[openssl-commits] [openssl] master update
Matt Caswell
matt at openssl.org
Mon Sep 10 16:06:04 UTC 2018
The branch master has been updated
via 6ccfc8fa316f8dcfe4c943e5a43e9e3661be9cb1 (commit)
from 3f8b623aaa4044908900767a8991b7769b320880 (commit)
- Log -----------------------------------------------------------------
commit 6ccfc8fa316f8dcfe4c943e5a43e9e3661be9cb1
Author: Matt Caswell <matt at openssl.org>
Date: Mon Sep 10 14:44:04 2018 +0100
More updates to CHANGES and NEWS for the 1.1.1 release
Reviewed-by: Ben Kaduk <kaduk at mit.edu>
Reviewed-by: Richard Levitte <levitte at openssl.org>
(Merged from https://github.com/openssl/openssl/pull/7167)
-----------------------------------------------------------------------
Summary of changes:
CHANGES | 8 ++++++++
NEWS | 18 ++++++++++++++++--
2 files changed, 24 insertions(+), 2 deletions(-)
diff --git a/CHANGES b/CHANGES
index be44954..63fe26c 100644
--- a/CHANGES
+++ b/CHANGES
@@ -9,6 +9,14 @@
Changes between 1.1.0i and 1.1.1 [xx XXX xxxx]
+ *) Add a new ClientHello callback. Provides a callback interface that gives
+ the application the ability to adjust the nascent SSL object at the
+ earliest stage of ClientHello processing, immediately after extensions have
+ been collected but before they have been processed. In particular, this
+ callback can adjust the supported TLS versions in response to the contents
+ of the ClientHello
+ [Benjamin Kaduk]
+
*) Add SM2 base algorithm support.
[Jack Lloyd]
diff --git a/NEWS b/NEWS
index b49d51a..ae0c2d7 100644
--- a/NEWS
+++ b/NEWS
@@ -7,7 +7,19 @@
Major changes between OpenSSL 1.1.0i and OpenSSL 1.1.1 [in pre-release]
- o Support for TLSv1.3 added
+ o Support for TLSv1.3 added (see https://wiki.openssl.org/index.php/TLS1.3
+ for further important information). The TLSv1.3 implementation includes:
+ o Fully compliant implementation of RFC8446 (TLSv1.3) on by default
+ o Early data (0-RTT)
+ o Post-handshake authentication and key update
+ o Middlebox Compatibility Mode
+ o TLSv1.3 PSKs
+ o Support for all five RFC8446 ciphersuites
+ o RSA-PSS signature algorithms (backported to TLSv1.2)
+ o Configurable session ticket support
+ o Stateless server support
+ o Rewrite of the packet construction code for "safer" packet handling
+ o Rewrite of the extension handling code
o Complete rewrite of the OpenSSL random number generator to introduce the
following capabilities
o The default RAND method now utilizes an AES-CTR DRBG according to
@@ -21,7 +33,7 @@
o Support for various new cryptographic algorithms including:
o SHA3
o SHA512/224 and SHA512/256
- o EdDSA (including Ed25519 and Ed448)
+ o EdDSA (both Ed25519 and Ed448) including X509 and TLS support
o X448 (adding to the existing X25519 support in 1.1.0)
o Multi-prime RSA
o SM2
@@ -30,6 +42,8 @@
o SipHash
o ARIA (including TLS support)
o Significant Side-Channel attack security improvements
+ o Add a new ClientHello callback to provide the ability to adjust the SSL
+ object at an early stage.
o Add 'Maximum Fragment Length' TLS extension negotiation and support
o A new STORE module, which implements a uniform and URI based reader of
stores that can contain keys, certificates, CRLs and numerous other
More information about the openssl-commits
mailing list