X-Git-Url: https://git.openssl.org/gitweb/?p=openssl.git;a=blobdiff_plain;f=CHANGES;h=684280d83514c623686f753d1b35a0065fe401a2;hp=a469186a2703c6f6f33e535bfc7e0e13eda2e080;hb=c6a926d9e27af13da1108b821db5e508e4a19cbe;hpb=bdec3c5323c7a726814257ec9b43fcd259f4e206 diff --git a/CHANGES b/CHANGES index a469186a27..684280d835 100644 --- a/CHANGES +++ b/CHANGES @@ -3,6 +3,12 @@ Changes between 0.9.6 and 0.9.7 [xx XXX 2000] + *) Store verify_result within SSL_SESSION also for client side to + avoid potential security hole. (Re-used sessions on the client side + always resulted in verify_result==X509_V_OK, not using the original + result of the server certificate verification.) + [Lutz Jaenicke] + *) Make BN_mod_inverse faster by explicitly handling small quotients in the Euclid loop. (Speed gain about 20% for small moduli [256 or 512 bits], about 30% for larger ones [1024 or 2048 bits].)