| 
							
							
								 Tomas Mraz | 4e423c3c50 | make DTLS1 work in FIPS mode - avoid RSA and DSA 512 bits and Whirlpool in 'openssl speed' in FIPS mode | 2013-09-27 15:43:51 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | df94661da5 | avoid dlopening libssl.so from libcrypto (#1010357) | 2013-09-23 18:30:01 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 372f3ac997 | fix small memory leak in FIPS aes selftest | 2013-09-20 16:04:50 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 8c28623e94 | fix segfault in openssl speed hmac in the FIPS mode | 2013-09-19 15:16:50 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | d907abae39 | Merge branch 'f20' of ssh://pkgs.fedoraproject.org/openssl into f20 Conflicts:
	openssl.spec | 2013-09-13 15:33:34 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | fa93b626ad | Add documentation of -attime to verify manpage | 2013-09-12 11:26:07 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 30ebb4d732 | document the nextprotoneg option in manual pages original patch by Hubert Kario | 2013-09-12 10:39:33 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | ae08b15c89 | document the nextprotoneg option in manual pages original patch by Hubert Kario | 2013-09-12 10:23:34 +02:00 |  | 
			
				
					| 
							
							
								 Kyle McMartin | cb069618e7 | arm: use auxv to figure out armcap.c instead of using signals (#1006474) | 2013-09-11 10:36:42 -04:00 |  | 
			
				
					| 
							
							
								 Kyle McMartin | f6aa3c2ddd | arm: use auxv to figure out armcap.c instead of using signals (#1006474) | 2013-09-11 09:52:25 -04:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | eb63cc63df | try to avoid some races when updating the -fips subpackage | 2013-09-04 13:53:38 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 850ca72b9a | use version-release in .hmac suffix to avoid overwrite during upgrade | 2013-09-02 15:02:18 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | b5d2711ab6 | allow deinitialization of the FIPS mode | 2013-08-29 16:41:24 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 1465572e17 | always perform the FIPS selftests in library constructor if FIPS module is installed | 2013-08-29 11:45:04 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | bb2f3882f2 | add -fips subpackage that contains the FIPS module files | 2013-08-27 16:03:43 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 9c324da28e | fix use of rdrand if available - more commits cherry picked from upstream
- documentation fixes | 2013-08-16 16:06:51 +02:00 |  | 
			
				
					| 
							
							
								 Petr Písař | a254940dd1 | Perl 5.18 rebuild | 2013-08-03 12:05:42 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | acdf8a62f6 | use symbol versioning also for the textual version - additional manual page fix | 2013-07-26 13:16:10 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 9b36f08da8 | additional manual page fixes | 2013-07-25 15:14:25 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 653e1efa34 | use _prefix macro | 2013-07-19 11:46:56 +02:00 |  | 
			
				
					| 
							
							
								 Petr Písař | 49a1fc761b | Perl 5.18 rebuild | 2013-07-17 16:32:50 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 7ccde74773 | add openssl.cnf.5 manpage symlink to config.5 | 2013-07-11 10:44:55 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 9555809e80 | add relro linking flag | 2013-07-10 17:54:24 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 6a0a35eb5f | Add missing fix of renamed manpages. | 2013-07-10 16:43:07 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 30aa9303c7 | add support for the -trusted_first option for certificate chain verification | 2013-07-10 11:02:41 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | dad6e3ee78 | fix build of manual pages with current pod2man (#959439) | 2013-05-03 18:38:28 +02:00 |  | 
			
				
					| 
							
							
								 Peter Robinson | 6705192b85 | Enable ARM optimised build | 2013-04-21 14:33:34 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 64e30c5369 | fix random bad record mac errors (#918981) | 2013-03-18 21:34:18 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 9cf55df55b | fix up the SHLIB_VERSION_NUMBER | 2013-02-19 20:35:16 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 169c3a0ddb | disable ZLIB loading by default (due to CRIME attack) | 2013-02-19 16:41:14 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | dc696fdac4 | new upstream version | 2013-02-19 13:57:39 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 0fd0958b75 | more fixes from upstream - fix errors in manual causing build failure (#904777) | 2013-01-30 18:32:56 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 2ca16b9a24 | Add the renew-dummy-cert script to file list | 2012-12-21 17:38:32 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | c67ea975b9 | add script for renewal of a self-signed cert by Philip Prindeville (#871566) - allow X509_issuer_and_serial_hash() produce correct result in
  the FIPS mode (#881336) | 2012-12-21 17:21:50 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 07ac3d216e | Fix bogus dates in changelog. | 2012-12-07 12:37:49 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 728b1133e0 | s_time uses tm_ctx. | 2012-12-07 10:01:17 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 650873ff0e | do not load default verify paths if CApath or CAfile specified (#884305) | 2012-12-06 18:30:15 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 12aab15a03 | more fixes from upstream CVS - fix DSA key pairwise check (#878597) | 2012-11-20 22:33:42 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | d8e7bfc73b | Add the marker for required patch. | 2012-11-19 17:43:07 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | b7eb6f4a5f | use 1024 bit DH parameters in s_server as 512 bit is not allowed in FIPS mode and it is quite weak anyway | 2012-11-15 21:11:36 +01:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 79971bf194 | Use secure_getenv() with new glibc. | 2012-09-10 20:25:19 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | c015bd1b1e | add missing initialization of str in aes_ccm_init_key (#853963) - add important patches from upstream CVS | 2012-09-07 10:48:56 +02:00 |  | 
			
				
					| 
							
							
								 Dennis Gilmore | eaa5561c35 | - Rebuilt for https://fedoraproject.org/wiki/Fedora_18_Mass_Rebuild | 2012-07-20 02:06:56 -05:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | af044b4037 | use __getenv_secure() instead of __libc_enable_secure | 2012-07-13 22:21:05 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 72a1bddddc | do not move libcrypto to /lib - do not use environment variables if __libc_enable_secure is on
- fix strict aliasing problems in modes | 2012-07-13 14:30:31 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | c2e3151786 | do not move libcrypto to /lib - do not use environment variables if __libc_enable_secure is on
- fix strict aliasing problems in modes | 2012-07-13 14:23:34 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 55a3598cc7 | fix DSA key generation in FIPS mode (#833866) - allow duplicate FIPS_mode_set(1)
- enable build on ppc64 subarch (#834652) | 2012-07-12 21:59:56 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 5183d32904 | Make it build with new Perl | 2012-07-12 00:35:57 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 254f85a5c0 | fix s_server with new glibc when no global IPv6 address (#839031) | 2012-07-12 00:05:11 +02:00 |  | 
			
				
					| 
							
							
								 Tomas Mraz | 18ccae20f6 | fix s_server with new glibc when no global IPv6 address (#839031) | 2012-07-12 00:04:06 +02:00 |  |