Re: [PATCH] [www] - spell 'X.509' consistently when talking about the standard

2021-10-08 Thread Raf Czlonka
Could someone "do it", please? ;^)

Regards,

Raf

On Fri, Oct 08, 2021 at 04:13:16PM BST, Theo de Raadt wrote:
> do it
> 
> Raf Czlonka  wrote:
> 
> > On Wed, Oct 06, 2021 at 11:50:01PM BST, Raf Czlonka wrote:
> > > Hello,
> > > 
> > > Outside of X509_* functions, filenames, openssl(1) commands, etc.
> > > there are places where the spelling of 'X.509' could be made
> > > consistent when talking about the standard.
> > 
> > I realise the patch might have been too long so how about only the
> > upcoming release page for now?
> > 
> > Cheers,
> > 
> > Raf
> > 
> > Index: 70.html
> > ===
> > RCS file: /cvs/www/70.html,v
> > retrieving revision 1.82
> > diff -u -p -r1.82 70.html
> > --- 70.html 8 Oct 2021 03:44:52 -   1.82
> > +++ 70.html 8 Oct 2021 09:11:34 -
> > @@ -567,7 +567,7 @@ to 7.0.
> > roa-sets.
> > In RRDP, limited the number of deltas to 300 per repo. If more 
> > deltas
> >exist, downloading a full snapshot is faster.
> > -   Limited the validation depth of X509 certificate chains to 12, 
> > double
> > +   Limited the validation depth of X.509 certificate chains to 12, 
> > double
> >the current depth seen in RPKI.
> >  
> >  
> > @@ -687,7 +687,7 @@ to 7.0.
> >  New Features
> >  
> >Added support for OpenSSL 1.1.1 TLSv1.3 APIs.
> > -  Enabled the new x509 validator to allow verification of modern 
> > certificate chains.
> > +  Enabled the new X.509 validator to allow verification of modern 
> > certificate chains.
> >  
> >  
> >  Portable Improvements
> > @@ -750,12 +750,12 @@ to 7.0.
> >  
> >Added additional state machine test coverage.
> >Improved integration test support with ruby/openssl tests.
> > -  Error codes and callback support in new x509 validator made 
> > compatible with p5-Net_SSLeay tests.
> > +  Error codes and callback support in new X.509 validator made 
> > compatible with p5-Net_SSLeay tests.
> >  
> >  
> >  Internal Improvements
> >  
> > -  Numerous fixes and improvements to the new X509 validator to 
> > ensure compatible error codes
> > +  Numerous fixes and improvements to the new X.509 validator to 
> > ensure compatible error codes
> > and callback support compatible with the legacy OpenSSL validator.
> >  
> >  
> > 



Re: [PATCH] [www] - spell 'X.509' consistently when talking about the standard

2021-10-08 Thread Raf Czlonka
On Wed, Oct 06, 2021 at 11:50:01PM BST, Raf Czlonka wrote:
> Hello,
> 
> Outside of X509_* functions, filenames, openssl(1) commands, etc.
> there are places where the spelling of 'X.509' could be made
> consistent when talking about the standard.

I realise the patch might have been too long so how about only the
upcoming release page for now?

Cheers,

Raf

Index: 70.html
===
RCS file: /cvs/www/70.html,v
retrieving revision 1.82
diff -u -p -r1.82 70.html
--- 70.html 8 Oct 2021 03:44:52 -   1.82
+++ 70.html 8 Oct 2021 09:11:34 -
@@ -567,7 +567,7 @@ to 7.0.
roa-sets.
In RRDP, limited the number of deltas to 300 per repo. If more 
deltas
   exist, downloading a full snapshot is faster.
-   Limited the validation depth of X509 certificate chains to 12, 
double
+   Limited the validation depth of X.509 certificate chains to 12, 
double
   the current depth seen in RPKI.
 
 
@@ -687,7 +687,7 @@ to 7.0.
 New Features
 
   Added support for OpenSSL 1.1.1 TLSv1.3 APIs.
-  Enabled the new x509 validator to allow verification of modern 
certificate chains.
+  Enabled the new X.509 validator to allow verification of modern 
certificate chains.
 
 
 Portable Improvements
@@ -750,12 +750,12 @@ to 7.0.
 
   Added additional state machine test coverage.
   Improved integration test support with ruby/openssl tests.
-  Error codes and callback support in new x509 validator made 
compatible with p5-Net_SSLeay tests.
+  Error codes and callback support in new X.509 validator made 
compatible with p5-Net_SSLeay tests.
 
 
 Internal Improvements
 
-  Numerous fixes and improvements to the new X509 validator to ensure 
compatible error codes
+  Numerous fixes and improvements to the new X.509 validator to ensure 
compatible error codes
and callback support compatible with the legacy OpenSSL validator.
 
 



[PATCH] [www] - spell 'X.509' consistently when talking about the standard

2021-10-06 Thread Raf Czlonka
Hello,

Outside of X509_* functions, filenames, openssl(1) commands, etc.
there are places where the spelling of 'X.509' could be made
consistent when talking about the standard.

Regards,

Raf

Index: plus29.html
===
RCS file: /cvs/www/plus29.html,v
retrieving revision 1.87
diff -u -p -r1.87 plus29.html
--- plus29.html 19 Sep 2021 19:22:16 -  1.87
+++ plus29.html 6 Oct 2021 22:46:22 -
@@ -199,7 +199,7 @@ For changes in other releases, click bel
 Avoid losing RTC after suspend/resume on some laptops.
 Repair an integer conversion bug in https://man.openbsd.org/pms.4;>pms(4) which fixes the mouse 
resolution setting in X.
 Fix non-TCP protocol mappings in https://man.openbsd.org/ipnat.4;>ipnat(4).
-In https://man.openbsd.org/isakmpd.8;>isakmpd(8), encode X509 
expirations into KeyNote credientials/policies.
+In https://man.openbsd.org/isakmpd.8;>isakmpd(8), encode 
X.509 expirations into KeyNote credientials/policies.
 In https://man.openbsd.org/pppoe.8;>pppoe(8), try every BPF 
device, not just even-numbered ones.
 Support -C flag in https://man.openbsd.org/nm.1;>nm(1).
 Update ISC https://man.openbsd.org/cron.8;>cron(8) to 4.0b1, 
maintaining our local changes, including signal handling fixes.
Index: plus30.html
===
RCS file: /cvs/www/plus30.html,v
retrieving revision 1.65
diff -u -p -r1.65 plus30.html
--- plus30.html 19 Sep 2021 19:22:16 -  1.65
+++ plus30.html 6 Oct 2021 22:46:22 -
@@ -455,7 +455,7 @@ For changes in other releases, click bel
 New https://man.openbsd.org/md5.1;>md5(1) implementation with 
a BSD copyright and other improvements; includes regression test.
 Improve https://man.openbsd.org/swapctl.8;>swapctl(8).
 Don't allow packets that need https://man.openbsd.org/ipsec.4;>IPsec(4) processing to be 
bridge-broadcast.
-Expand handling of X509 and KeyNote certificates in https://man.openbsd.org/isakmpd.8;>isakmpd(8).
+Expand handling of X.509 and KeyNote certificates in https://man.openbsd.org/isakmpd.8;>isakmpd(8).
 Fix some https://man.openbsd.org/tcp.4;>tcp(4) behaviour with 
connections in the CLOSING state.
 Some https://man.openbsd.org/ld.so.1;>ld.so(1) renovations.
 Repair https://man.openbsd.org/kqueue.2;>kqueue(2) related 
panic.
Index: plus55.html
===
RCS file: /cvs/www/plus55.html,v
retrieving revision 1.32
diff -u -p -r1.32 plus55.html
--- plus55.html 19 Sep 2021 19:22:17 -  1.32
+++ plus55.html 6 Oct 2021 22:46:22 -
@@ -712,7 +712,7 @@ For changes in other releases, click bel
 https://man.openbsd.org/iked.8;>iked(8) now drops duplicate 
requests, to avoid corrupt child-SA tables.
 Made https://man.openbsd.org/iked.8;>iked(8) discard & free 
duplicate IKESAs; made sure new SAs are not created that cannot be inserted in 
the SA tree.
 Include hexdump in https://man.openbsd.org/iked.8;>iked(8) 
debug output only for -vvv.
-Support raw pubkey authentication w/o x509 certificates in https://man.openbsd.org/iked.8;>iked(8).
+Support raw pubkey authentication w/o X.509 certificates in https://man.openbsd.org/iked.8;>iked(8).
 When https://man.openbsd.org/wpi.4;>wpi(4) has a fatal 
firmware error, reset the chip, reload the firmware and bring the interface up 
again.
 Limit the number of envelopes to recall in the https://man.openbsd.org/smtpd.8;>smtpd(8) hoststat cache.
 Removed some double frees in https://man.openbsd.org/fuse.4;>fuse(4).
@@ -808,7 +808,7 @@ For changes in other releases, click bel
 Made https://man.openbsd.org/athn.4;>athn(4) tick calculation 
work as intended. Should fix excessive timeouts and "Michael mic" errors.
 Cope with the EAGAIN API change for https://man.openbsd.org/msgbuf_write.3;>msgbuf_write(3) in various 
daemons.
 Improvements for https://man.openbsd.org/sppp.4;>sppp(4) 
address assignment and related issues in IPv6CP; deal with IFID collisions 
instead of ignoring them; use https://man.openbsd.org/arc4random.3;>arc4random(3) during IFID 
generation; assign destination address to /128 point-to-point links.
-Fixed https://man.openbsd.org/isakmpd.8;>isakmpd(8) parameter 
types for x509 routines.
+Fixed https://man.openbsd.org/isakmpd.8;>isakmpd(8) parameter 
types for X.509 routines.
 Be more specific in https://man.openbsd.org/ksh.1;>ksh(1) 
ulimit error messages.
 Fixed ^C handling in miniroot.
 
@@ -892,7 +892,7 @@ For changes in other releases, click bel
 Enabled TX checksum offload in https://man.openbsd.org/jme.4;>jme(4).
 Removed unnecessary spinlock that slowed down https://man.openbsd.org/pthread_getspecific.3;>pthread_getspecific(3).
 Use curve25519 for default https://man.openbsd.org/sshd.8;>sshd(8) key exchange 
(curve25519-sha...@libssh.org).
-Let https://man.openbsd.org/ssh.1;>ssh(1) support pkcs#11 
tokens that only provide x509 certificates instead of raw pubkeys (fixes 
bz#1908).
+Let