diff options
author | adam <adam@pkgsrc.org> | 2018-07-19 09:24:37 +0000 |
---|---|---|
committer | adam <adam@pkgsrc.org> | 2018-07-19 09:24:37 +0000 |
commit | 8e5d91b67be5c338980cf9d90209e7a80b111ea9 (patch) | |
tree | 5e19dcea8641f838f0fc2661f83cbd2d4b5bf015 /security | |
parent | 830199f629a8c5dc9e87170552168312481ff453 (diff) | |
download | pkgsrc-8e5d91b67be5c338980cf9d90209e7a80b111ea9.tar.gz |
py-cryptography[_vectors]: updated to 2.3
2.3:
SECURITY ISSUE: :meth:~cryptography.hazmat.primitives.ciphers.AEADDecryptionContext.finalize_with_tag allowed tag truncation by default which can allow tag forgery in some cases. The method now enforces the min_tag_length provided to the :class:~cryptography.hazmat.primitives.ciphers.modes.GCM constructor. CVE-2018-10903
Added support for Python 3.7.
Added :meth:~cryptography.fernet.Fernet.extract_timestamp to get the authenticated timestamp of a :doc:Fernet </fernet> token.
Support for Python 2.7.x without hmac.compare_digest has been deprecated. We will require Python 2.7.7 or higher (or 2.7.6 on Ubuntu) in the next cryptography release.
Fixed multiple issues preventing cryptography from compiling against LibreSSL 2.7.x.
Added :class:~cryptography.x509.CertificateRevocationList.get_revoked_certificate_by_serial_number for quick serial number searches in CRLs.
The :class:~cryptography.x509.RelativeDistinguishedName class now preserves the order of attributes. Duplicate attributes now raise an error instead of silently discarding duplicates.
:func:~cryptography.hazmat.primitives.keywrap.aes_key_unwrap and :func:~cryptography.hazmat.primitives.keywrap.aes_key_unwrap_with_padding now raise :class:~cryptography.hazmat.primitives.keywrap.InvalidUnwrap if the wrapped key is an invalid length, instead of ValueError.
Diffstat (limited to 'security')
-rw-r--r-- | security/py-cryptography/Makefile | 4 | ||||
-rw-r--r-- | security/py-cryptography/distinfo | 10 | ||||
-rw-r--r-- | security/py-cryptography_vectors/Makefile | 4 | ||||
-rw-r--r-- | security/py-cryptography_vectors/PLIST | 31 | ||||
-rw-r--r-- | security/py-cryptography_vectors/distinfo | 10 |
5 files changed, 44 insertions, 15 deletions
diff --git a/security/py-cryptography/Makefile b/security/py-cryptography/Makefile index 9408c6456cf..1285e580399 100644 --- a/security/py-cryptography/Makefile +++ b/security/py-cryptography/Makefile @@ -1,6 +1,6 @@ -# $NetBSD: Makefile,v 1.66 2018/04/02 13:19:31 adam Exp $ +# $NetBSD: Makefile,v 1.67 2018/07/19 09:24:37 adam Exp $ -DISTNAME= cryptography-2.2.2 +DISTNAME= cryptography-2.3 PKGNAME= ${PYPKGPREFIX}-${DISTNAME} CATEGORIES= security python MASTER_SITES= ${MASTER_SITE_PYPI:=c/cryptography/} diff --git a/security/py-cryptography/distinfo b/security/py-cryptography/distinfo index 6112f0bd3c8..7b91629796a 100644 --- a/security/py-cryptography/distinfo +++ b/security/py-cryptography/distinfo @@ -1,6 +1,6 @@ -$NetBSD: distinfo,v 1.52 2018/04/02 13:19:31 adam Exp $ +$NetBSD: distinfo,v 1.53 2018/07/19 09:24:37 adam Exp $ -SHA1 (cryptography-2.2.2.tar.gz) = 4e2afea2c84325b9b89ac885ed7b01875d2792db -RMD160 (cryptography-2.2.2.tar.gz) = 990169925f758a3499c8ea57b17ee4cb028733d7 -SHA512 (cryptography-2.2.2.tar.gz) = 6c1b19cdb870d65abad42523697e9a0bebc7a0025b34f10c4bdd30c313333efd7c41bcb4237a29b3a1b270e3fbade75ccb35df172b055b7c075d619f4d9424c9 -Size (cryptography-2.2.2.tar.gz) = 443822 bytes +SHA1 (cryptography-2.3.tar.gz) = 2bb0184cab9ac1f78e011d243fbcb039028e79e6 +RMD160 (cryptography-2.3.tar.gz) = 1315cd64f8476d15699cd3908546bc538a38a23f +SHA512 (cryptography-2.3.tar.gz) = 75e14020da500fdbbd578f004b22ef3237844185329adf59288b29f1b3ee9dd2005a2c4a933fe8609a59d168012a9f687bab0f31ab39ed6ca325198aa9295e52 +Size (cryptography-2.3.tar.gz) = 449464 bytes diff --git a/security/py-cryptography_vectors/Makefile b/security/py-cryptography_vectors/Makefile index 3dd99d224ca..01e62da6b3a 100644 --- a/security/py-cryptography_vectors/Makefile +++ b/security/py-cryptography_vectors/Makefile @@ -1,6 +1,6 @@ -# $NetBSD: Makefile,v 1.14 2018/04/02 13:19:31 adam Exp $ +# $NetBSD: Makefile,v 1.15 2018/07/19 09:24:37 adam Exp $ -DISTNAME= cryptography_vectors-2.2.2 +DISTNAME= cryptography_vectors-2.3 PKGNAME= ${PYPKGPREFIX}-${DISTNAME} CATEGORIES= security python MASTER_SITES= ${MASTER_SITE_PYPI:=c/cryptography_vectors/} diff --git a/security/py-cryptography_vectors/PLIST b/security/py-cryptography_vectors/PLIST index 17325e91f39..1e68061a345 100644 --- a/security/py-cryptography_vectors/PLIST +++ b/security/py-cryptography_vectors/PLIST @@ -1,4 +1,4 @@ -@comment $NetBSD: PLIST,v 1.7 2018/03/22 11:49:19 adam Exp $ +@comment $NetBSD: PLIST,v 1.8 2018/07/19 09:24:37 adam Exp $ ${PYSITELIB}/${EGG_INFODIR}/PKG-INFO ${PYSITELIB}/${EGG_INFODIR}/SOURCES.txt ${PYSITELIB}/${EGG_INFODIR}/dependency_links.txt @@ -460,6 +460,34 @@ ${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512LongMsg.rsp ${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512Monte.rsp ${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512Monte.txt ${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_224LongMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_224Monte.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_224Monte.txt +${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_224ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_256LongMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_256Monte.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_256Monte.txt +${PYSITELIB}/cryptography_vectors/hashes/SHA2/SHA512_256ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_224LongMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_224Monte.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_224ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_256LongMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_256Monte.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_256ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_384LongMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_384Monte.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_384ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_512LongMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_512Monte.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHA3/SHA3_512ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE128LongMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE128Monte.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE128ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE128VariableOut.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE256LongMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE256Monte.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE256ShortMsg.rsp +${PYSITELIB}/cryptography_vectors/hashes/SHAKE/SHAKE256VariableOut.rsp ${PYSITELIB}/cryptography_vectors/hashes/blake2/blake2b.txt ${PYSITELIB}/cryptography_vectors/hashes/blake2/blake2s.txt ${PYSITELIB}/cryptography_vectors/hashes/ripemd160/ripevectors.txt @@ -2054,6 +2082,7 @@ ${PYSITELIB}/cryptography_vectors/x509/PKITS_data/smime/SignedValidpathLenConstr ${PYSITELIB}/cryptography_vectors/x509/PKITS_data/smime/SignedValidpre2000UTCnotBeforeDateTest3.eml ${PYSITELIB}/cryptography_vectors/x509/PKITS_data/smime/SignedinhibitAnyPolicyTest3.eml ${PYSITELIB}/cryptography_vectors/x509/alternate-rsa-sha1-oid.pem +${PYSITELIB}/cryptography_vectors/x509/badasn1time.pem ${PYSITELIB}/cryptography_vectors/x509/badssl-sct.pem ${PYSITELIB}/cryptography_vectors/x509/bigoid.pem ${PYSITELIB}/cryptography_vectors/x509/cryptography.io.pem diff --git a/security/py-cryptography_vectors/distinfo b/security/py-cryptography_vectors/distinfo index 3bf3486f872..2849df1aace 100644 --- a/security/py-cryptography_vectors/distinfo +++ b/security/py-cryptography_vectors/distinfo @@ -1,6 +1,6 @@ -$NetBSD: distinfo,v 1.14 2018/04/02 13:19:31 adam Exp $ +$NetBSD: distinfo,v 1.15 2018/07/19 09:24:37 adam Exp $ -SHA1 (cryptography_vectors-2.2.2.tar.gz) = 902bd2339c2ca02fde5568be34ba6db9ae21ac88 -RMD160 (cryptography_vectors-2.2.2.tar.gz) = 3baa49b197480af73496e9899489869018637b1d -SHA512 (cryptography_vectors-2.2.2.tar.gz) = bdaf53c8087d6c44fcd3ab54069d1d45b60ee80d98fd813fe180b9e88272203b5dd2abd5fa6dcd3b4ce9ec3215997fd8e99e63309e2f0ac619a6f72d552afff9 -Size (cryptography_vectors-2.2.2.tar.gz) = 27270814 bytes +SHA1 (cryptography_vectors-2.3.tar.gz) = 275e55bc76d74134c7e3e8ed733f2ca31c19286b +RMD160 (cryptography_vectors-2.3.tar.gz) = 118062bc683d59ceae6a67c38ed6dc5d96de2cd6 +SHA512 (cryptography_vectors-2.3.tar.gz) = 7c51b0c29c182c4da3265824a1b6e44c943bd41dfa89199cded963d0182a8ade678a560ec9ea13f6e8918119fcacf1c90d804cc90368e51cc5d430228448231c +Size (cryptography_vectors-2.3.tar.gz) = 35303908 bytes |