<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/usr.sbin/ocspcheck, branch libressl-v3.2.0</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=libressl-v3.2.0</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=libressl-v3.2.0'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2020-01-23T03:53:39+00:00</updated>
<entry>
<title>The X509_LOOKUP code tries to grope around in /etc/ssl/cert/ to find</title>
<updated>2020-01-23T03:53:39+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2020-01-23T03:53:39+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=d074b68b31fc121e4b52ff0c09efcf6d853b383d'/>
<id>urn:sha1:d074b68b31fc121e4b52ff0c09efcf6d853b383d</id>
<content type='text'>
CA certs it couldn't find otherwise. This may lead to a pledge rpath
violation reported by Kor, son of Rynar.  Unfortunately, providing certs
inside a directory is common in linuxes, so we need to keep this
functionality for portable.

Check if /etc/ssl/cert.pem and /etc/ssl/cert exist and pledge
accordingly. Add unveils to restrict this program further on a
default OpenBSD install. Fix -C to look only inside the provided
root bundle.

Input from jsing and sthen, tests by sthen and Kor

ok beck, jsing, sthen (after much back and forth)
</content>
</entry>
<entry>
<title>Set "Content-Type: application/ocsp-request" in ocspcheck(1)'s POSTs,</title>
<updated>2020-01-11T17:37:19+00:00</updated>
<author>
<name>sthen</name>
<email></email>
</author>
<published>2020-01-11T17:37:19+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=447ae9961c3e13c550103d720a0cabeb72e6b84f'/>
<id>urn:sha1:447ae9961c3e13c550103d720a0cabeb72e6b84f</id>
<content type='text'>
it is required by the RFC and some CAs require it (e.g. sectigo).
From daharmasterkor at gmail com, ok jca@
</content>
</entry>
<entry>
<title>When system calls indicate an error they return -1, not some arbitrary</title>
<updated>2019-06-28T13:35:02+00:00</updated>
<author>
<name>deraadt</name>
<email></email>
</author>
<published>2019-06-28T13:35:02+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=835d788017c49be8b4986b0f04686da55f2cd0da'/>
<id>urn:sha1:835d788017c49be8b4986b0f04686da55f2cd0da</id>
<content type='text'>
value &lt; 0.  errno is only updated in this case.  Change all (most?)
callers of syscalls to follow this better, and let's see if this strictness
helps us in the future.
</content>
</entry>
<entry>
<title>check result of ftruncate() as we do write() below</title>
<updated>2019-05-15T13:44:18+00:00</updated>
<author>
<name>bcook</name>
<email></email>
</author>
<published>2019-05-15T13:44:18+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=e237f626b47bb3bb017599ce57e9d817f613b817'/>
<id>urn:sha1:e237f626b47bb3bb017599ce57e9d817f613b817</id>
<content type='text'>
ok beck@
</content>
</entry>
<entry>
<title>update for libtls default cert changes.</title>
<updated>2018-11-29T14:25:07+00:00</updated>
<author>
<name>tedu</name>
<email></email>
</author>
<published>2018-11-29T14:25:07+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5f08effe8d3a6601a2f55a020ef051bef28cf946'/>
<id>urn:sha1:5f08effe8d3a6601a2f55a020ef051bef28cf946</id>
<content type='text'>
bonus: this exposed a few missing const qualifiers.
</content>
</entry>
<entry>
<title>Use TLS_CA_CERT_FILE instead of a separate define.</title>
<updated>2018-11-06T20:41:11+00:00</updated>
<author>
<name>jsing</name>
<email></email>
</author>
<published>2018-11-06T20:41:11+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5b8cabaeb0bc8cca139fc6efd8423cf50026cd9c'/>
<id>urn:sha1:5b8cabaeb0bc8cca139fc6efd8423cf50026cd9c</id>
<content type='text'>
ok beck@ bluhm@ tb@
</content>
</entry>
<entry>
<title>Avoid using an uninitialized variable.</title>
<updated>2017-12-01T14:42:23+00:00</updated>
<author>
<name>visa</name>
<email></email>
</author>
<published>2017-12-01T14:42:23+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=a5ca61165484466ec3d6f7be600dc13db3aec881'/>
<id>urn:sha1:a5ca61165484466ec3d6f7be600dc13db3aec881</id>
<content type='text'>
Found by gcc.

OK jca@
</content>
</entry>
<entry>
<title>add -i to SYNOPSIS/usage() and sundry tweaks;</title>
<updated>2017-11-29T21:15:45+00:00</updated>
<author>
<name>jmc</name>
<email></email>
</author>
<published>2017-11-29T21:15:45+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=08c4e99b14bccaafbb034cbe270550470fbe9df5'/>
<id>urn:sha1:08c4e99b14bccaafbb034cbe270550470fbe9df5</id>
<content type='text'>
ok beck
</content>
</entry>
<entry>
<title>Add option -i to allow oscpcheck to be used to validate an on-disk staple</title>
<updated>2017-11-28T23:32:00+00:00</updated>
<author>
<name>beck</name>
<email></email>
</author>
<published>2017-11-28T23:32:00+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5929e16c289458fb0cbcee595cab8746bac4a72f'/>
<id>urn:sha1:5929e16c289458fb0cbcee595cab8746bac4a72f</id>
<content type='text'>
ok claudio@ benno@
</content>
</entry>
<entry>
<title>add missing HISTORY; based on CVS logs and release announcements</title>
<updated>2017-10-17T22:47:58+00:00</updated>
<author>
<name>schwarze</name>
<email></email>
</author>
<published>2017-10-17T22:47:58+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=1971a9ab930ab942769bad5284af3752e6397e3d'/>
<id>urn:sha1:1971a9ab930ab942769bad5284af3752e6397e3d</id>
<content type='text'>
</content>
</entry>
</feed>
