Index index by Group index by Distribution index by Vendor index by creation date index by Name Mirrors Help Search

libtcnative-2-0-2.0.16-1.1 RPM for s390x

From OpenSuSE Ports Tumbleweed for s390x

Name: libtcnative-2-0 Distribution: openSUSE:Factory:zSystems
Version: 2.0.16 Vendor: openSUSE
Release: 1.1 Build date: Fri Sep 25 07:40:19 2026
Group: Productivity/Networking/Web/Servers Build host: reproducible
Size: 101535 Source RPM: libtcnative-2-0-2.0.16-1.1.src.rpm
Packager: https://bugs.opensuse.org
Url: https://tomcat.apache.org/native-doc/index.html
Summary: Tomcat resources for performance, compatibility, etc
The Apache Tomcat Native Library is an optional component for use
with Apache Tomcat that allows Tomcat to use OpenSSL as a
replacement for JSSE to support TLS connections.

Provides

Requires

License

Apache-2.0

Changelog

* Fri Sep 25 2026 Fridrich Strba <fstrba@suse.com>
  - Upgrade to version 2.0.16
    * Security fixes
      + Client certificate requirements can be down-graded
      (bsc#1282621, CVE-2026-86247)
      A race condition allowed client certificate verification
      requirements to be down-graded for some configurations.
      + Insecure OpenSSL options enabled (bsc#1282622, CVE-2026-86246)
      Apache Tomcat Native enabled insecure options by default
      including ALLOW_CLIENT_RENEGOTIATION,
      NO_EXTENDED_MASTER_SECRET, IGNORE_UNEXPECTED_EOF and
      ALLOW_NO_DHE_KEX.
      + DoS via TLS handshake (bsc#1282623, CVE-2026-86243)
      A buffer over-read vulnerability in Apache Tomcat Native
      during the TLS handshaking permits a malicious user to trigger
      a DoS via a JVM crash.
    * Changes
      + Code: Remove call to ERR_remove_thread_state() from Windows
      specific code to allow building with OpenSSL 4.0.x
      ERR_remove_thread_state() is a no-op in OpenSSL 1.1+ and got
      removed in OpenSSL 4
      + Update: Remove support for Windows build on IA64 architecture
      (Itanium)
      + Update: Make x64 the default architecture for Windows build
      + Update: Make Windows 10 / 11 the default target version for
      Windows builds
      + Fix: Fix a potential crash when negotiating ALPN
      + Fix: If ALPN negotiation fails and failure is configured to
      use the last server protocol in the list, use it rather than
      the last protocol offered by the client
      + Fix: Add support for the extended range of options available
      from OpenSSL 3.0.x. The options flag is now a 64-bit unsigned
      int (represented by a Java long) rather than a 32-bit unsigned
      int (represented by a Java int)
      + Code: Remove unused code
      + Fix: Ensure that per connection changes to certificate
      verification settings, e.g. to support client certificate
      authentication, do not modify the certificate verification
      settings for other connections
      + Fix: Fix a potential crash when configuring raw certificates
      + Fix: Avoid a potential crash with very long ALPN protocol
      names
      + Fix: Make the call to a CertificateVerifier more robust
      + Fix: Avoid a potential crash when processing OCSP URLs
      + Fix: Make the processing of OCSP responses more robust
      + Fix: Stricter OCSP handling when soft-fail is disabled
      + Fix: Harden against the mis-use of Buffer.address(ByteBuffer)
      + Fix: Harden against the mis-use of Pool.destroy(long)
* Tue Jun 16 2026 Fridrich Strba <fstrba@suse.com>
  - Upgrade to version 2.0.15
    * Changes
      + Fix a memory leak when parsing certificates
      + Fix two potential memory leaks on error paths identified by
      Copilot
      + Fix post handshake authentication Tomcat is configured with a
      trust store using JSSE style configuration
      + Correct expected size of tickets when calling
      SSLContext.setSessionTicketKeys
* Tue Apr 07 2026 Fridrich Strba <fstrba@suse.com>
  - Upgrade to version 2.0.14
    * Changes of 2.0.14
      + Code: Refactor access to ASN1_OCTET_STRING to use setters to
      fix errors when building against the latest OpenSSL 4.0.x code
      + Fix: Fix the handling of OCSP requests with multiple responder
      URIs
      + Fix: Fix the handling of TRY_AGAIN responses to OCSP requests
      when soft fail is disabled.
    * Changes of 2.0.13
      + Code: Due to various refactorings, the 2.0.x code no longer
      compiles with LibreSSL. Without a volunteer to maintain
      LibreSSL support, the LibreSSL code will be removed no earlier
      than 30 September 2026
      + Fix: Remove group write permissions from the files in the
      tar.gz source archive
      + Code: Refactor the SSL_CONF_CTX clean-up to align it with SSL
      and SSL_CTX clean-up
      + Fix: Fix unnecessarily large buffer allocation when filtering
      out NULL and export ciphers. Pull requests #35 and #37
      provided by chenjp
      + Fix: Fix a potential memory leak if an invalid OpenSSLConf is
      provided. Pull request #36 provided by chenjp. (markt)
      + Fix: Refactor setting of OCSP configuration defaults as they
      were only applied if the SSL_CONF_CTX was used. While one was
      always used with Tomcat versions aware of the OCSP
      configuration options, one was not always used with Tomcat
      versions unaware of the OCSP configuration options leading to
      OCSP verification being enabled by default when the expected
      behaviour was disabled by default
      + Code: Improve performance for the rare case of handling large
      OCSP responses
      + Fix: 69939: Fix the cause of a crash with OpenSSL 3.0.x when a
      certificate PEM file does not contain explicit DH parameters
      + Fix: Refactor extraction of ECDH curve name from the
      Certificate to avoid deprecated OpenSSL methods.
      + Fix: Refactor the native implementation of SSL.getTime() to
      avoid the Y2038 problem in SSL_SESSION_get_time() when running
      on a version of OpenSSL that includes the new
      SSL_SESSION_get_time_ex() method.
  - Build against libopenssl-3-devel and not against the meta-package
    libopenssl-devel. This allows buiding on distributions where the
    openssl-3 exists, but is not default
  - Added patch:
    * apr163.patch
      + Allow building and running against libapr-1 1.6.3
* Mon Feb 09 2026 Michele Bussolotto <michele.bussolotto@suse.com>
  - Add conflict to previous devel version
* Thu Feb 05 2026 Michele Bussolotto <michele.bussolotto@suse.com>
  - The first release in SUSE (2.0.12)
    * fix of enhancenment request (bsc#1232390)

Files

/usr/lib64/libtcnative-2.so
/usr/lib64/libtcnative-2.so.0
/usr/lib64/libtcnative-2.so.0.0.16
/usr/share/doc/packages/libtcnative-2-0
/usr/share/doc/packages/libtcnative-2-0/CHANGELOG.txt
/usr/share/doc/packages/libtcnative-2-0/README.txt


Generated by rpm2html 1.8.1

Fabrice Bellet, Tue Sep 29 22:49:03 2026