Skip to content

Releases: sonertari/SSLproxy

SSLproxy 0.9.11

Choose a tag to compare

@sonertari sonertari released this 28 Aug 12:34
  • Fix autossl connection stall with passthrough mode, pr #93 by @Drewsif
  • Add the StripClientHello option to prevent logging ClientHello during autossl upgrade, pr #92 by @Drewsif
  • Add TLS 1.3 master key logging via OpenSSL keylog callback, pr #91 by @wmetcalf
  • Update aho-corasick-1975
  • Trap signals for clean up in e2e tests

SSLproxy 0.9.10

Choose a tag to compare

@sonertari sonertari released this 14 Nov 18:23

This is a bugfix release due to issue #89 reported by @5u623l20.

SSLproxy 0.9.9

Choose a tag to compare

@sonertari sonertari released this 13 Nov 21:14
  • Fix fd leak, do not setup dst again in autossl, issue #88 reported by @victorjulien
  • Fix memory leak in config load, reported by valgrind
  • Disable r/w cbs and clear all cbs before all bufferevent_free() calls
    • Also, disable the events first, then clear the callbacks, for conventional pattern
  • Check fd usage before content logging, issue #88 reported by @victorjulien
    • This change is expected to prevent sslproxy to crash if it runs out of fds while content logging
  • Make sure the other conn end not closed before using it
  • Increase sizes of bufs used in ClientHello parsing as a defensive measure against modern TLS handshake sizes, suggested by @dpward
  • Use unused retvals from functions in autossl
  • Remove unused return value
  • Fix recursive expansion in main.mk, thanks to @dpward
  • Improve error handling and memory leak prevention in filter.c, for correctness, suggested and mostly implemented by Copilot
  • Simplify platform check in main.mk for UserAuth feature
  • Print version after unit tests in GitHub Actions

SSLproxy 0.9.8

Choose a tag to compare

@sonertari sonertari released this 08 May 13:15
  • Force SSL/TLS configuration in SSL proxyspecs
    SSL proxyspecs should always have a complete SSL/TLS configuration, even if their filter rules have complete SSL/TLS configuration, because it is very difficult, if not impossible, to check the coverage of filter rules to make sure we have complete SSL/TLS configuration if no filter rule matches, in which case sslproxy may crash
  • Fix crash if no global ca crt/key specified, issue #80 reported by @pranavbhalerao
  • Fix ClientHello parser for TLS 1.3, issue #84 reported by @GhostNaix
  • Fix unit tests on arm64 macOS, issue #81 reported by @jmayer
  • Suppress deprecation warnings for engines in unit tests with OpenSSL 3.x

SSLproxy 0.9.7

Choose a tag to compare

@sonertari sonertari released this 23 Oct 19:00
  • Fix deprecation warnings with OpenSSL 3.x for
    • DH_free()
    • DH config
    • ECDH config
    • RSA functions
    • Engines
  • Remove unused ssl_dh_refcount_inc()
  • Fix memleak, develop proto_free functions for pop3 and smtp, fixes issue #72 reported by @applehxb
  • Fix possible memleak and use after free for srchost_clean
  • Use strdup instead of strlen+malloc+memcpy in sys_sockaddr_str(), thanks to @disaykin
  • Use CLOCK_REALTIME to fix pcap timestamp, issue #78 thanks to @mdulaney

SSLproxy 0.9.6

Choose a tag to compare

@sonertari sonertari released this 06 Jul 14:01
  • Fix clang-static-analysis warnings, thanks to @disaykin
  • Use clock_gettime() instead of gettimeofday(), thanks to @disaykin
  • Fix deprecation warnings for function declarations without a prototype

SSLproxy 0.9.5

Choose a tag to compare

@sonertari sonertari released this 27 Feb 19:03
  • Fix possible double free of host and serv variables, thanks to @disaykin
  • Fix possible integer overflow, thanks to @disaykin
  • Close fds only once, thanks to @disaykin
  • Fix memory leak, thanks to @disaykin
  • Handle ftell error, thanks to @disaykin
  • Fix mismatched call arguments, thanks to @disaykin
  • Fix memory leak in case of cert key mismatch, thanks to @disaykin
  • Fix file descriptor leak, thanks to @disaykin
  • Handle partial write, thanks to @disaykin
  • Handle return value of gmtime(), thanks to @disaykin
  • Fix double free bugs, thanks to @disaykin
    • Bugs found by Svace static analyzer
  • Fix possible segfault in proto smtp in split mode
  • Fix retval of privsep_server_opensock_verify(), thanks to @Qbog
  • Fix header-size calculation in IPv6 packet mirroring, thanks to @matoro
  • Fix e2e tests with openssl 3
  • Replace deprecated fail_unless() with ck_assert_msg() in unit tests

SSLproxy 0.9.4

Choose a tag to compare

@sonertari sonertari released this 30 Dec 10:12
  • Fix byte order for ports in mirror trafic, thanks to @piolug93.
  • Fix unit tests with opaque x509 struct.
  • Update testproxy version to 0.0.5.
  • Fix warning for array subscript outside array bounds in function declaration.

SSLproxy 0.9.3

Choose a tag to compare

@sonertari sonertari released this 10 May 08:49
  • Implement a generic upgrade mechanism with autossl, without STARTTLS.
  • Refactor and improve autossl and split mode.
  • Fix watermarking for underlying buffers in autossl.
  • Fix macOS header selection, update XNU headers for macOS, and re-enable osx on Travis CI.
  • Fix the natengine option passed in proxyspecs on command line.
  • Fix enabling of pcap and mirror logging.
  • Fix build errors with OpenSSL 3.x.

SSLproxy 0.9.2

Choose a tag to compare

@sonertari sonertari released this 15 Nov 18:27
  • Update with the license change of the Aho Corasick library to the LGPL.
  • Migrate to travis-ci.com.
  • Various fixes and improvements.