<?xml version="1.0" encoding="UTF-8" ?>

<bugzilla version="5.2"
          urlbase="https://bugzilla.altlinux.org/"
          
          maintainer="jenya@basealt.ru"
>

    <bug>
          <bug_id>22615</bug_id>
          
          <creation_ts>2009-12-24 20:10:23 +0300</creation_ts>
          <short_desc>Cisco&apos;s implementation of the DTLS protocol</short_desc>
          <delta_ts>2010-01-08 21:26:51 +0300</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>4</classification_id>
          <classification>Development</classification>
          <product>Sisyphus</product>
          <component>openssl</component>
          <version>unstable</version>
          <rep_platform>all</rep_platform>
          <op_sys>Linux</op_sys>
          <bug_status>CLOSED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>P3</priority>
          <bug_severity>normal</bug_severity>
          <target_milestone>---</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter name="Alexey Shabalin">shaba</reporter>
          <assigned_to name="Gleb F-Malinovskiy">glebfm</assigned_to>
          <cc>glebfm</cc>
    
    <cc>shaba</cc>
          
          <qa_contact>qa-sisyphus</qa_contact>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>104776</commentid>
    <comment_count>0</comment_count>
    <who name="Alexey Shabalin">shaba</who>
    <bug_when>2009-12-24 20:10:23 +0300</bug_when>
    <thetext>For openconnect package:

Cisco&apos;s implementation of the DTLS protocol unfortunately does not
comply with the relevant standards. We need some patches to OpenSSL to
be compatible with it.

For the 0.9.8 branch of OpenSSL, the required patch is
        http://cvs.openssl.org/chngview?cn=18037

This was included in OpenSSL CVS in April 2009 and should be in the
next release from the 0.9.8 branch, which will presumably be 0.9.8l.
OpenSSL 1.0.0-beta2 and later require no patching; all the required
support is already present.

PS: 05-Nov-2009 OpenSSL 0.9.8l is now available</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104791</commentid>
    <comment_count>1</comment_count>
    <who name="Dmitry V. Levin">ldv</who>
    <bug_when>2009-12-25 04:43:08 +0300</bug_when>
    <thetext>(In reply to comment #0)
&gt; For openconnect package:
&gt; 
&gt; Cisco&apos;s implementation of the DTLS protocol unfortunately does not
&gt; comply with the relevant standards. We need some patches to OpenSSL to
&gt; be compatible with it.
&gt; 
&gt; For the 0.9.8 branch of OpenSSL, the required patch is
&gt;         http://cvs.openssl.org/chngview?cn=18037
&gt; 
&gt; This was included in OpenSSL CVS in April 2009 and should be in the
&gt; next release from the 0.9.8 branch, which will presumably be 0.9.8l.
&gt; OpenSSL 1.0.0-beta2 and later require no patching; all the required
&gt; support is already present.
&gt; 
&gt; PS: 05-Nov-2009 OpenSSL 0.9.8l is now available

Unfortunately, 0.9.8l was released as 0.9.8k with just one change (so called CVE-2009-3555 fix), without any changed available in OpenSSL_0_9_8-stable branch at that time.

I&apos;ve just fetched and pushed this change, please test:
http://git.altlinux.org/people/ldv/packages/?p=openssl.git;a=commit;h=ef8799678b107be51606d940a751fa6c3eaeb0b1</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104812</commentid>
    <comment_count>2</comment_count>
    <who name="Alexey Shabalin">shaba</who>
    <bug_when>2009-12-25 13:52:07 +0300</bug_when>
    <thetext>&gt; I&apos;ve just fetched and pushed this change, please test:
&gt; http://git.altlinux.org/people/ldv/packages/?p=openssl.git;a=commit;h=ef8799678b107be51606d940a751fa6c3eaeb0b1

openconnect собрался успешно.
Его работу проверю позже.
Спасибо.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>105255</commentid>
    <comment_count>3</comment_count>
    <who name="Repository Robot">repository-robot</who>
    <bug_when>2010-01-08 21:26:51 +0300</bug_when>
    <thetext>openssl098-0.9.8l-alt4 -&gt; sisyphus:

* Fri Jan 08 2010 Dmitry V. Levin &lt;ldv@altlinux&gt; 0.9.8l-alt4

- Built for target linux-generic32 on ARM.
- Applied upstream crypto/{md5,sha1} build fixes (by Evgeny Sinelnikov
  and Kirill A. Shutemov).
- Applied upstream compatibility patch for Cisco VPN client DTLS
  (closes: #22615).</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>