SHA256
1
0
forked from pool/openssl-1_1
Go to file
Vítězslav Čížek 1434a42e91 - Update to 1.1.0i
OpenSSL Security Advisory [12 June 2018]
  * Reject excessively large primes in DH key generation
    (bsc#1097158, CVE-2018-0732)
  * Make EVP_PKEY_asn1_new() a bit stricter about its input
  * Revert blinding in ECDSA sign and instead make problematic addition
    length-invariant. Switch even to fixed-length Montgomery multiplication.
  * Change generating and checking of primes so that the error rate of not
    being prime depends on the intended use based on the size of the input.
  * Increase the number of Miller-Rabin rounds for DSA key generating to 64.
  * Add blinding to ECDSA and DSA signatures to protect against side channel
    attacks
  * When unlocking a pass phrase protected PEM file or PKCS#8 container, we
    now allow empty (zero character) pass phrases.
  * Certificate time validation (X509_cmp_time) enforces stricter
    compliance with RFC 5280. Fractional seconds and timezone offsets
    are no longer allowed.
  * Fixed a text canonicalisation bug in CMS
- drop patches (upstream):
  * 0001-Limit-scope-of-CN-name-constraints.patch
  * 0001-Revert-util-dofile.pl-only-quote-stuff-that-actually.patch
  * 0001-Tolerate-a-Certificate-using-a-non-supported-group-o.patch
  * 0002-Skip-CN-DNS-name-constraint-checks-when-not-needed.patch
- refresh patches:
  * openssl-1.1.0-fips.patch
  * openssl-disable_rsa_keygen_tests_with_small_modulus.patch
- rename openssl-CVE-2018-0737.patch to openssl-CVE-2018-0737-fips.patch
  as it now only includes changes to the fips code

OBS-URL: https://build.opensuse.org/package/show/security:tls/openssl-1_1?expand=0&rev=17
2018-08-14 14:11:16 +00:00
.gitattributes - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
.gitignore - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0001-Axe-builtin-printf-implementation-use-glibc-instead.patch Accepting request 591684 from home:vitezslav_cizek:branches:security:tls 2018-03-27 15:20:21 +00:00
0001-Resume-reading-from-randfile-when-interrupted-by-a-s.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0002-crypto-modes-asm-ghash-s390x.pl-fix-gcm_gmult_4bit-K.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0004-s390x-assembly-pack-add-OPENSSL_s390xcap-environment.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0005-s390x-assembly-pack-add-OPENSSL_s390xcap-man-page.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0006-s390x-assembly-pack-extended-s390x-capability-vector.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0007-crypto-evp-e_aes.c-add-foundations-for-extended-s390.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0008-s390x-assembly-pack-extended-s390x-capability-vector.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0009-crypto-aes-asm-aes-s390x.pl-add-KMA-code-path.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0010-doc-man3-OPENSSL_s390xcap.pod-update-KMA.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0011-crypto-aes-asm-aes-s390x.pl-add-CFI-annotations-KMA-.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0012-s390x-assembly-pack-add-KMA-code-path-for-aes-gcm.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
0013-crypto-aes-asm-aes-s390x.pl-add-CFI-annotations-KMA-.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
baselibs.conf Accepting request 580786 from home:dimstar:Factory 2018-02-27 20:50:55 +00:00
openssl-1_1.changes - Update to 1.1.0i 2018-08-14 14:11:16 +00:00
openssl-1_1.spec - Update to 1.1.0i 2018-08-14 14:11:16 +00:00
openssl-1.0.1e-add-suse-default-cipher.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-1.0.1e-add-test-suse-default-cipher-suite.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-1.1.0-fips.patch - Update to 1.1.0i 2018-08-14 14:11:16 +00:00
openssl-1.1.0-no-html.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-1.1.0i.tar.gz - Update to 1.1.0i 2018-08-14 14:11:16 +00:00
openssl-1.1.0i.tar.gz.asc - Update to 1.1.0i 2018-08-14 14:11:16 +00:00
openssl-CVE-2018-0737-fips.patch - Update to 1.1.0i 2018-08-14 14:11:16 +00:00
openssl-disable_rsa_keygen_tests_with_small_modulus.patch - Update to 1.1.0i 2018-08-14 14:11:16 +00:00
openssl-fips_disallow_ENGINE_loading.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-fips-clearerror.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-fips-dont_run_FIPS_module_installed.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-fips-dont-fall-back-to-default-digest.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-fips-fix-odd-rsakeybits.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-fips-rsagen-d-bits.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-fips-selftests_in_nonfips_mode.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-no-date.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-pkgconfig.patch Accepting request 591684 from home:vitezslav_cizek:branches:security:tls 2018-03-27 15:20:21 +00:00
openssl-ppc64-config.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-rsakeygen-minimum-distance.patch Accepting request 591684 from home:vitezslav_cizek:branches:security:tls 2018-03-27 15:20:21 +00:00
openssl-static-deps.patch Accepting request 591684 from home:vitezslav_cizek:branches:security:tls 2018-03-27 15:20:21 +00:00
openssl-truststore.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl-urandom-reseeding.patch - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
openssl.keyring - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00
showciphers.c - Renamed from openssl-1_1_0 (bsc#1081335) 2018-02-16 12:13:08 +00:00