[Pkg-gnutls-commits] r964 - in /packages/gnutls26/trunk/debian:	changelog libgnutls26.NEWS
    ametzler at users.alioth.debian.org 
    ametzler at users.alioth.debian.org
       
    Sun Feb  6 14:50:55 UTC 2011
    
    
  
Author: ametzler
Date: Sun Feb  6 14:50:53 2011
New Revision: 964
URL: http://svn.debian.org/wsvn/pkg-gnutls/?sc=1&rev=964
Log:
[merge r872 from branch2.9.x] [lintian] reformat NEWS entry.
Modified:
    packages/gnutls26/trunk/debian/changelog
    packages/gnutls26/trunk/debian/libgnutls26.NEWS
Modified: packages/gnutls26/trunk/debian/changelog
URL: http://svn.debian.org/wsvn/pkg-gnutls/packages/gnutls26/trunk/debian/changelog?rev=964&op=diff
==============================================================================
--- packages/gnutls26/trunk/debian/changelog (original)
+++ packages/gnutls26/trunk/debian/changelog Sun Feb  6 14:50:53 2011
@@ -1,13 +1,12 @@
-gnutls26 (2.9.12-2) UNRELEASED; urgency=low
-
-  * NOT RELEASED YET
+gnutls26 (2.9.12-2) experimental; urgency=low
+
   * Work around gcc-4.4 bug <http://bugs.debian.org/519006> by building
     without -g on mips/mipsel. (As a side effect this makes libgnutls26-dbg a
     useless and almost empty package on these archs.)
   * Drop ancient workaround for gcc bug on hppa.
     http://bugs.debian.org/128036
 
- -- Andreas Metzler <ametzler at debian.org>  Thu, 17 Jun 2010 19:35:27 +0200
+ -- Andreas Metzler <ametzler at debian.org>  Sat, 19 Jun 2010 14:38:22 +0200
 
 gnutls26 (2.9.12-1) experimental; urgency=low
 
Modified: packages/gnutls26/trunk/debian/libgnutls26.NEWS
URL: http://svn.debian.org/wsvn/pkg-gnutls/packages/gnutls26/trunk/debian/libgnutls26.NEWS?rev=964&op=diff
==============================================================================
--- packages/gnutls26/trunk/debian/libgnutls26.NEWS (original)
+++ packages/gnutls26/trunk/debian/libgnutls26.NEWS Sun Feb  6 14:50:53 2011
@@ -1,25 +1,25 @@
 gnutls26 (2.6.6-1) unstable; urgency=high
 
-  * libgnutls: Check expiration/activation time on untrusted certificates.
-    Before the library did not check activation/expiration times on
-    certificates, and was documented as not doing so. We have realized that
-    many applications that use libgnutls, including gnutls-cli, fail to
-    perform proper checks.  Implementing similar logic in all applications
-    leads to code duplication.  Hence, we decided to check whether the
-    current time (as reported by the time function) is within the
-    activation/expiration period of certificates when verifying untrusted
-    certificates.
+  libgnutls: Check expiration/activation time on untrusted certificates.
+  Before the library did not check activation/expiration times on
+  certificates, and was documented as not doing so. We have realized that
+  many applications that use libgnutls, including gnutls-cli, fail to
+  perform proper checks.  Implementing similar logic in all applications
+  leads to code duplication.  Hence, we decided to check whether the
+  current time (as reported by the time function) is within the
+  activation/expiration period of certificates when verifying untrusted
+  certificates.
 
-    This changes the semantics of gnutls_x509_crt_list_verify, which in
-    turn is used by gnutls_certificate_verify_peers and
-    gnutls_certificate_verify_peers2.  We add two new
-    gnutls_certificate_status_t codes for reporting the new error
-    condition, GNUTLS_CERT_NOT_ACTIVATED and GNUTLS_CERT_EXPIRED.  We also
-    add a new gnutls_certificate_verify_flags flag,
-    GNUTLS_VERIFY_DISABLE_TIME_CHECKS, that can be used to disable the new
-    behaviour.
-    GNUTLS-SA-2009-3 CVE-2009-1417
-    http://www.gnu.org/software/gnutls/security.html
+  This changes the semantics of gnutls_x509_crt_list_verify, which in
+  turn is used by gnutls_certificate_verify_peers and
+  gnutls_certificate_verify_peers2.  We add two new
+  gnutls_certificate_status_t codes for reporting the new error
+  condition, GNUTLS_CERT_NOT_ACTIVATED and GNUTLS_CERT_EXPIRED.  We also
+  add a new gnutls_certificate_verify_flags flag,
+  GNUTLS_VERIFY_DISABLE_TIME_CHECKS, that can be used to disable the new
+  behaviour.
+  GNUTLS-SA-2009-3 CVE-2009-1417
+  http://www.gnu.org/software/gnutls/security.html
 
  -- Andreas Metzler <ametzler at debian.org>  Thu, 30 Apr 2009 19:00:21 +0200
 
    
    
More information about the Pkg-gnutls-commits
mailing list