Update to 2.018
- New upstream release 2.018 - Checks for readability of files/dirs for certificates and CA no longer use -r because this is not safe when ACLs are used (CPAN RT#106295) - New method sock_certificate similar to peer_certificate (CPAN RT#105733) - get_fingerprint can now take optional certificate as argument and compute the fingerprint of it; useful in connection with sock_certificate - Check for both EWOULDBLOCK and EAGAIN since these codes are different on some platforms (CPAN RT#106573) - Enforce default verification scheme if nothing was specified, i.e. no longer just warn but accept; if really no verification is wanted, a scheme of 'none' must be explicitly specified - Support different cipher suites per SNI hosts - startssl.t failed on darwin with old openssl since server requested client certificate but offered also anon ciphers (CPAN RT#106687) - Update patches as needed
This commit is contained in:
parent
ff435e5558
commit
6f9741cacd
@ -9,7 +9,7 @@
|
||||
SSL_verify_callback => undef,
|
||||
SSL_verifycn_scheme => undef, # fallback cn verification
|
||||
SSL_verifycn_publicsuffix => undef, # fallback default list verification
|
||||
@@ -2133,7 +2133,7 @@ WARN
|
||||
@@ -2135,7 +2135,7 @@ sub new {
|
||||
$ssl_op |= &Net::SSLeay::OP_SINGLE_DH_USE;
|
||||
$ssl_op |= &Net::SSLeay::OP_SINGLE_ECDH_USE if $can_ecdh;
|
||||
|
||||
@ -20,7 +20,7 @@
|
||||
or croak("invalid SSL_version specified");
|
||||
--- lib/IO/Socket/SSL.pod
|
||||
+++ lib/IO/Socket/SSL.pod
|
||||
@@ -932,11 +932,12 @@ protocol to the specified version.
|
||||
@@ -934,11 +934,12 @@ protocol to the specified version.
|
||||
All values are case-insensitive. Instead of 'TLSv1_1' and 'TLSv1_2' one can
|
||||
also use 'TLSv11' and 'TLSv12'. Support for 'TLSv1_1' and 'TLSv1_2' requires
|
||||
recent versions of Net::SSLeay and openssl.
|
@ -56,7 +56,7 @@
|
||||
# set values inside _init to work with perlcc, RT#95452
|
||||
--- lib/IO/Socket/SSL.pod
|
||||
+++ lib/IO/Socket/SSL.pod
|
||||
@@ -958,12 +958,8 @@ documentation (L<http://www.openssl.org/
|
||||
@@ -960,12 +960,8 @@ documentation (L<http://www.openssl.org/
|
||||
for more details.
|
||||
|
||||
Unless you fail to contact your peer because of no shared ciphers it is
|
||||
@ -69,5 +69,5 @@
|
||||
+recommended to leave this option at the default setting, which honors the
|
||||
+system-wide DEFAULT cipher list.
|
||||
|
||||
=item SSL_honor_cipher_order
|
||||
|
||||
In case different cipher lists are needed for different SNI hosts a hash can be
|
||||
given with the host as key and the cipher suite as value, similar to
|
@ -1,16 +1,19 @@
|
||||
Name: perl-IO-Socket-SSL
|
||||
Version: 2.016
|
||||
Release: 3%{?dist}
|
||||
Version: 2.018
|
||||
Release: 1%{?dist}
|
||||
Summary: Perl library for transparent SSL
|
||||
Group: Development/Libraries
|
||||
License: GPL+ or Artistic
|
||||
URL: http://search.cpan.org/dist/IO-Socket-SSL/
|
||||
Source0: http://search.cpan.org/CPAN/authors/id/S/SU/SULLR/IO-Socket-SSL-%{version}.tar.gz
|
||||
Patch0: IO-Socket-SSL-2.016-use-system-default-cipher-list.patch
|
||||
Patch1: IO-Socket-SSL-2.016-use-system-default-SSL-version.patch
|
||||
Patch0: IO-Socket-SSL-2.018-use-system-default-cipher-list.patch
|
||||
Patch1: IO-Socket-SSL-2.018-use-system-default-SSL-version.patch
|
||||
BuildRoot: %{_tmppath}/%{name}-%{version}-%{release}-root-%(id -nu)
|
||||
BuildArch: noarch
|
||||
# Module Build
|
||||
BuildRequires: coreutils
|
||||
BuildRequires: findutils
|
||||
BuildRequires: make
|
||||
BuildRequires: perl
|
||||
BuildRequires: perl(ExtUtils::MakeMaker)
|
||||
# Module Runtime
|
||||
@ -112,6 +115,23 @@ rm -rf %{buildroot}
|
||||
%{_mandir}/man3/IO::Socket::SSL::Utils.3*
|
||||
|
||||
%changelog
|
||||
* Mon Aug 31 2015 Paul Howarth <paul@city-fan.org> - 2.018-1
|
||||
- Update to 2.018
|
||||
- Checks for readability of files/dirs for certificates and CA no longer use
|
||||
-r because this is not safe when ACLs are used (CPAN RT#106295)
|
||||
- New method sock_certificate similar to peer_certificate (CPAN RT#105733)
|
||||
- get_fingerprint can now take optional certificate as argument and compute
|
||||
the fingerprint of it; useful in connection with sock_certificate
|
||||
- Check for both EWOULDBLOCK and EAGAIN since these codes are different on
|
||||
some platforms (CPAN RT#106573)
|
||||
- Enforce default verification scheme if nothing was specified, i.e. no
|
||||
longer just warn but accept; if really no verification is wanted, a scheme
|
||||
of 'none' must be explicitly specified
|
||||
- Support different cipher suites per SNI hosts
|
||||
- startssl.t failed on darwin with old openssl since server requested client
|
||||
certificate but offered also anon ciphers (CPAN RT#106687)
|
||||
- Update patches as needed
|
||||
|
||||
* Thu Jun 18 2015 Fedora Release Engineering <rel-eng@lists.fedoraproject.org> - 2.016-3
|
||||
- Rebuilt for https://fedoraproject.org/wiki/Fedora_23_Mass_Rebuild
|
||||
|
||||
|
Loading…
Reference in New Issue
Block a user