[Touch-packages] [Bug 2003903] Re: [BPO] openssl/3.0.5-2ubuntu2 from kinetic

2023-01-25 Thread Mark Pruett
Thomas and Marc, thanks for the guidance and time spent here. :) I'll look into the SRU process. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/2003903 Title: [BPO]

[Touch-packages] [Bug 2003903] [NEW] [BPO] openssl/3.0.5-2ubuntu2 from kinetic

2023-01-25 Thread Mark Pruett
Public bug reported: Humbly requesting backporting OpenSSL 3.0.5-2ubuntu2 from kinetic to jammy. [Impact] >From the OpenSSL 3.0 migration guide: (https://www.openssl.org/docs/man3.0/man7/migration_guide.html) "Secure renegotiation is now required by default for TLS connections Support for RFC

[Touch-packages] [Bug 1963834] Re: openssl 3.0 - SSL: UNSAFE_LEGACY_RENEGOTIATION_DISABLED]

2023-01-25 Thread Mark Pruett
Can we reopen this and potentially backport OpenSSL 3.0.5 from kinetic to jammy? The "UnsafeLegacyServerConnect" option was mentioned above in #3. Unfortunately, that option was documented but not implemented in the 3.0.2 OpenSSL release available in the jammy repos. (See