X-Git-Url: https://git.openssl.org/gitweb/?p=openssl.git;a=blobdiff_plain;f=CHANGES;h=e770a240b7f0af5cae79448c8febd6910f939b0d;hp=6e4eaaed70c16fb9b5f41945d45e62cbd1b1749f;hb=15652f9825de25481676767aa73945409f9c82e2;hpb=d88926f1815d79c800e4cf11ecee8e43f3a7ad1f diff --git a/CHANGES b/CHANGES index 6e4eaaed70..e770a240b7 100644 --- a/CHANGES +++ b/CHANGES @@ -4,6 +4,44 @@ Changes between 1.0.x and 1.1.0 [xx XXX xxxx] + *) Make openssl verify return errors. + [Chris Palmer and Ben Laurie] + + *) Fix OCSP checking. + [Rob Stradling and Ben Laurie] + + *) New option -crl_download in several openssl utilities to download CRLs + from CRLDP extension in certificates. + [Steve Henson] + + *) Integrate hostname, email address and IP address checking with certificate + verification. New verify options supporting checking in opensl utility. + [Steve Henson] + + *) New function X509_CRL_diff to generate a delta CRL from the difference + of two full CRLs. Add support to "crl" utility. + [Steve Henson] + + *) New options -CRL and -CRLform for s_client and s_server for CRLs. + [Steve Henson] + + *) Extend OCSP I/O functions so they can be used for simple general purpose + HTTP as well as OCSP. New wrapper function which can be used to download + CRLs using the OCSP API. + [Steve Henson] + + *) New functions to set lookup_crls callback and to retrieve + X509_STORE from X509_STORE_CTX. + [Steve Henson] + + *) New ctrl and macro to retrieve supported points extensions. + Print out extension in s_server and s_client. + [Steve Henson] + + *) New function ASN1_TIME_diff to calculate the difference between two + ASN1_TIME structures or one structure and the current time. + [Steve Henson] + *) Fixes and wildcard matching support to hostname and email checking functions. Add manual page. [Florian Weimer (Red Hat Product Security Team)] @@ -13,8 +51,8 @@ [Steve Henson] *) New functions to check a hostname email or IP address against a - certificate. Add options to s_client, s_server and x509 utilities - to print results of checks against a certificate. + certificate. Add options x509 utility to print results of checks against + a certificate. [Steve Henson] *) Add -rev test option to s_server to just reverse order of characters