This repository was archived by the owner on Apr 22, 2023. It is now read-only.
Upgrade to openssl-1.0.1n to v0.10#25513
Closed
shigeki wants to merge 5 commits intonodejs:v0.10from
Closed
Conversation
This just replaces all sources of openssl-1.0.1n.tar.gz into deps/openssl/openssl.
Change all openssl/include/openssl/*.h to include resolved symbolic links and openssl/crypto/opensslconf.h to refer config/opensslconf.h.
sha256-x86_64.pl does not exist in the origin openssl distribution. It was copied from sha512-x86_64.pl and both sha256/sha512 scripts were modified so as to generates only one asm file specified as its key hash length. PR: nodejs#9451 PR-URL: nodejs#9451 Reviewed-By: Julien Gilli <[email protected]>
`x86masm.pl` was mistakenly using .486 instruction set, why `cpuid` (and perhaps others) are requiring .686 . PR: nodejs#9451 PR-URL: nodejs#9451 Reviewed-By: Julien Gilli <[email protected]>
reapply b910613 PR: nodejs#9451 PR-URL: nodejs#9451 Reviewed-By: Julien Gilli <[email protected]>
Author
|
Note that v0.10 does not support DHE so node-v0.10.x is vulnerable only to CVE-2015-1788. |
Author
|
|
Author
|
move to #25523 for a new release of 1.0.1o. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This is an upgrade to openssl-1.0.1n to the v0.10 branch. No asm and conf files are changed.
I don't have an access to CI of joyent so
make testwas done on my Ubuntu(x64) and only test-debugger-client.js was failed. I think it is not related to this PR.OpenSSL-1.0.1n includes alt chain support in openssl/openssl@f7bf8e0 so that re-adding 1024-bit root certs of 1425ccd can be reverted. But it is not included here yet.
For v0.12,
-no_rand_screenpatch and limiting DHParam size below 1024 bits for logjam attack would be needed in addition. I will submit another PR to agains v0.12 branch.