<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib/libcrypto, branch libressl-v3.3.3</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=libressl-v3.3.3</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=libressl-v3.3.3'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2021-04-15T14:15:03+00:00</updated>
<entry>
<title>Switch back to the legacy verifier for the release.</title>
<updated>2021-04-15T14:15:03+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-04-15T14:15:03+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=013c39e97f0af8342cdb560b4a2a45f87602f7b7'/>
<id>urn:sha1:013c39e97f0af8342cdb560b4a2a45f87602f7b7</id>
<content type='text'>
This is disappointing as a lot of work was put into the new verifier
during this cycle. However, there are still too many known bugs and
incompatibilities. It is better to be faced with known broken behavior
than with new broken behavior and to switch now rather than via errata.
This way we have another cycle to iron out the kinks and to fix some of
the remaining bugs.

ok jsing
</content>
</entry>
<entry>
<title>Don't leak param-&gt;name in x509_verify_param_zero()</title>
<updated>2021-04-05T07:02:50+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-04-05T07:02:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=57e3ff55d71172acc1caf21e8c346e67b7089676'/>
<id>urn:sha1:57e3ff55d71172acc1caf21e8c346e67b7089676</id>
<content type='text'>
For dynamically allocated verify parameters, param-&gt;name is only ever set
in X509_VERIFY_set1_name() where the old one is freed and the new one is
assigned via strdup(). Setting it to NULL without freeing it beforehand is
a leak.

looks correct to millert, ok inoguchi
</content>
</entry>
<entry>
<title>Bump minors after symbol addition</title>
<updated>2021-03-31T17:02:18+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-03-31T17:02:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=0c1b885ba6292c3b2d58d343977ac4cab728cc2b'/>
<id>urn:sha1:0c1b885ba6292c3b2d58d343977ac4cab728cc2b</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Expose various DTLSv1.2 specific functions and defines</title>
<updated>2021-03-31T16:59:32+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-03-31T16:59:32+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2ebb1bafcf20e3417b35907fc27572bb0ff9faac'/>
<id>urn:sha1:2ebb1bafcf20e3417b35907fc27572bb0ff9faac</id>
<content type='text'>
ok bcook inoguchi jsing
</content>
</entry>
<entry>
<title>Provide missing prototype for d2i_DSAPrivateKey_fp(3)</title>
<updated>2021-03-31T16:51:06+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-03-31T16:51:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=a2c7dc9f61c905842b4ecaed7ee8beba13289e15'/>
<id>urn:sha1:a2c7dc9f61c905842b4ecaed7ee8beba13289e15</id>
<content type='text'>
ok bcook inoguchi jsing
</content>
</entry>
<entry>
<title>Document EVP_PKEY_new_CMAC_key(3)</title>
<updated>2021-03-31T16:48:43+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-03-31T16:48:43+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5f72b11bd2dc2e740c447ac146e4fdf67f2aee3b'/>
<id>urn:sha1:5f72b11bd2dc2e740c447ac146e4fdf67f2aee3b</id>
<content type='text'>
ok bcook inoguchi jsing
</content>
</entry>
<entry>
<title>Provide EVP_PKEY_new_CMAC_key(3)</title>
<updated>2021-03-31T16:47:01+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-03-31T16:47:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=c7922f8b9a137af47dc02a37ceec9bfacef62554'/>
<id>urn:sha1:c7922f8b9a137af47dc02a37ceec9bfacef62554</id>
<content type='text'>
ok bcook inoguchi jsing
</content>
</entry>
<entry>
<title>Prepare documenting EVP_PKEY_new_CMAC_key(3)</title>
<updated>2021-03-29T17:58:29+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-03-29T17:58:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=43988cfad5dfc057f452876ef7cfca69a2f3779c'/>
<id>urn:sha1:43988cfad5dfc057f452876ef7cfca69a2f3779c</id>
<content type='text'>
Based on some text in OpenSSL 1.1.1's EVP_PKEY_new.pod.
</content>
</entry>
<entry>
<title>Prepare to provide EVP_PKEY_new_CMAC_key()</title>
<updated>2021-03-29T15:57:23+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-03-29T15:57:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e5044a16b50be503267937298648ce4abb8bbcbc'/>
<id>urn:sha1:e5044a16b50be503267937298648ce4abb8bbcbc</id>
<content type='text'>
sebastia ran into this when attempting to update security/hcxtools.
This will be tested via wycheproof.go once the symbol is public.

ok jsing, tested by sebastia
</content>
</entry>
<entry>
<title>Avoid mangled output in BIO_debug_callback</title>
<updated>2021-03-25T09:26:17+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2021-03-25T09:26:17+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=0939b7a663a0450286c355c29910f9611128d2b0'/>
<id>urn:sha1:0939b7a663a0450286c355c29910f9611128d2b0</id>
<content type='text'>
Instead of blindly skipping 14 characters, we can use the return
value of snprintf() to determine how much we should skip.

From Martin Vahlensieck with minor tweaks by me
</content>
</entry>
</feed>
