Release of the LibreSSL cryptographic library 3.9.0.

The developers of the OpenBSD project have released a portable version of the LibreSSL package 3.9.0, which develops a fork of OpenSSL aimed at providing a higher level of security. The LibreSSL project is focused on quality support for SSL/TLS protocols by removing unnecessary functionality, adding additional protective measures, and conducting a significant cleanup and reworking of the codebase. The release of LibreSSL 3.9.0 is considered experimental, in which capabilities are being developed that will be included in OpenBSD 7.5. At the same time, a stable release of LibreSSL 3.8.3 has been formed, which fixes several Windows-specific bugs and strengthens support for the CET (Control-flow Enforcement Technology) protection mechanism.

Features of LibreSSL 3.9.0:

  • Support for ECDSA-based digital signature algorithms with SHA-3 hashes has been added.
  • Support for HMAC with truncated SHA-2 and SHA-3 hashes as PBE PRF has been added.
  • Changes have been made to improve portability to other platforms. To avoid issues during static linking, most of the exported symbols used for compatibility in LibreSSL are prefixed with 'libressl_'. The export of compat symbols from libcrypto has been discontinued in CMake-based builds.
  • Changes aimed at improving compatibility with OpenSSL have been made. For example, aliases 'ChaCha20' and 'chacha20' have been added for the ChaCha algorithm, the behavior of SSL_library_init() and OPENSSL_init_ssl() functions has been unified, and calls to EVP_{CIPHER,MD}_CTX_init() have been aligned with OpenSSL's behavior.
  • The openssl utility has added support for the flags '-new -force_pubkey', '-multivalue-rdn', '-set_issuer', '-set_subject', and '-utf8'.
  • The transition from using the OBJ_bsearch_() call to the standard bsearch() function has been implemented.
  • The implementation of the by_file_ctrl(), EVP_Cipher{Init,Update,Final}(), and API OBJ_* functions has been simplified.
  • A major reorganization of the EVP API has been conducted. The functions EVP_add_{cipher,digest}() have been removed.
  • The handling of X509_TRUST has been simplified.
  • The functions BIO_dump*() have been rewritten.
  • Support for global tables that are not adapted for multi-threading has been discontinued. As a result, the assignment of aliases to ciphers and hashes, adding custom strings, ASN.1 methods, PKEY, and CRL is no longer supported.
  • The functions BIO_set(), BIO_{sn,v,vsn}printf(), sk_find_ex(), and OBJ_bsearch_(), along with many deprecated CRYPTO API functions, have been removed.
  • Public access to the X509_CERT_AUX and X509_TRUST APIs has been discontinued.
  • Support for GOST and STREEBOG algorithms has been discontinued.
  • Extended support for the CET (Control-flow Enforcement Technology) mechanism has been added, which is used to protect against exploits that leverage Return-Oriented Programming (ROP) techniques.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster