Changelog for
stunnel-doc-5.44-lp150.3.2.noarch.rpm :
* Tue Feb 06 2018 vetterAATTphysik.uni-wuerzburg.de- Revamp SLE11 builds
* Thu Feb 01 2018 jengelhAATTinai.de- Do not ignore errors from useradd. Ensure nogroup exists beforehand.- Replace old $RPM_ variables. Combine two nested ifs.
* Wed Jan 24 2018 avindraAATTopensuse.org- update to version 5.44
* Default accept address restored to INADDR_ANY
* Fix race condition in \"make check\"
* Fix removing the pid file after configuration reload- includes 5.43
* Allow for multiple \"accept\" ports per section
* Self-test framework (make check)
* Added config load before OpenSSL init
* OpenSSL 1.1.1-dev compilation fixes
* Fixed round-robin failover in the FORK threading model
* Fixed handling SSL_ERROR_ZERO_RETURN in SSL_shutdown()
* Minor fixes of the logging subsystem
* OpenSSL DLLs updated to version 1.0.2m- add new checking to build- rebase stunnel-listenqueue-option.patch- Cleanup with spec-cleaner
* Thu Nov 23 2017 rbrownAATTsuse.com- Replace references to /var/adm/fillup-templates with new %_fillupdir macro (boo#1069468)
* Thu Aug 17 2017 vetterAATTphysik.uni-wuerzburg.de- add more verbose change log: Version 5.42, 2017.07.16, urgency: HIGH- New features
* \"redirect\" also supports \"exec\" and not only \"connect\".
* PKCS#11 engine DLL updated to version 0.4.7.- Bugfixes
* Fixed premature cron thread initialization causing hangs.
* Fixed \"verifyPeer = yes\" on OpenSSL <= 1.0.1.
* Fixed pthreads support on OpenSolaris.
* Wed Jul 19 2017 michaelAATTstroeder.com- update to version 5.42
* Thu Apr 06 2017 wernerAATTsuse.de- Require package config for libsystemd to help the configure script to detect and enable systemd socket activation (boo#1032557)- Refresh patch stunnel-listenqueue-option.patch
* Sat Apr 01 2017 michaelAATTstroeder.com- update to version 5.41
* Fri Feb 10 2017 kukukAATTsuse.de- Don\'t require insserv if we don\'t use it
* Sat Jan 28 2017 michaelAATTstroeder.com- update to version 5.40
* Mon Jan 02 2017 michaelAATTstroeder.com- update to version 5.39
* Thu Dec 08 2016 michaelAATTstroeder.com- update to version 5.38
* Sun Oct 16 2016 jengelhAATTinai.de- Update rpm group and description and make -doc noarch- Do not suppress errors from useradd- Remove redundant %clean section
* Fri Oct 14 2016 drahnAATTsuse.com- update to version 5.36- Removed direct zlib dependency.
* Wed Sep 21 2016 drahnAATTsuse.com- update to version 5.35- repackage source as bz2- adjust systemd unit file to start after network-online.target- bugixes:
* Fixed incorrectly enforced client certificate requests.
* Fixed thread safety of the configuration file reopening.
* Fixed malfunctioning \"verify = 4\".
* Only reset the watchdog if some data was actually transferred.
* Fixed logging an incorrect value of the round-robin starting point (thx to Jose Alf.).- new features:
* Added three new service-level options: requireCert, verifyChain, and verifyPeer for fine-grained certificate verification control.
* SNI support also enabled on OpenSSL 0.9.8f and later (thx to Guillermo Rodriguez Garcia).
* Added support for PKCS #12 (.p12/.pfx) certificates (thx to Dmitry Bakshaev).
* New \"socket = a:IPV6_V6ONLY=yes\" option to only bind IPv6.
* Added logging the list of client CAs requested by the server.
* Wed Feb 03 2016 michaelAATTstroeder.com- update to 5.30 New features Improved compatibility with the current OpenSSL 1.1.0-dev tree. Added OpenSSL autodetection for the recent versions of Xcode. Bugfixes Fixed references to /etc removed from stunnel.init.in. Stopped even trying -fstack-protector on unsupported platforms (thx to Rob Lockhart).
* Wed Jan 20 2016 opensuseAATTdstoecker.de- update to 5.29- system script restarts stunnel after a crash- readd rcstunnel macro for systemd systems- drop stunnel-ocsp-host.patch (included upstream)
* Thu Aug 06 2015 drahnAATTsuse.com- stunnel-ocsp-host.patch: Fix compatibility issues with older OpenSSL versions. Replaces stunnel-5.22-code11-openssl-compat.diff.
* Fri Jul 31 2015 drahnAATTsuse.com- update to version 5.22 New features - \"OCSPaia = yes\" added to the configuration file templates. - Improved double free detection. Bugfixes - Fixed a number of OCSP bugs. The most severe of those bugs caused stunnel to treat OCSP responses that failed OCSP_basic_verify() checks as if they were successful. - Fixed the passive IPv6 resolver (broken in stunnel 5.21).- Remove executable bit from sample scripts- stunnel-5.22-code11-openssl-compat.diff: Compatibility for openssl on CODE11
* Tue Jul 28 2015 drahnAATTsuse.com- update to version 5.21 New features - Signal names are displayed instead of numbers. - First resolve IPv4 addresses on passive resolver requests. - More elaborate descriptions were added to the warning about using \"verify = 2\" without \"checkHost\" or \"checkIP\". - Performance optimization was performed on the debug code. Bugfixes - Fixed the FORK and UCONTEXT threading support. - Fixed \"failover=prio\" (broken since stunnel 5.15). - Added a retry when sleep(3) was interrupted by a signal in the cron thread scheduler.
* Tue Jul 14 2015 drahnAATTsuse.com- update to version 5.20 New features - The SSL library detection algorithm was made a bit smarter. - Warnings about insecure authentication were modified to include the name of the affected service section. - Documentation updates (closes Debian bug #781669). Bugfixes - Signal pipe reinitialization added to prevent turning the main accepting thread into a busy wait loop when an external condition breaks the signal pipe. This bug was found to surface on Win32, but other platforms may also be affected. - Generated temporary DH parameters are used for configuration reload instead of the static defaults. - Fixed the manual page headers (thx to Gleydson Soares).
* Mon Jun 29 2015 drahnAATTsuse.com- update to version 5.19 Bugfixes: - Improved socket error handling. - Fixed handling of dynamic connect targets. - Fixed handling of trailing whitespaces in the Content-Length header of the NTLM authentication. - Fixed memory leaks in certificate verification. New features: - The \"redirect\" option was improved to not only redirect sessions established with an untrusted certificate, but also sessions established without a client certificate. - Randomize the initial value of the round-robin counter. - Added \"include\" configuration file option to include all configuration file parts located in a specified directory. - Temporary DH parameters are refreshed every 24 hours, unless static DH parameters were provided in the certificate file. - Warnings are logged on potentially insecure authentication.- stunnel-listenqueue-option.patch: Refresh.- stunnel3-binpath.patch: Obsolete, dropped.- stunnel.service: Modified to start after network.target, not syslog.target.
* Wed Jan 14 2015 michaelAATTstroeder.com- Update to version 5.09 Version 5.09, 2015.01.02, urgency: LOW:
* New features - Added PSK authentication with two new service-level configuration file options \"PSKsecrets\" and \"PSKidentity\". - Added additional security checks to the OpenSSL memory management functions. - Added support for the OPENSSL_NO_OCSP and OPENSSL_NO_ENGINE OpenSSL configuration flags. - Added compatibility with the current OpenSSL 1.1.0-dev tree.
* Bugfixes - Removed defective s_poll_error() code occasionally causing connections to be prematurely closed (truncated). This bug was introduced in stunnel 4.34. - Fixed ./configure systemd detection (thx to Kip Walraven). - Fixed ./configure sysroot detection (thx to Kip Walraven). - Fixed compilation against old versions of OpenSSL. - Removed outdated French manual page. Version 5.08, 2014.12.09, urgency: MEDIUM:
* New features - Added SOCKS4/SOCKS4a protocol support. - Added SOCKS5 protocol support. - Added SOCKS RESOLVE [F0] TOR extension support. - Updated automake to version 1.14.1. - OpenSSL directory searching is now relative to the sysroot.
* Bugfixes - Fixed improper hangup condition handling. - Fixed missing -pic linker option. This is required for Android 5.0 and improves security. Version 5.07, 2014.11.01, urgency: MEDIUM:
* New features - Several SMTP server protocol negotiation improvements. - Added UTF-8 byte order marks to stunnel.conf templates. - DH parameters are no longer generated by \"make cert\". The hardcoded DH parameters are sufficiently secure, and modern TLS implementations will use ECDH anyway. - Updated manual for the \"options\" configuration file option. - Added support for systemd 209 or later. - New --disable-systemd ./configure option. - setuid/setgid commented out in stunnel.conf-sample.
* Bugfixes - Added support for UTF-8 byte order mark in stunnel.conf. - Compilation fix for OpenSSL with disabled SSLv2 or SSLv3. - Non-blocking mode set on inetd and systemd descriptors. - shfolder.h replaced with shlobj.h for compatibility with modern Microsoft compilers. Version 5.06, 2014.10.15, urgency: HIGH:
* Security bugfixes - OpenSSL DLLs updated to version 1.0.1j. https://www.openssl.org/news/secadv_20141015.txt - The insecure SSLv2 protocol is now disabled by default. It can be enabled with \"options = -NO_SSLv2\". - The insecure SSLv3 protocol is now disabled by default. It can be enabled with \"options = -NO_SSLv3\". - Default sslVersion changed to \"all\" (also in FIPS mode) to autonegotiate the highest supported TLS version.
* New features - Added missing SSL options to match OpenSSL 1.0.1j. - New \"-options\" commandline option to display the list of supported SSL options.
* Bugfixes - Fixed FORK threading build regression bug. - Fixed missing periodic Win32 GUI log updates. Version 5.05, 2014.10.10, urgency: MEDIUM:
* New features - Asynchronous communication with the GUI thread for faster logging on Win32. - systemd socket activation (thx to Mark Theunissen). - The parameter of \"options\" can now be prefixed with \"-\" to clear an SSL option, for example: \"options = -LEGACY_SERVER_CONNECT\". - Improved \"transparent = destination\" manual page (thx to Vadim Penzin).
* Bugfixes - Fixed POLLIN|POLLHUP condition handling error resulting in prematurely closed (truncated) connection. - Fixed a null pointer dereference regression bug in the \"transparent = destination\" functionality (thx to Vadim Penzin). This bug was introduced in stunnel 5.00. - Fixed startup thread synchronization with Win32 GUI. - Fixed erroneously closed stdin/stdout/stderr if specified as the -fd commandline option parameter. - A number of minor Win32 GUI bugfixes and improvements. - Merged most of the Windows CE patches (thx to Pierre Delaage). - Fixed incorrect CreateService() error message on Win32. - Implemented a workaround for defective Cygwin file descriptor passing breaking the libwrap support: http://wiki.osdev.org/Cygwin_Issues#Passing_file_descriptors Version 5.04, 2014.09.21, urgency: LOW:
* New features - Support for local mode (\"exec\" option) on Win32. - Support for UTF-8 config file and log file. - Win32 UTF-16 build (thx to Pierre Delaage for support). - Support for Unicode file names on Win32. - A more explicit service description provided for the Windows SCM (thx to Pierre Delaage). - TCP/IP dependency added for NT service in order to prevent initialization failure at boot time. - FIPS canister updated to version 2.0.8 in the Win32 binary build.
* Bugfixes - load_icon_default() modified to return copies of default icons instead of the original resources to prevent the resources from being destroyed. - Partially merged Windows CE patches (thx to Pierre Delaage). - Fixed typos in stunnel.init.in and vc.mak. - Fixed incorrect memory allocation statistics update in str_realloc(). - Missing REMOTE_PORT environmental variable is provided to processes spawned with \"exec\" on Unix platforms. - Taskbar icon is no longer disabled for NT service. - Fixed taskbar icon initialization when commandline options are specified. - Reportedly more compatible values used for the dwDesiredAccess parameter of the CreateFile() function (thx to Pierre Delaage). - A number of minor Win32 GUI bugfixes and improvements.
* Thu Sep 18 2014 asvetterAATTcip.physik.uni-wuerzburg.de- Cleanup of spec file.- Build for SLE11-SP3 with --disable-fips- Build for SLE11-Security-Module (with enabled fips)
* Thu Aug 21 2014 asvetterAATTcip.physik.uni-wuerzburg.de- Update to version 5.03 Version 5.03, 2014.08.07, urgency: HIGH:
* Security bugfixes - OpenSSL DLLs updated to version 1.0.1i. See https://www.openssl.org/news/secadv_20140806.txt
* New features - FIPS autoconfiguration cleanup. - FIPS canister updated to version 2.0.6. - Improved SNI diagnostic logging.
* Bugfixes - Compilation fixes for old versions of OpenSSL. - Fixed whitespace handling in the stunnel.init script. Version 5.02, 2014.06.09, urgency: HIGH:
* Security bugfixes - OpenSSL DLLs updated to version 1.0.1h. See https://www.openssl.org/news/secadv_20140605.txt
* New features - Major rewrite of the protocol.c interface: it is now possible to add protocol negotiations at multiple connection phases, protocols can individually decide whether the remote connection will be established before or after SSL/TLS is negotiated. - Heap memory blocks are wiped before release. This only works for block allocated by stunnel, and not by OpenSSL or other libraries. - The safe_memcmp() function implemented with execution time not dependent on the compared data. - Updated the stunnel.conf and stunnel.init templates. - Added a client-mode example to the manual.
* Bugfixes - Fixed \"failover = rr\" broken since version 5.00. - Fixed \"taskbar = no\" broken since version 5.00. - Compilation fix for missing SSL_OP_MSIE_SSLV2_RSA_PADDING option.
* Sun Apr 20 2014 michaelAATTstroeder.com- update to upstream v5.01 code- original ChangeLog: Security bugfixes OpenSSL DLLs updated to version 1.0.1g. This version mitigates TLS heartbeat read overrun (CVE-2014-0160). New features X.509 extensions added to the created self-signed stunnel.pem. \"FIPS = no\" also allowed in non-FIPS builds of stunnel. Search all certificates with the same subject name for a matching public key rather than only the first one (thx to Leon Winter). Create logs in the local application data folder if stunnel folder is not writable on Win32. Bugfixes close_notify not sent when SSL still has some data buffered. Protocol negotiation with server-side SNI fixed. A Mac OS X missing symbols fixed. Win32 configuration file reload crash fixed. Added s_pool_free() on exec+connect service retires. Line-buffering enforced on stderr output.
* Thu Mar 06 2014 drahnAATTsuse.com- update to final v5.00 code- security fix: Added PRNG state update in fork threading (CVE-2014-0016).- Patches: - stunnel-listenqueue-option.patch refreshed.
* Wed Feb 05 2014 drahnAATTsuse.com- re-add openssl cert conf file stunnel.cnf dropped by oversight.
* Wed Jan 29 2014 drahnAATTsuse.com- - Update to version 5.0b1 (FATE#315694) - Default \"pid\" is now \"\", i.e. not to create a pid file at startup. - Default \"ciphers\" updated to \"HIGH:MEDIUM:+3DES:+DH:!aNULL:!SSLv2\" due to AlFBPPS attack and bad performance of DH ciphersuites. - New service-level option \"redirect\" to redirect SSL client connections on authentication failures instead of rejecting them. - New global \"engineDefault\" configuration file option to control which OpenSSL tasks are delegated to the current engine. - New service-level configuration file option \"engineId\" to select the engine by identifier, e.g. \"engineId = capi\". - Improved readability of error messages printed when stunnel refuses to start due to a critical error.- Patches: - stunnel-CVE-2013-1762.patch obsoleted. Drpped. - stunnel-default-fips-off.patch obsoleted. Dropped. - stunnel-listenqueue-option.patch refreshed.
* Fri Nov 01 2013 michaelAATTstroeder.com- update to version 4.56
* Mon Jul 23 2012 drahnAATTsuse.com- Fix background operation to really go into background (stunnel-daemonize.diff)
* Sat Jul 21 2012 drahnAATTsuse.com- update to version 4.53 - Usage of uninitialized variables fixed in exec+connect services. - Fixed handling of a rare inetd mode use case, where either stdin or stdout is a socket, but not both of them at the same time. - Fixed crash on termination with FORK threading model. - Fixed missing file descriptors passed to local mode processes.- refreshed stunnel-listenqueue-option.patch to apply cleanly again
* Tue Nov 29 2011 darixAATTnordisch.org- update to version 4.49 - A bug was fixed causing crashes on MacOS X and some other platforms.- additional changes from 4.48 - FIPS support on Win32 platform added. OpenSSL 0.9.8r DLLs based on FIPS 1.2.3 canister are included with this version of stunnel. FIPS mode can be disabled with \"fips = no\" configuration file option. - Fixed canary initialization problem on Win32 platform.
* Thu Nov 24 2011 darixAATTnordisch.org- refreshed stunnel-listenqueue-option.patch to apply cleanly again- pass the path to the config file to the binary in the init script: without this the init script does not work for me.
* Thu Nov 24 2011 darixAATTnordisch.org- update to version 4.47
* Internal improvements - CVE-2010-3864 workaround improved to check runtime version of OpenSSL rather than compiled version, and to allow OpenSSL 0.x.x >= 0.9.8p. - Encoding of man page sources changed to UTF-8.
* Bugfixes - Handling of socket/SSL close in transfer() function was fixed. - Logging was modified to save and restore system error codes. - Option \"service\" was restricted to Unix, as since stunnel 4.42 it wasn\'t doing anything useful on Windows platform.- additional changes from version 4.46
* New features - Added Unix socket support (e.g. \"connect = /var/run/stunnel/socket\"). - Added \"verify = 4\" mode to ignore CA chain and only verify peer certificate. - Removed the limit of 16 IP addresses for a single \'connect\' option. - Removed the limit of 256 stunnel.conf sections in PTHREAD threading model. It is still not possible have more than 63 sections on WIN32 platform. http://msdn.microsoft.com/en-us/library/windows/desktop/ms740141(v=vs.85).aspx
* Optimizations - Reduced per-connection memory usage. - Performed a major refactoring of internal data structures. Extensive internal testing was performed, but some regression bugs are expected.
* Bugfixes - Fixed WIN32 compilation with Mingw32. - Fixed non-blocking API emulation layer in UCONTEXT threading model. - Fixed signal handling in UCONTEXT threading model.- additional changes from version 4.45
* New features - \"protocol = proxy\" support to send original client IP address to haproxy: http://haproxy.1wt.eu/download/1.5/doc/proxy-protocol.txt This requires accept-proxy bind option of haproxy 1.5-dev3 or later. - Added Win32 configuration reload without a valid configuration loaded. - Added compatibility with LTS OpenSSL versions 0.9.6 and 0.9.7. Some features are only available in OpenSSL 1.0.0 and later.
* Performance optimizations - Use SSL_MODE_RELEASE_BUFFERS if supported by the OpenSSL library. - Libwrap helper processes are no longer started if libwrap is disabled in all sections of the configuration file.
* Internal improvements - Protocol negotiation framework was rewritten to support additional code to be executed after SSL_accept()/SSL_connect(). - Handling of memory allocation errors was rewritten to gracefully terminate the process (thx to regenrecht for the idea).
* Bugfixes - Fixed -l option handling in stunnel3 script (thx to Kai Gülzau). - Script to build default stunnel.pem was fixed (thx to Sebastian Kayser). - MinGW compilation script (mingw.mak) was fixed (thx to Jose Alf). - MSVC compilation script (vc.mak) was fixed. - A number of problems in WINSOCK error handling were fixed.- additional changes from version 4.44
* New features - Major automake/autoconf cleanup. - Heap buffer overflow protection with canaries. - Stack buffer overflow protection with -fstack-protector.
* Bugfixes - Fixed garbled error messages on errors with setuid/setgid options. - SNI fixes (thx to Alexey Drozdov). - Use after free in fdprintf() (thx to Alexey Drozdov). This issue might cause GPF with \"protocol\" or \"ident\" options.
* Fri Sep 09 2011 drahnAATTsuse.com- update to version 4.43
* New features: - Major optimization of the logging subsystem.
* Bugfixes - Fixed FORK and UCONTEXT threading models.
* Fri Sep 02 2011 drahnAATTsuse.com- update to version 4.42
* New features - New verify level 0 to request and ignore peer certificate. - Manual page has been updated.
* Bugfixes - Fixed a heap corruption vulnerability in versions 4.40 and 4.41. It may possibly be leveraged to perform DoS or remote code execution attacks (CVE-2011-2940).
* Sun Aug 07 2011 drahnAATTsuse.com- correct path in stunnel3 (bnc#710879)
* Mon Jul 25 2011 drahnAATTsuse.com- update package to 4.40
* New features: - Hardcoded 2048-bit DH parameters are used as a fallback if DH parameters are not provided in stunnel.pem. - Default \"ciphers\" value updated to prefer ECDH: \"ALL:!SSLv2:!aNULL:!EXP:!LOW:-MEDIUM:RC4:+HIGH\". - Default ECDH curve updated to \"prime256v1\". - Removed support for temporary RSA keys (used in obsolete export ciphers).- refresh stunnel-listenqueue-option.patch
* Wed Jun 29 2011 daniel.rahnAATTnovell.com- split off doc package
* Wed Jun 29 2011 daniel.rahnAATTnovell.com- update package to 4.38
* New features: - Server-side SNI implemented (RFC 3546 section 3.1) with a new service-level option \"nsi\". - \"socket\" option also accepts \"yes\" and \"no\" for flags. - Nagle\'s algorithm is now disabled by default for improved interactivity.
* Bugfixes: - A compilation fix was added for OpenSSL version < 1.0.0. - Signal pipe set to non-blocking mode. This bug caused hangs of stunnel features based on signals, e.g. local mode, FORK threading, or configuration file reload on Unix.
* Mon Jun 20 2011 daniel.rahnAATTnovell.com- disable the previous two patches for the time being- create debug packages
* Sat Jun 18 2011 daniel.rahnAATTnovell.com- fix ucontext handling (backport from v4.37)
* Sat Jun 18 2011 daniel.rahnAATTnovell.com- fix non-blocking socket handling (backport from v4.37)
* Thu Jun 16 2011 daniel.rahnAATTnovell.com- update package to 4.36- obsoletes SOMAXCONN and libwrap disable patches (bnc#674554)- forward port listenqueue patch (bnc#674554)- explicitly enable libwrap in configure call
* New features - Dynamic memory management for strings manipulation: no more static STRLEN limit, lower stack footprint. - Strict public key comparison added for \"verify = 3\" certificate checking mode (thx to Philipp Hartwig). - Backlog parameter of listen(2) changed from 5 to SOMAXCONN: improved behavior on heavy load. Old behavior can be restored with \"listenqueue = 5\" in stunnel.conf
* Bugfixes - Missing pthread_attr_destroy() added to fix memory leak (thx to Paul Allex and Peter Pentchev). - Fixed the incorrect way of setting FD_CLOEXEC flag. - Fixed --enable-libwrap option of ./configure script. - Retry implemented on EAI_AGAIN error returned by resolver calls.
* Mon Feb 07 2011 asvetterAATTcip.physik.uni-wuerzburg.de- update to 4.35:
* New features - Updated Win32 DLLs for OpenSSL 1.0.0c. - Transparent source (non-local bind) added for FreeBSD 8.x. - Transparent destination (\"transparent = destination\") added for Linux.
* Bugfixes - Fixed reload of FIPS-enabled stunnel. - Compiler options are now auto-detected by ./configure script in order to support obsolete versions of gcc. - Async-signal-unsafe s_log() removed from SIGTERM/SIGQUIT/SIGINT handler. - CLOEXEC file descriptor leaks fixed on Linux >= 2.6.28 with glibc >= 2.10. Irreparable race condition leaks remain on other Unix platforms. This issue may have security implications on some deployments. - Directory lib64 included in the OpenSSL library search path. - Windows CE compilation fixes (thx to Pierre Delaage). - Deprecated RSA_generate_key() replaced with RSA_generate_key_ex().
* Domain name changes (courtesy of Bri Hatch) - http://stunnel.mirt.net/ --> http://www.stunnel.org/ - ftp://stunnel.mirt.net/ --> http://ftp.stunnel.org/ - stunnel.mirt.net::stunnel --> rsync.stunnel.org::stunnel - stunnel-usersAATTmirt.net --> stunnel-usersAATTstunnel.org - stunnel-announceAATTmirt.net --> stunnel-announceAATTstunnel.org
* Tue Sep 28 2010 dmuellerAATTsuse.de- update to 4.34: - Added ECC support with a new service-level \"curve\" option. - DH support is now enabled by default. - Added support for OpenSSL builds with some algorithms disabled. - ./configure modified to support cross-compilation. - Implemented fixes in user interface to enter engine PIN. - Fixed a transfer() loop issue on socket errors. - Fixed missing WIN32 taskbar icon while displaying a global option error. - Inetd mode fixed. - New service-level \"libwrap\" option for run-time control whether /etc/hosts.allow and /etc/hosts.deny are used for access control. Disabling libwrap significantly increases performance of stunnel. - Win32 DLLs for OpenSSL 0.9.8m. - Fixed a transfer() loop issue with SSLv2 connections. - Fixed a \"setsockopt IP_TRANSPARENT\" warning with \"local\" option. - Logging subsystem bugfixes and cleanup. - Installer bugfixes for Vista and later versions of Windows. - FIPS mode can be enabled/disabled at runtime. - Log file reopen on USR1 signal was added. - Some regression issues introduced in 4.30 were fixed. - Graceful configuration reload with HUP signal on Unix and with GUI on Windows. - A serious bug in asynchronous shutdown code fixed. - Data alignment updated in libwrap.c. - Polish manual encoding fixed. - Notes on compression implementation in OpenSSL added to the manual.
* Fri Nov 27 2009 vetterAATTphysik.uni-wuerzburg.de- fix compile problems with openssl 0.9.7d
* Fri Nov 27 2009 vetterAATTphysik.uni-wuerzburg.de- bugfixes for 4.28
* Bugfixes o \"execargs\" defaults to the \"exec\" parameter (thx to Peter Pentchev). o no_ticket.patch- update to 4.27:
* New features o Win32 DLLs for OpenSSL 0.9.8l. o Transparent proxy support on Linux kernels >=2.6.28. See the manual for details. o New socket options to control TCP keepalive on Linux: TCP_KEEPCNT, TCP_KEEPIDLE, TCP_KEEPINTVL. o SSL options updated for the recent version of OpenSSL library.
* Bugfixes o A serious bug in asynchronous shutdown code fixed. o Data alignment updated in libwrap.c. o Polish manual encoding fixed. o Notes on compression implementation in OpenSSL added to the manual.
* Fri Apr 17 2009 vetterAATTphysik.uni-wuerzburg.de- update to 4.27:
* New features - Win32 DLLs for OpenSSL 0.9.8k. - FIPS support was updated for openssl-fips 1.2. - New priority failover strategy for multiple \"connect\" targets, controlled with \"failover=rr\" (default) or \"failover=prio\". - pgsql protocol negotiation by Marko Kreen
. - Building instructions were updated in INSTALL.W32 file.
* Bugfixes - Libwrap helper processes fixed to close standard input/output/error file descriptors. - OS2 compilation fixes. - WCE fixes by Pierre Delaage .