Re: [edk2] [PATCH] CryptoPkg: update OpenSSL dependency to version 1.0.2d

2015-07-12 Thread Ard Biesheuvel
On 12 July 2015 at 19:34, Long, Qin wrote: > Ard, > > This looks good to me. (And thanks for doing this. I was out of office this > week, so sorry for late response.) > > Reviewed-by: Qin Long > Thanks! Committed as SVN r17928 Regards, Ard. > -Original Message- > From: Ard Biesheuvel

Re: [edk2] [PATCH] CryptoPkg: update OpenSSL dependency to version 1.0.2d

2015-07-12 Thread Long, Qin
Ard, This looks good to me. (And thanks for doing this. I was out of office this week, so sorry for late response.) Reviewed-by: Qin Long Best Regards & Thanks, LONG, Qin -Original Message- From: Ard Biesheuvel [mailto:ard.biesheu...@linaro.org] Sent: Friday, July 10, 2015 5:21 PM T

Re: [edk2] [PATCH] CryptoPkg: update OpenSSL dependency to version 1.0.2d

2015-07-10 Thread Ard Biesheuvel
On 10 July 2015 at 09:53, Ye, Ting wrote: > Looks good to me. > Reviewed-by: Ye Ting > @Qin: are you ok with this patch? I would like to get it submitted asap to fix our automated build (it is broken because 1.0.2c is no longer available for download) Thanks, Ard. > -Original Message-

Re: [edk2] [PATCH] CryptoPkg: update OpenSSL dependency to version 1.0.2d

2015-07-10 Thread Ye, Ting
Looks good to me. Reviewed-by: Ye Ting -Original Message- From: Ard Biesheuvel [mailto:ard.biesheu...@linaro.org] Sent: Friday, July 10, 2015 2:54 PM To: edk2-devel@lists.sourceforge.net; Long, Qin; Dong, Guo; Ye, Ting Cc: Justen, Jordan L; Gao, Liming; Ard Biesheuvel Subject: [PATCH] C

Re: [edk2] [PATCH] CryptoPkg: update OpenSSL dependency to version 1.0.2d

2015-07-10 Thread Laszlo Ersek
On 07/10/15 08:54, Ard Biesheuvel wrote: > Upstream OpenSSL version 1.0.2c contained a fatal flaw > [CVE-2015-1793] and is no longer available from the openssl.org > download servers. So upgrade to its replacement, version 1.0.2d. > > Contributed-under: TianoCore Contribution Agreement 1.0 > Signe

[edk2] [PATCH] CryptoPkg: update OpenSSL dependency to version 1.0.2d

2015-07-09 Thread Ard Biesheuvel
Upstream OpenSSL version 1.0.2c contained a fatal flaw [CVE-2015-1793] and is no longer available from the openssl.org download servers. So upgrade to its replacement, version 1.0.2d. Contributed-under: TianoCore Contribution Agreement 1.0 Signed-off-by: Ard Biesheuvel --- CryptoPkg/Library/Open