X-Git-Url: https://ruderich.org/simon/gitweb/?p=tlsproxy%2Ftlsproxy.git;a=blobdiff_plain;f=NEWS;h=3f3c66399e1542a28d592d0d374be246c570ded1;hp=4327d395f9309e2165147f9529592a41da2eaa4c;hb=412b6491a940ba3de97e5be95bd35197e51ee210;hpb=6d66815519fcf6733651adb7c81c737fa2fe4189 diff --git a/NEWS b/NEWS index 4327d39..3f3c663 100644 --- a/NEWS +++ b/NEWS @@ -4,14 +4,28 @@ NEWS 0.X --- +- Important: The file proxy-dh.pem is now required. tlsproxy-setup creates it, + but running it will overwrite the existing proxy-*.pem files (which will + invalidate all certificate-*-proxy.pem files). To create only proxy-dh.pem + use: + + certtool --generate-dh-params --sec-param high --outfile proxy-dh.pem + +- Use "SECURE" as GnuTLS priority string which disallows insecure algorithms. - Add -a option, authentication for tlsproxy via basic digest authentication. +- Add new debug level (-d 3) for even more debug output, including information + about the current TLS session. +- Allow rehandshakes for server connections (%SAFE_RENEGOTIATION is forced to + prevent issues). +- Use pre-generated Diffie-Hellman parameters in proxy-dh.pem. - Code cleanup. - Better error handling. - Fix compile with recent GnuTLS (e.g. 3.2.3). - Improve (error) logging; log to stderr. - Add (basic) man pages. - Improve test suite. -- tlsproxy-setup: Increase expiry-date and use larger private key. +- tlsproxy-setup: Increase expiry-date and use larger private key, generate + proxy-dh.pem. 0.2