Commit Graph

  • 1417ec988d enable secp256k1 (bz1021898) Tom Callaway 2015-08-12 17:07:46 -0400
  • 5675d07a14 minor upstream release 1.0.2d fixing a high severity security issue Tomas Mraz 2015-07-09 17:25:58 +0200
  • 7f0b164051 fix the aarch64 build Tomas Mraz 2015-07-07 09:47:17 +0200
  • 49a07018fb - Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild Dennis Gilmore 2015-06-18 00:06:33 +0000
  • 837dd04882 minor upstream release 1.0.2c fixing multiple security issues Tomas Mraz 2015-06-15 18:23:46 +0200
  • 18455c91c0 Add aarch64 sslarch details Peter Robinson 2015-05-07 16:04:05 +0100
  • e4bf425a79 fix some 64 bit build targets Tomas Mraz 2015-05-07 12:01:04 +0200
  • d743a79756 add alternative certificate chain discovery support from upstream Tomas Mraz 2015-04-28 17:10:52 +0200
  • a1fb602a95 rebase to 1.0.2 branch Tomas Mraz 2015-04-23 13:57:26 +0200
  • 805c06e347 drop the AES-GCM restriction of 2^32 operations Tomas Mraz 2015-04-09 13:10:25 +0200
  • 729d2d0e11 Multiple security issues fixed. Tomas Mraz 2015-03-19 18:08:12 +0100
  • 446f9bea43 fix bug in the CRYPTO_128_unwrap() Tomas Mraz 2015-03-16 18:02:06 +0100
  • 303fb7be60 fix bug in the RFC 5649 support (#1185878) Tomas Mraz 2015-02-27 15:54:36 +0100
  • 1804d4c857 Rebuilt for Fedora 23 Change Till Maas 2015-02-21 22:15:20 +0100
  • 6a450be963 test in the non-FIPS RSA keygen for minimal distance of p and q Tomas Mraz 2015-01-16 16:16:14 +0100
  • 7e7e3f299f new upstream release fixing multiple security issues Tomas Mraz 2015-01-09 10:54:51 +0100
  • 8c1cdfe3ab Fix date in changelog. Tomas Mraz 2014-11-20 11:14:35 +0100
  • 80b5477597 disable SSLv3 by default again Tomas Mraz 2014-11-20 10:25:56 +0100
  • 3f43f7e93a update the FIPS RSA keygen to be FIPS 186-4 compliant Tomas Mraz 2014-10-21 16:02:25 +0200
  • 0a961bb5e3 new upstream release fixing multiple security issues Tomas Mraz 2014-10-16 14:02:00 +0200
  • 613f664141 new upstream release fixing multiple security issues Tomas Mraz 2014-10-16 13:50:08 +0200
  • 1f162bf2ee copy negotiated digests when switching certs by SNI (#1150032) Tomas Mraz 2014-10-10 14:16:48 +0200
  • 11aeae71ed add support for RFC 5649 Tomas Mraz 2014-09-08 15:22:44 +0200
  • 58eec73ac0 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_22_Mass_Rebuild Peter Robinson 2014-08-17 14:08:44 +0000
  • 0e8cc69f30 Make the fips_standalone_sha build on PPC. Tomas Mraz 2014-08-14 14:48:26 +0200
  • a577400ed8 drop RSA X9.31 from RSA FIPS selftests Tomas Mraz 2014-08-13 20:03:17 +0200
  • 638098da51 Merge branch 'master' into f21 Tomas Mraz 2014-08-07 16:16:19 +0200
  • a78828f786 new upstream release fixing multiple moderate security issues Tomas Mraz 2014-08-07 16:00:47 +0200
  • a751492d12 fix license handling Tom Callaway 2014-07-18 19:31:40 -0400
  • 6c0bfa087d fix license handling Tom Callaway 2014-07-18 19:31:16 -0400
  • c66230af31 Sign the test string in the pairwise check instead of empty data. Tomas Mraz 2014-07-04 17:08:44 +0200
  • 6466466115 disable SSLv2 and SSLv3 protocols by default Tomas Mraz 2014-06-30 14:21:11 +0200
  • 873dc4a466 And never call fclose with NULL parameter. Tomas Mraz 2014-06-11 16:21:37 +0200
  • 9c4f375672 Cannot use malloc with OPENSSL_free. Tomas Mraz 2014-06-11 15:30:49 +0200
  • f550490681 use system profile for default cipher list Tomas Mraz 2014-06-11 15:07:06 +0200
  • a98d99a503 fix CVE-2014-0224 fix that broke EAP-FAST session resumption support Tomas Mraz 2014-06-10 16:38:56 +0200
  • 0a491cd9f2 - Rebuilt for https://fedoraproject.org/wiki/Fedora_21_Mass_Rebuild Dennis Gilmore 2014-06-07 12:02:05 -0500
  • 360a4bb67c new upstream release 1.0.1h Tomas Mraz 2014-06-05 15:05:17 +0200
  • b5f54ff916 Drop obsolete and irrelevant docs, Move devel docs to appropriate package, they're all rather large and of little use for all but historical reference Peter Robinson 2014-05-31 22:49:33 +0100
  • 0376d8368c new upstream release 1.0.1g Tomas Mraz 2014-05-07 11:42:32 +0200
  • e55cd2c0e4 pull in upstream patch for CVE-2014-0160 Dennis Gilmore 2014-04-07 19:20:31 -0500
  • 239d122765 add support for ppc64le architecture (#1072633) Tomas Mraz 2014-04-03 16:24:35 +0200
  • 477d4a1758 properly detect encryption failure in BIO Tomas Mraz 2014-03-17 17:22:08 +0100
  • 423ab177c8 use the key length from configuration file if req -newkey rsa is invoked Tomas Mraz 2014-02-14 16:24:31 +0100
  • 3f8863c3cd Avoid unnecessary reseeding in BN_rand in FIPS mode. Tomas Mraz 2014-02-13 16:54:43 +0100
  • 165cee17b3 Remove obsolete sentence. Tomas Mraz 2014-02-13 16:17:58 +0100
  • a9591c7f1f Add macro for performance build on certain arches. Tomas Mraz 2014-02-12 16:58:49 +0100
  • 24632bb1db print ephemeral key size negotiated in TLS handshake (#1057715) Tomas Mraz 2014-02-12 16:20:03 +0100
  • abe62302b2 make expiration and key length changeable by DAYS and KEYLEN Tomas Mraz 2014-02-06 18:07:59 +0100
  • 40825564d8 make 3des strength to be 128 bits instead of 168 (#1056616) Tomas Mraz 2014-01-22 17:57:22 +0100
  • 519fe2cc24 Two security fixes Tomas Mraz 2014-01-07 15:09:40 +0100
  • c5b74d70a3 dh->q might be NULL. Tomas Mraz 2014-01-07 11:57:56 +0100
  • 8978637f3b fix CVE-2013-6449 - crash when version in SSL structure is incorrect Tomas Mraz 2013-12-20 14:14:15 +0100
  • 5713696953 Additional FIPS requirements changes. Tomas Mraz 2013-12-19 17:42:43 +0100
  • dc728e2d8b drop weak ciphers from the default TLS ciphersuite list Tomas Mraz 2013-12-18 15:55:26 +0100
  • ad237d19e6 fix locking and reseeding problems with FIPS drbg Tomas Mraz 2013-11-19 14:52:30 +0100
  • c9a46cb3ac Fix typos. Tomas Mraz 2013-11-15 16:57:33 +0100
  • e64d4ea7bb additional changes required for FIPS validation Tomas Mraz 2013-11-15 16:13:44 +0100
  • 9caf868063 disable verification of certificate, CRL, and OCSP signatures using MD5 Tomas Mraz 2013-11-13 20:06:28 +0100
  • dcd0fb1ec9 disable verification of certificate, CRL, and OCSP signatures using MD5 Tomas Mraz 2013-11-13 19:42:54 +0100
  • 1e5b73a151 add back support for secp521r1 EC curve Tomas Mraz 2013-11-08 18:23:00 +0100
  • 83d99a68af add back support for secp521r1 EC curve Tomas Mraz 2013-11-08 18:16:49 +0100
  • 5714047e75 fix misdetection of RDRAND support on Cyrix CPUS (from upstream) (#1022346) Tomas Mraz 2013-10-29 16:24:08 +0100
  • eca676db7a do not advertise ECC curves we do not support (#1022493) Tomas Mraz 2013-10-24 10:40:18 +0200
  • a8799e01c4 Merge remote-tracking branch 'origin/f19' into f19 Tomas Mraz 2013-10-16 16:52:19 +0200
  • e241743946 Merge remote-tracking branch 'origin/f20' into f20 Tomas Mraz 2013-10-16 16:00:01 +0200
  • b3551463ca only ECC NIST Suite B curves support Tomas Mraz 2013-10-16 14:37:51 +0200
  • 4d56d16496 resolve bugzilla 319901 (phew! only took 6 years & 9 days) Tom Callaway 2013-10-15 02:14:11 +0100
  • 9a59868619 resolve bugzilla 319901 (phew! only took 6 years & 9 days) Tom Callaway 2013-10-15 02:13:38 +0100
  • 1f19ac14f9 resolve bugzilla 319901 (phew! only took 6 years & 9 days) Tom Callaway 2013-10-15 02:08:35 +0100
  • 7ae1dc1df9 Bump release Tomas Mraz 2013-09-27 15:46:03 +0200
  • 4e423c3c50 make DTLS1 work in FIPS mode Tomas Mraz 2013-09-27 15:43:51 +0200
  • df94661da5 avoid dlopening libssl.so from libcrypto (#1010357) Tomas Mraz 2013-09-23 18:30:01 +0200
  • 372f3ac997 fix small memory leak in FIPS aes selftest Tomas Mraz 2013-09-20 16:04:50 +0200
  • 8c28623e94 fix segfault in openssl speed hmac in the FIPS mode Tomas Mraz 2013-09-19 15:16:50 +0200
  • d907abae39 Merge branch 'f20' of ssh://pkgs.fedoraproject.org/openssl into f20 Tomas Mraz 2013-09-13 15:33:34 +0200
  • fa93b626ad Add documentation of -attime to verify manpage Tomas Mraz 2013-09-12 11:26:07 +0200
  • 30ebb4d732 document the nextprotoneg option in manual pages Tomas Mraz 2013-09-12 10:39:33 +0200
  • ae08b15c89 document the nextprotoneg option in manual pages Tomas Mraz 2013-09-12 10:23:34 +0200
  • cb069618e7 arm: use auxv to figure out armcap.c instead of using signals (#1006474) Kyle McMartin 2013-09-11 09:52:25 -0400
  • f6aa3c2ddd arm: use auxv to figure out armcap.c instead of using signals (#1006474) Kyle McMartin 2013-09-11 09:52:25 -0400
  • eb63cc63df try to avoid some races when updating the -fips subpackage Tomas Mraz 2013-09-04 13:53:38 +0200
  • 850ca72b9a use version-release in .hmac suffix to avoid overwrite during upgrade Tomas Mraz 2013-09-02 15:02:18 +0200
  • b5d2711ab6 allow deinitialization of the FIPS mode Tomas Mraz 2013-08-29 16:41:24 +0200
  • 1465572e17 always perform the FIPS selftests in library constructor Tomas Mraz 2013-08-29 11:45:04 +0200
  • bb2f3882f2 add -fips subpackage that contains the FIPS module files Tomas Mraz 2013-08-27 16:03:43 +0200
  • 9c324da28e fix use of rdrand if available Tomas Mraz 2013-08-16 16:06:51 +0200
  • a254940dd1 Perl 5.18 rebuild Petr Písař 2013-08-03 12:05:42 +0200
  • acdf8a62f6 use symbol versioning also for the textual version Tomas Mraz 2013-07-26 13:16:10 +0200
  • 9b36f08da8 additional manual page fixes Tomas Mraz 2013-07-25 15:14:25 +0200
  • 653e1efa34 use _prefix macro Tomas Mraz 2013-07-19 11:36:23 +0200
  • 49a1fc761b Perl 5.18 rebuild Petr Písař 2013-07-17 16:32:50 +0200
  • 7ccde74773 add openssl.cnf.5 manpage symlink to config.5 Tomas Mraz 2013-07-11 10:44:55 +0200
  • 9555809e80 add relro linking flag Tomas Mraz 2013-07-10 17:54:24 +0200
  • 6a0a35eb5f Add missing fix of renamed manpages. Tomas Mraz 2013-07-10 16:43:07 +0200
  • 30aa9303c7 add support for the -trusted_first option for certificate chain verification Tomas Mraz 2013-07-10 11:02:41 +0200
  • dad6e3ee78 fix build of manual pages with current pod2man (#959439) Tomas Mraz 2013-05-03 18:38:28 +0200
  • 6705192b85 Enable ARM optimised build Peter Robinson 2013-04-21 14:33:34 +0100
  • 64e30c5369 fix random bad record mac errors (#918981) Tomas Mraz 2013-03-18 21:34:18 +0100
  • 9cf55df55b fix up the SHLIB_VERSION_NUMBER Tomas Mraz 2013-02-19 20:35:16 +0100