46 Commits

Author SHA1 Message Date
Timo Teräs
5c90471732 [all autotools packages]: normalize ./configure 2013-07-30 08:54:53 +00:00
Timo Teräs
74cb6d5e1e main/openssl: support crosscompiling, arm and musl 2013-07-08 11:40:50 +00:00
Timo Teräs
095daa82b9 main/openssl: fix openssl tools default CApath
Apply patch from openssl rt.
2013-06-15 19:46:09 +03:00
Timo Teräs
96a7c6be64 main/openssl: update padlock sha1 patch
Add EVP_MD_FLAG_PKEY_METHOD_SIGNATURE to padlock_sha1_md to fix
DSA/SHA1 verification in certain cases. Seems that NID_sha1 instead
of NID_dss is used sometimes incorrectly, and this seems to be the
workaround regular SHA1 code does too.

Suggested-by: Daniel Mansfield <daniel.mansfield@unsw.edu.au>
2013-03-05 07:54:04 +02:00
Natanael Copa
2d9183b2ab main/openssl: upgrade to 1.0.1e 2013-02-12 15:59:11 +00:00
Natanael Copa
24db490f2b main/openssl: fix regression
http://marc.info/?t=136018837600003&r=1&w=2
2013-02-08 08:57:53 +00:00
Carlo Landmeter
361d85064a main/openssl: eglibc update verioned symbols 2013-02-07 10:21:20 +00:00
Natanael Copa
240d4d3c17 main/openssl: security upgrade to 1.0.1d (CVE-2013-0169,CVE-2012-2686,CVE-2013-0166)
fixes #1591
2013-02-06 09:02:01 +00:00
Carlo Landmeter
62d8f48083 main/openssl: add versioned symbols
when building on eglibc we need versioned symbols
2013-01-04 17:11:11 +01:00
William Pitcock
056a1e8999 main/openssl: add ircv3 tls-3.1 extension support to s_client 2012-09-22 16:32:37 -05:00
Timo Teräs
cdbddc83dc main/openssl: refresh hmac/oneshot and padlock patches
* fixed hmac oneshot flag to work as expected
 * renamed the patch series, and rebased against 1.0.1c
2012-08-02 17:23:40 +03:00
Timo Teräs
70f1e866bf main/openssl: fix padlock sha1/256 oneshot finalizing update
We want to handle bytes upto next block boundary, to work with
hardware from block boundary. The code incorrectly fed just the
amount of bytes in the block.
2012-08-02 11:34:39 +03:00
Natanael Copa
d578a77271 main/openssl: security upgrade to 1.0.1c (CVE-2012-2333)
fixes #1151
(cherry picked from commit 1831053bb87f432f0d45ccd9f7a368fc885a1d64)
2012-05-14 12:45:02 +00:00
Natanael Copa
50e3c80a28 main/openssl: upgrade to 1.0.1b 2012-04-26 12:36:11 +00:00
Natanael Copa
75d80e98d6 main/openssl: security upgrade to 1.0.1a (CVE-2012-2110)
fixes #1107
2012-04-23 07:13:56 +00:00
Timo Teräs
7c8821678c main/openssl: upgrade to 1.0.1
Remove the unneeded 0002-apps-speed-fix; the speed utility can now
measure evp speeds with -evp flag.

Padlock autoloading patch is rebased.
2012-03-28 10:07:49 +03:00
Natanael Copa
6e5e231d63 main/openssl: upgrade to 1.0.0h 2012-03-13 12:08:59 +00:00
Natanael Copa
ffe9b2793f main/openssl: security upgrade to 1.0.0g (CVE-2012-0050)
fixes #935
2012-01-19 07:18:34 +00:00
Natanael Copa
f991495d95 main/openssl: security upgrade to 1.0.0f
CVE-2011-4108
CVE-2011-4109
CVE-2011-4576
CVE-2011-4577
CVE-2011-4619
CVE-2012-0027

fixes #893
2012-01-05 14:46:15 +00:00
Natanael Copa
b9f27ea770 main/openssl: security upgrade to 1.0.0e (CVE-2011-3207, CVE-2011-3210) 2011-09-06 15:06:51 +00:00
Timo Teräs
de7dd2b946 main/openssl: update to 1.0.0d
* contains security fix to CVE-2011-0014
2011-02-09 08:47:26 +02:00
William Pitcock
ba2600dc6e Set all packages with arch="x86 x86_64" to arch="all". 2011-01-13 06:06:02 -06:00
Natanael Copa
da49ad32c4 main/*: add arch 2010-12-13 16:00:16 +00:00
Timo Teräs
b8e89bf918 main/openssl: security update to 1.0.0c
- Fix for security issue CVE-2010-4180
 - Fix for CVE-2010-4252
 - Fix mishandling of absent EC point format extension.
 - Fix various platform compilation issues.
 - Corrected fix for security issue CVE-2010-3864.
2010-12-03 08:26:33 +02:00
Natanael Copa
83d6bfc645 main/openssl: specify libdir
so we avoid /usr/lib64 on x86_64
2010-11-23 10:10:09 +00:00
Timo Teräs
f2ecdc70a8 main/openssl: upgrade to 1.0.0b and claim maintainership
* upgrade to 1.0.0b which has security fixes
 * update patch which did not apply anymore
 * delete patch merged upstream
2010-11-17 12:56:37 +02:00
Natanael Copa
928dd04996 main/openssl: fix double free. cve-2010-2939 2010-10-08 07:50:08 +00:00
Natanael Copa
930dadc2e0 main/openssl: -dev package needs zlib-dev 2010-08-31 08:05:28 +00:00
Timo Teräs
c27aacffd3 main/openssl: refresh padlock patches
The new feature is support for VIA Nano Padlock in 64-bit mode.
2010-07-28 10:50:42 +03:00
Andrew Manison
85fd77589b Merge remote branch 'alpine/master'
Conflicts:
	main/openssl/APKBUILD
2010-06-19 09:02:05 +00:00
Andrew Manison
8fdcdf953f Fixes for total repository build. 2010-06-11 13:17:35 +00:00
Timo Teräs
2d8adebb5a main/openssl: add padlock sha support, autoload dynamic padlock
Add new version of padlock patches which enable:
 - limited support of VIA C7 SHA acceleration
 - full support for VIA Nano SHA acceleration

Openssl HMAC core is also patched to take full performance out of
padlock. Speed application is updated for measuring hmac(sha1).

Padlock was moved to be dynamic engine in openssl-1.0.0. So add some
code that losfd automatically that engine.
2010-06-04 18:26:46 +03:00
Andrew Manison
8e157a2055 Deleted old patch file. 2010-06-01 23:45:07 +00:00
Natanael Copa
3bffb04160 main/openssl: upgrade to 1.0.0a 2010-06-01 15:02:42 +00:00
Natanael Copa
009f3f560a main/openssl: upgrade to 1.0.0
and introduce libssl1.0 and libcrypto1.0 packages
2010-05-14 17:50:22 +00:00
Natanael Copa
b4eecaf058 main/[various]: bump pkgrel to force rebuild against nptl 2010-05-04 08:26:51 +00:00
Natanael Copa
190bb4b5a6 main/openssl: upgrade to 0.9.8n 2010-03-30 07:29:15 +00:00
Natanael Copa
a83972c6ef main/openssl: upgrade to 0.9.8m 2010-03-12 15:16:34 +00:00
Natanael Copa
58c4a2ed5b main/openssl: security patches
* CVE-2009-1377
 * CVE-2009-1378
 * CVE-2009-1379
 * CVE-2009-1387
 * CVE-2009-2409
 * CVE-2009-3555
2009-12-09 13:30:46 +00:00
Natanael Copa
fcb8211479 main/openssl: upgrade to 0.9.8l 2009-11-09 12:45:00 +00:00
Timo Teras
aef60a2639 main/openssl: enable optimized montgomery multiplication
gives about 2x performance improvement on sse enabled chips.
2009-08-20 14:21:36 +03:00
Natanael Copa
f4a76bb2a0 main/openssl: the libcrypto subpackage replaces openssl for upgrades 2009-08-06 08:54:01 +00:00
Timo Teras
37907999d1 main/openssl: fix random padlock sha1 breakage
fix copying of oneshot sha1 context. also decrease the size
of "small buffer", to make context smaller (and context copy
faster in most cases); it should be still enough to catch
most hmac operations.
2009-07-30 22:09:49 +03:00
Natanael Copa
0af11418b4 main/openssl: update checksum 2009-07-27 14:02:45 +00:00
Timo Teras
31ee725d62 main/openssl: fix padlock patch
there was a bug sha context copying, that caused all hmac users
(and possibly others) to crash. also implemented a third
intermediate hashing mode with small buffer: it'll speed up
hashing in most cases considerably (packets / certificates to
be hashed are not usually too long).
2009-07-27 16:20:51 +03:00
Natanael Copa
2d2ddf507b move core/* to main/
added maintainer to several packages as well
2009-07-23 18:24:11 +00:00