I-LibreSSL 2.9.1 Ukukhishwa Kwelabhulali Ye-Cryptographic

I-OpenBSD Project Developers kwethulwe ukukhishwa kwe-edishini ephathekayo yephakheji I-LibreSSL 2.9.1, lapho kuthuthukiswa khona imfoloko ye-OpenSSL, okuhloswe ngayo ukunikeza izinga eliphezulu lokuphepha. Iphrojekthi ye-LibreSSL igxile ekusekelweni kwekhwalithi ephezulu kwezivumelwano ze-SSL/TLS ngokususa ukusebenza okungadingekile, ukwengeza izici zokuphepha ezengeziwe, nokuhlanza ngokuphawulekayo nokusebenza kabusha isisekelo sekhodi. Ukukhishwa kwe-LibreSSL 2.9.1 kuthathwa njengokukhishwa kokuhlola okuthuthukisa izici ezizofakwa ku-OpenBSD 6.5.

Izinguquko ku-LibreSSL 2.9.1:

  • Umsebenzi we-SM3 we-hashi owengeziwe (i-Chinese standard GB/T 32905-2016);
  • Kwengezwe i-SM4 block cipher (i-Chinese standard GB/T 32907-2016);
  • Kungezwe amamakhro OPENSSL_NO_* ukuze kuthuthukiswe ukusebenzisana ne-OpenSSL;
  • Indlela ye-EC_KEY_METHOD ithuthwe kancane isuka ku-OpenSSL;
  • Kusetshenziswe amakholi we-OpenSSL 1.1 API angekho;
  • Ukwesekwa okwengeziwe kwe-XChaCha20 ne-XChaCha20-Poly1305;
  • Ukwesekwa okwengeziwe kokudlulisa okhiye be-AES ngesixhumi esibonakalayo se-EVP;
  • Ihlinzeke ngokuqalisa okuzenzakalelayo kwe-CRYPTO_LOCK;
  • Ukuze kuthuthukiswe ukuhambisana ne-OpenSSL, usekelo lwe-pbkdf2 key hashing scheme yengezwe kunsiza ye-openssl, ngokuzenzakalelayo, imiyalo ye-enc, crl, x509 kanye ne-dgst isebenzisa indlela ye-sha25 hashing;
  • Kwengezwe izivivinyo zokuhlola ukuphatheka phakathi kwe-LibreSSL ne-OpenSSL
    I-1.0 / 1.1;

  • Kwengezwe izivivinyo ezengeziwe ze-Wycheproof;
  • Kwengezwe ikhono lokusebenzisa i-algorithm ye-RSA PSS kumasiginesha edijithali lapho kuxoxiswana ngokuxhunywa (ukuxhawula);
  • Ukuqaliswa okwengeziwe komshini wombuso wokubamba ukuxhawula, okuchazwe ku-RFC-8446;
  • Kukhishwe ikhodi ehlobene ne-ASN.1 yefa ku-libcrypto engakaze isetshenziswe iminyaka engaba ngu-20;
  • Kungezwe ukulungiselelwa komhlangano wezinhlelo ze-32-bit ARM kanye ne-Mingw-w64;
  • Ukusebenzisana okuthuthukisiwe neplathifomu ye-Android.

Source: opennet.ru

Engeza amazwana