by TimWolla on 10/12/22, 2:37 PM with 9 comments
by frankjr on 10/12/22, 4:21 PM
- Regression: X509_sign, etc., no longer implicitly refresh the cached TBSCertificate (https://github.com/openssl/openssl/issues/19388)
- PKCS12_parse leaves errors on stack [3.0.6] (https://github.com/openssl/openssl/issues/19389)
by bombcar on 10/12/22, 3:24 PM
https://www.openssl.org/news/vulnerabilities.html#CVE-2022-3...
1.1.1r was "Added a missing header for memcmp that caused compilation failure on some platforms"
by Felger on 10/12/22, 3:45 PM
by TillE on 10/12/22, 4:25 PM
We also dodged the serious bug introduced in 3.0.4 that way.
by remram on 10/13/22, 6:09 AM
The other day my cluster went down because the rules for "self-signed certificates" changed between releases, and a certificate signed by a different CA with a similar Common Name was now rejected as "self-signed" by the client library.
What's the point of suffering a naming scheme this silly if we can expect major breakage between each release anyway?
by nwmcsween on 10/12/22, 11:52 PM