2018-04-03 - firstname.lastname@example.org
- Add BuildRequires pkgconfig(libpcsclite/libpskc) to enable
liboath (TOTP/HOTP) and yubikey support.
2017-12-08 - email@example.com
- Add explicit python2-base and python2-xml BuildRequires: the
buildsystem checks for python2 and disables building the
documentation if not found. Buildinf the documentation in plus
depends on the xml modules.
So far we relied on other packages pulling in python2 for us.
2017-09-25 - firstname.lastname@example.org
- Drop vpnc dependency by including vpnc-script from vpnc package
2016-12-16 - email@example.com
- update to version 7.08 (bsc#1056389)
* Add SHA256 support for server cert hashes.
* Enable DHE ciphers for Cisco DTLS.
* Increase initial oNCP configuration buffer size.
* Improve support for point-to-point routing on Windows.
* Check for non-resumed DTLS sessions which may indicate a MiTM attack.
* Fix compatibility with Pulse Secure 8.2R5.
* Support DTLS automatic negotiation.
* Support --key-password for GnuTLS PKCS#11 PIN.
* Support automatic DTLS MTU detection with OpenSSL.
* Update OpenSSL to allow TLSv1.2, improve compatibility options.
* Remove --no-cert-check option. It was being (mis)used.
* Fix OpenSSL support for PKCS#11 EC keys without public key.
* Fix polling/retry on "tun" socket when buffers full.
* Fix AnyConnect server-side MTU setting.
* Fix ESP replay detection.
* Add certificate torture test suite.
* Support PKCS#11 PIN via pin-value= and --key-password for OpenSSL.
* Fix integer overflow issues with ESP packet replay detection.
* Add --pass-tos option as in OpenVPN.
* Support role selection form in Juniper VPN.
* Support DER-format certificates, add certificate format torture tests.
* For OpenSSL >= 1.0.2, fix certificate validation when only an
intermediate CA is specified with the --cafile option.
* Support Juniper "Pre Sign-in Message".
- dropped juniper-fix-for-upstream-sources.patch, upstreamed
2016-10-04 - firstname.lastname@example.org
- Upgraded to 7.07, included fix for Juniper vpn
2016-10-04 - email@example.com
- Update to version 7.0.7
* More fixes for OpenSSL 1.1 build.
* Support Juniper "Post Sign-in Message".
* Add --protocol option.
* Fix ChaCha20-Poly1305 cipher suite to reflect final standard.
* Add ability to disable IPv6 support via library API.
* Set groups appropriately when using setuid().
* Automatic DTLS MTU detection.
* Support SSL client certificate authentication with Juniper servers.
* Revamp SSL certificate validation for OpenSSL and stop supporting OpenSSL older than 0.9.8.
* Fix handling of multiple DNS search domains with Network Connect.
* Fix handling of large configuration packets for Network Connect.
* Enable SNI when built with OpenSSL (1.0.1g or later).
* Add --resolve and --local-hostname options to command line.
- juniper-fix-for-upstream-sources.patch included to fix upgraded Juniper servers
* Submitted to upstream, not yet included in release
2015-03-17 - firstname.lastname@example.org
- Update to version 7.0.6
* Fix openconnect.pc breakage after liboath removal.
* Refactor Juniper Network Connect receive loop.
* Fix some memory leaks.
* Add Bosnian translation.
2015-03-11 - email@example.com
- Update to version 7.0.5
* Fix alignment issue which broke LZS compression on ARM etc.
* Support HTTP authentication to servers, not just proxies.
* Add SHA256/SHA512 support for OATH.
* Remove liboath dependency.
* Support DTLS v1.2 and AES-GCM with OpenSSL 1.0.2.
* Add OpenSSL 1.0.2 to known-broken releases (RT#3703, RT#3711).
* Fix build with OpenSSL HEAD (OpenSSL 1.1.x).
* Preliminary support for Juniper SSL VPN.
2015-01-26 - firstname.lastname@example.org
- Update to Version 7.04
* Change default behaviour to enable only stateless compression.
* Add --compression argument and openconnect_set_compression_mode().
* Add support for LZS compression
* Add support for LZ4 compression
- Add liblz4-devel dependency for LZ4 compression support.