154 Commits

Author SHA256 Message Date
55b1276c7b Accepting request 1305335 from security:tls
- Update to 3.5.3:
  * Added FIPS 140-3 PCT on DH key generation.
  * Fixed the synthesised OPENSSL_VERSION_NUMBER.
- Rebase patches:
  * openssl-DH-Disable-FIPS-186-4-type-parameters-in-FIPS-mode.patch
  * openssl-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch
  * openssl-FIPS-limit-rsa-encrypt.patch

OBS-URL: https://build.opensuse.org/request/show/1305335
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=46
2025-09-18 19:07:54 +00:00
35a448b6ff Accepting request 1305272 from home:lmulling:branches:security:tls
- Update to 3.5.3:
  * Added FIPS 140-3 PCT on DH key generation.
  * Fixed the synthesised OPENSSL_VERSION_NUMBER.
- Rebase patches:
  * openssl-DH-Disable-FIPS-186-4-type-parameters-in-FIPS-mode.patch
  * openssl-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch
  * openssl-FIPS-limit-rsa-encrypt.patch

OBS-URL: https://build.opensuse.org/request/show/1305272
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=155
2025-09-17 09:11:46 +00:00
3a89148bb4 Accepting request 1297961 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1297961
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=45
2025-08-09 17:57:12 +00:00
508f9651c5 Accepting request 1297953 from home:lmulling:branches:security:tls
- Update to 3.5.2:
  * Miscellaneous minor bug fixes.
  * The FIPS provider now performs a PCT on key import for RSA, EC and ECX.
    This is mandated by FIPS 140-3 IG 10.3.A additional comment 1.
- Rebase patches:
  * openssl-FIPS-140-3-keychecks.patch
  * openssl-FIPS-NO-DES-support.patch
  * openssl-FIPS-enforce-EMS-support.patch
  * openssl-disable-fipsinstall.patch
- Move ssl configuration files to the libopenssl package [bsc#1247463]
- Don't install unneeded NOTES

OBS-URL: https://build.opensuse.org/request/show/1297953
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=153
2025-08-06 13:16:19 +00:00
b74e4ca662 Accepting request 1296523 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1296523
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=44
2025-07-31 15:45:52 +00:00
be0ae6dfb2 Accepting request 1296522 from home:pmonrealgonzalez:branches:security:tls
- Disable LTO for userspace livepatching [jsc#PED-13245]

OBS-URL: https://build.opensuse.org/request/show/1296522
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=151
2025-07-30 09:28:14 +00:00
d76edf32e8 Accepting request 1296057 from home:Andreas_Schwab:glibc:rebuild
- Use termios instead of obsolete termio

OBS-URL: https://build.opensuse.org/request/show/1296057
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=150
2025-07-29 08:21:34 +00:00
f7b11c0ced Accepting request 1291169 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1291169
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=43
2025-07-09 15:25:32 +00:00
6a5f3b877d Accepting request 1291089 from home:lmulling:branches:security:tls
- Update to 3.5.1:
  * Fix x509 application adds trusted use instead of rejected use.
    [bsc#1243564, CVE-2025-4575]
- Remove patches:
  * openssl-Fix-P384-on-P8-targets.patch
  * openssl-CVE-2025-4575.patch
- Rebase patches:
  * openssl-Allow-disabling-of-SHA1-signatures.patch
  * openssl-FIPS-Allow-SHA1-in-seclevel-2-if-rh-allow-sha1-signatures.patch
  * openssl-FIPS-NO-DES-support.patch
- Fix a bogus warning caused by -Wfree-nonheap-object
  * Add patch openssl-Fix-Wfree-nonheap-object-warning.patch

OBS-URL: https://build.opensuse.org/request/show/1291089
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=148
2025-07-08 06:49:27 +00:00
6a9c8b477d Accepting request 1281096 from security:tls
- Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014]
  * Add openssl-Fix-P384-on-P8-targets.patch [a72f753c]

- Security fix: [bsc#1243564, CVE-2025-4575]
  * Fix the x509 application adding trusted use instead of rejected use
  * Add openssl-CVE-2025-4575.patch

  * Security fixes:
    - [bsc#1243459, CVE-2025-27587] Minerva side channel vulnerability in P-384

OBS-URL: https://build.opensuse.org/request/show/1281096
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=42
2025-05-30 12:20:40 +00:00
7f75b4690a Accepting request 1281095 from security:tls:unstable
- Fix P-384 curve on lower-than-P9 PPC64 targets [bsc#1243014]
  * Add openssl-Fix-P384-on-P8-targets.patch [a72f753c]

OBS-URL: https://build.opensuse.org/request/show/1281095
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=146
2025-05-29 09:27:54 +00:00
025a7f299f Accepting request 1280811 from security:tls:unstable
OBS-URL: https://build.opensuse.org/request/show/1280811
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=145
2025-05-28 09:26:43 +00:00
d9abb43056 Accepting request 1280498 from home:ayankov:branches:security:tls:unstable
- Fixed CVE-2025-27587

OBS-URL: https://build.opensuse.org/request/show/1280498
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=144
2025-05-28 06:57:23 +00:00
b3e219d8e3 Accepting request 1280158 from home:lmulling:branches:security:tls
- bsc#1243564 CVE-2025-4575: Fix the x509 application adding trusted use instead of rejected use
  * Add openssl-CVE-2025-4575.patch

OBS-URL: https://build.opensuse.org/request/show/1280158
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=143
2025-05-27 09:21:22 +00:00
4086df5291 Accepting request 1278744 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1278744
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=41
2025-05-23 12:26:45 +00:00
9f84079583 Accepting request 1278695 from security:tls:unstable
OBS-URL: https://build.opensuse.org/request/show/1278695
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=141
2025-05-20 13:04:16 +00:00
932a41fb64 Accepting request 1270033 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1270033
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=40
2025-04-29 14:39:52 +00:00
424cec1e00 Accepting request 1270031 from security:tls:unstable
- Update to 3.5.0:
  * Changes:
    - Default encryption cipher for the req, cms, and smime applications
      changed from des-ede3-cbc to aes-256-cbc.
    - The default TLS supported groups list has been changed to include
      and prefer hybrid PQC KEM groups. Some practically unused groups
      were removed from the default list.
    - The default TLS keyshares have been changed to offer X25519MLKEM768
      and and X25519.
    - All BIO_meth_get_*() functions were deprecated.
  * New features:
    - Support for server side QUIC (RFC 9000)
    - Support for 3rd party QUIC stacks including 0-RTT support
    - Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA)
    - A new configuration option no-tls-deprecated-ec to disable support
      for TLS groups deprecated in RFC8422
    - A new configuration option enable-fips-jitter to make the FIPS
      provider to use the JITTER seed source
    - Support for central key generation in CMP
    - Support added for opaque symmetric key objects (EVP_SKEY)
    - Support for multiple TLS keyshares and improved TLS key establishment
      group configurability
    - API support for pipelining in provided cipher algorithms
  * Remove patches:
    - openssl-3-disable-hmac-hw-acceleration-with-engine-digest.patch
    - openssl-3-support-CPACF-sha3-shake-perf-improvement.patch
    - openssl-3-add-defines-CPACF-funcs.patch
    - openssl-3-fix-memleak-s390x_HMAC_CTX_copy.patch
    - openssl-3-add-xof-state-handling-s3_absorb.patch
    - openssl-3-fix-state-handling-sha3_absorb_s390x.patch

OBS-URL: https://build.opensuse.org/request/show/1270031
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=139
2025-04-16 13:02:20 +00:00
d24a1a85c7 Accepting request 1255522 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1255522
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=39
2025-03-27 21:31:30 +00:00
aebedfd50e Accepting request 1255099 from home:lmulling:branches:security:tls
- FIPS: Mark SHA-1 as non-approved in the SLI. [jsc#PED-12224]
  * Add openssl-FIPS-Mark-SHA1-as-nonapproved.patch

OBS-URL: https://build.opensuse.org/request/show/1255099
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=137
2025-03-24 08:13:44 +00:00
7a6a27b11b Accepting request 1251128 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1251128
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=38
2025-03-08 16:51:16 +00:00
3ccdcb76ff Accepting request 1250719 from home:lmulling:branches:security:tls
- Introduce --without lto. When %{optflags} contains -flto=*, tests cases are
  also built using -flto=* which significantly increases build times, this
  option disables lto which improve iteration times when developing.

OBS-URL: https://build.opensuse.org/request/show/1250719
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=135
2025-03-07 08:17:54 +00:00
7d987586ad Accepting request 1245244 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1245244
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=37
2025-02-12 20:30:27 +00:00
50f27fb2ad Accepting request 1245243 from home:pmonrealgonzalez:branches:security:tls
expected. [bsc#1236599, CVE-2024-12797]

OBS-URL: https://build.opensuse.org/request/show/1245243
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=133
2025-02-12 07:58:33 +00:00
d9cf24d3d7 Accepting request 1245178 from home:lmulling:branches:security:tls
- Update to 3.2.4:
  * Fixed RFC7250 handshakes with unauthenticated servers don't abort as
    expected. [CVE-2024-12797]
  * Fixed timing side-channel in ECDSA signature computation. [CVE-2024-13176]
  * Fixed possible OOB memory access with invalid low-level GF(2^m) elliptic
    curve parameters. [CVE-2024-9143]
- Remove patch openssl-CVE-2024-13176.patch
- Rebase patches:
  * openssl-3-add_EVP_DigestSqueeze_api.patch
  * openssl-DH-Disable-FIPS-186-4-type-parameters-in-FIPS-mode.patch
  * openssl-FIPS-RSA-encapsulate.patch
  * openssl-disable-fipsinstall.patch

OBS-URL: https://build.opensuse.org/request/show/1245178
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=132
2025-02-12 07:49:34 +00:00
0a9263581d Accepting request 1240110 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1240110
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=36
2025-01-25 18:09:48 +00:00
eed5c4a078 Accepting request 1239888 from home:lmulling:branches:security:tls
- bsc#1236136 CVE-2024-13176: Fix timing side-channel in ECDSA signature computation
  * Add patch openssl-CVE-2024-13176.patch

OBS-URL: https://build.opensuse.org/request/show/1239888
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=130
2025-01-24 08:48:18 +00:00
124a82228a Accepting request 1234617 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1234617
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=35
2025-01-05 14:27:00 +00:00
34de714067 Accepting request 1234615 from home:pmonrealgonzalez:branches:security:tls
- Add support for userspace livepatching on ppc64le (jsc#PED-11850).
- Fix evp_properties section in the openssl.cnf file [bsc#1234647]
  * Rebase patches:
    - openssl-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch
    - openssl-TESTS-Disable-default-provider-crypto-policies.patch

OBS-URL: https://build.opensuse.org/request/show/1234615
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=128
2025-01-02 18:17:13 +00:00
25ab083387 Accepting request 1233180 from home:gbelinassi:branches:security:tls
- Add support for userspace livepatching on ppc64le (jsc#PED-10952).
- Use gcc-13 for ppc64le.

OBS-URL: https://build.opensuse.org/request/show/1233180
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=127
2025-01-02 08:25:49 +00:00
5ef05738b6 Accepting request 1223748 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1223748
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=34
2024-11-13 14:26:48 +00:00
6a83bb0308 Accepting request 1223747 from security:tls:unstable
OBS-URL: https://build.opensuse.org/request/show/1223747
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=125
2024-11-12 16:03:34 +00:00
d592fa6a25 Accepting request 1223296 from security:tls:unstable
OBS-URL: https://build.opensuse.org/request/show/1223296
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=124
2024-11-11 09:13:41 +00:00
593a68ff93 Accepting request 1222755 from security:tls:unstable
OBS-URL: https://build.opensuse.org/request/show/1222755
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=123
2024-11-11 07:53:58 +00:00
8d72170ca7 Accepting request 1221596 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1221596
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=33
2024-11-06 15:49:16 +00:00
02ccd5d27c Accepting request 1221594 from security:tls:unstable
- Support MSA 11 HMAC on s390x jsc#PED-10273 
  * Add openssl-3-disable-hmac-hw-acceleration-with-engine-digest.patch
  * Add openssl-3-fix-hmac-digest-detection-s390x.patch
  * Add openssl-3-fix-memleak-s390x_HMAC_CTX_copy.patch

- Add hardware acceleration for full AES-XTS  jsc#PED-10273
  * Add openssl-3-hw-acceleration-aes-xts-s390x.patch

- Support MSA 12 SHA3 on s390x jsc#PED-10280
  * Add openssl-3-add_EVP_DigestSqueeze_api.patch
  * Add openssl-3-support-multiple-sha3_squeeze_s390x.patch
  * Add openssl-3-add-xof-state-handling-s3_absorb.patch
  * Add openssl-3-fix-state-handling-sha3_absorb_s390x.patch
  * Add openssl-3-fix-state-handling-sha3_final_s390x.patch
  * Add openssl-3-fix-state-handling-shake_final_s390x.patch
  * Add openssl-3-fix-state-handling-keccak_final_s390x.patch
  * Add openssl-3-support-EVP_DigestSqueeze-in-digest-prov-s390x.patch
  * Add openssl-3-add-defines-CPACF-funcs.patch
  * Add openssl-3-add-hw-acceleration-hmac.patch
  * Add openssl-3-support-CPACF-sha3-shake-perf-improvement.patch
  * Add openssl-3-fix-s390x_sha3_absorb.patch
  * Add openssl-3-fix-s390x_shake_squeeze.patch

- Update to 3.2.3:
  * Changes between 3.2.2 and 3.2.3:
    - Fixed possible denial of service in X.509 name checks. [CVE-2024-6119]
    - Fixed possible buffer overread in SSL_select_next_proto(). [CVE-2024-5535]
  * Changes between 3.2.1 and 3.2.2:
    - Fixed potential use after free after SSL_free_buffers() is called. [CVE-2024-4741]
    - Fixed an issue where checking excessively long DSA keys or parameters may

OBS-URL: https://build.opensuse.org/request/show/1221594
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=121
2024-11-05 19:08:08 +00:00
4d2f7a6f6d Accepting request 1217013 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1217013
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=32
2024-10-29 13:32:23 +00:00
e324356f82 Accepting request 1217011 from security:tls:unstable
- Update to 3.1.7:
  * Major changes between OpenSSL 3.1.6 and OpenSSL 3.1.7 [3 Sep 2024]
    - Fixed possible denial of service in X.509 name checks (CVE-2024-6119)
    - Fixed possible buffer overread in SSL_select_next_proto()
      (CVE-2024-5535)
  * Major changes between OpenSSL 3.1.5 and OpenSSL 3.1.6 [4 Jun 2024]
    - Fixed potential use after free after SSL_free_buffers() is
      called (CVE-2024-4741)
    - Fixed an issue where checking excessively long DSA keys or
      parameters may be very slow (CVE-2024-4603)
    - Fixed unbounded memory growth with session handling in TLSv1.3
      (CVE-2024-2511)
  * Major changes between OpenSSL 3.1.4 and OpenSSL 3.1.5 [30 Jan 2024]
    - Fixed PKCS12 Decoding crashes (CVE-2024-0727)
    - Fixed Excessive time spent checking invalid RSA public keys
      [CVE-2023-6237)
    - Fixed POLY1305 MAC implementation corrupting vector registers
      on PowerPC CPUs which support PowerISA 2.07 (CVE-2023-6129)
    - Fix excessive time spent in DH check / generation with large
      Q parameter value (CVE-2023-5678)
  * Update openssl.keyring with BA5473A2B0587B07FB27CF2D216094DFD0CB81EF
  * Rebase patches:
    - openssl-Force-FIPS.patch
    - openssl-FIPS-embed-hmac.patch
    - openssl-FIPS-services-minimize.patch
    - openssl-FIPS-RSA-disable-shake.patch
    - openssl-CVE-2023-50782.patch
  * Remove patches fixed in the update:
    - openssl-Improve-performance-for-6x-unrolling-with-vpermxor-i.patch
    - openssl-CVE-2024-6119.patch openssl-CVE-2024-5535.patch

OBS-URL: https://build.opensuse.org/request/show/1217011
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=119
2024-10-22 12:02:36 +00:00
8de5f9f15f Accepting request 1208827 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1208827
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=31
2024-10-20 08:02:58 +00:00
e6ed9f2171 Accepting request 1208826 from home:pmonrealgonzalez:branches:security:tls
* Added openssl-CVE-2024-41996.patch

OBS-URL: https://build.opensuse.org/request/show/1208826
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=117
2024-10-18 08:58:53 +00:00
e830b331ca Accepting request 1208823 from home:pmonrealgonzalez:branches:security:tls
- Security fix: [bsc#1231741, CVE-2024-9143]
  * Low-level invalid GF(2^m) parameters lead to OOB memory access
  * Add openssl-CVE-2024-9143.patch

- Security fix: [bsc#1220262, CVE-2023-50782]
  * Implicit rejection in PKCS#1 v1.5
  * Add openssl-CVE-2023-50782.patch

  * Validating the order of the public keys in the Diffie-Hellman
    Key Agreement Protocol, when an approved safe prime is used.
  * Added openssl-3-CVE-2024-41996.patch

OBS-URL: https://build.opensuse.org/request/show/1208823
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=116
2024-10-18 08:55:02 +00:00
1c94970ea8 Accepting request 1202944 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1202944
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=30
2024-09-25 19:51:14 +00:00
eda0349390 Accepting request 1202190 from home:ayankov:branches:security:tls
- Security fix: [bsc#1230698, CVE-2024-41996] 
  * Validating the order of the public keys in the Diffie-Hellman Key Agreement Protocol, when an approved safe prime is used
  * Added openssl-CVE-2024-41996.patch

OBS-URL: https://build.opensuse.org/request/show/1202190
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=114
2024-09-24 12:22:05 +00:00
1685dc00d5 Accepting request 1198659 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1198659
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=29
2024-09-05 13:45:58 +00:00
92f37af083 Accepting request 1198658 from home:pmonrealgonzalez:branches:security:tls
- Security fix: [bsc#1229465, CVE-2024-6119]
  * possible denial of service in X.509 name checks
  * openssl-CVE-2024-6119.patch

OBS-URL: https://build.opensuse.org/request/show/1198658
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=112
2024-09-04 08:01:42 +00:00
177e75f2a8 Accepting request 1192379 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1192379
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=28
2024-08-14 12:14:36 +00:00
46691be39e Accepting request 1192291 from home:pmonrealgonzalez:branches:security:tls
- FIPS: Deny SHA-1 signature verification in FIPS provider [bsc#1221365]
  * SHA-1 is not allowed anymore in FIPS 186-5 for signature
    verification operations. After 12/31/2030, NIST will disallow
    SHA-1 for all of its usages.
  * Add openssl-3-FIPS-Deny-SHA-1-sigver-in-FIPS-provider.patch

- FIPS: RSA keygen PCT requirements.
  * Skip the rsa_keygen_pairwise_test() PCT in rsa_keygen() as the
    self-test requirements are covered by do_rsa_pct() for both
    RSA-OAEP and RSA signatures [bsc#1221760]
  * Enforce error state if rsa_keygen PCT is run and fails [bsc#1221753]
  * Add openssl-3-FIPS-PCT_rsa_keygen.patch

- FIPS: Check that the fips provider is available before setting
  it as the default provider in FIPS mode. [bsc#1220523]
  * Rebase openssl-Force-FIPS.patch

- FIPS: Port openssl to use jitterentropy [bsc#1220523]
  * Set the module in error state if the jitter RNG fails either on
    initialization or entropy gathering because health tests failed.
  * Add jitterentropy as a seeding source output also in crypto/info.c
  * Move the jitter entropy collector and the associated lock out
    of the header file to avoid redefinitions.
  * Add the fips_local.cnf symlink to the spec file. This simlink
    points to the openssl_fips.config file that is provided by the
    crypto-policies package.
  * Rebase openssl-3-jitterentropy-3.4.0.patch
  * Rebase openssl-FIPS-enforce-EMS-support.patch

- FIPS: Block non-Approved Elliptic Curves [bsc#1221786]

OBS-URL: https://build.opensuse.org/request/show/1192291
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=110
2024-08-07 21:54:42 +00:00
90261d7ea8 Accepting request 1189313 from security:tls
OBS-URL: https://build.opensuse.org/request/show/1189313
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/openssl-3?expand=0&rev=27
2024-07-26 14:12:26 +00:00
8b13cbe1f4 Accepting request 1189310 from home:pmonrealgonzalez:branches:security:tls
- Build with no-afalgeng [bsc#1226463]

OBS-URL: https://build.opensuse.org/request/show/1189310
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=108
2024-07-24 06:29:07 +00:00
26e43d536f Accepting request 1189030 from home:pmonrealgonzalez:branches:security:tls
- Apply "openssl-CVE-2024-4741.patch" to fix a use-after-free
  security vulnerability. Calling the function SSL_free_buffers()
  potentially caused memory to be accessed that was previously
  freed in some situations and a malicious attacker could attempt
  to engineer a stituation where this occurs to facilitate a
  denial-of-service attack. [CVE-2024-4741, bsc#1225551]

OBS-URL: https://build.opensuse.org/request/show/1189030
OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-3?expand=0&rev=107
2024-07-22 13:04:55 +00:00