From: Andre Noll Date: Sun, 16 Apr 2017 18:15:35 +0000 (+0200) Subject: Merge branch 'refs/heads/t/rm_rc4' X-Git-Tag: v0.6.0~11 X-Git-Url: http://git.tuebingen.mpg.de/?p=paraslash.git;a=commitdiff_plain;h=a826152ba51fd4813f715e5fa30e7d70407dc846 Merge branch 'refs/heads/t/rm_rc4' This patch removes support for RC4, making the AES-based stream cipher mandadory. The aes_ctr128 server feature is made a no-op, breaking support with very old clients (<= 0.5.1). Cooking for three months. * refs/heads/t/rm_rc4: crypt: Remove RC4 support. --- a826152ba51fd4813f715e5fa30e7d70407dc846 diff --cc NEWS.md index fb666529,d9326db7..08acd22c --- a/NEWS.md +++ b/NEWS.md @@@ -1,22 -1,6 +1,25 @@@ NEWS ==== +------------------------------------ +0.6.0 (to be announced) "fuzzy flux" +------------------------------------ +- Support for Mac OS X has been removed. +- On Linux systems, glibc-2.17 or newer is required to build the + source tree. +- Support for RSA public keys in ASN format (as generated by openssl + genrsa) has been removed. These keys have been deprecated since + 2011, so users should have long switched to keys generated with + ssh-keygen(1). +- If libgcrypt is used as the crypto library, we now require version + 1.5.0 (released in 2011) or later. ++- The insecure RC4 stream cipher has been removed. It was superseded ++ by aes_ctr128 three years ago but the RC4 code had been kept for ++ backwards compatibility. + +Downloads: +[tarball](./releases/paraslash-git.tar.bz2), + ------------------------------------- 0.5.7 (2016-12-31) "semantic density" -------------------------------------