From: Pauli Date: Wed, 24 Jul 2024 01:45:51 +0000 (+1000) Subject: changes: add no_short_mac entry X-Git-Tag: openssl-3.4.0-alpha1~277 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=50a91de440f05e369f02e10c34aaf16fca4dbc62;p=thirdparty%2Fopenssl.git changes: add no_short_mac entry Reviewed-by: Shane Lontis Reviewed-by: Tom Cosgrove (Merged from https://github.com/openssl/openssl/pull/24917) --- diff --git a/CHANGES.md b/CHANGES.md index 7b3ec56fc85..594efc44de8 100644 --- a/CHANGES.md +++ b/CHANGES.md @@ -29,6 +29,12 @@ OpenSSL 3.4 ### Changes between 3.3 and 3.4 [xx XXX xxxx] + * Add FIPS provider configuration option to enforce the a minimal + MAC length check. The option '-no_short_mac' can optionally be + supplied to 'openssl fipsinstall'. + + *Paul Dale* + * Redesigned Windows use of OPENSSLDIR/ENGINESDIR/MODULESDIR such that what were formerly build time locations can now be defined at run time with registry keys. See NOTES-WINDOWS.md @@ -1108,7 +1114,7 @@ OpenSSL 3.1 * Add FIPS provider configuration option to enforce the Extended Master Secret (EMS) check during the TLS1_PRF KDF. - The option '-ems-check' can optionally be supplied to + The option '-ems_check' can optionally be supplied to 'openssl fipsinstall'. *Shane Lontis*