Go to file
Pedro Monreal Gonzalez 443be2c653 Accepting request 1009758 from home:pmonrealgonzalez:branches:security:tls
- Update to 3.7.8:
  * libgnutls: In FIPS140 mode, RSA signature verification is an
    approved operation if the key has modulus with known sizes
    (1024, 1280, 1536, and 1792 bits), in addition to any modulus
    sizes larger than 2048 bits, according to SP800-131A rev2.
  * libgnutls: gnutls_session_channel_binding performs additional
    checks when GNUTLS_CB_TLS_EXPORTER is requested. According to
    RFC9622 4.2, the "tls-exporter" channel binding is only usable
    when the handshake is bound to a unique master secret (i.e.,
    either TLS 1.3 or extended master secret extension is
    negotiated). Otherwise the function now returns error.
  * libgnutls: usage of the following functions, which are designed
    to loosen restrictions imposed by allowlisting mode of
    configuration, has been additionally restricted. Invoking
    them is now only allowed if system-wide TLS priority string
    has not been initialized yet:
      - gnutls_digest_set_secure
      - gnutls_sign_set_secure
      - gnutls_sign_set_secure_for_certs
      - gnutls_protocol_set_enabled
  * Delete gnutls-3.6.6-set_guile_site_dir.patch and use the
    --with-guile-extension-dir configure option to properly
    handle the guile extension directory.
  * Rebase gnutls-Make-XTS-key-check-failure-not-fatal.patch
  * Update gnutls.keyring
  * Add a build depencency on gtk-doc required by autoreconf

OBS-URL: https://build.opensuse.org/request/show/1009758
OBS-URL: https://build.opensuse.org/package/show/security:tls/gnutls?expand=0&rev=77
2022-10-11 12:44:03 +00:00
.gitattributes OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/gnutls?expand=0&rev=1 2007-01-15 23:15:20 +00:00
.gitignore OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/gnutls?expand=0&rev=1 2007-01-15 23:15:20 +00:00
baselibs.conf Accepting request 1003382 from home:AndreasStieger:branches:security:tls 2022-09-14 06:43:45 +00:00
gnutls_ECDSA_signing.patch Accepting request 1003480 from home:pmonrealgonzalez:branches:security:tls 2022-09-14 08:41:21 +00:00
gnutls-3.5.11-skip-trust-store-tests.patch Accepting request 832939 from home:vitezslav_cizek:branches:security:tls 2020-09-08 11:31:26 +00:00
gnutls-3.7.8.tar.xz Accepting request 1009758 from home:pmonrealgonzalez:branches:security:tls 2022-10-11 12:44:03 +00:00
gnutls-3.7.8.tar.xz.sig Accepting request 1009758 from home:pmonrealgonzalez:branches:security:tls 2022-10-11 12:44:03 +00:00
gnutls-FIPS-disable-failing-tests.patch Accepting request 991873 from home:pmonrealgonzalez:branches:security:tls 2022-08-01 08:36:39 +00:00
gnutls-FIPS-jitterentropy.patch Accepting request 1003480 from home:pmonrealgonzalez:branches:security:tls 2022-09-14 08:41:21 +00:00
gnutls-FIPS-Run-CFB8-without-offset.patch Accepting request 1003573 from home:pmonrealgonzalez:branches:security:tls 2022-09-14 15:37:16 +00:00
gnutls-FIPS-SLI-pbkdf2-verify-keylengths-only-SHA.patch Accepting request 1003480 from home:pmonrealgonzalez:branches:security:tls 2022-09-14 08:41:21 +00:00
gnutls-FIPS-TLS_KDF_selftest.patch Accepting request 991873 from home:pmonrealgonzalez:branches:security:tls 2022-08-01 08:36:39 +00:00
gnutls-Make-XTS-key-check-failure-not-fatal.patch Accepting request 1009758 from home:pmonrealgonzalez:branches:security:tls 2022-10-11 12:44:03 +00:00
gnutls.changes Accepting request 1009758 from home:pmonrealgonzalez:branches:security:tls 2022-10-11 12:44:03 +00:00
gnutls.keyring Accepting request 1009758 from home:pmonrealgonzalez:branches:security:tls 2022-10-11 12:44:03 +00:00
gnutls.spec Accepting request 1009758 from home:pmonrealgonzalez:branches:security:tls 2022-10-11 12:44:03 +00:00