SEARCH
NEW RPMS
DIRECTORIES
ABOUT
FAQ
VARIOUS
BLOG

 
 
Changelog for libopenssl0.9.7-devel-0.9.7g-2.5.20060mdk.i586.rpm :
Sat Sep 30 04:00:00 2006 Stew Benedict 0.9.7g-2.5.20060mdk
- P14: re-patch the CVE-2006-2940 patch

Wed Sep 27 04:00:00 2006 Stew Benedict 0.9.7g-2.4.20060mdk
- P10: security fix for CVE-2006-2940
- P11: security fix for CVE-2006-4343
- P12: security fix for CVE-2006-3738
- P13: security fix for CVE-2006-2937

Thu Sep 7 04:00:00 2006 Vincent Danen 0.9.7g-2.3.20060mdk
- updated P9 from the openssl team

Wed Sep 6 04:00:00 2006 Vincent Danen 0.9.7g-2.2.20060mdk
- P9: security fix for CVE-2006-4339

Tue Oct 11 04:00:00 2005 Stew Benedict 0.9.7g-2.1.20060mdk
- security update for CAN-2005-2969 (P7), CAN-2005-2946 (P8)

Fri May 6 04:00:00 2005 Oden Eriksson 0.9.7g-2mdk
- rebuilt with gcc4

Sat Apr 16 04:00:00 2005 Oden Eriksson 0.9.7g-1mdk
- 0.9.7g
- rediffed P2

Fri Apr 1 04:00:00 2005 Oden Eriksson 0.9.7f-1mdk
- 0.9.7f
- use the %mkrel macro
- drop the libfips patch (P5), it\'s implemented upstream
- drop the CAN-2004-0975 patch (P4) as the code is gone
- rediffed P2

Thu Mar 3 03:00:00 2005 Oden Eriksson 0.9.7e-5mdk
- added P6 to support Brazilian Government OTHERNAME X509v3 field (#14158)

Tue Feb 1 03:00:00 2005 Oden Eriksson 0.9.7e-4mdk
- fix deps and conditional %multiarch
- added P5 as there\'s no libfips

Tue Jan 11 03:00:00 2005 Frederic Lepied 0.9.7e-3mdk
- build in parallel

Wed Dec 8 03:00:00 2004 Oden Eriksson 0.9.7e-2mdk
- apply the CAN-2004-0975 patch (P4) from 0.9.7d-1.1.101mdk

Tue Nov 9 03:00:00 2004 Oden Eriksson 0.9.7e-1mdk
- 0.9.7e
- rediffed P2 & P3
- misc spec file fixes

Sat Jun 19 04:00:00 2004 Jean-Michel Dault 0.9.7d-1mdk
- new version
- rediff P3
- remove P4/P5 since they\'re included in the release

Thu Mar 18 03:00:00 2004 Vincent Danen 0.9.7c-3mdk
- P4/P5: security fixes for CAN-2004-0079 and CAN-204-0112

Mon Jan 12 03:00:00 2004 Stefan van der Eijk 0.9.7c-2mdk
- Don\'t use broken sparc / sparc64 asm optimizations for now

Tue Dec 16 03:00:00 2003 Jean-Michel Dault 0.9.7c-1mdk
- new version

Wed Sep 10 04:00:00 2003 Gwenole Beauchesne 0.9.7b-5mdk
- Don\'t use broken AMD64 asm optimizations for now

Fri Aug 1 04:00:00 2003 Gwenole Beauchesne 0.9.7b-4mdk
- Patch2: Make sure to handle RPM_OPT_FLAGS in Configure

Wed Jul 9 04:00:00 2003 Guillaume Cottenceau 0.9.7b-3mdk
- rebuild for new devel provides

Sun May 11 04:00:00 2003 Stefan van der Eijk 0.9.7b-2mdk
- add Provides to static-devel package
- Removed BuildRequires: /usr/bin/perl --> is Required by rpm-build

Thu May 8 04:00:00 2003 Yves Duret 0.9.7b-1mdk
- doing the work.
- %ifarch ia64 x86_64 patch1 and2
- removed patch 7, 8 merged upstream.

Thu May 8 04:00:00 2003 Frederic Crozat - 0.9.7a-3mdk
- Add missing pkgconfig file in devel package

Wed Apr 2 04:00:00 2003 Vincent Danen 0.9.7a-2mdk
- security update

Sun Feb 23 03:00:00 2003 Jean-Michel Dault 0.9.7a-1mdk
- new security release, fixes timing-based attack on CBC ciphersuites in
SSL and TLS. See: http://www.openssl.org/news/secadv_20030219.txt
- use %mklibname

Wed Jan 15 03:00:00 2003 Frederic Lepied 0.9.7-3mdk
- removed libssl.so.0

Wed Jan 15 03:00:00 2003 Frederic Lepied 0.9.7-2mdk
- conflicts with openssh < 3.5p1-4md

Tue Jan 14 03:00:00 2003 Jean-Michel Dault 0.9.7-1mdk
- new version
- rediff p0 and p2
- remove p3 (what was that for?)

Tue Dec 10 03:00:00 2002 Fran�ois Pons 0.9.6h-1mdk
- rebuild using make instead of %make, sorry this is much faster to fix.
- 0.9.6h.

Fri Aug 16 04:00:00 2002 Christian Belisle 0.9.6g-1mdk
- 0.9.6g
- include md5 signature
- rediff patch2

Fri Aug 2 04:00:00 2002 Frederic Lepied 0.9.6e-1mdk
- removed patch6 (integrated upstream)
- rediff patch3
- split static lib
- 0.9.6e

Thu Jun 27 04:00:00 2002 Thierry Vignaud 0.9.6d-6mdk
- fix err.3 conflict

Tue Jun 25 04:00:00 2002 Gwenole Beauchesne 0.9.6d-5mdk
- Sanitize specfile (factorization)
- Make sure tests are always run and don\'t let them fail
- Patch6: Use -dumpversion to get gcc3 version
- Patch7: Add 64-bit config support

Mon May 27 04:00:00 2002 Yves Duret 0.9.6d-4mdk
- openssl requires libopenssl = 0.9.7g-2.5.20060mdk.
- more spec clean up.
- rpmlint: license is BSD-like as say the LICENSE file instead of the unprecise OpenSource term.

Thu May 23 04:00:00 2002 Christian Belisle 0.9.6d-3mdk
- Fix Requires/BuildRequires.

Fri May 17 04:00:00 2002 Christian Belisle 0.9.6d-2mdk
- Little spec cleanup.

Fri May 17 04:00:00 2002 Christian Belisle 0.9.6d-1mdk
- Release 0.9.6d.
- Remake the patches.

Tue Feb 5 03:00:00 2002 Christian Belisle 0.9.6c-2mdk
- Don\'t apply patch for the SSL ciphers limit.

Tue Jan 22 03:00:00 2002 Christian Belisle 0.9.6c-1mdk
- Release 0.9.6c.
- Remake the patches

Thu Jan 10 03:00:00 2002 Gwenole Beauchesne 0.9.6b-6mdk
- Remove Patch6 as all SSH implementations are required to support
SSH_CIPHER_DES and SSH_CIPHER_3DES. The latter turns out to be
Triple-Key Triple-DES.

Wed Jan 9 03:00:00 2002 Gwenole Beauchesne 0.9.6b-5mdk
- 2 patches to follow French policy:
- Patch5: Limit SSL ciphers available to 128 bits
- Patch6: Temptatively disable triple-key triple DES but keep
double-key triple DES

Thu Dec 6 03:00:00 2001 Christian Belisle 0.9.6b-4mdk
- gzip the source (for the sig file).

Thu Dec 6 03:00:00 2001 Christian Belisle 0.9.6b-3mdk
- Patch for gcc3 (thanks to fcrozat)
- bzip2 the source.

Thu Oct 11 04:00:00 2001 Christian Belisle 0.9.6b-2mdk
- Added missing files (thanx to jacco2_at_dds.nl)

Mon Sep 3 04:00:00 2001 Frederic Lepied 0.9.6b-1mdk
- new version

Fri Jul 13 04:00:00 2001 Stew Benedict 0.9.6a-4mdk
- PPC configure patch

Tue Jun 26 04:00:00 2001 Matthias Badaire 0.9.6a-3mdk
- ia64 patch for configure

Tue May 8 04:00:00 2001 Frederic Lepied 0.9.6a-2mdk
- libopenssl0-devel Obsoletes openssl-devel

Fri May 4 04:00:00 2001 Frederic Lepied 0.9.6a-1mdk
- libification
- 0.9.6a

Sat Mar 24 03:00:00 2001 David BAUDENS 0.9.6-7mdk
- PPC: build with gcc

Fri Mar 23 03:00:00 2001 Pixel 0.9.6-6mdk
- require /usr/bin/perl (aka perl-base) instead of perl

Sat Feb 3 03:00:00 2001 Francis Galiegue 0.9.6-5mdk
- Added patch from RH (ia64 asm stuff)
- ia64 fails at make test, disable it for now

Fri Jan 5 03:00:00 2001 Till Kamppeter 0.9.6-4mdk
- moved /usr/lib/ssl/ directory from the devel package to the main package,
it is needed for creating certificates.

Sat Dec 23 03:00:00 2000 Stefan van der Eijk 0.9.6-3mdk
- fixed %ifarch statement ( %alpha --> alpha)
- fixed perl replace statement (alpha)

Thu Dec 21 03:00:00 2000 David BAUDENS 0.9.6-2mdk
- PPC: build with egcs. Compilation doesn\'t failed with gcc-2.96 but
\"make test\" does. So...
- Use optimizations on all archs supported by LMDK
- Some spec clean up

Sun Dec 3 03:00:00 2000 Geoffrey Lee 0.9.6-1mdk
- new and shiny source.

Mon Oct 2 04:00:00 2000 Frederic Lepied 0.9.5a-8mdk
- added BuildRequires on bc.

Mon Sep 25 04:00:00 2000 Alexander Skwar 0.9.5a-7mdk
- As suggested by Chmou,
*all
* man pages for ssl are beneath
/usr/share/man, but the offending man pages (rand.3 and passwd.1) have been
renamed to ssl-rand.3 and ssl-passwd.1
- Added README.Mandrake-manpage to warn/inform users about the conflicting
man pages
- Removed de and fr summaries and decriptions

Mon Sep 25 04:00:00 2000 Alexander Skwar 0.9.5a-6mdk
- bzip2 the man pages

Mon Sep 25 04:00:00 2000 Alexander Skwar 0.9.5a-5mdk
- Re-add the man pages, which were left out in -4mdk
- Man pages in /usr/lib/ssl as passwd.1 conflicts with the man page for passwd from
the package passwd and because rand.3 conflicts with rand.3 from man-pages
- Some more clean up
- More doc files

Sat Sep 23 04:00:00 2000 Alexander Skwar 0-9-5a-4mdk
- Use macros
- Doc\'s in /usr/share/doc
- Man pages in /usr/share/man, no longer \"hidden\" in /usr/lib/ssl/man
- Quiet setup
- Clean up a lot (chmou).

Thu May 25 04:00:00 2000 Frederic Lepied 0.9.5a-3mdk
- corrected configure on sparc.

Tue May 9 04:00:00 2000 Jean-Michel Dault 0.9.5a-3mdk
- forgot libcrypto.a in devel (DOH!) Put it back again

Fri Apr 28 04:00:00 2000 Jean-Michel Dault 0.9.5a-2mdk
- mv /usr/local/ssl to /usr/lib/ssl

Thu Apr 27 04:00:00 2000 Jean-Michel Dault 0.9.5a-1mdk
- re-did package for 0.9.5a

Wed Mar 1 03:00:00 2000 Jean-Michel Dault 0.9.5-1mdk
- updated to 0.9.5

Sun Feb 27 03:00:00 2000 Jean-Michel Dault 0.9.4-9mdk
- removed brokenmips and linux.sh search&replace because they are
not in the source anymore

Tue Jan 4 03:00:00 2000 Jean-Michel Dault
- final cleanup for Mandrake 7

Fri Dec 31 03:00:00 1999 Jean-Michel Dault
- rebuild on 7.0

Sun Aug 15 04:00:00 1999 Jean-Michel Dault
- updated to 0.9.4
- cleaned SPEC file to compile on Solaris/UltraSparc
- added SSL_USE_SDBM to avoid segfaults

Sun Aug 1 04:00:00 1999 Jean-Michel Dault
- made a link from openssl to ssleay because many sites have old
documentation

Fri Jul 23 04:00:00 1999 Jean-Michel Dault
- added fr summary

Fri Jun 25 04:00:00 1999 Bernhard Rosenkr�nzer
- permit SMP build

Sun May 30 04:00:00 1999 Jean-Michel Dault
- updated to 0.9.3a
- added fr locale

Mon May 24 04:00:00 1999 Bernhard Rosenkr�nzer
- handle RPM_OPT_FLAGS
- add de locale

Sun May 23 04:00:00 1999 Jean-Michel Dault
Updated the compiler flags

Sat May 22 04:00:00 1999 Jean-Michel Dault
Packaged for Linux-Mandrake

Tue May 18 04:00:00 1999 Henri Gomez
BIO_set_fp patch added. (no more core under RH6.0).
Correct rm -rf of /var/tmp

Tue Mar 23 03:00:00 1999 rse
- function names recently changed - consistency.

- Be consistent: 0.9.2b

Tue Mar 23 03:00:00 1999 Ben Laurie, problem pointed out by Holger Reif, Bodo Moeller (and ???)
- Fix security hole.

Sun Mar 21 03:00:00 1999 Ulf Moeller
- Some more source tree cleanups (removed obsolete files
crypto/bf/asm/bf586.pl, test/test.txt and crypto/sha/asm/f.s; changed
permission on \"config\" script to be executable) and a fix for the
INSTALL document. Submitted by: Ulf Moeller Reviewed
by: Ralf S. Engelschall

Mon Mar 15 03:00:00 1999 Lennart Bang , with minor changes by Steve
- Remove some references which called malloc and free instead of Malloc
and Free.

Sat Mar 13 03:00:00 1999 Ulf Moeller
- Fail if test fails.

Sat Mar 13 03:00:00 1999 Matthias Loepfe
- Solaris shared library support.

Sat Mar 13 03:00:00 1999 Ben Laurie
- Use the right compiler for ctx_size.

Sat Mar 13 03:00:00 1999 Steve Henson
- Delete NULL ciphers from \'ALL\' in the cipher list aliases. This means
that NULL ciphers specifically have to be enabled with e.g.
\"DEFAULT:eNULL\". This prevents cipher lists from inadvertantly having
NULL ciphers at the top of their list (e.g. the default ones) because
they didn\'t have to be taken into account before.

Fri Mar 12 03:00:00 1999 Steve Henson
- Fix for RSA private key encryption if p < q. This took
*
*
*ages
*
*
* to
track down.

Thu Mar 11 03:00:00 1999 Matthias Loepfe
- Be less restrictive and allow also `perl util/perlpath.pl
/path/to/bin/perl\' in addition to `perl util/perlpath.pl /path/to/bin\',
because this way one can also use an interpreter named `perl5\' (which
is usually the name of Perl 5.xxx on platforms where an Perl 4.x is
still installed as `perl\'). Submitted by: Matthias Loepfe
Reviewed by: Ralf S. Engelschall
- Let util/clean-depend.pl work also with older Perl 5.00x versions.
Submitted by: Matthias Loepfe Reviewed by:
Ralf S. Engelschall

Thu Mar 11 03:00:00 1999 Steve Henson
- Fix couple of ANSI declarations and prototypes

Thu Mar 11 03:00:00 1999 steve
- Make CC,CFLAG etc get passed to make links and various Win32 fixes.

Wed Mar 10 03:00:00 1999 Ben Laurie
- Fix quad checksum bug.

Wed Mar 10 03:00:00 1999 Steve Henson
- Comment out two unimplemented functions from bio.h. Attempt to get
the Win32 test batch file going again.

Tue Mar 9 03:00:00 1999 steve
- Add missing funtions from non ANSI section of header files and add
missing ordinals to libeay.num.

Tue Mar 9 03:00:00 1999 Ralf S. Engelschall
- Make `openssl version\' output lines consistent.
- Fix Win32 symbol export lists for BIO functions: Added
BIO_get_ex_new_index, BIO_get_ex_num, BIO_get_ex_data and
BIO_set_ex_data to ms/libeay{16,32}.def. I\'m not a Win32 hacker, but I
think I\'ve done it correctly. Steve or Ben: can you confirm that
it\'s correct? I don\'t want to break any Win32 stuff.
- Second round of fixing the OpenSSL perl/ stuff. It now at least
compiled fine under Unix and passes some trivial tests I\'ve now added.
But the whole stuff is horribly incomplete, so a README.1ST with a
disclaimer was added to make sure no one expects that this stuff really
works in the OpenSSL 0.9.2 release. Additionally I\'ve started to clean
the XS sources up and fixed a few little bugs and inconsistencies in
OpenSSL.{pm,xs} and openssl_bio.xs. PS: I\'m still not convinces
whether we should try to make this finally running or kick it out and
replace it with some other module....

Mon Mar 8 03:00:00 1999 ben
- Don\'t make links on Windoze.

Mon Mar 8 03:00:00 1999 Kenji Miyake , integrated by Ben Laurie
- Fix perl assembler.

Mon Mar 8 03:00:00 1999 John Tobey
- Linux MIPS support.

Mon Mar 8 03:00:00 1999 Ben Laurie
- Always make links.

Sun Mar 7 03:00:00 1999 steve
- Added support for adding extensions to CRLs, also fix a memory leak
and make \'req\' check the config file syntax before it adds extensions.
Added info in the documentation as well.

Sun Mar 7 03:00:00 1999 Ralf S. Engelschall
- Add a useful kludge to allow package maintainers to specify compiler
and other platforms details on the command line without having to patch
the Configure script everytime: One now can use ``perl Configure
:
\'\', i.e. platform ids are allowed to have details
appended to them (seperated by colons). This is treated as there would
be a static pre-configured entry in Configure\'s %table under key
with value
and ``perl Configure \'\' is called. So, when
you want to perform a quick test-compile under FreeBSD 3.1 with pgcc
and without assembler stuff you can use ``perl Configure
\"FreeBSD-elf:pgcc:-O6:::\"\'\' now, which overrides the FreeBSD-elf entry
on-the-fly. (PS: Notice that the same effect _cannot_ be achieved
by using ``make CC=pgcc ..\'\' etc, because you cannot override all
things from there.)

Sun Mar 7 03:00:00 1999 Ben Laurie
- Disable new TLS1 ciphersuites.

Sun Mar 7 03:00:00 1999 Ralf S. Engelschall
- Allow DSO flags like -fpic, -fPIC, -KPIC etc. to be specified on the
`perl Configure ...\' command line. This way one can compile OpenSSL
libraries with Position Independent Code (PIC) which is needed for
linking it into DSOs.

Sun Mar 7 03:00:00 1999 Ben Laurie
- Fix export ciphersuites, again.

Sun Mar 7 03:00:00 1999 rse
- just a little typo

Sun Mar 7 03:00:00 1999 Ralf S. Engelschall
- Cleaned up the LICENSE document: The official contact for any license
questions now is the OpenSSL core team under openssl-coreAATTopenssl.org.
And add a paragraph about the dual-license situation to make sure
people recognize that _BOTH_ the OpenSSL license _AND_ the SSLeay
license apply to the OpenSSL toolkit.
- General source tree makefile cleanups: Made `making xxx in yyy...\'
display consistent in the source tree and replaced `/bin/rm\' by `rm\'.
Additonally cleaned up the `make links\' target: Remove unnecessary
semicolons, subsequent redundant removes, inline point.sh into
mklink.sh to speed processing and no longer clutter the display with
confusing stuff. Instead only the actually done links are displayed.

Sun Mar 7 03:00:00 1999 Ben Laurie
- Permit null ciphers.

Sat Mar 6 03:00:00 1999 Steve Henson
- Fix the PKCS#7 stuff: signature verify could fail if attributes
reordered, the detached data encoding was wrong and free up public keys.

Sat Mar 6 03:00:00 1999 steve
- Workaround for a Win95 console bug triggered by the password read
stuff.

Fri Mar 5 03:00:00 1999 Steve Henson
- Deleted my str_dup() function from X509V3: the same functionality is
provided by BUF_MEM_strdup(). Added text documentation to the BUF_MEM
stuff.

Fri Mar 5 03:00:00 1999 Ralf S. Engelschall
- Added the new `Includes OpenSSL Cryptography Software\' button as
doc/openssl_button.{gif,html} which is similar in style to the old
SSLeay button and can be used by applications based on OpenSSL to show
the relationship to the OpenSSL project. PS: This beast caused me
three hours to create, because of the size I had to hand-paint the 7pt
fonts in Photoshop.

Fri Mar 5 03:00:00 1999 Lennart Bong
- Remove confusing variables in function signatures in files
ssl/ssl_lib.c and ssl/ssl.h. At least the double ctx-variable confused
some compilers. Submitted by: Lennart Bong
Reviewed by: Ralf S. Engelschall
- Don\'t install bss_file.c under PREFIX/include/. It was introduced by
Eric between SSLeay 0.8 and 0.9 and just looks useless and confusing.
Pointed out by: Lennart Bong Submitted
by: Ralf S. Engelschall

Thu Mar 4 03:00:00 1999 Steve Henson
- Fix the Win32 compile environment and add various changes so it will
now compile under Win32 (9X and NT) again. Note: some signed/unsigned
changes recently checked in were killing the Win32 compile.

Mon Mar 1 03:00:00 1999 Ben Laurie
- Add functions to add certs to stacks, used for CA file/path stuff in
servers.
- Experiment with doxygen documentation.

Sun Feb 28 03:00:00 1999 Ralf S. Engelschall, pointed out by Carlos Amengual
- Get rid of remaining C++-style comments which strict C compilers
hate. (Pointed out by Carlos Amengual).

Sat Feb 27 03:00:00 1999 Steve Henson
- BN_RECURSION causes the stuff in bn_mont.c to fall over for large
keys. For now change it to BN_RECURSION_MONT so it isn\'t compiled in.

Fri Feb 26 03:00:00 1999 Ralf S. Engelschall
- Add a bunch of SSL_xxx() functions for configuring the temporary RSA
and DH private keys and/or callback functions which directly correspond
to their SSL_CTX_xxx() counterparts but work on a per-connection basis.
This is needed for applications which have to configure certificates on
a per-connection basis (e.g. Apache+mod_ssl) instead of a per-context
basis (e.g. s_server). For the RSA certificate situation is makes
no difference, but for the DSA certificate situation this fixes the \"no
shared cipher\" problem where the OpenSSL cipher selection procedure
failed because the temporary keys were not overtaken from the context
and the API provided no way to reconfigure them. The new functions
now let applications reconfigure the stuff and they are in detail:
SSL_need_tmp_RSA, SSL_set_tmp_rsa, SSL_set_tmp_dh,
SSL_set_tmp_rsa_callback and SSL_set_tmp_dh_callback. Additionally a
new non-public-API function ssl_cert_instantiate() is used as a helper
function and also to reduce code redundancy inside ssl_rsa.c.
Submitted by: Ralf S. Engelschall Reviewed by: Ben Laurie
- Move s_server -dcert and -dkey options out of the undocumented
feature area because they are useful for the DSA situation and should
be recognized by the users. Thanks to Steve for the original hint.

Fri Feb 26 03:00:00 1999 Richard Levitte
- Fix the cipher decision scheme for export ciphers: the export bits
are
*not
* within SSL_MKEY_MASK or SSL_AUTH_MASK, they are within
SSL_EXP_MASK. So, the original variable has to be used instead of the
already masked variable. Submitted by: Richard Levitte
Reviewed by: Ralf S. Engelschall
- Fix \'port\' variable from `int\' to `unsigned int\' in
crypto/bio/b_sock.c Submitted by: Richard Levitte
Reviewed by: Ralf S. Engelschall
- Change type of another md_len variable in
pk7_doit.c:PKCS7_dataFinal() from `int\' to `unsigned int\' because it\'s
a length and initialized by EVP_DigestFinal() which expects an
`unsigned int
*\'. Submitted by: Richard Levitte
Reviewed by: Ralf S. Engelschall

Fri Feb 26 03:00:00 1999 Ralf S. Engelschall
- Don\'t hard-code path to Perl interpreter on shebang line of Configure
script. Instead use the usual Shell->Perl transition trick.

Thu Feb 25 03:00:00 1999 Ralf S. Engelschall
- Make `openssl x509 -noout -modulus\' functional also for DSA
certificates (in addition to RSA certificates) to match the behaviour
of `openssl dsa -noout -modulus\' as it\'s already the case for `openssl
rsa -noout -modulus\'. For RSA the -modulus is the real \"modulus\" while
for DSA currently the public key is printed (a decision which was
already done by `openssl dsa -modulus\' in the past) which serves a
similar purpose. Additionally the NO_RSA no longer completely removes
the whole -modulus option; it now only avoids using the RSA stuff. Same
applies to NO_DSA now, too.

Wed Feb 24 03:00:00 1999 Arne Ansper
- Add reliable BIO.

Wed Feb 24 03:00:00 1999 Steve Henson
- Redo the way \'req\' and \'ca\' add objects: add support for oid_section.

Tue Feb 23 03:00:00 1999 Arne Ansper , integrated by Ben Laurie
- Add syslogging BIO.

Mon Feb 22 03:00:00 1999 Ben Laurie
- Add support for new TLS export ciphersuites.

Mon Feb 22 03:00:00 1999 Steve Henson
- Add preliminary user level config documentation for extension stuff.
Programming info will come later... Feel free to reformat and tidy
this up...

Mon Feb 22 03:00:00 1999 Ulf Moeller
- Make RSA_NO_PADDING really use no padding. Submitted by: Ulf
Moeller

Sun Feb 21 03:00:00 1999 Ben Laurie
- Generate errors when public/private key check is done.

Sat Feb 20 03:00:00 1999 Steve Henson
- Overhaul \'crl\' application, add a proper X509_CRL_print function and
start to support CRL extensions.

Thu Feb 18 03:00:00 1999 Steve Henson
- Fuller authority key id support, partial support for private key
usage extension and really fix the ASN.1 IMPLICIT bug this time :-)

Thu Feb 18 03:00:00 1999 Ulf Moeller , reformatted, corrected and integrated by
+ Ben Laurie
- Add OAEP.

Wed Feb 17 03:00:00 1999 Eric A. Young, (from changes to C2Net SSLeay, integrated by Mark Cox)
- Updates to the new SSL compression code [Eric A. Young, (from changes
to C2Net SSLeay, integrated by Mark Cox)] Fix so that the version
number in the master secret, when passed via RSA, checks that if TLS
was proposed, but we roll back to SSLv3 (because the server will not
accept higher), that the version number is 0x03,0x01, not 0x03,0x00
[Eric A. Young, (from changes to C2Net SSLeay, integrated by Mark Cox)]
Submitted by: Reviewed by: PR:

Tue Feb 16 03:00:00 1999 Steve Henson
- Fix various memory leaks in SSL, apps and DSA

Mon Feb 15 03:00:00 1999 steve
- Add support for raw extensions. This means that you can include the
DER encoding of an arbitrary extension: e.g.
1.3.4.5=critical,RAW:12:34:56 Using this technique currently
unsupported extensions can be generated if you know their DER encoding.
Even if the extension is supported in future the raw extension will
still work: that is the raw version can always be used even if it is a
supported extension.

Mon Feb 15 03:00:00 1999 Lars Weber <3weberAATTinformatik.uni-hamburg.de>
- Make sure latest Perl versions don\'t interpret some generated C array
as Perl array code in the crypto/err/err_genc.pl script. Submitted
by: Lars Weber <3weberAATTinformatik.uni-hamburg.de> Reviewed by: Ralf s.
Engelschall

Mon Feb 15 03:00:00 1999 Steve Henson
- More Win32 fixes and upsdate INSTALL.W32 documentation.

Sun Feb 14 03:00:00 1999 Steve Henson
- Oops... add other changes this time too.

Sun Feb 14 03:00:00 1999 Ben Laurie
- Fix ghastly DES declarations, and all consequential warnings.

Sun Feb 14 03:00:00 1999 Steve Henson
- Fix typo in asn1.h (PRINTABLESTRING_STRING) and fix a bug in object
creation perl script. It failed if the OID had any zeros in it.

Sun Feb 14 03:00:00 1999 Ben Laurie
- Add support for 3DES CBCM mode.
- In the absence of feedback either way, commit the fix that looks
right for wrong keylength with export null ciphers.

Fri Feb 12 03:00:00 1999 steve
- Make the \'crypto\' and \'ssl\' options in the perl script mkdef.pl
really work, also add an \'update\' option to automatically append any
new functions to the ssleay.num and libeay.num files.

Thu Feb 11 03:00:00 1999 Ralf S. Engelschall
- Overhauled the Perl interface (perl/
*):

* ported BN stuff to OpenSSL\'s different BN library

* made the perl/ source tree CVS-aware

* renamed the package from SSLeay to OpenSSL (the files still contain
their history because I\'ve copied them in the repository)

* removed obsolete files (the test scripts will be replaced by better
Test::Harness variants in the future)
- Remember the cleanup

Thu Feb 11 03:00:00 1999 Steve Henson
- More extension code. Incomplete support for subject and issuer alt
name, issuer and authority key id. Change the i2v function parameters
and add an extra \'crl\' parameter in the X509V3_CTX structure: guess
what that\'s for :-) Fix to ASN1 macro which messed up IMPLICIT tag and
add f_enum.c which adds a2i, i2a for ENUMERATED.

Wed Feb 10 03:00:00 1999 Steve Henson
- Support for ASN1 ENUMERATED type. This copies and duplicates the
ASN1_INTEGER code and adds support to ASN1_TYPE and asn1parse.

Mon Feb 1 03:00:00 1999 Eric A. Young, (from changes to C2Net SSLeay, integrated by Mark Cox)
- Add new function, EVP_MD_CTX_copy() to replace frequent use of
memcpy. Submitted by: Eric A Young - from changes to C2Net SSLeay
Reviewed by: Mark Cox PR:

Mon Feb 1 03:00:00 1999 Ralf S. Engelschall, Matthias Loepfe
- Make sure `make rehash\' target really finds the `openssl\' program.

Sun Jan 31 03:00:00 1999 Ben Laurie
- Squeeze a bit more speed out of MD5 assembler.

Sun Jan 31 03:00:00 1999 Alan Batie
- Add CygWin32 platform information to Configure script. Submitted
by: Alan Batie

Sun Jan 31 03:00:00 1999 Rainer W. Gerling
- Fixed ms/32all.bat script: `no_asm\' -> `no-asm\' Submitted by:
Rainer W. Gerling Reviewed by: Ralf S.
Engelschall

Sat Jan 30 03:00:00 1999 Steve Henson
- New program \'nseq\' added to apps to allow Netscape certificate
sequences to be pulled apart and built.
- Allow the -certfile argument to be used multiple times in crl2pkcs7.
Also fix typos in the usage messages: \"inout\" instead of \"input\".

Fri Jan 29 03:00:00 1999 Eric A. Young, (from changes to C2Net SSLeay, integrated by Mark Cox)
- Fixes to BN code. Previously the default was to define BN_RECURSION
but the BN code had some problems that would cause failures when doing
certificate verification and some other functions. Submitted by:
Eric A Young from a C2Net version of SSLeay Reviewed by: Mark J Cox PR:

Fri Jan 29 03:00:00 1999 Steve Henson
- Add ASN1 code for netscape certificate sequences.

Wed Jan 27 03:00:00 1999 Steve Henson
- Add a few extended key usage OIDs.
- Still more X509 V3 stuff. Modify ca.c to work with the new code and
modify openssl.cnf for the new syntax.

Tue Jan 26 03:00:00 1999 Steve Henson
- More X509 V3 stuff. Add support for extensions in the \'req\'
application so that: openssl req -x509 -new -out cert.pem will take
extensions from openssl.cnf a sample for a CA is included. Also change
the directory order so pem is nearer the end. Otherwise \'make links\'
wont work because pem.h can\'t be built.

Mon Jan 25 03:00:00 1999 steve
- Continuing adding X509 V3 support. This starts to integrate the code
with the main library, but only with printing at present. To see this
try: openssl x509 -in cert.pem -text on a certificate with some
extensions in it.

Mon Jan 25 03:00:00 1999 Steve Henson
- Initial addition of new X509 V3 files, tidy of old files.

Thu Jan 21 03:00:00 1999 Steve Henson
- Continued patches so certificates and CRLs now can support and use
GeneralizedTime.

Wed Jan 20 03:00:00 1999 Ben Laurie
- Finally lay dependencies to rest (I hope!).

Wed Jan 20 03:00:00 1999 Ben Laurie, reported by Jeremy Hylton
- Spelling mistake.

Tue Jan 19 03:00:00 1999 steve
- New err_code.pl script to retain old error codes. This should allow
the use of \'make errors\' without causing huge re-organisations of files
when a new code is added.

Mon Jan 18 03:00:00 1999 Ulf M�ller
- Fix major cockup with short keys in CAST-128.

Mon Jan 18 03:00:00 1999 Steve Henson
- Update CHANGES for GeneralizedTime info.

Mon Jan 18 03:00:00 1999 Ulf M�ller
- Correct Linux 1 recognition. Contributed by: Ulf M�ller

Mon Jan 18 03:00:00 1999 Anonymous
- Remove pointless MD5 hash. Contributed by: Anonymous


Mon Jan 18 03:00:00 1999 Ben Laurie, reported by Anonymous
- Generate an error on an invalid directory.

Sun Jan 17 03:00:00 1999 Ben Laurie
- More prototypes.

Fri Jan 15 03:00:00 1999 Steve Henson
- Fix parameters to dummy function BN_ref_mod_exp().

Fri Jan 15 03:00:00 1999 Neil Costigan
- Submitted by: Neil Costigan PR:

Wed Jan 13 03:00:00 1999 Steve Henson
- Fix OBJ_txt2nid(): old function was broken when input used the \"dot\"
form, e.g. 1.2.3.4 . Also added new function OBJ_txt2obj().

Mon Jan 11 03:00:00 1999 Ben Laurie
- Add prototype, fix parameter passing bug.

Sun Jan 10 03:00:00 1999 Ben Laurie
- Sort openssl functions by name.

Sun Jan 10 03:00:00 1999 Steve Henson
- Fix the gendsa program and add it to the app list. The progs.h file
is auto generated but not auto updated so it is included. Also remove
the encryption from the sample DSA keys.

Fri Jan 8 03:00:00 1999 Frans Heymans
- Accept NULL in
*_free.

Fri Jan 8 03:00:00 1999 Anonymous
- Fix DH key generation. Contributed by: Anonymous

Fri Jan 8 03:00:00 1999 Bodo Moeller <3moellerAATTinformatik.uni-hamburg.de>
- Send the right CAs to the client.
- Fix numeric -newkey args. Contributed by: Bodo Moeller
<3moellerAATTinformatik.uni-hamburg.de>

Thu Jan 7 03:00:00 1999 Anonymous
- Fix export tests.

Thu Jan 7 03:00:00 1999 Ben Laurie
- Make the world a safer place (if people object to this kind of
change, speak up soon - I intend to do a lot of it!).

Thu Jan 7 03:00:00 1999 Steve Henson
- Oops! update CHANGES file properly.

Thu Jan 7 03:00:00 1999 steve
- Fix things so DH_free() will be no-op when passed NULL, like
RSA_free() and DSA_free(): this was causing crashes when for example an
attempt was made to handle a (currently) unsupported DH public key.
Also X509_PUBKEY_set()i wasn\'t checking errors from d2i_PublicKey().

Tue Jan 5 03:00:00 1999 Arne Ansper
- Free the right thing.
- Only free if it ain\'t NULL.
- Remove the bugfix that was really a bug. Submitted by: Arne Ansper

- Pass on BIO_CTRL_FLUSH. Submitted by: Arne Ansper

Mon Jan 4 03:00:00 1999 Ralf S. Engelschall
- Make sure the already existing X509_STORE->depth variable is
initialized in X509_STORE_new(), but document the fact that this
variable is still unused in the certificate verification process.

Mon Jan 4 03:00:00 1999 Steve Henson
- Make sure applications free up pkey structures and add netscape
extension handling to x509.c

Sun Jan 3 03:00:00 1999 Ralf S. Engelschall, Paul Sutton and Ben Laurie
- Fix reference counting.

Sun Jan 3 03:00:00 1999 Ralf S. Engelschall
- First cut of a cleanup for apps/. First the `ssleay\' program is now
named `openssl\' and second, the shortcut symlinks for the `openssl
\' are no longer created. This way we have a single and
consistent command line interface `openssl \', similar to `cvs
\'. Notice, the openssl.cnf, openssl.c and progs.pl files
were changed after a repository copy, i.e. they still contain the
complete file history.

Sun Jan 3 03:00:00 1999 Steve Henson
- Move DSA test in ca.c inside #ifdef and make pubkey BIT STRING always
have zero unused bits.

Sat Jan 2 03:00:00 1999 Steve Henson
- Add extended key usage OID and update STATUS file.

Sat Jan 2 03:00:00 1999 Paul Sutton
- Make the installation documentation easier to follow.

- Makefiles updated to exit if an error occurs in a sub-directory make
(including if user presses ^C)

Fri Jan 1 03:00:00 1999 Ben Laurie
- Document recent changes.

Fri Jan 1 03:00:00 1999 rse
- Fix version stuff: 1. The already released version was 0.9.1c and
not 0.9.1b 2. The next release should be 0.9.2 and not 0.9.1d,
because first the changes are already too large, second we should avoid
any more 0.9.1x confusions and third, the Apache version semantics of
VERSION.REVISION.PATCHLEVEL for the version string is reasonable (and
here .2 is already just a patchlevel and not major change). tVS:
----------------------------------------------------------------------

Fri Jan 1 03:00:00 1999 Steve Henson
- Update CHANGES file for latest additions

Thu Dec 31 03:00:00 1998 Ben Laurie - pointed out by Ulf M�ller
- MIME encoding and ISO chars at the same time messes up the stuff

Thu Dec 31 03:00:00 1998 Ralf S. Engelschall
- Ops, forgot to commit the changes entry in recent commit...

Wed Dec 30 03:00:00 1998 Ben Laurie
- Fix incorrect DER encoding of SETs and all knock-ons from that.

Wed Dec 30 03:00:00 1998 Ben Laurie - pointed out by Ulf M�ller
- Add prototypes. Make Montgomery stuff explicitly for that purpose.

Tue Dec 29 03:00:00 1998 Ben Laurie
- Deal with generated files.

Tue Dec 29 03:00:00 1998 ben
- Typo.

Tue Dec 29 03:00:00 1998 Ben Laurie
- Autodetect FreeBSD 3.

- Add strictness, fix variable substition bugs.

Sun Dec 27 03:00:00 1998 rse
- Test for new CVS repository

Thu Dec 24 03:00:00 1998 The OpenSSL Project
- Switch to OpenSSL name

Wed Dec 23 03:00:00 1998 Ralf S. Engelschall, Beckmann
- Incorporation of RSEs assembled patches


 
ICM