<feed xmlns='http://www.w3.org/2005/Atom'>
<title>src/secure, branch release/10.3.0</title>
<subtitle>FreeBSD source tree</subtitle>
<id>https://cgit-dev.freebsd.org/src/atom?h=release%2F10.3.0</id>
<link rel='self' href='https://cgit-dev.freebsd.org/src/atom?h=release%2F10.3.0'/>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/'/>
<updated>2016-03-14T13:05:13Z</updated>
<entry>
<title>MFS (r296781):</title>
<updated>2016-03-14T13:05:13Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2016-03-14T13:05:13Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=2ef5a941ca44b7baf127b9877f7bde69488fa40f'/>
<id>urn:sha1:2ef5a941ca44b7baf127b9877f7bde69488fa40f</id>
<content type='text'>
  MFH (r296633): upgrade to 7.2p2 (fixes xauth command injection bug)
  MFH (r296634): re-add aes-cbc to server-side default cipher list
  MFH (r296651, r296657): fix gcc build of pam_ssh

PR:		207679
Security:	CVE-2016-3115
Approved by:	re (marius)
</content>
</entry>
<entry>
<title>Re-enable SSLv2 support to restore ABI.</title>
<updated>2016-03-04T00:40:15Z</updated>
<author>
<name>Jung-uk Kim</name>
<email>jkim@FreeBSD.org</email>
</author>
<published>2016-03-04T00:40:15Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=9e8336cc7205b3140d5ce887c5b4b754f03e66e4'/>
<id>urn:sha1:9e8336cc7205b3140d5ce887c5b4b754f03e66e4</id>
<content type='text'>
Excerpt from CHANGES:

    Even if "enable-ssl2" is used, users who want to negotiate SSLv2 via
    the version-flexible SSLv23_method() will need to explicitly call
    either of:

	SSL_CTX_clear_options(ctx, SSL_OP_NO_SSLv2);
    or
	SSL_clear_options(ssl, SSL_OP_NO_SSLv2);

    as appropriate.  Even if either of those is used, or the application
    explicitly uses the version-specific SSLv2_method() or its client and
    server variants, SSLv2 ciphers vulnerable to exhaustive search key
    recovery have been removed.  Specifically, the SSLv2 40-bit EXPORT
    ciphers, and SSLv2 56-bit DES are no longer available.

Approved by:	re (marius, gjb), so (delphij)
</content>
</entry>
<entry>
<title>Merge OpenSSL 1.0.1s.  This is a security update.</title>
<updated>2016-03-02T15:43:01Z</updated>
<author>
<name>Xin LI</name>
<email>delphij@FreeBSD.org</email>
</author>
<published>2016-03-02T15:43:01Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=2aab9f2e02bfc1930b0c9f7704bee21c4f910a4b'/>
<id>urn:sha1:2aab9f2e02bfc1930b0c9f7704bee21c4f910a4b</id>
<content type='text'>
Relnotes:	yes
Approved by:	re (so@ implicit)
</content>
</entry>
<entry>
<title>MFH (r265214, r294333, r294407, r294467): misc prop fixes</title>
<updated>2016-02-07T11:38:54Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2016-02-07T11:38:54Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=18f332e3cd2c94e60664a4940f7fd23c1ac7bc12'/>
<id>urn:sha1:18f332e3cd2c94e60664a4940f7fd23c1ac7bc12</id>
<content type='text'>
MFH (r285975, r287143): register mergeinfo for security fixes
MFH (r294497, r294498, r295139): internal documentation
MFH (r294328): upgrade to openssh 6.7p1, re-add libwrap
MFH (r294332): upgrade to openssh 6.8p1
MFH (r294367): update pam_ssh for api changes
MFH (r294909): switch usedns back on
MFH (r294336): upgrade to openssh 6.9p1
MFH (r294495): re-enable dsa keys
MFH (r294464): upgrade to openssh 7.0p1
MFH (r294496): upgrade to openssh 7.1p2

Approved by:	re (gjb)
Relnotes:	yes
</content>
</entry>
<entry>
<title>Merge OpenSSL 1.0.1r.</title>
<updated>2016-01-28T21:42:10Z</updated>
<author>
<name>Jung-uk Kim</name>
<email>jkim@FreeBSD.org</email>
</author>
<published>2016-01-28T21:42:10Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=be17a92a4c9367b4ab99a8434d6ea240c870bfe4'/>
<id>urn:sha1:be17a92a4c9367b4ab99a8434d6ea240c870bfe4</id>
<content type='text'>
Relnotes:	yes
</content>
</entry>
<entry>
<title>MFH (r291198, r291260, r291261, r291375, r294325, r294335, r294563)</title>
<updated>2016-01-24T22:28:18Z</updated>
<author>
<name>Dag-Erling Smørgrav</name>
<email>des@FreeBSD.org</email>
</author>
<published>2016-01-24T22:28:18Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=1c4a30b5fcee61a2418092b1cd900a26ed9a1681'/>
<id>urn:sha1:1c4a30b5fcee61a2418092b1cd900a26ed9a1681</id>
<content type='text'>
Remove the HPN and None cipher patches.
</content>
</entry>
<entry>
<title>MFC r291941:</title>
<updated>2016-01-07T23:26:16Z</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2016-01-07T23:26:16Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=c7b0e8b2937de368c42f2b407d94ec00c170b652'/>
<id>urn:sha1:c7b0e8b2937de368c42f2b407d94ec00c170b652</id>
<content type='text'>
  Replace unneeded manual dependency on header by adding it to SRCS.
</content>
</entry>
<entry>
<title>MFC r289393:</title>
<updated>2015-12-04T18:14:31Z</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2015-12-04T18:14:31Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=677dfcac9f405eb023fb1a69ce77249e89210cf1'/>
<id>urn:sha1:677dfcac9f405eb023fb1a69ce77249e89210cf1</id>
<content type='text'>
  Add more SUBDIR_PARALLEL.
</content>
</entry>
<entry>
<title>MFC r289360,r289361,r289378,r289430,r289605,r289676:</title>
<updated>2015-12-04T17:56:10Z</updated>
<author>
<name>Bryan Drewery</name>
<email>bdrewery@FreeBSD.org</email>
</author>
<published>2015-12-04T17:56:10Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=842a101b8ead75432d119c285c5897d178c3c81d'/>
<id>urn:sha1:842a101b8ead75432d119c285c5897d178c3c81d</id>
<content type='text'>
  r289360:
    Add temporary workaround for .MAKE being applied to _worldtmp, since
    r251750.
  r289361:
    Consider top-level targets to be .PHONY as bmake won't build them otherwise
    if a file with the same name is found in the directory.
  r289378:
    Mark sub-make targets as .MAKE and .PHONY to handle -n and always-build
    properly.
  r289430:
    Remove .MAKE from targets that do more than just run sub-makes, such as
    calling rm or mtree.
  r289605:
    Add missing .PHONY for parallel subdir target.
  r289676:
    Add some missing '+', .MAKE, and .PHONY modifiers.
</content>
</entry>
<entry>
<title>Merge OpenSSL 1.0.1q.</title>
<updated>2015-12-03T21:18:48Z</updated>
<author>
<name>Jung-uk Kim</name>
<email>jkim@FreeBSD.org</email>
</author>
<published>2015-12-03T21:18:48Z</published>
<link rel='alternate' type='text/html' href='https://cgit-dev.freebsd.org/src/commit/?id=2825c9578714005bd79d04b563ba98c8ea637641'/>
<id>urn:sha1:2825c9578714005bd79d04b563ba98c8ea637641</id>
<content type='text'>
</content>
</entry>
</feed>
