| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: libtcnative-1-0-devel | Distribution: openSUSE Tumbleweed |
| Version: 1.3.9 | Vendor: openSUSE |
| Release: 1.1 | Build date: Fri Sep 25 09:00:34 2026 |
| Group: Development/Libraries/C and C++ | Build host: reproducible |
| Size: 38494 | Source RPM: libtcnative-1-0-1.3.9-1.1.src.rpm |
| Packager: http://bugs.opensuse.org | |
| Url: https://tomcat.apache.org/native-1.2-doc/index.html | |
| Summary: Tomcat resources for performance, compatibility, etc | |
The Apache Tomcat Native Library is an optional component for use with Apache Tomcat that allows Tomcat to use certain native resources for performance, compatibility, etc. Specifically, the Apache Tomcat Native Library gives Tomcat access to the Apache Portable Runtime (APR) library's network connection (socket) implementation and random-number generator. See the Apache Tomcat documentation for more information on how to configure Tomcat to use the APR connector. Features of the APR connector: * Non-blocking I/O for Keep-Alive requests (between requests) * Uses OpenSSL for TLS/SSL capabilities (if supported by linked APR library) * FIPS 140-2 support for TLS/SSL (if supported by linked OpenSSL library) * Support for IPv4, IPv6 and Unix Domain Sockets
Apache-2.0
* Fri Sep 25 2026 Fridrich Strba <fstrba@suse.com>
- Update to 1.3.9
* Security fixes
+ Client certificate requirements can be down-graded
(bsc#1282621, CVE-2026-86247)
A race condition allowed client certificate verification
requirements to be down-graded for some configurations.
+ Insecure OpenSSL options enabled (bsc#1282622, CVE-2026-86246)
Apache Tomcat Native enabled insecure options by default
including ALLOW_CLIENT_RENEGOTIATION,
NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and
ALLOW_NO_DHE_KEX.
+ DoS via TLS handshake (bsc#1282623, CVE-2026-86243)
A buffer over-read vulnerability in Apache Tomcat Native
during the TLS handshaking permits a malicious user to trigger
a DoS via a JVM crash.
* Changes
+ Code: Remove call to ERR_remove_thread_state() from Windows
specific code to allow building with OpenSSL 4.0.x.
ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got
removed in OpenSSL 4
+ Fix: Fix a potential crash when negotiating ALPN
+ If ALPN negotiation fails and failure is configured to use
the last server protocol in the list, use it rather than the
last protocol offered by the client
+ Fix: Add support for the extended range of options available
from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned
int (represented by a Java long) rather than a 32-bit unsigned
int (represented by a Java int)
+ Code: Remove unused code
+ Ensure that per connection changes to certificate verification
settings, e.g. to support client certificate authentication,
do not modify the certificate verification settings for other
connections
+ Fix: Fix a potential crash when configuring raw certificates
+ Fix: Avoid a potential crash with very long ALPN protocol
names
+ Fix: Make the call to a CertificateVerifier more robust
+ Fix: Avoid a potential crash when processing OCSP URLs
+ Fix: Make the processing of OCSP responses more robust
+ Fix: Stricter OCSP handling when soft-fail is disabled
+ Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
+ Fix: Harden against the mis-use of Pool.destroy(long)
+ Code: The minimum supported OpenSSL version is now 3.0.x.
OpenSSL 1.1.1 support was accidentally broken in 1.3.8. As no
bug reports were receive for that failure and since both
Debian and Ubuntu versions that used OpenSSL 1.1.1 have
reached end of support, OpenSSL 1.1.1 is no longer supported
+ Update: OpenSSL 3.0.x is approaching end of support so the
recommended version of OpenSSL (and the version that windows
binaries will be built with) now follows the 3.5.x LTS branch
+ Fix: Switch to automatic configuration of DH parameters.
Manual configuration attempts will be ignored
+ Code: Make setTmpECDHByCurveName() a NO-OP
+ Fix: Refactor extraction of ECDH curve name from the
Certificate to avoid deprecated OpenSSL methods
+ Fix: Refactor the native implementation of SSL.getTime() to
avoid the Y2038 problem in SSL_SESSION_get_time() when running
on a verion of OpenSSL that includes the new
SSL_SESSION_get_time_ex() method
- Added patch:
* 0001-Bring-back-OpenSSL-1.1.1-support.patch
+ restore openssl 1.1.1 support
* Tue Jun 16 2026 Fridrich Strba <fstrba@suse.com>
- Update to 1.3.8
* Changes
+ Fix a memory leak when parsing certificates
+ Fix two potential memory leaks on error paths identified by
Copilot
+ Fix post handshake authentication when Tomcat is configured
with a trust store using JSSE style configuration
+ Correct expected size of tickets when calling
SSLContext.setSessionTicketKeys
* Wed Mar 25 2026 Petr Gajdos <pgajdos@suse.com>
- Update to 1.3.7: [bsc#1260322]
1.3.7
* Code: Refactor access to ASN1_OCTET_STRING to use setters to fix
errors when building against the latest OpenSSL 4.0.x code. (markt)
* Fix: Fix the handling of OCSP requests with multiple responder URIs.
(jfclere)
* Fix: Fix the handling of TRY_AGAIN responses to OCSP requests when
soft fail is disabled. (jfclere)
1.3.6
* Code: Refactor the SSL_CONF_CTX clean-up to align it with SSL and
SSL_CTX clean-up. (markt)
* Fix: Fix unnecessarily large buffer allocation when filtering out NULL
and export ciphers. Pull requests #35 and #37 provided by chenjp.
(markt)
* Fix: Fix a potential memory leak if an invalid OpenSSLConf is
provided. Pull request #36 provided by chenjp. (markt)
* Fix: Refactor setting of OCSP configuration defaults as they were only
applied if the SSL_CONF_CTX was used. While one was always used with
Tomcat versions aware of the OCSP configuration options, one was not
always used with Tomcat versions unaware of the OCSP configuration
options leading to OCSP verification being enabled by default when the
expected behaviour was disabled by default. (markt)
* Code: Improve performance for the rare case of handling large OCSP
responses. (markt)
1.3.5
* Fix: Remove group write permissions from the files in the tar.gz
source archive. (markt)
* Fix: Clear an additional error in OCSP processing that was preventing
OCSP soft fail working with Tomcat's APR/native connector. (markt)
1.3.4
* Fix: Correct logic error that prevented the configuration of TLS 1.3
cipher suites. (markt)
1.3.3
* Fix: Refactor the addition of TLS 1.3 cipher suite configuration to
avoid a regression when running a version of Tomcat that pre-dates
this change. (markt)
1.3.2
* Update: Rename configure.in to modern autotools style configure.ac.
(rjung)
* Update: Fix incomplete updates for autotools generated files during
"buildconf" execution. (rjung)
* Update: Improve quoting in tcnative.m4. (rjung)
* Update: Update the minimum version of autoconf for releasing to 2.68.
(rjung)
* Fix: Fix the autoconf warnings when creating a release. (markt)
* Update: The Windows binaries are now built with OCSP support enabled
by default. (markt)
* Add: Include a nonce with OCSP requests and check the nonce, if any,
in the OCSP response. (markt)
* Add: Expand verification of OCSP responses. (markt)
* Add: Add the ability to configure the OCSP checks to soft-fail - i.e.
if the responder cannot be contacted or fails to respond in a timely
manner the OCSP check will not fail. (markt)
* Add: Add a configurable timeout to the writing of OCSP requests and
reading of OCSP responses. (markt)
* Add: Add the ability to control the OCSP verification flags. (markt)
* Add: Configure TLS 1.3 connections from the provided ciphers list as
well as connections using TLS 1.2 and earlier. Pull request provided
by gastush. (markt)
* Update: Update the Windows build environment to use Visual Studio
2022. (markt)
1.3.1
* Fix: Fix a crash on Windows when SSLContext.setCACertificate() is
invoked with a null value for caCertificateFile and a non-null value
for caCertificatePath until properly addressed with
https://github.com/openssl/openssl/issues/24416. (michaelo)
* Add: Use ERR_error_string_n with a definite buffer length as a named
constant. (schultz)
* Add: Ensure local reference capacity is available when creating new
arrays and Strings. (schultz)
* Update: Update the recommended minimum version of OpenSSL to 3.0.14.
(markt)
1.3.0
* Update: Drop useless compile.optimize option. (michaelo)
* Update: Align Java source compile configuration with Tomcat.
(michaelo)
* Fix: Fix version set in DLL header on Windows. (michaelo)
* Update: Remove an unreachable if condition around CRLs in
sslcontext.c. (michaelo)
* Fix: 67818: When calling SSL.setVerify() or SSLContext.setVerify(),
the default verify paths are no longer set. Only the explicitly
configured trust store, if any, will be used. (michaelo)
* Update: Update the minimum supported version of LibreSSL to 3.5.2.
(markt)
* Design: Remove NPN support as NPN was never standardised and browser
support was removed in 2019. (markt)
* Update: Update the recommended minimum version of OpenSSL to 3.0.13.
(markt)
* Sun Sep 29 2024 Fridrich Strba <fstrba@suse.com>
- Fix build after removal of the default %%{java_home} define
* Tue Feb 13 2024 Pedro Monreal <pmonreal@suse.com>
- Update to 1.2.39:
* Fix: 67061: If the insecure optionalNoCA certificate verification
mode is used, disable OCSP if enabled else client certificates
from unknown certificate authorities will be rejected.
* Update: Update the recommended minimum version of OpenSSL to
3.0.11.
* Change the hardcoded libopenssl-1_1-devel to libopenssl-devel
for distributions that have the right version
* Tue Nov 14 2023 Michele Bussolotto <michele.bussolotto@suse.com>
- Version update to version 1.2.38:
* Align default pass phrase prompt with HTTPd.
* #66669: Fix memory leak in SNI processing.
* Update the recommended minimum version of OpenSSL to 1.1.1v.
* Update the recommended minimum version of APR to 1.7.4.
* Document the TLS rengotiation behaviour.
* Add HOWTO-RELEASE.txt that describes the release process.
* Refactor library initialization so it is compatible with Tomcat
10.1.x onwards where a number of Java classes have been removed.
* Map the OpenSSL 3.x FIPS behaviour to the OpenSSL 1.x API to
allow clients to determine if the FIPS provider is being used
when Tomcat Native is compiled against OpenSSL 3.x.
* #66035: Fix crash when attempting to read TLS session ID after
a handshake failure.
* Enable download_deps.sh to be called from any directory.
* Fix release script so it works with the current git layout.
* #65441: Correct previous fix that enabled building to continue
with OpenSSL 3.x.
* #65659: Remove remaining reference to pkg-config which is no
longer included in the Tomcat Native distribution.
* #65181: Additional changes required to provided support for
using OpenSSL Engines that use proprietary key formats.
* #65329: Correct handling of WINVER in make file to use correct
constant for Windows 7. Add constants for Windows 8, Windows 8.1
and Windows 10. Rename WINNT to WIN2k as it is used for Windows
2000 upwards, not Windows NT upwards.
* Add a patch for APR that fixes an issue where some Windows
systems in some configurations would only listen on IPv6
addresses on dual stack systems even though configured to listen
on both IPv6 and IPv4 addresses.
* Correct a regression in the fix for 65181 that prevented an
error message from being displayed if an invalid key file was
provided and no OpenSSL Engine was configured.
* #65181: Improve support for using OpenSSL Engines that use
proprietary key formats.
* Enable building to continue against OpenSSL 3.x and 1.1.1.
* Incomplete name mangling fix for C++ compilers in tcn_api.h.
* Improve OS-specific header include for native thread id.
* Disable keylog callback support for LibreSSL.
* Add support for SSLContext.addChainCertificateRaw() with
LibreSSL 2.9.1 and up.
* Add support for HP-UX's _lwp_self() in our ssl_thread_id(void).
* Remove default option passed for rpath to linker on HP-UX.
* Add an option to allow the OCSP responder check to be bypassed.
Note that if OCSP is enabled, a missing responder is now treated
as an error.
* #64429: Fix compilation with LibreSSL.
* #63671: libtcnative does not compile with OpenSSL < 1.1.0 and
APR w/o threading support.
* Correct configure message for OpenSSL libdir.
* #64260: Clean up install target.
* #64315: configure output for OpenSSL wrong/incomplete sometimes.
* Drop obsolete build time workarounds for HP-UX.
* Add support for FreeBSD's pthread_getthreadid_np() in our
ssl_thread_id(void).
* #64316: Introduce tcn_get_thread_id(void) to reduce code
duplication.
* Fix linking against OpenSSL in non-standard locations on FreeBSD.
- Removed patch:
* libtcnative-1-0-bsc1199170.patch
+ fix integrated
* Fri Jul 29 2022 pgajdos@suse.com
- Fix for SG#63251, bsc#1199170 (thanks to ohollmann@suse.com)
- added patches
fix https://github.com/apache/tomcat-native/commit/5ac1175a0cf24aae2a285b3f3fb877ff83aef0c0
+ libtcnative-1-0-bsc1199170.patch
* Thu Nov 07 2019 Matei Albu <malbu@suse.com>
- Add GPG keyring.
* Mon Aug 12 2019 Matei Albu <malbu@suse.com>
- Version update to version 1.2.23:
* See changelog.html for in-depth upstream changes
* Thu Jun 06 2019 Matei <malbu@suse.com>
- Version update to version 1.2.21:
* See changelog.html for in-depth upstream changes
* Fix incompatibility with Tomcat (bsc#1130843)
/usr/include/ssl_private.h /usr/include/tcn.h /usr/include/tcn_api.h /usr/include/tcn_version.h /usr/share/licenses/libtcnative-1-0-devel /usr/share/licenses/libtcnative-1-0-devel/LICENSE /usr/share/licenses/libtcnative-1-0-devel/NOTICE
Generated by rpm2html 1.8.1
Fabrice Bellet, Fri Oct 2 22:42:39 2026