsec engine driver
acdedc
acdedc
* Tue Aug 28 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-7
acdedc
- tweaks to the ubsec engine driver
acdedc
acdedc
* Fri Aug 24 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-6
acdedc
- tweaks to the ubsec engine driver
acdedc
acdedc
* Thu Aug 23 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-5
acdedc
- update ubsec engine driver from Broadcom
acdedc
acdedc
* Fri Aug 10 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-4
acdedc
- move man pages back to %%{_mandir}/man?/foo.?ssl from
acdedc
  %%{_mandir}/man?ssl/foo.?
acdedc
- add an [ engine ] section to the default configuration file
acdedc
acdedc
* Thu Aug  9 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add a patch for selecting a default engine in SSL_library_init()
acdedc
acdedc
* Mon Jul 23 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-3
acdedc
- add patches for AEP hardware support
acdedc
- add patch to keep trying when we fail to load a cert from a file and
acdedc
  there are more in the file
acdedc
- add missing prototype for ENGINE_ubsec() in engine_int.h
acdedc
acdedc
* Wed Jul 18 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-2
acdedc
- actually add hw_ubsec to the engine list
acdedc
acdedc
* Tue Jul 17 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add in the hw_ubsec driver from CVS
acdedc
acdedc
* Wed Jul 11 2001 Nalin Dahyabhai <nalin@redhat.com> 0.9.6b-1
acdedc
- update to 0.9.6b
acdedc
acdedc
* Thu Jul  5 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- move .so symlinks back to %%{_libdir}
acdedc
acdedc
* Tue Jul  3 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- move shared libraries to /lib (#38410)
acdedc
acdedc
* Mon Jun 25 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- switch to engine code base
acdedc
acdedc
* Mon Jun 18 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add a script for creating dummy certificates
acdedc
- move man pages from %%{_mandir}/man?/foo.?ssl to %%{_mandir}/man?ssl/foo.?
acdedc
acdedc
* Thu Jun 07 2001 Florian La Roche <Florian.LaRoche@redhat.de>
acdedc
- add s390x support
acdedc
acdedc
* Fri Jun  1 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- change two memcpy() calls to memmove()
acdedc
- don't define L_ENDIAN on alpha
acdedc
acdedc
* Wed May 23 2001 Joe Orton <jorton@redhat.com> stronghold-0.9.6a-1
acdedc
- Add 'stronghold-' prefix to package names.
acdedc
- Obsolete standard openssl packages.
acdedc
acdedc
* Wed May 16 2001 Joe Orton <jorton@redhat.com>
acdedc
- Add BuildArch: i586 as per Nalin's advice.
acdedc
acdedc
* Tue May 15 2001 Joe Orton <jorton@redhat.com>
acdedc
- Enable assembler on ix86 (using new .tar.bz2 which does
acdedc
  include the asm directories).
acdedc
acdedc
* Tue May 15 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- make subpackages depend on the main package
acdedc
acdedc
* Tue May  1 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- adjust the hobble script to not disturb symlinks in include/ (fix from
acdedc
  Joe Orton)
acdedc
acdedc
* Fri Apr 27 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- drop the m2crypo patch we weren't using
acdedc
acdedc
* Tue Apr 24 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- configure using "shared" as well
acdedc
acdedc
* Sun Apr  8 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- update to 0.9.6a
acdedc
- use the build-shared target to build shared libraries
acdedc
- bump the soversion to 2 because we're no longer compatible with
acdedc
  our 0.9.5a packages or our 0.9.6 packages
acdedc
- drop the patch for making rsatest a no-op when rsa null support is used
acdedc
- put all man pages into <section>ssl instead of <section>
acdedc
- break the m2crypto modules into a separate package
acdedc
acdedc
* Tue Mar 13 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- use BN_LLONG on s390
acdedc
acdedc
* Mon Mar 12 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- fix the s390 changes for 0.9.6 (isn't supposed to be marked as 64-bit)
acdedc
acdedc
* Sat Mar  3 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- move c_rehash to the perl subpackage, because it's a perl script now
acdedc
acdedc
* Fri Mar  2 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- update to 0.9.6
acdedc
- enable MD2
acdedc
- use the libcrypto.so and libssl.so targets to build shared libs with
acdedc
- bump the soversion to 1 because we're no longer compatible with any of
acdedc
  the various 0.9.5a packages circulating around, which provide lib*.so.0
acdedc
acdedc
* Wed Feb 28 2001 Florian La Roche <Florian.LaRoche@redhat.de>
acdedc
- change hobble-openssl for disabling MD2 again
acdedc
acdedc
* Tue Feb 27 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- re-disable MD2 -- the EVP_MD_CTX structure would grow from 100 to 152
acdedc
  bytes or so, causing EVP_DigestInit() to zero out stack variables in
acdedc
  apps built against a version of the library without it
acdedc
acdedc
* Mon Feb 26 2001 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- disable some inline assembly, which on x86 is Pentium-specific
acdedc
- re-enable MD2 (see http://www.ietf.org/ietf/IPR/RSA-MD-all)
acdedc
acdedc
* Thu Feb 08 2001 Florian La Roche <Florian.LaRoche@redhat.de>
acdedc
- fix s390 patch
acdedc
acdedc
* Fri Dec 8 2000 Than Ngo <than@redhat.com>
acdedc
- added support s390
acdedc
acdedc
* Mon Nov 20 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- remove -Wa,* and -m* compiler flags from the default Configure file (#20656)
acdedc
- add the CA.pl man page to the perl subpackage
acdedc
acdedc
* Thu Nov  2 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- always build with -mcpu=ev5 on alpha
acdedc
acdedc
* Tue Oct 31 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add a symlink from cert.pem to ca-bundle.crt
acdedc
acdedc
* Wed Oct 25 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add a ca-bundle file for packages like Samba to reference for CA certificates
acdedc
acdedc
* Tue Oct 24 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- remove libcrypto's crypt(), which doesn't handle md5crypt (#19295)
acdedc
acdedc
* Mon Oct  2 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add unzip as a buildprereq (#17662)
acdedc
- update m2crypto to 0.05-snap4
acdedc
acdedc
* Tue Sep 26 2000 Bill Nottingham <notting@redhat.com>
acdedc
- fix some issues in building when it's not installed
acdedc
acdedc
* Wed Sep  6 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- make sure the headers we include are the ones we built with (aaaaarrgh!)
acdedc
acdedc
* Fri Sep  1 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- add Richard Henderson's patch for BN on ia64
acdedc
- clean up the changelog
acdedc
acdedc
* Tue Aug 29 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- fix the building of python modules without openssl-devel already installed
acdedc
acdedc
* Wed Aug 23 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- byte-compile python extensions without the build-root
acdedc
- adjust the makefile to not remove temporary files (like .key files when
acdedc
  building .csr files) by marking them as .PRECIOUS
acdedc
acdedc
* Sat Aug 19 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- break out python extensions into a subpackage
acdedc
acdedc
* Mon Jul 17 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- tweak the makefile some more
acdedc
acdedc
* Tue Jul 11 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- disable MD2 support
acdedc
acdedc
* Thu Jul  6 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- disable MDC2 support
acdedc
acdedc
* Sun Jul  2 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- tweak the disabling of RC5, IDEA support
acdedc
- tweak the makefile
acdedc
acdedc
* Thu Jun 29 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- strip binaries and libraries
acdedc
- rework certificate makefile to have the right parts for Apache
acdedc
acdedc
* Wed Jun 28 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- use %%{_perl} instead of /usr/bin/perl
acdedc
- disable alpha until it passes its own test suite
acdedc
acdedc
* Fri Jun  9 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- move the passwd.1 man page out of the passwd package's way
acdedc
acdedc
* Fri Jun  2 2000 Nalin Dahyabhai <nalin@redhat.com>
acdedc
- update to 0.9.5a, modified for U.S.
acdedc
- add perl as a build-time requirement
acdedc
- move certificate makefile to another package
acdedc
- disable RC5, IDEA, RSA support
acdedc
- remove optimizations for now
acdedc
acdedc
* Wed Mar  1 2000 Florian La Roche <Florian.LaRoche@redhat.de>
acdedc
- Bero told me to move the Makefile into this package
acdedc
acdedc
* Wed Mar  1 2000 Florian La Roche <Florian.LaRoche@redhat.de>
acdedc
- add lib*.so symlinks to link dynamically against shared libs
acdedc
acdedc
* Tue Feb 29 2000 Florian La Roche <Florian.LaRoche@redhat.de>
acdedc
- update to 0.9.5
acdedc
- run ldconfig directly in post/postun
acdedc
- add FAQ
acdedc
acdedc
* Sat Dec 18 1999 Bernhard Rosenkrdnzer <bero@redhat.de>
acdedc
- Fix build on non-x86 platforms
acdedc
acdedc
* Fri Nov 12 1999 Bernhard Rosenkrdnzer <bero@redhat.de>
acdedc
- move /usr/share/ssl/* from -devel to main package
acdedc
acdedc
* Tue Oct 26 1999 Bernhard Rosenkrdnzer <bero@redhat.de>
acdedc
- inital packaging
acdedc
- changes from base:
acdedc
  - Move /usr/local/ssl to /usr/share/ssl for FHS compliance
acdedc
  - handle RPM_OPT_FLAGS