OpenSSL Security Advisory

2024-06-27 Thread Matt Caswell
Additional analysis was provided by David Benjamin (Google). The fix was developed by Matt Caswell. General Advisory Notes == URL for this Security Advisory: https://www.openssl.org/news/secadv/20240627.txt Note: the online version of the advisory may be updated with additional de

[openssl/technical-policies] 9aaea0: Record Nicola's vote

2024-06-18 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 9aaea0fd5f8453c6f2d68562d780c52e7aa08718 https://github.com/openssl/technical-policies/commit/9aaea0fd5f8453c6f2d68562d780c52e7aa08718 Author: Matt Caswell Date: 2024-06-18 (Tue, 18 Jun 2024

[openssl/technical-policies] e99a4d: Record Kurt's vote and correct the issue link

2024-06-14 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: e99a4d4b8112d70da47bf5d81712756d76bcf343 https://github.com/openssl/technical-policies/commit/e99a4d4b8112d70da47bf5d81712756d76bcf343 Author: Matt Caswell Date: 2024-06-14 (Fri, 14 Jun 2024

[openssl/technical-policies] 01ced1: Add AES-XTS optimization vote

2024-06-04 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 01ced135b96e585df33a89151feb65bf7325e4c3 https://github.com/openssl/technical-policies/commit/01ced135b96e585df33a89151feb65bf7325e4c3 Author: Matt Caswell Date: 2024-06-04 (Tue, 04 Jun 2024

OTC Vote: Allow the backport of the AES-XTS optimization on Power platform

2024-06-04 Thread Matt Caswell
OTC members who were not present in today's meeting please vote on the following topic: Topic: Allow the backport of the AES-XTS optimization on Power platform as per #24531 to all branches back to 3.0 subject to the standard review process normal review process Please place your votes here:

[openssl/technical-policies] 61a970: Correct issue link in vote

2024-06-03 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 61a97034868bcc026acd955d0996834a964a7a1c https://github.com/openssl/technical-policies/commit/61a97034868bcc026acd955d0996834a964a7a1c Author: Matt Caswell Date: 2024-06-03 (Mon, 03 Jun 2024

OpenSSL Security Advisory

2024-05-28 Thread Matt Caswell
c88c3de510 (for 3.2), commit 704f725b96 (for 3.1) and commit b3f0eb0a29 (for 3.0) in the OpenSSL git repository. It is available to premium support customers in commit f7a045f314 (for 1.1.1). This issue was reported on 10th April 2024 by William Ahern (Akamai). The fix was developed by Matt Caswell and

OTC VOTE: FIPS indicator design

2024-05-28 Thread Matt Caswell
OTC members who were not present in today's OTC meeting, please vote on the following: Topic: OTC approve the FIPS indicator design presented in PR#23609 subject to the normal review process Please record your votes here: https://github.com/openssl/technical-policies/issues/95 Matt

[openssl/technical-policies] 0acf9e: Add FIPS indicators vote

2024-05-28 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 0acf9e537ae5a0831da2a8094204bc4701ced54d https://github.com/openssl/technical-policies/commit/0acf9e537ae5a0831da2a8094204bc4701ced54d Author: Matt Caswell Date: 2024-05-28 (Tue, 28 May 2024

Re: Design Contributions?

2022-11-02 Thread Matt Caswell
Hi Randall, The logo is managed by the OpenSSL Management Committee (OMC): https://www.openssl.org/community/omc.html I'm not sure we were necessarily looking for a new logo, but if you have some ideas for alternatives we'd love to see them. You can contact the OMC by emailing osf-cont...@ope

New Blog Post: CVE-2022-3786 and CVE-2022-3602: X.509 Email Address Buffer Overflows

2022-11-01 Thread Matt Caswell
Please see the new blog post here: https://www.openssl.org/blog/blog/2022/11/01/email-address-overflows/ OpenPGP_0xD9C4D26D0E604491.asc Description: OpenPGP public key OpenPGP_signature Description: OpenPGP digital signature

[openssl/technical-policies] 95b43d: Correct summary total in a vote

2022-10-18 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 95b43d3949d5dc28c119069a9613db21a6ebe645 https://github.com/openssl/technical-policies/commit/95b43d3949d5dc28c119069a9613db21a6ebe645 Author: Matt Caswell Date: 2022-10-18 (Tue, 18 Oct 2022

[openssl/technical-policies] 27e90c: Close a vote

2022-10-18 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 27e90c5a782bdc500efa0c86d5e625740b4c54f8 https://github.com/openssl/technical-policies/commit/27e90c5a782bdc500efa0c86d5e625740b4c54f8 Author: Matt Caswell Date: 2022-10-18 (Tue, 18 Oct 2022

Withdrawal of OpenSSL 3.0.6 and 1.1.1r

2022-10-12 Thread Matt Caswell
We have received a report of a significant regression in the latest 3.0.6 and 1.1.1r versions. The regression is not thought to have security consequences. While the regression is further investigated we have taken the decision to withdraw the 3.0.6 and 1.1.1r versions and instead recommend that

OpenSSL Security Advisory

2022-10-11 Thread Matt Caswell
Supercomputing Center. The fix was developed by Matt Caswell. References == URL for this Security Advisory: https://www.openssl.org/news/secadv/20221011.txt Note: the online version of the advisory may be updated with additional details over time. For details of OpenSSL severity

OpenSSL version 3.0.6 published

2022-10-11 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 3.0.6 released == OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 3.0.6 of our open source

OpenSSL version 1.1.1r published

2022-10-11 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 1.1.1r released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.1.1r of our open sour

[openssl/technical-policies] 4d4adb: Start a vote on PR17984

2022-10-11 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 4d4adbb1222a01924656f14def143a9327ac253d https://github.com/openssl/technical-policies/commit/4d4adbb1222a01924656f14def143a9327ac253d Author: Matt Caswell Date: 2022-10-11 (Tue, 11 Oct 2022

OTC VOTE: OTC considers PR#17984 as a bug fix

2022-10-11 Thread Matt Caswell
OTC members please vote on the following issue: https://github.com/openssl/technical-policies/issues/55 Matt

Forthcoming OpenSSL Releases

2022-10-04 Thread Matt Caswell
Hello, The OpenSSL project team would like to announce the forthcoming release of OpenSSL versions 3.0.6 and 1.1.1r. These releases will be made available on Tuesday 11th October 2022 between 1300-1700 UTC. OpenSSL 3.0.6 is a security-fix release. The highest severity issue fixed in OpenSSL 3.

OMC VOTE: Provider ABI testing

2022-09-14 Thread Matt Caswell
Vote called on https://github.com/openssl/general-policies/pull/27 Matt

OpenSSL 3.0 FIPS 140-2 Validation Certificate Issued

2022-08-24 Thread Matt Caswell
Please read the blog post about this here: https://www.openssl.org/blog/blog/2022/08/24/FIPS-validation-certificate-issued/ Matt

Monthly Status Report (July)

2022-08-04 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up and sprint planning meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, responding to public github issues, CLA submissions, handling security repo

[openssl/technical-policies] e83bed: Record vote results

2022-08-02 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: e83bed7a99ddb318c4e21008f86405a744f291cc https://github.com/openssl/technical-policies/commit/e83bed7a99ddb318c4e21008f86405a744f291cc Author: Matt Caswell Date: 2022-08-02 (Tue, 02 Aug 2022

[openssl/technical-policies] 22c31c: Record some votes

2022-08-01 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 22c31c1a4d4c7edb6880225b17b00302576551ab https://github.com/openssl/technical-policies/commit/22c31c1a4d4c7edb6880225b17b00302576551ab Author: Matt Caswell Date: 2022-08-01 (Mon, 01 Aug 2022

[openssl/technical-policies] 257a19: Start vote for deprecate long and add notes on int...

2022-07-25 Thread Matt Caswell
Branch: refs/heads/master Home: https://github.com/openssl/technical-policies Commit: 257a198460f3c5333f12e141af187b0cbdf905b0 https://github.com/openssl/technical-policies/commit/257a198460f3c5333f12e141af187b0cbdf905b0 Author: Matt Caswell Date: 2022-07-25 (Mon, 25 Jul 2022

OTC VOTE: Deprecate long and add notes on integer types

2022-07-25 Thread Matt Caswell
Topic: Deprecate long and add notes on integer types Proposed by: Matt Caswell Issue link: https://github.com/openssl/technical-policies/pull/51 Public: yes Opened: 2022-07-25 Closed: -MM-DD Accepted: yes/no (for: X, against: Y, abstained: Z, not voted: W) Dmitry [ ] Matt

Monthly Status Report (June)

2022-07-18 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up and sprint planning meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, responding to public github issues, CLA submissions, handling security repo

OpenSSL Security Advisory

2022-06-21 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL Security Advisory [21 June 2022] The c_rehash script allows command injection (CVE-2022-2068) Severity: Moderate In addition to the c_reh

OpenSSL version 3.0.4 published

2022-06-21 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 3.0.4 released == OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 3.0.4 of our open source

OpenSSL version 1.1.1p published

2022-06-21 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 1.1.1p released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.1.1p of our open sour

Proposal to stop supporting Windows XP and Windows Server 2003 from OpenSSL 3.1

2022-06-08 Thread Matt Caswell
There was some discussion during the OMC meeting today about stopping Windows XP and Windows Server 2003 support. No decision was made but it led me to write up this proposal: https://github.com/openssl/general-policies/issues/22 I'm not calling an actual vote yet just gathering feedback. P

OpenSSL is looking to hire a Platform Engineer

2022-06-08 Thread Matt Caswell
OpenSSL is looking to hire a Platform Engineer (a sysadmin role). Details of the role are here: https://www.openssl.org/blog/blog/2022/05/30/hiring-platform-engineer/ Matt

Monthly Status Report (May)

2022-06-02 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up and sprint planning meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, responding to public github issues, CLA submissions, handling security repo

Re: HPKE PR process question

2022-06-01 Thread Matt Caswell
On 23/05/2022 22:41, Stephen Farrell wrote: Hi, Back in November 2021 (~6 months ago) I created a PR [1] suggesting an implementation of RFC 9180. In discussion, the  "need OMC decision" tag was added to the PR on Dec 14th. Since then, I have heard nothing at all and so far as I can see, fr

Re: HPKE PR process question

2022-05-25 Thread Matt Caswell
Acknowledging receipt of this. We'll get back to you on it. Matt On 23/05/2022 22:41, Stephen Farrell wrote: Hi, Back in November 2021 (~6 months ago) I created a PR [1] suggesting an implementation of RFC 9180. In discussion, the  "need OMC decision" tag was added to the PR on Dec 14th. Sin

OpenSSL is looking to hire a Business Operations Administrator

2022-05-19 Thread Matt Caswell
Please see the following blog post for details of the role: https://www.openssl.org/blog/blog/2022/05/18/hiring-business-operations-administrator/ Matt

Monthly Status Report (April)

2022-05-04 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, CLA submissions, handling security reports, etc., key activities this month: Started looking a

OMC VOTE: Accept the security policy

2022-05-04 Thread Matt Caswell
: Accept the security policy as of 53b2fdfc640960da03ab9519e27de6c0fefe7dd6 Proposed by: Matt Caswell Issue link: https://github.com/openssl/general-policies/pull/18 Public: yes Opened: 2022-05-04 Closed: -MM-DD Accepted: yes/no (for: X, against: Y, abstained: Z, not voted: W) Kurt

OpenSSL Security Advisory

2022-05-03 Thread Matt Caswell
s issue was reported to OpenSSL on the 6th April 2022 by Raul Metsma. The fix was developed by Matt Caswell from OpenSSL. Incorrect MAC key used in the RC4-MD5 ciphersuite (CVE-2022-1434) = Severity: Low The OpenSSL 3.0 implement

OpenSSL version 1.1.1o published

2022-05-03 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 1.1.1o released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.1.1o of our open sour

OpenSSL version 3.0.3 published

2022-05-03 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 3.0.3 released == OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 3.0.3 of our open source

Re: Forthcoming OpenSSL Releases

2022-04-26 Thread Matt Caswell
: https://www.openssl.org/policies/secpolicy.html#moderate Yours The OpenSSL Project Team On 19/04/2022 20:51, Matt Caswell wrote: The OpenSSL project team would like to announce the forthcoming release of OpenSSL versions 3.0.3 and 1.1.1o. These releases will be made available on Tuesday 26th

Forthcoming OpenSSL Releases

2022-04-19 Thread Matt Caswell
The OpenSSL project team would like to announce the forthcoming release of OpenSSL versions 3.0.3 and 1.1.1o. These releases will be made available on Tuesday 26th April 2022 between 1300-1700 UTC. These are security-fix releases. The highest severity issue fixed in these releases is MODERATE: h

Monthly Status Report (March)

2022-04-01 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, CLA submissions, handling security reports, etc., key activities this month: Wrote the QUIC SS

OTC VOTE: Accept the technical requirements document

2022-03-25 Thread Matt Caswell
Topic: Accept the technical requirements document provided in openssl/openssl#17577 OTC members please cast your votes here: https://github.com/openssl/technical-policies/issues/37 Matt

Re: OMC VOTE: Extend the primary platforms support

2022-03-22 Thread Matt Caswell
Due to a procedural issue this vote has been restarted. OMC members should cast their vote here (even if they previously voted on this): https://github.com/openssl/general-policies/issues/12 Matt On 02/03/2022 10:54, Matt Caswell wrote: The proposal is: We should add linux-x86, linux

OpenSSL Security Advisory

2022-03-15 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL Security Advisory [15 March 2022] Infinite loop in BN_mod_sqrt() reachable when parsing certificates (CVE-2022-0778) ==

OpenSSL version 1.1.1n published

2022-03-15 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 1.1.1n released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.1.1n of our open sour

OpenSSL version 3.0.2 published

2022-03-15 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 3.0.2 released == OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 3.0.2 of our open source

Re: Auto github PR script and 3.0

2022-03-14 Thread Matt Caswell
That script should really be moved to the tools repo. Also I think there are a large number of PRs which the script isn't pinging at the moment, but which are completely stale and haven't been touched (for years in some cases). Perhaps we could have a "no activity" ping...and after so long of

Re: Auto github PR script and 3.0

2022-03-14 Thread Matt Caswell
On 14/03/2022 10:29, Mark J Cox wrote: We have a script that runs daily and makes sure things needing action for OTC/OMC are pinged if they get old. It also autocloses issues where it was waiting for the reporter with no action, or waiting for a NDA for a significant amount of time. I assume

Forthcoming OpenSSL releases

2022-03-08 Thread Matt Caswell
The OpenSSL project team would like to announce the forthcoming release of OpenSSL versions 3.0.2 and 1.1.1n. These releases will be made available on Tuesday 15th March 2022 between 1300-1700 UTC. These are security-fix releases. The highest severity issue fixed in these releases is HIGH: https

OpenSSL 3.0 LTS

2022-03-04 Thread Matt Caswell
OpenSSL 3.0 has recently been designated as a Long Term Support (LTS) release. This means that it will now be supported until 7th September 2026 (5 years after its initial release). Our previous LTS release (1.1.1) will continue to be supported until 11th September 2023. We encourage all use

OMC VOTE: Extend the primary platforms support

2022-03-02 Thread Matt Caswell
The proposal is: We should add linux-x86, linux-generic32 and linux-generic64 as primary platforms in the platform policy OMC members should vote here: https://github.com/openssl/general-policies/issues/12

Monthly Status Report (February)

2022-03-01 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, CLA submissions, handling security reports, etc., key activities this month: Worked on Proof o

Please welcome our newest committer

2022-02-25 Thread Matt Caswell
I am pleased to be able to welcome Todd Short as the newest member of the OpenSSL committer team. Todd has been a long time member of the OpenSSL community and already has many commits to his name. Welcome on board! Matt

OMC VOTE: The next LTS release

2022-02-16 Thread Matt Caswell
The OMC vote for the following proposal has now started: "We should announce that the next LTS release will be 3.0" OMC members please cast your votes here: https://github.com/openssl/general-policies/issues/9 Matt

Monthly Status Report (January)

2022-02-03 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, CLA submissions, handling security reports, etc., key activities this month: Created a PR to c

OMC Vote for the policy change process has started

2022-02-02 Thread Matt Caswell
The OMC vote for this policy proposal has now started. OMC members please cast your votes here: https://github.com/openssl/general-policies/pull/2 Matt

OpenSSL Security Advisory

2022-01-28 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL Security Advisory [28 January 2022] === BN_mod_exp may produce incorrect results on MIPS (CVE-2021-4160) Severity: Moderate There is a

OTC Vote for the voting policy update

2022-01-28 Thread Matt Caswell
The OTC vote for this policy proposal has now started. OTC members please cast your votes here: https://github.com/openssl/technical-policies/pull/17 Matt

OMC Vote for the voting policy has started

2022-01-25 Thread Matt Caswell
The OMC vote for this policy proposal has now started. OMC members please cast your votes here: https://github.com/openssl/general-policies/pull/1 Matt

OTC Vote for the testing policy has started

2022-01-25 Thread Matt Caswell
The OTC vote for this policy proposal has now started. OTC members please cast your votes here: https://github.com/openssl/technical-policies/pull/13 Matt

Monthly Status Report (December)

2022-01-10 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, CLA submissions, handling security reports, etc., key activities this month: - Attended many Q

OpenSSL Security Advisory

2021-12-14 Thread Matt Caswell
. Users of this version should upgrade to OpenSSL 3.0.1. OpenSSL 1.1.1 and 1.0.2 are not affected by this issue. This issue was reported to OpenSSL on 29th November 2021 by Tobias Nießen. The fix was developed by Matt Caswell and Tobias Nießen. Note OpenSSL 1.0.2 is out of support and no

OpenSSL version 3.0.1 published

2021-12-14 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 3.0.1 released == OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 3.0.1 of our open source

OpenSSL version 1.1.1m published

2021-12-14 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 1.1.1m released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.1.1m of our open sour

Testing policy

2021-12-13 Thread Matt Caswell
See this PR for a first pass attempt at writing a testing policy: https://github.com/openssl/technical-policies/pull/13 Matt

Re: OTC VOTE: Accept PR #16705 into 3.0

2021-12-08 Thread Matt Caswell
I forgot I was now supposed to record these votes as issues in the technical policies repository. I have now done so: https://github.com/openssl/technical-policies/issues/12 Matt On 07/12/2021 10:35, Matt Caswell wrote: topic: Accept PR #16705 into 3.0 subject to the normal review process

Support and Stability Policy

2021-12-08 Thread Matt Caswell
I've created a proposal for an OMC support and Stability Policy here: https://github.com/openssl/general-policies/pull/3 This is intended to be complementary to the OTC's Stable Release Update's Policy currently in review here: https://github.com/openssl/technical-policies/pull/8 The content

General policy drafts

2021-12-08 Thread Matt Caswell
The OTC have previously created policies for how voting and policy updates should occur. The policies are here: https://github.com/openssl/technical-policies/blob/master/policies/voting-procedure.md https://github.com/openssl/technical-policies/blob/master/policies/policy-change-process.md I'v

Forthcoming OpenSSL Releases

2021-12-07 Thread Matt Caswell
The OpenSSL project team would like to announce the forthcoming release of OpenSSL versions 1.1.1m and 3.0.1. These releases will be made available on Tuesday 14th December 2021 between 1300-1700 UTC. OpenSSL 3.0.1 is a security and bug fix release. The highest severity issue fixed in this rele

OTC VOTE: Accept PR #16705 into 3.0

2021-12-07 Thread Matt Caswell
topic: Accept PR #16705 into 3.0 subject to the normal review process Proposed by Matt Caswell Public: yes opened: 2021-12-07 closed: 2021-12-07 accepted: yes (for: 4, against: 1, abstained: 3, not voted: 2) Dmitry [+0] Matt [+1] Pauli [-0] Tim[-1] Richard

Re: Starting the QUIC Design

2021-12-03 Thread Matt Caswell
Event Loop Design https://github.com/openssl/pull/17185 -Original Message- From: openssl-users On Behalf Of Matt Caswell Sent: Friday, December 3, 2021 1:05 PM To: openssl-project@openssl.org; openssl-us...@openssl.org Subject: Starting the QUIC Design Please see my blog post on

Starting the QUIC Design

2021-12-03 Thread Matt Caswell
Please see my blog post on starting the QUIC design here: https://www.openssl.org/blog/blog/2021/12/03/starting-the-quic-design/ Matt

Monthly Status Report (November)

2021-12-03 Thread Matt Caswell
As well as normal reviews, attending regular OMC and OTC meetings, attending daily stand up meetings, responding to user queries, wiki user requests, OMC business, sys-admin, support customer issues, CLA submissions, handling security reports, etc., key activities this month: - Investigated an

OTC vote for the assembler optimisations policy

2021-11-30 Thread Matt Caswell
The OTC vote for this policy proposal has now started. OTC members please cast your votes here: https://github.com/openssl/technical-policies/pull/9 Matt

New Blog Post

2021-11-25 Thread Matt Caswell
Please see the new blog post by Tim Hudson giving an update on the OpenSSL Project. https://www.openssl.org/blog/blog/2021/11/25/openssl-update/ Matt

Vote on the design process policy

2021-11-23 Thread Matt Caswell
As per our new policy voting procedure the vote on the design process policy is now open in this PR: https://github.com/openssl/technical-policies/pull/3 Matt

Re: OTC VOTE: Accept Policy change process proposal

2021-11-01 Thread Matt Caswell
+1 On 01/11/2021 10:23, Tomas Mraz wrote: topic: Accept openssl/technical-policies PR#1 - the policy change process proposal as of commit 3bccdf6. This will become an official OTC policy. comment: This will implement the formal policy change process so we can introduce and amend further policie

Proposed design process policy

2021-11-01 Thread Matt Caswell
I have proposed a new policy for creating designs here: https://github.com/openssl/technical-policies/pull/3 Please take a look. It would be good to discuss this at tomorrow's OTC. Matt

Monthly Status Report (October)

2021-11-01 Thread Matt Caswell
As well as normal reviews, responding to user queries, wiki user requests, OMC business, support customer issues, CLA submissions, handling security reports, etc., key activities this month: - Numerous OMC related tasks - Investigated issue with RSA and padding with RSA_PKCS1_WITH_TLS_PADDING - I

Re: OTC VOTE: Accept PR#16725

2021-10-20 Thread Matt Caswell
I have now closed this vote: topic: Accept PR#16725 as a bug fix for backport into 3.0 subject to the normal review process Proposed by Matt Caswell Public: yes opened: 2021-10-19 closed: 2021-10-20 accepted: yes (for: 4, against: 2, abstained: 4, not voted: 0) Dmitry [+0

Re: OTC VOTE: Accept PR#16725

2021-10-20 Thread Matt Caswell
your decision. Cheers, Nicola On Tue, Oct 19, 2021 at 9:10 PM Kurt Roeckx wrote: On Tue, Oct 19, 2021 at 11:07:26AM +0100, Matt Caswell wrote: topic: Accept PR#16725 as a bug fix for backport into 3.0 subject to the normal review process So we have various people voting -1. Does someone want to explain why they vote -1? Kurt

OTC VOTE: Accept PR#16725

2021-10-19 Thread Matt Caswell
topic: Accept PR#16725 as a bug fix for backport into 3.0 subject to the normal review process Proposed by Matt Caswell Public: yes opened: 2021-10-19 closed: 2021-mm-dd accepted: yes/no (for: X, against: Y, abstained: Z, not voted: T) Dmitry [+0] Matt [+1] Pauli

OMC Release Requirements

2021-10-13 Thread Matt Caswell
FYI, the OMC have agreed the attached release requirements document. Matt # OMC Release Requirements This document provides information on the OMC requirements and expectations for the next release after 3.0 and subsequent releases. ## Release timeframe The OMC objective is to have shorter rel

Agenda for the next OTC meeting

2021-10-12 Thread Matt Caswell
My proposed agenda for the next OTC meeting (2021-10-19): 1) Nominate a minute taker and confirm agenda 2) Review policy process strawman 3) PR #16725 4) Agree agenda for next meeting 5) AOB Matt

Monthly Status Report (September)

2021-10-05 Thread Matt Caswell
As well as normal reviews, responding to user queries, wiki user requests, OMC business, support customer issues, CLA submissions, handling security reports, etc., key activities this month: - Significant amount of time spent on various OMC tasks this month - Prepared various website updates read

Re: Blog post about FIPS submission

2021-09-23 Thread Matt Caswell
On 23/09/2021 21:51, Kurt Roeckx wrote: On Thu, Sep 23, 2021 at 09:42:01PM +0200, Dmitry Belyavsky wrote: Hello Matt, The link https://csrc.nist.gov/projects/cryptographic-module-validation-program/modules-in-processmodules-in-process-list (You can see the official listing for the submission

Blog post about FIPS submission

2021-09-23 Thread Matt Caswell
FYI, please see my blog post about the OpenSSL 3 FIPS submission here: https://www.openssl.org/blog/blog/2021/09/22/OpenSSL3-fips-submission/ Matt

OTC VOTE: Increase the default security level from 1 to 2

2021-09-21 Thread Matt Caswell
topic: Increase the default security level from 1 to 2 in master Proposed by Matt Caswell Public: yes opened: 2021-09-21 closed: 2021-09-21 accepted: yes (for: 7, against: 1, abstained: 1, not voted: 1) Dmitry [+1] Matt [+1] Pauli [+1] Tim[+0] Richard[+1

OTC VOTE: Restart merging of non-breaking small features

2021-09-14 Thread Matt Caswell
topic: Allow the restart of merging of non-breaking small features to the master branch Proposed by Matt Caswell Public: yes opened: 2021-09-14 closed: 2021-09-14 accepted: yes (for: 5, against: 1, abstained: 1, not voted: 2) Dmitry [+1] Matt [+1] Pauli [ ] Tim

Monthly Status Report (August)

2021-09-06 Thread Matt Caswell
As well as normal reviews, responding to user queries, wiki user requests, OMC business, support customer issues, CLA submissions, handling security reports, etc., key activities this month: - Implemented the (extended) patch CVE-2021-3712 as well as significant analysis time spent on this issue

Re: OTC vote: branching 3.0

2021-08-31 Thread Matt Caswell
+1 On 31/08/2021 10:15, Dr Paul Dale wrote: topic: Create `openssl-3.0' git branch today. comment: This cascades to other names/version information on GitHub. For example, change the release version information in the master branch to 3.1.0-dev Proposed by Pauli. Public: yes

Re: OTC vote: release of 3.0.0

2021-08-31 Thread Matt Caswell
+1 On 31/08/2021 09:47, Dr Paul Dale wrote: topic: /Release 3.0.0 final on Tuesday the 7th of September 2021 if run-checker and CI builds have been clean for two days./ Proposed by Pauli. Public: yes opened: 2021-08-31 closed: 2021-08-31 accepted:  yes  (for: 8, against: 0, abstained:

OpenSSL Security Advisory

2021-08-24 Thread Matt Caswell
essed before the final release. This issue was reported to OpenSSL on 12th August 2021 by John Ouyang. The fix was developed by Matt Caswell. Read buffer overruns processing ASN.1 strings (CVE-2021-3712) = Severity: Moderate ASN.1 stri

OpenSSL version 1.1.1l published

2021-08-24 Thread Matt Caswell
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 OpenSSL version 1.1.1l released === OpenSSL - The Open Source toolkit for SSL/TLS https://www.openssl.org/ The OpenSSL project team is pleased to announce the release of version 1.1.1l of our open sour

Update on 3.0 release

2021-08-24 Thread Matt Caswell
FYI, OTC met today to discuss the 3.0 final release. Due to the security release taking place later today they decided that 3.0 final will not be released this week. Matt

Forthcoming OpenSSL release

2021-08-17 Thread Matt Caswell
The OpenSSL project team would like to announce the forthcoming release of OpenSSL version 1.1.1l. This release will be made available on Tuesday 24th August 2021 between 1200-1600 UTC. OpenSSL 1.1.1l is a security-fix release. The highest severity issue fixed in this release is HIGH: https://ww

  1   2   3   4   5   6   7   >