CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]    2026/09/29 08:11:47

Modified files:
        lib/libcrypto/man: Tag: OPENBSD_7_9 x509v3.cnf.5 
        lib/libcrypto/x509: Tag: OPENBSD_7_9 x509_crld.c x509_purp.c 
        lib/libssl     : Tag: OPENBSD_7_9 d1_both.c 

Log message:
libcrypto: remove support for nameRelativeToCRLIssuer

Drop support for nameRelativeToCRLIssuer from the CRL Distribution Point
extension. Per RFC 5280, 4.2.1.13, conforming CAs SHOULD not use it, which
is sound advice since this garbage was eating memory for breakfast before
signature thanks to the wonderful gem that is the extension cache.

One has to wonder why this was needed in libcrypto... This isn't worth
fixing so off to the bit bucket it goes.

from tb, ok beck jsing

libssl: Avoid potential overread on interrupted retransmission in DTLS

from OpenSSL via jsing

this is errata/7.9/024_libressl.patch.sig

Reply via email to