Angus Robertson 577 Posted March 18, 2020 Two new zips for Win32 and Win64 versions of OpenSSL 1.1.1e can now be downloadable from the Wiki at: http://wiki.overbyte.eu/wiki/index.php/ICS_Download or https://www.magsys.co.uk/delphi/magics.asp . The latest 1.1.1 DLLs are also included in the ICS distribution SVN and overnight zip. This release includes one low priority security improvements and bug fixes, including one that allows IcsJoseJWKPubKey support RSA-PSS keys. ICS applications require V8.57 or later to support OpenSSL 1.1.1e. Changes in 1.1.1e may be found at https://www.openssl.org/news/openssl-1.1.1-notes.html Angus Share this post Link to post
Angus Robertson 577 Posted April 1, 2020 Updated OpenSSL to 1.1.1f, this reverts a change in 1.1.1e that caused problems in some applications, but I don't believe ICS was effected. Angus Share this post Link to post
Angus Robertson 577 Posted April 22, 2020 Updated OpenSSL Windows binaries to 1.1.1g, this fixes a severe security vulnerability (denial of service) checking certificates with TLS/1.3, however the API that does this is not used by ICS so our applications are not effected. https://www.openssl.org/news/secadv/20200421.txt Angus Share this post Link to post
Angus Robertson 577 Posted September 23, 2020 Updated OpenSSL Windows binaries to 1.1.1h, regular minor release only, no security fixes. Angus 1 Share this post Link to post
Angus Robertson 577 Posted December 9, 2020 Updated OpenSSL to 1.1.1i, fixes a high severity problem reading specially crafted malformed SSL certificates that could cause OpenSSL to crash, also minor bug fixes. The same high severity problem happens in 1.0.2 and 1.1.0, but these are out of support so users should update to 1.1.1. Angus Share this post Link to post