⭐ 欢迎来到虫虫下载站! | 📦 资源下载 📁 资源专辑 ℹ️ 关于我们
⭐ 虫虫下载站

📄 news

📁 mediastreamer2是开源的网络传输媒体流的库
💻
📖 第 1 页 / 共 2 页
字号:
  NEWS  ====  This file gives a brief overview of the major changes between each OpenSSL  release. For more details please read the CHANGES file.  Major changes between OpenSSL 0.9.8 and OpenSSL 0.9.8a:      o Fix potential SSL 2.0 rollback, CAN-2005-2969      o Extended Windows CE support  Major changes between OpenSSL 0.9.7g and OpenSSL 0.9.8:      o Major work on the BIGNUM library for higher efficiency and to        make operations more streamlined and less contradictory.  This        is the result of a major audit of the BIGNUM library.      o Addition of BIGNUM functions for fields GF(2^m) and NIST        curves, to support the Elliptic Crypto functions.      o Major work on Elliptic Crypto; ECDH and ECDSA added, including        the use through EVP, X509 and ENGINE.      o New ASN.1 mini-compiler that's usable through the OpenSSL        configuration file.      o Added support for ASN.1 indefinite length constructed encoding.      o New PKCS#12 'medium level' API to manipulate PKCS#12 files.      o Complete rework of shared library construction and linking        programs with shared or static libraries, through a separate        Makefile.shared.      o Rework of the passing of parameters from one Makefile to another.      o Changed ENGINE framework to load dynamic engine modules        automatically from specifically given directories.      o New structure and ASN.1 functions for CertificatePair.      o Changed the ZLIB compression method to be stateful.      o Changed the key-generation and primality testing "progress"        mechanism to take a structure that contains the ticker        function and an argument.      o New engine module: GMP (performs private key exponentiation).      o New engine module: VIA PadLOck ACE extension in VIA C3        Nehemiah processors.      o Added support for IPv6 addresses in certificate extensions.        See RFC 1884, section 2.2.      o Added support for certificate policy mappings, policy        constraints and name constraints.      o Added support for multi-valued AVAs in the OpenSSL        configuration file.      o Added support for multiple certificates with the same subject        in the 'openssl ca' index file.      o Make it possible to create self-signed certificates using        'openssl ca -selfsign'.      o Make it possible to generate a serial number file with        'openssl ca -create_serial'.      o New binary search functions with extended functionality.      o New BUF functions.      o New STORE structure and library to provide an interface to all        sorts of data repositories.  Supports storage of public and        private keys, certificates, CRLs, numbers and arbitrary blobs.	This library is unfortunately unfinished and unused withing	OpenSSL.      o New control functions for the error stack.      o Changed the PKCS#7 library to support one-pass S/MIME        processing.      o Added the possibility to compile without old deprecated        functionality with the OPENSSL_NO_DEPRECATED macro or the        'no-deprecated' argument to the config and Configure scripts.      o Constification of all ASN.1 conversion functions, and other        affected functions.      o Improved platform support for PowerPC.      o New FIPS 180-2 algorithms (SHA-224, -256, -384 and -512).      o New X509_VERIFY_PARAM structure to support parametrisation        of X.509 path validation.      o Major overhaul of RC4 performance on Intel P4, IA-64 and        AMD64.      o Changed the Configure script to have some algorithms disabled        by default.  Those can be explicitely enabled with the new        argument form 'enable-xxx'.      o Change the default digest in 'openssl' commands from MD5 to        SHA-1.      o Added support for DTLS.      o New BIGNUM blinding.      o Added support for the RSA-PSS encryption scheme      o Added support for the RSA X.931 padding.      o Added support for BSD sockets on NetWare.      o Added support for files larger than 2GB.      o Added initial support for Win64.      o Added alternate pkg-config files.  Major changes between OpenSSL 0.9.7f and OpenSSL 0.9.7g:      o More compilation issues fixed.      o Adaptation to more modern Kerberos API.      o Enhanced or corrected configuration for Solaris64, Mingw and Cygwin.      o Enhanced x86_64 assembler BIGNUM module.      o More constification.      o Added processing of proxy certificates (RFC 3820).  Major changes between OpenSSL 0.9.7e and OpenSSL 0.9.7f:      o Several compilation issues fixed.      o Many memory allocation failure checks added.      o Improved comparison of X509 Name type.      o Mandatory basic checks on certificates.      o Performance improvements.  Major changes between OpenSSL 0.9.7d and OpenSSL 0.9.7e:      o Fix race condition in CRL checking code.      o Fixes to PKCS#7 (S/MIME) code.  Major changes between OpenSSL 0.9.7c and OpenSSL 0.9.7d:      o Security: Fix Kerberos ciphersuite SSL/TLS handshaking bug      o Security: Fix null-pointer assignment in do_change_cipher_spec()      o Allow multiple active certificates with same subject in CA index      o Multiple X509 verification fixes      o Speed up HMAC and other operations  Major changes between OpenSSL 0.9.7b and OpenSSL 0.9.7c:      o Security: fix various ASN1 parsing bugs.      o New -ignore_err option to OCSP utility.      o Various interop and bug fixes in S/MIME code.      o SSL/TLS protocol fix for unrequested client certificates.  Major changes between OpenSSL 0.9.7a and OpenSSL 0.9.7b:      o Security: counter the Klima-Pokorny-Rosa extension of        Bleichbacher's attack       o Security: make RSA blinding default.      o Configuration: Irix fixes, AIX fixes, better mingw support.      o Support for new platforms: linux-ia64-ecc.      o Build: shared library support fixes.      o ASN.1: treat domainComponent correctly.      o Documentation: fixes and additions.  Major changes between OpenSSL 0.9.7 and OpenSSL 0.9.7a:      o Security: Important security related bugfixes.      o Enhanced compatibility with MIT Kerberos.      o Can be built without the ENGINE framework.      o IA32 assembler enhancements.      o Support for new platforms: FreeBSD/IA64 and FreeBSD/Sparc64.      o Configuration: the no-err option now works properly.      o SSL/TLS: now handles manual certificate chain building.      o SSL/TLS: certain session ID malfunctions corrected.  Major changes between OpenSSL 0.9.6 and OpenSSL 0.9.7:      o New library section OCSP.      o Complete rewrite of ASN1 code.      o CRL checking in verify code and openssl utility.      o Extension copying in 'ca' utility.      o Flexible display options in 'ca' utility.      o Provisional support for international characters with UTF8.      o Support for external crypto devices ('engine') is no longer        a separate distribution.      o New elliptic curve library section.      o New AES (Rijndael) library section.      o Support for new platforms: Windows CE, Tandem OSS, A/UX, AIX 64-bit,        Linux x86_64, Linux 64-bit on Sparc v9      o Extended support for some platforms: VxWorks      o Enhanced support for shared libraries.      o Now only builds PIC code when shared library support is requested.      o Support for pkg-config.      o Lots of new manuals.      o Makes symbolic links to or copies of manuals to cover all described        functions.      o Change DES API to clean up the namespace (some applications link also        against libdes providing similar functions having the same name).        Provide macros for backward compatibility (will be removed in the        future).      o Unify handling of cryptographic algorithms (software and engine)        to be available via EVP routines for asymmetric and symmetric ciphers.      o NCONF: new configuration handling routines.      o Change API to use more 'const' modifiers to improve error checking        and help optimizers.      o Finally remove references to RSAref.      o Reworked parts of the BIGNUM code.      o Support for new engines: Broadcom ubsec, Accelerated Encryption        Processing, IBM 4758.      o A few new engines added in the demos area.      o Extended and corrected OID (object identifier) table.      o PRNG: query at more locations for a random device, automatic query for        EGD style random sources at several locations.      o SSL/TLS: allow optional cipher choice according to server's preference.      o SSL/TLS: allow server to explicitly set new session ids.      o SSL/TLS: support Kerberos cipher suites (RFC2712).	Only supports MIT Kerberos for now.      o SSL/TLS: allow more precise control of renegotiations and sessions.      o SSL/TLS: add callback to retrieve SSL/TLS messages.      o SSL/TLS: support AES cipher suites (RFC3268).  Major changes between OpenSSL 0.9.6j and OpenSSL 0.9.6k:      o Security: fix various ASN1 parsing bugs.      o SSL/TLS protocol fix for unrequested client certificates.  Major changes between OpenSSL 0.9.6i and OpenSSL 0.9.6j:      o Security: counter the Klima-Pokorny-Rosa extension of        Bleichbacher's attack       o Security: make RSA blinding default.      o Build: shared library support fixes.  Major changes between OpenSSL 0.9.6h and OpenSSL 0.9.6i:      o Important security related bugfixes.

⌨️ 快捷键说明

复制代码 Ctrl + C
搜索代码 Ctrl + F
全屏模式 F11
切换主题 Ctrl + Shift + D
显示快捷键 ?
增大字号 Ctrl + =
减小字号 Ctrl + -