The ChangeLog entry:
Version 4.30, 2010.01.21, urgency: LOW/EXPERIMENTAL:
* New features
- Graceful configuration reload with HUP signal on Unix
and with GUI on Windows.
This release involves major modifications of the code.
I expect some regression issues, so please make sure to test this version
well before running it on your production systems.
SHA-1 value for stunnel-4.30.tar.gz:
46d21c3ad0e761d697f4de8c258ef999287f13f9
Home page: http://stunnel.mirt.net/
Download: ftp://stunnel.mirt.net/stunnel/
Best regards,
Michal Trojnara
Dear Users,
I'm eager to hear your comments, suggestions or issues regarding sessiond.
Feel free to use the stunnel-users mailing list or the bug tracking system:
https://stunnel.mirt.net/?page=bts
Best regards,
Mike
The ChangeLog entry:
Version 4.29, 2009.12.02, urgency: MEDIUM:
* New feature sponsored by Searchtech Limited http://www.astraweb.com/
- sessiond, a high performance SSL session cache was built for stunnel.
A new service-level "sessiond" option was added. sessiond is
available for download on ftp://stunnel.mirt.net/stunnel/sessiond/ .
stunnel clusters will be a lot faster, now!
* Bugfixes
- "execargs" defaults to the "exec" parameter (thx to Peter Pentchev).
- Compilation fixes added for AIX and old versions of OpenSSL.
- Missing "fips" option was added to the manual.
SHA-1 value for stunnel-4.29.tar.gz:
f93ac9054c62b1db0dcf44f668d323d82cc0f413
Home page: http://stunnel.mirt.net/
Download: ftp://stunnel.mirt.net/stunnel/
Best regards,
Michal Trojnara
The ChangeLog entry:
Version 4.28, 2009.11.08, urgency: MEDIUM:
* New features
- Win32 DLLs for OpenSSL 0.9.8l.
- Transparent proxy support on Linux kernels >=2.6.28.
See the manual for details.
- New socket options to control TCP keepalive on Linux:
TCP_KEEPCNT, TCP_KEEPIDLE, TCP_KEEPINTVL.
- SSL options updated for the recent version of OpenSSL library.
* Bugfixes
- A serious bug in asynchronous shutdown code fixed.
- Data alignment updated in libwrap.c.
- Polish manual encoding fixed.
- Notes on compression implementation in OpenSSL added to the manual.
SHA-1 value for stunnel-4.28.tar.gz:
868cba9ec56ed6a02c8ecfa2a87614b4d433611b
Home page: http://stunnel.mirt.net/
Download: ftp://stunnel.mirt.net/stunnel/
Best regards,
Michal Trojnara
Dear Users,
I've just uploaded some patches sent to stunnel-users list over the years
to ftp://stunnel.mirt.net/stunnel/contrib/. Please remember my policy is
*not* to include any GPL code into the official stunnel distribution. If
you're brave you're free to apply the patches yourself, or even create a
fork of stunnel with some additional functionality. Just be aware there
were already some security vulnerabilities (including remote code
execution) discovered in the 3rd party stunnel patches. For this reason I
also don't recommend stunnel package/port maintainers to include any 3rd
party code with stunnel.
Best regards,
Mike
Dear Users,
Version 4.26, 2008.09.20, urgency: MEDIUM:
* New features
- Win32 DLLs for OpenSSL 0.9.8i.
- /etc/hosts.allow and /etc/hosts.deny no longer need to be copied to
the chrooted directory, as the libwrap processes are no longer
chrooted.
- A more informative error messages for invalid port number specified
in stunnel.conf file.
- Support for Microsoft Visual C++ 9.0 Express Edition.
* Bugfixes
- Killing all libwrap processes at stunnel shutdown fixed.
- A minor bug in stunnel.init sample SysV startup file fixed.
Home page/download: http://stunnel.mirt.net/
sha1sum for stunnel-4.24.tar.gz file:
1c9f5dd6b21f354c356cd9100899a90a83068c68
Best regards,
Mike
Dear Users,
Version 4.25, 2008.06.01, urgency: MEDIUM:
* New features
- Win32 DLLs for OpenSSL 0.9.8h.
* Bugfixes
- Spawning libwrap processes delayed until privileges are dropped.
- Compilation fix for systems without struct msghdr.msg_control.
Home page/download: http://stunnel.mirt.net/
sha1sum for stunnel-4.24.tar.gz file:
fc6d61fad996f750c76ea627c5dd9f789af0eaf6
Best regards,
Mike
Dear Users,
I have just released a new version of stunnel.
Please find below the ChangeLog entry:
Version 4.23, 2008.05.03, urgency: HIGH:
* Bugfixes
- Local privilege escalation bug on Windows NT based
systems fixed. A local user could exploit stunnel
running as a service to gain localsystem privileges.
Home page/download: http://stunnel.mirt.net/
sha1sum for stunnel-4.23.tar.gz file:
d0fef8b518a44b9623692381a53680e0b4b01686
Best regards,
Mike
Dear Users,
Please test the new stunnel 4.21 and report your issues on the Bug Tracking
System (http://stunnel.mirt.net/bts.html) or email the information to the
stunnel-users mailing list. This is the easiest way to help stunnel working
fine on your various systems. I was developing it for quite a long time and
I likely failed to fix all the bugs. I'm especially interested in all
compilation or runtime issues with the new FIPS and libwrap code.
By the time you can find a patch for setuid/setgid+chroot problem here:
ftp://stunnel.mirt.net/stunnel/setuid.patch
Best regards,
Mike
Dear Users,
The new version is available for download on:
ftp://stunnel.mirt.net/stunnel/
Version 4.21, 2007.10.27, urgency: LOW/EXPERIMENTAL:
* New features sponsored by Open-Source Software Institute
- Initial FIPS 140-2 support (see INSTALL.FIPS for details).
Win32 platform is not currently supported.
* New features
- Experimental fast support for non-MT-safe libwrap is provided
with pre-spawned processes.
- Stunnel binary moved from /usr/local/sbin to /usr/local/bin
in order to meet FHS and LSB requirements.
Please delete the /usr/local/sbin/stunnel when upgrading.
- Added code to disallow compiling stunnel with pthreads when
OpenSSL is compiled without threads support.
- Win32 DLLs for OpenSSL 0.9.8g.
- Minor manual update.
- TODO file updated.
* Bugfixes
- Dynamic locking callbacks added (needed by some engines to work).
- AC_ARG_ENABLE fixed in configure.am to accept yes/no arguments.
- On some systems libwrap requires yp_get_default_domain from libnsl,
additional checking was added.
- Sending a list of trusted CAs for the client to choose the right
certificate restored.
- Some compatibility issues with NTLM authentication fixed.
- Taskbar icon (unless there is a config file parsing error) and
"Save As" disabled in the service mode for local Win32 security
(it's much like Yeti -- some people claim they have seen it).
sha1 hash for stunnel-4.21.tar.gz file:
7785c45167d902aa728b839adee02a8cc056d86a
Best regards,
Mike