Jump to content

Angus Robertson

Members
  • Content Count

    2162
  • Joined

  • Last visited

  • Days Won

    40

Everything posted by Angus Robertson

  1. Angus Robertson

    Not greying out inactive code

    Greying out suppressed code is working as expected in D13 for the ICS component library. ICS has a lot of defines and optional code, greying is a very useful feature. Angus
  2. Angus Robertson

    Forum running slow

    I get solid 30ms pings, but still the server sometimes fails to respond, just overloaded in some way, probably by AIs trying to access many years of old messages for the massive wealth of information collected here over the years. Angus
  3. The ICS C++ Common package seems to have a unit OverbyteIcsCryptuiApi, try removing it from the package and see if your application stops complaining about crypt32.lib? That unit is to display Microsoft crypto dialogs and I don't believe is now used in any ICS samples. It's code should not compile due to DEFINEs, but who knows. Angus
  4. Angus Robertson

    ICS V9.5 announced

    SVN and the overnight zip have been updated with another refresh of ICS V9.5, including four new OpenSSL versions. OpenSSL has issued a new minor release 3.6.0 as part of it's twice yearly release strategy, which adds several private key improvements and Leighton-Micali Signature (LMS) verification support which is a FIPS requirement. This version will be supported until October 2027. OpenSSL 3.6.0 becomes the default version with V9.5, provided you use the latest OverbyteIcsDefs.inc file. OpenSSL has also issued security fixes for all its free supported and paid support versions, so the new versions included with ICS and on the downloads page are 3.5.4, 3.4.3 and 3.0.18. OpenSSL 3.3 and 3.2 are no longer updated for ICS since their support is ceasing, and we have too many versions. Finally content that automatic certificate ordering is behaving as designed and re-ordering certificates before they expire, not easy to test when most don't expire for 90 days. The ICS Web, FTP and proxy server samples have now all ordered new certificates. The distribution version is not yet changed, still documenting the automatic certificate ordering stuff. Angus
  5. Angus Robertson

    ICS V9.5 announced

    ICS V9.5 has been released at: https://wiki.overbyte.eu/wiki/index.php/ICS_Download ICS is a free internet component library for Delphi 7, 2006 to 2010, XE to XE8, 10, 10.1, 10.2, 10.3, 10.4, 11, 12 and 13 and C++ Builder 10.4, 11, 12 and 13. ICS supports VCL and FMX, Win32 and Win64 targets. The distribution zip includes the latest OpenSSL 3.5.2, 3.4.2, 3.3.4, 3.2.5 and 3.0.17 for Win32 and Win64. Changes in ICS V9.5 include: 1 - Major improvements in ICS V9.5 include a new geographic component that has built in IP address databases for countries and ASN; server components have a new event called before a connection is accepted allowing 'firewall' rejection of connections based on IP address; the MQTT client and server components now support protocol 3.1.1; the automatic certification ordering component now supports Google Trust Services and other ACME suppliers, as well as Let's Encrypt; changes for the HTTP clients and servers to better support REST request APIs; 2 - Many of these improvements, and the delay finishing this release, relate to web server improvements needed to mitigate a nine month long attack on a public web server, that started with millions of accesses from two Far East IP addresses, progressed to accesses from VPNs at data centres worldwide, then finally to a botnet that caused access from over one million different IP addresses in 150 countries each week. It's not often a developer has first hand experience of such web server abuse, we try to plan for it, but rarely experience it directly. The ICS web server samples already had filtering by IP addresses and reverse DNS lookup and this worked for a few months with manual updating of the filtering lists, but this was time consuming. So a new GEO component was added with an IP address to country database that allowed specific countries to be blocked, then regions of the world, finally an ASN database allowed specific cloud/ISPs to be blocked. During these months, the ICS web server kept working, albeit slowing as logs tried to handle the vast volumes of IP addresses, needing rewrites of some ICS components. But everything is now stable and ICS capable of handling such heavy traffic. 3 - TWSocketServer has a new event OnClientAcceptFilter event called before the component accepts an incoming connection allowing filtering on the remote IP address so the connection is refused without any more events being called. This action is similar to a firewall refusing a connection, rather than opening and immediately closing it again. Before the event is called, a TIcsSessIpInfo record if filled with remote and local addresses and ports in binary and as strings, saving a lot of application code, the event can complete other record fields. This event can be used with the new GEO components to check countries and regions that should be blocked, and with the TIcsBlacklist component to stop those previously blocked addresses from accessing the server. The THttpSrv HTTP server has a similar OnHttpAcceptFilter event, and it will be added to other servers for the next release. 4 - Added a new TIcsGeoTools component that reads MaxMind formatted GEO database files using the MMDBReader component, and includes two small databases from db-ip.com, 'IP to Country Lite' and 'IP to ASN Lite', but can handle other MaxMind databases. Both databases can are available as resource files that can be linked into applications or loaded from a file to be shared between servers. There is also a country name database ICS-Countries.csv linked as a resource file that contains country GEO information. ASN is Autonomous System Name, an ISP or cloud name, that supplements reverse DNS (often missing) in identifying the owners of IP addresses. The databases are updated monthly by db-ip.com and can be downloaded from them, will try to keep ICS up to date. The TIcsGeoTools component is a self contained unit, IcsGeoUtils.pas with no dependencies, but is only available for Delphi 11 and later due to use of new language features. The component needs to be created in code and the databases required loaded before use, see the samples mentioned below. The main lookup methods are FindISOA2Code and FindASNCode, then FindCountry and FindRegion from an ISOA2 country code, region is a quick was to block all Asian countries for instance. The TIcsDomainNameCache and TIcsBlacklist now include ISOA2 and ASN fields that are included in responses and reports from these components. Beware block countries and regions may have unexpected consequences, for instance Let's Encrypt and Google validate SSL/TLS certificate domain names from multiple countries. The OverbyteIcsSslMultiWebServ and OverbyteIcsDDWebService samples use the databases in the new server OnHttpAcceptFilter event, and writes country and ASN to the web log file, as well as allowing hacker filtering using this information. The OverbyteIcsNetTools sample Trace Route now shows the country and ASN for each IP in the route to the destination, as well as reverse DNS, although the IP addresses allocated to network routers don't appear to totally accurate. These samples only use TIcsGeoTools if DEFINE USE_IcsGeoTools is set in Defs.inc. 5 - Added new components TIcsFilterList and TIcsIpAddrList to replace TestFilters using HackFilterList and TestIpWhiteList using WhiteIpList in sample OverbyteIcsSslMultiWebServ1.pas. TIcsFilterList reads same file hackfilterlist.txt containing key=value pairs which are used to filter incoming connections for path, remhost, country, useragent or referrer, trying to filter out abusive remote hosts. TIcsIpAddrList reads same file whiteiplist.txt which is a list of ASCII IP full or partial addresses, generally that should not be blocked by filters. The TIcsBlacklist has major changes including support for saving IPv6 addresses in binary as well as ASCII, they sort better in reports and take less memory, adding and checking an TSockAddrIn6 which avoids conversion to strings, and other improvements to handle one million IP addresses more efficiently. 6 - Since Let's Encrypt introduced the ACME (Automatic Certificate Management Environment) protocol to download free SSL/TLS certificates, other suppliers have added automated ordering using the same API, mostly with extra account information for commercial certificates. ICS has been tested successfully with free certificates from Google Trust Services, and should work with DigiCert, ZeroSSL and SSLcom, but these three are primarily commercial suppliers and need prepaid accounts, so not tested yet. Google Trust Services offers an excellent alternate to Let's Encrypt and offers almost the same free certificates up to 90 days with multiple wildcards, but allows the expiry days to be specified during ordering, down to three days. Some companies were reluctant to use Let's Encrypt when there was no alternative in case of extended down time, now Google offers that alternate. Apart from Let's Encrypt, suppliers use ACME external accounting to tie the ordering process to web site accounts, which is explained in comments in the OverbyteIcsSslX509Certs unit, more information will be added and the wiki pages updated soon. Google needs the Google Cloud CLI Windows application installing, type a few commands and you get the external account information Acme needs. The OverbyteIcsX509CertsTst sample has a major revision to support multiple account suppliers and to specify the external accounting information. The sample needs to be run on any servers that will order certificates to create the initial Acme account (except for Let's Encrypt), and includes a web server allowing test certificates to be ordered provided DNS points to a public IP on the server. Most suppliers provide a testing endpoint which is listed in OverbyteIcsX509CertsTst so you can order fake certificates to understand the process. There is now a facility to ask ICS servers to renew certificates on demand from the OverbyteIcsX509CertsTst sample, previously you had to mess with the INI file to force a new order. 7 - TWSocketServer has a lot of improvements relating to SSL/TLS certificates, many relating to new IcsHosts options to support suppliers other than Let'S Encrypt. IcsHosts has a new property AcmeSupplier as TAcmeSupplier which may be AcmeLetsEncrypt or AcmeGoogle (or several others), and property SupplierTitle to specify the account name of than supplier from a database. The supplier accounts database is generally maintained by the OverbyteIcsX509CertsTst sample, which must be used to create accounts for new suppliers, and which may be used to view certificate orders. SupplierTitle is used instead of specifying CertDirWork which will be looked up from C:\ProgramData\ICS-Acme-Accounts\ics-acme-accounts.db. By default, new work directories will be in: C:\ProgramData\ICS-Acme-Accounts\. CertDirWork is still supported, but it's recommended that applications move to using supplier accounts instead, which can be monitored using OverbyteIcsX509CertsTst. Google and other suppliers only work with supplier accounts, since information is needed that is not in IcsHosts. IcsHosts has other new properties: AcmeCertProfile to specify the type of certificate requested for Let's Encrypt, listed in FAcmeProfileNames array, default classic, optional tlsserver and shortlived (7 day, not yet available); AcmeCertValidity to specify certificate life in days, default 90, only Google at present, down to 3 days. Certificate ordering now makes use of the ACME Renewal Information API that specifies how many days before expiry a certificate should be renewed, and how often these dates should be rechecked to see if the certificate needs immediate renewal due to being revoked. This overrides CertExpireDays. Renewal Information is checked each time the certificate chain is checked, but is cached so there is usually only a server API call every six hours. Note with OCSP gone, this is now the only way to check if a certificate is revoked. Reworked certificate checking so if automatic ordering is enabled the Acme account information is looked up when the certificate is first loaded to get renewal information and maybe working directory, rather than only when time to order a new certificate, so there is more logging and error checking at load time. Temporary ICS self signed certificates are now created in GSSL_CERTS_DIR instead of TempPath. When starting a certificate order, if the challenges have been previously completed OK, collect order immediately, don't try to start them again. Let's Encrypt is implementing a change in the way new certificates are issued, which may be delayed a few seconds after the CSR is provided, rather than immediately, so the component now waits and checks every five seconds for the new certificate to be issued. This already happens for Google. Note this Let's Encrypt change means earlier ICS versions will soon fail to work. ICS now supports ordering SSL/TLS certificates with IP addresses as well as host domain names, tested with Let's Encrypt Staging but not available yet from live certificates. Testing showed a problem using SSL with IP addresses URLs relating to the Server Name Indication HELO feature which does not allow simple IP addresses which must be converted to domain names, ie 217.146.102.139 becomes 139.102.146.217.in-addr.arpa. Automatic certificate ordering in IcsHosts now has a database property CertRenewNow that if set true in the database using the OverbyteIcsX509CertsTst, will override certificate expiry checking and cause an immediate new certificate replacement order by in servers with IcsHosts the next time RecheckSslCerts is called by the server, typically every two hours. Fixed a long term problem where SSL/TLS server name SNI checking for a matching IcsHost used the certificate SANs that might have included a wild card, instead of the Hosts list of host names. If one IcsHost allowed wild cards it might have been found instead a specific IcsHost for a single host. 8 - New major versions of OpenSSL often add new functions and deprecate older functions that are then removed in a subsequent major release after applications should have been updated. ICS has added a DEFINE OpenSSL_Deprecated without which no deprecated functions should be loaded. ICS has been testing with a special build of OpenSSL 3.5 without deprecated functions and several units have now been updated to use newer 3.0 functions, so no more work should be necessary for OpenSSL 4.0 when those deprecated could disappear. The DEFINE OpenSSL_Deprecated should only be needed if your application uses old OpenSSL functions for encryption or signing. The OverbyteIcsJoseTst sample also needs OpenSSL_Deprecated for RSA string encryption, pending a rewrite without deprecated functions. ICS now only creates the C:\ProgramData\ICS-OpenSSL directory if conditionals OpenSSL_Resource_Files or OpenSSL_ProgramData are specified meaning OpenSSL files are expected there. Otherwise the developer is responsible for setting GSSL_DLL_DIR to the OpenSSL DLL directory. 9 - Updated the MQTT client and server components to support protocol 3.1.1 which is commonly used, previously we only supported 3.1. The client will connect to a v5 server by ignoring dozens of new options, but needs a lot more work, much more complicated than v3.1.1, not planning any more v5 unless there is a specific requirement. Added LogPackets property to log packets in ASCII and hex for diagnostics, UseSSL property to force client to use SSL on any port, BlankClient property (anonymous) for 3.1.1 so server allocates ClientId, but only v5 tells us that ID. BurstMode property for 3.1.1 so client does not wait for response to Connect, but publishes immediately. When Subscribing With v3.1.1, the server now returns a failure flag for permissions failure, which is returned as QoS qtFAILURE. Also improvements to the OverbyteIcsMQTTst sample, allow Username/Password to be set, so they may be left blank, ClientHost is now a drop down box, and includes test.mosquitto.org that may be used for client testing, see https://test.mosquitto.org/ for a long list of ports for different testing purposes, allow MQTT protocol to be specified, added v3.1.1 and v5, and options to test all new functions. If the server SSL port non-zero, the server will create an ICS CA signed certificate for the host name (ie localhost) if a certificate file bundle is not found. 10 - There are various WebSocket improvements. The client now has optional asynchronous connection which no longer blocks the initial WSConnect which now returns immediately and a OnWSConnected event is called when the connections is ready or fails, so should now correctly process a welcome message or packets sent immediately upon connection. The server now has a configurable delay after connection before sending a welcome message or packets, for clients that can not process them immediately. Fixed a problem that data sent immediately a new connection opened could be lost because the component had not switched to Websocket mode. Allow Sec-WebSocket-Protocol: header to added with HeaderSecWebSocketProtocol values (char, superchat, etc). Added a new OnWSFramesDone event called when a queue of frames have been sent, for flow control when sending a lot of data. Note the IcsAppMonMan.dpr sample illustrates how to use multiple WebSocket client components to contact multiple WebSocket servers and display information from them, it comes configured to view three public servers running ICS web, FTP and proxy servers. 11 - Fixed a long term problem with ECDSA binary digests, which have two formats, ASN.1 used by OpenSSL and IEEE P1363 which is shorter fixed length and often also used. Added IcsDigestAsntoIEEE and IcsDigestIEEEtoAsn to convert between the two formats, and a new EcdsaIEE flag to IcsAsymSignDigestTB, IcsAsymVerifyDigestTB, IcsJoseJWSJson, IcsJoseGetSigTB, IcsJoseCheckSigTB and IcsJoseCheckJWS to use the new format, only effective when using EC private keys. Signing Acme requests with EC keys now correctly use IEEE P1363 digests so finally work properly, been looking for this since 2018. 12 - CreateSelfSignCertEx now adds IP addresses to the correct alternate list, not allowed as common name. TSslCertTools has new certificate properties for more Distinguished Names, mainly for personal names: Street, SurName, GivenName, NameTitle, NameInitials, used when creating Certificate Requests. Using Description no longer gives an error. 13 - The HTTP clients THttpCli and TSslHttpRest have new properties RespAttachment (Boolean) and RespFileName, parsed from Content-Disposition: response header which can be used to offer to save content as a file, and RespRetryDT parsed from Retry-After: response header, when this request should next be repeated as TDateTime. ResponseNoException now defaults to True to skip exceptions for most connection errors like 404, etc, beware this default change may cause applications expecting exceptions to misbehave, either set it false or check StatusCode in RequestDone. 14 - In HTTP client TSslHttpRest, if HttpUploadStrat=HttpUploadSimple, add unofficial Content-Disposition request header that some web servers might check for an upload file name. Check for a Json response of any array only [] without objects. Allow GET and DELETE methods to use PContBodyJson, PContBodyUrlEn and PContBodyXML content types, beware web servers may not support this. 15 - The TRestParams component has a new RParamFmt property that for Json only defines whether nested objects or an array should be formatted, default is RPFmtNestObj (Nested Objects, same as previously), or RPFmtArrayVal (Array of Values) if first element is any array, or RPFmtArrayObj (Array of Objects) where each element is treated as object in the array. Note RPFmtArrayObj allows duplicate names in Add methods, since output into different objects. For instance: RPFmtNestObj: {"field1":"data1","field2":"data2","field3":[data1, data2, data3]} RPFmtArrayVal: [data1, data2, data3] RPFmtArrayObj: [{"field":"data1"},{"field":"data2"},{"field":[data1, data2, data3]}] 16 - In the HTTP servers THttpSrv and THttpAppSrv, allow the built in HTTP error response to be customised using new event OnHttpCustomError which is called by the error handlers with the error, path, and existing Body, that may be replaced or modified as required. Called for errors 301, 302, 307, 308, 400, 401, 403, 404, 416, 501. Added new hoContDispHdr Option and AttachmentTypes list of file extensions that if matched causes the server to add an Content-Disposition: attachment header with the filename, that should cause a browser to offer a 'Save As' dialog to save a binary file, rather than trying to display it. Note the default list includes .pdf so Acrobat files are saved rather than displayed. The Get and Delete methods now accept uploaded body content similarly to POST/PUT. The derived THttpAppSrv server has handlers for uploaded content, for THttpSrv you need to write your own. Added OnHttpAcceptFilter event called before TWSocketServer accepts an incoming connection allowing filtering on the remote IP address so the connection is refused without any more events being called. 17 - TWSocket has a new property SessionIpInfo which is TIcsSessIpInfo record set after connection with the local and remote IP addresses and ports from the socket, also socket type and protocol, as internal and string versions. Might be easier to use than various GetPeer methods. Set for accepted listen connections. Fixed a missing inherited DupConnected that meant counters did not get reset. The SSL/TLS Server Name extension does not allow raw IP addresses, so convert then to domain names, ie 217.146.102.139 becomes 139.102.146.217.in-addr.arpa. 18 - Added Windows memory reporting functions IcsMemInfoProg, IcsMemInfoGlob and IcsMemInfoPerf to the OverbyteIcsWinUtils unit, useful for server monitoring, used by the sample IcsAppMon.dpr. Also IcsMemWarning to check for low or critical memory problems, returns Warning at 85% physical or page file usage, critical at 95% usage (reboot probably required). 19 - ICS added OSCP (Online Certificate Status Protocol) support a few years ago, used to check if certificates have been revoked. But running the massive OCSP databases needed has proved challenging, and the industry is moving away from OCSP, Let's Encrypt stopped adding an OCSP URL to certificates in May 2025. OCSP adds quite a lot of code, so added new defines to ICS so OCSP code is only linked if using authorities that still support OCSP, see information about OverbyteIcsDefs.inc. This change effects many components that check certificates, if the defines are disabled OCSP properties are still available, but will be ineffective, removing the OCSP properties would in too many form errors. Another reason for OCSP's demise is shorter SSL/TLS certificate life, so they expire rather than needing to the revoked. From 15th March 2026, certificate life span is reduced to 200 days, from 15th March 2027 down to 100 days and finally from 15th March 2029 to 47 days, but only 10 days for domain control validated certificates, such as most free certificates which are currently 90 days maximum. ICS can already order seven day certificates from Google Trust Services, with Let's Encrypt adding this later in 2025. 20 - ICS now defaults to the latest OpenSSL version 3.5.2 which includes support for new Post Quantum Cryptography (PQC) algorithms (ML-KEM, ML-DSA and SLH-DSA) and for server side QUIC (RFC 9000). ICS has no plans for QUIC support, not yet investigated PQC, don't believe any low level changes are needed, maybe changes to the cipher lists. This is a long term support release with fixes and security updates for five years, until April 2030. ICS still includes four older OpenSSL versions, which will slowly disappear as they reach end of life, about one every six months. 21 - The OverbyteIcsDefs.inc file included in most ICS units has several new defines. DEFINE OpenSSL_36 (due Oct 2025) and OpenSSL_40 (due Apr 2026). Enabled DEFINE OpenSSL_35 for OpenSSL 3.5. DEFINE OpenSSL_OcspStaple, should SSL server staple an OCSP response to check if server certificate is revoked. Let's Encrypt stopped adding an OCSP URL to certificates in May 2025 so only enable this if using authorities that still support OCSPL, to avoid extra code being linked. DEFINE OpenSSL_OcspChains, should SSL clients checking a certificate chain check an OCSP server to see if the certificate is revoked, only happens if the certificate has an OCSP URL, undefine to remove the extra code that does OCSP checks. DEFINE OpenSSL_Deprecated, should OpenSSL deprecated functions be loaded, not needed for ICS but may be used by applications for encryption or signing. DEFINE USE_IcsGeoTools used by samples with the TIcsGeoTools component to lookup countries from IP addresses, D11 and later only. All ICS active samples are available as prebuilt executables, to allow ease of testing without needing to install ICS and build them all. There are four separate zip files split into clients, servers, tools and miscellaneous samples which can be downloaded from https://wiki.overbyte.eu/wiki/index.php/ICS_Samples
  6. Angus Robertson

    ISuperObject decimal issue with currency values

    That's convenient, never used it myself... I did fix a problem with floats variously using . and , which is a no-no in Json. Angus
  7. Angus Robertson

    ISuperObject decimal issue with currency values

    The ICS component library includes a fork of SuperObject, with various bug features and new features, including returning parsing errors and support for Delphi TDateTime, saved as an ISO 8601/RFC3339 string: obj.AsDateTime, obj.AsObject.DT['foo'] https://svn.overbyte.be/svn/icsv9/Source/OverbyteIcsSuperObject.pas I could add a currency type if useful. . Angus
  8. I used to use Pred and Succ, mainly because early Intel 8080 compilers mapped those to simple assembly instructions, rather than using arithmetic. But compilers got better. Angus
  9. Angus Robertson

    Can I use TsslWebSocketCli in a thread?

    You have not explained your environment, but assuming this is a Windows Service, you should have the message loop in the ServiceExecute event: procedure TIcsTcpServce.ServiceExecute(Sender: TService); begin while not Terminated do ServiceThread.ProcessRequests(TRUE); end; So there is only one thread for the main unit, just like most GUIs. Angus
  10. Angus Robertson

    Can I use TsslWebSocketCli in a thread?

    ICS components are widely used in Windows Services, less often in threads, really two different questions. For Windows Services, a VCL service project with SvcMgr gives you a form onto which to drop your components, and provides a message pump so they work just as if it is a GUI. ICS has a sample IcsAppMon;,dpr which has a WebSocket server component running as a Windows Service, although it uses the DDSvcMgr version ofSvcMgr which allows the application to be run as both a GUI or installed as a Windows Service, makes development and debugging much easier. Using the WebSocket Client would be no different, that is used in the sample IcsAppMonMan which talks to the server, but is only a GUI since it talks to multiple servers. Not sure why, but we don't seem to currently have any simple Windows Service samples, guess I need to add one for the next release. Angus
  11. And yet the Delphi Win64 compiler manages to open crypt32.lib using the usual Windows magic where Win64 DLL are in the System32 directory... Perhaps there is a crypt32.lib reference I've missed or a HPPEMIT that ignores other defines. I'll have a look tomorrow. Angus
  12. I'm confused here, why does your application need Crypt32.lib? What APIs is it using. As I said earlier, ICS does not use it and the Win64 packages now build OK on C++. Angus
  13. Provided you undefine MSCRYPT, which should happen automatically in defs.inc for BCB, ICS will ignore a lot of Windows crypto stuff that caused C++ problems in the past. It means components to access the Windows Certificate Store are not available for C++. Would be nice to fix those errors at some point. Angus
  14. I've updated SVN with the changes needed so that ICS can be built with C++ for Win32 and Win64, will be zipped overnight. One package builds OK for Win64x, but the other two packages dependent upon it fail with undefined symbol errors, which I believe is a long term Win64x linker problem, no quick fix. I'll look at a second V9.,5 refresh in a few days, once I've finished documentation that missed this release. OpenSSL has security fixes next week as well. Angus
  15. Excellent debugging, I'll make those changes and try Win64 again. On reflection, I see a pattern with the 'units were found in required package' error. It seems C++ can not build packages if any similar packages are installed in the IDE. I guess most other developers build their C++ packages using command line tools, not in the IDE, so don't see the problem. I saw the error with the Delphi package because it had been installed earlier and removed, but was still in memory until an IDE restart. C++ Win32 then works, but not Win64 if Win32 has been installed into the IDE. With Delphi, you don't get a Win64 error if Win32 is installed. Angus
  16. I was getting warnings building C++ IcsCommonCBNewRun that units were found in IcsCommonNewRun which is the Delphi package, and is not referred anywhere in C++, but they went away when I specified the Windows SDK, which I don't recall every doing before in RAD Studio. If you are not using Win64, just ignore the packages. I rarely test with Win32 now, all my servers and some GUIs are Win64, a couple use old components and need Win32. Are you using the old or new packages? Are changes still needed per your root message. Angus
  17. No, those properties don't exist in the non-SSL component, despite not being related to SSL. Good example of why define USE_SSL has to go, it makes the source very hard to maintain and wastes my time fixing problems like this. Angus
  18. Angus Robertson

    ICS V9.5 announced

    Replied in separate topic. Angus
  19. I was looking at C++ 13 yesterday, and have just uploaded new C++ packages to SVN, will be zipped overnight. I believe I've corrected all the Win64x paths and a few Win64 paths. Win32 built OK once I specified a Windows SDK to use, which strangely is version 10 and not 11, Win64 still gives undefined symbol errors, four in Common, dozens in Run, I've tried to fix these before but unsuccessfully. Win64x gives different errors, but I don't believe the linker bug is fixed yet the C++ compiler does not create the necessary files to allow other C++ packages to reference them, so you can build CommonRun but not CommonDesign or VCLRun which both need CommonRun. An Embarcadero engineer investigated this last year for 12.3, but RSB-503 is still open. Perhaps you could check and update these latest packages as necessary, email them, and I'll put them in SVN quickly for others, Angus
  20. I no longer test building without USE_SSL, it will be unsupported in ICS V10. You will need to add {$IFDEF USE_SSL} {$ENDIF} around those two lines, they used to be in an SSL only function, but moved. Angus
  21. Angus Robertson

    ICS V9.5 announced

    ICS V9,5 is now available to install from GetIt, thanks Embarcadero. Angus
  22. Angus Robertson

    ICS V9.5 announced

    Sorry, forget to upload the ICS release zips to the wiki site, they are correct now. The readme says 19 Sept. Angus
  23. Angus Robertson

    ICS V9.5 announced

    The release zips for ICS V9.5 have been refreshed, with bug fixes for automatic certificate ordering from Let's Encrypt and Google Trust Services, that missed the release a week ago. Done a lot of testing this week. There is also a new OpenSSL version 3.5.3, and the old version 3.2 has been removed to reduce the zip size, and also because it's out of support in December. We now have four OpenSSL releases, including two with long term support, 3.0 and 3.5. OpenSSL 3.5.3 added FIPS 140-3 PCT on DH key generation. It can be downloaded separately from the usual places. Angus
  24. Sync mode should exit after the default timeout of 30 seconds idleness, perhaps something in the component was resetting the LastAlive property. There is no fixed 'this request will never take more than x seconds' since it might take hours to download large content, something your application can handle if it knows it's expecting some lines of JSON. Angus
  25. Angus Robertson

    ICS V9.5 announced

    Thanks, will fix those for the next release. That is old code. Angus
×