diff options
author | manu <manu> | 2009-11-18 08:10:15 +0000 |
---|---|---|
committer | manu <manu> | 2009-11-18 08:10:15 +0000 |
commit | 7fbb482af1b6f24926a8a49741c0f21371e36811 (patch) | |
tree | f6c5aeee9a7be52469882303c064e106fe08a6a7 /x11/gtk2 | |
parent | 13d7427167804c315ea22c9f31c56ab4798d6fb3 (diff) | |
download | pkgsrc-7fbb482af1b6f24926a8a49741c0f21371e36811.tar.gz |
Update to 2.1rc21. From Changelog:
* Rebuilt OpenVPN Windows installer with OpenSSL 0.9.8l to address
CVE-2009-3555. Note that OpenVPN has never relied on the session
renegotiation capabilities that are built into the SSL/TLS protocol,
therefore the fix in OpenSSL 0.9.8l (disable SSL/TLS renegotiation
completely) will not adversely affect OpenVPN mid-session SSL/TLS
renegotation or any other OpenVPN capabilities.
* Added additional session renegotiation hardening. OpenVPN has always
required that mid-session renegotiations build up a new SSL/TLS
session from scratch. While the client certificate common name is
already locked against changes in mid-session TLS renegotiations, we
now extend this locking to the auth-user-pass username as well as all
certificate content in the full client certificate chain.
Diffstat (limited to 'x11/gtk2')
0 files changed, 0 insertions, 0 deletions