~ubuntu-branches/ubuntu/trusty/gnutls26/trusty-security

40 by Colin Watson
Link test-lock and test-thread_create with -Wl,--no-as-needed; see
1
gnutls26 (2.12.23-1ubuntu4) saucy; urgency=low
2
3
  * Link test-lock and test-thread_create with -Wl,--no-as-needed; see
4
    https://lists.gnu.org/archive/html/bug-gnulib/2013-10/msg00017.html.
5
    Based on a similar change by Matthias Klose in libidn.
6
7
 -- Colin Watson <cjwatson@ubuntu.com>  Mon, 07 Oct 2013 15:51:16 +0100
8
39.1.1 by Colin Watson
Drop the sipsak Breaks on armhf back to (<= 0.9.6-2.1), which is
9
gnutls26 (2.12.23-1ubuntu3) saucy; urgency=low
10
11
  * Drop the sipsak Breaks on armhf back to (<= 0.9.6-2.1), which is
12
    sufficient for Ubuntu.  The former versioning rendered sipsak
13
    uninstallable.
14
15
 -- Colin Watson <cjwatson@ubuntu.com>  Sat, 05 Oct 2013 00:00:39 +0100
16
39 by Marc Deslauriers
* SECURITY UPDATE: denial of service via incorrect pad
17
gnutls26 (2.12.23-1ubuntu2) saucy; urgency=low
18
19
  * SECURITY UPDATE: denial of service via incorrect pad
20
    - debian/patches/CVE-2013-2116.patch: added sanity check in
21
      lib/gnutls_cipher.c.
22
    - CVE-2013-2116
23
24
 -- Marc Deslauriers <marc.deslauriers@ubuntu.com>  Mon, 27 May 2013 08:34:01 -0400
25
38 by Timo Aaltonen
* Merge from debian-experimental, remaining changes:
26
gnutls26 (2.12.23-1ubuntu1) raring; urgency=low
27
28
  * Merge from debian-experimental, remaining changes:
29
    - Build gnutls-bin from this source package rather than from gnutls28:
30
      gnutls28's licensing is currently too strict for many of the free
31
      software packages built against it in Ubuntu main and we only want to
32
      support a single version.  Bump its version to achieve this.
33
  * Drop gnulib-gets.diff: upstream.
34
35
 -- Timo Aaltonen <tjaalton@ubuntu.com>  Thu, 07 Mar 2013 12:47:58 +0200
36
12.4.33 by Andreas Metzler
* New upstream version.
37
gnutls26 (2.12.23-1) experimental; urgency=low
38
39
  * New upstream version.
40
    + Includes fix for lucky thirteen TLS CBC padding timing
41
      attack. CVE-2013-0169 CVE-2013-1619 GNUTLS-SA-2013-1
42
43
 -- Andreas Metzler <ametzler@debian.org>  Wed, 06 Feb 2013 14:11:02 +0100
44
12.4.32 by Andreas Metzler
* Update watchfile, based on Bart Martens version from q.d.o, but use a)
45
gnutls26 (2.12.22-1) experimental; urgency=low
46
47
  * Update watchfile, based on Bart Martens version from q.d.o, but use a)
48
    ftp.gnutls.org as mirror and b) limit the the match to 2.x versions.
49
  * New upstream version.
50
    + Drop 30_strlen_on_null.diff.
51
52
 -- Andreas Metzler <ametzler@debian.org>  Sun, 06 Jan 2013 09:27:43 +0100
53
12.4.31 by Andreas Metzler
30_strlen_on_null.diff: Pulled from upstream git. Fix segfault caused
54
gnutls26 (2.12.21-4) experimental; urgency=low
55
56
  * 30_strlen_on_null.diff: Pulled from upstream git. Fix segfault caused
57
    by running strlen() on NULL. Closes: #647747
58
59
 -- Andreas Metzler <ametzler@debian.org>  Sun, 18 Nov 2012 14:48:57 +0100
60
12.4.30 by Andreas Metzler
Build with -sa.
61
gnutls26 (2.12.21-3) experimental; urgency=low
62
63
  * Build with -sa.
64
65
 -- Andreas Metzler <ametzler@debian.org>  Sun, 11 Nov 2012 09:50:41 +0100
66
67
gnutls26 (2.12.21-2) experimental; urgency=low
68
69
  * Fix documentation packaging. gnutls-doc is built from the GnuTLS 3.x
70
    packages. Add a new gnutls26-doc package which drops manpages and info
71
    format documentation in favour of being is co-installable with
72
    gnutls-doc.
73
74
 -- Andreas Metzler <ametzler@debian.org>  Sun, 11 Nov 2012 09:23:27 +0100
75
76
gnutls26 (2.12.21-1) experimental; urgency=low
77
78
  * New upstream release.
79
    + Works with libtasn1 3.0, requires at least libtasn1 2.14. Bump b-d.
80
81
 -- Andreas Metzler <ametzler@debian.org>  Sat, 10 Nov 2012 19:05:36 +0100
82
37 by Colin Watson
* Resynchronise with Debian. Remaining changes:
83
gnutls26 (2.12.20-2ubuntu1) raring; urgency=low
84
85
  * Resynchronise with Debian.  Remaining changes:
86
    - Build gnutls-bin from this source package rather than from gnutls28:
87
      gnutls28's licensing is currently too strict for many of the free
88
      software packages built against it in Ubuntu main and we only want to
89
      support a single version.  Bump its version to achieve this.
90
  * Avoid assuming that gets is declared.
91
92
 -- Colin Watson <cjwatson@ubuntu.com>  Thu, 06 Dec 2012 18:29:32 +0000
93
12.1.33 by Andreas Metzler
* 30_strlen_on_null.diff: Fix segfault caused by running strlen() on NULL.
94
gnutls26 (2.12.20-2) unstable; urgency=low
95
96
  * 30_strlen_on_null.diff: Fix segfault caused by running strlen() on NULL.
97
    Closes: #647747
98
  * Fix documentation packaging. gnutls-doc is built from the GnuTLS 3.x
99
    packages. Add a new gnutls26-doc package which drops manpages and info
100
    format documentation in favour of being co-installable with
101
    gnutls-doc.
102
103
 -- Andreas Metzler <ametzler@debian.org>  Tue, 13 Nov 2012 19:21:25 +0100
104
12.1.32 by Andreas Metzler
* New upstream release.
105
gnutls26 (2.12.20-1) unstable; urgency=low
106
107
  * New upstream release.
108
  * Drop 25_nssldapsfix.diff (already included).
109
110
 -- Andreas Metzler <ametzler@debian.org>  Sun, 10 Jun 2012 16:53:50 +0200
111
12.1.31 by Andreas Metzler
Pull debian/patches/25_nssldapsfix.diff from upstream git.
112
gnutls26 (2.12.19-2) unstable; urgency=low
113
114
  * Pull debian/patches/25_nssldapsfix.diff from upstream git.
115
    (LP: #1003841)
116
117
 -- Andreas Metzler <ametzler@debian.org>  Thu, 07 Jun 2012 19:17:07 +0200
118
12.1.30 by Andreas Metzler
New upstream release.
119
gnutls26 (2.12.19-1) unstable; urgency=low
120
121
  * New upstream release.
122
123
 -- Andreas Metzler <ametzler@debian.org>  Sat, 05 May 2012 20:02:34 +0200
124
12.1.29 by Andreas Metzler
New upstream release.
125
gnutls26 (2.12.18-1) unstable; urgency=low
126
127
  * New upstream release.
128
129
 -- Andreas Metzler <ametzler@debian.org>  Fri, 16 Mar 2012 19:34:18 +0100
130
12.1.28 by Andreas Metzler
Upload to unstable.
131
gnutls26 (2.12.17-2) unstable; urgency=low
132
133
  * Upload to unstable.
134
135
 -- Andreas Metzler <ametzler@debian.org>  Sat, 10 Mar 2012 16:07:43 +0100
136
12.4.29 by Andreas Metzler
* New upstream release.
137
gnutls26 (2.12.17-1) experimental; urgency=low
138
139
  * New upstream release.
140
   + Unfuzz 20_tests-select.diff.
141
   + Bump libp11-kit-dev build-dep.
142
   + Bump shlibs.
12.1.30 by Andreas Metzler
New upstream release.
143
   + Includes fix for CVE-2012-1573.
12.4.29 by Andreas Metzler
* New upstream release.
144
145
 -- Andreas Metzler <ametzler@debian.org>  Sat, 03 Mar 2012 18:17:30 +0100
146
12.1.27 by Andreas Metzler
New upstream release.
147
gnutls26 (2.12.16-1) unstable; urgency=low
148
149
  * New upstream release.
150
151
 -- Andreas Metzler <ametzler@debian.org>  Sat, 07 Jan 2012 13:20:09 +0100
152
36 by Thorsten Glaser
Apply upstream patch to fix validation of certificates when more than
153
gnutls26 (2.12.14-5ubuntu4) quantal; urgency=low
154
155
  * Apply upstream patch to fix validation of certificates when more than
156
    one with the same short hash exists in the CA bundle (LP: #1003841).
157
158
 -- Thorsten Glaser <tg@mirbsd.de>  Thu, 24 May 2012 11:19:12 +0200
159
35 by Tyler Hicks
* SECURITY UPDATE: Denial of service via crafted TLS record (LP: #978661)
160
gnutls26 (2.12.14-5ubuntu3) precise; urgency=low
161
162
  * SECURITY UPDATE: Denial of service via crafted TLS record (LP: #978661)
163
    - debian/patches/CVE-2012-1573.patch: Validate the size of a
164
      GenericBlockCipher structure as it is processed. Based on upstream
165
      patch.
166
    - CVE-2012-1573
167
168
 -- Tyler Hicks <tyhicks@canonical.com>  Wed, 11 Apr 2012 02:52:23 -0500
169
34 by Colin Watson
Bump the version of gnutls-doc too, for the same reason as gnutls-bin.
170
gnutls26 (2.12.14-5ubuntu2) precise; urgency=low
171
172
  * Bump the version of gnutls-doc too, for the same reason as gnutls-bin.
173
174
 -- Colin Watson <cjwatson@ubuntu.com>  Tue, 24 Jan 2012 20:05:00 +0000
175
33 by Colin Watson
Start building gnutls-bin from this source package again, superseding
176
gnutls26 (2.12.14-5ubuntu1) precise; urgency=low
177
178
  * Start building gnutls-bin from this source package again, superseding
179
    the version in gnutls28: gnutls28's licensing is currently too strict
180
    for many of the free software packages built against it in Ubuntu main
181
    and we only want to support a single version.  Bump its version to
182
    achieve this.
183
184
 -- Colin Watson <cjwatson@ubuntu.com>  Tue, 24 Jan 2012 18:18:46 +0000
185
12.1.26 by Andreas Metzler
Disable gnutls-guile package, let it be provided by gnutls28.
186
gnutls26 (2.12.14-5) unstable; urgency=low
187
188
  * Disable gnutls-guile package, let it be provided by gnutls28.
189
190
 -- Andreas Metzler <ametzler@debian.org>  Sat, 17 Dec 2011 12:05:34 +0100
191
12.1.25 by Andreas Metzler
* Prepare for uploading gnutls28 to unstable.
192
gnutls26 (2.12.14-4) unstable; urgency=low
193
194
  * Prepare for uploading gnutls28 to unstable.
195
    + Drop gnutls-bin package, it is going to be provided by gnutls28.
196
    + Binaries are still useful for debugging, ship them with libgnutls-dbg
197
      in LIBDIR/libgnutls26.
198
199
 -- Andreas Metzler <ametzler@debian.org>  Sat, 03 Dec 2011 09:39:54 +0100
200
12.1.24 by Andreas Metzler, 20_tests-select.diff
[20_tests-select.diff] Do not run gnulib test-select test anymore. The
201
gnutls26 (2.12.14-3) unstable; urgency=low
202
203
  * [20_tests-select.diff] Do not run gnulib test-select test anymore. The
204
    test fails on kfreebsd-i386, the gnutls library does not use select().
205
    Closes: #648247
206
207
 -- Andreas Metzler <ametzler@debian.org>  Tue, 15 Nov 2011 19:10:06 +0100
208
12.1.23 by Andreas Metzler
Build gnutls with --disable-largefile on armel, armhf and mipsel to fix
209
gnutls26 (2.12.14-2) unstable; urgency=low
210
211
  * Build gnutls with --disable-largefile on armel, armhf and mipsel to fix
212
    FTBFS on these architectures.
213
    See http://lists.gnu.org/archive/html/gnutls-devel/2011-10/msg00075.html
214
215
 -- Andreas Metzler <ametzler@debian.org>  Sat, 12 Nov 2011 09:30:42 +0100
216
12.1.22 by Andreas Metzler
* Simplify dependencies:
217
gnutls26 (2.12.14-1) unstable; urgency=medium
218
219
  * Simplify dependencies:
220
    + libgnutls-dev Provides/Conflicts/Replaces gnutls-dev (which is
221
      also provided by gnutls28' libgnutls*-dev).
222
    + Drop *ancient* Conflicts/Replaces against libgnutls5-dev, gnutls0.4-dev,
223
      gnutls-dev (<< 0.4.0-0), libgnutls11-dev.
224
  * New upstream bugfix release.
12.1.23 by Andreas Metzler
Build gnutls with --disable-largefile on armel, armhf and mipsel to fix
225
    + Fixes GNUTLS-SA-2011-2 CVE-2011-4128 Closes: #648441
12.1.22 by Andreas Metzler
* Simplify dependencies:
226
227
 -- Andreas Metzler <ametzler@debian.org>  Tue, 08 Nov 2011 19:34:28 +0100
228
12.1.21 by Andreas Metzler
* New upstream version.
229
gnutls26 (2.12.12-1) unstable; urgency=low
230
231
  * New upstream version.
232
  * Drop -mlong-double-64 on powerpc, updated gnulib should fix this issue and
233
    the build-failure on powerpc64. Closes: #644944
234
  * Delete superfluous info from debian/README.source.
235
  * Drop 20_guiledocstring, included upstream.
236
237
 -- Andreas Metzler <ametzler@debian.org>  Fri, 21 Oct 2011 19:33:04 +0200
238
12.1.20 by Andreas Metzler
* New upstream version.
239
gnutls26 (2.12.11-1) unstable; urgency=low
240
241
  * New upstream version.
242
    + Allow CA importing of 0 certificates to succeed. Closes: #640639
243
  * Add libp11-kit-dev to libgnutls-dev dependencies. (see #643811)
244
  * [20_guiledocstring.diff] guile: Fix docstring extraction with CPP 4.5+.
245
246
 -- Andreas Metzler <ametzler@debian.org>  Sat, 01 Oct 2011 15:28:13 +0200
247
12.1.19 by Andreas Metzler
Add -mlong-double-64 to CFLAGS on powerpc to work around gnulib testsuite
248
gnutls26 (2.12.10-2) unstable; urgency=low
249
250
  * Add -mlong-double-64 to CFLAGS on powerpc to work around gnulib testsuite
251
    error (test-float). See http://savannah.gnu.org/bugs/?33710 and 
252
    http://mid.gmane.org/relbj8-8jh.ln1%40argenau.downhill.at.eu.org
253
254
 -- Andreas Metzler <ametzler@debian.org>  Sun, 11 Sep 2011 08:23:54 +0200
255
12.1.18 by Andreas Metzler
* New upstream version.
256
gnutls26 (2.12.10-1) unstable; urgency=low
257
258
  * New upstream version.
259
    + Uses p11-kit instead of forked pakchois for PKCS#11. Update
260
      build-depends (libp11-kit-dev and pkg-config) and debian/copyright.
261
  * Drop superfluous patches (20_gcrypt15compat.diff,
262
    21_gnutls-cli.man.diff 22_export_gnutls_openpgp_privkey_sign_hash.diff
263
    23_deinit_privkey.diff 24_XmppAddr-UTF8String.diff).
264
  * Fix binary-control-field-duplicates-source lintian warnings.
265
266
 -- Andreas Metzler <ametzler@debian.org>  Sat, 03 Sep 2011 14:40:36 +0200
267
12.1.17 by Andreas Metzler
* Since libgnutls*-dbg contains debugging symbols of helper applications
268
gnutls26 (2.12.7-8) unstable; urgency=high
269
270
  * Since libgnutls*-dbg contains debugging symbols of helper applications
271
    libgnutls26-dbg and libgnutls28-dbg are not co-installable. Add Conflicts.
272
  * [24_XmppAddr-UTF8String.diff] Correct parsing of XMPP subject
273
    alternative names. Closes: #638586
274
  * [23_deinit_privkey.diff] gnutls_certificate_set_x509_key() and
275
    gnutls_certificate_set_openpgp_key() operate as in 2.10.x and allow the
276
    release of the private key during the lifetime of the certificate
277
    structure. Closes: #638595
278
  * Upload with urgency=high, 638595 breaks wwwoffle's TLS support.
279
280
 -- Andreas Metzler <ametzler@debian.org>  Sun, 28 Aug 2011 08:54:26 +0200
281
12.1.16 by Andreas Metzler
* 21_gnutls-cli.man.diff pulled from upstream git: Formatting fix for
282
gnutls26 (2.12.7-7) unstable; urgency=high
283
284
  * 21_gnutls-cli.man.diff pulled from upstream git: Formatting fix for
285
    gnutls-cli manpage. Closes: #637551
286
  * 22_export_gnutls_openpgp_privkey_sign_hash.diff. Fix ABI breakage,
287
    export_gnutls_openpgp_privkey_sign_hash() used to be present in 2.10.x was
288
    accidentally dropped from the symbol list. (Thanks, Jakub Wilk)
289
    Closes: #638801
290
291
 -- Andreas Metzler <ametzler@debian.org>  Mon, 22 Aug 2011 19:24:08 +0200
292
12.1.15 by Andreas Metzler
Use common-install-arch instead of common-install-prehook-arch to delete
293
gnutls26 (2.12.7-6) unstable; urgency=low
294
295
  * Use common-install-arch instead of common-install-prehook-arch to delete
296
    rpath.
297
298
 -- Andreas Metzler <ametzler@debian.org>  Fri, 12 Aug 2011 20:26:22 +0200
299
300
gnutls26 (2.12.7-5) unstable; urgency=low
301
302
  * libgnutls26 Breaks sipsak (<= 0.9.6-2.1+b1) [sparc armhf].
303
    Closes: #637520
304
  * Delete unneccessary rpath entries.
305
306
 -- Andreas Metzler <ametzler@debian.org>  Fri, 12 Aug 2011 16:55:24 +0200
307
12.1.14 by Andreas Metzler
* Upload to unstable.
308
gnutls26 (2.12.7-4) unstable; urgency=low
309
310
  * Upload to unstable.
311
  * Point watch file to stable release directory.
312
  * 18_gpgerrorinpkgconfig.diff: Add libgpg-error to pkg-config
313
    Libs.private. Closes: #632891
314
  * Update libgnutls26 Breaks (snowdrop and zoneminder versions.)
315
316
 -- Andreas Metzler <ametzler@debian.org>  Sun, 07 Aug 2011 09:58:28 +0200
317
12.4.28 by Andreas Metzler, Simon Josefsson, Andreas Metzler
[ Simon Josefsson ]
318
gnutls26 (2.12.7-3) experimental; urgency=low
319
320
  [ Simon Josefsson ]
321
  * Fix Debian BTS URL in --with-packager-bug-reports option.
322
323
  [ Andreas Metzler ]
324
  * [20_gcrypt15compat.diff] Fix compatibility with gcrypt 1.5.
325
326
 -- Andreas Metzler <ametzler@debian.org>  Mon, 25 Jul 2011 19:59:36 +0200
327
12.4.27 by Andreas Metzler
* Stop shipping libtool la files.
328
gnutls26 (2.12.7-2) experimental; urgency=low
329
330
  * Stop shipping libtool la files.
331
  * Convert to multi-arch. (Partial merge from Ubuntu 2.10.5-1ubuntu2):
332
    + configure with --libdir=\$${prefix}/lib/$(DEB_HOST_MULTIARCH), update
333
      *.install accordingly.
334
    + Bump cdbs Build-Depends to 0.4.93 (required for expanding
335
      $(DEB_HOST_MULTIARCH)).
336
    + Bump debhelper b-d to 8.1.3 (for ${misc:Pre-Depends}).
337
    + runtime libraries and guile-wrapper are Multi-Arch: same with 
338
      Pre-Depends: ${misc:Pre-Depends}, -bin (helper binaries) and -doc are 
339
      Multi-Arch: foreign, -dev and -dbg remain unchanged.
340
    + Diverge from Ubuntu patch  by not settting Multi-Arch: same on -dbg
341
      package. It contains debugging symbols for both library and helper
342
      binaries ( e.g. /usr/lib/debug/usr/bin/gnutls-cli) and is therefore not
343
      co-installable with itself.
344
345
 -- Andreas Metzler <ametzler@debian.org>  Sun, 26 Jun 2011 15:01:58 +0200
346
12.4.26 by Andreas Metzler
* New upstream version.
347
gnutls26 (2.12.7-1) experimental; urgency=low
348
349
  * New upstream version.
350
  * Update 17_ignoretestsuitteerrors.diff.
351
  * A new version of pokerth has been uploaded to sid, update libgnutls26
352
    Breaks accordingly.
353
354
 -- Andreas Metzler <ametzler@debian.org>  Sun, 19 Jun 2011 08:49:01 +0200
355
12.4.25 by Andreas Metzler
* New upstream version.
356
gnutls26 (2.12.6.1-1) experimental; urgency=low
357
358
  * New upstream version.
359
  * Bump shlibs, global_set_time_function() was added.
360
  * Stop setting CFLAGS += -Wall, it is set by default again.
361
  * [17_ignoretestsuitteerrors.diff] Ignore two (not serious) testsuite
362
    errors.
363
364
 -- Andreas Metzler <ametzler@debian.org>  Sun, 05 Jun 2011 13:18:50 +0200
365
12.4.24 by Andreas Metzler
* New upstream version.
366
gnutls26 (2.12.5-1) experimental; urgency=low
367
368
  * New upstream version.
369
  * Bump shlibs, gnutls_x509_crq_verify() was added.
370
371
 -- Andreas Metzler <ametzler@debian.org>  Sat, 14 May 2011 13:21:12 +0200
372
12.4.23 by Andreas Metzler
* New upstream version.
373
gnutls26 (2.12.4-1) experimental; urgency=low
374
375
  * New upstream version.
376
  * Bump shlibs. (gnutls_certificate_get_issuer() added).
377
378
 -- Andreas Metzler <ametzler@debian.org>  Sun, 08 May 2011 15:19:18 +0200
379
12.4.22 by Andreas Metzler
* New upstream version.
380
gnutls26 (2.12.3-1) experimental; urgency=low
381
382
  * New upstream version.
383
  * Drop patches included upstream: [18_restoreHMAC-MD5.diff]
384
385
 -- Andreas Metzler <ametzler@debian.org>  Fri, 22 Apr 2011 18:26:11 +0200
386
12.4.21 by Andreas Metzler, 18_restoreHMAC-MD5.diff
[18_restoreHMAC-MD5.diff], pulled from upstream git, restore HMAC-MD5
387
gnutls26 (2.12.2-2) experimental; urgency=low
388
389
  * [18_restoreHMAC-MD5.diff], pulled from upstream git, restore HMAC-MD5
390
    for compatibility. Closes: #623001
391
392
 -- Andreas Metzler <ametzler@debian.org>  Sun, 17 Apr 2011 15:44:30 +0200
393
12.4.20 by Andreas Metzler
* New upstream version.
394
gnutls26 (2.12.2-1) experimental; urgency=low
395
396
  * New upstream version.
397
  * [lintian] Drop article from short package descriptions.
398
399
 -- Andreas Metzler <ametzler@debian.org>  Fri, 08 Apr 2011 19:36:27 +0200
400
12.4.19 by Andreas Metzler
* New upstream version.
401
gnutls26 (2.12.1-1) experimental; urgency=low
402
403
  * New upstream version.
404
    + certtool: Generated certificate request with stricter permissions.
405
      Closes: #619746
406
  * Drop superfluous patches:
407
    17_sizeof_gnutls_openpgp_keyid_t.diff 18_ext_mod_iadef.diff
408
    19_uninitializedvar.diff 20_access_freedmemory.diff
409
  * Add Breaks for all packages using the GnuTLS OpenSSL wrapper. They will
410
    need a binNMU when gnutls 2.12.x uploaded to unstable.
411
412
 -- Andreas Metzler <ametzler@debian.org>  Sat, 02 Apr 2011 15:22:46 +0200
413
12.4.18 by Andreas Metzler
* New upstream stable release.
414
gnutls26 (2.12.0-1) experimental; urgency=low
415
416
  * New upstream stable release.
417
    + Drop superceded patches 17_goldhotfix.patch
418
      18_libgnutls-openssl_soname.diff.
419
  * Pull a couple of post release fixes from upstream gnutls_2_12_x branch:
420
    17_sizeof_gnutls_openpgp_keyid_t.diff 18_ext_mod_iadef.diff
421
    19_uninitializedvar.diff 20_access_freedmemory.diff
422
423
 -- Andreas Metzler <ametzler@debian.org>  Sun, 27 Mar 2011 10:23:11 +0200
424
12.4.17 by Andreas Metzler
* 18_libgnutls-openssl_soname.diff. Bump libgnutls-openssl soname (libtool
425
gnutls26 (2.11.7-2) experimental; urgency=low
426
427
  * 18_libgnutls-openssl_soname.diff. Bump libgnutls-openssl soname (libtool
428
    versioning: 27:0:0).
429
  * Split off libgnutls-openssl to a separate package, since the sonames are
430
    not in sync anymore.
431
432
 -- Andreas Metzler <ametzler@debian.org>  Fri, 11 Mar 2011 17:48:47 +0100
433
12.4.16 by Andreas Metzler
* New upstream version (rc for 2.12)
434
gnutls26 (2.11.7-1) experimental; urgency=low
435
436
  * New upstream version (rc for 2.12)
437
    + Drop superfluous patches (15_fixgnutlspc.diff 17_endian.diff)
438
    + Bump shlibs.
439
  * debian/patches/17_goldhotfix.patch Link gnutls-extra gainst gcrypt.
440
441
 -- Andreas Metzler <ametzler@debian.org>  Thu, 10 Mar 2011 12:12:01 +0100
442
12.4.15 by Andreas Metzler
17_endian.diff - Pulled from upstream. Fix testsuite error (./tests/resume)
443
gnutls26 (2.11.6-2) experimental; urgency=low
444
445
  * 17_endian.diff - Pulled from upstream. Fix testsuite error (./tests/resume)
446
    on big endian architectures.
447
448
 -- Andreas Metzler <ametzler@debian.org>  Wed, 23 Feb 2011 19:20:40 +0100
449
12.4.14 by Andreas Metzler
* Development release.
450
gnutls26 (2.11.6-1) experimental; urgency=low
451
452
  * Development release.
453
  * Continue building against libgcrypt, run configure with --with-libgcrypt.
454
  * Refresh patches/15_fixgnutlspc.diff.
455
  * Set --with-packager* options.
456
  * Install newly available p11tool binary.
457
  * Bump libgcrypt11-dev Build-Depends.
458
  * C++ wrapper soname bump, change package name accordingly.
459
  * Bump shlibs.
460
  * Update debian/copyright.
461
  * Set CFLAGS += -Wall, the latest combination of cdbs + dpkg-dev does not
462
    seem to set it by default.
463
464
 -- Andreas Metzler <ametzler@debian.org>  Sat, 19 Feb 2011 15:29:43 +0100
465
12.1.13 by Andreas Metzler, 20_gcrypt15compat.diff
[20_gcrypt15compat.diff] Fix compatibility with gcrypt 1.5.
466
gnutls26 (2.10.5-3) unstable; urgency=medium
467
468
  * [20_gcrypt15compat.diff] Fix compatibility with gcrypt 1.5.
469
470
 -- Andreas Metzler <ametzler@debian.org>  Mon, 25 Jul 2011 19:26:34 +0200
471
12.1.12 by Andreas Metzler
Stop shipping libtool la files.
472
gnutls26 (2.10.5-2) unstable; urgency=low
473
474
  * Stop shipping libtool la files.
475
476
 -- Andreas Metzler <ametzler@debian.org>  Sat, 25 Jun 2011 18:13:38 +0200
26 by Steve Langasek
* Merge from Debian unstable, remaining changes:
477
12.1.11 by Andreas Metzler
* New upstream bugfix release.
478
gnutls26 (2.10.5-1) unstable; urgency=low
479
480
  * New upstream bugfix release.
481
    + Drop 15_fixgnutlspc.diff, included upstream.
482
  * Set C(XX)FLAGS += -Wall, the latest combination of cdbs + dpkg-dev does not
483
    seem to set it by default.
484
485
 -- Andreas Metzler <ametzler@debian.org>  Mon, 28 Feb 2011 18:52:57 +0100
486
12.1.10 by Andreas Metzler
* Use debhelper compatibility level 7.
487
gnutls26 (2.10.4-2) unstable; urgency=low
488
489
  * Use debhelper compatibility level 7.
490
  * Merge in changes from 2.8.6-1:
491
    + Use dh_lintian.
492
    + Use dh_makeshlibs for the guile stuff, too. This gets us 
493
      a) ldconfig in postinst. Closes: #553109
494
      and
495
      b) a shlibs file.
496
      However the shared objects /usr/lib/libguile-gnutls*so* are still not
497
      designed to be used as libraries (linking) but are dlopened. guile-1.10
498
      will address this issue by keeping this stuff in a private directory.
499
    + hotfix pkg-config files (proper fix to be included upstream).
500
    + Stop unneeeded linkage against libgpg-error. 16_unnecessarydep.diff
501
      Closes: #405239
502
   * Upload to unstable.
503
504
 -- Andreas Metzler <ametzler@debian.org>  Sun, 06 Feb 2011 16:44:09 +0100
505
12.4.13 by Andreas Metzler
New upstream release. V1 CAs are trusted by default.
506
gnutls26 (2.10.4-1) experimental; urgency=low
507
508
  * New upstream release. V1 CAs are trusted by default.
509
510
 -- Andreas Metzler <ametzler@debian.org>  Mon, 06 Dec 2010 19:13:48 +0100
511
12.4.12 by Andreas Metzler
* Drop workaround for 519006, binutils is fixed even in squeeze.
512
gnutls26 (2.10.3-1) experimental; urgency=low
513
514
  * Drop workaround for 519006, binutils is fixed even in squeeze.
515
  * New upstream bugfix release.
516
517
 -- Andreas Metzler <ametzler@debian.org>  Fri, 19 Nov 2010 19:19:26 +0100
518
12.4.11 by Andreas Metzler
* New upstream version.
519
gnutls26 (2.10.2-1) experimental; urgency=low
520
521
  * New upstream version.
522
    + Fix asynchronous API handling. Closes: #588187
523
    + certtool does not crash on reading from /dev/null anymore.
524
      Closes: #588029
525
  * Standards-Version 3.9.1 -Stop building with -D_REENTRANT.
526
527
 -- Andreas Metzler <ametzler@debian.org>  Thu, 30 Sep 2010 19:10:31 +0200
528
12.4.10 by Andreas Metzler
* Update package descriptions. Closes: #588067
529
gnutls26 (2.10.1-1) experimental; urgency=low
530
531
  * Update package descriptions. Closes: #588067
532
  * New upstream version.
533
534
 -- Andreas Metzler <ametzler@debian.org>  Sun, 25 Jul 2010 14:56:45 +0200
535
12.4.9 by Andreas Metzler
libgnutls26 now Breaks: libsoup2.4-1 (<= 2.30.1-1),
536
gnutls26 (2.10.0-2) experimental; urgency=low
537
538
  * libgnutls26 now Breaks: libsoup2.4-1 (<= 2.30.1-1), 
539
    libsoup2.4-1 (= 2.31.2-1). The problem is caused by addition of TLS1.2
540
    support in GnuTLS. Sid (2.30.2-1) is already fixed, experimental
541
    (2.31.2-1) not yet. Closes: #587755
542
543
 -- Andreas Metzler <ametzler@debian.org>  Sat, 03 Jul 2010 08:58:57 +0200
544
12.4.8 by Andreas Metzler
* New upstream stable release.
545
gnutls26 (2.10.0-1) experimental; urgency=low
546
547
  * New upstream stable release.
548
  * Point watchfile to stable releases.
549
550
 -- Andreas Metzler <ametzler@debian.org>  Sat, 26 Jun 2010 14:48:40 +0200
551
12.4.7 by Andreas Metzler
* Work around gcc-4.4 bug <http://bugs.debian.org/519006> by building
552
gnutls26 (2.9.12-2) experimental; urgency=low
553
554
  * Work around gcc-4.4 bug <http://bugs.debian.org/519006> by building
555
    without -g on mips/mipsel. (As a side effect this makes libgnutls26-dbg a
556
    useless and almost empty package on these archs.)
557
  * Drop ancient workaround for gcc bug on hppa.
558
    http://bugs.debian.org/128036
559
560
 -- Andreas Metzler <ametzler@debian.org>  Sat, 19 Jun 2010 14:38:22 +0200
561
12.4.6 by Andreas Metzler
New upstream version.
562
gnutls26 (2.9.12-1) experimental; urgency=low
563
564
  * New upstream version.
565
566
 -- Andreas Metzler <ametzler@debian.org>  Thu, 17 Jun 2010 19:20:04 +0200
567
12.4.5 by Andreas Metzler
* New upstream version.
568
gnutls26 (2.9.11-1) experimental; urgency=low
569
570
  * New upstream version.
571
  * Drop 15_gnutlspriority.diff, superseded.
572
573
 -- Andreas Metzler <ametzler@debian.org>  Mon, 07 Jun 2010 19:36:33 +0200
574
12.4.4 by Andreas Metzler, 15_gnutlspriority.diff
[15_gnutlspriority.diff] Restore compatibility with programs using
575
gnutls26 (2.9.10-2) experimental; urgency=low
576
577
  * [15_gnutlspriority.diff] Restore compatibility with programs using 
578
    gnutls_*_set_priority() instead of gnutls_priority_*(), e.g. exim.
579
    Closes: #579831
580
581
 -- Andreas Metzler <ametzler@debian.org>  Thu, 27 May 2010 18:40:53 +0200
582
12.4.3 by Andreas Metzler
* New upstream version.
583
gnutls26 (2.9.10-1) experimental; urgency=low
584
585
  * New upstream version.
586
  * New functions added, bump shlibs.
587
588
 -- Andreas Metzler <ametzler@debian.org>  Thu, 22 Apr 2010 19:29:52 +0200
589
12.4.2 by Andreas Metzler
* Package upstream development branch for experimental.
590
gnutls26 (2.9.9-1) experimental; urgency=low
591
592
  * Package upstream development branch for experimental.
593
  * Track development versions in watchfile.
594
  * Package C++ wrapper again. Closes: #548637
595
596
 -- Andreas Metzler <ametzler@debian.org>  Sun, 20 Dec 2009 11:31:33 +0100
597
12.1.9 by Andreas Metzler
* Use dh_lintian.
598
gnutls26 (2.8.6-1) unstable; urgency=low
599
600
  * Use dh_lintian.
601
  * Use dh_makeshlibs for the guile stuff, too. This gets us 
602
    a) ldconfig in postinst. Closes: #553109
603
    and
604
    b) a shlibs file.
605
    However the shared objects /usr/lib/libguile-gnutls*so* are still not
606
    designed to be used as libraries (linking) but are dlopened. guile-1.10
607
    will address this issue by keeping this stuff in a private directory.
608
  * hotfix pkg-config files (proper fix to be included upstream).
609
  * Stop unneeeded linkage against libgpg-error. 16_unnecessarydep.diff
610
611
 -- Andreas Metzler <ametzler@debian.org>  Sat, 20 Mar 2010 15:53:35 +0100
612
12.3.1 by Andreas Metzler
Add a huge bunch of lintian overrides for the guile stuff to make dak
613
gnutls26 (2.8.5-2) unstable; urgency=low
614
615
  * Add a huge bunch of lintian overrides for the guile stuff to make dak
616
    happy.
617
618
 -- Andreas Metzler <ametzler@debian.org>  Fri, 13 Nov 2009 19:53:04 +0100
619
620
gnutls26 (2.8.5-1) unstable; urgency=low
621
622
  * Add datefudge to build-depends. (Only needed for the pkcs1-pad test.)
623
  * Switch to '3.0 (quilt)' source format, allowing us to use upstreams
624
    orig.tar.bz2 without repacking it to gz.
625
  * New upstream version.
626
    + Drop patches/20_fixtimebomb.diff.
627
628
 -- Andreas Metzler <ametzler@debian.org>  Thu, 12 Nov 2009 19:57:08 +0100
629
12.1.7 by Andreas Metzler, 20_fixtimebomb.diff
[20_fixtimebomb.diff] Fix testsuite error. Closes: #552920
630
gnutls26 (2.8.4-2) unstable; urgency=high
631
632
  * [20_fixtimebomb.diff] Fix testsuite error. Closes: #552920
633
634
 -- Andreas Metzler <ametzler@debian.org>  Sun, 01 Nov 2009 13:21:27 +0100
635
12.2.4 by Andreas Metzler
* New upstream version.
636
gnutls26 (2.8.4-1) unstable; urgency=low
637
638
  * New upstream version.
639
    + Drop debian/patches/15_openpgp.diff.
640
  * Sync priorities with override file, libgnutls26 has been bumped from
641
    important to standard.
642
643
 -- Andreas Metzler <ametzler@debian.org>  Sat, 26 Sep 2009 10:33:52 +0200
644
12.2.3 by Andreas Metzler
Empty dependency_libs in la-files. (Squeeze release goal.)
645
gnutls26 (2.8.3-3) unstable; urgency=low
646
647
  * Empty dependency_libs in la-files. (Squeeze release goal.)
648
649
 -- Andreas Metzler <ametzler@debian.org>  Sat, 05 Sep 2009 09:09:22 +0200
650
12.2.2 by Andreas Metzler, debian/patches/15_openpgp.diff
[ debian/patches/15_openpgp.diff ] The CVE-2009-2730 patch broke
651
gnutls26 (2.8.3-2) unstable; urgency=low
652
653
  * [ debian/patches/15_openpgp.diff ] The CVE-2009-2730 patch broke
654
    openpgp connections.
655
656
 -- Andreas Metzler <ametzler@debian.org>  Sat, 22 Aug 2009 14:14:48 +0200
657
12.2.1 by Andreas Metzler
* New upstream version.
658
gnutls26 (2.8.3-1) unstable; urgency=high
659
660
  * New upstream version.
661
    + Stops hardcoding a hard dependency on the versions of gcrypt and tasn it
662
      was built against. Closes: #540449
663
    + Fixes CVE-2009-2730, a vulnerability related to NUL bytes in X.509
664
      certificate name fields. Closes: #541439        GNUTLS-SA-2009-4
665
      http://lists.gnu.org/archive/html/help-gnutls/2009-08/msg00011.html
666
  * Drop 15_chainverify_expiredcert.diff, included upstream.
667
  * Urgency high, since 541439 applies to testing, too.
668
669
 -- Andreas Metzler <ametzler@debian.org>  Fri, 14 Aug 2009 19:14:29 +0200
670
12.1.2 by Andreas Metzler, Simon Josefsson, Andreas Metzler
[ Simon Josefsson ]
671
gnutls26 (2.8.1-2) unstable; urgency=low
672
673
  [ Simon Josefsson ]
674
  * Remove cruft in rules file.
675
  * Remove patches/15_tasn1inpc.diff, not needed.
676
677
  [ Andreas Metzler ]
678
  * Finally add an entry to the NEWS.Debian file concerning the deprecation of
679
    RSA-MD2 and RSA-MD5 for signature verification. Closes: #514578
680
  * Upload to unstable.
681
  * 15_chainverify_expiredcert.diff: New patch, pulled from upstream GIT.
682
    Fix testsuite error caused by expired certificate.
683
684
 -- Andreas Metzler <ametzler@debian.org>  Thu, 06 Aug 2009 19:12:51 +0200
685
12.4.1 by Andreas Metzler
New upstream stable release.
686
gnutls26 (2.8.1-1) experimental; urgency=low
687
688
  * New upstream stable release.
689
690
 -- Andreas Metzler <ametzler@debian.org>  Thu, 11 Jun 2009 09:15:28 +0200
691
692
gnutls26 (2.7.14-1) experimental; urgency=low
693
694
  * [debian/control] set section setting of source package to libs instead of
695
    devel.
696
  * New upstream version.
697
    + Drop debian/patches/16_symbolversioning_fix.diff, included upstream.
698
    + Bump shlibs, new symbols added.
699
700
 -- Andreas Metzler <ametzler@debian.org>  Tue, 26 May 2009 19:51:41 +0200
701
702
gnutls26 (2.7.12-1) experimental; urgency=low
703
704
  * Fix typo in changelog. Closes: #526427
705
  * New upstream release.
706
    + Does not ship the scripts libgnutls-extra-config and libgnutls-config
707
      and the .m4 snippet to use it anymore. Please switch to pkg-config or
708
      standard autoconf test. Drop manpages and
709
      both patches/13_lessdeps_gnutls-config.diff and
710
      patches/13_lessdeps_gnutls-config.diff from the debian diff.
711
    + Update remaining patches.
712
    + Bump shlibs, new symbols added.
713
  * [patches/16_symbolversioning_fix.diff] Since gnutls_x509_crq_set_key was
714
    already present in 2.6.x it needs to be versioned GNUTLS_1_4 instead of
715
    GNUTLS_2_8.
716
  * New upstream uses separate ./configure scripts for the different
717
    libraries. Invoke the main ./configure script with
718
    --cache-file=$(CURDIR)/config.cache to speed things up.
719
720
 -- Andreas Metzler <ametzler@debian.org>  Thu, 21 May 2009 11:18:35 +0200
721
12.1.1 by Andreas Metzler
* use @LTLIBTASN1@ instead of @LIBTASN1@ in Libs.private of *.pc.in. This
722
gnutls26 (2.6.6-1) unstable; urgency=high
723
724
  * use @LTLIBTASN1@ instead of @LIBTASN1@ in Libs.private of *.pc.in. This
725
    way lib-link.m4 gives us -ltasn1 instead of /usr/lib/libtasn1.so.
726
  * New upstream security release.
727
    + libgnutls: Corrected double free on signature verification failure.
728
      GNUTLS-SA-2009-1 CVE-2009-1415
729
    + libgnutls: Fix DSA key generation. Noticed when investigating the
730
      previous GNUTLS-SA-2009-1 problem. All DSA keys generated using GnuTLS
731
      2.6.x are corrupt.  See the advisory for more details.
732
      GNUTLS-SA-2009-2 CVE-2009-1416
733
    + libgnutls: Check expiration/activation time on untrusted certificates.
734
      Before the library did not check activation/expiration times on
735
      certificates, and was documented as not doing so.
736
      GNUTLS-SA-2009-3 CVE-2009-1417
737
   * The former two issues only apply to gnutls 2.6.x. The latter is a
12.4.1 by Andreas Metzler
New upstream stable release.
738
     behavior change, add a NEWS.Debian file to document it.
12.1.1 by Andreas Metzler
* use @LTLIBTASN1@ instead of @LIBTASN1@ in Libs.private of *.pc.in. This
739
740
 -- Andreas Metzler <ametzler@debian.org>  Thu, 30 Apr 2009 19:00:21 +0200
741
13 by Andreas Metzler
* Sync sections in debian/control with override file. libgnutls26-dbg is
742
gnutls26 (2.6.5-1) unstable; urgency=low
743
744
  * Sync sections in debian/control with override file. libgnutls26-dbg is
745
    section debug, guile-gnutls is section lisp.
746
  * New upstream version. (Needed for Libtasn1-3 2.0)
747
  * New patch 15_tasn1inpc.diff. Make sure libtasn1 is listed in Libs.private.
748
  * Standards-Version: 3.8.1, no changes required.
749
750
 -- Andreas Metzler <ametzler@debian.org>  Tue, 14 Apr 2009 14:23:19 +0200
751
752
gnutls26 (2.6.4-2) unstable; urgency=low
753
754
  * Upload to unstable.
755
  * Merge changelog entries from unstable and experimental.
756
757
 -- Andreas Metzler <ametzler@debian.org>  Mon, 16 Feb 2009 16:43:37 +0100
758
759
gnutls26 (2.6.4-1) experimental; urgency=low
760
761
  * New upstream version.
762
763
 -- Andreas Metzler <ametzler@debian.org>  Sat, 07 Feb 2009 14:32:57 +0100
764
765
gnutls26 (2.6.3-1) experimental; urgency=low
766
767
  * New upstream version.
768
    + Corrects bug gnutls-cli which caused a rehandshake request
769
      to be ignored. Closes: #396867
770
  * Drop debian/patches/21_GNUTLS-SA-2008-3.fix.patch (included upstream)
771
772
 -- Andreas Metzler <ametzler@debian.org>  Sun, 21 Dec 2008 10:46:38 +0100
773
774
gnutls26 (2.6.2-2) experimental; urgency=low
775
 
776
  * 21_GNUTLS-SA-2008-3.fix.patch Another fix for the verification fix. Some
777
    correct certificate chains were not recognized as verified.
778
    Closes: #507633
779
  * [lintian] Add ${misc:Depends} to multiple dendency lines.
780
781
 -- Andreas Metzler <ametzler@debian.org>  Sat, 06 Dec 2008 13:31:58 +0100
782
783
gnutls26 (2.6.2-1) experimental; urgency=low
784
785
  * New upstream version.
786
    + Fixes certification verifaction error CVE-2008-4989. Closes: #505360
787
    + Drop 20_fix_501077.diff.
788
  * ia64 has guile-1.8 nowadays, let's try building the guile-gnutls wrappper
789
    there.
790
  * Add Simon Josefsson to uploaders.
791
792
 -- Andreas Metzler <ametzler@debian.org>  Thu, 13 Nov 2008 19:30:06 +0100
793
794
gnutls26 (2.6.0-1) experimental; urgency=low
795
796
  * New upstream stable release.
797
  * Add debian/patches/20_fix_501077.diff to fix an out of bound access in
798
    gnutls-openssl. (Thanks, Thomas Viehmann). Closes: #501077
799
800
 -- Andreas Metzler <ametzler@debian.org>  Sat, 25 Oct 2008 09:59:03 +0200
801
802
gnutls26 (2.5.9-1) experimental; urgency=low
803
804
  * New upstream development version.
805
  * Bump shlibs.
806
807
 -- Andreas Metzler <ametzler@debian.org>  Sat, 04 Oct 2008 12:40:01 +0200
808
12 by Andreas Metzler
* New patches, syncing with 2.4.3 upstream oldstable release:
809
gnutls26 (2.4.2-6) unstable; urgency=medium
810
811
  * New patches, syncing with 2.4.3 upstream oldstable release:
812
    + 24_intermedcertificate.patch If a non-root certificate ist trusted
813
      gnutls certificateificate verification stops there instead of checking
814
      up to the root of the certificate chain.
815
    + 22_whitespace.patch - Whitespace only changes, to make it possible to
816
      apply upstream fixes without manual changes. 
817
    + 25_bufferoverrun.patch. Fix buffer overrun bug in
818
      gnutls_x509_crt_list_import.
819
      http://news.gmane.org/find-root.php?message_id=%3c000001c91d6e%2463059c90%242910d5b0%24%40com%3e
820
821
 -- Andreas Metzler <ametzler@debian.org>  Sat, 07 Feb 2009 12:58:51 +0100
822
11 by Andreas Metzler
* Pull two patches from upstream stable branch to make gnutls behavior
823
gnutls26 (2.4.2-5) unstable; urgency=low
824
825
  * Pull two patches from upstream stable branch to make gnutls behavior
826
    match documentation:
827
   + patch 23_permit_v1_CA.diff:Accept v1 x509 CA
828
     certs if GNUTLS_VERIFY_ALLOW_ANY_X509_V1_CA_CRT and/or
829
     GNUTLS_VERIFY_ALLOW_X509_V1_CA_CRT were supplied. Closes: #509593
830
   + 22_deprecate_md2_md5_x509_validation.diff: Verifying untrusted X.509
831
     certificates signed with RSA-MD2 or RSA-MD5 will now fail with a
832
     GNUTLS_CERT_INSECURE_ALGORITHM verification output.
12.1.2 by Andreas Metzler, Simon Josefsson, Andreas Metzler
[ Simon Josefsson ]
833
     CVE-2009-2409
11 by Andreas Metzler
* Pull two patches from upstream stable branch to make gnutls behavior
834
835
 -- Andreas Metzler <ametzler@debian.org>  Sat, 31 Jan 2009 16:26:52 +0100
836
10 by Andreas Metzler
* Add Simon Josefsson to uploaders.
837
gnutls26 (2.4.2-4) unstable; urgency=medium
838
839
  * Add Simon Josefsson to uploaders.
840
  * Another fix for the verification fix. Some correct certificate chains were
841
    not recognized as verified. Closes: #507633
842
843
 -- Andreas Metzler <ametzler@debian.org>  Sat, 06 Dec 2008 12:09:33 +0100
844
9 by Andreas Metzler
Fix a crash on trying to verify self-signed certificates introduced by the
845
gnutls26 (2.4.2-3) unstable; urgency=low
846
847
  * Fix a crash on trying to verify self-signed certificates introduced by the
848
    patch for CVE-2008-4989. Closes: #505279
849
850
 -- Andreas Metzler <ametzler@debian.org>  Wed, 12 Nov 2008 19:23:23 +0100
851
8 by Andreas Metzler, CVE-2008-4989.diff
[CVE-2008-4989.diff] Fix man in the middle attack for certificate
852
gnutls26 (2.4.2-2) unstable; urgency=medium
853
854
  * [CVE-2008-4989.diff] Fix man in the middle attack for certificate
855
    verification. CVE-2008-4989 GNUTLS-SA-2008-3
856
857
 -- Andreas Metzler <ametzler@debian.org>  Mon, 10 Nov 2008 19:42:54 +0100
858
7 by Andreas Metzler
* New upstream bugfix release.
859
gnutls26 (2.4.2-1) unstable; urgency=low
860
861
  * New upstream bugfix release.
862
  * Up to date gnutls-cli manpage. Closes: #492775
863
8 by Andreas Metzler, CVE-2008-4989.diff
[CVE-2008-4989.diff] Fix man in the middle attack for certificate
864
 -- Andreas Metzler <ametzler@debian.org>  Sun, 21 Sep 2008 10:35:16 +0200
6 by Martin Pitt
Rebuild against thread-enabled guile-1.8.
865
5 by Andreas Metzler
New upstream version, fixing a local denial of service vulnerability only
866
gnutls26 (2.4.1-1) unstable; urgency=medium
867
868
  * New upstream version, fixing a local denial of service vulnerability only
869
    present in >= 2.3.5. GNUTLS-SA-2008-2  CVE-2008-2377
870
871
 -- Andreas Metzler <ametzler@debian.org>  Tue, 01 Jul 2008 19:35:51 +0200
872
4 by Andreas Metzler
* Standards version 3.8.0. Rename README.source_and_patches to README.source.
873
gnutls26 (2.4.0-2) unstable; urgency=low
874
875
  * Standards version 3.8.0. Rename README.source_and_patches to README.source.
876
  * Upload to unstable.
877
  * Point watchfile to stable releases again.
878
  * Merge experimental and unstable changelog.
879
880
 -- Andreas Metzler <ametzler@debian.org>  Tue, 24 Jun 2008 19:13:25 +0200
881
882
gnutls26 (2.4.0-1) experimental; urgency=low
883
884
  * New upstream stable release.
885
  * New APIs to retrieve fingerprint from OpenPGP subkeys. Bump shlibs.
886
887
 -- Andreas Metzler <ametzler@debian.org>  Wed, 18 Jun 2008 19:40:38 +0200
888
889
gnutls26 (2.3.15-1) experimental; urgency=low
890
891
  * New upstream version. (rc4)
892
    Disables 'openpgp-certs' tests. Closes: #486269
893
894
 -- Andreas Metzler <ametzler@debian.org>  Mon, 16 Jun 2008 19:08:24 +0200
895
896
gnutls26 (2.3.14-1) experimental; urgency=low
897
898
  * New upstream version. (rc3)
899
900
 -- Andreas Metzler <ametzler@debian.org>  Wed, 11 Jun 2008 19:16:18 +0200
901
902
gnutls26 (2.3.13-1) experimental; urgency=low
903
904
  * New upstream version. 2nd rc for 2.4.0.
905
  * Drop debian/patches/15_gnutls-pgpself.diff, included upstream.
906
907
 -- Andreas Metzler <ametzler@debian.org>  Sun, 08 Jun 2008 18:00:51 +0200
908
909
gnutls26 (2.3.12-1) experimental; urgency=low
910
911
  * New upstream version. Bump shlibs.
912
  * Ship doc/certtool.cfg in /usr/share/doc/gnutls-bin/examples. Closes: #483798
913
  * Add 15_gnutls-pgpself.diff (Pulled from upstream GIT), fixing testsuite
914
    failure on sparc.
915
916
 -- Andreas Metzler <ametzler@debian.org>  Thu, 05 Jun 2008 19:08:29 +0200
917
918
gnutls26 (2.3.11-1) experimental; urgency=low
919
920
  * New upstream version.
921
    + Fixes three security vulnerabilities.
922
      [GNUTLS-SA-2008-1-1] [GNUTLS-SA-2008-1-2] [GNUTLS-SA-2008-1-3]. See
923
      <http://www.gnu.org/software/gnutls/security.html>.
924
      CVE-2008-1948, CVE-2008-1949, CVE-2008-1950. DSA-1581-1
925
    + Fixes subjectAltName wildcard matching. Closes: #479174
926
    + certtool now writes keyfiles with 0600 permissions. Closes: #373169
927
928
 -- Andreas Metzler <ametzler@debian.org>  Sat, 24 May 2008 08:25:36 +0200
929
3 by Andreas Metzler, GNUTLS-SA-2008-1-1
New upstream version.
930
gnutls26 (2.2.5-1) unstable; urgency=high
931
932
  * New upstream version.
933
    Fixes three security vulnerabilities.
934
    [GNUTLS-SA-2008-1-1] [GNUTLS-SA-2008-1-2] [GNUTLS-SA-2008-1-3]. See
935
    <http://www.gnu.org/software/gnutls/security.html>.
936
    CVE-2008-1948, CVE-2008-1949, CVE-2008-1950. DSA-1581-1
937
938
 -- Andreas Metzler <ametzler@debian.org>  Tue, 20 May 2008 19:19:55 +0200
939
4 by Andreas Metzler
* Standards version 3.8.0. Rename README.source_and_patches to README.source.
940
gnutls26 (2.3.9-1) experimental; urgency=low
941
942
  * New upstream development version.
943
    - OpenPGP support merged into libgnutls and is now licensed under LGPL.
944
      The included copy of OpenCDK has been stripped down and re-licensed
945
      under the LGPL. Using the external OpenCDK is not supported anymore, the
946
      external library will not be maintained anymore. Drop respective
947
      (build-)depends.
948
    - API extended, bump shlibs.
949
    - certtool asks for password confirmation. Closes: #364287
950
    - performance enhancements for gnutls_certificate_set_x509_trust_file.
951
      Closes: #400448
952
    - gnutls-cli: exits when hostname doesn't match certificate.
953
      Use --insecure to avoid hostname comparison.
954
  * For paranoia sake build with -D_REENTRANT even if upstream has stopped
955
    doing so.
956
  * [debian/copyright] : update, and stop including a GFDL copy.
957
  * Point watchfile to development versions.
958
959
 -- Andreas Metzler <ametzler@debian.org>  Sat, 17 May 2008 16:56:04 +0200
960
3 by Andreas Metzler, GNUTLS-SA-2008-1-1
New upstream version.
961
gnutls26 (2.2.3-1) unstable; urgency=low
962
963
  * New upstream stable release.
964
    - --priority is documented in gnutls-cli(1) manpage. Closes: #467051
965
966
 -- Andreas Metzler <ametzler@debian.org>  Mon, 12 May 2008 18:29:12 +0200
967
2 by Andreas Metzler
* New upstream version. Release candidate for 2.2.3.
968
gnutls26 (2.2.3~rc-1) unstable; urgency=low
969
970
  * New upstream version. Release candidate for 2.2.3.
971
    + Increase default handshake packet size limit to 48kb. Closes: #478191
972
  * remove unsupported .l command from debian/libgnutls-config.1
973
  * Use Programming/C as doc-base section.
974
975
 -- Andreas Metzler <ametzler@debian.org>  Thu, 01 May 2008 13:09:49 +0200
976
977
gnutls26 (2.2.2-1) unstable; urgency=low
978
979
  * New upstream version.
980
    Corrected the behaviour of gnutls_x509_crt_get_subject_alt_name()
981
    and gnutls_x509_crt_get_subject_alt_name() to not null terminate binary
982
    strings and return the proper size.
983
    corrected string handling in parse_general_name.
984
    Closes: #465197
985
  * Point watchfile to ftp.gnutls.org.
986
  * Downgrade libtasn build-dep from 0.3.4-1 to 0.3.4-0.
987
988
 -- Andreas Metzler <ametzler@debian.org>  Fri, 22 Feb 2008 19:08:36 +0100
989
990
gnutls26 (2.2.1-3) unstable; urgency=low
991
992
  * Resurrect accidentally reverted fix for ftbfs on ia64. Do not try to build
993
    gnutls guile wrapper on ia64.
994
995
 -- Andreas Metzler <ametzler@debian.org>  Mon, 04 Feb 2008 19:14:03 +0100
996
997
gnutls26 (2.2.1-2) unstable; urgency=low
998
999
  * Add Vcs-Svn: and Vcs-Browser control fields.
1000
  * Upload to unstable.
1001
1002
 -- Andreas Metzler <ametzler@debian.org>  Sun, 03 Feb 2008 18:14:21 +0100
1003
1004
gnutls26 (2.2.1-1) experimental; urgency=low
1005
1006
  * New upstream version.
1007
  * guile-1.8 does not build on ia64. Stop trying to build the gnutls wrapper
1008
    there.
1009
  * libgnutls26-dbg needs to conflict with libgnutls13-dbg, since both
1010
    packages contain gnutls-bin debugging symbols. Closes: #459295.
1011
1012
 -- Andreas Metzler <ametzler@debian.org>  Sun, 20 Jan 2008 18:27:33 +0100
1013
1014
gnutls26 (2.2.0-1) experimental; urgency=low
1015
1016
  * New upstream version.
1017
    License change! Main library stays LGPLv2.1+ but libgnutls-extra,
1018
    libgnutls-openssl and the binaries are GPLv3+ now. debian/copyright is
1019
    updated.
1020
  * Stop linking agains liblzo2. Version 2.02 of this library if GPLv2 (older
1021
    versions were GPLv2+) and this license is not compatible with GPLv3+.
1022
  * Non packaged 2.1.8 introduced new symbol
1023
    gnutls_x509_crt_get_subject_alt_name2(), bump shlibs.
1024
  * Standards-Version: 3.7.3. ${binary:Version} instead of ${Source-Version}.
1025
  * Bump build-depends to libgcrypt11-dev >= 1.3.2, since it is needed for
1026
    DSA2 support. Closes: #455513
1027
  * Drop erraneous libgcrypt11 (>= 1.3.0) from b-d.
1028
1029
 -- Andreas Metzler <ametzler@debian.org>  Sat, 15 Dec 2007 16:41:54 +0100
1030
1031
gnutls26 (2.1.7-1) experimental; urgency=low
1032
1033
  * New upstream version.
1034
    - Another soname bump. Packages renamed.
1035
  * Continue using a repacked orig.tar.gz, instead of upstream's tar.bz2 since
1036
    dak does not allow that yet.
1037
  * Add Build-Conflicts: libgnutls-dev to stop libtool from linking
1038
    libgnutls-extra against libgnutls.so in /usr/lib/. Closes: #453035
1039
1040
 -- Andreas Metzler <ametzler@debian.org>  Sat,  1 Dec 2007 10:40:17 +0100
1041
1042
gnutls25 (2.1.6-2) experimental; urgency=low
1043
1044
  * Temporarily add libgcrypt11 (>= 1.3.0) to build-depends, to make
1045
    experimental buildds happy.
1046
1047
 -- Andreas Metzler <ametzler@debian.org>  Mon, 19 Nov 2007 18:58:48 +0100
1048
1049
gnutls25 (2.1.6-1) experimental; urgency=low
1050
1051
  * New upstream version. API changes! Please consult
1052
    /usr/share/doc/libgnutls-dev/NEWS.gz for the detailed list of deprecated,
1053
    removed (mainly *_authz_*) and changed interfaces.
1054
    This is the first release canddate for 2.2. The deprecation of
1055
    gnutls_set_default_priority() is supposed to be undone before the final
1056
    stable release.
1057
  * Bump build-depends.
1058
  * Stop building and shipping the C++ library, since nobody is using it. I
1059
    will happly re-add it if requested.
1060
  * Add Homepage field to debian/control.
1061
  * Build and ship Guile bindings. Requested by Ludovic Courtès who also
1062
    provided the initial patch. (On a sidenote I think guile generally does
1063
    not do the right thing by throwing dlopened modules into /usr/lib/.)
1064
  * Update debian/copyright.
1065
1066
 -- Andreas Metzler <ametzler@debian.org>  Sat, 17 Nov 2007 16:42:01 +0100
1067
1068
gnutls13 (2.0.1-1) unstable; urgency=low
1069
1070
  * New upstream version.
1071
  * Remove doc/*.info* on clean to allow building thrice in a row.
1072
    (Closes: #441740)
1073
1074
 -- Andreas Metzler <ametzler@debian.org>  Sat, 29 Sep 2007 11:29:22 +0200
1075
1076
gnutls13 (1.7.19-1) unstable; urgency=low
1077
1078
  * New upstream version 1.7.19.
1079
    - Fix gnutls_error_is_fatal so that positive "errors" are non-critical.
1080
      This takes of care of the mutt breakage. Closes: #439640
1081
1082
 -- Andreas Metzler <ametzler@debian.org>  Mon, 27 Aug 2007 19:36:23 +0200
1083
1084
gnutls13 (1.7.18-2) unstable; urgency=low
1085
1086
  * Upload to unstable
1087
1088
 -- Andreas Metzler <ametzler@debian.org>  Sat, 25 Aug 2007 09:27:18 +0200
1089
1090
gnutls13 (1.7.18-1) experimental; urgency=low
1091
1092
  * New upstream version 1.7.18, release candidate for 2.0.
1093
  * Bump shlibs, since functions have been added.
1094
  * Image files renamed upstream with gnutls- prefix and symlinked to
1095
    /usr/share/info/ in Debian package. Closes: #423577
1096
1097
 -- Andreas Metzler <ametzler@debian.org>  Sat, 18 Aug 2007 09:06:11 +0200
1098
1099
gnutls13 (1.7.16-1) experimental; urgency=low
1100
1101
  * New upstream version 1.7.16.
1102
1103
 -- Andreas Metzler <ametzler@debian.org>  Sat, 11 Aug 2007 10:50:21 +0200
1104
1105
gnutls13 (1.7.14-1) experimental; urgency=low
1106
1107
  * New upstream version
1108
    - fixes crash in gnutls-cli when TLS handshake fails. Closes: #429183
1109
1110
 -- Andreas Metzler <ametzler@debian.org>  Sat, 30 Jun 2007 09:06:35 +0200
1111
1112
gnutls13 (1.7.12-1) experimental; urgency=low
1113
1114
  * New upstream version 1.7.12
1115
    - Fixes memory errors in certificate parsing. Closes: #333050
1116
  * Bump shlibs, due to API extensions in 1.7.10.
1117
  * Rebuilding of docs simpified, strip debian/README.source_and_patches to
1118
    reflect that.
1119
1120
 -- Andreas Metzler <ametzler@debian.org>  Sat, 23 Jun 2007 11:14:26 +0200
1121
1122
gnutls13 (1.7.9-1) experimental; urgency=low
1123
1124
  * Switch to liblzo2. (Thanks, Peter Eisentraut) (Closes: #423332)
1125
  * New upstream version.
1126
    - Uses opencdk10 (0.6.x).
1127
    - Improved gnutls_set_default_priority() priorities, with matching correct
1128
      docs. (Closes: #422024)
1129
    - bumped shlibs.
1130
  * Do not delete doc/gnutls.pdf on clean, allowing to run dpkg-buildpackage
1131
    twice in a row on the same sourcetree. (Closes: #424357) Document what is
1132
    needed to rebuild doc/gnutls.pdf in README.source_and_patches.
1133
1134
 -- Andreas Metzler <ametzler@debian.org>  Mon, 28 May 2007 08:36:42 +0200
1135
1136
gnutls13 (1.7.7-1) experimental; urgency=low
1137
1138
  * New development upstream version 1.7.7.
1139
    - Point watchfile to development versions.
1140
    - Bump shlibs for added APIs.
1141
    - Includes German translation. (Closes: #392857)
1142
1143
 -- Andreas Metzler <ametzler@debian.org>  Sun, 15 Apr 2007 10:11:21 +0200
1144
1145
gnutls13 (1.6.3-1) unstable; urgency=low
1146
1147
  * New upstream version, pulling selected fixes and features from 1.7.x.
1148
  * Bump shlibs.
1149
1150
 -- Andreas Metzler <ametzler@debian.org>  Sun, 27 May 2007 09:26:14 +0200
1151
1152
gnutls13 (1.6.2-2) unstable; urgency=low
1153
1154
  * Switch to liblzo2. (Thanks, Peter Eisentraut) (Closes: #423332)
1155
1156
 -- Andreas Metzler <ametzler@debian.org>  Sun, 13 May 2007 09:48:31 +0200
1157
1158
gnutls13 (1.6.2-1) unstable; urgency=low
1159
1160
  * New upstream version
1161
    - Really Closes: #403887 libgnutls failes to parse OpenSSL generated
1162
      certificates, since it contains a regenerated pkix_asn1_tab.c.
1163
    - Ship German translation. Closes: #392857
1164
1165
 -- Andreas Metzler <ametzler@debian.org>  Sat, 21 Apr 2007 10:57:02 +0200
1166
1167
gnutls13 (1.6.1-2) unstable; urgency=low
1168
1169
  * [gnutls-bin.install] Ship psktool.
1170
  * Ship gettext translations in deb package, but as gnutls13.mo instead of
1171
    gnutls.mo.
1172
  * Upload to unstable. Merge branch1.5.x.EXP to svn trunk. Include 1.4.4-*
1173
    changelog entries after branchoff. Point watchfile to stable upstream
1174
    versions again.
1175
  * Drop dependency of libgnutls13-dbg on libgnutlsxx13.
1176
1177
 -- Andreas Metzler <ametzler@debian.org>  Sat,  3 Feb 2007 13:49:48 +0100
1178
1179
gnutls13 (1.6.1-1) experimental; urgency=low
1180
1181
  [ James Westby ]
1182
  * New upstream release.
1183
1184
 -- Andreas Metzler <ametzler@debian.org>  Sat,  3 Feb 2007 13:18:03 +0100
1185
1186
gnutls13 (1.6.0-1) experimental; urgency=low
1187
1188
  * New upstream version.
1189
1190
 -- Andreas Metzler <ametzler@debian.org>  Sat, 18 Nov 2006 13:21:56 +0100
1191
1192
gnutls13 (1.5.3-1) experimental; urgency=low
1193
1194
  [ Andreas Metzler ]
1195
  * Fix debian/copyright.
1196
    - Do not use "copyright" as title of a paragraph listing licenses.
1197
      (Closes: #290194)
1198
    - Add a copy of the FDL 1.2 to debian/copyright.
1199
  * New upstream version 1.5.3.
1200
  * Bump shlibs to get rid of reference to ugly 1.5.1.cvs2006093.
1201
  * Drop code for re-libtoolizing and running auto* from debian/rules, it is
1202
    unused and would not work anymore. (We can later grab the from SVN and
1203
    update it to make work if we ever need it.)
1204
1205
 -- Andreas Metzler <ametzler@debian.org>  Sat, 28 Oct 2006 12:56:46 +0200
1206
1207
gnutls13 (1.5.1.cvs20060930-1) experimental; urgency=low
1208
1209
  [ Andreas Metzler ]
1210
  * Add a watchfile.
1211
  * New upstream development version.
1212
    - Pulled from http://josefsson.org/daily/gnutls/gnutls-20060930.tar.gz
1213
    - Using a cvs snapshot instead of 1.5.1 because the soname in 1.5.1 was
1214
      broken.
1215
    - Drop unneeded patches/16_libs.private_gnutls.diff
1216
      patches/16_libs.private_gnutls-extra.diff
1217
    - Point watchfile to development versions.
1218
    - Builds a C++ library.
1219
  * Switch to debhelper v5 mode to be able to ship debug symbols of
1220
    libgnutls13 and libgnutlsxx13 in a common libgnutls13-dbg package.
1221
  * Branched off from 1.4.4-1.
1222
1223
 -- Andreas Metzler <ametzler@debian.org>  Sat, 30 Sep 2006 09:54:38 +0200
1224
1225
gnutls13 (1.4.4-3) unstable; urgency=low
1226
1227
  * Pulled /patches/18_negotiate_cypher.diff from 1.4.5:
1228
       When a GnuTLS server receive a SSLv2 Client Hello for an unknown TLS
1229
       version, try to negotiate the highest version support by the GnuTLS
1230
       server, instead of the lowest.
1231
1232
 -- Andreas Metzler <ametzler@debian.org>  Sat, 11 Nov 2006 10:35:29 +0100
1233
1234
gnutls13 (1.4.4-2) unstable; urgency=low
1235
1236
  [ Andreas Metzler ]
1237
  * Add a watchfile.
1238
  * Fix debian/copyright.
1239
    - Do not use "copyright" as title of a paragraph listing licenses.
1240
      (Closes: #290194)
1241
    - Add a copy of the FDL 1.2 to debian/copyright.
1242
1243
 -- Andreas Metzler <ametzler@debian.org>  Tue, 12 Sep 2006 19:57:49 +0200
1244
1245
gnutls13 (1.4.4-1) unstable; urgency=high
1246
1247
  [ Andreas Metzler ]
1248
  * New upstream version 1.4.4
1249
    - Updated fix for GNUTLS-SA-2006-4, that is not too strict and doesn't
1250
      crash mutt. (closes: #386725)
1251
      GNUTLS-SA-2006-4 is CVE-2006-4790.
1252
1253
 -- Andreas Metzler <ametzler@debian.org>  Tue, 12 Sep 2006 19:09:47 +0200
1254
1255
gnutls13 (1.4.3-2) unstable; urgency=low
1256
1257
  * the lesser of two weevils release.
1258
  [ Andreas Metzler ]
1259
  * Revert patch for GNUTLS-SA-2006-4 as it caused segmentation faults in
1260
    various programs, including mutt. (closes: #386680)
1261
1262
 -- Andreas Metzler <ametzler@debian.org>  Sat,  9 Sep 2006 19:29:52 +0200
1263
1264
gnutls13 (1.4.3-1) unstable; urgency=high
1265
1266
  [ Andreas Metzler ]
1267
  * New upstream version 1.4.3.
1268
    - Fix PKCS#1 verification to avoid a variant of Bleichenbacher's Crypto 06
1269
      rump session attack. GNUTLS-SA-2006-4
1270
    - Fix PKCS#1 decryption to avoid Bleichenbacher's Crypto 98 attack..
1271
      GNUTLS-SA-2006-3
1272
    - Fix crash in gnutls_x509_crt_sign2 if passed a NULL issuer_key.
1273
1274
 -- Andreas Metzler <ametzler@debian.org>  Fri,  8 Sep 2006 19:12:33 +0200
1275
1276
gnutls13 (1.4.2-1) unstable; urgency=medium
1277
1278
  [ Andreas Metzler ]
1279
  * New upstream bugfix release.
1280
    - Fixes a crash in the certificate verification logic.
1281
1282
 -- Andreas Metzler <ametzler@debian.org>  Sat, 12 Aug 2006 10:44:16 +0200
1283
1284
gnutls13 (1.4.1-1) unstable; urgency=low
1285
1286
  [ James Westby ]
1287
  * New upstream release.
1288
  * Remove the following patches as they are now included upstream:
1289
    - 10_certtoolmanpage.diff
1290
    - 15_fixcompilewarning.diff
1291
    - 30_man_hyphen_*.patch
1292
  * Link the API reference in /usr/share/gtk-doc/html as gnutls rather than
1293
    gnutls-api so that devhelp can find it.
1294
1295
 -- Andreas Metzler <ametzler@debian.org>  Sat, 15 Jul 2006 11:11:08 +0200
1296
1297
gnutls13 (1.4.0-3) unstable; urgency=low
1298
1299
  [ Andreas Metzler ]
1300
  * Strip "libgnutls-config --libs"' output to only list stuff required for
1301
    dynamic linking. (Closes: #375815). Document this in "libgnutls-dev's
1302
    README.Debian.
1303
  * Pull patches/16_libs.private_gnutls.diff and
1304
    debian/patches/16_libs.private_gnutls-extra.diff from upstream to make
1305
    pkg-config usable for static linking.
1306
1307
 -- Andreas Metzler <ametzler@debian.org>  Sun,  2 Jul 2006 12:10:56 +0200
1308
1309
gnutls13 (1.4.0-2) unstable; urgency=low
1310
1311
  [ Andreas Metzler ]
1312
  * Set maintainer to alioth mailinglist.
1313
  * Drop code for updating config.guess/config.sub from debian/rules, as cdbs
1314
    handles this. Build-Depend on autotools-dev.
1315
  * Drop build-dependency on binutils (>= 2.14.90.0.7), even sarge has 2.15-6.
1316
  * Use cdbs' simple-patchsys.mk.
1317
    - add debian/README.source_and_patches
1318
    - add patches/10_certtoolmanpage.diff  patches/12_lessdeps.diff
1319
  * Fix libgnutls-dev's Suggests to point to existing package. (gnutls-doc)
1320
  * Also ship css-, devhelp- and sgml files in gnutls-doc.
1321
  * patches/15_fixcompilewarning.diff correct order of funtion arguments.
1322
1323
  [ James Westby ]
1324
  * This release allows the port to be specified as the name of the service
1325
    when using gnutls-cli (closes: #342891)
1326
1327
 -- Andreas Metzler <ametzler@debian.org>  Sat, 17 Jun 2006 20:44:09 +0200
1328
1329
gnutls13 (1.4.0-1) experimental; urgency=low
1330
1331
  * New maintainer team. Thanks, Matthias for all the work you did.
1332
  * Re-add gnutls-doc package, featuring api-reference as manual pages and
1333
    html, and reference manual in html and pdf format.
1334
    (closes: #368185,#368449)
1335
  * Fix reference to gnutls0.4-doc package in debian/copyright. Update
1336
    debian/copyright and include actual copyright statements.
1337
    (closes: #369071)
1338
  * Bump shlibs because of changes to extra.h
1339
  * Drop debian/libgnutls13.dirs and debian/libgnutls-dev.dirs. dh_* will
1340
    generate the necessary directories.
1341
  * Drop debian/NEWS.Debian as it only talks about the move of the (since
1342
    purged) gnutls-doc package to contrib a long time ago.
1343
    (Thanks Simon Josefsson, for these suggestions.)
1344
  * new upstream version. (closes: #368323)
1345
  * clean packaging against upstream tarball.
1346
    - Drop all patches, except for fixing error in certtool.1 and setting
1347
      gnutls_libs=-lgnutls-extra in libgnutls-extra-config.
1348
    - Add  --enable-ld-version-script
1349
      to DEB_CONFIGURE_EXTRA_FLAGS to force versioning of symbols, instead of
1350
      patching ./configure.in.
1351
    (closes: #367358)
1352
  * Set DEB_MAKE_CHECK_TARGET = check to run included testsuite.
1353
  * Build against external libtasn1-3. (closes: #363294)
1354
  * Standards-Version: 3.7.2, no changes required.
1355
  * debian/control and override file are in sync with respect to Priority and
1356
    Section, everthing except libgnutls13-dbg already was. (closes: #366956)
1357
  * acknowledge my own NMU. (closes: #367065)
1358
  * libgnutls13-dbg is nonempty (closes: #367056)
1359
1360
 -- Andreas Metzler <ametzler@debian.org>  Sat, 20 May 2006 11:22:36 +0000
1361
1362
gnutls13 (1.3.5-1.1) unstable; urgency=low
1363
1364
  * NMU
1365
  * Invoke ./configure with --with-included-libtasn1 to prevent accidental
1366
    linking against the broken 0.3.1-1 upload of libtasn1-2-dev which
1367
    contained libtasn1.so.3 and force gnutls13 to use the internal version of
1368
    libtasn instead until libtasn1-3-dev is uploaded. Drop broken
1369
    Build-Depency on libtasn1-2-dev (>= 0.3.1).  (closes: #363294)
1370
  * Make libgnutls13-dbg nonempty by using --dbg-package=libgnutls13 instead
1371
    of --dbg-package=libgnutls12. (closes: #367056)
1372
1373
 -- Andreas Metzler <ametzler@debian.org>  Sat, 13 May 2006 07:45:32 +0000
1374
1375
gnutls13 (1.3.5-1) unstable; urgency=low
1376
1377
  * New Upstream version.
1378
    - Security fix.
1379
    - Yet another ABI change.
1380
  * Depends on libgcrypt 1.2.2, thus should close:#330019,#355272
1381
  * Let -dev package depend on liblzo-dev (closes:#347438)
1382
  * Fix certtool help output (closes:#338623)
1383
1384
 -- Matthias Urlichs <smurf@debian.org>  Sat, 18 Mar 2006 22:46:25 +0100
1385
1386
gnutls12 (1.2.9-2) unstable; urgency=low
1387
1388
  * Install /usr/lib/pkgconfig/*.pc files.
1389
  * Depend on texinfo (>= 4.8, for the @euro{} sign).
1390
1391
 -- Matthias Urlichs <smurf@debian.org>  Tue, 15 Nov 2005 19:26:02 +0100
1392
1393
gnutls12 (1.2.9-1) unstable; urgency=low
1394
1395
  * New Upstream version.
1396
1397
 -- Matthias Urlichs <smurf@debian.org>  Fri, 11 Nov 2005 18:51:28 +0100
1398
1399
gnutls12 (1.2.8-1) unstable; urgency=low
1400
1401
  * New Upstream version.
1402
    - depends on libgcrypt11 1.2.2
1403
  * Bumped shlibs version, just to be on the safe side.
1404
1405
 -- Matthias Urlichs <smurf@debian.org>  Wed, 19 Oct 2005 12:05:14 +0200
1406
1407
gnutls12 (1.2.6-1) unstable; urgency=low
1408
1409
  * New Upstream version.
1410
  * Remove Provides: on libgnutls11-dev.
1411
    Hopefully this will be temporary (pending discussion with Upstream).
1412
1413
 -- Matthias Urlichs <smurf@debian.org>  Thu, 11 Aug 2005 12:21:36 +0200
1414
1415
gnutls12 (1.2.5-3) unstable; urgency=high
1416
1417
  * Updated libgnutls12.shlibs file.
1418
    Thanks to Mike Paul <w5ydkaz02@sneakemail.com>.
1419
    Closes: #319291: libgnutls12: Wrong soversion in shlibs file; breaks
1420
                                  dependencies on this library
1421
1422
 -- Matthias Urlichs <smurf@debian.org>  Thu, 21 Jul 2005 13:19:25 +0200
1423
1424
gnutls12 (1.2.5-2) unstable; urgency=medium
1425
1426
  * Did not depend on libgnutls12 -- not picked up by dh_shlibdeps.
1427
    Added an explicit dependency as a stopgap fix.
1428
1429
 -- Matthias Urlichs <smurf@debian.org>  Thu, 21 Jul 2005 08:27:22 +0200
1430
1431
gnutls12 (1.2.5-1) unstable; urgency=low
1432
1433
  * Merged with the latest stable release.
1434
  * Renamed to gnutls12.
1435
    - Changed the library version strings to GNUTLS_1_2.
1436
    - Renamed the development package back to "libgnutls-dev".
1437
1438
 -- Matthias Urlichs <smurf@debian.org>  Tue,  5 Jul 2005 10:35:56 +0200
1439
1440
gnutls11 (1.0.19-1) experimental; urgency=low
1441
1442
  * Merged with the latest stable release.
1443
1444
 -- Matthias Urlichs <smurf@debian.org>  Sun, 26 Dec 2004 13:28:45 +0100
1445
1446
gnutls11 (1.0.16-13) unstable; urgency=high
1447
1448
  * Fixed an ASN.1 extraction error.
1449
    Found by Pelle Johansson <morth@morth.org>.
1450
1451
 -- Matthias Urlichs <smurf@debian.org>  Mon, 29 Nov 2004 10:16:21 +0100
1452
1453
gnutls11 (1.0.16-12) unstable; urgency=high
1454
1455
  * Fixed a segfault in certtool. Closes: #278361.
1456
1457
 -- Matthias Urlichs <smurf@debian.org>  Thu, 11 Nov 2004 09:40:02 +0100
1458
1459
gnutls11 (1.0.16-11) unstable; urgency=medium
1460
1461
  * Merged binary (non-UF8) string printing code from Upstream.
1462
  * Password code in certtool was somewhat broken.
1463
1464
 -- Matthias Urlichs <smurf@debian.org>  Sat,  6 Nov 2004 13:11:03 +0100
1465
1466
gnutls11 (1.0.16-10) unstable; urgency=high
1467
1468
  * Fixed one instance of uninitialized memory usage.
1469
1470
 -- Matthias Urlichs <smurf@debian.org>  Thu, 21 Oct 2004 06:07:53 +0200
1471
1472
gnutls11 (1.0.16-9) unstable; urgency=high
1473
1474
  * Pulled from Upstream CVS:
1475
    - Fix two memory leaks.
1476
    - Fix NULL dereference.
1477
1478
 -- Matthias Urlichs <smurf@debian.org>  Fri,  8 Oct 2004 10:43:20 +0200
1479
1480
gnutls11 (1.0.16-8) unstable; urgency=high
1481
1482
  * Pulled these changes from Upstream CVS:
1483
    - Added default limits in the verification of certificate chains,
1484
      to avoid denial of service attacks.
1485
    - Added gnutls_certificate_set_verify_limits() to override them.
1486
    - Added gnutls_certificate_verify_peers2().
1487
1488
 -- Matthias Urlichs <smurf@debian.org>  Sun, 12 Sep 2004 02:05:25 +0200
1489
1490
gnutls11 (1.0.16-7) unstable; urgency=low
1491
1492
  * Removed superfluous -lFOO entries from libgnutls{,-extra}-config output.
1493
    Thanks to joeyh@debian.org for reporting this problem.
1494
1495
 -- Matthias Urlichs <smurf@debian.org>  Sat, 14 Aug 2004 11:22:51 +0200
1496
1497
gnutls11 (1.0.16-6) unstable; urgency=medium
1498
1499
  * Memory leak, found by Modestas Vainius <geromanas@mailas.com>.
1500
    - Closes: #264420
1501
1502
 -- Matthias Urlichs <smurf@debian.org>  Sun,  8 Aug 2004 22:21:01 +0200
1503
1504
gnutls11 (1.0.16-5) unstable; urgency=low
1505
1506
  * Depend on current libtasn1-2 (>= 0.2.10).
1507
    - Closes: #264198.
1508
  * Fixed maintainer email to point to Debian address.
1509
1510
 -- Matthias Urlichs <smurf@debian.org>  Sat,  7 Aug 2004 19:44:38 +0200
1511
1512
gnutls11 (1.0.16-4) unstable; urgency=low
1513
1514
  * The OpenSSL compatibility library has been linked incorrectly
1515
    (-ltasn1 was missing).
1516
  * Need to build-depend on current opencdk8 and libtasn1-2 version.
1517
1518
 -- Matthias Urlichs <smurf@debian.org>  Sat,  7 Aug 2004 19:29:32 +0200
1519
1520
gnutls11 (1.0.16-3) unstable; urgency=high
1521
1522
  * Documentation no longer includes LaTeX-produced output
1523
    (the source contains latex2html-specific features, which is non-free).
1524
  * Urgency: High because of pending base freeze.
1525
1526
 -- Matthias Urlichs <smurf@debian.org>  Mon, 26 Jul 2004 11:18:20 +0200
1527
1528
gnutls11 (1.0.16-2) unstable; urgency=high
1529
1530
  * Actually *enable* debug symbols :-/
1531
  * Urgency: High for speedy inclusion in d-i
1532
1533
 -- Matthias Urlichs <smurf@debian.org>  Fri, 23 Jul 2004 22:38:07 +0200
1534
1535
gnutls11 (1.0.16-1) experimental; urgency=low
1536
1537
  * Update to latest Upstream version.
1538
  * now depends on libgcrypt11
1539
  * Include debugging package
1540
  * Use hevea, not latex2html.
1541
1542
 -- Matthias Urlichs <smurf@debian.org>  Wed, 21 Jul 2004 16:58:26 +0200
1543
1544
gnutls10 (1.0.4-4) unstable; urgency=low
1545
1546
  * New maintainer.
1547
  * Run autotools at source package build time.
1548
    - Closes: #257237: FTBFS (i386/sid): aclocal failed
1549
  * Remove "package is still changed upstream" warning.
1550
  * Build-Depend on debhelper 4.1 (cdbs), versioned libgcrypt7.
1551
1552
 -- Matthias Urlichs <smurf@debian.org>  Fri, 16 Jul 2004 02:09:36 +0200
1553
1554
gnutls10 (1.0.4-3) unstable; urgency=low
1555
1556
  * control: Changed the build dependency and the dependency of
1557
    libgnutls10-dev to be versioned on libopencdk8-dev >= 0.5.3;
1558
    libopencdk8-dev 0.5.1 had an invalid dependency on libgcrypt-dev which
1559
    could cause linking against two versions of libgcrypt.
1560
1561
 -- Ivo Timmermans <ivo@debian.org>  Sat, 24 Jan 2004 15:32:22 +0100
1562
1563
gnutls10 (1.0.4-2) unstable; urgency=low
1564
1565
  * libgnutls-doc.doc-base: Removed HTML manual listing.
1566
  * control: Removed Jordi Mallach from the list of Uploaders.  Thanks,
1567
    Jordi :)
1568
1569
 -- Ivo Timmermans <ivo@debian.org>  Wed, 14 Jan 2004 13:35:42 +0100
1570
1571
gnutls10 (1.0.4-1) unstable; urgency=low
1572
1573
  * New upstream release  (Closes: #227527)
1574
      * The new documentation in libgnutls-doc fixes several typo's and
1575
        style glitches:  
1576
        Closes: #215772: inconsistent auth method list in manual
1577
        Closes: #215775: dangling footnote on page 14 of manual
1578
        Closes: #215777: bad sentence on page 18 of manual
1579
        Closes: #215780: incorrect info about ldaps/imaps in manual
1580
  * rules:
1581
      * Use --add-missing instead of --force in the call to automake.
1582
      * Don't build gnutls.ps, use the upstream version.
1583
        (Closes: #224846)
1584
  * gnutls-bin.manpages: Use glob to find manpages.
1585
  * patches/008_manpages.diff: Removed; included upstream.
1586
1587
 -- Ivo Timmermans <ivo@debian.org>  Tue, 13 Jan 2004 23:57:16 +0100
1588
1589
gnutls10 (1.0.0-1) unstable; urgency=low
1590
1591
  * New upstream release.
1592
  * Major soversion changed to 10.
1593
  * control: Changed build dependencies of libtasn1-dev.
1594
  * libgnutls10.shlibs: Added libgnutls-openssl to the list.
1595
1596
 -- Ivo Timmermans <ivo@debian.org>  Mon, 29 Dec 2003 23:23:08 +0100
1597
1598
gnutls8 (0.9.99-1) experimental; urgency=low
1599
1600
  * New upstream release.
1601
  * Included upstream GPG signature in .orig.tar.gz.
1602
1603
 -- Ivo Timmermans <ivo@debian.org>  Wed,  3 Dec 2003 22:33:52 +0100
1604
1605
gnutls8 (0.9.98-1) experimental; urgency=low
1606
1607
  * New upstream release.
1608
  * debian/control: libgnutls8-dev depends on libopencdk8-dev.
1609
  * debian/libgnutls-doc.examples: Install src/*.[ch].
1610
1611
 -- Ivo Timmermans <ivo@debian.org>  Sun, 23 Nov 2003 15:44:38 +0100
1612
1613
gnutls8 (0.9.95-1) experimental; urgency=low
1614
1615
  * New upstream version.
1616
1617
 -- Ivo Timmermans <ivo@debian.org>  Fri,  7 Nov 2003 19:50:22 +0100
1618
1619
gnutls8 (0.9.94-1) experimental; urgency=low
1620
1621
  * New upstream version; package based on gnutls7 0.8.12-2.
1622
  * debian/control:
1623
      * Build-depend on libgcrypt7-dev (>= 1.1.44-0).
1624
  * debian/rules: Run auto* after the patches have been applied.
1625
1626
 -- Ivo Timmermans <ivo@debian.org>  Fri, 31 Oct 2003 18:47:09 +0100
1627
1628