| non port: security/openssl/Makefile |
Number of commits found: 336 (showing only 36 on this page) |
|
Wednesday, 19 Mar 2003
|
06:26 dinoex
- switch to USE_PERL5_BUILD
- add security patch
Approved by: kris
Obtained from: http://www.openssl.org/news/secadv_20030317.txt
 |
|
Thursday, 20 Feb 2003
|
18:26 dinoex
- add COMMENT
 |
|
Wednesday, 19 Feb 2003
|
21:12 dinoex
- merged some patches in distribution
- added thread support on alpha, sparc64
- Update to 0.9.7a (with security fix)
- defaults openssl to port
 |
|
Saturday, 15 Feb 2003
|
06:31 dinoex
- sync SHLIBVER for OPENSSL_OVERWRITE_BASE=yes and 5.0-CURRENT
 |
|
Sunday, 9 Feb 2003
|
05:45 dinoex
- Fix spelling
 |
|
Friday, 31 Jan 2003
|
19:54 dinoex
- Fix CURRENT version bump in openssl, so ports link as expected.
 |
|
Wednesday, 29 Jan 2003
|
20:00 dinoex
- Update to 0.9.7
- rnd_keys.c now in distribution
- drop lib/libRSAglue.a
- build on i386, alpha, sparc64, ia64
- build on 2.2.8 with the gas-patch as noted in FAQ
 |
|
Thursday, 2 Jan 2003
|
04:17 dinoex
- Update to 0.9.6h
- md5 verified
- add test target
- make build on sparc64
 |
|
Friday, 25 Oct 2002
|
20:41 dinoex
- add rnd_keys.c for compatibilty with base. (patch by: jtraub@isilon.com)
- OPENSSL_OVERWRITE_BASE: fix package building
- Fix install of manpages for 3.x
 |
|
Wednesday, 16 Oct 2002
|
18:29 dinoex
remove pkg-plist.noshared and use PLIST_SUB
 |
|
Saturday, 12 Oct 2002
|
21:04 dinoex
Install manpages in standard only if OPENSSL_OVERWRITE_BASE is not set.
 |
20:27 dinoex
Install openssl's man pages in standard manpath
PR: 43658
 |
|
Sunday, 15 Sep 2002
|
13:01 dinoex
fix path for option OPENSSL_OVERWRITE_BASE
PR: 42665
Submitted by: roman@bellavista.cz
 |
|
Saturday, 14 Sep 2002
|
13:32 sobomax
Due to popular demant into each port which might be inserted into dependency
list by bsd.port.mk insert anti foot-shooting device, which prevents
infinite fork loop when the user defines corresponding USE_XXX in global
make.conf, command line or environment.
Similar devices should probably be inserted into ports that might be inserted
into dependency list by others bsd.foo.mk files (bsd.ruby.mk, bsd.python.mk
and so on.)
 |
|
Saturday, 10 Aug 2002
|
08:30 dinoex
Security Update to: 0.9.6g
 |
|
Tuesday, 6 Aug 2002
|
05:46 dinoex
Sync Bugfix from CURRENT
 |
|
Thursday, 1 Aug 2002
|
17:31 dinoex
when build with OPENSSL_OVERWRITE_BASE
reset SHLIBVER to 2, so the existing lib is overwritten fully.
Warning: some programs track the version number internally too.
Suggested by:nectar
 |
|
Tuesday, 30 Jul 2002
|
17:38 dinoex
Security Update to 0.9.6e
 |
|
Sunday, 23 Jun 2002
|
21:14 dinoex
Remove FORBIDDEN, oenssl-0.9.6d doesn't made in into 4.6 RELEASE
 |
|
Sunday, 16 Jun 2002
|
14:04 dinoex
Add an option OPENSSL_OVERWRITE_BASE=yes as we have done in OPENSHH
 |
|
Monday, 13 May 2002
|
18:54 dinoex
Update to: 0.9.6d
See:
http://www.openssl.org/source/exp/CHANGES
Port improvements:
proccessor type is now detected
Add option: OPENSSL_WITH_386
This set as default for package generation on bento
 |
|
Saturday, 4 May 2002
|
04:38 dinoex
openssl:
- some configure scripts check the version of the lib
so we need to update SHLIBVER
- bump PORTREVISION
openssh:
- build ports with local openssl, if it exists
 |
|
Sunday, 21 Apr 2002
|
13:02 dinoex
- Update to 0.9.6c
- more manpages
- shift FORBIDDEN
Excerpt of Changes between 0.9.6b and 0.9.6c [21 dec 2001]
*) Fix BN_rand_range bug pointed out by Dominikus Scherkl
*) Only add signing time to PKCS7 structures if it is not already present.
*) Fix crypto/objects/objects.h: "ld-ce" should be "id-ce", OBJ_ld_ce
should be OBJ_id_ce. Also some ip-pda OIDs in crypto/objects/objects.txt
were incorrect (cf. RFC 3039).
*) Release CRYPTO_LOCK_DYNLOCK when CRYPTO_destroy_dynlockid()
returns early because it has nothing to do.
*) Fix mutex callback return values in crypto/engine/hw_ncipher.c.
*) Change ssl/s2_clnt.c and ssl/s2_srvr.c so that received handshake
messages are stored in a single piece (fixed-length part and
variable-length part combined) and fix various bugs found on the way.
*) Disable caching in BIO_gethostbyname(), directly use gethostbyname()
instead. BIO_gethostbyname() does not know what timeouts are
appropriate, so entries would stay in cache even when they have
become invalid.
*) Change ssl23_get_client_hello (ssl/s23_srvr.c) behaviour when
faced with a pathologically small ClientHello fragment that does
not contain client_version: Instead of aborting with an error,
simply choose the highest available protocol version (i.e.,
TLS 1.0 unless it is disabled).
*) Fix SSL handshake functions and SSL_clear() such that SSL_clear()
never resets s->method to s->ctx->method when called from within
one of the SSL handshake functions.
*) In ssl3_get_client_hello (ssl/s3_srvr.c), generate a fatal alert
(sent using the client's version number) if client_version is
smaller than the protocol version in use. Also change
ssl23_get_client_hello (ssl/s23_srvr.c) to select TLS 1.0 if
the client demanded SSL 3.0 but only TLS 1.0 is enabled; then
the client will at least see that alert.
*) Fix ssl3_get_message (ssl/s3_both.c) to handle message fragmentation
correctly.
*) Avoid infinite loop in ssl3_get_message (ssl/s3_both.c) if a
client receives HelloRequest while in a handshake.
*) Bugfix in ssl3_accept (ssl/s3_srvr.c): Case SSL3_ST_SW_HELLO_REQ_C
should end in 'break', not 'goto end' which circuments various
cleanups done in state SSL_ST_OK. But session related stuff
must be disabled for SSL_ST_OK in the case that we just sent a
HelloRequest. Also avoid some overhead by not calling
ssl_init_wbio_buffer() before just sending a HelloRequest.
*) Fix ssl/s3_enc.c, ssl/t1_enc.c and ssl/s3_pkt.c so that we don't
reveal whether illegal block cipher padding was found or a MAC
verification error occured. (Neither SSLerr() codes nor alerts
are directly visible to potential attackers, but the information
may leak via logfiles.) ssl/s2_pkt.c failed to verify that the
purported number of padding bytes is in the legal range.
*) Improve RSA_padding_check_PKCS1_OAEP() check again to avoid
'wristwatch attack' using huge encoding parameters (cf.
James H. Manger's CRYPTO 2001 paper). Note that the
RSA_PKCS1_OAEP_PADDING case of RSA_private_decrypt() does not use
encoding parameters and hence was not vulnerable.
*) BN_sqr() bug fix.
*) Rabin-Miller test analyses assume uniformly distributed witnesses,
so use BN_pseudo_rand_range() instead of using BN_pseudo_rand()
followed by modular reduction.
*) Add BN_pseudo_rand_range() with obvious functionality: BN_rand_range()
equivalent based on BN_pseudo_rand() instead of BN_rand().
*) s3_srvr.c: allow sending of large client certificate lists (> 16 kB).
This function was broken, as the check for a new client hello message
to handle SGC did not allow these large messages.
*) Add alert descriptions for TLSv1 to SSL_alert_desc_string[_long]().
*) Fix buggy behaviour of BIO_get_num_renegotiates() and BIO_ctrl()
for BIO_C_GET_WRITE_BUF_SIZE ("Stephen Hinton" <shinton@netopia.com>).
*) In ssl3_get_key_exchange (ssl/s3_clnt.c), call ssl3_get_message()
with the same message size as in ssl3_get_certificate_request().
Otherwise, if no ServerKeyExchange message occurs, CertificateRequest
messages might inadvertently be reject as too long.
*) Modified SSL library such that the verify_callback that has been set
specificly for an SSL object with SSL_set_verify() is actually being
used. Before the change, a verify_callback set with this function was
ignored and the verify_callback() set in the SSL_CTX at the time of
the call was used. New function X509_STORE_CTX_set_verify_cb() introduced
to allow the necessary settings.
*) In OpenSSL 0.9.6a and 0.9.6b, crypto/dh/dh_key.c ignored
dh->length and always used
BN_rand_range(priv_key, dh->p).
So switch back to
BN_rand(priv_key, l, ...)
where 'l' is dh->length if this is defined, or BN_num_bits(dh->p)-1
otherwise.
*) In RSA_eay_public_encrypt, RSA_eay_private_decrypt, RSA_eay_private_encrypt
RSA_eay_public_decrypt always reject numbers >= n.
*) In crypto/rand/md_rand.c, use a new short-time lock CRYPTO_LOCK_RAND2
to synchronize access to 'locking_thread'.
*) In crypto/rand/md_rand.c, set 'locking_thread' to current thread's ID
*before* setting the 'crypto_lock_rand' flag. The previous code had
a race condition if 0 is a valid thread ID.
 |
|
Saturday, 5 Jan 2002
|
23:43 dinoex
- make portlint happier - use DOCSDIR or EXAMPLESDIR - get rid of some
INTERACTIVE scrips in news/ifmail
 |
|
Monday, 3 Sep 2001
|
19:53 dinoex
Allow to build libcrypto.so.2 for 4.0, 4,1 and 4.2 RELEASE so dependent ports
can build correctly.
 |
|
Friday, 20 Jul 2001
|
15:24 okazaki
Upgrade openssl to 0.9.6b.
 |
|
Sunday, 8 Jul 2001
|
00:34 okazaki
Make it buildable on 2.2-STABLE again.
 |
|
Wednesday, 23 May 2001
|
03:47 dougb
Upgrade openssl to 0.9.6a and bump the shlib version in the process due to
non-backwards compatible changes. The shlib bump necessitates a corresponding
bump in bsd.port.mk for the automagic openssl dependency. Mistakes in the port
are my responsibility. Approval for the bsd.port.mk commit comes through asami
-> kkenn -> me. Kris is a little busy at the moment, so he asked me to lob it
in.
 |
|
Sunday, 22 Apr 2001
|
19:42 sobomax
1. In addition to OSVERSION test, check for existence of /usr/lib/libssl.a and
don't mark BROKEN if it doesn't exist. 2. Provide a workaround for inability
of recent gcc to link shared library when -Wl,-whole-archive ld(1) option is
used. This should make possible to build the port on recent -stable or
-current.
 |
|
Sunday, 18 Feb 2001
|
13:35 dirk
Hand out maintainership to ports@FreeBSD.org.
 |
|
Saturday, 10 Feb 2001
|
01:30 alfred
give aout machines shared libraries as well
 |
|
Sunday, 8 Oct 2000
|
11:23 asami
Change PKGDIR from pkg/ to . Also fix places where ${PKGDIR} is spelled out
(many of which are ${PKGDIR}/MESSAGE -> ${PKGMESSAGE} type fixes that
shouldn't have been necessary) and the string "/pkg/" appear.
 |
06:59 asami
Rename PLIST.noshared to pkg-plist.noshared.
 |
|
Sunday, 17 Sep 2000
|
12:06 dirk
Rip off rsaref (and thus USA_RESIDENT).
 |
|
Sunday, 16 Jul 2000
|
10:18 dirk
Set INSTALLS_SHLIB.
 |
|
Friday, 16 Jun 2000
|
09:48 sobomax
Fourth round of INSTALLS_SHLIBS conversion.
 |
Number of commits found: 336 (showing only 36 on this page) |