- libgnutls: leancrypto was added as an interim option for PQC The library can now be built with leancrypto instead of liboqs for post-quantum cryptography (PQC), when configured with --with-leancrypto option instead of --with-liboqs. - libgnutls: Experimental support for ML-DSA signature algorithm The library and certtool now support ML-DSA signature algorithm as defined in FIPS 204 and based on draft-ietf-lamps-dilithium-certificates-04. This feature is currently marked as experimental and can only be enabled when compiled with --with-leancrypto or --with-liboqs. Contributed by David Dudas. - libgnutls: Support for ML-KEM-1024 key encapsulation mechanism The support for ML-KEM post-quantum key encapsulation mechanisms has been extended to cover ML-KEM-1024, in addition to ML-KEM-768. MLKEM1024 is only offered as SecP384r1MLKEM1024 hybrid as per draft-kwiatkowski-tls-ecdhe-mlkem-03. - libgnutls: Fix potential DoS in handling certificates with numerous name constraints, as a follow-up of CVE-2024-12133 in libtasn1. The bundled copy of libtasn1 has also been updated to the latest 4.20.0 release to complete the fix. Reported by Bing Shi (#1553). [GNUTLS-SA-2025-02-07, CVSS: medium] [bsc#1236974, CVE-2024-12243 - Licensing information moved to REAMDE.md, COPYING, COPYING.LESSERv2 * Rebased gnutls-FIPS-140-3-references.patch * Rebased gnutls-FIPS-TLS_KDF_selftest.patch * Rebased gnutls-FIPS-jitterentropy.patch * Rebased gnutls-disable-flaky-test-dtls-resume.patch * Rebased gnutls-srp-test-SIGPIPE.patch * Rebased gnutls-3.5.11-skip-trust-store-tests.patch * Add gnutls-set-cligen-python-interp.patch OBS-URL: https://build.opensuse.org/package/show/security:tls/gnutls?expand=0&rev=119
35 lines
1.3 KiB
Diff
35 lines
1.3 KiB
Diff
Index: gnutls-3.8.9/tests/Makefile.am
|
|
===================================================================
|
|
--- gnutls-3.8.9.orig/tests/Makefile.am
|
|
+++ gnutls-3.8.9/tests/Makefile.am
|
|
@@ -603,8 +603,6 @@ ctests += win32-certopenstore
|
|
|
|
endif
|
|
|
|
-dist_check_SCRIPTS += pqc-hybrid-kx.sh
|
|
-
|
|
cpptests =
|
|
if ENABLE_CXX
|
|
if HAVE_CMOCKA
|
|
Index: gnutls-3.8.9/tests/Makefile.in
|
|
===================================================================
|
|
--- gnutls-3.8.9.orig/tests/Makefile.in
|
|
+++ gnutls-3.8.9/tests/Makefile.in
|
|
@@ -3236,7 +3236,7 @@ am__dist_check_SCRIPTS_DIST = rfc2253-es
|
|
gnutls-cli-self-signed.sh gnutls-cli-invalid-crl.sh \
|
|
gnutls-cli-rawpk.sh dh-fips-approved.sh p11-kit-trust.sh \
|
|
testpkcs11.sh certtool-pkcs11.sh pkcs11-tool.sh \
|
|
- p11-kit-load.sh danetool.sh tpmtool_test.sh pqc-hybrid-kx.sh
|
|
+ p11-kit-load.sh danetool.sh tpmtool_test.sh
|
|
AM_V_P = $(am__v_P_@AM_V@)
|
|
am__v_P_ = $(am__v_P_@AM_DEFAULT_V@)
|
|
am__v_P_0 = false
|
|
@@ -7106,7 +7106,6 @@ dist_check_SCRIPTS = rfc2253-escape-test
|
|
$(am__append_18) $(am__append_20) $(am__append_21) \
|
|
$(am__append_23) $(am__append_25) $(am__append_26) \
|
|
$(am__append_27) $(am__append_29) $(am__append_30) \
|
|
- pqc-hybrid-kx.sh
|
|
@WINDOWS_FALSE@dtls_stress_SOURCES = dtls/dtls-stress.c
|
|
@WINDOWS_FALSE@dtls_stress_LDADD = $(COMMON_GNUTLS_LDADD) \
|
|
@WINDOWS_FALSE@ $(COMMON_DEPS_LDADD)
|