diff options
author | manu <manu@pkgsrc.org> | 2009-11-18 08:10:15 +0000 |
---|---|---|
committer | manu <manu@pkgsrc.org> | 2009-11-18 08:10:15 +0000 |
commit | 3905fa5acb63a08351dd1b38405b72187f3939af (patch) | |
tree | f6c5aeee9a7be52469882303c064e106fe08a6a7 /x11 | |
parent | 9c7a0756a22f701c649d6534c78d3276398bb035 (diff) | |
download | pkgsrc-3905fa5acb63a08351dd1b38405b72187f3939af.tar.gz |
Update to 2.1rc21. From Changelog:
* Rebuilt OpenVPN Windows installer with OpenSSL 0.9.8l to address
CVE-2009-3555. Note that OpenVPN has never relied on the session
renegotiation capabilities that are built into the SSL/TLS protocol,
therefore the fix in OpenSSL 0.9.8l (disable SSL/TLS renegotiation
completely) will not adversely affect OpenVPN mid-session SSL/TLS
renegotation or any other OpenVPN capabilities.
* Added additional session renegotiation hardening. OpenVPN has always
required that mid-session renegotiations build up a new SSL/TLS
session from scratch. While the client certificate common name is
already locked against changes in mid-session TLS renegotiations, we
now extend this locking to the auth-user-pass username as well as all
certificate content in the full client certificate chain.
Diffstat (limited to 'x11')
0 files changed, 0 insertions, 0 deletions