[ubuntu/focal-proposed] openssl 1.1.1d-2ubuntu3 (Accepted)

Dimitri John Ledkov xnox at ubuntu.com
Thu Jan 16 14:17:14 UTC 2020


openssl (1.1.1d-2ubuntu3) focal; urgency=medium

  * Use perl:native in the autopkgtest for installability on i386.

openssl (1.1.1d-2ubuntu2) focal; urgency=low

  * Merge from Debian unstable.  Remaining changes:
    - Replace duplicate files in the doc directory with symlinks.
    - debian/libssl1.1.postinst:
      + Display a system restart required notification on libssl1.1
        upgrade on servers.
      + Use a different priority for libssl1.1/restart-services depending
        on whether a desktop, or server dist-upgrade is being performed.
      + Bump version check to to 1.1.1.
      + Import libraries/restart-without-asking template as used by above.
    - Revert "Enable system default config to enforce TLS1.2 as a
      minimum" & "Increase default security level from 1 to 2".
    - Reword the NEWS entry, as applicable on Ubuntu.
    - Cherrypick s390x SIMD acceleration patches for poly1305 and chacha20
      from master.

  * Set OPENSSL_TLS_SECURITY_LEVEL=2 as compiled-in minimum security
    level. Change meaning of SECURITY_LEVEL=2 to prohibit TLS versions
    below 1.2 and update documentation. Previous default of 1, can be set
    by calling SSL_CTX_set_security_level(), SSL_set_security_level() or
    using ':@SECLEVEL=1' CipherString value in openssl.cfg.

openssl (1.1.1d-2) unstable; urgency=medium

  * Reenable AES-CBC-HMAC-SHA ciphers (Closes: #941987).

openssl (1.1.1d-1) unstable; urgency=medium

  * New upstream version
   - CVE-2019-1549 (Fixed a fork protection issue).
   - CVE-2019-1547 (Compute ECC cofactors if not provided during EC_GROUP
     construction).
   - CVE-2019-1563 (Fixed a padding oracle in PKCS7_dataDecode and
     CMS_decrypt_set1_pkey).
  * Update symbol list

Date: Thu, 16 Jan 2020 14:15:26 +0000
Changed-By: Dimitri John Ledkov <xnox at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/openssl/1.1.1d-2ubuntu3
-------------- next part --------------
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Thu, 16 Jan 2020 14:15:26 +0000
Source: openssl
Architecture: source
Version: 1.1.1d-2ubuntu3
Distribution: focal
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Dimitri John Ledkov <xnox at ubuntu.com>
Closes: 941987
Changes:
 openssl (1.1.1d-2ubuntu3) focal; urgency=medium
 .
   * Use perl:native in the autopkgtest for installability on i386.
 .
 openssl (1.1.1d-2ubuntu2) focal; urgency=low
 .
   * Merge from Debian unstable.  Remaining changes:
     - Replace duplicate files in the doc directory with symlinks.
     - debian/libssl1.1.postinst:
       + Display a system restart required notification on libssl1.1
         upgrade on servers.
       + Use a different priority for libssl1.1/restart-services depending
         on whether a desktop, or server dist-upgrade is being performed.
       + Bump version check to to 1.1.1.
       + Import libraries/restart-without-asking template as used by above.
     - Revert "Enable system default config to enforce TLS1.2 as a
       minimum" & "Increase default security level from 1 to 2".
     - Reword the NEWS entry, as applicable on Ubuntu.
     - Cherrypick s390x SIMD acceleration patches for poly1305 and chacha20
       from master.
 .
   * Set OPENSSL_TLS_SECURITY_LEVEL=2 as compiled-in minimum security
     level. Change meaning of SECURITY_LEVEL=2 to prohibit TLS versions
     below 1.2 and update documentation. Previous default of 1, can be set
     by calling SSL_CTX_set_security_level(), SSL_set_security_level() or
     using ':@SECLEVEL=1' CipherString value in openssl.cfg.
 .
 openssl (1.1.1d-2) unstable; urgency=medium
 .
   * Reenable AES-CBC-HMAC-SHA ciphers (Closes: #941987).
 .
 openssl (1.1.1d-1) unstable; urgency=medium
 .
   * New upstream version
    - CVE-2019-1549 (Fixed a fork protection issue).
    - CVE-2019-1547 (Compute ECC cofactors if not provided during EC_GROUP
      construction).
    - CVE-2019-1563 (Fixed a padding oracle in PKCS7_dataDecode and
      CMS_decrypt_set1_pkey).
   * Update symbol list
Checksums-Sha1:
 bb59d089fb9bb35280d4e3ed93b3cff9cc8c5e4d 2699 openssl_1.1.1d-2ubuntu3.dsc
 056057782325134b76d1931c48f2c7e6595d7ef4 8845861 openssl_1.1.1d.orig.tar.gz
 d3bbfe1db19cc36bb17f2b6dc39fa8ade6a8cdd3 488 openssl_1.1.1d.orig.tar.gz.asc
 00a9714319cc8e18e8a462020b307b4d438cfb9b 146992 openssl_1.1.1d-2ubuntu3.debian.tar.xz
 6797c557b94aaf94cc7b87d7b0f32e56b2d3cd6d 6594 openssl_1.1.1d-2ubuntu3_source.buildinfo
Checksums-Sha256:
 47cc9e348c5751b170c8b7f0e5f5074a894feb3096c1773d617e375ffbde21c0 2699 openssl_1.1.1d-2ubuntu3.dsc
 1e3a91bc1f9dfce01af26026f856e064eab4c8ee0a8f457b5ae30b40b8b711f2 8845861 openssl_1.1.1d.orig.tar.gz
 f3fd3299a79421fffd51d35f62636b8e987dab1d3033d93a19d7685868e15395 488 openssl_1.1.1d.orig.tar.gz.asc
 cc0de82d54fa27c176d0f91681b2379d4b0bd1e9db1bbde825746adf1c73c318 146992 openssl_1.1.1d-2ubuntu3.debian.tar.xz
 1c1636f75517c4b4e653fe21db35f8710bcfeddb72ebc2794e1331dd905ac395 6594 openssl_1.1.1d-2ubuntu3_source.buildinfo
Files:
 9268f8f6f2f57db8450d613f10dfd45d 2699 utils optional openssl_1.1.1d-2ubuntu3.dsc
 3be209000dbc7e1b95bcdf47980a3baa 8845861 utils optional openssl_1.1.1d.orig.tar.gz
 56a525b2d934330e1c2de3bc9b55e4e2 488 utils optional openssl_1.1.1d.orig.tar.gz.asc
 33856883102d762ea6a836bd3c984f1b 146992 utils optional openssl_1.1.1d-2ubuntu3.debian.tar.xz
 17122ffee9295b8a071aee7590d32b3d 6594 utils optional openssl_1.1.1d-2ubuntu3_source.buildinfo
Original-Maintainer: Debian OpenSSL Team <pkg-openssl-devel at lists.alioth.debian.org>

-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7iQKBSojGtiSWEHXm47ISdXvcO0FAl4gcCoACgkQm47ISdXv
cO3DVBAAhdNFNnYz3GhUY2tCDaJLGsBtrAgzMNyysfq2AEsuKIOnHIbizH/06Ds3
Rfo7wDGw1gCsRpxakChEBhkObVdGwKsbdZADtAxYYJbf5BwdDhTrd6NaC4MNKh3v
NfFdvQzjH6tW8A7PvKxMznWWsl8bcHxFc+x9Fqm3UYGN7ZWlePKb70auit+Go1Lr
0FsXZ0UorCTxC03VyoPQaQt0qbEWfnjONvqvzjqSA+IMVSo7TeIJyjGmARqlIdk6
jKalFJU2G6fEQZs6vCexXwr31rjhivtDG3JCipTyD+DuYplWWHudOb3QzzCtmJip
gX7xK4c/UOJTjwLl/ine3GYLBBErDt2gF1mVmNVMKQlzClzeXqFjmQfaBzcPugFp
5Ilf5/c7fseUdgf2hpC2b4kz5e4kc8xhZJg+xcFNDe7JqB6Wtc9q8lOcWi+OnL32
jolP8YnR1MOJs5wKXKYiLVStN5y6f1EXpbt2wIYTenHjnSv4DuJatAVZ+ZcKxtVU
CdRsfAkUaZuOHc6phwbHnIQwnDTtfId41npTI2SeZ5Y5n+OnNVSi1QWBEgHFcb5j
wk1qe22eB5Ux54AM6D9f+/udblOVkNqgziKaNi/63Lj1TN+gpzJFqqUnhh5x9G7a
9DBPw42Xb7454Oe0oGJkHyHLqv+JxRRfJvFxnGyxYo52VvGSYbo=
=ymcs
-----END PGP SIGNATURE-----


More information about the Focal-changes mailing list