Skip to content

Commit d0f29bd

Browse files
committed
[release] prepare for 0.19.2
1 parent c888c8e commit d0f29bd

3 files changed

Lines changed: 36 additions & 2 deletions

File tree

‎History.md‎

Lines changed: 34 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,37 @@
1+
## 0.19.2
2+
3+
ASN.1 and X.509 compatibility improvements, new OpenSSL::Timestamp support &
4+
upgrading Bouncy Castle to latest.
5+
6+
- [feat] implement `OpenSSL::Timestamp` support (#372)
7+
- [feat] implement `SSLContext#add_certificate`
8+
- [compat] improve ASN.1 BER parsing, including high tags, indefinite lengths,
9+
nested constructed values, malformed input, EOC, SET ordering and tagging
10+
- [compat] preserve X.509 RDN sets and CRL extension order
11+
- [compat] implement `OCSP::Request#signed?` and `X509::Revoked#to_der`
12+
- [compat] improve CRL and `Time` writer handling
13+
- [compat] align `ASN1::ObjectId` handling with MRI
14+
- [compat] improve extended key usage parsing
15+
- [compat] reject invalid DH peer values
16+
- [compat] add BN `mod_sqrt` and left/right shift support
17+
- [compat] reject incomplete PKCS7 recipients and non-SET X.509 attribute values
18+
- [compat] ignore `FAIL_IF_NO_PEER_CERT` without `VERIFY_PEER`
19+
- [compat] reject unexpected TLS EOFs unless `OP_IGNORE_UNEXPECTED_EOF` is enabled
20+
- [compat] align SSL `close_notify` handling with OpenSSL
21+
- [compat] add `SSLSocket#readbyte`
22+
- [compat] verify PKCS12 PBMAC1 across BC-FIPS versions
23+
- [fix] harden OCSP response verification
24+
- [fix] encode long-form ASN.1 lengths correctly
25+
- [fix] preserve changes made to `X509::CRL`
26+
- [fix] try all certificates with the issuer's subject name
27+
- [fix] match CRLs from the same issuer
28+
- [fix] encode empty PKCS7 signer signatures (#373)
29+
- [fix] wait for partial TLS records before unwrapping
30+
- [fix] interrupt blocking SSL reads when the socket is closed concurrently
31+
- [fix] avoid shutdown spin on non-blocking SSL writes
32+
- [fix] retry a full handshake when TLS session reuse fails (#369)
33+
- [deps] upgrade BC to version 1.86
34+
135
## 0.16.3
236

337
- [deps] upgrade BC to version 1.86

‎lib/jopenssl/version.rb‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
# frozen_string_literal: true
22
module JOpenSSL
3-
VERSION = '0.19.2.dev'
3+
VERSION = '0.19.2'
44
BOUNCY_CASTLE_VERSION = '1.86'
55

66
# @private

‎pom.xml‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ DO NOT MODIFY - GENERATED CODE
1111
<modelVersion>4.0.0</modelVersion>
1212
<groupId>org.jruby.openssl</groupId>
1313
<artifactId>jruby-openssl</artifactId>
14-
<version>0.19.2.dev-SNAPSHOT</version>
14+
<version>0.19.2</version>
1515
<packaging>gem</packaging>
1616
<name>SSL/TLS and general-purpose cryptography for JRuby</name>
1717
<description>Ruby OpenSSL compatibility for JRuby, based on Java JCA/JCE and Bouncy Castle libraries (does not depend on native OpenSSL).</description>

0 commit comments

Comments
 (0)