head 1.32; access; symbols pkgsrc-2026Q1:1.32.0.20 pkgsrc-2026Q1-base:1.32 pkgsrc-2025Q4:1.32.0.18 pkgsrc-2025Q4-base:1.32 pkgsrc-2025Q3:1.32.0.16 pkgsrc-2025Q3-base:1.32 pkgsrc-2025Q2:1.32.0.14 pkgsrc-2025Q2-base:1.32 pkgsrc-2025Q1:1.32.0.12 pkgsrc-2025Q1-base:1.32 pkgsrc-2024Q4:1.32.0.10 pkgsrc-2024Q4-base:1.32 pkgsrc-2024Q3:1.32.0.8 pkgsrc-2024Q3-base:1.32 pkgsrc-2024Q2:1.32.0.6 pkgsrc-2024Q2-base:1.32 pkgsrc-2024Q1:1.32.0.4 pkgsrc-2024Q1-base:1.32 pkgsrc-2023Q4:1.32.0.2 pkgsrc-2023Q4-base:1.32 pkgsrc-2023Q3:1.31.0.2 pkgsrc-2023Q3-base:1.31 pkgsrc-2023Q2:1.30.0.34 pkgsrc-2023Q2-base:1.30 pkgsrc-2023Q1:1.30.0.32 pkgsrc-2023Q1-base:1.30 pkgsrc-2022Q4:1.30.0.30 pkgsrc-2022Q4-base:1.30 pkgsrc-2022Q3:1.30.0.28 pkgsrc-2022Q3-base:1.30 pkgsrc-2022Q2:1.30.0.26 pkgsrc-2022Q2-base:1.30 pkgsrc-2022Q1:1.30.0.24 pkgsrc-2022Q1-base:1.30 pkgsrc-2021Q4:1.30.0.22 pkgsrc-2021Q4-base:1.30 pkgsrc-2021Q3:1.30.0.20 pkgsrc-2021Q3-base:1.30 pkgsrc-2021Q2:1.30.0.18 pkgsrc-2021Q2-base:1.30 pkgsrc-2021Q1:1.30.0.16 pkgsrc-2021Q1-base:1.30 pkgsrc-2020Q4:1.30.0.14 pkgsrc-2020Q4-base:1.30 pkgsrc-2020Q3:1.30.0.12 pkgsrc-2020Q3-base:1.30 pkgsrc-2020Q2:1.30.0.10 pkgsrc-2020Q2-base:1.30 pkgsrc-2020Q1:1.30.0.6 pkgsrc-2020Q1-base:1.30 pkgsrc-2019Q4:1.30.0.8 pkgsrc-2019Q4-base:1.30 pkgsrc-2019Q3:1.30.0.4 pkgsrc-2019Q3-base:1.30 pkgsrc-2019Q2:1.30.0.2 pkgsrc-2019Q2-base:1.30 pkgsrc-2019Q1:1.29.0.26 pkgsrc-2019Q1-base:1.29 pkgsrc-2018Q4:1.29.0.24 pkgsrc-2018Q4-base:1.29 pkgsrc-2018Q3:1.29.0.22 pkgsrc-2018Q3-base:1.29 pkgsrc-2018Q2:1.29.0.20 pkgsrc-2018Q2-base:1.29 pkgsrc-2018Q1:1.29.0.18 pkgsrc-2018Q1-base:1.29 pkgsrc-2017Q4:1.29.0.16 pkgsrc-2017Q4-base:1.29 pkgsrc-2017Q3:1.29.0.14 pkgsrc-2017Q3-base:1.29 pkgsrc-2017Q2:1.29.0.10 pkgsrc-2017Q2-base:1.29 pkgsrc-2017Q1:1.29.0.8 pkgsrc-2017Q1-base:1.29 pkgsrc-2016Q4:1.29.0.6 pkgsrc-2016Q4-base:1.29 pkgsrc-2016Q3:1.29.0.4 pkgsrc-2016Q3-base:1.29 pkgsrc-2016Q2:1.29.0.2 pkgsrc-2016Q2-base:1.29 pkgsrc-2016Q1:1.28.0.2 pkgsrc-2016Q1-base:1.28 pkgsrc-2015Q4:1.27.0.4 pkgsrc-2015Q4-base:1.27 pkgsrc-2015Q3:1.27.0.2 pkgsrc-2015Q3-base:1.27 pkgsrc-2015Q2:1.26.0.6 pkgsrc-2015Q2-base:1.26 pkgsrc-2015Q1:1.26.0.4 pkgsrc-2015Q1-base:1.26 pkgsrc-2014Q4:1.26.0.2 pkgsrc-2014Q4-base:1.26 pkgsrc-2014Q3:1.25.0.24 pkgsrc-2014Q3-base:1.25 pkgsrc-2014Q2:1.25.0.22 pkgsrc-2014Q2-base:1.25 pkgsrc-2014Q1:1.25.0.20 pkgsrc-2014Q1-base:1.25 pkgsrc-2013Q4:1.25.0.18 pkgsrc-2013Q4-base:1.25 pkgsrc-2013Q3:1.25.0.16 pkgsrc-2013Q3-base:1.25 pkgsrc-2013Q2:1.25.0.14 pkgsrc-2013Q2-base:1.25 pkgsrc-2013Q1:1.25.0.12 pkgsrc-2013Q1-base:1.25 pkgsrc-2012Q4:1.25.0.10 pkgsrc-2012Q4-base:1.25 pkgsrc-2012Q3:1.25.0.8 pkgsrc-2012Q3-base:1.25 pkgsrc-2012Q2:1.25.0.6 pkgsrc-2012Q2-base:1.25 pkgsrc-2012Q1:1.25.0.4 pkgsrc-2012Q1-base:1.25 pkgsrc-2011Q4:1.25.0.2 pkgsrc-2011Q4-base:1.25 pkgsrc-2011Q3:1.24.0.2 pkgsrc-2011Q3-base:1.24 pkgsrc-2011Q2:1.22.0.10 pkgsrc-2011Q2-base:1.22 pkgsrc-2011Q1:1.22.0.8 pkgsrc-2011Q1-base:1.22 pkgsrc-2010Q4:1.22.0.6 pkgsrc-2010Q4-base:1.22 pkgsrc-2010Q3:1.22.0.4 pkgsrc-2010Q3-base:1.22 pkgsrc-2010Q2:1.22.0.2 pkgsrc-2010Q2-base:1.22 pkgsrc-2010Q1:1.21.0.12 pkgsrc-2010Q1-base:1.21 pkgsrc-2009Q4:1.21.0.10 pkgsrc-2009Q4-base:1.21 pkgsrc-2009Q3:1.21.0.8 pkgsrc-2009Q3-base:1.21 pkgsrc-2009Q2:1.21.0.6 pkgsrc-2009Q2-base:1.21 pkgsrc-2009Q1:1.21.0.4 pkgsrc-2009Q1-base:1.21 pkgsrc-2008Q4:1.21.0.2 pkgsrc-2008Q4-base:1.21 pkgsrc-2008Q3:1.20.0.8 pkgsrc-2008Q3-base:1.20 cube-native-xorg:1.20.0.6 cube-native-xorg-base:1.20 pkgsrc-2008Q2:1.20.0.4 pkgsrc-2008Q2-base:1.20 cwrapper:1.20.0.2 pkgsrc-2008Q1:1.19.0.10 pkgsrc-2008Q1-base:1.19 pkgsrc-2007Q4:1.19.0.8 pkgsrc-2007Q4-base:1.19 pkgsrc-2007Q3:1.19.0.6 pkgsrc-2007Q3-base:1.19 pkgsrc-2007Q2:1.19.0.4 pkgsrc-2007Q2-base:1.19 pkgsrc-2007Q1:1.19.0.2 pkgsrc-2007Q1-base:1.19 pkgsrc-2006Q4:1.18.0.2 pkgsrc-2006Q4-base:1.18 pkgsrc-2006Q3:1.17.0.14 pkgsrc-2006Q3-base:1.17 pkgsrc-2006Q2:1.17.0.12 pkgsrc-2006Q2-base:1.17 pkgsrc-2006Q1:1.17.0.10 pkgsrc-2006Q1-base:1.17 pkgsrc-2005Q4:1.17.0.8 pkgsrc-2005Q4-base:1.17 pkgsrc-2005Q3:1.17.0.6 pkgsrc-2005Q3-base:1.17 pkgsrc-2005Q2:1.17.0.4 pkgsrc-2005Q2-base:1.17 pkgsrc-2005Q1:1.17.0.2 pkgsrc-2005Q1-base:1.17 pkgsrc-2004Q4:1.15.0.8 pkgsrc-2004Q4-base:1.15 pkgsrc-2004Q3:1.15.0.6 pkgsrc-2004Q3-base:1.15 pkgsrc-2004Q2:1.15.0.4 pkgsrc-2004Q2-base:1.15 pkgsrc-2004Q1:1.15.0.2 pkgsrc-2004Q1-base:1.15 pkgsrc-2003Q4:1.14.0.2 pkgsrc-2003Q4-base:1.14 netbsd-1-6-1:1.13.0.2 netbsd-1-6-1-base:1.13 netbsd-1-6:1.12.0.8 netbsd-1-6-RELEASE-base:1.12 pkgviews:1.12.0.4 pkgviews-base:1.12 buildlink2:1.12.0.2 buildlink2-base:1.12 netbsd-1-5-PATCH003:1.12 netbsd-1-5-PATCH001:1.7 netbsd-1-5-RELEASE:1.5 netbsd-1-4-PATCH003:1.5 pkgsrc-base:1.1.1.1 TNF:1.1.1; locks; strict; comment @# @; 1.32 date 2023.11.24.13.32.48; author ryoon; state Exp; branches; next 1.31; commitid 7EnTrIsKNKPyKRNE; 1.31 date 2023.07.09.02.00.53; author taca; state Exp; branches; next 1.30; commitid d0GuvSGnQo0dm4wE; 1.30 date 2019.04.02.14.39.55; author ryoon; state Exp; branches; next 1.29; commitid xv0hzdgfjm7zFMhB; 1.29 date 2016.06.03.23.12.06; author jym; state Exp; branches; next 1.28; commitid kEJIW0gCe4kJH49z; 1.28 date 2015.12.27.18.36.06; author ryoon; state Exp; branches; next 1.27; commitid Rp9pIlGNXU57iCOy; 1.27 date 2015.07.25.03.11.18; author ryoon; state Exp; branches; next 1.26; commitid 09qRJHW6byNJ9Cuy; 1.26 date 2014.11.07.11.30.47; author schmonz; state Exp; branches; next 1.25; commitid gd0jshWAj3eihfXx; 1.25 date 2011.11.10.21.01.39; author ryoon; state Exp; branches; next 1.24; 1.24 date 2011.08.24.17.56.50; author tron; state Exp; branches; next 1.23; 1.23 date 2011.07.11.14.20.24; author ryoon; state Exp; branches; next 1.22; 1.22 date 2010.04.15.09.57.47; author tron; state Exp; branches; next 1.21; 1.21 date 2008.10.17.07.31.58; author adam; state Exp; branches; next 1.20; 1.20 date 2008.05.27.11.51.32; author tnn; state Exp; branches; next 1.19; 1.19 date 2007.01.14.00.07.15; author schmonz; state Exp; branches 1.19.10.1; next 1.18; 1.18 date 2006.10.14.11.12.19; author obache; state Exp; branches; next 1.17; 1.17 date 2005.01.09.13.09.12; author schmonz; state Exp; branches; next 1.16; 1.16 date 2004.12.28.09.09.52; author martti; state Exp; branches; next 1.15; 1.15 date 2004.02.16.11.48.38; author martti; state Exp; branches; next 1.14; 1.14 date 2003.07.29.11.18.42; author jmmv; state Exp; branches; next 1.13; 1.13 date 2003.01.18.08.33.43; author martti; state Exp; branches; next 1.12; 1.12 date 2001.12.28.07.22.30; author tron; state Exp; branches; next 1.11; 1.11 date 2001.11.20.15.15.15; author martti; state Exp; branches; next 1.10; 1.10 date 2001.10.31.10.00.24; author martti; state Exp; branches; next 1.9; 1.9 date 2001.08.19.16.26.08; author martin; state Exp; branches; next 1.8; 1.8 date 2001.08.10.14.41.19; author martin; state Exp; branches; next 1.7; 1.7 date 2001.01.22.13.30.36; author martin; state Exp; branches; next 1.6; 1.6 date 2000.12.19.07.03.22; author jlam; state Exp; branches; next 1.5; 1.5 date 2000.06.17.21.52.18; author tron; state Exp; branches; next 1.4; 1.4 date 2000.04.26.13.00.17; author tron; state Exp; branches; next 1.3; 1.3 date 2000.04.03.17.23.12; author tron; state Exp; branches; next 1.2; 1.2 date 2000.04.03.16.51.17; author tron; state dead; branches; next 1.1; 1.1 date 2000.04.03.09.25.36; author martin; state Exp; branches 1.1.1.1; next ; 1.19.10.1 date 2008.05.27.13.29.03; author rtr; state Exp; branches; next ; 1.1.1.1 date 2000.04.03.09.25.36; author martin; state Exp; branches; next ; desc @@ 1.32 log @stunnel: Update to 5.71 Changelog: ### Version 5.71, 2023.09.19, urgency: MEDIUM * Security bugfixes - OpenSSL DLLs updated to version 3.1.3. * Bugfixes - Fixed the console output of tstunnel.exe. * Features sponsored by SAE IT-systems - OCSP stapling is requested and verified in the client mode. - Using "verifyChain" automatically enables OCSP stapling in the client mode. - OCSP stapling is always available in the server mode. - An inconclusive OCSP verification breaks TLS negotiation. This can be disabled with "OCSPrequire = no". - Added the "TIMEOUTocsp" option to control the maximum time allowed for connecting an OCSP responder. * Features - Added support for Red Hat OpenSSL 3.x patches. @ text @$NetBSD: patch-aa,v 1.31 2023/07/09 02:00:53 taca Exp $ Install configuration files into examples directory. --- tools/Makefile.in.orig 2023-09-19 20:16:29.000000000 +0000 +++ tools/Makefile.in @@@@ -292,7 +292,7 @@@@ EXTRA_DIST = ca.html ca.pl importCA.html stunnel.license stunnel.conf stunnel.conf-sample.in \ stunnel.init.in stunnel.service.in stunnel.logrotate \ stunnel.rh.init stunnel.spec.in ca-certs.pem -confdir = $(sysconfdir)/stunnel +confdir = $(datadir)/examples/stunnel conf_DATA = stunnel.conf-sample examplesdir = $(docdir)/examples examples_DATA = stunnel.init stunnel.service stunnel.logrotate \ @@@@ -506,7 +506,7 @@@@ info: info-am info-am: -install-data-am: install-confDATA install-data-local \ +install-data-am: install-confDATA \ install-dist_bashcompDATA install-examplesDATA install-dvi: install-dvi-am @ 1.31 log @security/stunnel: update to 5.69 Now support OpenSSL 3.0 and stop pkglint's warning. Version 5.69, 2023.03.04, urgency: MEDIUM * New features - Improved logging performance with the "output" option. - Improved file read performance on the WIN32 platform. - DH and kDHEPSK ciphersuites removed from FIPS defaults. - Set the LimitNOFILE ulimit in stunnel.service to allow for up to 10,000 concurrent clients. * Bugfixes - Fixed the "CApath" option on the WIN32 platform by applying https://github.com/openssl/openssl/pull/20312. - Fixed stunnel.spec used for building rpm packages. - Fixed tests on some OSes and architectures by merging Debian 07-tests-errmsg.patch (thx to Peter Pentchev). Version 5.68, 2023.02.07, urgency: HIGH * Security bugfixes - OpenSSL DLLs updated to version 3.0.8. * New features - Added the new 'CAengine' service-level option to load a trusted CA certificate from an engine. - Added requesting client certificates in server mode with 'CApath' besides 'CAfile'. - Improved file read performance. - Improved logging performance. * Bugfixes - Fixed EWOULDBLOCK errors in protocol negotiation. - Fixed handling TLS errors in protocol negotiation. - Prevented following fatal TLS alerts with TCP resets. - Improved OpenSSL initialization on WIN32. - Improved testing suite stability. Version 5.67, 2022.11.01, urgency: HIGH * Security bugfixes - OpenSSL DLLs updated to version 3.0.7. * New features - Provided a logging callback to custom engines. * Bugfixes - Fixed "make cert" with OpenSSL older than 3.0. - Fixed the code and the documentation to use conscious language for SNI servers (thx to Clemens Lang). Version 5.66, 2022.09.11, urgency: MEDIUM * New features - OpenSSL 3.0 FIPS Provider support for Windows. * Bugfixes - Fixed building on machines without pkg-config. - Added the missing "environ" declaration for BSD-based operating systems. - Fixed the passphrase dialog with OpenSSL 3.0. Version 5.65, 2022.07.17, urgency: HIGH * Security bugfixes - OpenSSL DLLs updated to version 3.0.5. * Bugfixes - Fixed handling globally enabled FIPS. - Fixed openssl.cnf processing in WIN32 GUI. - Fixed a number of compiler warnings. - Fixed tests on older versions of OpenSSL. Version 5.64, 2022.05.06, urgency: MEDIUM * Security bugfixes - OpenSSL DLLs updated to version 3.0.3. * New features - Updated the pkcs11 engine for Windows. * Bugfixes - Removed the SERVICE_INTERACTIVE_PROCESS flag in "stunnel -install". Version 5.63, 2022.03.15, urgency: HIGH * Security bugfixes - OpenSSL DLLs updated to version 3.0.2. * New features - Updated stunnel.spec to support bash completion. * Bugfixes - Fixed a PRNG initialization crash (thx to Gleydson Soares). Version 5.62, 2022.01.17, urgency: MEDIUM * New features - Added a bash completion script. * Bugfixes - Fixed a transfer() loop bug. Version 5.61, 2021.12.22, urgency: LOW * New features sponsored by the University of Maryland - Added new "protocol = capwin" and "protocol = capwinctrl" configuration file options. * New features for the Windows platform - Added client mode allowing authenticated users to view logs, reconfigure and terminate running stunnel services. - Added support for multiple GUI and service instances distinguised by the location of stunnel.conf. - Improved log window scrolling. - Added a new 'Pause auto-scroll' GUI checkbox. - Double click on the icon tray replaced with single click. - OpenSSL DLLs updated to version 3.0.1. * Other new features - Rewritten the testing framework in python (thx to Peter Pentchev for inspiration and initial framework). - Added support for missing SSL_set_options() values. - Updated stunnel.spec to support RHEL8. * Bugfixes - Fixed OpenSSL 3.0 build. - Fixed reloading configuration with "systemctl reload stunnel.service". - Fixed incorrect messages logged for OpenSSL errors. - Fixed printing IPv6 socket option defaults on FreeBSD. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.30 2019/04/02 14:39:55 ryoon Exp $ d5 1 a5 1 --- tools/Makefile.in.orig 2023-02-07 19:03:08.000000000 +0000 d10 1 a10 1 stunnel.rh.init stunnel.spec ca-certs.pem d16 1 a16 1 @@@@ -505,7 +505,7 @@@@ info: info-am @ 1.30 log @Update to 5.50 Changelog: Version 5.50, 2018.12.02, urgency: MEDIUM * New features - 32-bit Windows builds replaced with 64-bit builds. - OpenSSL DLLs updated to version 1.1.1. - Check whether "output" is not a relative file name. - Major code cleanup in the configuration file parser. - Added sslVersion, sslVersionMin and sslVersionMax for OpenSSL 1.1.0 and later. * Bugfixes - Fixed PSK session resumption with TLS 1.3. - Fixed a memory leak in WIN32 logging subsystem. - Allow for zero value (ignored) TLS options. - Partially refactored configuration file parsing and logging subsystems for clearer code and minor bugfixes. * Caveats - We removed FIPS support from our standard builds. FIPS will still be available with bespoke builds. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.29 2016/06/03 23:12:06 jym Exp $ d5 1 a5 1 --- tools/Makefile.in.orig 2018-11-09 15:53:56.000000000 +0000 d7 4 a10 4 @@@@ -283,7 +283,7 @@@@ EXTRA_DIST = ca.html ca.pl importCA.html stunnel.conf stunnel.conf-sample.in stunnel.init.in \ stunnel.service.in stunnel.logrotate stunnel.rh.init \ stunnel.spec plugins ca-certs.pem d16 1 a16 1 @@@@ -472,7 +472,7 @@@@ info: info-am d22 1 a22 1 install-examplesDATA @ 1.29 log @Update to 5.32. Changelog: Version 5.32, 2016.05.03, urgency: HIGH * Security bugfixes - OpenSSL DLLs updated to version 1.0.2h. https://www.openssl.org/news/secadv_20160503.txt * New features - New "socket = a:IPV6_V6ONLY=yes" option to only bind IPv6. - Memory leak detection. - Improved compatibility with the current OpenSSL 1.1.0-dev tree. - Added/fixed Red Hat scripts (thx to Andrew Colin Kissa). * Bugfixes - Workaround for a WinCE sockets quirk (thx to Richard Kraemer). - Fixed data alignment on 64-bit MSVC (thx to Yuris W. Auzins). @ text @d1 1 a1 1 $NetBSD$ d5 1 a5 1 --- tools/Makefile.in.orig 2016-05-03 18:35:48.000000000 +0000 d7 1 a7 1 @@@@ -276,7 +276,7 @@@@ EXTRA_DIST = ca.html ca.pl importCA.html d10 1 a10 1 stunnel.spec d16 1 a16 1 @@@@ -466,7 +466,7 @@@@ info: info-am @ 1.28 log @Update to 5.28 Changelog: Version 5.28, 2015.12.11, urgency: HIGH * New features - Build matrix (.travis.yml) extended with ./configure options. - mingw.mak updated to build tstunnel.exe (thx to Jose Alf.). * Bugfixes - Fixed incomplete initialization. - Fixed UCONTEXT threading on OSX. - Fixed exit codes for information requests (as in "stunnel -version" or "stunnel -help"). Version 5.27, 2015.12.03, urgency: MEDIUM * Security bugfixes - OpenSSL DLLs updated to version 1.0.2e. https://www.openssl.org/news/secadv_20151203.txt * New features - Automated build testing configured with .travis.yml. - Added reading server certificates from hardware engines. For example: cert = id_45 - Only attempt to use potentially harmful compiler or linker options if gcc was detected. - /opt/csw added to the OpenSSL directory lookup list. - mingw.mak updates (thx to Jose Alf.). - TODO list updated. Version 5.26, 2015.11.06, urgency: MEDIUM * Bugfixes - Compilation fixes for OSX, *BSD and Solaris. Version 5.25, 2015.11.02, urgency: MEDIUM * New features - SMTP client protocol negotiation support for "protocolUsername", "protocolPassword", and "protocolAuthentication" (thx to Douglas Harris). - New service-level option "config" to specify configuration commands introduced in OpenSSL 1.0.2 (thx to Stephen Wall). - The global option "foreground" now also accepts "quiet" parameter, which does not enable logging to stderr. - Manual page updated. - Obsolete OpenSSL engines removed from the Windows build: 4758cca, aep, atalla, cswift, nuron, sureware. - Improved compatibility with the current OpenSSL 1.1.0-dev tree: gracefully handle symbols renamed from SSLeay* to OpenSSL*. * Bugfixes - Fixed the "s_poll_wait returned 1, but no descriptor is ready" internal error. - Fixed "exec" hangs due to incorrect thread-local storage handling (thx to Philip Craig). - Fixed PRNG initialization (thx to Philip Craig). - Setting socket options no longer performed on PTYs. - Fixed 64-bit Windows build. Version 5.24, 2015.10.08, urgency: MEDIUM * New features - Custom CRL verification was replaced with the internal OpenSSL functionality. - *BSD support for "transparent = destination" and client-side "protocol = socks". This feature should work at least on FreeBSD, OpenBSD and OS X. - Added a new "protocolDomain" option for the NTLM authentication (thx to Andreas Botsikas). - Improved compatibility of the NTLM phase 1 message (thx to Andreas Botsikas). - "setuid" and "setgid" options are now also available in service sections. They can be used to set owner and group of the Unix socket specified with "accept". - Added support for the new OpenSSL 1.0.2 SSL options. - Added OPENSSL_NO_EGD support (thx to Bernard Spil). - VC autodetection added to makew32.bat (thx to Andreas Botsikas). * Bugfixes - Fixed the RESOLVE [F0] TOR extension support in SOCKS5. - Fixed the error code reported on the failed bind() requests. - Fixed the sequential log id with the FORK threading. - Restored the missing Microsoft.VC90.CRT.manifest file. Version 5.23, 2015.09.02, urgency: LOW * New features - Client-side support for the SOCKS protocol. See https://www.stunnel.org/socksvpn.html for details. - Reject SOCKS requests to connect loopback addresses. - New service-level option "OCSPnonce". The default value is "OCSPnonce = no". - Win32 directory structure rearranged. The installer script provides automatic migration for common setups. - Added Win32 installer option to install stunnel for the current user only. This feature does not deploy the NT service, but it also does not require aministrative privileges to install and configure stunnel. - stunnel.cnf was renamed to openssl.cnf in order to to prevent users from mixing it up with stunnel.conf. - Win32 desktop is automatically refreshed when the icon is created or removed. - The ca-certs.pem file is now updated on stunnel upgrade. - Inactive ports were removed from the PORTS file. - Added IPv6 support to the transparent proxy code. * Bugfixes - Compilation fix for OpenSSL version older than 1.0.0. - Compilation fix for mingw. Version 5.22, 2015.07.30, urgency: HIGH * New features - "OCSPaia = yes" added to the configuration file templates. - Improved double free detection. * Bugfixes - Fixed a number of OCSP bugs. The most severe of those bugs caused stunnel to treat OCSP responses that failed OCSP_basic_verify() checks as if they were successful. - Fixed the passive IPv6 resolver (broken in stunnel 5.21). Version 5.21, 2015.07.27, urgency: MEDIUM * New features - Signal names are displayed instead of numbers. - First resolve IPv4 addresses on passive resolver requests. This speeds up stunnel startup on Win32 with a slow/defunct DNS service. - The "make check" target was modified to only build Win32 executables when stunnel is built from a git repository (thx to Peter Pentchev). - More elaborate descriptions were added to the warning about using "verify = 2" without "checkHost" or "checkIP". - Performance optimization was performed on the debug code. * Bugfixes - Fixed the FORK and UCONTEXT threading support. - Fixed "failover=prio" (broken since stunnel 5.15). - Added a retry when sleep(3) was interrupted by a signal in the cron thread scheduler. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.27 2015/07/25 03:11:18 ryoon Exp $ d5 1 a5 1 --- tools/Makefile.in.orig 2015-12-08 15:59:03.000000000 +0000 d7 4 a10 4 @@@@ -275,7 +275,7 @@@@ EXTRA_DIST = ca.html ca.pl importCA.html stunnel.spec openssl.cnf stunnel.nsi stunnel.license stunnel.conf \ stunnel.conf-sample.in stunnel.init.in stunnel.service.in d15 2 a16 2 examples_DATA = stunnel.spec stunnel.init stunnel.service ca.html \ @@@@ -464,7 +464,7 @@@@ info: info-am @ 1.27 log @Update to 5.20 Changelog: Version 5.20, 2015.07.09, urgency: HIGH * Security bugfixes - OpenSSL DLLs updated to version 1.0.2d. https://www.openssl.org/news/secadv_20150709.txt * New features - poll(2) re-enabled on MacOS X 10.5 and later. - Xcode SDK is automatically used on MacOS X if no other locally installed OpenSSL directory is found. - The SSL library detection algorithm was made a bit smarter. - Warnings about insecure authentication were modified to include the name of the affected service section. - A warning was added to stunnel.init if no pid file was specified in the configuration file (thx to Peter Pentchev). - Optional debugging symbols are included in the Win32 installer. - Documentation updates (closes Debian bug #781669). * Bugfixes - Signal pipe reinitialization added to prevent turning the main accepting thread into a busy wait loop when an external condition breaks the signal pipe. This bug was found to surface on Win32, but other platforms may also be affected. - Fixed removing the disabled taskbar icon. - Generated temporary DH parameters are used for configuration reload instead of the static defaults. - LSB compatibility fixes added to the stunnel.init script (thx to Peter Pentchev). - Fixed the manual page headers (thx to Gleydson Soares). Version 5.19, 2015.06.16, urgency: MEDIUM: * New features - OpenSSL DLLs updated to version 1.0.2c. - Added a runtime check whether COMP_zlib() method is implemented in order to improve compatibility with the Debian OpenSSL build. * Bugfixes - Improved socket error handling. - Cron thread priority on Win32 platform changed to THREAD_PRIORITY_LOWEST to improve portability. - Makefile bugfixes for stunnel 5.18 regressions. - Fixed some typos in docs and scripts (thx to Peter Pentchev). - Fixed a log level check condition (thx to Peter Pentchev). Version 5.18, 2015.06.12, urgency: MEDIUM: * New features - OpenSSL DLLs updated to version 1.0.2b. https://www.openssl.org/news/secadv_20150611.txt - Added "include" configuration file option to include all configuration file parts located in a specified directory. - Log file is reopened every 24 hours. With "log = overwrite" this feature can be used to prevent filling up disk space. - Temporary DH parameters are refreshed every 24 hours, unless static DH parameters were provided in the certificate file. - Unique initial DH parameters are distributed with each release. - Warnings are logged on potentially insecure authentication. - Improved compatibility with the current OpenSSL 1.1.0-dev tree: removed RLE compression support, etc. - Updated stunnel.spec (thx to Bill Quayle). * Bugfixes - Fixed handling of dynamic connect targets. - Fixed handling of trailing whitespaces in the Content-Length header of the NTLM authentication. - Fixed --sysconfdir and --localstatedir handling (thx to Dagobert Michelsen). @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.26 2014/11/07 11:30:47 schmonz Exp $ d5 1 a5 1 --- tools/Makefile.in.orig 2015-07-03 12:08:23.000000000 +0000 d7 2 a8 2 @@@@ -273,7 +273,7 @@@@ EXTRA_DIST = ca.html ca.pl importCA.html stunnel.spec stunnel.cnf stunnel.nsi stunnel.license stunnel.conf \ d16 1 a16 1 @@@@ -463,7 +463,7 @@@@ info: info-am @ 1.26 log @Update to 5.07. From the changelog: Version 5.07, 2014.11.01, urgency: MEDIUM: * New features - Several SMTP server protocol negotiation improvements. - Added UTF-8 byte order marks to stunnel.conf templates. - DH parameters are no longer generated by "make cert". The hardcoded DH parameters are sufficiently secure, and modern TLS implementations will use ECDH anyway. - Updated manual for the "options" configuration file option. - Added support for systemd 209 or later. - New --disable-systemd ./configure option. - setuid/setgid commented out in stunnel.conf-sample. * Bugfixes - Added support for UTF-8 byte order mark in stunnel.conf. - Compilation fix for OpenSSL with disabled SSLv2 or SSLv3. - Non-blocking mode set on inetd and systemd descriptors. - shfolder.h replaced with shlobj.h for compatibility with modern Microsoft compilers. Version 5.06, 2014.10.15, urgency: HIGH: * Security bugfixes - OpenSSL DLLs updated to version 1.0.1j. https://www.openssl.org/news/secadv_20141015.txt - The insecure SSLv2 protocol is now disabled by default. It can be enabled with "options = -NO_SSLv2". - The insecure SSLv3 protocol is now disabled by default. It can be enabled with "options = -NO_SSLv3". - Default sslVersion changed to "all" (also in FIPS mode) to autonegotiate the highest supported TLS version. * New features - Added missing SSL options to match OpenSSL 1.0.1j. - New "-options" commandline option to display the list of supported SSL options. * Bugfixes - Fixed FORK threading build regression bug. - Fixed missing periodic Win32 GUI log updates. Version 5.05, 2014.10.10, urgency: MEDIUM: * New features - Asynchronous communication with the GUI thread for faster logging on Win32. - systemd socket activation (thx to Mark Theunissen). - The parameter of "options" can now be prefixed with "-" to clear an SSL option, for example: "options = -LEGACY_SERVER_CONNECT". - Improved "transparent = destination" manual page (thx to Vadim Penzin). * Bugfixes - Fixed POLLIN|POLLHUP condition handling error resulting in prematurely closed (truncated) connection. - Fixed a null pointer dereference regression bug in the "transparent = destination" functionality (thx to Vadim Penzin). This bug was introduced in stunnel 5.00. - Fixed startup thread synchronization with Win32 GUI. - Fixed erroneously closed stdin/stdout/stderr if specified as the -fd commandline option parameter. - A number of minor Win32 GUI bugfixes and improvements. - Merged most of the Windows CE patches (thx to Pierre Delaage). - Fixed incorrect CreateService() error message on Win32. - Implemented a workaround for defective Cygwin file descriptor passing breaking the libwrap support: http://wiki.osdev.org/Cygwin_Issues#Passing_file_descriptors Version 5.04, 2014.09.21, urgency: LOW: * New features - Support for local mode ("exec" option) on Win32. - Support for UTF-8 config file and log file. - Win32 UTF-16 build (thx to Pierre Delaage for support). - Support for Unicode file names on Win32. - A more explicit service description provided for the Windows SCM (thx to Pierre Delaage). - TCP/IP dependency added for NT service in order to prevent initialization failure at boot time. - FIPS canister updated to version 2.0.8 in the Win32 binary build. * Bugfixes - load_icon_default() modified to return copies of default icons instead of the original resources to prevent the resources from being destroyed. - Partially merged Windows CE patches (thx to Pierre Delaage). - Fixed typos in stunnel.init.in and vc.mak. - Fixed incorrect memory allocation statistics update in str_realloc(). - Missing REMOTE_PORT environmental variable is provided to processes spawned with "exec" on Unix platforms. - Taskbar icon is no longer disabled for NT service. - Fixed taskbar icon initialization when commandline options are specified. - Reportedly more compatible values used for the dwDesiredAccess parameter of the CreateFile() function (thx to Pierre Delaage). - A number of minor Win32 GUI bugfixes and improvements. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.25 2011/11/10 21:01:39 ryoon Exp $ d5 1 a5 1 --- tools/Makefile.in.orig 2014-10-23 15:09:25.000000000 +0000 d7 3 a9 3 @@@@ -226,7 +226,7 @@@@ top_srcdir = @@top_srcdir@@ EXTRA_DIST = ca.html ca.pl importCA.html importCA.sh script.sh \ stunnel.spec stunnel.cnf stunnel.nsi stunnel.license stunnel.conf d15 2 a16 2 examples_DATA = ca.html ca.pl importCA.html importCA.sh script.sh \ @@@@ -414,7 +414,7 @@@@ info: info-am @ 1.25 log @Update to 4.46 Changelog: Version 4.46, 2011.11.04, urgency: LOW: * New features - Added Unix socket support (e.g. "connect = /var/run/stunnel/socket"). - Added "verify = 4" mode to ignore CA chain and only verify peer certificate. - Removed the limit of 16 IP addresses for a single 'connect' option. - Removed the limit of 256 stunnel.conf sections in PTHREAD threading model. It is still not possible have more than 63 sections on WIN32 platform. http://msdn.microsoft.com/en-us/library/windows/desktop/ms740141(v=vs.85).aspx * Optimizations - Reduced per-connection memory usage. - Performed a major refactoring of internal data structures. Extensive internal testing was performed, but some regression bugs are expected. * Bugfixes - Fixed WIN32 compilation with Mingw32. - Fixed non-blocking API emulation layer in UCONTEXT threading model. - Fixed signal handling in UCONTEXT threading model. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.24 2011/08/24 17:56:50 tron Exp $ d5 1 a5 1 --- tools/Makefile.in.orig 2011-10-27 14:53:32.000000000 +0000 d7 1 a7 1 @@@@ -196,7 +196,7 @@@@ top_srcdir = @@top_srcdir@@ d16 1 a16 1 @@@@ -377,7 +377,7 @@@@ info: info-am @ 1.24 log @Update "stunnel" package to version 4.42. Changes since version 4.39: - New features - New verify level 0 to request and ignore peer certificate. This feature is useful with the new Windows GUI menu to save cached peer certificate chains, as SSL client certificates are not sent by default. - Manual page has been updated. - Removed support for changing Windows Service name with "service" option. - Hardcoded 2048-bit DH parameters are used as a fallback if DH parameters are not provided in stunnel.pem. - Default "ciphers" value updated to prefer ECDH: "ALL:!SSLv2:!aNULL:!EXP:!LOW:-MEDIUM:RC4:+HIGH". - Default ECDH curve updated to "prime256v1". - Removed support for temporary RSA keys (used in obsolete export ciphers). - Bugfixes - The -quiet commandline option was applied to *all* message boxes. - Silent install (/S option) no longer attempts to create stunnel.pem. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.23 2011/07/11 14:20:24 ryoon Exp $ d5 3 a7 3 --- tools/Makefile.in.orig 2011-08-17 12:15:27.000000000 +0100 +++ tools/Makefile.in 2011-08-24 18:46:44.000000000 +0100 @@@@ -192,7 +192,7 @@@@ d16 1 a16 1 @@@@ -373,7 +373,7 @@@@ @ 1.23 log @Update to 4.39 Version 4.39, 2011.07.06, urgency: LOW: New features New Win32 installer module to build self-signed stunnel.pem. Added configuration file editing with Windows GUI. Added log file reopening file editing with Windows GUI. It might be useful to also implement log file rotation. Improved configuration file reload with Windows GUI. Version 4.38, 2011.06.28, urgency: MEDIUM: New features Server-side SNI implemented (RFC 3546 section 3.1) with a new service-level option "nsi". "socket" option also accepts "yes" and "no" for flags. Nagle's algorithm is now disabled by default for improved interactivity. Bugfixes A compilation fix was added for OpenSSL version < 1.0.0. Signal pipe set to non-blocking mode. This bug caused hangs of stunnel features based on signals, e.g. local mode, FORK threading, or configuration file reload on Unix. Win32 platform was not affected. Version 4.37, 2011.06.17, urgency: MEDIUM: New features Client-side SNI implemented (RFC 3546 section 3.1). Default "ciphers" changed from the OpenSSL default to a more secure and faster "RC4-MD5:HIGH:!aNULL:!SSLv2". A paranoid (and usually slower) setting would be "HIGH:!aNULL:!SSLv2". Recommended "options = NO_SSLv2" added to the sample stunnel.conf file. Default client method upgraded from SSLv3 to TLSv1. To connect servers without TLS support use "sslVersion = SSLv3" option. Improved --enable-fips and --disable-fips ./configure option handling. On startup stunnel now compares the compiled version of OpenSSL against the running version of OpenSSL. A warning is logged on mismatch. Bugfixes Non-blocking socket handling in local mode fixed (Debian bug #626856). UCONTEXT threading mode fixed. Removed the use of gcc Thread-Local Storage for improved portability. va_copy macro defined for platforms that do not have it. Fixed "local" option parsing on IPv4 systems. Solaris compilation fix (redefinition of "STR"). Version 4.36, 2011.05.03, urgency: LOW: New features Updated Win32 DLLs for OpenSSL 1.0.0d. Dynamic memory management for strings manipulation: no more static STRLEN limit, lower stack footprint. Strict public key comparison added for "verify = 3" certificate checking mode (thx to Philipp Hartwig). Backlog parameter of listen(2) changed from 5 to SOMAXCONN: improved behavior on heavy load. Example tools/stunnel.service file added for systemd service manager. Bugfixes Missing pthread_attr_destroy() added to fix memory leak (thx to Paul Allex and Peter Pentchev). Fixed the incorrect way of setting FD_CLOEXEC flag. Fixed --enable-libwrap option of ./configure script. /opt/local added to OpenSSL search path for MacPorts compatibility. Workaround implemented for signal handling on MacOS X. A trivial bug fixed in the stunnel.init script. Retry implemented on EAI_AGAIN error returned by resolver calls. Version 4.35, 2011.02.05, urgency: LOW: New features Updated Win32 DLLs for OpenSSL 1.0.0c. Transparent source (non-local bind) added for FreeBSD 8.x. Transparent destination ("transparent = destination") added for Linux. Bugfixes Fixed reload of FIPS-enabled stunnel. Compiler options are now auto-detected by ./configure script in order to support obsolete versions of gcc. Async-signal-unsafe s_log() removed from SIGTERM/SIGQUIT/SIGINT handler. CLOEXEC file descriptor leaks fixed on Linux >= 2.6.28 with glibc >= 2.10. Irreparable race condition leaks remain on other Unix platforms. This issue may have security implications on some deployments: http://udrepper.livejournal.com/20407.html Directory lib64 included in the OpenSSL library search path. Windows CE compilation fixes (thx to Pierre Delaage). Deprecated RSA_generate_key() replaced with RSA_generate_key_ex(). Domain name changes (courtesy of Bri Hatch) http://stunnel.mirt.net/ --> http://www.stunnel.org/ ftp://stunnel.mirt.net/ --> http://ftp.stunnel.org/ stunnel.mirt.net::stunnel --> rsync.stunnel.org::stunnel stunnel-users@@mirt.net --> stunnel-users@@stunnel.org stunnel-announce@@mirt.net --> stunnel-announce@@stunnel.org Version 4.34, 2010.09.19, urgency: LOW: New features Updated Win32 DLLs for OpenSSL 1.0.0a. Updated Win32 DLLs for zlib 1.2.5. Updated automake to version 1.11.1 Updated libtool to version 2.2.6b Added ECC support with a new service-level "curve" option. DH support is now enabled by default. Added support for OpenSSL builds with some algorithms disabled. ./configure modified to support cross-compilation. Sample stunnel.init updated based on Debian init script. Bugfixes Implemented fixes in user interface to enter engine PIN. Fixed a transfer() loop issue on socket errors. Fixed missing WIN32 taskbar icon while displaying a global option error. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.22 2010/04/15 09:57:47 tron Exp $ d3 5 a7 3 --- tools/Makefile.in.orig 2011-05-02 22:14:27.000000000 +0000 +++ tools/Makefile.in @@@@ -192,7 +192,7 @@@@ top_srcdir = @@top_srcdir@@ d9 1 a9 1 stunnel.spec stunnel.cnf stunnel.nsi stunnel.conf d16 1 a16 1 @@@@ -373,7 +373,7 @@@@ info: info-am @ 1.22 log @Update "stunnel" package to version 4.33. Changes since 4.29: - New features - New service-level "libwrap" option for run-time control whether /etc/hosts.allow and /etc/hosts.deny are used for access control. Disabling libwrap significantly increases performance of stunnel. - Log file reopen on USR1 signal was added. - Graceful configuration reload with HUP signal on Unix and with GUI on Windows. - Bugfixes - Inetd mode fixed - Fixed a transfer() loop issue with SSLv2 connections. - Fixed a "setsockopt IP_TRANSPARENT" warning with "local" option. - Logging subsystem bugfixes and cleanup. - Installer bugfixes for Vista and later versions of Windows. - FIPS mode can be enabled/disabled at runtime. @ text @d1 1 a1 1 $NetBSD$ d3 3 a5 3 --- tools/Makefile.in.orig 2010-03-31 10:45:09.000000000 +0100 +++ tools/Makefile.in 2010-04-15 10:43:07.000000000 +0100 @@@@ -169,7 +169,7 @@@@ d14 1 a14 1 @@@@ -334,7 +334,7 @@@@ @ 1.21 log @Changes 4.26: * libwrap related fixes, better debugging messages, MS Visual C++ support Changes 4.25: * delay libwrap process spawning after dropping privs, other improvements @ text @d3 3 a5 3 --- tools/Makefile.in.orig 2008-09-20 22:32:29.000000000 +0200 +++ tools/Makefile.in @@@@ -167,7 +167,7 @@@@ target_alias = @@target_alias@@ d14 1 a14 1 @@@@ -337,7 +337,7 @@@@ info: info-am d22 1 a22 1 install-exec-am: @ 1.20 log @Update to stunnel-4.24. 4.24: fix security problem (properly reject revoked certs) 4.23: WinNT bugfix 4.22: - A new global option to control logging to syslog. Simultaneous logging to a file and the syslog is now possible. - A new service level option to control stack size. - Restored chroot() to be executed after decoding numerical userid and groupid values in drop_privileges(). - A few bugs fixed the in the new libwrap support code. - TLSv1 method used by default in FIPS mode instead of SSLv3 client and SSLv23 server methods. 4.21: - Initial FIPS 140-2 support (see INSTALL.FIPS for details). - Experimental fast support for non-MT-safe libwrap is provided with pre-spawned processes. - Stunnel binary moved from /usr/local/sbin to /usr/local/bin in order to meet FHS and LSB requirements. - Added code to disallow compiling stunnel with pthreads when OpenSSL is compiled without threads support. - Minor manual update. - TODO file updated. - Dynamic locking callbacks added (needed by some engines to work). - AC_ARG_ENABLE fixed in configure.am to accept yes/no arguments. - On some systems libwrap requires yp_get_default_domain from libnsl, additional checking for libnsl was added to the ./configure script. - Sending a list of trusted CAs for the client to choose the right certificate restored. - Some compatibility issues with NTLM authentication fixed. @ text @d3 1 a3 1 --- tools/Makefile.in.orig 2008-05-18 13:46:07.000000000 +0200 d7 1 a7 1 stunnel.spec stunnel.mak stunnel.cnf stunnel.nsi stunnel.conf @ 1.19 log @Update to 4.20. From the changelog: Version 4.20, 2006.11.30, urgency: MEDIUM: * Release notes - The new transfer() function has been well tested. I recommend upgrading any previous version with this one. * Bugfixes - Fixed support for encrypted passphases (broken in 4.19). - Reduced amount of debug logs. - A minor man page update. Version 4.19, 2006.11.11, urgency: LOW/EXPERIMENTAL: * Release notes - There are a lot of new features in this version. I recommend to test it well before upgrading your mission-critical systems. * New features - New service-level option to specify OCSP server flag: OCSPflag = - "protocolCredentials" option changed to "protocolUsername" and "protocolPassword" - NTLM support to be enabled with the new service-level option: protocolAuthentication = NTLM - imap protocol negotiation support added. - Passphrase cache was added so the user does not need to reenter the same passphrase for each defined service any more. - New service-level option to retry connect+exec section: retry = yes|no - Local IP and port is logged for each established connection. - Win32 DLLs for OpenSSL 0.9.8d. * Bugfixes - Serious problem with SSL_WANT_* retries fixed. The new code requires extensive testing! Version 4.18, 2006.09.26, urgency: MEDIUM: * Bugfixes - GPF on entering private key pass phrase on Win32 fixed. - Updated OpenSSL Win32 DLLs. - Minor configure script update. Version 4.17, 2006.09.10, urgency: MEDIUM: * New features - Win32 DLLs for OpenSSL 0.9.8c. * Bugfixes - Problem with detecting getaddrinfo() in ./configure fixed. - Compilation problem due to misplaced #endif in ssl.c fixed. - Duplicate 220 in smtp_server() function in protocol.c fixed. - Minor os2.mak update. - Minor update of safestring()/safename() macros. Version 4.16, 2006.08.31, urgency: MEDIUM: * New features sponsored by Hewlett-Packard - A new global option to control engine: engineCtrl = [:] - A new service-level option to select engine to read private key: engineNum = - OCSP support: ocsp = * New features - A new option to select version of SSL protocol: sslVersion = all|SSLv2|SSLv3|TLSv1 - Visual Studio vc.mak by David Gillingham . - OS2 support by Paul Smedley (http://smedley.info) * Bugfixes - An ordinary user can install stunnel again. - Compilation problem with --enable-dh fixed. - Some minor compilation warnings fixed. - Service-level CRL cert store implemented. - GPF on protocol negotiations fixed. - Problem detecting addrinfo() on Tru64 fixed. - Default group is now detected by configure script. - Check for maximum number of defined services added. - OpenSSL_add_all_algorithms() added to SSL initialization. - configure script sections reordered to detect pthread library funcions. - RFC 2487 autdoetection improved. High resolution s_poll_wait() not currently supported by UCONTEXT threading. - More precise description of cert directory file names (thx to Muhammad Muquit). * Other changes - Maximum number of services increased from 64 to 256 when poll() is used. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.18 2006/10/14 11:12:19 obache Exp $ d3 1 a3 1 --- tools/Makefile.in.orig 2006-11-11 09:58:22.000000000 -0500 d5 1 a5 1 @@@@ -161,7 +161,7 @@@@ target_alias = @@target_alias@@ a11 1 docdir = $(datadir)/doc/stunnel d13 2 a14 1 @@@@ -332,7 +332,7 @@@@ info: info-am @ 1.19.10.1 log @pullup ticket #2400 - requested by tnn stunnel: update package due to security issue revisions pulled up: - pkgsrc/security/stunnel/MESSAGE 1.1 - pkgsrc/security/stunnel/Makefile 1.62 - pkgsrc/security/stunnel/PLIST 1.10 - pkgsrc/security/stunnel/distinfo 1.24 - pkgsrc/security/stunnel/files/stunnel.sh 1.2 - pkgsrc/security/stunnel/patches/patch-aa 1.20 - pkgsrc/security/stunnel/patches/patch-ac r0 Module Name: pkgsrc Committed By: tnn Date: Tue May 27 11:51:32 UTC 2008 Modified Files: pkgsrc/security/stunnel: Makefile PLIST distinfo pkgsrc/security/stunnel/files: stunnel.sh pkgsrc/security/stunnel/patches: patch-aa Added Files: pkgsrc/security/stunnel: MESSAGE Removed Files: pkgsrc/security/stunnel/patches: patch-ac Log Message: Update to stunnel-4.24. 4.24: fix security problem (properly reject revoked certs) 4.23: WinNT bugfix 4.22: - A new global option to control logging to syslog. Simultaneous logging to a file and the syslog is now possible. - A new service level option to control stack size. - Restored chroot() to be executed after decoding numerical userid and groupid values in drop_privileges(). - A few bugs fixed the in the new libwrap support code. - TLSv1 method used by default in FIPS mode instead of SSLv3 client and SSLv23 server methods. 4.21: - Initial FIPS 140-2 support (see INSTALL.FIPS for details). - Experimental fast support for non-MT-safe libwrap is provided with pre-spawned processes. - Stunnel binary moved from /usr/local/sbin to /usr/local/bin in order to meet FHS and LSB requirements. - Added code to disallow compiling stunnel with pthreads when OpenSSL is compiled without threads support. - Minor manual update. - TODO file updated. - Dynamic locking callbacks added (needed by some engines to work). - AC_ARG_ENABLE fixed in configure.am to accept yes/no arguments. - On some systems libwrap requires yp_get_default_domain from libnsl, additional checking for libnsl was added to the ./configure script. - Sending a list of trusted CAs for the client to choose the right certificate restored. - Some compatibility issues with NTLM authentication fixed. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.19 2007/01/14 00:07:15 schmonz Exp $ d3 1 a3 1 --- tools/Makefile.in.orig 2008-05-18 13:46:07.000000000 +0200 d5 1 a5 1 @@@@ -167,7 +167,7 @@@@ target_alias = @@target_alias@@ d12 1 d14 1 a14 2 examples_DATA = ca.html ca.pl importCA.html importCA.sh script.sh \ @@@@ -337,7 +337,7 @@@@ info: info-am @ 1.18 log @Update stunnel to 4.15. Patch provided by Shaun Amott via PR 34436, take maintainership. And define USE_LIBTOOL, regen patch with mkpatches. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.17 2005/01/09 13:09:12 schmonz Exp $ d3 1 a3 1 --- tools/Makefile.in.orig 2006-03-06 21:02:39.000000000 +0000 d5 1 a5 1 @@@@ -160,7 +160,7 @@@@ target_alias = @@target_alias@@ d14 1 a14 1 @@@@ -331,7 +331,7 @@@@ info: info-am @ 1.17 log @pkgsrc changes: * An "stunnel3" perl script is installed. REPLACE_PERL and add to PLIST. * Regenerate patches to lose fuzz. * Format DESCR. * Bump PKGREVISION. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.16 2004/12/28 09:09:52 martti Exp $ d3 1 a3 1 --- tools/Makefile.in.orig 2004-12-30 06:57:40.000000000 -0500 d5 1 a5 1 @@@@ -162,8 +162,8 @@@@ DISTCLEANFILES = stunnel.pem d7 1 a7 1 stunnel.spec stunnel.mak stunnel.cnf a9 1 -conf_DATA = stunnel.conf-sample stunnel.pem d11 1 a11 1 +conf_DATA = stunnel.conf-sample d14 1 a14 3 examples_DATA = ca.html ca.pl importCA.html importCA.sh script.sh \ @@@@ -399,7 +399,7 @@@@ stunnel.pem: stunnel.cnf -in stunnel.pem d16 1 a16 3 install-data-hook: - chmod 0600 $(DESTDIR)$(confdir)/stunnel.pem + true d18 5 a22 2 clean-local: -rm -f stunnel.rnd @ 1.16 log @Updated stunnel to 4.06 Version 4.06, 2004.12.26, urgency: LOW: * New feature sponsored by SURFnet http://www.surfnet.nl/ - IPv6 support (to be enabled with ./configure --enable-ipv6). * New features - poll() support - no more FD_SETSIZE limit! - Multiple connect=host:port options are allowed in a single service section. Remote hosts are connected using round-robin algorithm. This feature is not compatible with delayed resolver. - New 'compression' option to enable compression. To use zlib algorithm you have to enable it when building OpenSSL library. - New 'engine' option to select a hardware engine. - New 'TIMEOUTconnect' option with 10 seconds default added. - stunnel3 perl script to emulate version 3.x command line options. - French manual updated by Bernard Choppy . - A watchdog to detect transfer() infinite loops added. - Configuration file comment character changed from '#' to ';'. '#' will still be recognized to keep compatibility. - MT-safe getaddrinfo() and getnameinfo() are used where available to get better performance on resolver calls. - Automake upgraded from 1.4-p4 to 1.7.9. * Bugfixes - log() changed to s_log() to avoid conflicts on some systems. - Common CRIT_INET critical section introduced instead of separate CRIT_NTOA and CRIT_RESOLVER to avoid potential problems with libwrap (TCP Wrappers) library. - CreateThread() finally replaced with _beginthread() on Win32. - make install creates $(localstatedir)/stunnel. $(localstatedir)/stunnel/dev/zero is also created on Solaris. - Race condition with client session cache fixed. - Other minor bugfixes. * Release notes - Default is *not* to use IPv6 '::' for accept and '::1' for connect. For example to accept pop3s on IPv6 you could use: 'accept = :::995'. I hope the new syntax is clear enough. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.15 2004/02/16 11:48:38 martti Exp $ d3 5 a7 3 --- tools/Makefile.in.orig 2004-12-26 01:36:52.000000000 +0200 +++ tools/Makefile.in 2004-12-28 12:28:16.000000000 +0200 @@@@ -164,4 +164,4 @@@@ d14 5 a18 1 @@@@ -401,3 +401,3 @@@@ d23 2 @ 1.15 log @Updated stunnel to 4.05 * New feature sponsored by SURFnet http://www.surfnet.nl/ - Support for CIFS aka SMB protocol SSL negotiation. * New features - CRL support with new CApath and CAfile global options. - New 'taskbar' option on WIN32 (thx to Ken Mattsen ). - New -fd command line parameter to read configuration from a specified file descriptor instead of a file. - accept is reported as error with [section] defined (in stunnel 4.04 it was silently ignored causing problems for lusers that did not read the fine manual). - Use fcntl() instead of ioctlsocket() to set socket nonblocking when it is supported. - Basic support for hardware engines with OpenSSL >= 0.9.7. - French manual by Bernard Choppy . - Thread stack size reduced to 64KB for maximum scalability. - Added optional code to debug thread stack usage. - Support for nsr-tandem-nsk (thx to Tom Bates ). * Bugfixes - TCP wrappers code moved to CRIT_NTOA critical section since it uses static inet_ntoa() result buffer. - SSL_ERROR_SYSCALL handling problems fixed. - added code to retry nonblocking SSL_shutdown() calls. - Use FD_SETSIZE instead of 16 file descriptors in inetd mode. - fdscanf groks lowercase protocol negotiation commands. - WIN32 taskbar GDI objects leak fixed. - Libwrap detection bug in ./configure script fixed. - grp.h header detection fixed for NetBSD and possibly other systems. - Some other minor updates. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.14 2003/07/29 11:18:42 jmmv Exp $ d3 3 a5 5 --- tools/Makefile.in.orig 2004-02-14 16:31:34.000000000 +0200 +++ tools/Makefile.in 2004-02-16 13:41:21.000000000 +0200 @@@@ -82,8 +82,8 @@@@ EXTRA_DIST = ca.html ca.pl importCA.html importCA.sh script.sh stunnel.spec stunnel.mak stunnel.cnf a10 1 d12 1 a12 4 examplesdir = $(docdir)/examples @@@@ -251,7 +251,7 @@@@ -in stunnel.pem a16 2 clean-local: -rm -f stunnel.rnd @ 1.14 log @Install example file under the examples hierarchy and honour PKG_SYSCONFDIR. Bump PKGREVISION to 1. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.13 2003/01/18 08:33:43 martti Exp $ d3 4 a6 4 --- tools/Makefile.in.orig 2003-01-12 16:48:39.000000000 +0100 +++ tools/Makefile.in @@@@ -82,8 +82,8 @@@@ DISTCLEANFILES = stunnel.pem EXTRA_DIST = ca.html ca.pl importCA.html importCA.sh stunnel.spec stunnel.mak stunnel.cnf d16 1 a16 1 @@@@ -251,7 +251,7 @@@@ stunnel.pem: stunnel.cnf d20 1 a20 1 - chmod 0600 $(confdir)/stunnel.pem @ 1.13 log @Updated stunnel to 4.04 (upgrade to 4.03 provided by Juan RP in pkg/19310) * New features sponsored by MAXIMUS http://www.maximus.com/ - New 'options' configuration option to setup OpenSSL library hacks with SSL_CTX_set_options(). - 'service' option also changes the name for TCP Wrappers access control in inetd mode. - SSL is negotiated before connecting remote host or spawning local process whenever possible. - REMOTE_HOST variable is always placed in the enrivonment of a process spawned with 'exec'. - Whole SSL error stack is dumped on errors. - Manual page updated (special thanks to Brian Hatch). - New user interface (config file). - Single daemon can listen on multiple ports, now. - Delayed DNS lookup added. * Other new features - All the timeouts are now configurable including TIMEOUTclose that can be set to 0 for MSIE and other buggy clients that do not send close_notify. - Stunnel process can be chrooted in a specified directory. - Numerical values for setuid() and setgid() are allowed, now. - Confusing code for setting certificate defaults introduced in version 3.8p3 was removed to simplify stunnel setup. There are no built-in defaults for CApath and CAfile options. - Private key file for a certificate can be kept in a separate file. Default remains to keep it in the cert file. - Manual page updated. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.12 2001/12/28 07:22:30 tron Exp $ d3 4 a6 3 --- tools/Makefile.in.orig Sun Jan 12 15:48:39 2003 +++ tools/Makefile.in Sat Jan 18 08:08:05 2003 @@@@ -83,7 +83,7 @@@@ d9 1 a9 1 confdir = $(sysconfdir)/stunnel d11 1 d16 1 a16 1 @@@@ -251,7 +251,7 @@@@ @ 1.12 log @Update "stunnel" package to version 3.22. Changes sinc version 3.21c: - Format string bug fixed in protocol.c smtp, pop3 and nntp in client mode were affected. (stunnel clients could be attacked by malicious servers) - Certificate chain can be supplied with -p option or in stunnel.pem. - Problem with -r and -l options used together fixed. - memmove() instead of memcpy() is used to move data in buffers. - More detailed information about negotiated ciphers is printed. - New ./configure options: "--enable-no-rsa" and "--enable-dh". @ text @d1 1 a1 1 $NetBSD$ d3 17 a19 36 --- Makefile.in.orig Sun Dec 23 20:03:25 2001 +++ Makefile.in Fri Dec 28 08:13:29 2001 @@@@ -9,7 +9,7 @@@@ sbindir=@@sbindir@@ libdir=@@libdir@@ man8dir=@@mandir@@/man8 -piddir=@@localstatedir@@/stunnel/ +piddir=/var/run/ ssldir=@@ssldir@@ openssl=$(ssldir)/bin/openssl PEM_DIR=@@PEM_DIR@@ @@@@ -24,7 +24,7 @@@@ LIBS=@@LIBS@@ HEADERS=common.h prototypes.h client.h OBJS=client.o stunnel.o ssl.o protocol.o sthreads.o pty.o log.o options.o -DESTFILES=$(sbindir)/stunnel $(libdir)/stunnel.so $(man8dir)/stunnel.8 $(PEM_DIR)/stunnel.pem +DESTFILES=$(sbindir)/stunnel $(libdir)/stunnel.so $(man8dir)/stunnel.8 WINGCC=i386-mingw32msvc-gcc WINCFLAGS=-O2 -Wall -DUSE_WIN32=1 -DHAVE_OPENSSL=1 -DFD_SETSIZE=4096 -DVERSION=\"@@VERSION@@\" -I../openssl-0.9.6b/outinc @@@@ -33,7 +33,7 @@@@ # standard external rules -all: stunnel stunnel.8 stunnel.html stunnel.so stunnel.pem +all: stunnel stunnel.8 stunnel.html stunnel.so install: all installdirs $(DESTFILES) @@@@ -62,7 +62,6 @@@@ installdirs: mkinstalldirs ./mkinstalldirs $(sbindir) $(libdir) $(man8dir) $(PEM_DIR) $(piddir) - chmod a=rwx,+t $(piddir) # non-standard external rules d21 2 @ 1.11 log @Updated to version 3.21.3 (a.k.a 3.21c). Changelog for version 3.21c, 2001.11.11, urgency: LOW: * autoconf scripts upgraded to version 2.52. * Problem with pthread_sigmask on Darwin fixed (I hope). * Some documentation typos corrected. * Attempt to ignore EINTR in transfer(). * Shared library version reported on startup. * DLLs for OpenSSL 0.9.6b. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.10 2001/10/31 10:00:24 martti Exp $ d3 2 a4 2 --- Makefile.in.orig Sun Nov 11 19:09:51 2001 +++ Makefile.in Tue Nov 20 15:43:00 2001 d12 1 d14 1 a14 2 @@SET_MAKE@@ @@@@ -21,7 +21,7 @@@@ d23 1 a23 1 @@@@ -30,7 +30,7 @@@@ d32 1 a32 1 @@@@ -59,7 +59,6 @@@@ @ 1.10 log @Changelog for version 3.21, 2001.10.31, urgency: MEDIUM: * Problem with errno and posix threads fixed. * It is assumed that system has getopt() if it has getopt.h header file. * SSL_CLIENT_DN and SSL_CLIENT_I_DN environment variables set in local mode (-l) process. This feature doesn't work if client mode (-c) or protocol negotiation (-n) is used. * Winsock error descriptions hardcoded (English version only). * SetConsoleCtrlHandler() used to handle CTRL+C, logoff and shutdown on Win32. * Stunnel always requests peer certificate with -v 0. * sysconf()/getrlimit() used to calculate number of clients allowed. * SSL mode changed for OpenSSL >= 0.9.6. * close-on-exec option used to avoid socket inheriting. * Buffer size increased from 8KB to 16KB. * fdscanf()/fdprintf() changes: - non-blocking socket support, - timeout after 1 minute of inactivity. * auth_user() redesigned to force 1 minute timeout. * Some source arrangement towards 4.x architecture. * No need for "goto" any more. * New Makefile "test" rule. It performs basic test of standalone/inetd, remote/local and server/client mode. * pop3 server mode support added. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.9 2001/08/19 16:26:08 martin Exp $ d3 2 a4 2 --- Makefile.in.orig Tue Oct 30 22:38:38 2001 +++ Makefile.in Wed Oct 31 09:02:39 2001 d22 1 a22 1 WINCFLAGS=-O2 -Wall -DUSE_WIN32=1 -DHAVE_OPENSSL=1 -DFD_SETSIZE=4096 -DVERSION=\"@@VERSION@@\" -I../openssl-0.9.6/outinc @ 1.9 log @Update of stunnel to version 3.20, from Martti Kuparinen in PR pkg/13728. Changelog for version 3.20, 2001.08.15, urgency: LOW: * setsockopt() optlen set according to the optval for Solaris. * Minor NetBSD compatibility fixes by Martti Kuparinen. * Minor MSVC6 compatibility fixes by Patrick Mayweg. * SSL close_notify timeout reduced to 10 seconds of inactivity. * Socket close instead of reset on close_notify timeout. * Some source arrangement and minor bugfixes. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.8 2001/08/10 14:41:19 martin Exp $ d3 2 a4 2 --- Makefile.in.orig Sun Aug 12 21:52:10 2001 +++ Makefile.in Thu Aug 16 09:02:37 2001 d14 1 a14 2 @@@@ -20,7 +20,7 @@@@ CFLAGS=@@CFLAGS@@ @@DEFS@@ -Dlibdir=\"$(libdir)\" -DPIDDIR=\"$(piddir)\" d16 2 a17 1 OBJS=stunnel.o ssl.o client.o protocol.o sthreads.o pty.o log.o options.o d22 2 a23 2 WINCFLAGS=-O2 -Wall -DUSE_WIN32 -DHAVE_OPENSSL -DVERSION=\"@@VERSION@@\" -I../openssl-0.9.6/outinc @@@@ -29,7 +29,7 @@@@ d32 1 a32 1 @@@@ -57,7 +57,6 @@@@ @ 1.8 log @Update stunnel to version 3.19. Based on PR pkg/13679 by Martti Kuparinen. Changelog for version 3.19, 2001.08.10, urgency: MEDIUM: * Critical section added around non MT-safe TCP Wrappers code. * Problem with "select: Interrupted system call" error fixed. * errno replaced with get_last_socket_error() for Win32. * Some FreeBSD/NetBSD patches to ./configure from Martti Kuparinen. * Local mode process pid logged. * Default FQDN (localhost) removed from stunnel.cnf * ./configure changed to recognize POSIX threads library on OSF. * New -O option to set socket options. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.7 2001/01/22 13:30:36 martin Exp $ d3 2 a4 2 --- Makefile.in.orig Mon Aug 6 18:41:24 2001 +++ Makefile.in Fri Aug 10 16:26:56 2001 d17 1 a17 1 OBJS=stunnel.o ssl.o protocol.o sthreads.o pty.o log.o options.o d22 1 a22 1 WINCFLAGS=-O2 -Wall -DUSE_WIN32 -DHAVE_OPENSSL -I../openssl-0.9.6/outinc @ 1.7 log @Update pkg to stunnel-3.11. Fixes key-length and zombies problems. @ text @d1 1 a1 1 $NetBSD$ d3 2 a4 2 --- Makefile.in.orig Tue Dec 19 19:42:46 2000 +++ Makefile.in Mon Jan 22 13:59:59 2001 d17 1 a17 1 OBJS=stunnel.o ssl.o protocol.o sthreads.o pty.o log.o @ 1.6 log @Update stunnel to 3.9. For NetBSD, if in-tree OpenSSL exists, then the default certificate directory is now /etc/openssl/certs (matches OpenSSL's default), but if stunnel uses the pkgsrc OpenSSL, then the default is ${PREFIX}/certs. Changes from version 3.8 include: * Updated temporary key generation: - stunnel is now honoring requested key-lengths correctly, - temporary key is changed every hour. * transfer() no longer hangs on some platforms. Special thanks to Peter Wagemans for the patch. * Potential security problem with syslog() call fixed. * use daemon() function instead of daemonize, if available * added -S flag, allowing you to choose which default verify sources to use * relocated service name output logging until after log_open. (no longer outputs log info to inetd socket, causing bad SSL) * -V flag now outputs the default values used by stunnel * Added rigerous PRNG seeding * PID changes (and related security-fix) * Man page fixes * Client SSL Session-IDs now used * -N flag to specify tcpwrapper service name * UPGRADE NOTE: this version seriously changes several previous stunnel default behaviours. There are no longer any default cert file/dirs compilied into stunnel, you must use the --with-cert-dir and --with-cert-file configure arguments to set these manually, if desired. Stunnel does not use the underlying ssl library defaults by default unless configured with --enable-ssllib-cs. Note that these can always be enabled at run time with the -A,-a, and -S flags. Additionally, unless --with-pem-dir is specified at compile time, stunnel will default to looking for stunnel.pem in the current directory. @ text @d3 2 a4 2 --- Makefile.in.orig Sat Oct 21 10:02:03 2000 +++ Makefile.in d10 1 a10 1 +piddir=/var/run d14 1 a14 1 @@@@ -20,11 +20,11 @@@@ d21 4 d27 2 a28 2 -all: stunnel stunnel.so stunnel.pem +all: stunnel stunnel.so d32 1 a32 1 @@@@ -52,7 +52,6 @@@@ @ 1.5 log @Don't install automatically created certificate. It is useless and will only overwrite a useful one. @ text @d3 3 a5 3 --- Makefile.in.orig Tue Feb 22 13:08:16 2000 +++ Makefile.in Sat Jun 17 23:46:38 2000 @@@@ -7,9 +7,9 @@@@ d9 1 a9 1 -piddir=@@localstatedir@@/stunnel d12 1 a12 2 -certdir=$(ssldir)/certs +certdir=@@prefix@@/certs d14 2 a15 4 VERSION=stunnel-@@VERSION@@ RANDOM_OPT=@@RANDOM_OPT@@ @@@@ -18,7 +18,7 @@@@ CFLAGS=@@CFLAGS@@ @@DEFS@@ -Dcertdir=\"$(certdir)\" -Dlibdir=\"$(libdir)\" -Dpiddir=\"$(piddir)\" d18 1 a18 1 -DESTFILES=$(sbindir)/stunnel $(libdir)/stunnel.so $(man8dir)/stunnel.8 $(certdir)/stunnel.pem d23 6 a28 1 @@@@ -50,7 +50,6 @@@@ d31 1 a31 1 ./mkinstalldirs $(sbindir) $(libdir) $(man8dir) $(certdir) $(piddir) @ 1.4 log @Don't clobber permission of "/var/run" during installation. @ text @d4 1 a4 1 +++ Makefile.in Wed Apr 26 14:59:30 2000 d17 9 @ 1.3 log @Put pid file to "/var/run" and certificates to "${PREFIX}/certs". @ text @d4 1 a4 1 +++ Makefile.in Mon Apr 3 19:18:33 2000 d17 8 @ 1.2 log @Patching "configure" doesn't make any sense if it is overwritten by "autoreconf" later. @ text @d1 1 a1 1 $NetBSD: patch-aa,v 1.1 2000/04/03 09:25:36 martin Exp $ d3 14 a16 30 --- configure.old Thu Feb 24 12:28:45 2000 +++ configure Sat Apr 1 19:39:10 2000 @@@@ -935,19 +935,17 @@@@ checkssldir() { : - if test -d "$1/certs"; then - if test -f "$1/include/openssl/ssl.h"; then - cat >> confdefs.h <<\EOF + if test -f "$1/include/openssl/ssl.h"; then + cat >> confdefs.h <<\EOF #define HAVE_OPENSSL 1 EOF - ssldir="$1" - return 0 - fi - if test -f "$1/include/ssl.h"; then - ssldir="$1" - return 0 - fi + ssldir="$1" + return 0 + fi + if test -f "$1/include/ssl.h"; then + ssldir="$1" + return 0 fi return 1 } @ 1.1 log @Initial revision @ text @d1 1 a1 1 $NetBSD$ @ 1.1.1.1 log @A new pkg for the stunnel program, a tool to wrap existing servers into SSL connections. @ text @@