· @doboprobodyne
28 followers · 607 posts · Server mathstodon.xyz

@kkarhan @animemer @thecatcollective

runs servers and computers at and other high-reliability-requirement institutions.

It gave rise to and which I believe windows 10 uses to improve your parents' security online.

was developed for defence application and now runs everything from to signalling networks to

The same is also true for and which drive rockets into space. There are many programs involved in rocketry at the highest levels, both civil and martial.

Perhaps most importantly to parents, these are things you can exploit freely, a torch passed to you by others, free as in speech, a tool to better command whatever hardware you elect to use.

I hope you succeed in providing some food for thought about different ways to achieve success ;)

#opensource #rtems #freertos #autopilots #railway #missiles #dod #ada #libressl #openssh #banks #openbsd

Last updated 1 year ago

Felix Palmen 📯 · @zirias
10 followers · 29 posts · Server techhub.social

@stefano , mostly because I tried it, liked it, even started contributing to it quickly and never felt the need to look at a different one so far 🙈

I even use a customized build (leaving out things from base I don't use like e.g. sendmail or tcsh) and build all ports using instead of , both is perfectly supported (except for the occassional build issues of some ports with LibreSSL, which are most of the time an easy fix....)

#freebsd #libressl #openssl

Last updated 1 year ago

GateLinker · @gatelinker
8 followers · 48 posts · Server fosstodon.org

O-Ha! has published an update release v1.1.1u some days ago too.
Old OpenSSL is the only library I can use to support antique platforms like or with their native compilers without additional patches.
Support for 1.1.1 will be dropped this year, and for all new stuff I already use .

I saw a macro named OPENSSL_SYS_UEFI during review for the first time. So they already have pure builds somewhere.

How could I have missed that so long?
I need to catch up. 👀

#openssl #winxp #wince #libressl #uefi

Last updated 1 year ago

R. L. Dane · @RL_Dane
1306 followers · 21481 posts · Server fosstodon.org

@mirabilos @fbievan @pixelherodev @Anachron @sirber @sotolf @benjaminhollon

, not ?

I thought the whole point of LibreSSL was to be a more carefully audited and maintained fork of Open (although I understand that it doesn't have all of Open's features)

#openssl #libressl

Last updated 1 year ago

Free Software Foundation · @fsf
21894 followers · 6367 posts · Server hostux.social

The maintainers of Dragora, a fully free distro that uses and , have recently announced the latest release "dragora 3.0-beta2." Read the release notes and download it for yourself: u.fsf.org/3zk

#linuxlibre #libressl

Last updated 1 year ago

PR submitted to update MacPorts' libressl to 3.7.3 here:

github.com/macports/macports-p

CI/build bot checks passed!

It's up to someone else to merge it.

Next to submit a PR for 2.33 for the snac MacPort.

#libressl #macports #tls #opensource #openssl

Last updated 1 year ago

OK, PR submitted to update MacPorts' libressl-devel to 3.8.0 here:

github.com/macports/macports-p

CI/build bot checks passed!

It's up to someone else to merge it.

Next to submit a PR for 3.7.3 for the stable libressl MacPort.

#libressl #macports #libresslーdevel

Last updated 1 year ago

Meanwhile, Brent Cook updated the SHA256 and SHA256.sig so now signify output looks less sus:

signify -C -p libressl.pub -x SHA256.sig libressl-3.6.3.tar.gz
Signature Verified
libressl-3.6.3.tar.gz: OK

signify -C -p libressl.pub -x SHA256.sig libressl-3.7.3.tar.gz
Signature Verified
libressl-3.7.3.tar.gz: OK

signify -C -p libressl.pub -x SHA256.sig libressl-3.8.0.tar.gz
Signature Verified
libressl-3.8.0.tar.gz: OK

huzzah!

#libressl #signify #tls #opensource #openssl

Last updated 1 year ago

LibreSSL version 3.6.3 (legacy, not an official term, just more or less what it represents) 3.7.3 (stable) and 3.8.0 (development) have been released!

Release notes for 3.6.3:
ftp.openbsd.org/pub/OpenBSD/Li

Release notes for 3.7.3:
ftp.openbsd.org/pub/OpenBSD/Li

Release notes for 3.8.0:
ftp.openbsd.org/pub/OpenBSD/Li

I am preparing PRs for 3.8.0 for libressl-devel and 3.7.3 for libressl MacPorts already.

However, note that the SHA256 and SHA256.sig on the main distribution site and mirrors, though they have today (2023-05-27)'s date as their time stamp, they do not list any versions more recent than 3.7.2 so signify will produce a FAIL because it has nothing to check against in the new releases. I have brought this to the attention of Brent Cook et al and hopefully that will be rectified soon.

#libressl #macports #opensource #openbsd #tls #openssl

Last updated 1 year ago

Free Software Foundation · @fsf
21866 followers · 6341 posts · Server hostux.social

The maintainers of Dragora, a fully free distro that uses and , have recently announced the latest release "dragora 3.0-beta2." Read the release notes and download it for yourself: u.fsf.org/3zk

#linuxlibre #libressl

Last updated 1 year ago

Free Software Foundation · @fsf
21836 followers · 6296 posts · Server hostux.social

The maintainers of Dragora, a fully free distro that uses and , have recently announced the latest release "dragora 3.0-beta2." Read the release notes and download it for yourself: u.fsf.org/3zk

#linuxlibre #libressl

Last updated 1 year ago

social elephant in the room · @tseitr
22 followers · 324 posts · Server mastodon.sdf.org

@mgorny

it seems to install urllib3-2.0.2 on 7.3

# python3 --version
Python 3.10.11

openssl version
LibreSSL 3.7.2
.2

so is just broken for systems that use now?

#openbsd #urllib3 #libressl

Last updated 1 year ago

· @dbread
29 followers · 347 posts · Server qoto.org

The Road to Secure Cryptography: Understanding and Preventing Common Misuses

"Do not invent your own crypto":
A whole talk to by 💪 ☺️

media.ccc.de/v/glt23-374-the-r

#ssh #cryptography #security #obscurity #talk #libressl

Last updated 2 years ago

· @dbread
28 followers · 336 posts · Server qoto.org

I'm writing on a talk about using OpenSSH in industrial environments, and there is a slide that says: Where do you know SSH from?

My question is, where do YOU know OpenSSH from?

Answers appreciated :)

#ssh #openssh #security #it #operations #raspi #libressl

Last updated 2 years ago

CK's Technology News · @CKsTechNews
1344 followers · 6347 posts · Server cktn.todon.de
Mark Gardner ‍:sdf: · @mjgardner
532 followers · 2672 posts · Server social.sdf.org

@SpaceLifeForm @Perl This isn’t just shelling out to or (which core tools like already fall back on). This is about in-process , which is currently best supported in by IO::Socket::SSL and its dependency Net::SSLeay, which in turn depends on either or with development header files.

There are modules that wrap and other interfaces, but the more popular HTTP and other client modules don’t use them.

#curl #wget #cpan #tls #perl #openssl #libressl #libcurl

Last updated 2 years ago

グレェ「grey」 · @byterhymer
268 followers · 8549 posts · Server mastodon.social

I should be asleep, but just saw email that thanks to Herby Gillot, those two PRs are now merged!

Phew.

Hopefully I will rest with less stress over and and ?

#openssh #libressl #macports

Last updated 2 years ago

Peter N. M. Hansteen · @pitrh
1587 followers · 1096 posts · Server mastodon.social
グレェ「grey」 · @byterhymer
267 followers · 8507 posts · Server mastodon.social

(continued):

"LibreSSL 3.5.4 also includes the following reliability fix:

* An uninitialized variable was used in ASN1_STRING_to_UTF8() to decide whether the no-op freezero(NULL, 0) should be called."

#libressl

Last updated 2 years ago

グレェ「grey」 · @byterhymer
267 followers · 8506 posts · Server mastodon.social

Via Brent Cook on the LibreSSL mailing list:

"We have released LibreSSL 3.5.4 and 3.6.2, which will be arriving in the LibreSSL directory of your local OpenBSD mirror soon.

They include the following security fix:

* A malicious certificate revocation list or timestamp response token
would allow an attacker to read arbitrary memory."

#libressl

Last updated 2 years ago