ืฉื—ืจื•ืจ ืกืคืจื™ื™ืช ืงืจื™ืคื˜ื•ื’ืจืคื™ืช LibreSSL 3.2.0

ืžืคืชื—ื™ ืคืจื•ื™ืงื˜ื™ื ืฉืœ OpenBSD ื”ืฆื™ื’ ืฉื—ืจื•ืจ ืžื”ื“ื•ืจื” ื ื™ื™ื“ืช ืฉืœ ื”ื—ื‘ื™ืœื” LibreSSL 3.2.0, ืฉื‘ืชื•ื›ื• ืžืคื•ืชื— ืžื–ืœื’ ืฉืœ OpenSSL, ืฉืžื˜ืจืชื• ืœืกืคืง ืจืžืช ืื‘ื˜ื—ื” ื’ื‘ื•ื”ื” ื™ื•ืชืจ. ืคืจื•ื™ืงื˜ LibreSSL ืžืชืžืงื“ ื‘ืชืžื™ื›ื” ื‘ืื™ื›ื•ืช ื’ื‘ื•ื”ื” ื‘ืคืจื•ื˜ื•ืงื•ืœื™ SSL/TLS ืขืœ ื™ื“ื™ ื”ืกืจืช ืคื•ื ืงืฆื™ื•ื ืœื™ื•ืช ืžื™ื•ืชืจืช, ื”ื•ืกืคืช ืชื›ื•ื ื•ืช ืื‘ื˜ื—ื” ื ื•ืกืคื•ืช ื•ื ื™ืงื•ื™ ื•ืขื™ื‘ื•ื“ ืžืฉืžืขื•ืชื™ ืฉืœ ื‘ืกื™ืก ื”ืงื•ื“. ื”ืžื”ื“ื•ืจื” ืฉืœ LibreSSL 3.2.0 ื ื—ืฉื‘ืช ืœืžื”ื“ื•ืจื” ื ื™ืกื™ื•ื ื™ืช ื”ืžืคืชื—ืช ืชื›ื•ื ื•ืช ืฉื™ื™ื›ืœืœื• ื‘-OpenBSD 6.8.

ืชื›ื•ื ื•ืช ืฉืœ LibreSSL 3.2.0:

  • ืฆื“ ื”ืฉืจืช ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ TLS 1.3 ื‘ื ื•ืกืฃ ืœื—ืœืง ื”ืœืงื•ื— ืฉื”ื•ืฆืข ื‘ืขื‘ืจ. ื”ื™ื™ืฉื•ื ืฉืœ TLS 1.3 ื ื‘ื ื” ืขืœ ื‘ืกื™ืก ืžื›ื•ื ืช ืžืฆื‘ ื—ื“ืฉื” ื•ืชืช ืžืขืจื›ืช ืœืขื‘ื•ื“ื” ืขื ืจืฉื•ืžื•ืช. API ืชื•ืื OpenSSL TLS 1.3 ืขื“ื™ื™ืŸ ืœื ื–ืžื™ืŸ, ืืš ืืคืฉืจื•ื™ื•ืช ืงืฉื•ืจื•ืช ืœ-TLS 1.3 ื ื•ืกืคื• ืœืคืงื•ื“ืช openssl.
  • ื‘ืชืช-ืžืขืจื›ืช ืขื™ื‘ื•ื“ ื”ืจืฉื•ืžื•ืช, ื‘ื“ื™ืงืช ื’ื•ื“ืœ ื”ืฉื“ื” TLS 1.3 ืฉื•ืคืจื” ื•ืžื•ืฆื’ืช ืื–ื”ืจื” ืื ื—ืจื™ื’ื” ืžื”ืžื’ื‘ืœื•ืช.
  • ืฉืจืช TLS ืžื‘ื˜ื™ื— ืฉืจืง ืฉืžื•ืช ืžืืจื—ื™ื ื—ื•ืงื™ื™ื ื‘-SNI ื”ืขื•ืžื“ื™ื ื‘ื“ืจื™ืฉื•ืช ืฉืœ RFC 5890 ื•-RFC 6066 ื™ืขื•ื‘ื“ื•.
  • ื™ื™ืฉื•ื TLS 1.3 ื”ื•ืกื™ืฃ ืชืžื™ื›ื” ื‘ืžืฆื‘ SSL_MODE_AUTO_RETRY ื›ื“ื™ ืœืฉืœื•ื— ืžื—ื“ืฉ ื‘ืื•ืคืŸ ืื•ื˜ื•ืžื˜ื™ ื”ื•ื“ืขื•ืช ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ.
  • ื”ืฉืจืช ื•ื”ืœืงื•ื— TLS 1.3 ื”ื•ืกื™ืคื• ืชืžื™ื›ื” ืœืฉืœื™ื—ืช ื‘ืงืฉื•ืช ืœื‘ื“ื™ืงืช ืกื˜ื˜ื•ืก ืื™ืฉื•ืจ ื‘ืืžืฆืขื•ืช ื”ืชื•ืกืฃ ืกื™ื›ื•ืช OCSP (ืชื’ื•ื‘ืช OCSP ืžืื•ืฉืจืช ืขืœ ื™ื“ื™ ืจืฉื•ืช ืื™ืฉื•ืจื™ื ืžื•ืขื‘ืจืช ืขืœ ื™ื“ื™ ื”ืฉืจืช ื”ืžืฉืจืช ืืช ื”ืืชืจ ื‘ืขืช ืžืฉื ื•ืžืชืŸ ืขืœ ื—ื™ื‘ื•ืจ TLS).
  • ื›ืืฉืจ I/O ืžื•ืคืขืœ ื›ื‘ืจื™ืจืช ืžื—ื“ืœ, SSL_MODE_AUTO_RETRY ืžื•ืคืขืœ, ื‘ื“ื•ืžื” ืœืžื”ื“ื•ืจื•ืช ื—ื“ืฉื•ืช ืฉืœ OpenSSL.
  • ื ื•ืกืคื• ืžื‘ื—ื ื™ ืจื’ืจืกื™ื” ืขืœ ืกืžืš tlsfuzzer.
  • ื”ืคืงื•ื“ื” "openssl x509" ืžืกืคืงืช ืื™ื ื“ื™ืงืฆื™ื” ืœืชืืจื™ืš ืชืคื•ื’ื” ืฉื’ื•ื™ ืฉืœ ืื™ืฉื•ืจ.
  • TLS 1.3 ืขื RSA ืžืืคืฉืจ ืจืง ื—ืชื™ืžื•ืช ื“ื™ื’ื™ื˜ืœื™ื•ืช ืฉืœ PSS.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”