From 25d8a429c13a240de8789e12d26ea036b921a665 Mon Sep 17 00:00:00 2001 From: Brent Cook Date: Sun, 31 Jul 2016 17:59:59 -0500 Subject: update for 2.3.7 --- ChangeLog | 11 +++++++++++ 1 file changed, 11 insertions(+) diff --git a/ChangeLog b/ChangeLog index 39f6055..6687e5b 100644 --- a/ChangeLog +++ b/ChangeLog @@ -28,6 +28,17 @@ history is also available from Git. LibreSSL Portable Release Notes: +2.3.7 - OCSP fixes + + * Fix several issues in the OCSP code that could result in the + incorrect generation and parsing of OCSP requests. This remediates a + lack of error checking on time parsing in these functions, and + ensures that only GENERALIZEDTIME formats are accepted for OCSP, as + per RFC 6960. + + Issues reported, and fixes provided by Kazuki Yamaguchi + and Kinichiro Inoguchi + 2.3.6 - Security fix * Correct a problem that prevents the DSA signing algorithm from -- cgit v1.2.3-55-g6feb