diff options
| author | Markus Theil <theil.markus@gmail.com> | 2025-01-10 18:27:20 +0100 |
|---|---|---|
| committer | Markus Theil <theil.markus@gmail.com> | 2025-02-11 15:48:51 +0100 |
| commit | c05c515eff3cb57822df6399e923d05b24c4ede7 (patch) | |
| tree | c22d6f70f877d2b499ce91894a31768ff17b1cdf /pkgs/development/python-modules/rangehttpserver | |
| parent | 7703504a251ad38dc2a082f4aa9c7d8ee06191dd (diff) | |
openssl_3_4: init at 3.4.1; openssl_3_3: remove
Updates OpenSSL 3.x latest to 3.4.1
Security Fixes in 3.4.1:
* Fixed RFC7250 handshakes with unauthenticated servers don't abort as expected. ([CVE-2024-12797])
* Fixed timing side-channel in ECDSA signature computation. ([CVE-2024-13176](https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176))
Release notes:
https://github.com/openssl/openssl/blob/openssl-3.4.0/NEWS.md#openssl-34
Some significant changes:
* Deprecation of TS_VERIFY_CTX_set_* functions and addition of replacement TS_VERIFY_CTX_set0_*
functions with improved semantics
* SHAKE-128 and SHAKE-256 implementations have no default digest length anymore.
That means these algorithms cannot be used with EVP_DigestFinal/_ex() unless the xoflen param is set before.
* An empty renegotiate extension will be used in TLS client hellos instead of the empty renegotiation SCSV, for
all connections with a minimum TLS version > 1.0.
* Deprecation of SSL_SESSION_get_time(), SSL_SESSION_set_time() and SSL_CTX_flush_sessions() functions in favor
of their respective _ex functions which are Y2038-safe on platforms with Y2038-safe time_t
Some new features:
* Support for directly fetched composite signature algorithms such as RSA-SHA2-256 including new API functions
* New options -not_before and -not_after for explicit setting start and end dates of certificates created with
the req and x509 apps
* Support for attribute certificates
* Support for pkeyutl in combination with key encapsulation (e.q.
PQC-KEMs): -encap/-decap
Signed-off-by: Markus Theil <theil.markus@gmail.com>
Diffstat (limited to 'pkgs/development/python-modules/rangehttpserver')
0 files changed, 0 insertions, 0 deletions
