summaryrefslogtreecommitdiff
path: root/x11
diff options
context:
space:
mode:
authormanu <manu@pkgsrc.org>2009-11-18 08:10:15 +0000
committermanu <manu@pkgsrc.org>2009-11-18 08:10:15 +0000
commit3905fa5acb63a08351dd1b38405b72187f3939af (patch)
treef6c5aeee9a7be52469882303c064e106fe08a6a7 /x11
parent9c7a0756a22f701c649d6534c78d3276398bb035 (diff)
downloadpkgsrc-3905fa5acb63a08351dd1b38405b72187f3939af.tar.gz
Update to 2.1rc21. From Changelog:
* Rebuilt OpenVPN Windows installer with OpenSSL 0.9.8l to address CVE-2009-3555. Note that OpenVPN has never relied on the session renegotiation capabilities that are built into the SSL/TLS protocol, therefore the fix in OpenSSL 0.9.8l (disable SSL/TLS renegotiation completely) will not adversely affect OpenVPN mid-session SSL/TLS renegotation or any other OpenVPN capabilities. * Added additional session renegotiation hardening. OpenVPN has always required that mid-session renegotiations build up a new SSL/TLS session from scratch. While the client certificate common name is already locked against changes in mid-session TLS renegotiations, we now extend this locking to the auth-user-pass username as well as all certificate content in the full client certificate chain.
Diffstat (limited to 'x11')
0 files changed, 0 insertions, 0 deletions