You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 
Go to file
Michel Lind 488971d8fd
Drop openssl-fips-provider requirement, accidentally included due to incorrect gating
5 months ago
.fmf Add interop rpm-tmt-tests 1 year ago
plans Add interop rpm-tmt-tests 1 year ago
.gitignore Rebasing to OpenSSL 3.2.1 5 months ago
0001-Aarch64-and-ppc64le-use-lib64.patch Rebase to OpenSSL version 3.0.0 3 years ago
0002-Use-more-general-default-values-in-openssl.cnf.patch Rebase to OpenSSL version 3.0.0 3 years ago
0003-Do-not-install-html-docs.patch Rebasing to OpenSSL 3.2.1 5 months ago
0004-Override-default-paths-for-the-CA-directory-tree.patch Provide empty evp_properties section in main OpenSSL configuration file 11 months ago
0005-apps-ca-fix-md-option-help-text.patch Rebase to OpenSSL version 3.0.0 3 years ago
0006-Disable-signature-verification-with-totally-unsafe-h.patch Update to Beta1 version 3 years ago
0007-Add-support-for-PROFILE-SYSTEM-system-default-cipher.patch Rebasing to OpenSSL 3.2.1 5 months ago
0008-Add-FIPS_mode-compatibility-macro.patch Adjusting include for the FIPS_mode macro 2 years ago
0009-Add-Kernel-FIPS-mode-flag-support.patch Rebasing to OpenSSL 3.2.1 5 months ago
0010-Add-changes-to-ectest-and-eccurve.patch Rebasing to OpenSSL 3.2.1 5 months ago
0011-Remove-EC-curves.patch Rebasing to OpenSSL 3.2.1 5 months ago
0012-Disable-explicit-ec.patch Forbid explicit curves when created via EVP_PKEY_fromdata 11 months ago
0013-skipped-tests-EC-curves.patch Rebasing to OpenSSL 3.2.1 5 months ago
0024-load-legacy-prov.patch Add a directory for OpenSSL providers configuration 8 months ago
0025-for-tests.patch Always activate default provider via config 3 years ago
0032-Force-fips.patch Rebasing to OpenSSL 3.2.1 5 months ago
0033-FIPS-embed-hmac.patch Rebasing to OpenSSL 3.2.1 5 months ago
0034.fipsinstall_disable.patch Rebasing to OpenSSL 3.2.1 5 months ago
0035-speed-skip-unavailable-dgst.patch Rebasing to OpenSSL 3.0.7 2 years ago
0044-FIPS-140-3-keychecks.patch Rebasing to OpenSSL 3.2.1 5 months ago
0045-FIPS-services-minimize.patch Rebasing to OpenSSL 3.2.1 5 months ago
0047-FIPS-early-KATS.patch Rebasing to OpenSSL 3.2.1 5 months ago
0049-Selectively-disallow-SHA1-signatures.patch Rebasing to OpenSSL 3.2.1 5 months ago
0050-FIPS-enable-pkcs12-mac.patch OpenSSL will generate keys with prime192v1 curve if it is provided using explicit parameters 3 years ago
0052-Allow-SHA1-in-seclevel-2-if-rh-allow-sha1-signatures.patch Rebasing to OpenSSL 3.2.1 5 months ago
0056-strcasecmp.patch Merge c9s openssl changes to pick up CVE fixes 5 months ago
0058-FIPS-limit-rsa-encrypt.patch Rebasing to OpenSSL 3.2.1 5 months ago
0061-Deny-SHA-1-signature-verification-in-FIPS-provider.patch Rebasing to OpenSSL 3.0.7 2 years ago
0062-fips-Expose-a-FIPS-indicator.patch Rebasing to OpenSSL 3.2.1 5 months ago
0073-FIPS-Use-OAEP-in-KATs-support-fixed-OAEP-seed.patch Rebasing to OpenSSL 3.2.1 5 months ago
0074-FIPS-Use-digest_sign-digest_verify-in-self-test.patch Rebasing to OpenSSL 3.2.1 5 months ago
0075-FIPS-Use-FFDHE2048-in-self-test.patch FIPS self-test: RSA-OAEP, FFDHE2048, digest_sign 2 years ago
0076-FIPS-140-3-DRBG.patch Rebasing to OpenSSL 3.2.1 5 months ago
0077-FIPS-140-3-zeroization.patch Rebasing to OpenSSL 3.2.1 5 months ago
0078-KDF-Add-FIPS-indicators.patch Rebasing to OpenSSL 3.2.1 5 months ago
0080-rand-Forbid-truncated-hashes-SHA-3-in-FIPS-prov.patch Rebasing to OpenSSL 3.2.1 5 months ago
0081-signature-Remove-X9.31-padding-from-FIPS-prov.patch Remove support for X9.31 signature padding in FIPS mode 2 years ago
0083-hmac-Add-explicit-FIPS-indicator-for-key-length.patch Rebasing to OpenSSL 3.2.1 5 months ago
0084-pbkdf2-Set-minimum-password-length-of-8-bytes.patch Rebasing to OpenSSL 3.2.1 5 months ago
0085-FIPS-RSA-disable-shake.patch Disallow SHAKE in OAEP decryption in FIPS mode 2 years ago
0088-signature-Add-indicator-for-PSS-salt-length.patch Rebasing to OpenSSL 3.2.1 5 months ago
0091-FIPS-RSA-encapsulate.patch Fix explicit indicator for PSS salt length 2 years ago
0093-DH-Disable-FIPS-186-4-type-parameters-in-FIPS-mode.patch FIPS: Re-enable DHX, disable FIPS 186-4 groups 1 year ago
0110-GCM-Implement-explicit-FIPS-indicator-for-IV-gen.patch Rebasing to OpenSSL 3.2.1 5 months ago
0112-pbdkf2-Set-indicator-if-pkcs5-param-disabled-checks.patch Add explicit FIPS indicator for PBKDF2 2 years ago
0113-asymciphers-kem-Add-explicit-FIPS-indicator.patch Rebasing to OpenSSL 3.2.1 5 months ago
0114-FIPS-enforce-EMS-support.patch Rebasing to OpenSSL 3.2.1 5 months ago
0115-skip-quic-pairwise.patch Rebasing to OpenSSL 3.2.1 5 months ago
0116-version-aliasing.patch Rebasing to OpenSSL 3.2.1 5 months ago
0117-ignore-unknown-sigalgorithms-groups.patch Rebasing to OpenSSL 3.2.1 5 months ago
0118-no-crl-memleak.patch Rebasing to OpenSSL 3.2.1 5 months ago
0119-provider-sigalgs-in-signaturealgorithms-conf.patch Rebasing to OpenSSL 3.2.1 5 months ago
0121-FIPS-cms-defaults.patch Use OAEP padding and aes-128-cbc by default in cms command in FIPS mode 1 year ago
0122-TMP-KTLS-test-skip.patch Rebasing to OpenSSL 3.2.1 5 months ago
Makefile.certificate RHEL 9.0.0 Alpha bootstrap 4 years ago
README.md Add instructions for keeping in sync with upstream repo 3 years ago
ci.fmf ci.fmf: Enable golang tests as reverse dependency 1 year ago
configuration-prefix.h Rebase to OpenSSL version 3.0.0 3 years ago
configuration-switch.h Rebase to OpenSSL version 3.0.0 3 years ago
gating.yaml Temporary manual test 2 years ago
genpatches Rebase to OpenSSL version 3.0.0 3 years ago
make-dummy-cert RHEL 9.0.0 Alpha bootstrap 4 years ago
openssl3.spec Drop openssl-fips-provider requirement, accidentally included due to incorrect gating 5 months ago
renew-dummy-cert RHEL 9.0.0 Alpha bootstrap 4 years ago
rpminspect.yaml Make rpminspect happy 3 years ago
sources Rebasing to OpenSSL 3.2.1 5 months ago

README.md

openssl3

The openssl3 package

This is lightly forked from, and should be kept in sync with, CentOS Stream 9's openssl.

Add this as a remote to ease merging changes, e.g.:

git remote add gitlab https://gitlab.com/redhat/centos-stream/rpms/openssl.git

And merge changes

git fetch gitlab
git merge gitlab/c9s