LibreSSL 3.8.0 inosvika neshanduko dzakawanda nekuvandudzwa

FreeSSL

LibreSSL iforogo yeOpenSSL yakagadziriswa neiyo OpenBSD chirongwa.

Ivo vanogadzira chirongwa cheOpenBSD nguva pfupi yadarika vakazivisa kuburitswa kweinotakurika edition yepakeji. "FreeSSL 3.8.0", shanduro umo shanduko dzinoverengeka uye kuvandudzwa kwakanangana nekugadzikana uye kuenderana kwakaitwa.

Kune avo vasingazive nezve LibreSSL, iwe unofanirwa kuziva kuti izvi ndeye yakavhurika sosi kuita yeprotocol TLS inogadzira forogo yeOpenSSL chinangwa chekupa hutano hwepamusoro. LibreSSL yakatanga kugadzirwa seyakagadzirirwa kutsiva OpenSSL paOpenBSD, uye yakaendeswa kune mamwe mapuratifomu kana shanduro yakabviswa-pasi yeraibhurari yakagadzikana.

Iyo LibreSSL purojekiti inotarisana nerutsigiro rwemhando yepamusoro yeSSL/TLS mapuroteni nekubvisa zvisingakoshi, kuwedzera mamwe maficha ekuchengetedza, uye kwakakosha kucheneswa uye kugadziridza kweiyo kodhi base.

Hunhu hutsva hutsva hweLibreSSL 3.8.0

LibreSSL shanduro 3.8.0 inonzi ishanduro yekuedza iyo inovandudza mabasa anozoverengerwa neOpenBSD 7.4. Panguva imwecheteyo, shanduro dzakagadzikana dzeLibreSSL 3.6.3 uye 3.7.3 dzakaumbwa, umo zvikwata zvakasiyana-siyana zvakagadziriswa.

Muiyi vhezheni nyowani yeLibreSSL 3.8.0, inosimbiswa kuti yakavandudzwa endian.h kuenderana nehto* uye *toh macros, Pamusoro pekuwedzera iyo rutsigiro rweSHA-2 uye SHA-3 truncated uye yemukati SHA kodhi yekuchenesa uye rework maitiro atanga.

Imwe shanduko inocherechedzwa ndeye kunyorwazve mukati mabasa BN_exp() uye BN_copy(), pamwe nekutsiva kuitwa kweBN_mod_sqrt() basa.

Mukuwedzera kune izvi, zvinoratidzwa zvakare kuti mirayiridzo yakawedzerwa assembler yezvivakwa AMD64 shandisa endbr64 mirairo (Kumisa Bazi Risina Kunanga).

Zvinotaridzawo kuti yakawedzerwa gadziriso yekuchinja kusingafungirwe zvakanaka muOpenSSL 3 iyo yakatyora tsigiro yekuparadzaniswa kweropafadzo mumabtls, Pamusoro pezvo, iyo BoringSSL kodhi yakatakurwa kuti ione mitemo inotsanangurwa muRFC 5280 uye shanduro yeLibcrypto inoramba ichishandisa CBB (bytebuilder) uye CBS (bytestring) nzvimbo.

Kune rimwe divi, zvinoratidzwa kuti iyo BoringSSL RFC 5280 kodhi yekusimbisa mutemo yakaunzwa uye yakashandiswa.
kutsiva yekare exponential timecode, kuwedzera pakubvisa tsigiro yeGF2m:BIGNUM sezvo isingatsigire bhinari yekuwedzera, ichibvisa akawanda ezviratidzo zveruzhinji zvakadzikiswa muOpenSSL 0.9.8.

Yeimwe shanduko izvo zvinoratidzika kubva pane iyi nyowani vhezheni:

  • Yakabviswa X9.31 public API (RSA_X931_PADDING ichiri kuwanikwa).
  • Yakabviswa ciphertext stealing mode.
  • Yakabviswa rutsigiro rweSXNET neNETCAPE_CERT_SEQUENCE, kusanganisira iyo
    openssl(1) command nseq.
  • Yakadonhedza proxy chitupa (RFC 3820) rutsigiro.
  • POLICY_TREE nezvimiro zvayo uye maAPIs zvabviswa.
  • Yakagadziriswa bug cheki ye i2d_ECDSA_SIG() mu ossl_ecdsa_sign().
  • Yakagadziriswa yekuona yeakawedzera mashandiro (XOP) pane AMD hardware.
  • Yakagadziriswa kukanganisa kubata mu tls_check_common_name().
  • Yakawedzera kushaikwa kwepointer muSSL_free().
  • Yakagadziriswa X509err() uye X509V3err() uye neshanduro dzadzo dzemukati.
  • Yakavandudzwa zvakanyanya bvunzo yekuvhara yeBN_mod_sqrt () uye GCD.
  • Senguva dzose, bvunzo nyowani yekuvhara inowedzerwa sezvo bugs uye subsystems zvakagadziriswa
    vanocheneswa.

Chekupedzisira, kana iwe uchifarira kuziva zvakawanda nezvazvo, unogona kutarisa ruzivo Mune inotevera chinongedzo.

Maitiro ekuisa iyo nyowani vhezheni yeLibreSSL?

Kune avo vanofarira kukwanisa kuisa iyi vhezheni itsva, vanofanirwa kuziva kuti parizvino haisati yasvika pakugoverwa kweLinux kwakawanda, saka kuisirwa kuripo ikozvino. wakagadzira pasuru wega.

Asi usazvinetse, iyo LibreSSL inovaka Izvo zviri nyore uye nekuda kweizvi unongofanirwa kuvhura terminal uye mhanyisa iyo inotevera mirairo (iwe unofanirwa kuve neanotevera zvinoenderana otomatiki, autoconf, git, libtool, perl uye git).

Chinhu chekutanga kutora iyo kodhi kodhi, iyo iwe yaunogona kuita nemurairo uyu:

git clone https://github.com/libressl/portable.git

Kana izvi zvangoitwa, ikozvino tave kugadzirira nzira yekuita kuunganidzwa, nekuda kweizvi tinoisa dhairekitori rine iyo kodhi kodhi yeLibreSSL uye isu tichanyora:

cd inotakurika ./autogen.sh ./dist.sh

Kana izvi zvaitwa, tinoenderera mberi nekugadzira ne:

./configure make check make install

Kana kana uchida kuzviita neCMake:

mkdir kuvaka cd kuvaka cmake .. ita bvunzo

Siya yako yekutaura

Your kero e havazobvumirwi ichibudiswa. Raida minda anozivikanwa ne *

*

*

  1. Inotarisira iyo data: Miguel Ángel Gatón
  2. Chinangwa cheiyo data: Kudzora SPAM, manejimendi manejimendi.
  3. Legitimation: Kubvuma kwako
  4. Kutaurirana kwedata
  5. Dhata yekuchengetedza: Dhatabhesi inobatwa neOccentus Networks (EU)
  6. Kodzero: Panguva ipi neipi iwe unogona kudzora, kupora uye kudzima ruzivo rwako