aboutsummaryrefslogtreecommitdiff
tag namev2.4.4 (2b1b437de878aecb9d3884cf8b1d4a6ebb2139b1)
tag date2017-09-25 22:51:23 +0200
tagged byDavid Sommerseth
tagged objectcommit 1f458322cd...
downloadopenvpn-2.4.4.zip
openvpn-2.4.4.tar.gz
OpenVPN v2.4.4 release
2017.09.25 -- Version 2.4.4 Antonio Quartulli (23): crypto: correct typ0 in error message use M_ERRNO instead of explicitly printing errno don't print errno twice ntlm: avoid useless cast ntlm: unwrap multiple function calls route: improve error message management: preserve wait_for_push field when asking for user/pass tls-crypt: avoid warnings when --disable-crypto is used ntlm: convert binary buffers to uint8_t * ntlm: restyle compressed multiple function calls ntlm: improve code style and readability OpenSSL: remove unreachable call to SSL_CTX_get0_privatekey() make function declarations C99 compliant remove unused functions use NULL instead of 0 when assigning pointers add missing static attribute to functions ntlm: avoid breaking anti-aliasing rules remove the --disable-multi config switch rename mroute_extract_addr_ipv4 to mroute_extract_addr_ip route: avoid definition of unused variables in certain configurations fix a couple of typ0s in comments and strings fragment.c: simplify boolean expression tcp-server: ensure AF family is propagated to child context Arne Schwabe (2): Set tls-cipher restriction before loading certificates Print ec bit details, refuse management-external-key if key is not RSA Conrad Hoffmann (2): Use provided env vars in up/down script. Document down-root plugin usage in client.down David Sommerseth (11): doc: The CRL processing is not a deprecated feature cleanup: Move write_pid() to where it is being used contrib: Remove keychain-mcd code cleanup: Move init_random_seed() to where it is being used sample-plugins: fix ASN1_STRING_to_UTF8 return value checks Highlight deprecated features Use consistent version references docs: Replace all PolarSSL references to mbed TLS systemd: Ensure systemd shuts down OpenVPN in a proper way systemd: Enable systemd's auto-restart feature for server profiles lz4: Move towards a newer LZ4 API Emmanuel Deloget (3): OpenSSL: remove pre-1.1 function from the OpenSSL compat interface OpenSSL: remove EVP_CIPHER_CTX_new() from the compat layer OpenSSL: remove EVP_CIPHER_CTX_free() from the compat layer Gert van Dijk (1): Warn that DH config option is only meaningful in a tls-server context Ilya Shipitsin (3): travis-ci: add 3 missing patches from master to release/2.4 travis-ci: update openssl to 1.0.2l, update mbedtls to 2.5.1 travis-ci: update pkcs11-helper to 1.22 Richard Bonhomme (1): man: Corrections to doc/openvpn.8 Steffan Karger (17): Fix typo in extract_x509_extension() debug message Move adjust_power_of_2() to integer.h Undo cipher push in client options state if cipher is rejected Remove strerror_ts() Move openvpn_sleep() to manage.c fixup: also change missed openvpn_sleep() occurrences Always use default keysize for NCP'd ciphers Move create_temp_file() out of #ifdef ENABLE_CRYPTO Deprecate --keysize Deprecate --no-replay Move run_up_down() to init.c tls-crypt: introduce tls_crypt_kt() crypto: create function to initialize encrypt and decrypt key Add coverity static analysis to Travis CI config tls-crypt: don't leak memory for incorrect tls-crypt messages travis: reorder matrix to speed up build Fix bounds check in read_key() Szilárd Pfeiffer (1): OpenSSL: Always set SSL_OP_CIPHER_SERVER_PREFERENCE flag Thomas Veerman via Openvpn-devel (1): Fix socks_proxy_port pointing to invalid data -----BEGIN PGP SIGNATURE----- Version: GnuPG v2.0.22 (GNU/Linux) iQIcBAABCgAGBQJZyWx7AAoJEIbPlEyWcf3yMpQP/jk2m1az64qeeyu+6Y6hwd9y Q63sAQQmY9doBnyNaLJrNzs/DFNHCqJ1Sp5DUsW+JH1jXfDdiT7wJs2HODMT1XSz eSvd0PTlgl8XXipOFdFP6RBl5Gz+aw3Q4SsRUSt8HgBn++hiw2wGBvUmnWI9qYhn PAxvxrrsoKq6frLFuNBvLJCJWfCHKMu/2jZ8xbKKjFAB/LDtuWXDzBAZ/PvgE/cJ w9dViYgsWwhrl4f80s5/0PtIzN2GavHFjZUAVWPhDKvKZg89ICAeJ6Nt297SIhki PY9yhnd98mLVYWP3SukhT73E3yuBuoJeouGQwFn71fAGII7c+85Qk+moLDaEV6+D 8aBO1LrZE4HoDEHKVJCb/mHey8dlR+nwPWG+pSLzY/9DaD3PBd2SO1TEAdvUt/Gk RXrzXOgJBhqf7fswptEtIRN16OfYfBUrToDEUE99o/3YAZPdMbYGrycOar4KA0tt eln9Plc4yzL/npw7YdExWMV7TC7hjTtp4P8aFiH0RP1uMQ0wagZyb24mPOkycN2b PH7s3R8yXW/F7n73Zth17qg2drXSuw83p1oyZb8R3ozcRzDd657Enf8o/5ZT/TIv MEizCmIRVGYn/Gg85S1/kvgt0xcRZ4+63Tp4kb8KMG5tv5vEEUCivLxn4bzQM1Ov y89N4AVrzR0DcErajV9x =anMC -----END PGP SIGNATURE-----