Forthcoming OpenSSL releases
mta.openssl.org
mta.openssl.org
Support the OpenBSD team:
http://www.openbsdfoundation.org/campaign2016.html
that makes the LibreSSL.
Personally, I find Network Security Services (NSS) much better designed than OpenSSL/LibreSSL and wish more things would use it. Notably better is the use of an actual database to store objects. This really helps when you are using certificate revocation lists (CRLs) which may be huge blobs that change frequently.
Specifically mentioned here, OpenSSL 1.1.x won't have FIPS support: https://groups.google.com/forum/#!searchin/mailing.openssl.d...
btw
HIGH Severity.
This includes issues that are of a lower risk than critical,
perhaps due to affecting less common configurations,
or which are less likely to be exploitable.
These issues will be kept private and will trigger
a new release of all supported versions.Do you have data besides "look at all the vulns!"?
Do you have clear evidence of a negative economic trend that is linked to insecure software?
Does anybody know why the update is announced a couple of days in advance? Are e.g. maintainers of corresponding packages in Linux distros or *BSD given access to the code ahead of time so they can build new packages?
For server operators to be prepared. (And I would prefer if they would narrow the timescales more for that.)
>Are e.g. maintainers of corresponding packages in Linux distros or *BSD given access to the code ahead of time so they can build new packages?
Yes, but that doesn't require a public announcement.
By announcing in advance what is going to happen, people can be ready to update as soon as the patch is available.
16 + 7 = 19?
5 + 31 + 12 = 36?