aboutsummaryrefslogtreecommitdiffstats
path: root/NEWS
diff options
context:
space:
mode:
authorMatthias Andree <matthias.andree@gmx.de>2009-01-22 12:11:16 +0000
committerMatthias Andree <matthias.andree@gmx.de>2009-01-22 12:11:16 +0000
commit4691082c9b0659476e919bd7a8a30ec1b5537a7c (patch)
tree7af723caa9b77b25c8819f42f8432d777e5824dc /NEWS
parentaf7d73c7ab76ad81fed78b7f5c024daf1af87d9d (diff)
downloadfetchmail-4691082c9b0659476e919bd7a8a30ec1b5537a7c.tar.gz
fetchmail-4691082c9b0659476e919bd7a8a30ec1b5537a7c.tar.bz2
fetchmail-4691082c9b0659476e919bd7a8a30ec1b5537a7c.zip
case-insensitive check of SSL fingerprints (Daniel Richard G.)
Daniel Richard G. writes: | I was clearing out an old Fetchmail SVN checkout I had lying around | here, and came across one small change that I forgot to send in. | | In socket.c, there's a bit of code that compares SSL certificate | fingerprints: [...] | | That strcmp() call should be an strcasecmp(). At one point, I | encountered a certificate where the fingerprint's hex digits were in a | different case than what was expected, and the connection attempt failed | because of that. Not exactly what you'd call a potential MitM attack | :-) He's right, we can compare case-insensitively without sacrificing fetchmail's security, so let's just do that for the sake of ease of use. svn path=/branches/BRANCH_6-3/; revision=5262
Diffstat (limited to 'NEWS')
-rw-r--r--NEWS3
1 files changed, 3 insertions, 0 deletions
diff --git a/NEWS b/NEWS
index b026effb..a86d05c0 100644
--- a/NEWS
+++ b/NEWS
@@ -57,6 +57,9 @@ fetchmail 6.3.10 (not yet released):
* Do not overlap source and destination fields in snprintf() in interface.c.
Courtesy of Nico Golde, Debian.
+# CHANGES
+* Make the comparison of the SSL fingerprints case insensitive, to
+ ease its use. Suggested by Daniel Richard G.
# TRANSLATION UPDATES AND ADDITIONS (ordered by language name):
* [it] Italian (Vincenzo Campanella)