Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							07bd81ddaf 
							
						 
					 
					
						
						
							
							- must also verify checksum of libssl.so in the FIPS mode  
						
						... 
						
						
						
						- obtain the seed for FIPS rng directly from the kernel device
- drop the temporary symlinks 
						
					 
					
						2009-02-02 16:46:33 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							c7641abc30 
							
						 
					 
					
						
						
							
							- drop the temporary triggerpostun and symlinking in post  
						
						... 
						
						
						
						- fix the pkgconfig files and drop the unnecessary buildrequires on
    pkgconfig as it is a rpmbuild dependency (#481419 ) 
						
					 
					
						2009-01-26 21:07:21 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							919b2c6500 
							
						 
					 
					
						
						
							
							- add temporary triggerpostun to reinstate the symlinks  
						
						
						
					 
					
						2009-01-17 20:49:48 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							7e0fce6fea 
							
						 
					 
					
						
						
							
							- add temporary triggerpostun to reinstate the symlinks  
						
						
						
					 
					
						2009-01-17 20:48:44 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							105eb2ce8f 
							
						 
					 
					
						
						
							
							- no pairwise key tests in non-fips mode ( #479817 )  
						
						
						
					 
					
						2009-01-17 19:31:29 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							ebd2901e1d 
							
						 
					 
					
						
						
							
							- even more robust test for the temporary symlinks  
						
						
						
					 
					
						2009-01-16 16:11:07 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							b33a50c5b2 
							
						 
					 
					
						
						
							
							- try to ensure the temporary symlinks exist  
						
						
						
					 
					
						2009-01-16 13:02:42 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							1d20b5f238 
							
						 
					 
					
						
						
							
							- new upstream version with necessary soname bump ( #455753 )  
						
						... 
						
						
						
						- temporarily provide symlink to old soname to make it possible to rebuild
    the dependent packages in rawhide
- add eap-fast support (#428181 )
- add possibility to disable zlib by setting
- add fips mode support for testing purposes
- do not null dereference on some invalid smime files
- add buildrequires pkgconfig (#479493 ) 
						
					 
					
						2009-01-15 09:10:25 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							f1fb664cb6 
							
						 
					 
					
						
						
							
							- rediff for no fuzz  
						
						
						
					 
					
						2008-08-10 20:36:12 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							c59bdb11a0 
							
						 
					 
					
						
						
							
							- do not add tls extensions to server hello for SSLv3 either  
						
						
						
					 
					
						2008-08-10 19:45:27 +00:00 
						 
				 
			
				
					
						
							
							
								jorton 
							
						 
					 
					
						
						
						
						
							
						
						
							acba378bc3 
							
						 
					 
					
						
						
							
							- restore the touch -r for openssl.cnf  
						
						
						
					 
					
						2008-06-02 11:31:55 +00:00 
						 
				 
			
				
					
						
							
							
								jorton 
							
						 
					 
					
						
						
						
						
							
						
						
							50e76b460a 
							
						 
					 
					
						
						
							
							- remove reference to deleted source  
						
						
						
					 
					
						2008-06-02 11:28:03 +00:00 
						 
				 
			
				
					
						
							
							
								jorton 
							
						 
					 
					
						
						
						
						
							
						
						
							bb2baacca9 
							
						 
					 
					
						
						
							
							- move root CA bundle to ca-certificates package  
						
						
						
					 
					
						2008-06-02 11:06:57 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							2c01b19843 
							
						 
					 
					
						
						
							
							- fix CVE-2008-0891 - server name extension crash ( #448492 )  
						
						... 
						
						
						
						- fix CVE-2008-1672 - server key exchange message omit crash (#448495 ) 
						
					 
					
						2008-05-28 15:52:21 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							6e489d9c90 
							
						 
					 
					
						
						
							
							- release bump  
						
						
						
					 
					
						2008-05-27 08:39:57 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							cc7d549a79 
							
						 
					 
					
						
						
							
							- super-H arch support  
						
						... 
						
						
						
						- drop workaround for bug 199604 as it should be fixed in gcc-4.3 
						
					 
					
						2008-05-27 08:38:06 +00:00 
						 
				 
			
				
					
						
							
							
								Tom Callaway 
							
						 
					 
					
						
						
						
						
							
						
						
							3bbf540789 
							
						 
					 
					
						
						
							
							sparc handling  
						
						
						
					 
					
						2008-05-20 15:16:15 +00:00 
						 
				 
			
				
					
						
							
							
								jorton 
							
						 
					 
					
						
						
						
						
							
						
						
							dfabafc476 
							
						 
					 
					
						
						
							
							- update to new root CA bundle from mozilla.org (r1.45)  
						
						
						
					 
					
						2008-03-10 10:45:36 +00:00 
						 
				 
			
				
					
						
							
							
								Jesse Keating 
							
						 
					 
					
						
						
						
						
							
						
						
							d08968bcfa 
							
						 
					 
					
						
						
							
							- Autorebuild for GCC 4.3  
						
						
						
					 
					
						2008-02-20 05:36:13 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							1181966c58 
							
						 
					 
					
						
						
							
							- rename required for build  
						
						
						
					 
					
						2008-01-25 17:04:12 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							5980c2800d 
							
						 
					 
					
						
						
							
							- merge review fixes ( #226220 )  
						
						... 
						
						
						
						- adjust the SHLIB_VERSION_NUMBER to reflect library name (#429846 ) 
						
					 
					
						2008-01-25 16:44:05 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							d8cd5c45d8 
							
						 
					 
					
						
						
							
							- set default paths when no explicit paths are set ( #418771 )  
						
						... 
						
						
						
						- do not add tls extensions to client hello for SSLv3 (#422081 ) 
						
					 
					
						2007-12-13 17:16:43 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							2a80bfda1d 
							
						 
					 
					
						
						
							
							- enable some new crypto algorithms and features  
						
						... 
						
						
						
						- add some more important bug fixes from openssl CVS 
						
					 
					
						2007-12-03 19:57:11 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							139aecb45e 
							
						 
					 
					
						
						
							
							- we have Dec now and not Nov  
						
						
						
					 
					
						2007-12-03 15:26:28 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							3849a1678a 
							
						 
					 
					
						
						
							
							- update to latest upstream release, SONAME bumped to 7  
						
						
						
					 
					
						2007-12-03 14:24:08 +00:00 
						 
				 
			
				
					
						
							
							
								Bill Nottingham 
							
						 
					 
					
						
						
						
						
							
						
						
							96585a061a 
							
						 
					 
					
						
						
							
							makefile update to properly grab makefile.common  
						
						
						
					 
					
						2007-10-15 19:12:21 +00:00 
						 
				 
			
				
					
						
							
							
								jorton 
							
						 
					 
					
						
						
						
						
							
						
						
							6427162702 
							
						 
					 
					
						
						
							
							- update to new CA bundle from mozilla.org  
						
						
						
					 
					
						2007-10-15 15:20:47 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							873b8d554b 
							
						 
					 
					
						
						
							
							- fix CVE-2007-5135 - off-by-one in SSL_get_shared_ciphers ( #309801 )  
						
						... 
						
						
						
						- fix CVE-2007-4995 - out of order DTLS fragments buffer overflow (#321191 )
- add alpha sub-archs (#296031 ) 
						
					 
					
						2007-10-12 12:17:08 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							65e6d90529 
							
						 
					 
					
						
						
							
							- fix CVE-2007-5135 - off-by-one in SSL_get_shared_ciphers ( #309801 )  
						
						... 
						
						
						
						- fix CVE-2007-4995 - out of order DTLS fragments buffer overflow (#321191 )
- add alpha sub-archs (#296031 ) 
						
					 
					
						2007-10-12 12:16:00 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							568fd16a03 
							
						 
					 
					
						
						
							
							- rebuild  
						
						
						
					 
					
						2007-08-21 19:42:52 +00:00 
						 
				 
			
				
					
						
							
							
								Patrick Laughton 
							
						 
					 
					
						
						
						
						
							
						
						
							de79c32133 
							
						 
					 
					
						
						
							
							Test succeeded, apologies to Tomas for the noise.  
						
						
						
					 
					
						2007-08-09 00:49:27 +00:00 
						 
				 
			
				
					
						
							
							
								Patrick Laughton 
							
						 
					 
					
						
						
						
						
							
						
						
							366d8b3e20 
							
						 
					 
					
						
						
							
							Testing Fedora SPARC ACL group permissions.  
						
						
						
					 
					
						2007-08-09 00:47:13 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							aa64c417f5 
							
						 
					 
					
						
						
							
							- use localhost in testsuite, hopefully fixes slow build in koji  
						
						... 
						
						
						
						- CVE-2007-3108 - fix side channel attack on private keys (#250577 )
- make ssl session cache id matching strict (#233599 ) 
						
					 
					
						2007-08-03 12:16:54 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							b191bc7a11 
							
						 
					 
					
						
						
							
							- allow building on ARM architectures ( #245417 )  
						
						... 
						
						
						
						- use reference timestamps to prevent multilib conflicts (#218064 )
- -devel package must require pkgconfig (#241031 ) 
						
					 
					
						2007-07-25 13:37:15 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							fba756feb1 
							
						 
					 
					
						
						
							
							- detect duplicates in add_dir properly ( #206346 )  
						
						
						
					 
					
						2006-12-11 19:46:13 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							4ca06fa547 
							
						 
					 
					
						
						
							
							- the previous change still didn't make X509_NAME_cmp transitive  
						
						
						
					 
					
						2006-11-30 23:10:43 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							f0fb64db28 
							
						 
					 
					
						
						
							
							- make X509_NAME_cmp transitive otherwise certificate lookup is broken  
						
						... 
						
						
						
						(#216050 )
- Resolves: rhbz#216050 
						
					 
					
						2006-11-23 20:38:24 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							a99897e811 
							
						 
					 
					
						
						
							
							- aliasing bug in engine loading, patch by IBM ( #213216 )  
						
						
						
					 
					
						2006-11-02 21:16:00 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							98d8457650 
							
						 
					 
					
						
						
							
							- CVE-2006-2940 fix was incorrect ( #208744 )  
						
						
						
					 
					
						2006-10-02 08:37:59 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							6dc7017559 
							
						 
					 
					
						
						
							
							- fix CVE-2006-2937 - mishandled error on ASN.1 parsing ( #207276 )  
						
						... 
						
						
						
						- fix CVE-2006-2940 - parasitic public keys DoS (#207274 )
- fix CVE-2006-3738 - buffer overflow in SSL_get_shared_ciphers (#206940 )
- fix CVE-2006-4343 - sslv2 client DoS (#206940 ) 
						
					 
					
						2006-09-28 19:59:16 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							cd294fcd2a 
							
						 
					 
					
						
						
							
							- fix CVE-2006-2937 - mishandled error on ASN.1 parsing ( #207276 )  
						
						... 
						
						
						
						- fix CVE-2006-2940 - parasitic public keys DoS (#207274 )
- fix CVE-2006-3738 - buffer overflow in SSL_get_shared_ciphers (#206940 )
- fix CVE-2006-4343 - sslv2 client DoS (#206940 ) 
						
					 
					
						2006-09-28 19:58:49 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							ba40f6bb66 
							
						 
					 
					
						
						
							
							- fix CVE-2006-4339 - prevent attack on PKCS#1 v1.5 signatures ( #205180 )  
						
						
						
					 
					
						2006-09-05 13:44:39 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							2020821670 
							
						 
					 
					
						
						
							
							- set buffering to none on stdio/stdout FILE when bufsize is set ( #200580 )  
						
						... 
						
						
						
						patch by IBM 
						
					 
					
						2006-08-02 18:18:43 +00:00 
						 
				 
			
				
					
						
							
							
								aoliva 
							
						 
					 
					
						
						
						
						
							
						
						
							c1d3bf9a12 
							
						 
					 
					
						
						
							
							- rebuild with new binutils ( #200330 )  
						
						
						
					 
					
						2006-07-29 02:54:33 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							e9887c37ef 
							
						 
					 
					
						
						
							
							- add a temporary workaround for sha512 test failure on s390 ( #199604 )  
						
						
						
					 
					
						2006-07-21 08:28:43 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							4d4d77e68c 
							
						 
					 
					
						
						
							
							- add ipv6 support to s_client and s_server (by Jan Pazdziora) ( #198737 )  
						
						... 
						
						
						
						- add patches for BN threadsafety, AES cache collision attack hazard fix
    and pkcs7 code memleak fix from upstream CVS 
						
					 
					
						2006-07-20 12:58:48 +00:00 
						 
				 
			
				
					
						
							
							
								Jesse Keating 
							
						 
					 
					
						
						
						
						
							
						
						
							a362beea0e 
							
						 
					 
					
						
						
							
							bumped for rebuild  
						
						
						
					 
					
						2006-07-12 07:35:49 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							6b8c7ea159 
							
						 
					 
					
						
						
							
							- dropped libica and ica engine from build  
						
						
						
					 
					
						2006-06-21 21:14:05 +00:00 
						 
				 
			
				
					
						
							
							
								jorton 
							
						 
					 
					
						
						
						
						
							
						
						
							24c8087012 
							
						 
					 
					
						
						
							
							- update to new CA bundle from mozilla.org; adds CA certificates from  
						
						... 
						
						
						
						netlock.hu and startcom.org 
						
					 
					
						2006-06-21 12:49:44 +00:00 
						 
				 
			
				
					
						
							
							
								Tomáš Mráz 
							
						 
					 
					
						
						
						
						
							
						
						
							810d3c4e49 
							
						 
					 
					
						
						
							
							- add export  
						
						
						
					 
					
						2006-06-06 12:03:44 +00:00