Skip to content

OpenSSL 2023.02 security updates.#174

Merged
dumol merged 24 commits intocleanup-ssl-subdirfrom
openssl-2023-feb-updates
Feb 15, 2023
Merged

OpenSSL 2023.02 security updates.#174
dumol merged 24 commits intocleanup-ssl-subdirfrom
openssl-2023-feb-updates

Conversation

@dumol
Copy link
Copy Markdown
Contributor

@dumol dumol commented Feb 8, 2023

Scope

Patch latest OpenSSL known vulnerabilities, as published at https://www.openssl.org/news/vulnerabilities.html#y2023.

Changes

Updated OpenSSL 1.1.1s sources to version 1.1.1t.

Can't patch OpenSSL 1.0.2 sources yet, nothing at https://git.centos.org/rpms/openssl/commits/c7 for now…

Drive-by fixes:

How to try and test the changes

reviewers: @adiroiban

No code changes to review, only version numbers are changed in our scripts. And a bit of documentation:

git diff cleanup-ssl-subdir chevah_build python-modules/ src/*/README*

Automatic tests should all pass.

@dumol dumol requested a review from adiroiban February 10, 2023 12:16
@dumol dumol self-assigned this Feb 10, 2023
@dumol
Copy link
Copy Markdown
Contributor Author

dumol commented Feb 10, 2023

As discussed today on #chevah, let's do a release without the OpenSSL 1.0.2 patches.

@adiroiban, beware this is on top of #173 (also a minor PR, not much to review).

Thanks!

@dumol
Copy link
Copy Markdown
Contributor Author

dumol commented Feb 14, 2023

All fine on AIX as well. Build, own tests and compat tests. Resulting binary uploaded at https://bin.chevah.com:20443/testing/2.7.18.3ff2ddf/python-2.7.18.3ff2ddf-aix71-ppc.tar.gz.

(Note that on AIX we don't have yet a patch for OpenSSL 1.0.2. But there are some other fixes there too.)

@adiroiban
Copy link
Copy Markdown
Member

Thanks. Let's merge this and have it included into chevah/server

@dumol
Copy link
Copy Markdown
Contributor Author

dumol commented Feb 15, 2023

For the record, all required server tests have passed for current python-package testing version at https://github.com/chevah/server/pull/6063/commits/336348d2cc8cc9ea6649712c5aa3cad7f20c8948.

Merging…

@dumol dumol merged commit cc62314 into cleanup-ssl-subdir Feb 15, 2023
@dumol dumol deleted the openssl-2023-feb-updates branch February 15, 2023 11:06
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants