Bug#873055: libgnutls30: Safe renegotiation breaks on session resumption with OpenSSL client

2017-08-24 Thread Thomas Klute
Package: libgnutls30 Version: 3.5.14-3 Severity: normal If the %SAFE_RENEGOTIATION flag is enabled in the priorities string of a GnuTLS server, Client Hellos from OpenSSL clients attempting session resumption are rejected with a "safe renegotiation failed" error, even though the client does

Bug#855933: mod-gnutls: FTBFS: Test failures

2017-03-05 Thread Thomas Klute
Hi Daniel, hi Lucas, I have pushed a suggested version 0.8.2-3 to the "for-debian" branch at commit 266c7750aa4c1a25089d3ad79e4b5359b9342214 in my Github repository [1]. I tried to keep the differences reasonably small, I hope the result is acceptable during the freeze. The set of changes

Bug#855933: GnuTLS 3.5.9 compatibility

2017-02-23 Thread Thomas Klute
From: Thomas Klute <thomas2.kl...@uni-dortmund.de> Date: Sun, 19 Feb 2017 18:57:56 +0100 Subject: [PATCH] Do not treat warnings about deprecated declarations as errors GnuTLS has declared OpenPGP support as deprecated in version 3.5.9. Treating deprecation warnings as errors causes the build t

Bug#855933: mod-gnutls: FTBFS: Test failures

2017-02-23 Thread Thomas Klute
These look like the timeout issues I discovered in the build logs for 0.8.2-2, see [1] for Daniel's report and [2] for my analysis, plus my two follow up mails if jessie-backports and hurd-i386 matter. I'm going to quote that mail below. Just a little clarification ahead: I've since confirmed

Bug#851384: Fixed upstream

2017-01-15 Thread Thomas Klute
This is a bug in the program which generates the OCSP database used in the failed test. I believe I have fixed this issue upstream in version 0.8.2. A build in a qemubuilder mips environment produced a correct test database.

Bug#848743: Build problem fixed in mod_gnutls 0.8.1

2016-12-20 Thread Thomas Klute
I have confirmed that the patch in my previous mail works on i386, and released mod_gnutls 0.8.1 to fix the build failures on 32 bit architectures.

Bug#848743: mod_gnutls 0.8.0-1 build failures

2016-12-20 Thread Thomas Klute
It looks like the test failures were cause by bug #848339, which was fixed in libunbound2 1.6.0-2. Relevant log excerpts: Setting up the build environment (libunbound2 version): > Selecting previously unselected package libunbound2:amd64. > Preparing to unpack

Bug#798396: Still present in 2.1.0-2

2016-04-18 Thread Thomas Klute
Control: found -1 2.1.0-2 This bug is still present in 2.1.0-2 according to the logs from buildd (https://buildd.debian.org/status/fetch.php?pkg=softhsm2=arm64=2.1.0-2=1459985395): > configure:4560: checking if we can compile in 64-bit mode > configure:4583: gcc -o conftest -m64 -Wdate-time

Bug#820235: SoftHSM2 support

2016-04-14 Thread Thomas Klute
Am 12.04.2016 um 18:38 schrieb Daniel Kahn Gillmor: > i'm aiming to get 0.7.3 into debian in the next couple days, sorry for > the delay! if you get 0.7.4 out the door before i get 0.7.3 into > debian, i'll just roll those changes together. I've just released version 0.7.4. If possible under

Bug#820235: SoftHSM2 support

2016-04-12 Thread Thomas Klute
Hi, this is the upstream mod_gnutls maintainer. The patch is not going to be enough to use SoftHSM 2, that would need a bunch of changes to the test environment setup as well. If the build doesn't fail with the patch, that's because the PKCS #11 test is skipped when "make check" cannot find a

Bug#514005: Patch available

2016-02-11 Thread Thomas Klute
I have a patch for this problem in my development repository [1], the fix will be included in mod_gnutls 0.7.3 (to be released soon). [1] https://github.com/airtower-luna/mod_gnutls/commit/8ac7c0dbd1357a8acadafc2aab8568bdebe7ae8f

Bug#642357: Fixed upstream & in unstable/testing

2016-02-10 Thread Thomas Klute
The test suite included in mod_gnutls since version 0.6 uses only connections from and to localhost, so it is safe to say that this bug is fixed.

Bug#813243: gnutls-bin: Broken Key Usage flags in certificates created with certtool

2016-01-30 Thread Thomas Klute
Package: gnutls-bin Version: 3.4.8-2 Severity: normal Tags: upstream patch I found that certtool writes broken Key Usage extensions to generated certificates. For example, when using the follwing template (from the mod_gnutls test suite) to create a CA, neither of the requested flags (certificate

Bug#785683: RFS: mod-gnutls/0.6-1.4 [NMU]

2015-05-19 Thread Thomas Klute
: * Fix segfaults with reverse proxy configuration (Closes: #775909) * Upgrade Standards-Version to 3.9.6, change DocumentRoot in default-tls.conf to /var/www/html accordingly. Regards, Thomas Klute [1] https://www.debian.org/security/2015/dsa-3177 -- To UNSUBSCRIBE, email to debian-bugs-dist

Bug#784961: JamVM: Relocation error on startup, JVM_GetResourceLookupCacheURLs undefined

2015-05-11 Thread Thomas Klute
Package: openjdk-8-jre-jamvm Version: 8u45-b14-2 Severity: important When trying to run a Java program with JamVM, the JVM fails to start with the following error message: java: relocation error: /usr/lib/jvm/java-8-openjdk-amd64/jre/lib/amd64/libjava.so: symbol JVM_GetResourceLookupCacheURLs,

Bug#766284: Still broken in version 8u45-b14-1

2015-05-08 Thread Thomas Klute
Control: found -1 8u45-b14-1 I still encountered this bug when testing the current version of openjdk-8-jre-jamvm in unstable on amd64 (8u45-b14-1). $ java -jamvm -version Error initialising VM (initialiseClassStage2) ClassBlock padding is less than java.lang.Class fields! Error: Could not

Bug#775909: Seeking sponsor for patched package

2015-04-20 Thread Thomas Klute
For the record: I have uploaded a source package containing my patches to mentors.debian.net [1] as version 0.6-1.4 and am looking for a sponsor for it (or comments if improvements are necessary). [1] https://mentors.debian.net/package/mod-gnutls -- To UNSUBSCRIBE, email to

Bug#635711: Still broken in monkeysphere 0.37-2 on sid

2015-02-19 Thread Thomas Klute
I still see this bug in monkeysphere 0.37-2 on sid (fresh stable install, upgrade through testing to unstable). Aptitude installation: Setting up monkeysphere (0.37-2) ... adding monkeysphere user... ms: setting up Monkeysphere authentication trust core... Failed running transition script

Bug#578663: libapache2-mod-gnutls: GnuTLSClientVerify require is ignored.

2015-02-17 Thread Thomas Klute
5a8a32bbfb8a83fe6358c5c31c443325a7775fc2 Mon Sep 17 00:00:00 2001 From: Thomas Klute thomas2.kl...@uni-dortmund.de Date: Thu, 5 Feb 2015 14:48:45 +0100 Subject: [PATCH] TLS Client auth: Check server verify mode if unset for dir The authentication hook (mgs_hook_authz) failed to consider the server's client verify mode, even

Bug#775909: libapache2-mod-gnutls: segfaults with reverse proxy configuration

2015-01-21 Thread Thomas Klute
3d361b8e5d7c4c971d344658728979fe978dc759 Mon Sep 17 00:00:00 2001 From: Thomas Klute thomas2.kl...@uni-dortmund.de Date: Tue, 13 Jan 2015 17:04:38 +0100 Subject: [PATCH] Check if filters exist before removing them in ssl_engine_disable Trying to remove filters that are NULL leads to a segfault

Bug#766284: openjdk-8-jre-jamvm: JamVM fails with incorrect ClassBlock padding

2014-10-21 Thread Thomas Klute
Package: openjdk-8-jre-jamvm Version: 8u40~b09-1 Severity: important Any attempt to use JamVM, even just checking the version, results in failure with the following error message: $ java -jamvm -version Error initialising VM (initialiseClassStage2) ClassBlock padding is less than java.lang.Class

Bug#754942: jtreg uses /usr/lib/jvm/default-java/ but does not depend on default-jre-headless

2014-07-16 Thread Thomas Klute
Package: jtreg Version: 4.1-2 Severity: important While trying to compile the experimental openjdk-8 package from source, the jtreg test suite completely failed to run with the error message Cannot determine version of java to run jtreg. I found that the reason was that jtreg expects to find a

Bug#754942: jtreg uses /usr/lib/jvm/default-java/ but does not depend on default-jre-headless

2014-07-16 Thread Thomas Klute
Hi Emmanuel! Am 16.07.2014 11:15, schrieb Emmanuel Bourg: jtreg doesn't depend on a Java runtime because it can use the JDK being tested to run. This is done by setting the JT_JAVA environment variable (or JAVA_HOME with jtreg 4.1-2 in Wheezy). I know, but the openjdk-8 build doesn't do that

Bug#742864: Build without nostrip fails on weezy, another try for debian/control generation

2014-07-11 Thread Thomas Klute
Am 08.07.2014 14:13, schrieb Emmanuel Bourg: Le 08/07/2014 11:47, Thomas Klute a écrit : Compiling with the same build system (plus freshly generated debian/control) in a sid chroot works just fine. I'm not sure if this should be considered important for OpenJDK 8 packaging (looks more like

Bug#742864: Build without nostrip fails on weezy, another try for debian/control generation

2014-07-08 Thread Thomas Klute
Compiling on wheezy fails unless nostrip is set in DEB_BUILD_OPTIONS: dh_strip -s -Nopenjdk-8-8-jre-cacao -Nopenjdk-8-8-jre-jamvm \ -Xlibjvm.so --dbg-package=openjdk-8-dbg objcopy:debian/openjdk-8-jdk/usr/lib/jvm/java-8-openjdk-amd64/bin/stEZfrnA: cannot create debug link

Bug#742864: Update to jdk8u20-b18

2014-06-21 Thread Thomas Klute
Am 18.06.2014 14:55, schrieb Emmanuel Bourg: Even if removing the generated files could avoid mistakes like updating the control file but not its template, I lean toward keeping them for the convenience. Checking out the package and not seeing debian/control could also be confusing. I

Bug#742864: Update to jdk8u20-b18

2014-06-18 Thread Thomas Klute
Am 17.06.2014 22:08, schrieb Emmanuel Bourg: Le 17/06/2014 20:09, Thomas Klute a écrit : * g++-4.9 was a hardcoded build dependency, but is not available on stable. I could build the package with g++-4.7 from Wheezy, so I've changed the dependency to g++ = 4.7. Actually debian/control

Bug#751873: fakeupstream.cgi rejects hg repository URLs containing numbers

2014-06-17 Thread Thomas Klute
Package: qa.debian.org Severity: normal While trying to check for the latest version in the OpenJDK 8 upstream repository, I found that fakeupstream.cgi would not accept hg repository URLs containing numbers before the project name part (after the last slash in the URL). Upstream repository URL:

Bug#742864: Update to jdk8u20-b18

2014-06-17 Thread Thomas Klute
Hi everyone, I've cloned Emmanuel's repository and worked with it on Wheezy (amd64). Results so far: * I've updated the build system to work with the newest upstream version (jdk8u29-b18). Refreshing the patches was fairly straightforward, but I'd be great if someone with more knowledge of