ubuntu/+source/openssl:ubuntu/cosmic-security

Last commit made on 2018-12-06
Get this branch:
git clone -b ubuntu/cosmic-security https://git.launchpad.net/ubuntu/+source/openssl
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
ubuntu/cosmic-security
Repository:
lp:ubuntu/+source/openssl

Recent commits

e4e0ca1... by Marc Deslauriers on 2018-12-04

Import patches-unapplied version 1.1.1-1ubuntu2.1 to ubuntu/cosmic-security

Imported using git-ubuntu import.

Changelog parent: 5c27691e1b200dee6ee3530b9b2d499d0cc8092c

New changelog entries:
  * SECURITY UPDATE: timing side channel attack in DSA
    - debian/patches/CVE-2018-0734-1.patch: fix mod inverse in
      crypto/dsa/dsa_ossl.c.
    - debian/patches/CVE-2018-0734-2.patch: fix timing vulnerability in
      crypto/dsa/dsa_ossl.c.
    - debian/patches/CVE-2018-0734-3.patch: add a constant time flag in
      crypto/dsa/dsa_ossl.c.
    - CVE-2018-0734
  * SECURITY UPDATE: timing side channel attack in ECDSA
    - debian/patches/CVE-2018-0735.patch: fix timing vulberability in
      crypto/ec/ec_mult.c.
    - CVE-2018-0735

5c27691... by Dimitri John Ledkov on 2018-09-25

Import patches-unapplied version 1.1.1-1ubuntu2 to ubuntu/cosmic-proposed

Imported using git-ubuntu import.

Changelog parent: c95f92275d7e52006b9b2f41c5cb7071184ab2ff

New changelog entries:
  * Fixup typpos in the autopkgtest binary name.

c95f922... by Dimitri John Ledkov on 2018-09-17

Import patches-unapplied version 1.1.1-1ubuntu1 to ubuntu/cosmic-proposed

Imported using git-ubuntu import.

Changelog parent: ec7b59aab88eec3d1da0e1dc81d7daa16ca50623

New changelog entries:
  * Merge from Debian unstable, remaining changes:
    - Replace duplicate files in the doc directory with symlinks.
    - debian/libssl1.1.postinst:
      + Display a system restart required notification on libssl1.1
        upgrade on servers.
      + Use a different priority for libssl1.1/restart-services depending
        on whether a desktop, or server dist-upgrade is being performed.
    - Revert "Enable system default config to enforce TLS1.2 as a
      minimum" & "Increase default security level from 1 to 2".
    - Further decrease security level from 1 to 0, for compatibility with
      openssl 1.0.2.

ec7b59a... by Sebastian Andrzej Siewior <email address hidden> on 2018-09-12

Import patches-unapplied version 1.1.1-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 2c0e822beb69b78e1307fba20a505c5a5953f09e

New changelog entries:
  * New upstream version.
   - Update symbol file for 1.1.1
   - CVE-2018-0732 (actually since pre8).
  * Add Breaks on python-httplib2 (Addresses: #907015)
  * Add hardening=+all.
  * Update to policy 4.2.1
    - Less verbose testsuite with terse
    - Use RRR=no

2c0e822... by Kurt Roeckx on 2018-08-21

Import patches-unapplied version 1.1.1~~pre9-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: ad855d8f10d1a5349b86c641ffe236be1e5a8ae3

New changelog entries:
  * New upstream version.
    - Support the final TLS 1.3 version (RFC 8446)
  * Upload to unstable

ad855d8... by Sebastian Andrzej Siewior <email address hidden> on 2018-07-04

Import patches-unapplied version 1.1.1~~pre8-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: b3efc01a93c549b7cc7b1035edff837315784473

New changelog entries:
  * New upstream version.

b3efc01... by Sebastian Andrzej Siewior <email address hidden> on 2018-05-30

Import patches-unapplied version 1.1.1~~pre7-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: 32de7f72f09e8539f456f9d4954b88a39ad79f14

New changelog entries:
  * Drop afalgeng on kfreebsd-* which go enabled because they inherit from
    the linux target.
  * Fix debian-rules-sets-dpkg-architecture-variable.
  * Update to policy 4.1.4
    - only Suggest: libssl-doc instead Recommends (only documentation and
      example code is shipped).
    - drop Priority: important.
    - use signing-key.asc and a https links for downloads
  * Use compat 11.
    - this moves the examples to /usr/share/doc/libssl-{doc->dev}/demos but it
      seems to make sense.
  * Add a 25-test_verify.t for autopkgtest which runs against intalled
    openssl binary.
  * Fix CVE-2018-0737 (Closes: #895844).

32de7f7... by Kurt Roeckx on 2018-05-01

Import patches-unapplied version 1.1.1~~pre6-2 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: e55e803850cb122f02cbfbd2778d5e9533344b74

New changelog entries:
  * Update libssl1.1.symbols
  * New upstream version
  * Increase default security level from 1 to 2. This moves from the 80 bit
    security level to the 112 bit securit level and will require 2048 bit RSA
    and DHE keys.

e55e803... by Sebastian Andrzej Siewior <email address hidden> on 2018-04-03

Import patches-unapplied version 1.1.1~~pre4-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: bf3f0b60bcf342901ce43fd8a405b3e5237a5b0f

New changelog entries:
  * Update to 1.1.1-pre4 (Closes: #892276, #894282).
  * Add riscv64 target (Closes: #891797).

bf3f0b6... by Sebastian Andrzej Siewior <email address hidden> on 2018-03-20

Import patches-unapplied version 1.1.1~~pre3-1 to debian/experimental

Imported using git-ubuntu import.

Changelog parent: ab0a0702b256f8a3d41d81babf2976aefb712667

New changelog entries:
  * Update to 1.1.1-pre3
  * Don't suggest 1024 bit RSA key to be typical (Closes: #878303).
  * Don't insist on TLS1.3 cipher for <TLS1.3 connections (Closes: #891570).
  * Enable system default config to enforce TLS1.2 as a minimum.