| Index | index by Group | index by Distribution | index by Vendor | index by creation date | index by Name | Mirrors | Help | Search |
| Name: libtcnative-2-0 | Distribution: openSUSE:Factory:zSystems |
| Version: 2.0.16 | Vendor: openSUSE |
| Release: 1.1 | Build date: Fri Sep 25 07:40:19 2026 |
| Group: Productivity/Networking/Web/Servers | Build host: reproducible |
| Size: 101535 | Source RPM: libtcnative-2-0-2.0.16-1.1.src.rpm |
| Packager: https://bugs.opensuse.org | |
| Url: https://tomcat.apache.org/native-doc/index.html | |
| Summary: Tomcat resources for performance, compatibility, etc | |
The Apache Tomcat Native Library is an optional component for use with Apache Tomcat that allows Tomcat to use OpenSSL as a replacement for JSSE to support TLS connections.
Apache-2.0
* Fri Sep 25 2026 Fridrich Strba <fstrba@suse.com>
- Upgrade to version 2.0.16
* Security fixes
+ Client certificate requirements can be down-graded
(bsc#1282621, CVE-2026-86247)
A race condition allowed client certificate verification
requirements to be down-graded for some configurations.
+ Insecure OpenSSL options enabled (bsc#1282622, CVE-2026-86246)
Apache Tomcat Native enabled insecure options by default
including ALLOW_CLIENT_RENEGOTIATION,
NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and
ALLOW_NO_DHE_KEX.
+ DoS via TLS handshake (bsc#1282623, CVE-2026-86243)
A buffer over-read vulnerability in Apache Tomcat Native
during the TLS handshaking permits a malicious user to trigger
a DoS via a JVM crash.
* Changes
+ Code: Remove call to ERR_remove_thread_state() from Windows
specific code to allow building with OpenSSL 4.0.x
ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got
removed in OpenSSL 4
+ Update: Remove support for Windows build on IA64 architecture
(Itanium)
+ Update: Make x64 the default architecture for Windows build
+ Update: Make Windows 10 / 11 the default target version for
Windows builds
+ Fix: Fix a potential crash when negotiating ALPN
+ Fix: If ALPN negotiation fails and failure is configured to
use the last server protocol in the list, use it rather than
the last protocol offered by the client
+ Fix: Add support for the extended range of options available
from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned
int (represented by a Java long) rather than a 32-bit unsigned
int (represented by a Java int)
+ Code: Remove unused code
+ Fix: Ensure that per connection changes to certificate
verification settings, e.g. to support client certificate
authentication, do not modify the certificate verification
settings for other connections
+ Fix: Fix a potential crash when configuring raw certificates
+ Fix: Avoid a potential crash with very long ALPN protocol
names
+ Fix: Make the call to a CertificateVerifier more robust
+ Fix: Avoid a potential crash when processing OCSP URLs
+ Fix: Make the processing of OCSP responses more robust
+ Fix: Stricter OCSP handling when soft-fail is disabled
+ Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
+ Fix: Harden against the mis-use of Pool.destroy(long)
* Tue Jun 16 2026 Fridrich Strba <fstrba@suse.com>
- Upgrade to version 2.0.15
* Changes
+ Fix a memory leak when parsing certificates
+ Fix two potential memory leaks on error paths identified by
Copilot
+ Fix post handshake authentication Tomcat is configured with a
trust store using JSSE style configuration
+ Correct expected size of tickets when calling
SSLContext.setSessionTicketKeys
* Tue Apr 07 2026 Fridrich Strba <fstrba@suse.com>
- Upgrade to version 2.0.14
* Changes of 2.0.14
+ Code: Refactor access to ASN1_OCTET_STRING to use setters to
fix errors when building against the latest OpenSSL 4.0.x code
+ Fix: Fix the handling of OCSP requests with multiple responder
URIs
+ Fix: Fix the handling of TRY_AGAIN responses to OCSP requests
when soft fail is disabled.
* Changes of 2.0.13
+ Code: Due to various refactorings, the 2.0.x code no longer
compiles with LibreSSL. Without a volunteer to maintain
LibreSSL support, the LibreSSL code will be removed no earlier
than 30 September 2026
+ Fix: Remove group write permissions from the files in the
tar.gz source archive
+ Code: Refactor the SSL_CONF_CTX clean-up to align it with SSL
and SSL_CTX clean-up
+ Fix: Fix unnecessarily large buffer allocation when filtering
out NULL and export ciphers. Pull requests #35 and #37
provided by chenjp
+ Fix: Fix a potential memory leak if an invalid OpenSSLConf is
provided. Pull request #36 provided by chenjp. (markt)
+ Fix: Refactor setting of OCSP configuration defaults as they
were only applied if the SSL_CONF_CTX was used. While one was
always used with Tomcat versions aware of the OCSP
configuration options, one was not always used with Tomcat
versions unaware of the OCSP configuration options leading to
OCSP verification being enabled by default when the expected
behaviour was disabled by default
+ Code: Improve performance for the rare case of handling large
OCSP responses
+ Fix: 69939: Fix the cause of a crash with OpenSSL 3.0.x when a
certificate PEM file does not contain explicit DH parameters
+ Fix: Refactor extraction of ECDH curve name from the
Certificate to avoid deprecated OpenSSL methods.
+ Fix: Refactor the native implementation of SSL.getTime() to
avoid the Y2038 problem in SSL_SESSION_get_time() when running
on a version of OpenSSL that includes the new
SSL_SESSION_get_time_ex() method.
- Build against libopenssl-3-devel and not against the meta-package
libopenssl-devel. This allows buiding on distributions where the
openssl-3 exists, but is not default
- Added patch:
* apr163.patch
+ Allow building and running against libapr-1 1.6.3
* Mon Feb 09 2026 Michele Bussolotto <michele.bussolotto@suse.com>
- Add conflict to previous devel version
* Thu Feb 05 2026 Michele Bussolotto <michele.bussolotto@suse.com>
- The first release in SUSE (2.0.12)
* fix of enhancenment request (bsc#1232390)
/usr/lib64/libtcnative-2.so /usr/lib64/libtcnative-2.so.0 /usr/lib64/libtcnative-2.so.0.0.16 /usr/share/doc/packages/libtcnative-2-0 /usr/share/doc/packages/libtcnative-2-0/CHANGELOG.txt /usr/share/doc/packages/libtcnative-2-0/README.txt
Generated by rpm2html 1.8.1
Fabrice Bellet, Tue Sep 29 22:49:03 2026