Release of the cryptographic library LibreSSL 3.8.0

The developers of the OpenBSD project have released the portable edition of the LibreSSL 3.8.0 package, which is based on the OpenSSL fork aimed at providing a higher level of security. The LibreSSL project focuses on high-quality support for SSL/TLS protocols by removing unnecessary functionality, adding additional protection features, and conducting significant cleaning and restructuring of the codebase. The release of LibreSSL 3.8.0 is considered experimental, developing features that will be included in OpenBSD 7.4. At the same time, stable releases of LibreSSL 3.6.3 and 3.7.3 have been formed, which fix several bugs.

Features of LibreSSL 3.8.0:

  • Support for a truncated version of SHA-2 and SHA-3 has been added.
  • The process of cleaning and restructuring the internal code for SHA has begun.
  • The internal functions BN_exp() and BN_copy() have been rewritten. The implementation of the BN_mod_sqrt() function has been replaced.
  • Assembler inserts for the AMD64 architecture have utilized the endbr64 (Terminate Indirect Branch) instructions.
  • Code for validating the rules defined in RFC 5280 has been ported from BoringSSL.
  • The transition of libcrypto to using CBB (bytebuilder) and CBS (bytestring) interfaces continues.
  • Workarounds have been implemented for issues that lead to privilege separation violations in libtls due to changes in OpenSSL 3.
  • Support for proxy certificates (RFC 3820), GF2m, API X9.31, CTS (Cipher Text Stealing) mode, SXNET, NETSCAPE_CERT_SEQUENCE, POLICY_TREE, as well as unsafe fast implementations of operations with prime numbers and elliptic curves from NIST, such as EC_GFp_nist_method(), have been discontinued.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster