ubuntu/+source/openssl:ubuntu/quantal

Last commit made on 2012-10-07
Get this branch:
git clone -b ubuntu/quantal https://git.launchpad.net/ubuntu/+source/openssl
Members of Ubuntu Server Dev import team can upload to this branch. Log in for directions.

Branch merges

Branch information

Name:
ubuntu/quantal
Repository:
lp:ubuntu/+source/openssl

Recent commits

6a84e73... by Tyler Hicks on 2012-10-04

Import patches-unapplied version 1.0.1c-3ubuntu2 to ubuntu/quantal

Imported using git-ubuntu import.

Changelog parent: 2f84dee8ff1bdc3c9ddfad42fed4ee06f20da7b5

New changelog entries:
  [ Tyler Hicks <email address hidden> ]
  * debian/patches/tls12_workarounds.patch: Readd the change to check
    TLS1_get_client_version rather than TLS1_get_version to fix incorrect
    client hello cipher list truncation when TLS 1.1 and lower is in use.
    (LP: #1051892)
  [ Micah Gersten <email address hidden> ]
  * Mark Debian Vcs-* as XS-Debian-Vcs-*
    - update debian/control

2f84dee... by Marc Deslauriers on 2012-06-29

Import patches-unapplied version 1.0.1c-3ubuntu1 to ubuntu/quantal

Imported using git-ubuntu import.

Changelog parent: 79e8663eddb6e1140f68c98add690f24351da12e

New changelog entries:
  * Resynchronise with Debian. Remaining changes:
    - debian/libssl1.0.0.postinst:
      + Display a system restart required notification on libssl1.0.0
        upgrade on servers.
      + Use a different priority for libssl1.0.0/restart-services depending
        on whether a desktop, or server dist-upgrade is being performed.
    - debian/{libssl1.0.0-udeb.dirs, control, rules}: Create
      libssl1.0.0-udeb, for the benefit of wget-udeb (no wget-udeb package
      in Debian).
    - debian/{libcrypto1.0.0-udeb.dirs, libssl1.0.0.dirs, libssl1.0.0.files,
      rules}: Move runtime libraries to /lib, for the benefit of
      wpasupplicant.
    - debian/patches/perlpath-quilt.patch: Don't change perl #! paths under
      .pc.
    - debian/rules:
      + Don't run 'make test' when cross-building.
      + Use host compiler when cross-building. Patch from Neil Williams.
      + Don't build for processors no longer supported: i586 (on i386)
      + Fix Makefile to properly clean up libs/ dirs in clean target.
      + Replace duplicate files in the doc directory with symlinks.
    - Unapply patch c_rehash-multi and comment it out in the series as it
      breaks parsing of certificates with CRLF line endings and other cases
      (see Debian #642314 for discussion), it also changes the semantics of
      c_rehash directories by requiring applications to parse hash link
      targets as files containing potentially *multiple* certificates rather
      than exactly one.
    - Bump version passed to dh_makeshlibs to 1.0.1 for new symbols.
    - debian/patches/tls12_workarounds.patch: workaround large client hello
      issue: Compile with -DOPENSSL_MAX_TLS1_2_CIPHER_LENGTH=50 and
      with -DOPENSSL_NO_TLS1_2_CLIENT.
  * Dropped upstreamed patches:
    - debian/patches/CVE-2012-2110.patch
    - debian/patches/CVE-2012-2110b.patch
    - debian/patches/CVE-2012-2333.patch
    - debian/patches/CVE-2012-0884-extra.patch
    - most of debian/patches/tls12_workarounds.patch

79e8663... by Kurt Roeckx on 2012-06-06

Import patches-unapplied version 1.0.1c-3 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 0981ef39db63efe309e74592997d983db1d320ec

New changelog entries:
  * Disable padlock engine again, causes problems for hosts not supporting it.

0981ef3... by Kurt Roeckx on 2012-06-05

Import patches-unapplied version 1.0.1c-2 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 061e2165f691c68d1d843660d8954f2301d8a0aa

New changelog entries:
  * Fix renegiotation when using TLS > 1.0. This breaks tor. Patch from
    upstream. (Closes: #675990)
  * Enable the padlock engine by default.
  * Change default bits from 1024 to 2048 (Closes: #487152)

061e216... by Kurt Roeckx on 2012-05-11

Import patches-unapplied version 1.0.1c-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 85ed39a72573ecd3db3d04abfa12886280d6305f

New changelog entries:
  * New upstream version
    - Fixes CVE-2012-2333 (Closes: #672452)

85ed39a... by Kurt Roeckx on 2012-04-26

Import patches-unapplied version 1.0.1b-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 390f8982ed38219808a6d98e93b7fdb9b9b65d2e

New changelog entries:
  * New upstream version
    - Remaps SSL_OP_NO_TLSv1_1, so applications linked to 1.0.0
      can talk to servers supporting TLS 1.1 but not TLS 1.2
    - Drop rc4_hmac_md5.patch, applied upstream

390f898... by Kurt Roeckx on 2012-04-19

Import patches-unapplied version 1.0.1a-3 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 38204fdc08384530b7a6105af5759fb9dff78fcc

New changelog entries:
  * Use patch from upstream for the rc4_hmac_md5 issue.
  * Fix rc4_hmac_md5 on non-i386/amd64 arches.

38204fd... by Kurt Roeckx on 2012-04-19

Import patches-unapplied version 1.0.1a-1 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 80d1b191d547b2eb76ec48a083fbf1772d23a433

New changelog entries:
  * New upstream version
    - Fixes CVE-2012-2110
    - Fix crash in rc4_hmac_md5 (Closes: #666405)
    - Fixes some issues with talking to other servers when TLS 1.1 and 1.2 is
      supported
    - Drop patches no_ssl2.patch vpaes.patch tls1.2_client_algorithms.patch,
      applied upstream.

80d1b19... by Kurt Roeckx on 2012-03-31

Import patches-unapplied version 1.0.1-4 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 10215eaec53ce765318f86f477b1e832cc0704c8

New changelog entries:
  * Use official patch for the vpaes problem, also covering amd64.

10215ea... by Kurt Roeckx on 2012-03-31

Import patches-unapplied version 1.0.1-3 to debian/sid

Imported using git-ubuntu import.

Changelog parent: 374fcd4ee61af70b5b7f65ea36098921de820067

New changelog entries:
  * Fix crash in vpaes (Closes: #665836)
  * use client version when deciding whether to send supported signature
    algorithms extension