<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/lib, branch OPENBSD_4_8</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_4_8</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_4_8'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2011-02-11T03:24:29+00:00</updated>
<entry>
<title>MFC:</title>
<updated>2011-02-11T03:24:29+00:00</updated>
<author>
<name>djm</name>
<email></email>
</author>
<published>2011-02-11T03:24:29+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=1fe599fd100c11cb40db62e487aad54473fca534'/>
<id>urn:sha1:1fe599fd100c11cb40db62e487aad54473fca534</id>
<content type='text'>
----------------------------
revision 1.8
date: 2011/02/10 22:40:27;  author: djm;  state: Exp;  lines: +7 -1
fix for CVE-2011-0014 "OCSP stapling vulnerability";
ok markus@ jasper@ miod@

AFAIK nothing in base uses this, though apache2 from ports may be affected.
----------------------------
</content>
</entry>
<entry>
<title>Security fix for CVE-2010-4180 as mentioned in http://www.openssl.org/news/secadv_20101202.txt.</title>
<updated>2010-12-15T09:43:55+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-12-15T09:43:55+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=68ed203952c3b617331b455050995ec6996479c8'/>
<id>urn:sha1:68ed203952c3b617331b455050995ec6996479c8</id>
<content type='text'>
where clients could modify the stored session
cache ciphersuite and in some cases even downgrade the suite to weaker ones.

This code is not enabled by default.

ok djm@
</content>
</entry>
<entry>
<title>- Apply security fix for CVE-2010-3864.</title>
<updated>2010-11-17T19:12:57+00:00</updated>
<author>
<name>jasper</name>
<email></email>
</author>
<published>2010-11-17T19:12:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=177bc2377a2dcb3fa5f2ec36f9182fd8635e98f3'/>
<id>urn:sha1:177bc2377a2dcb3fa5f2ec36f9182fd8635e98f3</id>
<content type='text'>
ok djm@ deraadt@
</content>
</entry>
<entry>
<title>This commit was manufactured by cvs2git to create branch 'OPENBSD_4_8'.</title>
<updated>2010-07-28T09:00:22+00:00</updated>
<author>
<name>cvs2svn</name>
<email>admin@example.com</email>
</author>
<published>2010-07-28T09:00:22+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=2cd27778e908a259063b84a1e91bb327cf27026c'/>
<id>urn:sha1:2cd27778e908a259063b84a1e91bb327cf27026c</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Sync hcreate(3) with NetBSD, adding some caveats.</title>
<updated>2010-07-28T09:00:20+00:00</updated>
<author>
<name>ray</name>
<email></email>
</author>
<published>2010-07-28T09:00:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=b8cf097636fac0ceae64ef6eaea1e283d31c6d71'/>
<id>urn:sha1:b8cf097636fac0ceae64ef6eaea1e283d31c6d71</id>
<content type='text'>
OK jmc
</content>
</entry>
<entry>
<title>getopt_long.c replaced getopt.c 6+ years ago; we can retire</title>
<updated>2010-07-22T19:31:53+00:00</updated>
<author>
<name>blambert</name>
<email></email>
</author>
<published>2010-07-22T19:31:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=0e5819976ae422dacdfb32d9b4bf3cc18ad089b2'/>
<id>urn:sha1:0e5819976ae422dacdfb32d9b4bf3cc18ad089b2</id>
<content type='text'>
the REPLACE_GETOPT macro, at long last

ok millert@
</content>
</entry>
<entry>
<title>Document new unsetenv() error returns.</title>
<updated>2010-07-06T20:52:00+00:00</updated>
<author>
<name>naddy</name>
<email></email>
</author>
<published>2010-07-06T20:52:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=b4bd20add01dcd4b9a8b58e83b1e16b8e1a5f039'/>
<id>urn:sha1:b4bd20add01dcd4b9a8b58e83b1e16b8e1a5f039</id>
<content type='text'>
From Nicolas Legrand &lt;nlegrand@ethelred.fr&gt;; ok jmc@
</content>
</entry>
<entry>
<title>getpeereid() can now be a library routine using getsockopt() with</title>
<updated>2010-07-01T19:15:30+00:00</updated>
<author>
<name>deraadt</name>
<email></email>
</author>
<published>2010-07-01T19:15:30+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=3f82b28f1afc35ad022d05115d5cc220518cdef7'/>
<id>urn:sha1:3f82b28f1afc35ad022d05115d5cc220518cdef7</id>
<content type='text'>
SOL_SOCKET and SO_PEERCRED, only issue being that it cannot return
EFAULT for a page fault.  The kernel code will soon be put into
compat, and then in 10 years or so tedu will delete it.
ok guenther millert
</content>
</entry>
<entry>
<title>oops. Missed this from my aes-ni commit.</title>
<updated>2010-07-01T17:44:57+00:00</updated>
<author>
<name>thib</name>
<email></email>
</author>
<published>2010-07-01T17:44:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=4722e3b8cd01eb49fdc03a02aed428c5118eaf49'/>
<id>urn:sha1:4722e3b8cd01eb49fdc03a02aed428c5118eaf49</id>
<content type='text'>
</content>
</entry>
<entry>
<title>AES-NI engine support for OpenSSL.</title>
<updated>2010-07-01T17:44:20+00:00</updated>
<author>
<name>thib</name>
<email></email>
</author>
<published>2010-07-01T17:44:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=9084f839ac0f269821a954788017d4349b614e7d'/>
<id>urn:sha1:9084f839ac0f269821a954788017d4349b614e7d</id>
<content type='text'>
This is code mostly picked up from upstream OpenSSL, or to be more exact
a diff from David Woodhouse &lt;dwmw2 at infradead dot org&gt;.

Remember to make includes before doing a build!

no objections from djm@
OK deraadt@, reyk@ (AES is about 4.25x faster on his x201 now)
</content>
</entry>
</feed>
