summaryrefslogtreecommitdiffstats
path: root/security/openssl
Commit message (Collapse)AuthorAgeFilesLines
* - Update to 0.9.7dinoex2003-01-2911-614/+848
| | | | | | | - rnd_keys.c now in distribution - drop lib/libRSAglue.a - build on i386, alpha, sparc64, ia64 - build on 2.2.8 with the gas-patch as noted in FAQ
* - add new checksum, only "OPENSSL_VERSION_NUMBER" has been changeddinoex2003-01-021-0/+1
| | | | | | in the distribution after 6th December. 2178290 6 Dez 00:25 /usr/ports/distfiles/openssl-0.9.6h.tar.gz 2178314 8 Dez 21:43 /usr/ports/distfiles/openssl-0.9.6h.tar.gz
* - Update to 0.9.6hdinoex2003-01-024-8/+31
| | | | | | - md5 verified - add test target - make build on sparc64
* - add rnd_keys.c for compatibilty with base. (patch by: jtraub@isilon.com)dinoex2002-10-255-17/+503
| | | | | - OPENSSL_OVERWRITE_BASE: fix package building - Fix install of manpages for 3.x
* remove pkg-plist.noshared and use PLIST_SUBdinoex2002-10-163-81/+6
|
* Install manpages in standard only if OPENSSL_OVERWRITE_BASE is not set.dinoex2002-10-122-1/+9
|
* Install openssl's man pages in standard manpathdinoex2002-10-123-7/+13
| | | | PR: 43658
* fix path for option OPENSSL_OVERWRITE_BASEdinoex2002-09-151-1/+4
| | | | | PR: 42665 Submitted by: roman@bellavista.cz
* Due to popular demant into each port which might be inserted into dependencysobomax2002-09-141-0/+4
| | | | | | | | | | list by bsd.port.mk insert anti foot-shooting device, which prevents infinite fork loop when the user defines corresponding USE_XXX in global make.conf, command line or environment. Similar devices should probably be inserted into ports that might be inserted into dependency list by others bsd.foo.mk files (bsd.ruby.mk, bsd.python.mk and so on.)
* new Option USE_OPENSSL_BETAdinoex2002-08-301-0/+5
|
* Security Update to: 0.9.6gdinoex2002-08-103-14/+2
|
* Sync Bugfix from CURRENTdinoex2002-08-062-0/+12
|
* Fix links to the Handbook, the FAQ and the porters-handbook.blackend2002-08-041-1/+1
| | | | Approved by: portmgr
* when build with OPENSSL_OVERWRITE_BASEdinoex2002-08-011-0/+1
| | | | | | reset SHLIBVER to 2, so the existing lib is overwritten fully. Warning: some programs track the version number internally too. Suggested by:nectar
* Security Update to 0.9.6edinoex2002-07-303-58/+6
|
* Remove FORBIDDEN, oenssl-0.9.6d doesn't made in into 4.6 RELEASEdinoex2002-06-231-3/+0
|
* Add an option OPENSSL_OVERWRITE_BASE=yes as we have done in OPENSHHdinoex2002-06-161-0/+5
|
* - get rid of duplicate code in Makefiles.dinoex2002-05-311-0/+56
| | | | | - Fix USE_OPENSSL_PORT and USE_OPENSSL_BASE - drop obsolete/broken USE_OPENSSL
* Update to: 0.9.6ddinoex2002-05-133-15/+18
| | | | | | | | | | | See: http://www.openssl.org/source/exp/CHANGES Port improvements: proccessor type is now detected Add option: OPENSSL_WITH_386 This set as default for package generation on bento
* openssl:dinoex2002-05-042-3/+5
| | | | | | | | | - some configure scripts check the version of the lib so we need to update SHLIBVER - bump PORTREVISION openssh: - build ports with local openssl, if it exists
* - Update to 0.9.6cdinoex2002-04-213-26/+32
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | - more manpages - shift FORBIDDEN Excerpt of Changes between 0.9.6b and 0.9.6c [21 dec 2001] *) Fix BN_rand_range bug pointed out by Dominikus Scherkl *) Only add signing time to PKCS7 structures if it is not already present. *) Fix crypto/objects/objects.h: "ld-ce" should be "id-ce", OBJ_ld_ce should be OBJ_id_ce. Also some ip-pda OIDs in crypto/objects/objects.txt were incorrect (cf. RFC 3039). *) Release CRYPTO_LOCK_DYNLOCK when CRYPTO_destroy_dynlockid() returns early because it has nothing to do. *) Fix mutex callback return values in crypto/engine/hw_ncipher.c. *) Change ssl/s2_clnt.c and ssl/s2_srvr.c so that received handshake messages are stored in a single piece (fixed-length part and variable-length part combined) and fix various bugs found on the way. *) Disable caching in BIO_gethostbyname(), directly use gethostbyname() instead. BIO_gethostbyname() does not know what timeouts are appropriate, so entries would stay in cache even when they have become invalid. *) Change ssl23_get_client_hello (ssl/s23_srvr.c) behaviour when faced with a pathologically small ClientHello fragment that does not contain client_version: Instead of aborting with an error, simply choose the highest available protocol version (i.e., TLS 1.0 unless it is disabled). *) Fix SSL handshake functions and SSL_clear() such that SSL_clear() never resets s->method to s->ctx->method when called from within one of the SSL handshake functions. *) In ssl3_get_client_hello (ssl/s3_srvr.c), generate a fatal alert (sent using the client's version number) if client_version is smaller than the protocol version in use. Also change ssl23_get_client_hello (ssl/s23_srvr.c) to select TLS 1.0 if the client demanded SSL 3.0 but only TLS 1.0 is enabled; then the client will at least see that alert. *) Fix ssl3_get_message (ssl/s3_both.c) to handle message fragmentation correctly. *) Avoid infinite loop in ssl3_get_message (ssl/s3_both.c) if a client receives HelloRequest while in a handshake. *) Bugfix in ssl3_accept (ssl/s3_srvr.c): Case SSL3_ST_SW_HELLO_REQ_C should end in 'break', not 'goto end' which circuments various cleanups done in state SSL_ST_OK. But session related stuff must be disabled for SSL_ST_OK in the case that we just sent a HelloRequest. Also avoid some overhead by not calling ssl_init_wbio_buffer() before just sending a HelloRequest. *) Fix ssl/s3_enc.c, ssl/t1_enc.c and ssl/s3_pkt.c so that we don't reveal whether illegal block cipher padding was found or a MAC verification error occured. (Neither SSLerr() codes nor alerts are directly visible to potential attackers, but the information may leak via logfiles.) ssl/s2_pkt.c failed to verify that the purported number of padding bytes is in the legal range. *) Improve RSA_padding_check_PKCS1_OAEP() check again to avoid 'wristwatch attack' using huge encoding parameters (cf. James H. Manger's CRYPTO 2001 paper). Note that the RSA_PKCS1_OAEP_PADDING case of RSA_private_decrypt() does not use encoding parameters and hence was not vulnerable. *) BN_sqr() bug fix. *) Rabin-Miller test analyses assume uniformly distributed witnesses, so use BN_pseudo_rand_range() instead of using BN_pseudo_rand() followed by modular reduction. *) Add BN_pseudo_rand_range() with obvious functionality: BN_rand_range() equivalent based on BN_pseudo_rand() instead of BN_rand(). *) s3_srvr.c: allow sending of large client certificate lists (> 16 kB). This function was broken, as the check for a new client hello message to handle SGC did not allow these large messages. *) Add alert descriptions for TLSv1 to SSL_alert_desc_string[_long](). *) Fix buggy behaviour of BIO_get_num_renegotiates() and BIO_ctrl() for BIO_C_GET_WRITE_BUF_SIZE ("Stephen Hinton" <shinton@netopia.com>). *) In ssl3_get_key_exchange (ssl/s3_clnt.c), call ssl3_get_message() with the same message size as in ssl3_get_certificate_request(). Otherwise, if no ServerKeyExchange message occurs, CertificateRequest messages might inadvertently be reject as too long. *) Modified SSL library such that the verify_callback that has been set specificly for an SSL object with SSL_set_verify() is actually being used. Before the change, a verify_callback set with this function was ignored and the verify_callback() set in the SSL_CTX at the time of the call was used. New function X509_STORE_CTX_set_verify_cb() introduced to allow the necessary settings. *) In OpenSSL 0.9.6a and 0.9.6b, crypto/dh/dh_key.c ignored dh->length and always used BN_rand_range(priv_key, dh->p). So switch back to BN_rand(priv_key, l, ...) where 'l' is dh->length if this is defined, or BN_num_bits(dh->p)-1 otherwise. *) In RSA_eay_public_encrypt, RSA_eay_private_decrypt, RSA_eay_private_encrypt RSA_eay_public_decrypt always reject numbers >= n. *) In crypto/rand/md_rand.c, use a new short-time lock CRYPTO_LOCK_RAND2 to synchronize access to 'locking_thread'. *) In crypto/rand/md_rand.c, set 'locking_thread' to current thread's ID *before* setting the 'crypto_lock_rand' flag. The previous code had a race condition if 0 is a valid thread ID.
* - make portlint happierdinoex2002-01-051-2/+2
| | | | | - use DOCSDIR or EXAMPLESDIR - get rid of some INTERACTIVE scrips in news/ifmail
* - PORTDOCS policepat2001-12-241-2/+2
| | | | | - DOCSDIR support to some - Brush out some lint
* Style police: WWW tags should either end in a file/script or TRAILING /; Fix ↵lioux2001-11-201-1/+1
| | | | the later case
* Allow to build libcrypto.so.2 for 4.0, 4,1 and 4.2 RELEASEdinoex2001-09-031-1/+1
| | | | so dependent ports can build correctly.
* Upgrade openssl to 0.9.6b.okazaki2001-07-202-2/+2
|
* Make it buildable on 2.2-STABLE again.okazaki2001-07-071-1/+1
|
* Upgrade openssl to 0.9.6a and bump the shlib version in the processdougb2001-05-236-49/+85
| | | | | | | | | | due to non-backwards compatible changes. The shlib bump necessitates a corresponding bump in bsd.port.mk for the automagic openssl dependency. Mistakes in the port are my responsibility. Approval for the bsd.port.mk commit comes through asami -> kkenn -> me. Kris is a little busy at the moment, so he asked me to lob it in. Approved by: kris
* 1. In addition to OSVERSION test, check for existence of /usr/lib/libssl.asobomax2001-04-222-6/+9
| | | | | | | and don't mark BROKEN if it doesn't exist. 2. Provide a workaround for inability of recent gcc to link shared library when -Wl,-whole-archive ld(1) option is used. This should make possible to build the port on recent -stable or -current.
* Hand out maintainership to ports@FreeBSD.org.dirk2001-02-181-1/+1
| | | | I don't use any 3.x system any longer.
* give aout machines shared libraries as wellalfred2001-02-102-2/+5
|
* Change PKGDIR from pkg/ to . Also fix places where ${PKGDIR} isasami2000-10-081-1/+1
| | | | | | spelled out (many of which are ${PKGDIR}/MESSAGE -> ${PKGMESSAGE} type fixes that shouldn't have been necessary) and the string "/pkg/" appear.
* Rename PLIST.noshared to pkg-plist.noshared.asami2000-10-081-1/+1
|
* Rip off rsaref (and thus USA_RESIDENT).dirk2000-09-171-16/+2
| | | | Submitted by: kris
* Set INSTALLS_SHLIB.dirk2000-07-161-0/+1
| | | | | Submitted by: Dmitry Grigorovich <odip@bionet.nsc.ru> Forgotten by: sobomax
* Fourth round of INSTALLS_SHLIBS conversion.sobomax2000-06-162-3/+0
|
* Disable shared libraries for a.out systems in order to make it builddirk2000-04-252-0/+85
| | | | | | | | | on such systems. (I know we aren't supporting a.out systems any more, but this was requested by some people. And the change is trivial.) Tested by: nate
* Correct whitespace introduced during PORTNAME conversion and portlintmharo2000-04-211-1/+1
|
* Add missing ldconfig.dirk2000-04-161-0/+2
|
* Upgrade to 0.9.5a.dirk2000-04-165-70/+81
|
* Update with the new PORTNAME/PORTVERSION variablescpiazza2000-04-091-2/+2
|
* Check against ${OSVERSION} instead of the existence of the library filesdirk2000-01-281-2/+3
| | | | whether openssl should be build or not.
* Check wheather OpenSSL is installed in the base system already anddirk1999-12-301-0/+4
| | | | | | | skip openssl port if so. (I. e. check the existence of /usr/bin/openssl, /usr/lib/libcrypto.so and /usr/lib/libssl.so. If they exist set FORBIDDEN.)
* Build and install shared libraries libcrypto.so.1 and libssl.so.1, too.dirk1999-11-073-5/+39
| | | | Submitted by: Issei Suzuki <issei@jp.freebsd.org>
* Don't use ${PREFIX} in pkg/MESSAGE but /usr/local and substitutedirk1999-09-172-2/+2
| | | | | | /usr/local accordingly via Makefile. Submitted by: Bill Fumerola <billf@FreeBSD.org>
* $Id$ -> $FreeBSD$peter1999-08-311-1/+1
|
* Make it clear(er) that RSAREF is a port that must be installed, not, perhaps,hoek1999-08-181-2/+2
| | | | | | some piece of the base system (a-la crypto). I wrote "rsaref port" instead of "security/rsaref" since on the remote chance that rsaref switches categories, I don't want the message to become wrong.
* Upgrade to 0.9.4.dirk1999-08-095-75/+69
|
* Upgrade to 0.9.3a.dirk1999-06-062-5/+5
|
* Upgrade to OpenSSL 0.9.3:dirk1999-06-027-105/+161
| | | | | - some changes of the directory layout: e. g. ${PREFIX}/lib/openssl.cnf -> ${PREFIX}/openssl/openssl.cnf
OpenPOWER on IntegriCloud