openssl/STATUS

125 lines
4.8 KiB
Text
Raw Normal View History

OpenSSL STATUS Last modified at
2003-02-19 14:02:37 +00:00
______________ $Date: 2003/02/19 14:02:37 $
DEVELOPMENT STATE
2002-06-01 15:33:36 +00:00
o OpenSSL 0.9.8: Under development...
2003-02-19 14:02:37 +00:00
o OpenSSL 0.9.7a: Released on February 19th, 2003
2002-12-30 23:56:09 +00:00
o OpenSSL 0.9.7: Released on December 31st, 2002
2003-02-19 14:02:37 +00:00
o OpenSSL 0.9.6i: Released on February 19th, 2003
o OpenSSL 0.9.6h: Released on December 5th, 2002
2002-08-12 06:54:54 +00:00
o OpenSSL 0.9.6g: Released on August 9th, 2002
2002-08-08 22:55:28 +00:00
o OpenSSL 0.9.6f: Released on August 8th, 2002
2002-07-30 11:32:47 +00:00
o OpenSSL 0.9.6e: Released on July 30th, 2002
2002-05-09 23:54:02 +00:00
o OpenSSL 0.9.6d: Released on May 9th, 2002
2001-12-21 03:23:15 +00:00
o OpenSSL 0.9.6c: Released on December 21st, 2001
o OpenSSL 0.9.6b: Released on July 9th, 2001
2001-04-09 07:15:16 +00:00
o OpenSSL 0.9.6a: Released on April 5th, 2001
2000-09-24 15:42:34 +00:00
o OpenSSL 0.9.6: Released on September 24th, 2000
o OpenSSL 0.9.5a: Released on April 1st, 2000
o OpenSSL 0.9.5: Released on February 28th, 2000
o OpenSSL 0.9.4: Released on August 09th, 1999
o OpenSSL 0.9.3a: Released on May 29th, 1999
o OpenSSL 0.9.3: Released on May 25th, 1999
o OpenSSL 0.9.2b: Released on March 22th, 1999
o OpenSSL 0.9.1c: Released on December 23th, 1998
[See also http://www.openssl.org/support/rt2.html]
2002-05-16 09:28:09 +00:00
RELEASE SHOWSTOPPERS
2002-11-21 22:39:08 +00:00
o [2002-11-21]
PR 343 mentions that scrubbing memory with 'memset(ptr, 0, n)' may
be optimized away in modern compilers. This is definitely not good
and needs to be fixed immediately. The formula to use is presented
in:
http://online.securityfocus.com/archive/82/297918/2002-10-27/2002-11-02/0
The problem report that mentions this is:
https://www.aet.TU-Cottbus.DE/rt2/Ticket/Display.html?id=343
AVAILABLE PATCHES
2001-11-14 21:21:47 +00:00
o
IN PROGRESS
o Steve is currently working on (in no particular order):
2000-07-02 21:11:11 +00:00
ASN1 code redesign, butchery, replacement.
OCSP
EVP cipher enhancement.
Enhanced certificate chain verification.
Private key, certificate and CRL API and implementation.
Developing and bugfixing PKCS#7 (S/MIME code).
Various X509 issues: character sets, certificate request extensions.
o Geoff and Richard are currently working on:
ENGINE (the new code that gives hardware support among others).
o Richard is currently working on:
2001-06-20 15:11:15 +00:00
UI (User Interface)
UTIL (a new set of library functions to support some higher level
functionality that is currently missing).
2000-09-07 08:14:46 +00:00
Shared library support for VMS.
Kerberos 5 authentication (Heimdal)
2000-11-19 14:11:03 +00:00
Constification
2002-12-07 20:03:42 +00:00
Compression
Attribute Certificate support
Certificate Pair support
Storage Engines (primarly an LDAP storage engine)
2002-12-12 19:40:55 +00:00
Certificate chain validation with full RFC 3280 compatibility
NEEDS PATCH
2002-08-14 11:07:29 +00:00
o 0.9.8-dev: COMPLEMENTOFALL and COMPLEMENTOFDEFAULT do not
handle ECCdraft cipher suites correctly.
o apps/ca.c: "Sign the certificate?" - "n" creates empty certificate file
1999-04-08 20:45:53 +00:00
o "OpenSSL STATUS" is never up-to-date.
OPEN ISSUES
o The Makefile hierarchy and build mechanism is still not a round thing:
1. The config vs. Configure scripts
It's the same nasty situation as for Apache with APACI vs.
src/Configure. It confuses.
Suggestion: Merge Configure and config into a single configure
script with a Autoconf style interface ;-) and remove
Configure and config. Or even let us use GNU Autoconf
itself. Then we can avoid a lot of those platform checks
which are currently in Configure.
1998-12-31 12:14:27 +00:00
o Support for Shared Libraries has to be added at least
for the major Unix platforms. The details we can rip from the stuff
Ralf has done for the Apache src/Configure script. Ben wants the
solution to be really simple.
Status: Ralf will look how we can easily incorporate the
compiler PIC and linker DSO flags from Apache
into the OpenSSL Configure script.
Ulf: +1 for using GNU autoconf and libtool (but not automake,
which apparently is not flexible enough to generate
libcrypto)
WISHES
2002-02-09 01:49:53 +00:00
o Add variants of DH_generate_parameters() and BN_generate_prime() [etc?]
where the callback function can request that the function be aborted.
[Gregory Stark <ghstark@pobox.com>, <rayyang2000@yahoo.com>]
2001-06-04 06:51:43 +00:00
o SRP in TLS.
2001-06-04 16:23:15 +00:00
[wished by:
Dj <derek@yo.net>, Tom Wu <tom@arcot.com>,
Tom Holroyd <tomh@po.crl.go.jp>]
2001-06-04 06:51:43 +00:00
See http://search.ietf.org/internet-drafts/draft-ietf-tls-srp-00.txt
as well as http://www-cs-students.stanford.edu/~tjw/srp/.
2001-06-04 16:23:15 +00:00
Tom Holroyd tells us there is a SRP patch for OpenSSH at
http://members.tripod.com/professor_tom/archives/, that could
be useful.