Requests: https GET ์š”์ฒญ์ด "ํ•ธ๋“œ์…ฐ์ดํฌ ์‹คํŒจ"์™€ ํ•จ๊ป˜ ์‹คํŒจํ•ฉ๋‹ˆ๋‹ค.

์— ๋งŒ๋“  2014๋…„ 04์›” 26์ผ  ยท  83์ฝ”๋ฉ˜ํŠธ  ยท  ์ถœ์ฒ˜: psf/requests

์•„๋งˆ๋„ #1083๊ณผ ๊ด€๋ จ์ด ์žˆ์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ด ํŠน์ • ์‚ฌ์ดํŠธ/ํŽ˜์ด์ง€ https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html $์— ๋Œ€ํ•œ ํ‘œ์ค€ requests.get() #$ ๊ฒฐ๊ณผ:

>>> import requests
>>> requests.get('https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html')
Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/api.py", line 55, in get
    return request('get', url, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/api.py", line 44, in request
    return session.request(method=method, url=url, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 383, in request
    resp = self.send(prep, **send_kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 486, in send
    r = adapter.send(request, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/adapters.py", line 385, in send
    raise SSLError(e)
requests.exceptions.SSLError: [Errno 1] _ssl.c:504: error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure

request-toolbelt ์˜ SSLAdapter ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค์–‘ํ•œ ssl ๋ฒ„์ „์„ ์‹œ๋„ํ•˜๋ฉด ๋ชจ๋‘ ์‹คํŒจํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ์—ญ์ถ”์ ์„ ์ฐธ์กฐํ•˜์„ธ์š”.

TLSv1:

>>> adapter = SSLAdapter('TLSv1')
>>> s = requests.Session()
>>> s.mount('https://', adapter)
>>> s.get('https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html')
Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 395, in get
    return self.request('GET', url, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 383, in request
    resp = self.send(prep, **send_kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 486, in send
    r = adapter.send(request, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/adapters.py", line 385, in send
    raise SSLError(e)
requests.exceptions.SSLError: [Errno 1] _ssl.c:504: error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure

SSLv3:

>>> adapter = SSLAdapter('SSLv3')
>>> s = requests.Session()
>>> s.mount('https://', adapter)
>>> s.get('https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html')
Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 395, in get
    return self.request('GET', url, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 383, in request
    resp = self.send(prep, **send_kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 486, in send
    r = adapter.send(request, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/adapters.py", line 385, in send
    raise SSLError(e)
requests.exceptions.SSLError: [Errno 1] _ssl.c:504: error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure

SSLv2:

>>> adapter = SSLAdapter('SSLv2')
>>> s = requests.Session()
>>> s.mount('https://', adapter)
>>> s.get('https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html')
Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 395, in get
    return self.request('GET', url, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 383, in request
    resp = self.send(prep, **send_kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 486, in send
    r = adapter.send(request, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/adapters.py", line 378, in send
    raise ConnectionError(e)
requests.exceptions.ConnectionError: HTTPSConnectionPool(host='docs.apitools.com', port=443): Max retries exceeded with url: /2014/04/24/a-small-router-for-openresty.html (Caused by <class 'socket.error'>: [Errno 54] Connection reset by peer)

๋งˆ์ง€๋ง‰ ๊ฒƒ์€ ๋‹ค๋ฅธ ๊ฒƒ๋“ค๊ณผ ๋‹ค๋ฅธ Connection reset by peer ์˜ค๋ฅ˜๋ฅผ ์ œ๊ณตํ•˜์ง€๋งŒ ์–ด์จŒ๋“  SSLv2๋Š” ์„œ๋ฒ„์—์„œ ์ง€์›๋˜์ง€ ์•Š๋Š”๋‹ค๊ณ  ํ™•์‹ ํ•ฉ๋‹ˆ๋‹ค.

์žฌ๋ฏธ๋ฅผ ์œ„ํ•ด ๋งˆ์ง€๋ง‰ ์š”์ฒญ์—์„œ๋„ ์ข€ ๋” ์ ์ ˆํ•œ ํ—ค๋”๋ฅผ ์ „๋‹ฌํ•˜๋ ค๊ณ  ํ–ˆ์Šต๋‹ˆ๋‹ค.

>>> headers = {
...     'Accept': u"text/html,application/xhtml+xml,application/xml",
...     'User-Agent': u"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/34.0.1847.131 Safari/537.36",
...     'Accept-Encoding': u"gzip,deflate",
...     'Accept-Language': u"en-US,en;q=0.8"
... }
>>> adapter = SSLAdapter('SSLv2')
>>> s = requests.Session()
>>> s.mount('https://', adapter)
>>> s.get('https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html', headers=headers)
Traceback (most recent call last):
  File "<stdin>", line 1, in <module>
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 395, in get
    return self.request('GET', url, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 383, in request
    resp = self.send(prep, **send_kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/sessions.py", line 486, in send
    r = adapter.send(request, **kwargs)
  File "/Users/jaddison/.virtualenvs/techtown/lib/python2.7/site-packages/requests/adapters.py", line 378, in send
    raise ConnectionError(e)
requests.exceptions.ConnectionError: HTTPSConnectionPool(host='docs.apitools.com', port=443): Max retries exceeded with url: /2014/04/24/a-small-router-for-openresty.html (Caused by <class 'socket.error'>: [Errno 54] Connection reset by peer)

๊ฑฐ๊ธฐ์— ์ฃผ์‚ฌ์œ„๋„ ์—†์Šต๋‹ˆ๋‹ค. Mac์šฉ Chrome์˜ HTTPS ์—ฐ๊ฒฐ ์ •๋ณด๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

screen shot 2014-04-26 at 10 35 21 am

๋‚˜๋Š” ๊ธ์ •์ ์ด์ง€ ์•Š์ง€๋งŒ ์ผ๋ถ€ ์ธํ„ฐ๋„ท ๊ฒ€์ƒ‰์€ ๊ทธ๊ฒƒ์ด ๋” ๋งŽ์€ urllib3์ธ ์•”ํ˜ธ ๋ชฉ๋ก ๋ฌธ์ œ์ผ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Œ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.

DEFAULT_CIPHER_LIST in pyopenssl ์„ ์ˆ˜์ •ํ•˜๋ ค๊ณ  ํ–ˆ์ง€๋งŒ ๊ฐ€์ ธ์˜ค๊ธฐ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•˜๊ธฐ ์‹œ์ž‘ํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด ์‹œ์ ์—์„œ ๋ชจ๋“  ๊ฒƒ์ด ๊ณ ์žฅ๋‚œ ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์˜€๊ณ  ์•„์ง ์ด๋ฅผ ๊ณ ์น  ์ ์ ˆํ•œ ์ ‘๊ทผ ๋ฐฉ์‹์ด ์—†์—ˆ์Šต๋‹ˆ๋‹ค.

๋ฒ„์ „ ์ •๋ณด:
OSX ๋งค๋ฒ„๋ฆญ์Šค
ํŒŒ์ด์ฌ 2.7.5
OpenSSL 0.9.8y 2013๋…„ 2์›” 5์ผ - ( python -c "import ssl; print ssl.OPENSSL_VERSION" ๋ถ€ํ„ฐ)
์š”์ฒญ 2.2.1
์š”์ฒญ ๋„๊ตฌ ๋ฒจํŠธ 0.2.0
urllib3 1.8

๊ฐ€์žฅ ์œ ์šฉํ•œ ๋Œ“๊ธ€

์Šฌํ”„๊ฒŒ๋„ ์ด๊ฒƒ์€ ๊ท€ํ•˜๊ฐ€ ์‹๋ณ„ํ•œ ๋ฌธ์ œ์™€ ๊ด€๋ จ์ด ์—†์œผ๋ฉฐ ์ „์ ์œผ๋กœ OS X์ด ๊ธฐ๋ณธ์ ์œผ๋กœ ์ œ๊ณต๋˜๋Š” ์—‰ํ„ฐ๋ฆฌ OpenSSL์— ๋‹ฌ๋ ค ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฒ„์ „ 0.9.8y๋Š” SSL ํ•ธ๋“œ์…ฐ์ดํฌ๋ฅผ ์ˆ˜ํ–‰ํ•˜๋Š” ๋ฐ ๋ช‡ ๊ฐ€์ง€ ์‹ค์ œ ๋ฌธ์ œ๊ฐ€ ์žˆ์œผ๋ฉฐ ์ผ๋ถ€ ์„œ๋ฒ„๋Š” ์ด๋ฅผ ์ž˜ ์šฉ๋‚ฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋‚ด OS X ์ƒ์ž์—์„œ Python 3์„ ์‚ฌ์šฉํ•˜๋ฉด(๋”ฐ๋ผ์„œ ์ตœ์‹  OpenSSL ์‚ฌ์šฉ) ๋ฌธ์ œ๊ฐ€ ์—†์Œ์„ ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋‘ ๊ฐ€์ง€ ์˜ต์…˜์ด ์žˆ์Šต๋‹ˆ๋‹ค.

  1. Homebrew์—์„œ OpenSSL์„ ์„ค์น˜ํ•œ ๋‹ค์Œ Homebrew์—์„œ ์ œ๊ณตํ•˜๋Š” OpenSSL๊ณผ ์ž๋™์œผ๋กœ ์—ฐ๊ฒฐ๋˜๋Š” ์ƒˆ ๋ฒ„์ „์˜ Python 2๋ฅผ Homebrew์—์„œ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.
  2. Homebrew์—์„œ OpenSSL์„ ์„ค์น˜ํ•œ ๋‹ค์Œ env ARCHFLAGS="-arch x86_64" LDFLAGS="-L/usr/local/opt/openssl/lib" CFLAGS="-I/usr/local/opt/openssl/include" pip install PyOpenSSL ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ƒˆ ๋ฒ„์ „์— ๋Œ€ํ•ด PyOpenSSL์„ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

๋ชจ๋“  83 ๋Œ“๊ธ€

์Šฌํ”„๊ฒŒ๋„ ์ด๊ฒƒ์€ ๊ท€ํ•˜๊ฐ€ ์‹๋ณ„ํ•œ ๋ฌธ์ œ์™€ ๊ด€๋ จ์ด ์—†์œผ๋ฉฐ ์ „์ ์œผ๋กœ OS X์ด ๊ธฐ๋ณธ์ ์œผ๋กœ ์ œ๊ณต๋˜๋Š” ์—‰ํ„ฐ๋ฆฌ OpenSSL์— ๋‹ฌ๋ ค ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฒ„์ „ 0.9.8y๋Š” SSL ํ•ธ๋“œ์…ฐ์ดํฌ๋ฅผ ์ˆ˜ํ–‰ํ•˜๋Š” ๋ฐ ๋ช‡ ๊ฐ€์ง€ ์‹ค์ œ ๋ฌธ์ œ๊ฐ€ ์žˆ์œผ๋ฉฐ ์ผ๋ถ€ ์„œ๋ฒ„๋Š” ์ด๋ฅผ ์ž˜ ์šฉ๋‚ฉํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๋‚ด OS X ์ƒ์ž์—์„œ Python 3์„ ์‚ฌ์šฉํ•˜๋ฉด(๋”ฐ๋ผ์„œ ์ตœ์‹  OpenSSL ์‚ฌ์šฉ) ๋ฌธ์ œ๊ฐ€ ์—†์Œ์„ ์•Œ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋‘ ๊ฐ€์ง€ ์˜ต์…˜์ด ์žˆ์Šต๋‹ˆ๋‹ค.

  1. Homebrew์—์„œ OpenSSL์„ ์„ค์น˜ํ•œ ๋‹ค์Œ Homebrew์—์„œ ์ œ๊ณตํ•˜๋Š” OpenSSL๊ณผ ์ž๋™์œผ๋กœ ์—ฐ๊ฒฐ๋˜๋Š” ์ƒˆ ๋ฒ„์ „์˜ Python 2๋ฅผ Homebrew์—์„œ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.
  2. Homebrew์—์„œ OpenSSL์„ ์„ค์น˜ํ•œ ๋‹ค์Œ env ARCHFLAGS="-arch x86_64" LDFLAGS="-L/usr/local/opt/openssl/lib" CFLAGS="-I/usr/local/opt/openssl/include" pip install PyOpenSSL ๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ƒˆ ๋ฒ„์ „์— ๋Œ€ํ•ด PyOpenSSL์„ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

์•„, ๊ทธ๋•Œ ๋‚ด๊ฐ€ ์ฒญ์–ด๋ฅผ ๋”ฐ๋ผ๊ฐ€๋Š” ๊ฒƒ ๊ฐ™์•˜์Šต๋‹ˆ๋‹ค. ์–ด์จŒ๋“  OSX์— ์•„๋ฌด ๊ฒƒ๋„ ๋ฐฐํฌํ•  ๊ณ„ํš์ด ์—†์Šต๋‹ˆ๋‹ค. ๋‚ด ํ…Œ์ŠคํŠธ๋ฅผ Linux ๊ฐ€์ƒ ์ƒ์ž๋กœ ์˜ฎ๊ธธ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์ด ์žฅํ™ฉํ•œ ๋ฌธ์ œ์— ๋Œ€ํ•ด ์‚ฌ๊ณผ๋“œ๋ฆฝ๋‹ˆ๋‹ค!

์‚ฌ๊ณผํ•  ํ•„์š”๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. ๊ทธ ์งˆ๋ฌธ์„ ํ•˜๋Š” ๊ฒƒ์ด ์˜ณ์€ ์ผ์ด์—ˆ์Šต๋‹ˆ๋‹ค. OS X์— ์ด ๋ฌธ์ œ๊ฐ€ ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์•„๋Š” ๊ฒƒ์€ ์ด์ƒํ•˜๊ฒŒ๋„ ๊ตฌ์ฒด์ ์ธ ์ง€์‹์ž…๋‹ˆ๋‹ค. =)

์•Œ๊ฒ ์Šต๋‹ˆ๋‹ค. ์‹คํŒจ์ž…๋‹ˆ๋‹ค. Vagrant๋ฅผ ํ†ตํ•ด Ubuntu 14.04 ์„œ๋ฒ„ 32๋น„ํŠธ Virtualbox ์ด๋ฏธ์ง€๋ฅผ ์ƒ์„ฑํ–ˆ์œผ๋ฉฐ ์ด๊ฒƒ์€ SSLv2์˜ ๊ฒฝ์šฐ๋ฅผ ์ œ์™ธํ•˜๊ณ  ๋ชจ๋‘ ๊ณ„์† ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ํ”„๋กœํ† ์ฝœ์ด Ubuntu 14.04์˜ OpenSSL ๋ฒ„์ „์— ํฌํ•จ๋˜์–ด ์žˆ์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ์‹คํŒจํ•ฉ๋‹ˆ๋‹ค(์„ค๊ณ„์ƒ - SSLv2๊ฐ€ ์˜ค๋ž˜๋œ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ๊ตฌ์‹).

๋ฒ„์ „:
Ubuntu 14.04 32๋น„ํŠธ(Vagrant/Virtualbox ์ฝค๋ณด๋ฅผ ํ†ตํ•ด)
ํŒŒ์ด์ฌ 2.7.6
์š”์ฒญ==2.2.1
์š”์ฒญ ๋„๊ตฌ ๋ฒจํŠธ==0.2.0
urllib3==1.8.2

ํŽธ์ง‘ : OpenSSL ๋ฒ„์ „์„ ์žŠ์–ด ๋ฒ„๋ ธ์Šต๋‹ˆ๋‹ค ...

python -c "ssl ๊ฐ€์ ธ์˜ค๊ธฐ, ssl.OPENSSL_VERSION ์ธ์‡„"
OpenSSL 1.0.1f 2014๋…„ 1์›” 6์ผ

TLSv1:

>>> import requests
>>> from requests_toolbelt import SSLAdapter
>>> adapter = SSLAdapter('TLSv1')
>>> s = requests.Session()
>>> s.mount('https://', adapter)
>>> s.get('https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html')
Traceback (most recent call last):
  File "<console>", line 1, in <module>
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 395, in get
    return self.request('GET', url, **kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 383, in request
    resp = self.send(prep, **send_kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 486, in send
    r = adapter.send(request, **kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/adapters.py", line 385, in send
    raise SSLError(e)
SSLError: [Errno 1] _ssl.c:510: error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure

SSLv2:

>>> import requests
>>> from requests_toolbelt import SSLAdapter
>>> adapter = SSLAdapter('SSLv3')
>>> s = requests.Session()
>>> s.mount('https://', adapter)
>>> s.get('https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html')
Traceback (most recent call last):
  File "<console>", line 1, in <module>
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 395, in get
    return self.request('GET', url, **kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 383, in request
    resp = self.send(prep, **send_kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 486, in send
    r = adapter.send(request, **kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/adapters.py", line 385, in send
    raise SSLError(e)
SSLError: [Errno 1] _ssl.c:510: error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure

SSLv23:

>>> import requests
>>> from requests_toolbelt import SSLAdapter
>>> adapter = SSLAdapter('SSLv23')
>>> s = requests.Session()
>>> s.mount('https://', adapter)
>>> s.get('https://docs.apitools.com/2014/04/24/a-small-router-for-openresty.html')
Traceback (most recent call last):
  File "<console>", line 1, in <module>
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 395, in get
    return self.request('GET', url, **kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 383, in request
    resp = self.send(prep, **send_kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/sessions.py", line 486, in send
    r = adapter.send(request, **kwargs)
  File "/home/vagrant/.virtualenvs/techtown/local/lib/python2.7/site-packages/requests/adapters.py", line 385, in send
    raise SSLError(e)
SSLError: [Errno 1] _ssl.c:510: error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure

์•„๋งˆ๋„ ์ด๊ฒƒ์€ ์•”ํ˜ธ ๋ชฉ๋ก ๋ฌธ์ œ์ž…๋‹ˆ๊นŒ? ์•„๋‹ˆ๋ฉด ์—ฌ๊ธฐ์— ์‚ฌ์šฉ๋œ OpenSSL ๋ฒ„์ „์ด ์—ฌ์ „ํžˆ ๋ฌธ์ œ๊ฐ€ ์žˆ์Šต๋‹ˆ๊นŒ?

ํ•„์š”ํ•œ ๊ฒฝ์šฐ ๋””๋ฒ„๊น…์„ ๋•๊ธฐ ์œ„ํ•ด ์‹œ๊ฐ„์„ ํ• ์• ํ•  ์šฉ์˜๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค... ์—ฌ๋Ÿฌ๋ถ„์ด ๋ฐฉํ–ฅ์„ ์ œ์‹œํ•œ๋‹ค๋ฉด.

VM์„ ๋‹ค์šด๋กœ๋“œ ์ค‘์ž…๋‹ˆ๋‹ค. ArchLinux์—์„œ๋Š” ์ด๊ฒƒ์„ ์žฌํ˜„ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
stacktraces๋Š” ์ด๊ฒƒ์„ ๋‚˜ํƒ€๋‚ด์ง€๋งŒ ๋‚˜๋Š” ํ™•์‹ ํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค: ๋‹น์‹ ์€ PyOpenSSL์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์ง€ ์•Š๊ณ  stdlib๋งŒ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๊นŒ?

@t-8ch ๋ด์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ์กฐ๊ธˆ ํ—ท๊ฐˆ๋ฆฌ๋„ค์š”. OpenSSL์€ ๋‚ด ์‚ถ์„ ์ •๋ง ํž˜๋“ค๊ฒŒ ๋งŒ๋“ญ๋‹ˆ๋‹ค =(

@t-8ch ๊ทธ๊ฒŒ ๋‹น์‹ ์ด ๋ฌป๋Š”๋‹ค๋ฉด PyOpenSSL์„ ์„ค์น˜ํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๊นŒ?

๋‚˜๋Š” pip install requests ๊ฐ€ HTTPS ํŽ˜์ด์ง€์—์„œ requests.get('...') ๋ฅผ ์„ฑ๊ณต์ ์œผ๋กœ ํ˜ธ์ถœํ•˜๋Š” ๋ฐ ํ•„์š”ํ•œ ๋ชจ๋“  ๊ฒƒ์„ ์ œ๊ณตํ•ด์•ผ ํ•œ๋‹ค๊ณ  (์•„๋งˆ๋„ ๋ถ€์ •ํ™•ํ•˜๊ฒŒ) ๊ฐ€์ •ํ–ˆ์„ ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋ฌผ๋ก  ๋Œ€๋ถ€๋ถ„์˜ ๊ฒฝ์šฐ ์ž‘๋™ํ•˜์ง€๋งŒ ์–ด๋–ค ์ด์œ ๋กœ ์ด ์‚ฌ์ดํŠธ์—์„œ๋Š” ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

@jaddison _๋Œ€๋ถ€๋ถ„ _ ๊ทธ๋ ‡์Šต๋‹ˆ๋‹ค. ๋ถˆํ–‰ํžˆ๋„, Python 2.7s ํ‘œ์ค€ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋Š” ๋งค์šฐ ํ˜•ํŽธ์—†๊ณ  SNI์™€ ๊ฐ™์€ ์ผ๋ถ€ ๊ธฐ๋Šฅ์„ ์ง€์›ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์ด๊ฒŒ SNI์ธ๊ฐ€...

@jaddison ๋ฐฐํ›„ ์—๋Š” ๋‘ ๊ฐ€์ง€ ๋‹ค๋ฅธ ์ฝ”๋“œ ๊ฒฝ๋กœ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๊ฒƒ๋“ค์— ๋Œ€ํ•ด ์‹ ๊ฒฝ ์“ธ ํ•„์š”๋Š” ์—†์ง€๋งŒ ๋””๋ฒ„๊น…ํ•  ๋•Œ ์•Œ๋ฉด ๋„์›€์ด ๋ฉ๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ ์ด์ œ ์šฐ๋ถ„ํˆฌ์—์„œ ์ด๊ฒƒ์„ ์žฌํ˜„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ Py2์—๋งŒ ํ•ด๋‹น๋ฉ๋‹ˆ๋‹ค. Py3์—์„œ๋Š” ๋ชจ๋“  ๊ฒƒ์ด ์ •์ƒ์ž…๋‹ˆ๋‹ค.
@Lukasa ๊ฐ€ ๋งž๋‹ค๊ณ  ์ƒ๊ฐํ•˜๊ณ  ํด๋ผ์ด์–ธํŠธ๊ฐ€ SNI๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š์„ ๋•Œ ์„œ๋ฒ„๊ฐ€ ์‹คํŒจํ•ฉ๋‹ˆ๋‹ค.

SNI๊ฐ€ ์—†์œผ๋ฉด ํ•ด๋‹น ์„œ๋ฒ„์— ๋”ฐ๋ผ ์—ฌ๋Ÿฌ ๊ฐ€์ง€ ๋‹ค๋ฅธ ๋ฐฉ์‹์œผ๋กœ ์‹คํŒจํ•˜๋Š” ๊ฒƒ์ด ๊ท€์ฐฎ์Šต๋‹ˆ๋‹ค.

๋‚˜๋Š” OpenSSL 1.0.1f์™€ 1.0.1g(https://www.openssl.org/news/openssl-1.0.1-notes.html) ์‚ฌ์ด์˜ ์ด๋Ÿฌํ•œ ๋ณ€ํ™”๋ฅผ ์•Œ์•„์ฐจ๋ ธ์Šต๋‹ˆ๋‹ค.

Add TLS padding extension workaround for broken servers.

ํŽธ์ง‘: ์•„, ์‹ ๊ฒฝ ์“ฐ์ง€ ๋งˆ์„ธ์š”. ๋ฒ„๊ทธ๊ฐ€ Py 2์™€ 3 ์‚ฌ์ด์—์„œ ๋‹ฌ๋ผ์„œ๋Š” ์•ˆ ๋œ๋‹ค๊ณ  ์ƒ๊ฐํ•ฉ๋‹ˆ๋‹ค.

@jaddison ์ด๊ฒƒ์ด SNI์ธ์ง€ ํ…Œ์ŠคํŠธํ•˜๋ ค๋ฉด Python 2์— ๋Œ€ํ•œ SNI ์š”๊ตฌ ์‚ฌํ•ญ์„ ์„ค์น˜ ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

@๋ฃจ์นด์‚ฌ ๋ง์ด ๋งž์•˜๋‹ค. ๋น„๊ตํ•˜๋‹ค:

$ openssl s_client -connect docs.apitools.com:443                              
CONNECTED(00000003)
139846853338768:error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure:s23_clnt.c:762:
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 7 bytes and written 517 bytes
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
---

$  openssl s_client -connect docs.apitools.com:443 -servername docs.apitools.com
... happy handshake here

์ž์„ธํžˆ ์„ค๋ช…ํ•˜์ž๋ฉด: ๋‘ ๋ฒˆ์งธ ๋ช…๋ น์€ openssl s_client ์˜ SNI ๊ธฐ๋Šฅ์„ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.

a) python3์œผ๋กœ ์ „ํ™˜ b) ์ถ”๊ฐ€ ์ข…์†์„ฑ์„ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
stdlib๋Š” ํ˜„์žฌ SNI๋ฅผ ์ˆ˜ํ–‰ํ•  ๋ฐฉ๋ฒ•์ด ์—†์Šต๋‹ˆ๋‹ค.

๋น ๋ฅธ ํ”ผ๋“œ๋ฐฑ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ๋ฒ„๊ทธ๊ฐ€ ์—†์–ด์„œ ์ด๊ธ€์„ ๋‹ซ๊ฒ ์Šต๋‹ˆ๋‹ค... ๋‹ค์‹œ..

์ด๋ด, ๊ณ ๋งˆ์›Œ ์–˜๋“ค์•„ !! ๋‚ด Mac๊ณผ ๋ถ์— python3์„ ์„ค์น˜ํ–ˆ๋Š”๋ฐ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

OS X 10.9.5, Python 2.7.7 ๋ฐ OpenSSL 0.9.8zc์—์„œ ์ด ๋ฌธ์ œ๋ฅผ ๊ฒฝํ—˜ํ–ˆ๋‹ค๊ณ  ๋งํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค.

๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ฐฉ๋ฒ•์œผ๋กœ ํ•ธ๋“œ์…ฐ์ดํ‚น ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

  1. brew install OpenSSL ๋ฅผ ํ†ตํ•ด ๋‚ด ์ปดํ“จํ„ฐ์— ์ตœ์‹  OpenSSL ์„ค์น˜
  2. ์ƒˆ OpenSSL( env ARCHFLAGS="-arch x86_64" LDFLAGS="-L/usr/local/opt/openssl/lib" CFLAGS="-I/usr/local/opt/openssl/include" pip install cryptography )์— ๋Œ€ํ•ด ๋งํฌ๋œ cryptography ํŒจํ‚ค์ง€ ์ปดํŒŒ์ผ ๋ฐ ์„ค์น˜
  3. pip install requests[security] ๋ฅผ ์ˆ˜ํ–‰ํ•˜์—ฌ SNI ์ง€์›์œผ๋กœ ์š”์ฒญ ์„ค์น˜

@Microsrf๋‹˜, ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ๋‚˜๋Š” ๊ฑฐ์˜ ๋™์ผํ•œ ์‚ฌ์–‘(10.9.5, Python 2.7.6์€ Homebrew๋ฅผ ํ†ตํ•ด ์„ค์น˜๋˜์—ˆ์ง€๋งŒ OpenSSL 0.9.8zg์—์„œ ์ œ๊ณตํ•˜๋Š” ์‹œ์Šคํ…œ์œผ๋กœ ์ปดํŒŒ์ผ๋จ)์„ ์‹คํ–‰ํ•˜๊ณ  ์žˆ์œผ๋ฉฐ ์ด๊ฒƒ์€ requests ๋ฅผ ์‹œ์ž‘ํ•˜๊ณ  Django๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ „์ฒด ํ”„๋กœ์„ธ์Šค์˜€์Šต๋‹ˆ๋‹ค. :

brew install openssl

OpenSSL์˜ ์ƒˆ๋กœ์šด ์„ค์น˜์— ๋Œ€ํ•ด ์ปดํŒŒ์ผ๋œ ๋งŽ์€ SNI ํ•ญ๋ชฉ ์œผ๋กœ requests ๋ฅผ ์„ค์น˜ํ•˜์‹ญ์‹œ์˜ค. [security] ์˜ต์…˜์€ ๋‹จ์ˆœํžˆ pyopenssl ndg-httpsclient pyasn1 ๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค.

env ARCHFLAGS="-arch x86_64" LDFLAGS="-L/usr/local/opt/openssl/lib" CFLAGS="-I/usr/local/opt/openssl/include" pip install requests[security] urllib3

๊ทธ๋ฆฌ๊ณ  ์šฐ๋ฆฌ๋Š” ๊ฐˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

"""
This may or may not be needed. See:
https://urllib3.readthedocs.org/en/latest/security.html#openssl-pyopenssl
"""
# from urllib3.contrib import pyopenssl
# pyopenssl.inject_into_urllib3()

import requests
# r = requests.get(...)

์šฐ๋ถ„ํˆฌ์—์„œ ์ด๊ฒƒ์„ ์ž‘๋™์‹œํ‚ค๋Š” ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ํ™•์‹คํ•œ ๋Œ€๋‹ต์ด ์žˆ์Šต๋‹ˆ๊นŒ? ์ด ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•˜๊ณ  ์žˆ์œผ๋ฉฐ ์—ฌ๊ธฐ์—์„œ ์œ ์ผํ•œ ๋Œ€๋‹ต์€ Mac์—์„œ ์ด ๋ฌธ์ œ๋ฅผ ์ž‘๋™์‹œํ‚ค๋Š” ๋ฐฉ๋ฒ•์— ๊ด€ํ•œ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. ์ „์ฒด ์ฝ”๋“œ๋ฒ ์ด์Šค๋ฅผ python 3์œผ๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜๋Š” ๊ฒƒ์€ ์„ ํƒ ์‚ฌํ•ญ์ด ์•„๋‹™๋‹ˆ๋‹ค.

์•Œ๊ฒ ์Šต๋‹ˆ๋‹ค. ๋ฐฉ๊ธˆ ์ œ ์งˆ๋ฌธ์— ๋‹ตํ–ˆ์„ ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚ด๊ฐ€ ํ•œ ์ผ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์š”์•ฝ๋ฉ๋‹ˆ๋‹ค.

sudo apt-get install libffi-dev
pip install pyOpenSSL ndg-httpsclient pyasn1

@lsemel ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ๋•๋ถ„์— ์‹œ๊ฐ„์ด ๋งŽ์ด ์ ˆ์•ฝ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

@lsemel ํ™•์‹คํ•ฉ๋‹ˆ๊นŒ? Ubuntu 15.10์—์„œ ์‹œ๋„ํ–ˆ์ง€๋งŒ ์—ฌ์ „ํžˆ Python 2.7.10์—์„œ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

Travis CI์˜ Python 2.7์—์„œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.
https://travis-ci.org/playing-se/swish-python

์ด์ œ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค! ๊ฐ„๋‹จํžˆ pyOpenSSL์„ ์ œ๊ฑฐํ–ˆ์Šต๋‹ˆ๋‹ค.
pip uninstall pyOpenSSL

Python ๋ฒ„์ „์ด 2.7.9 ๋ฏธ๋งŒ์ธ ๊ฒฝ์šฐ์—๋งŒ pyopenssl.inject_into_urllib3() ํ•ด์•ผ ํ•ฉ๋‹ˆ๊นŒ? pyOpenSSL์€ Python ๋ฒ„์ „์ด 2.7.10์ธ โ€‹โ€‹๊ฒฝ์šฐ Ubuntu ๋ฐ Windows์—์„œ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๋Š” ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค.

PyOpenSSL์€ ์•„๋ฌด ๊ฒƒ๋„ ๊นจ๋œจ๋ฆฌ์ง€ ์•Š์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡๋‹ค๋ฉด ๋ณด๊ณ ํ•ด์•ผ ํ•˜๋Š” ๋ฒ„๊ทธ์ž…๋‹ˆ๋‹ค.

๋‚˜๋Š” ์ด๊ฒƒ์„ ์กฐ์‚ฌํ•ด์•ผํ•˜์ง€๋งŒ Python ๋ฒ„์ „์ด 2.7.9 ์ด์ƒ์ธ ๊ฒฝ์šฐ urllib3์— pyopenssl์„ ์ฃผ์ž…ํ•ด์•ผ ํ•  ์ข‹์€ ์ด์œ ๊ฐ€ ์žˆ์Šต๋‹ˆ๊นŒ?

๋‚˜๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๊ฒƒ์„ ์ƒ๊ฐํ•˜๊ณ  ์žˆ๋‹ค.

# Check if Modern SSL with SNI support
try:
    from ssl import SSLContext
    from ssl import HAS_SNI
except ImportError:
    # Attempt to enable urllib3's SNI support, if possible
    try:
        from .packages.urllib3.contrib import pyopenssl
        pyopenssl.inject_into_urllib3()
    except ImportError:
        pass

๋„ค, ์ž์ฃผ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด OS X์—์„œ ๋Œ€๋ถ€๋ถ„์˜ Python์€ ๋ฒ„์ „ 0.9.8zg์ธ ์‹œ์Šคํ…œ OpenSSL์— ๋Œ€ํ•ด ๋งํฌํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ PyOpenSSL์€ ํ›จ์”ฌ ๋” ์ƒˆ๋กœ์šด OpenSSL(1.0.2)๊ณผ ์—ฐ๊ฒฐ๋ฉ๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ PyOpenSSL์„ ์‚ฌ์šฉํ•˜๋ฉด ๋ณด์•ˆ์ด ํฌ๊ฒŒ ํ–ฅ์ƒ๋ฉ๋‹ˆ๋‹ค.

๋˜ํ•œ PyOpenSSL์„ ์‚ฌ์šฉํ•˜๋ฉด OpenSSL์— ํ›จ์”ฌ ๋” ์‰ฝ๊ฒŒ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ๋” ํšจ๊ณผ์ ์œผ๋กœ ๋ณดํ˜ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ข‹์•„, ๋‚˜๋Š” ์ด์ œ ์ด๊ฒƒ์„ ์กฐ๊ธˆ ๊ฐ€์ง€๊ณ  ๋†€์•˜๋‹ค.

pyopenssl์—์„œ๋Š” ์ž‘๋™ํ•˜์ง€๋งŒ ndg-httpsclient๊ฐ€ ์„ค์น˜๋œ ๊ฒฝ์šฐ์—๋Š” ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ ๋‹ค์Œ ๊ฒฝ๊ณ ๋ฅผ ํ‘œ์‹œํ•˜๋Š” pyasn1์„ ์ œ๊ฑฐํ•˜๋ฉด ndg-httpsclient์—์„œ ์ž‘๋™ํ•˜๋„๋ก ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

/usr/lib/python2.7/dist-packages/ndg/httpsclient/subj_alt_name.py:22: UserWarning: Error importing pyasn1, subjectAltName check for SSL peer verification will be disabled.  Import error is: No module named pyasn1.type
  warnings.warn(import_error_msg)
/usr/lib/python2.7/dist-packages/ndg/httpsclient/ssl_peer_verification.py:25: UserWarning: SubjectAltName support is disabled - check pyasn1 package installation to enable
  warnings.warn(SUBJ_ALT_NAME_SUPPORT_MSG)
/usr/lib/python2.7/dist-packages/ndg/httpsclient/subj_alt_name.py:22: UserWarning: Error importing pyasn1, subjectAltName check for SSL peer verification will be disabled.  Import error is: No module named pyasn1.type
  warnings.warn(import_error_msg)

Python 2.7.10์ด ์„ค์น˜๋œ Ubuntu 15.10 ๋ฐ Windows 10์—์„œ ๋™์ผํ•œ ๋™์ž‘.

ndg-httpsclient๊ฐ€ ์—†์œผ๋ฉด PyOpenSSL ์ง€์›์ด ์‚ฌ์šฉ๋˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.

์˜ˆ, SubjectAltName์ด ๋น„ํ™œ์„ฑํ™”๋œ ๊ฒฝ์šฐ ์ž‘๋™ํ•˜๋Š” ์ด์œ ๋ฅผ ํŒŒํ—ค์ณ์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์–ด๋–ค ์•„์ด๋””์–ด๋ผ๋„?

๊ฑฐ์˜ ํ™•์‹คํ•˜๊ฒŒ ๋ฌธ์ œ๋Š” ๊ฐ ๊ฒฝ์šฐ์— ๋‹ค๋ฅธ OpenSSL์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

Ubuntu 14.04 ์ƒ์ž์™€ Python 2.7.11์—์„œ ๋™์ผํ•œ ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค.

SNI์—์„œ ์™”์Šต๋‹ˆ๋‹ค

๋‚˜๋ฅผ ์œ„ํ•ด ์ผํ•œ ๊ฒƒ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค.

  • ์ œ๊ฑฐ ์š”์ฒญ
  • urllib3 ์ œ๊ฑฐ
  • ๋‹ค์–‘ํ•œ ์•”ํ˜ธํ™” ์ข…์†์„ฑ ์„ค์น˜
  • urllib3 ์„ค์น˜
  • install urllib3[secure] # ์•ˆ์ „์„ ์œ„ํ•ด
  • ์„ค์น˜ ์š”์ฒญ

urllib3 ๋˜๋Š” ์ œ๊ฑฐ ์—†์ด ์ž‘๋™ํ•˜์ง€ ์•Š๋Š” ์š”์ฒญ์— ๋Œ€ํ•œ ์„ค์น˜ ์‹œ๊ฐ„ ํ™•์ธ์ด ์žˆ์—ˆ๋˜ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค.

@jvanasco ํ•ด๋‹น ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•˜๋Š” ๋ฐ ๋ฌด์—‡์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๊นŒ? ๋‚˜๋Š” ํ•์„ ๊ฐ€์ •ํ•ฉ๋‹ˆ๋‹ค. urllib3์™€ ์š”์ฒญ์„ ๋ณ„๋„๋กœ ์„ค์น˜ํ•˜๋Š” ์ด์œ ๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

๊ธ€์Ž„, ๋‚˜๋Š” virtualenv์— urllib3๊ฐ€ ํ•„์š”ํ–ˆ์ง€๋งŒ ... pip ๋ฐ easy_install์— ์˜ํ•ด ์„ค์น˜๋œ ์š”๊ตฌ ์‚ฌํ•ญ์„ ์‹œ๋„ํ•˜๊ณ  ์–ป๊ธฐ ์œ„ํ•ด ์„ค์น˜ํ–ˆ์Šต๋‹ˆ๋‹ค. (์ €๋Š” ๋‘˜ ๋‹ค ์‚ฌ์šฉํ–ˆ์Šต๋‹ˆ๋‹ค)

์›น ์ธ๋ฑ์„œ๊ฐ€ ์žˆ๊ณ  ๋ช‡ ๊ฐœ์˜ URL์ด ์†์ƒ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋‚˜๋Š” ๊นจ์ง„ ๊ฒƒ๋“ค์„ ์‹œ๋„ํ•˜๊ธฐ ์œ„ํ•ด ๋น ๋ฅธ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ–ˆ๊ณ , ์ž‘๋™ํ•  ๋•Œ๊นŒ์ง€ SSL ๋ฌธ์ œ์— ๋Œ€ํ•œ urllib3 ์ง€์นจ์—์„œ ํŒจํ‚ค์ง€๋ฅผ ๊ณ„์† ์žฌ์„ค์น˜/์‚ญ์ œ+์„ค์น˜ํ–ˆ์Šต๋‹ˆ๋‹ค.

2016๋…„ 5์›” 31์ผ ์˜คํ›„ 7์‹œ 25๋ถ„์— Ian Cordasco [email protected] ์ด ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ผ์Šต๋‹ˆ๋‹ค.

@jvanasco ํ•ด๋‹น ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•˜๋Š” ๋ฐ ๋ฌด์—‡์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๊นŒ? ๋‚˜๋Š” ํ•์„ ๊ฐ€์ •ํ•ฉ๋‹ˆ๋‹ค. urllib3์™€ ์š”์ฒญ์„ ๋ณ„๋„๋กœ ์„ค์น˜ํ•˜๋Š” ์ด์œ ๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

โ€”
๋‹น์‹ ์ด ์–ธ๊ธ‰๋˜์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ด๊ฒƒ์„ ๋ฐ›๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.
์ด ์ด๋ฉ”์ผ์— ์ง์ ‘ ๋‹ต์žฅํ•˜๊ฑฐ๋‚˜ GitHub์—์„œ ๋ณด๊ฑฐ๋‚˜ ์Šค๋ ˆ๋“œ๋ฅผ ์Œ์†Œ๊ฑฐํ•˜์„ธ์š”.๏ฟผ

์—ฌ์ „ํžˆ ์ด ๋ฌธ์ œ๊ฐ€ ํ‘œ์‹œ๋˜๋ฉฐ ์ œ์•ˆ๋œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์„ ์‹œ๋„ํ–ˆ์Šต๋‹ˆ๋‹ค.
๋‚ด ํŒŒ์ด์ฌ ๋ฒ„์ „์„ 2.7.11๋กœ ์—…๋ฐ์ดํŠธํ–ˆ์Šต๋‹ˆ๋‹ค.
3๊ฐœ์˜ ์ถ”๊ฐ€ ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ–ˆ์Šต๋‹ˆ๋‹ค.

@jvanasco ๊ฐ€ ์ œ์•ˆํ•œ ์ œ๊ฑฐ/์„ค์น˜ ์‹œํ€€์Šค๋ฅผ ์‹œ๋„ํ–ˆ์ง€๋งŒ ์—ฌ์ „ํžˆ SSLError๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค.
๋˜ํ•œ Ubuntu 14.04๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ๋ถˆํ–‰ํžˆ๋„ OpenSSL ์—…๋ฐ์ดํŠธ๊ฐ€ ์—†์œผ๋ฏ€๋กœ ์—ฌ๊ธฐ์— ๊ฒŒ์‹œ๋œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•ด์•ผ ํ•˜๋ฉฐ ์šด์ด ์—†์Šต๋‹ˆ๋‹ค.

๋‹น์‹ ์ด ์ทจํ•œ ์ถ”๊ฐ€ ์กฐ์น˜๊ฐ€ ์žˆ์Šต๋‹ˆ๊นŒ?

๊ฐ์‚ฌ ํ•ด์š”

@Lekinho ๋ฌธ์ œ๊ฐ€ ์žˆ๋Š” ๋„๋ฉ”์ธ์„ ํ…Œ์ŠคํŠธํ•˜๋Š” ์งง์€ ํ…Œ์ŠคํŠธ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋งŒ๋“œ๋Š” ๊ฒƒ์ด ๋„์›€์ด ๋˜์—ˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ์•˜์Šต๋‹ˆ๋‹ค.

๊ทธ๋ƒฅ:

 import requests
 r = requests.get(bad_url)
 print r.__dict__

@Lekinho ์ฝ”๋“œ์˜ ์š”์ฒญ์—์„œ pyopenssl์„ ์ถ”์ถœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

try:
    from requests.packages.urllib3.contrib import pyopenssl
    pyopenssl.extract_from_urllib3()
except ImportError:
    pass

@Lekinho Python 2.7.11์—์„œ ์ด ๋ฌธ์ œ๊ฐ€ ๊ณ„์† ๋ฐœ์ƒํ•œ๋‹ค๋ฉด ์›๊ฒฉ ์„œ๋ฒ„๊ฐ€ ์š”์ฒญ์— ์‚ฌ์šฉ๋˜๋Š” TLS ์„ค์ •์„ ์ง€์›ํ•˜์ง€ ์•Š์„ ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์Šต๋‹ˆ๋‹ค. ๋ฌธ์ œ์˜ ์„œ๋ฒ„๋ฅผ ๊ณต์šฉ ์ธํ„ฐ๋„ท์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? ๊ทธ๋ ‡๋‹ค๋ฉด URL์„ ์•Œ๋ ค์ฃผ์‹œ๊ฒ ์Šต๋‹ˆ๊นŒ?

์ œ์•ˆํ•œ ๋Œ€๋กœ pyopenssl ๊ฐ€์ ธ์˜ค๊ธฐ๋ฅผ ์‹œ๋„ํ–ˆ์Šต๋‹ˆ๋‹ค.
๋ถˆํ–‰ํžˆ๋„ ์ด๊ฒƒ์€ ๊ณต๊ฐœ์ ์œผ๋กœ ์•ก์„ธ์Šคํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.
๊ทธ๋Ÿฌ๋‚˜ ์„œ๋ฒ„์— ์žˆ๋Š” openSSL ๋ฒ„์ „์— ๋Œ€ํ•œ ์ •ํ™•ํ•œ ์„ธ๋ถ€ ์ •๋ณด๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.
๊ธฐ๋ณธ์ ์œผ๋กœ ์šฐ๋ฆฌ๋Š” redhat ๊ฐ€์ƒ ๋จธ์‹ ์—์„œ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ๋ชจ๋“  ๊ฒƒ์ด ์ž‘๋™ํ•  ๋•Œ ์ด openSSL์„ ์‚ฌ์šฉํ–ˆ์Šต๋‹ˆ๋‹ค. openssl-1.0.1e-42.el6_7.4.x86_64

๊ทธ๋Ÿฐ ๋‹ค์Œ ์šฐ๋ฆฌ๋Š” redhat ์—…๊ทธ๋ ˆ์ด๋“œ๋ฅผ ์ˆ˜ํ–‰ํ–ˆ์œผ๋ฉฐ openssl์— ๋Œ€ํ•œ ์—…๋ฐ์ดํŠธ๊ฐ€ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค. openssl-1.0.1e-48.el6_8.1.x86_64

์ด ๋ฒ„์ „์€ ์šฐ๋ถ„ํˆฌ 14.04์—์„œ openssl์„ ์‚ฌ์šฉํ•  ๋•Œ ํ•ญ์ƒ ์ž˜๋ชป๋œ ํ•ธ๋“œ์…ฐ์ดํฌ ๋ฌธ์ œ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์ด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ์‹œ๋„ํ•  ์ˆ˜ ์žˆ๋Š” ๊ณต๊ฐœ URL์ด ์žˆ์Šต๋‹ˆ๊นŒ? ๊ทธ๋ฆฌ๊ณ  ์ œ๊ฐ€ ๊ฐ€์ง€๊ณ  ์žˆ๋Š” ๊ณ ์œ ํ•œ ์กฐํ•ฉ์ด ๋ฌธ์ œ์ธ๊ฐ€์š”?

REST ์š”์ฒญ์ด ๋ธŒ๋ผ์šฐ์ €๋ฅผ ํ†ตํ•ด ์ „์†ก๋  ๋•Œ ๋™์ผํ•œ ์‹œ์Šคํ…œ์€ ๋ฌธ์ œ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค(์ฆ‰, ์šฐ๋ถ„ํˆฌ openssl ์—†์ด).

๊ฐ์‚ฌ ํ•ด์š”

rpm -q --changelog openssl ์˜ ์ถœ๋ ฅ์„ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?

[ admin@leke-2-2-8-11 ~]$ rpm -q --changelog openssl

  • 2016๋…„ 5์›” 2์ผ ์›”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-48.1
  • CVE-2016-2105 ์ˆ˜์ • - base64 ์ธ์ฝ”๋”ฉ์—์„œ ๊ฐ€๋Šฅํ•œ ์˜ค๋ฒ„ํ”Œ๋กœ
  • CVE-2016-2106 ์ˆ˜์ • - EVP_EncryptUpdate()์—์„œ ๊ฐ€๋Šฅํ•œ ์˜ค๋ฒ„ํ”Œ๋กœ
  • CVE-2016-2107 ์ˆ˜์ • - ์Šคํ‹ฐ์น˜๋œ AES-NI CBC-MAC์˜ ํŒจ๋”ฉ ์˜ค๋ผํด
  • CVE-2016-2108 ์ˆ˜์ • - ASN.1 ์ธ์ฝ”๋”์˜ ๋ฉ”๋ชจ๋ฆฌ ์†์ƒ
  • CVE-2016-2109 ์ˆ˜์ • - BIO์—์„œ ASN.1 ๋ฐ์ดํ„ฐ๋ฅผ ์ฝ์„ ๋•Œ DoS ๊ฐ€๋Šฅ
  • CVE-2016-0799 ์ˆ˜์ • - BIO_printf์˜ ๋ฉ”๋ชจ๋ฆฌ ๋ฌธ์ œ
  • 2016๋…„ 2์›” 24์ผ ์ˆ˜์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-48
  • CVE-2016-0702 ์ˆ˜์ • - ๋ชจ๋“ˆ์‹ ์ง€์ˆ˜์— ๋Œ€ํ•œ ๋ถ€์ฑ„๋„ ๊ณต๊ฒฉ
  • CVE-2016-0705 ์ˆ˜์ • - DSA ๊ฐœ์ธ ํ‚ค ๊ตฌ๋ฌธ ๋ถ„์„์—์„œ ์ด์ค‘ ๋ฌด๋ฃŒ
  • CVE-2016-0797 ์ˆ˜์ • - BN_hex2bn ๋ฐ BN_dec2bn์˜ ํž™ ์†์ƒ
  • 2016๋…„ 2์›” 16์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-47
  • CVE-2015-3197 ์ˆ˜์ • - SSLv2 ์•”ํ˜ธ ์ œํ’ˆ๊ตฐ ์‹œํ–‰
  • ์ผ๋ฐ˜ TLS ๋ฐฉ๋ฒ•์—์„œ SSLv2 ๋น„ํ™œ์„ฑํ™”
  • 2016๋…„ 1์›” 15์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-46
  • pkcs12 ๊ตฌ๋ฌธ ๋ถ„์„์—์„œ 1๋ฐ”์ดํŠธ ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜ ์ˆ˜์ •(#1229871)
  • ์†๋„ ๋ช…๋ น์˜ ์ผ๋ถ€ ์˜ต์…˜ ๋ฌธ์„œํ™”(#1197095)
  • 2016๋…„ 1์›” 14์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-45
  • ํƒ€์ž„์Šคํƒฌํ”„ ๊ธฐ๊ด€์—์„œ ๊ณ ์ •๋ฐ€ ํƒ€์ž„์Šคํƒฌํ”„ ์ˆ˜์ •
  • 2015๋…„ 12์›” 21์ผ ์›” Tomรกลก Mrรกz [email protected] 1.0.1e-44
  • CVE-2015-7575 ์ˆ˜์ • - TLS1.2์—์„œ MD5 ์‚ฌ์šฉ ๊ธˆ์ง€
  • 2015๋…„ 12์›” 4์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-43
  • CVE-2015-3194 ์ˆ˜์ • - PSS ๋งค๊ฐœ๋ณ€์ˆ˜๊ฐ€ ๋ˆ„๋ฝ๋œ ์ธ์ฆ์„œ ํ™•์ธ ์ถฉ๋Œ
  • CVE-2015-3195 - X509_ATTRIBUTE ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜ ์ˆ˜์ •
  • CVE-2015-3196 ์ˆ˜์ • - PSK ID ํžŒํŠธ ์ฒ˜๋ฆฌ ์‹œ ๊ฒฝ์Ÿ ์กฐ๊ฑด
  • 2015๋…„ 6์›” 23์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-42
  • CVE-2015-1791 ์ˆ˜์ •์˜ ์‹ค์ˆ˜๋กœ ์ธํ•œ ํšŒ๊ท€ ์ˆ˜์ •
  • 2015๋…„ 6์›” 11์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-41
  • CVE-2015-1791์— ๋Œ€ํ•œ ๊ฐœ์„ ๋œ ์ˆ˜์ • ์‚ฌํ•ญ
  • CVE-2015-0209์˜ ๋ˆ„๋ฝ๋œ ๋ถ€๋ถ„์„ ์ถ”๊ฐ€ํ•˜์—ฌ ์•…์šฉํ•  ์ˆ˜๋Š” ์—†์ง€๋งŒ ์ •ํ™•์„ฑ์„ ์œ„ํ•ด ์ˆ˜์ •
  • 2015๋…„ 6์›” 9์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-40
  • CVE-2014-8176 ์ˆ˜์ • - DTLS ๋ฒ„ํผ๋ง ์ฝ”๋“œ์—์„œ ์œ ํšจํ•˜์ง€ ์•Š์€ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
  • CVE-2015-1789 ์ˆ˜์ • - X509_cmp_time์—์„œ ๋ฒ”์œ„๋ฅผ ๋ฒ—์–ด๋‚œ ์ฝ๊ธฐ
  • CVE-2015-1790 ์ˆ˜์ • - EncryptedContent๊ฐ€ ๋ˆ„๋ฝ๋œ PKCS7 ์ถฉ๋Œ
  • CVE-2015-1791 ์ˆ˜์ • - ๊ฒฝ์Ÿ ์กฐ๊ฑด ์ฒ˜๋ฆฌ NewSessionTicket
  • CVE-2015-1792 ์ˆ˜์ • - CMS๊ฐ€ ์•Œ ์ˆ˜ ์—†๋Š” ํ•ด์‹œ ํ•จ์ˆ˜๋กœ ๋ฌดํ•œ ๋ฃจํ”„๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • 2015๋…„ 6์›” 2์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-39
  • CVE-2015-3216 ์ˆ˜์ • - segfault๋ฅผ ์ผ์œผํ‚ฌ ์ˆ˜ ์žˆ๋Š” RAND ์ž ๊ธˆ์˜ ํšŒ๊ท€
    ๋‹ค์ค‘ ์Šค๋ ˆ๋“œ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ ์ฝ๊ธฐ
  • 2015๋…„ 5์›” 25์ผ ์›”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-38
  • CVE-2015-4000 ์ˆ˜์ • - ํด๋ผ์ด์–ธํŠธ์— ๋Œ€ํ•œ logjam ๊ณต๊ฒฉ ๋ฐฉ์ง€ - ์ œํ•œ
    DH ํ‚ค ํฌ๊ธฐ๋ฅผ ์ตœ์†Œ 768๋น„ํŠธ๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค(ํ–ฅํ›„ ์ œํ•œ์ด ์ฆ๊ฐ€ํ•  ์˜ˆ์ •).
  • 2015๋…„ 3์›” 25์ผ ์ˆ˜์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-37
  • IV๊ฐ€
    ํ•ญ์ƒ 96๋น„ํŠธ(32๋น„ํŠธ ๊ณ ์ • ํ•„๋“œ + 64๋น„ํŠธ ํ˜ธ์ถœ ํ•„๋“œ)
  • 2015๋…„ 3์›” 19์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-36
  • ์—…์ŠคํŠธ๋ฆผ์— ๋ฆด๋ฆฌ์Šค๋œ CVE-2015-0287์— ๋Œ€ํ•œ ์—…๋ฐ์ดํŠธ ์ˆ˜์ •
  • 2015๋…„ 3์›” 18์ผ ์ˆ˜์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-35
  • CVE-2015-0209 ์ˆ˜์ • - d2i_ECPrivateKey()์—์„œ ํ•ด์ œ ํ›„ ์ž ์žฌ์  ์‚ฌ์šฉ
  • CVE-2015-0286 ์ˆ˜์ • - ASN.1 ๋ถ€์šธ ๋น„๊ต์˜ ๋ถ€์ ์ ˆํ•œ ์ฒ˜๋ฆฌ
  • CVE-2015-0287 ์ˆ˜์ • - ASN.1 ๊ตฌ์กฐ ์žฌ์‚ฌ์šฉ ๋””์ฝ”๋”ฉ ๋ฉ”๋ชจ๋ฆฌ ์†์ƒ
  • CVE-2015-0288 - X509_to_X509_REQ NULL ํฌ์ธํ„ฐ ์—ญ์ฐธ์กฐ ์ˆ˜์ •
  • CVE-2015-0289 ์ˆ˜์ • - ์ž˜๋ชป๋œ PKCS#7 ๋ฐ์ดํ„ฐ๋ฅผ ๋””์ฝ”๋”ฉํ•˜๋Š” NULL ์—ญ์ฐธ์กฐ
  • CVE-2015-0292 ์ˆ˜์ • - base64 ๋””์ฝ”๋”์˜ ์ •์ˆ˜ ์–ธ๋”ํ”Œ๋กœ
  • CVE-2015-0293 ์ˆ˜์ • - SSLv2 ์„œ๋ฒ„์—์„œ ํŠธ๋ฆฌ๊ฑฐ ๊ฐ€๋Šฅํ•œ ์–ด์„ค์…˜
  • 2015๋…„ 3์›” 3์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-34
  • SNI ์ปจํ…์ŠคํŠธ ์ „ํ™˜์„ ์ฒ˜๋ฆฌํ•  ๋•Œ ๋ณต์‚ฌ ๋‹ค์ด์ œ์ŠคํŠธ ์•Œ๊ณ ๋ฆฌ์ฆ˜
  • ์•”ํ˜ธ ๋ชจ์Œ ๋ฌธ์„œ ๊ฐœ์„  - Hubert Kario์˜ ํŒจ์น˜
  • Kerberos ์„œ๋น„์Šค ๋ฐ keytab ์„ค์ •์— ๋Œ€ํ•œ ์ง€์› ์ถ”๊ฐ€
    s_server ๋ฐ s_client
  • 2015๋…„ 1์›” 13์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-33
  • CVE-2014-3570 ์ˆ˜์ • - BN_sqr()์˜ ์ž˜๋ชป๋œ ๊ณ„์‚ฐ
  • CVE-2014-3571 ์ˆ˜์ • - dtls1_get_record()์—์„œ ๊ฐ€๋Šฅํ•œ ์ถฉ๋Œ
  • CVE-2014-3572 ์ˆ˜์ • - ECDH ์•”ํ˜ธ ์ œํ’ˆ๊ตฐ์„ PFS๊ฐ€ ์•„๋‹Œ ์ƒํƒœ๋กœ ๋‹ค์šด๊ทธ๋ ˆ์ด๋“œ ๊ฐ€๋Šฅ
  • CVE-2014-8275 ์ˆ˜์ • - ๋‹ค์–‘ํ•œ ์ธ์ฆ์„œ ์ง€๋ฌธ ๋ฌธ์ œ
  • CVE-2015-0204 ์ˆ˜์ • - ๋‚ด๋ณด๋‚ด๊ธฐ๊ฐ€ ์•„๋‹Œ RSA ์ž„์‹œ ํ‚ค ์ง€์› ์ œ๊ฑฐ
    ์•”ํ˜ธ ๋ชจ์Œ ๋ฐ ์„œ๋ฒ„
  • CVE-2015-0205 ์ˆ˜์ • - ์ธ์ฆ๋˜์ง€ ์•Š์€ ํด๋ผ์ด์–ธํŠธ DH ์ธ์ฆ์„œ ํ—ˆ์šฉ ์•ˆ ํ•จ
  • CVE-2015-0206 ์ˆ˜์ • - DTLS ๋ ˆ์ฝ”๋“œ ๋ฒ„ํผ๋ง ์‹œ ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜ ๊ฐ€๋Šฅ์„ฑ
  • 2014๋…„ 10์›” 16์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-32
  • RSA์—์„œ d ๊ณ„์‚ฐ์„ ์œ„ํ•ด FIPS ์Šน์ธ ๋ฐฉ๋ฒ• ์‚ฌ์šฉ
  • 2014๋…„ 10์›” 15์ผ ์ˆ˜์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-31
  • CVE-2014-3567 ์ˆ˜์ • - ์„ธ์…˜ ํ‹ฐ์ผ“ ์ฒ˜๋ฆฌ ์‹œ ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜
  • CVE-2014-3513 ์ˆ˜์ • - srtp ์ง€์›์—์„œ ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜
  • CVE-2014-3566์„ ๋ถ€๋ถ„์ ์œผ๋กœ ์™„ํ™”ํ•˜๊ธฐ ์œ„ํ•ด ๋Œ€์ฒด SCSV์— ๋Œ€ํ•œ ์ง€์› ์ถ”๊ฐ€
    (SSL3์— ๋Œ€ํ•œ ํŒจ๋”ฉ ๊ณต๊ฒฉ)
  • 2014๋…„ 8์›” 15์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-30
  • DTLS์— ECC TLS ํ™•์žฅ ์ถ”๊ฐ€(#1119800)
  • 2014๋…„ 8์›” 8์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-29
  • CVE-2014-3505 ์ˆ˜์ • - DTLS ํŒจํ‚ท ์ฒ˜๋ฆฌ์—์„œ doublefree
  • CVE-2014-3506 ์ˆ˜์ • - DTLS์—์„œ ๋ฉ”๋ชจ๋ฆฌ ๊ณ ๊ฐˆ ๋ฐฉ์ง€
  • CVE-2014-3507 ์ˆ˜์ • - DTLS์—์„œ ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜ ๋ฐฉ์ง€
  • CVE-2014-3508 ์ˆ˜์ • - ์ •๋ณด ๋ˆ„์ถœ์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด OID ์ฒ˜๋ฆฌ ์ˆ˜์ •
  • CVE-2014-3509 ์ˆ˜์ • - ์„œ๋ฒ„ hello๋ฅผ ๊ตฌ๋ฌธ ๋ถ„์„ํ•  ๋•Œ ๊ฒฝ์Ÿ ์กฐ๊ฑด ์ˆ˜์ •
  • CVE-2014-3510 ์ˆ˜์ • - DTLS์—์„œ ์ต๋ช…(EC)DH ์ฒ˜๋ฆฌ์˜ DoS ์ˆ˜์ •
  • CVE-2014-3511 ์ˆ˜์ • - ๋‹จํŽธํ™”๋ฅผ ํ†ตํ•œ ํ”„๋กœํ† ์ฝœ ๋‹ค์šด๊ทธ๋ ˆ์ด๋“œ ๊ธˆ์ง€
  • 2014๋…„ 6์›” 16์ผ ์›” Tomรกลก Mrรกz [email protected] 1.0.1e-28
  • EAP-FAST ์„ธ์…˜ ์žฌ๊ฐœ ์ง€์›์„ ์ค‘๋‹จ์‹œํ‚ค๋Š” CVE-2014-0224 ์ˆ˜์ • ์ˆ˜์ •
  • 2014๋…„ 6์›” 6์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-26
  • ๊ธฐ๋ณธ ์•”ํ˜ธ ๋ชฉ๋ก์—์„œ EXPORT, RC2 ๋ฐ DES ์‚ญ์ œ(#1057520)
  • TLS ํ•ธ๋“œ์…ฐ์ดํฌ์—์„œ ํ˜‘์ƒ๋œ ์ž„์‹œ ํ‚ค ํฌ๊ธฐ ์ธ์‡„(#1057715)
  • SSLv2 ํด๋ผ์ด์–ธํŠธ hello์— ECC ์•”ํ˜ธ ์ œํ’ˆ๊ตฐ์„ ํฌํ•จํ•˜์ง€ ์•Š์Œ(#1090952)
  • BIO์—์„œ ์•”ํ˜ธํ™” ์‹คํŒจ๋ฅผ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๊ฐ์ง€ํ•ฉ๋‹ˆ๋‹ค(#1100819).
  • .hmac ํŒŒ์ผ์ด ๋น„์–ด ์žˆ์œผ๋ฉด hmac ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์‚ฌ์— ์‹คํŒจํ•จ(#1105567)
  • FIPS ๋ชจ๋“œ: DSA, DH ๋ฐ RSA ํ‚ค ์ƒ์„ฑ์— ๋Œ€ํ•œ ์ œํ•œ ๋งŒ๋“ค๊ธฐ
    ๊ธธ์ด๋Š” OPENSSL_ENFORCE_MODULUS_BITS ํ™˜๊ฒฝ์ธ ๊ฒฝ์šฐ์—๋งŒ ์ ์šฉ๋ฉ๋‹ˆ๋‹ค.
    ๋ณ€์ˆ˜๊ฐ€ ์„ค์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค
  • 2014๋…„ 6์›” 2์ผ ์›” Tomรกลก Mrรกz [email protected] 1.0.1e-25
  • CVE-2010-5298 ์ˆ˜์ • - ํ•ด์ œ ํ›„ ๋ฉ”๋ชจ๋ฆฌ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
  • CVE-2014-0195 ์ˆ˜์ • - ์ž˜๋ชป๋œ DTLS ์กฐ๊ฐ์„ ํ†ตํ•œ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ
  • CVE-2014-0198 ์ˆ˜์ • - ๊ฐ€๋Šฅํ•œ NULL ํฌ์ธํ„ฐ ์—ญ์ฐธ์กฐ
  • CVE-2014-0221 ์ˆ˜์ • - ์œ ํšจํ•˜์ง€ ์•Š์€ DTLS ํ•ธ๋“œ์…ฐ์ดํฌ ํŒจํ‚ท์˜ DoS
  • CVE-2014-0224 - SSL/TLS MITM ์ทจ์•ฝ์  ์ˆ˜์ •
  • CVE-2014-3470 ์ˆ˜์ • - ์ต๋ช… ECDH๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ ํด๋ผ์ด์–ธํŠธ ์ธก DoS
  • 2014๋…„ 5์›” 22์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-24
  • secp521r1 EC ๊ณก์„ ์— ๋Œ€ํ•œ ์ง€์› ๋‹ค์‹œ ์ถ”๊ฐ€
  • 2014๋…„ 4์›” 7์ผ ์›” Tomรกลก Mrรกz [email protected] 1.0.1e-23
  • CVE-2014-0160 ์ˆ˜์ • - TLS ํ•˜ํŠธ๋น„ํŠธ ํ™•์žฅ์˜ ์ •๋ณด ๊ณต๊ฐœ
  • 2014๋…„ 3์›” 17์ผ ์›” Tomรกลก Mrรกz [email protected] 1.0.1e-22
  • FIPS ์ž์ฒด ํ…Œ์ŠคํŠธ์—์„œ 2048๋น„ํŠธ RSA ํ‚ค ์‚ฌ์šฉ
  • 2014๋…„ 2์›” 19์ผ ์ˆ˜์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-21
  • FIPS CAVS ํ…Œ์ŠคํŠธ์— ํ•„์š”ํ•œ DH_compute_key_padded ์ถ”๊ฐ€
  • 3des ๊ฐ•๋„๋ฅผ 168 ๋Œ€์‹  128๋น„ํŠธ๋กœ ๋งŒ๋“ญ๋‹ˆ๋‹ค(#1056616).
  • FIPS ๋ชจ๋“œ: DSA ํ‚ค ๋ฐ DH ๋งค๊ฐœ๋ณ€์ˆ˜ ์ƒ์„ฑ ์•ˆ ํ•จ < 2048๋น„ํŠธ
  • FIPS ๋ชจ๋“œ: ์Šน์ธ๋œ RSA ํ‚ค ์ƒ์„ฑ ์‚ฌ์šฉ(2048 ๋ฐ 3072๋น„ํŠธ ํ‚ค๋งŒ ํ—ˆ์šฉ)
  • FIPS ๋ชจ๋“œ: DH ์ž์ฒด ํ…Œ์ŠคํŠธ ์ถ”๊ฐ€
  • FIPS ๋ชจ๋“œ: RAND_add()์—์„œ DRBG๋ฅผ ์ ์ ˆํ•˜๊ฒŒ ๋‹ค์‹œ ์‹œ๋“œ
  • FIPS ๋ชจ๋“œ: RSA ์•”ํ˜ธํ™”/๋ณตํ˜ธํ™” ์ž์ฒด ํ…Œ์ŠคํŠธ ์ถ”๊ฐ€
  • FIPS ๋ชจ๋“œ: ๋™์ผํ•œ ํ‚ค๋กœ 2^32 GCM ๋ธ”๋ก ์•”ํ˜ธํ™”์— ๋Œ€ํ•œ ํ•˜๋“œ ์ œํ•œ ์ถ”๊ฐ€
  • req -newkey rsa๊ฐ€ ํ˜ธ์ถœ๋˜๋ฉด ๊ตฌ์„ฑ ํŒŒ์ผ์˜ ํ‚ค ๊ธธ์ด๋ฅผ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค.
  • 2014๋…„ 1์›” 7์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-20
  • CVE-2013-4353 ์ˆ˜์ • - ์ž˜๋ชป๋œ TLS ํ•ธ๋“œ์…ฐ์ดํฌ ์ถฉ๋Œ
  • 2014๋…„ 1์›” 6์ผ ์›” Tomรกลก Mrรกz [email protected] 1.0.1e-19
  • CVE-2013-6450 ์ˆ˜์ • - DTLS1์—์„œ ๊ฐ€๋Šฅํ•œ MiTM ๊ณต๊ฒฉ
  • 2013๋…„ 12์›” 20์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-18
  • CVE-2013-6449 ์ˆ˜์ • - SSL ๊ตฌ์กฐ์˜ ๋ฒ„์ „์ด ์˜ฌ๋ฐ”๋ฅด์ง€ ์•Š์„ ๋•Œ ์ถฉ๋Œ
  • 2013๋…„ 12์›” 12์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-17
  • ์‹ค์ˆ˜๋กœ ์‚ญ์ œ๋œ ์ผ๋ถ€ no-op ๊ธฐํ˜ธ๋ฅผ ๋‹ค์‹œ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
  • 2013๋…„ 10์›” 31์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-16
  • ์ง€์›ํ•˜์ง€ ์•Š๋Š” ECC ๊ณก์„ ์„ ๊ด‘๊ณ ํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค.
  • Cyrix CPU์—์„œ CPU ์‹๋ณ„ ์ˆ˜์ •
  • 2013๋…„ 9์›” 27์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-15
  • DTLS1์ด FIPS ๋ชจ๋“œ์—์„œ ์ž‘๋™ํ•˜๋„๋ก ๋งŒ๋“ค๊ธฐ
  • FIPS ๋ชจ๋“œ์˜ 'openssl ์†๋„'์—์„œ RSA ๋ฐ DSA 512๋น„ํŠธ ๋ฐ ์›”ํ’€ ๋ฐฉ์ง€
  • 2013๋…„ 9์›” 26์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-14
  • FIPS ๋ชจ๋“ˆ์ด ์„ค์น˜๋œ dracut-fips ํ‘œ์‹œ์˜ ์„ค์น˜
  • ์›” 2013๋…„ 9์›” 23์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-13
  • libcrypto์—์„œ libssl.so ์‚ญ์ œ ๋ฐฉ์ง€
  • 2013๋…„ 9์›” 20์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-12
  • FIPS es ์ž์ฒด ํ…Œ์ŠคํŠธ์—์„œ ์ž‘์€ ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜ ์ˆ˜์ •
  • FIPS ๋ชจ๋“œ์—์„œ openssl ์†๋„ hmac์˜ segfault ์ˆ˜์ •
  • 2013๋…„ 9์›” 12์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-11
  • ๋งค๋‰ด์–ผ ํŽ˜์ด์ง€์— nextprotoneg ์˜ต์…˜ ๋ฌธ์„œํ™”
    Hubert Kario์˜ ์˜ค๋ฆฌ์ง€๋„ ํŒจ์น˜
  • 2013๋…„ 8์›” 29์ผ ๋ชฉ Tomas Mraz [email protected] 1.0.1e-9
  • ํ•ญ์ƒ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์ƒ์„ฑ์ž์—์„œ FIPS ์ž์ฒด ํ…Œ์ŠคํŠธ๋ฅผ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.
    FIPS ๋ชจ๋“ˆ์ด ์„ค์น˜๋œ ๊ฒฝ์šฐ
  • 2013๋…„ 8์›” 16์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.1e-8
  • ๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ rdrand ์‚ฌ์šฉ ์ˆ˜์ •
  • ๋” ๋งŽ์€ ์ปค๋ฐ‹์€ ์—…์ŠคํŠธ๋ฆผ์—์„œ ์„ ํƒํ•œ ์ฒด๋ฆฌ
  • ๋ฌธ์„œ ์ˆ˜์ •
  • 2013๋…„ 7์›” 26์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.1e-7
  • ์ถ”๊ฐ€ ๋งค๋‰ด์–ผ ํŽ˜์ด์ง€ ์ˆ˜์ •
  • ํ…์ŠคํŠธ ๋ฒ„์ „์—๋„ ๊ธฐํ˜ธ ๋ฒ„์ „ ๊ด€๋ฆฌ ์‚ฌ์šฉ
  • 2013๋…„ 7์›” 25์ผ ๋ชฉ ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 1.0.1e-6
  • ์ถ”๊ฐ€ ๋งค๋‰ด์–ผ ํŽ˜์ด์ง€ ์ˆ˜์ •
  • ECDH ECDSA์— ๋Œ€ํ•œ ์ •๋ฆฌ ์†๋„ ๋ช…๋ น ์ถœ๋ ฅ
  • 2013๋…„ 7์›” 19์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.1e-5
  • _prefix ๋งคํฌ๋กœ ์‚ฌ์šฉ
  • 2013๋…„ 7์›” 10์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.1e-4
  • relro ์—ฐ๊ฒฐ ํ”Œ๋ž˜๊ทธ ์ถ”๊ฐ€
  • 2013๋…„ 7์›” 10์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.1e-2
  • ์ธ์ฆ์„œ ์ฒด์ธ ํ™•์ธ์„ ์œ„ํ•œ -trusted_first ์˜ต์…˜์— ๋Œ€ํ•œ ์ง€์› ์ถ”๊ฐ€
  • 2013๋…„ 5์›” 31์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.1e-1
  • 1.0.1e ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „์œผ๋กœ ๋ฆฌ๋ฒ ์ด์Šค
  • 2013๋…„ 2์›” 25์ผ ์›” Tomas Mraz [email protected] 1.0.0-28
  • CVE-2013-0169 ์ˆ˜์ • - SSL/TLS CBC ํƒ€์ด๋ฐ ๊ณต๊ฒฉ(#907589)
  • CVE-2013-0166 ์ˆ˜์ • - OCSP ์„œ๋ช… ๊ฒ€์‚ฌ์˜ DoS(#908052)
  • ๋˜๋Š” OPENSSL_DEFAULT_ZLIB๋ฅผ ๋ช…์‹œ์ ์œผ๋กœ ์š”์ฒญํ•œ ๊ฒฝ์šฐ์—๋งŒ ์••์ถ• ํ™œ์„ฑํ™”
    ํ™˜๊ฒฝ ๋ณ€์ˆ˜๊ฐ€ ์„ค์ •๋จ(CVE-2012-4929 #857051 ์ˆ˜์ •)
  • getenv() ๋Œ€์‹  __secure_getenv()๋ฅผ ๋ชจ๋“  ๊ณณ์—์„œ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค(#839735).
  • 2012๋…„ 10์›” 12์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-27
  • openssl(1) ๋งจํŽ˜์ด์ง€์—์„œ sslrand(1) ๋ฐ sslpasswd(1) ์ฐธ์กฐ ์ˆ˜์ •(#841645)
  • pkgconfig .pc ํŒŒ์ผ์—์„œ ๋ถˆํ•„์š”ํ•œ lib64 ์ˆ˜์ • ์‚ญ์ œ(#770872)
  • ๊ฐ•์ œ BIO_accept_new(*:) IPv4์—์„œ ์ˆ˜์‹  ๋Œ€๊ธฐ
  • 2012๋…„ 8์›” 15์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-26
  • FIPS ๋ชจ๋“œ์—์„œ ๊ฐœ์ธ ํ‚ค๋ฅผ ์ด์ „ ๋ฒ„์ „์œผ๋กœ ์“ธ ๋•Œ PKCS#8 ์‚ฌ์šฉ
    PEM ์•”ํ˜ธํ™” ๋ชจ๋“œ๊ฐ€ FIPS์™€ ํ˜ธํ™˜๋˜์ง€ ์•Š์Œ(#812348)
  • 2012๋…„ 5์›” 15์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 1.0.0-25
  • CVE-2012-2333 ์ˆ˜์ • - DTLS์—์„œ ๋ ˆ์ฝ”๋“œ ๊ธธ์ด์— ๋Œ€ํ•œ ๋ถ€์ ์ ˆํ•œ ๊ฒ€์‚ฌ(#820686)
  • CVE-2012-0884 ์ˆ˜์ •์—์„œ tkeylen์„ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ดˆ๊ธฐํ™”ํ•˜์‹ญ์‹œ์˜ค.
  • 2012๋…„ 4์›” 19์ผ ๋ชฉ Tomas Mraz [email protected] 1.0.0-24
  • CVE-2012-2110 ์ˆ˜์ • - asn1_d2i_read_bio()์˜ ๋ฉ”๋ชจ๋ฆฌ ์†์ƒ(#814185)
  • ์›” 2012๋…„ 3์›” 19์ผ Tomas Mraz [email protected] 1.0.0-23
  • ํ•ธ๋“œ์…ฐ์ดํฌ๋ฅผ ์ข…๋ฃŒํ•  ์ˆ˜ ์žˆ๋Š” SGC ์žฌ์‹œ์ž‘ ํŒจ์น˜ ๋ฌธ์ œ ์ˆ˜์ •
    ํ‹€๋ฆฌ๊ฒŒ
  • CVE-2012-0884 ์ˆ˜์ • - CMS ๋ฐ PKCS#7 ์ฝ”๋“œ์˜ MMA ์•ฝ์ (#802725)
  • CVE-2012-1165 ์ˆ˜์ • - ์ž˜๋ชป๋œ MIME ํ—ค๋”์— ๋Œ€ํ•œ NULL ์ฝ๊ธฐ ์—ญ์ฐธ์กฐ(#802489)
  • 2012๋…„ 3์›” 1์ผ ๋ชฉ Tomas Mraz [email protected] 1.0.0-22
  • CFB, OFB ๋ฐ CTR ๋ชจ๋“œ์—์„œ ์ •๋ ฌ๋˜์ง€ ์•Š์€ ์ฒญํฌ์˜ ์ž˜๋ชป๋œ ์•”ํ˜ธํ™” ์ˆ˜์ •
  • 2012๋…„ 1์›” 19์ผ ๋ชฉ Tomas Mraz [email protected] 1.0.0-21
  • CVE-2011-4108 ๋ฐ CVE-2012-0050 ์ˆ˜์ • - DTLS ์ผ๋ฐ˜ ํ…์ŠคํŠธ ๋ณต๊ตฌ
    ์ทจ์•ฝ์  ๋ฐ ์ถ”๊ฐ€ DTLS ์ˆ˜์ • ์‚ฌํ•ญ(#771770)
  • CVE-2011-4576 ์ˆ˜์ • - ์ดˆ๊ธฐํ™”๋˜์ง€ ์•Š์€ SSL 3.0 ํŒจ๋”ฉ(#771775)
  • CVE-2011-4577 ์ˆ˜์ • - ์ž˜๋ชป๋œ RFC 3779 ๋ฐ์ดํ„ฐ๋ฅผ ํ†ตํ•œ DoS ๊ฐ€๋Šฅ์„ฑ(#771778)
  • CVE-2011-4619 ์ˆ˜์ • - SGC ์žฌ์‹œ์ž‘ DoS ๊ณต๊ฒฉ(#771780)
  • 2011๋…„ 10์›” 31์ผ ์›” Tomas Mraz [email protected] 1.0.0-20
  • x86cpuid.pl ์ˆ˜์ • - Paolo Bonzini์˜ ํŒจ์น˜
  • 2011๋…„ 9์›” 29์ผ ๋ชฉ Tomas Mraz [email protected] 1.0.0-19
  • SHA2 ์•Œ๊ณ ๋ฆฌ์ฆ˜์— ๋Œ€ํ•œ ์•Œ๋ ค์ง„ ๋‹ต๋ณ€ ํ…Œ์ŠคํŠธ ์ถ”๊ฐ€
  • 2011๋…„ 9์›” 21์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-18
  • CHIL ์—”์ง„์—์„œ ๋ˆ„๋ฝ๋œ ๋ณ€์ˆ˜ ์ดˆ๊ธฐํ™” ์ˆ˜์ •(#740188)
  • ์›” 2011๋…„ 9์›” 12์ผ Tomas Mraz [email protected] 1.0.0-17
  • CRL ์กฐํšŒ๋ฅผ ์œ„ํ•ด X509_STORE_CTX๋ฅผ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ดˆ๊ธฐํ™” - CVE-2011-3207
    (#736087)
  • 2011๋…„ 8์›” 24์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-16
  • Intelx์—์„œ AES-NI, SHA1 ๋ฐ RC4์— ๋Œ€ํ•œ ์ตœ์ ํ™” ๋ณ‘ํ•ฉ
    ๋‚ด๋ถ€ ๊ตฌํ˜„์— ๋Œ€ํ•œ ์—”์ง„
  • ์›” 2011๋…„ 8์›” 15์ผ Tomas Mraz [email protected] 1.0.0-15
  • ์•ฑ์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋‹ค์ด์ œ์ŠคํŠธ์— ๋Œ€ํ•œ ๋” ๋‚˜์€ ๋ฌธ์„œํ™”(#693858)
  • ๋ฐฑํฌํŠธ๋œ CHIL ์—”์ง„ ์ˆ˜์ • ์‚ฌํ•ญ(#693863)
  • ๋‹ค์šด์ŠคํŠธ๋ฆผ ํŒจ์น˜ ์—†์ด ๋นŒ๋“œ ํ…Œ์ŠคํŠธ ํ—ˆ์šฉ(#708511)
  • ์—ฐ๊ฒฐ ์‹œ ๋ถ€๋ถ„ RELRO ํ™œ์„ฑํ™”(#723994)
  • ์ƒˆ๋กœ์šด Intel CPU์—์„œ ์„ฑ๋Šฅ์ด ํ–ฅ์ƒ๋œ Intelx ์—”์ง„ ์ถ”๊ฐ€
  • ๋น„ํ™œ์„ฑํ™”ํ•˜๋Š” OPENSSL_DISABLE_AES_NI ํ™˜๊ฒฝ ๋ณ€์ˆ˜ ์ถ”๊ฐ€
    AES-NI ์ง€์›(intelx ์—”์ง„์— ์˜ํ–ฅ์„ ๋ฏธ์น˜์ง€ ์•Š์Œ)
  • 2011๋…„ 6์›” 8์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-14
  • FIPS ๋ชจ๋“œ์—์„œ AES-NI ์—”์ง„ ์‚ฌ์šฉ
  • 2011๋…„ 5์›” 24์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 1.0.0-11
  • ์ƒˆ๋กœ์šด DSA ๋งค๊ฐœ๋ณ€์ˆ˜ ์ƒ์„ฑ์˜ CAVS ํ…Œ์ŠคํŠธ์— ํ•„์š”ํ•œ API ์ถ”๊ฐ€
  • ๋ชฉ 2011๋…„ 2์›” 10์ผ Tomas Mraz [email protected] 1.0.0-10
  • OCSP ์Šคํ…Œ์ดํ”Œ๋ง ์ทจ์•ฝ์  ์ˆ˜์ • - CVE-2011-0014(#676063)
  • README.FIPS ๋ฌธ์„œ ์ˆ˜์ •
  • 2011๋…„ 2์›” 4์ผ ๊ธˆ์š”์ผ ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 1.0.0-8
  • ANSI X9.31์„ ์‚ฌ์šฉํ•˜๋ ค๋ฉด openssl genrsa ๋ช…๋ น์— -x931 ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
    ํ‚ค ์ƒ์„ฑ ๋ฐฉ๋ฒ•
  • DSA ๋งค๊ฐœ๋ณ€์ˆ˜ ์ƒ์„ฑ์„ ์œ„ํ•ด FIPS-186-3 ๋ฐฉ๋ฒ• ์‚ฌ์šฉ
  • OPENSSL_FIPS_NON_APPROVED_MD5_ALLOW ํ™˜๊ฒฝ ๋ณ€์ˆ˜ ์ถ”๊ฐ€
    ์‹œ์Šคํ…œ์ด ์œ ์ง€ ๊ด€๋ฆฌ ์ƒํƒœ์ผ ๋•Œ MD5๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.
    /proc fips ํ”Œ๋ž˜๊ทธ๊ฐ€ ์ผœ์ ธ ์žˆ์–ด๋„
  • FIPS ๋ชจ๋“œ์—์„œ openssl pkcs12 ๋ช…๋ น์ด ๊ธฐ๋ณธ์ ์œผ๋กœ ์ž‘๋™ํ•˜๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.
  • 2011๋…„ 1์›” 24์ผ ์›” Tomas Mraz [email protected] 1.0.0-7
  • ์—ฐ๊ฒฐ์„ ์ˆ˜๋ฝํ•˜๋„๋ก s_server์˜ ipv6 ์™€์ผ๋“œ์นด๋“œ๋ฅผ ์ˆ˜์‹ ํ•ฉ๋‹ˆ๋‹ค.
    ipv4 ๋ฐ ipv6 ๋ชจ๋‘์—์„œ(#601612)
  • FIPS ๋ชจ๋“œ์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก openssl ์†๋„ ๋ช…๋ น ์ˆ˜์ •
    FIPS ํ—ˆ์šฉ ์•”ํ˜ธ ์‚ฌ์šฉ(#619762)
  • 2010๋…„ 12์›” 7์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 1.0.0-6
  • SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG์— ๋Œ€ํ•œ ์ฝ”๋“œ ๋น„ํ™œ์„ฑํ™” - CVE-2010-3864
    (#649304)
  • 2010๋…„ 11์›” 5์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-5
  • ํ™•์žฅ ๊ตฌ๋ฌธ ๋ถ„์„ ์ฝ”๋“œ์˜ ๋ ˆ์ด์Šค ์ˆ˜์ • - CVE-2010-3864(#649304)
  • 2010๋…„ 6์›” 30์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-4
  • openssl ๋งค๋‰ด์–ผ ํŽ˜์ด์ง€ ์ˆ˜์ •(#609484)
  • 2010๋…„ 6์›” 4์ผ ๊ธˆ์š”์ผ ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 1.0.0-3
  • OriginatorInfo์˜ ์ž˜๋ชป๋œ ASN.1 ์ •์˜ ์ˆ˜์ • - CVE-2010-0742(#598738)
  • rsa_verify_recover์˜ ์ •๋ณด ๋ˆ„์ถœ ์ˆ˜์ • - CVE-2010-1633(#598732)
  • 2010๋…„ 5์›” 19์ผ ์ˆ˜์š”์ผ Tomas Mraz [email protected] 1.0.0-2
  • CA dir์„ ์ฝ์„ ์ˆ˜ ์žˆ๋„๋ก ์„ค์ • - ๊ฐœ์ธ ํ‚ค๋Š” ๊ฐœ์ธ ํ•˜์œ„ ๋””๋ ‰ํ† ๋ฆฌ์— ์žˆ์Šต๋‹ˆ๋‹ค(#584810).
  • ์—…์ŠคํŠธ๋ฆผ CVS์˜ ๋ช‡ ๊ฐ€์ง€ ์ˆ˜์ • ์‚ฌํ•ญ
  • X509_NAME_hash_old๊ฐ€ FIPS ๋ชจ๋“œ์—์„œ ์ž‘๋™ํ•˜๋„๋ก ํ•ฉ๋‹ˆ๋‹ค(#568395).
  • 2010๋…„ 3์›” 30์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 1.0.0-1
  • ์ตœ์ข… 1.0.0 ์—…์ŠคํŠธ๋ฆผ ๋ฆด๋ฆฌ์Šค๋กœ ์—…๋ฐ์ดํŠธ
  • 2010๋…„ 2์›” 16์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 1.0.0-0.22.beta5
  • FIPS ๋ชจ๋“œ์—์„œ TLS ์ž‘๋™
  • 2010๋…„ 2์›” 12์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-0.21.beta5
  • ์–ด์…ˆ๋ธ”๋Ÿฌ ๊ตฌํ˜„์—์„œ 0 ๊ธธ์ด๋ฅผ ์ •์ƒ์ ์œผ๋กœ ์ฒ˜๋ฆฌ
    OPENSSL_cleanse(#564029)
  • ํด๋ผ์ด์–ธํŠธ ํ˜ธ์ŠคํŠธ ์ด๋ฆ„์„ ํ™•์ธํ•  ์ˆ˜ ์—†๋Š” ๊ฒฝ์šฐ s_server์—์„œ ์‹คํŒจํ•˜์ง€ ์•Š์Œ(#561260)
  • 2010๋…„ 1์›” 20์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-0.20.beta5
  • ์ƒˆ๋กœ์šด ์—…์ŠคํŠธ๋ฆผ ๋ฆด๋ฆฌ์Šค
  • 2010๋…„ 1์›” 14์ผ ๋ชฉ Tomas Mraz [email protected] 1.0.0-0.19.beta4
  • CVE-2009-4355 ์ˆ˜์ • - ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์—์„œ ๋ˆ„์ˆ˜๊ฐ€ ์ž˜๋ชป ํ˜ธ์ถœ๋จ
    ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ ์ข…๋ฃŒ ์ „ CRYPTO_free_all_ex_data()(#546707)
  • ํ–ฅํ›„ TLS ํ”„๋กœํ† ์ฝœ ๋ฒ„์ „ ์ฒ˜๋ฆฌ๋ฅผ ์œ„ํ•œ ์—…์ŠคํŠธ๋ฆผ ์ˆ˜์ •
  • 2010๋…„ 1์›” 13์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-0.18.beta4
  • Intel AES-NI์— ๋Œ€ํ•œ ์ง€์› ์ถ”๊ฐ€
  • 2010๋…„ 1์›” 7์ผ ๋ชฉ ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 1.0.0-0.17.beta4
  • ์„ธ์…˜ ์žฌ๊ฐœ ์‹œ ์—…์ŠคํŠธ๋ฆผ ์ˆ˜์ • ์••์ถ• ์ฒ˜๋ฆฌ
  • ์—…์ŠคํŠธ๋ฆผ์˜ ๋‹ค์–‘ํ•œ null ๊ฒ€์‚ฌ ๋ฐ ๊ธฐํƒ€ ์ž‘์€ ์ˆ˜์ • ์‚ฌํ•ญ
  • ์ตœ์‹  ์ดˆ์•ˆ์— ๋”ฐ๋ฅธ ์žฌํ˜‘์ƒ ์ •๋ณด์˜ ์—…์ŠคํŠธ๋ฆผ ๋ณ€๊ฒฝ ์‚ฌํ•ญ
  • 2009๋…„ 11์›” 23์ผ ์›” Tomas Mraz [email protected] 1.0.0-0.16.beta4
  • non-fips mingw ๋นŒ๋“œ ์ˆ˜์ • (Kalev Lember์˜ ํŒจ์น˜)
  • DTLS์— ๋Œ€ํ•œ IPV6 ์ˆ˜์ • ์‚ฌํ•ญ ์ถ”๊ฐ€
  • 2009๋…„ 11์›” 20์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-0.15.beta4
  • ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ์žฌํ˜‘์ƒ์„ ์œ„ํ•ด ๋” ๋‚˜์€ ์˜ค๋ฅ˜ ๋ณด๊ณ  ์ถ”๊ฐ€
  • 2009๋…„ 11์›” 20์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-0.14.beta4
  • s390x์—์„œ ๋นŒ๋“œ ์ˆ˜์ •
  • 2009๋…„ 11์›” 18์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-0.13.beta4
  • ํด๋ผ์ด์–ธํŠธ์—์„œ ์žฌํ˜‘์ƒ ํ™•์žฅ์˜ ์‹œํ–‰์„ ๋น„ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค(#537962).
  • ํ˜„์žฌ ์—…์ŠคํŠธ๋ฆผ ์Šค๋ƒ…์ƒท์—์„œ ์ˆ˜์ • ์‚ฌํ•ญ ์ถ”๊ฐ€
  • 2009๋…„ 11์›” 13์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-0.12.beta4
  • ๋‹ค์‹œ ๋นŒ๋“œํ•  ํ•„์š”๊ฐ€ ์—†๋„๋ก ๋ฒ„์ „ ๋ฒˆํ˜ธ์˜ ๋ฒ ํƒ€ ์ƒํƒœ๋ฅผ 3์œผ๋กœ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค.
    ๋„ˆ๋ฌด ์—„๊ฒฉํ•œ ๋ฒ„์ „ ํ™•์ธ์ด ์žˆ๋Š” openssh ๋ฐ ๊ธฐํƒ€ ์ข…์†์„ฑ
  • 2009๋…„ 11์›” 12์ผ ๋ชฉ Tomas Mraz [email protected] 1.0.0-0.11.beta4
  • ์ƒˆ๋กœ์šด ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธ, soname ๋ฒ”ํ”„ ํ•„์š” ์—†์Œ
  • ์ˆ˜์ • CVE-2009-3555 - SSL_OP_ALL์ด ์‚ฌ์šฉ๋˜๋Š” ๊ฒฝ์šฐ ์ˆ˜์ • ์‚ฌํ•ญ์ด ๋ฌด์‹œ๋ฉ๋‹ˆ๋‹ค.
    ๋”ฐ๋ผ์„œ ๊ณ ์ •๋˜์ง€ ์•Š์€ ํด๋ผ์ด์–ธํŠธ์™€์˜ ํ˜ธํ™˜์„ฑ์ด ์†์ƒ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ทธ๋งŒํผ
    ํ”„๋กœํ† ์ฝœ ํ™•์žฅ๋„ ์ตœ์ข…์ ์ด์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
  • 2009๋…„ 10์›” 16์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-0.10.beta3
  • SSL_CTX_free()๊ฐ€ ์ „์— ํ˜ธ์ถœ๋œ ๊ฒฝ์šฐ ํ•ด์ œ๋œ ๋ฉ”๋ชจ๋ฆฌ ์‚ฌ์šฉ ์ˆ˜์ •
    SSL_free() (#521342)
  • 2009๋…„ 10์›” 8์ผ ๋ชฉ ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 1.0.0-0.9.beta3
  • DTLS1 ์ฝ”๋“œ์˜ ์˜คํƒ€ ์ˆ˜์ •(#527015)
  • d2i_SSL_SESSION()์˜ ์˜ค๋ฅ˜ ์ฒ˜๋ฆฌ์—์„œ ๋ˆ„์ˆ˜ ์ˆ˜์ •
  • 2009๋…„ 9์›” 30์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-0.8.beta3
  • RSA ๋ฐ DSA FIPS ์ž์ฒด ํ…Œ์ŠคํŠธ ์ˆ˜์ •
  • ๊ณ ์ • x86_64 ๋™๋ฐฑ ์–ด์…ˆ๋ธ”๋Ÿฌ ์ฝ”๋“œ ์žฌํ™œ์„ฑํ™”(#521127)
  • 2009๋…„ 9์›” 4์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-0.7.beta3
  • x86_64 ๋™๋ฐฑ ์–ด์…ˆ๋ธ”๋Ÿฌ ์ฝ”๋“œ๋ฅผ ์ผ์‹œ์ ์œผ๋กœ ๋น„ํ™œ์„ฑํ™”(#521127)
  • 2009๋…„ 8์›” 31์ผ ์›” Tomas Mraz [email protected] 1.0.0-0.6.beta3
  • openssl dgst -dss1 ์ˆ˜์ •(#520152)
  • 2009๋…„ 8์›” 26์ผ ์ˆ˜ Tomas Mraz [email protected] 1.0.0-0.5.beta3
  • compat symlink ํ•ดํ‚น์„ ์‚ญ์ œํ•˜์‹ญ์‹œ์˜ค.
  • 2009๋…„ 8์›” 22์ผ ํ†  ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 1.0.0-0.4.beta3
  • SSL_CIPHER_description() ๊ตฌ์„ฑ
  • 2009๋…„ 8์›” 21์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-0.3.beta3
  • ์ˆ˜์ • WWW:Curl :tsget์—์„œ ์‰ฌ์šด ์ฐธ์กฐ
  • 2009๋…„ 8์›” 21์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 1.0.0-0.2.beta3
  • MD-2 ํ™œ์„ฑํ™”
  • ๋ชฉ 2009๋…„ 8์›” 20์ผ Tomas Mraz [email protected] 1.0.0-0.1.beta3
  • ์ƒˆ๋กœ์šด ์ฃผ์š” ์—…์ŠคํŠธ๋ฆผ ๋ฆด๋ฆฌ์Šค๋กœ ์—…๋ฐ์ดํŠธ
  • 2009๋…„ 7์›” 25์ผ ํ† ์š”์ผ Fedora Release Engineering [email protected] - 0.9.8k-7
  • https://fedoraproject.org/wiki/Fedora_12_Mass_Rebuild ๋ฅผ ์œ„ํ•ด ์žฌ๊ฑด
  • 2009๋…„ 7์›” 22์ผ ์ˆ˜์š”์ผ Bill Nottingham [email protected]
  • i686์„ ์œ„ํ•œ ํŠน๋ณ„ํ•œ '์ตœ์ ํ™”' ๋ฒ„์ „์„ ๊ตฌ์ถ•ํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค. ์ด๊ฒƒ์ด ๊ธฐ๋ณธ์ด๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.
    ์ง€๊ธˆ Fedora์˜ ์•„์น˜
  • 2009๋…„ 6์›” 30์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.8k-6
  • ์ž์ฒด ํ…Œ์ŠคํŠธ๊ฐ€ ์‹คํŒจํ•˜๊ณ  ๋‚œ์ˆ˜ ์ƒ์„ฑ๊ธฐ๊ฐ€ ํด๋ง๋˜๋ฉด ์ค‘๋‹จ
  • ๋งจํŽ˜์ด์ง€์—์„œ EVP_aes ๋ฐ EVP_sha2xx ๋ฃจํ‹ด ์–ธ๊ธ‰
  • README.FIPS ์ถ”๊ฐ€
  • CA dir ์ ˆ๋Œ€ ๊ฒฝ๋กœ ๋งŒ๋“ค๊ธฐ(#445344)
  • RSA ํ‚ค ์ƒ์„ฑ์˜ ๊ธฐ๋ณธ ๊ธธ์ด๋ฅผ 2048๋กœ ๋ณ€๊ฒฝ(#484101)
  • 2009๋…„ 5์›” 21์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8k-5
  • ์ˆ˜์ • CVE-2009-1377 CVE-2009-1378 CVE-2009-1379
    (DTLS DoS ๋ฌธ์ œ) (#501253, #501254, #501572)
  • 2009๋…„ 4์›” 21์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.8k-4
  • CISCO AnyConnect์— ๋Œ€ํ•œ ํ˜ธํ™˜์„ฑ DTLS ๋ชจ๋“œ ์ง€์›(#464629)
  • 2009๋…„ 4์›” 17์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 0.9.8k-3
  • SHLIB_VERSION ์ •์˜ ์ˆ˜์ •
  • 2009๋…„ 4์›” 15์ผ ์ˆ˜ Tomas Mraz [email protected] 0.9.8k-2
  • ๋™์ผํ•œ ์ฃผ์ œ๋ฅผ ๊ฐ€์ง„ ์—ฌ๋Ÿฌ CRL์— ๋Œ€ํ•œ ์ง€์› ์ถ”๊ฐ€
  • FIPS ๋ชจ๋“œ์—์„œ ๋™์  ์—”์ง„ ์ง€์›๋งŒ ๋กœ๋“œ
  • 2009๋…„ 3์›” 25์ผ ์ˆ˜์š”์ผ Tomas Mraz [email protected] 0.9.8k-1
  • ์ƒˆ๋กœ์šด ์—…์ŠคํŠธ๋ฆผ ๋ฆด๋ฆฌ์Šค๋กœ ์—…๋ฐ์ดํŠธ(์‚ฌ์†Œํ•œ ๋ฒ„๊ทธ ์ˆ˜์ •, ๋ณด์•ˆ
    ์ˆ˜์ • ๋ฐ ๊ธฐ๊ณ„ ์ฝ”๋“œ ์ตœ์ ํ™”๋งŒ ํ•ด๋‹น)
  • 2009๋…„ 3์›” 19์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8j-10
  • ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ /usr/lib๋กœ ์ด๋™(#239375)
  • 2009๋…„ 3์›” 13์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 0.9.8j-9
  • ์ •์  ํ•˜์œ„ ํŒจํ‚ค์ง€ ์ถ”๊ฐ€
  • 2009๋…„ 2์›” 26์ผ ๋ชฉ ํŽ˜๋„๋ผ ๋ฆด๋ฆฌ์Šค ์—”์ง€๋‹ˆ์–ด๋ง [email protected] - 0.9.8j-8
  • https://fedoraproject.org/wiki/Fedora_11_Mass_Rebuild ์šฉ์œผ๋กœ ์žฌ๊ตฌ์ถ•
  • 2009๋…„ 2์›” 2์ผ ์›” Tomas Mraz [email protected] 0.9.8j-7
  • FIPS ๋ชจ๋“œ์—์„œ libssl.so์˜ ์ฒดํฌ์„ฌ๋„ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • ์ปค๋„ ์žฅ์น˜์—์„œ ์ง์ ‘ FIPS rng์˜ ์‹œ๋“œ๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค.
  • ์ž„์‹œ ์‹ฌ๋ณผ๋ฆญ ๋งํฌ ์‚ญ์ œ
  • 2009๋…„ 1์›” 26์ผ ์›” Tomas Mraz [email protected] 0.9.8j-6
  • ํฌ์ŠคํŠธ์—์„œ ์ž„์‹œ triggerpostun ๋ฐ symlinking ์‚ญ์ œ
  • pkgconfig ํŒŒ์ผ์„ ์ˆ˜์ •ํ•˜๊ณ  ๋ถˆํ•„์š”ํ•œ buildrequires ์‚ญ์ œ
    rpmbuild ์ข…์†์„ฑ์ด๋ฏ€๋กœ pkgconfig์—์„œ (#481419)
  • 2009๋…„ 1์›” 17์ผ ํ†  ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 0.9.8j-5
  • ์‹ฌ๋ณผ๋ฆญ ๋งํฌ๋ฅผ ๋ณต์›ํ•˜๊ธฐ ์œ„ํ•ด ์ž„์‹œ triggerpostun ์ถ”๊ฐ€
  • 2009๋…„ 1์›” 17์ผ ํ†  ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 0.9.8j-4
  • non-fips ๋ชจ๋“œ์—์„œ pairwise ํ‚ค ํ…Œ์ŠคํŠธ ์—†์Œ(#479817)
  • 2009๋…„ 1์›” 16์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 0.9.8j-3
  • ์ž„์‹œ ์‹ฌ๋ณผ๋ฆญ ๋งํฌ์— ๋Œ€ํ•œ ๋”์šฑ ๊ฐ•๋ ฅํ•œ ํ…Œ์ŠคํŠธ
  • 2009๋…„ 1์›” 16์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 0.9.8j-2
  • ์ž„์‹œ ์‹ฌ๋ณผ๋ฆญ ๋งํฌ๊ฐ€ ์กด์žฌํ•˜๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค
  • 2009๋…„ 1์›” 15์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8j-1
  • ํ•„์š”ํ•œ ์ด๋ฆ„ ๋ฒ”ํ”„๊ฐ€ ์žˆ๋Š” ์ƒˆ ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „(#455753)
  • ๋‹ค์‹œ ๋นŒ๋“œํ•  ์ˆ˜ ์žˆ๋„๋ก ์ž„์‹œ๋กœ ์ด์ „ soname์— ๋Œ€ํ•œ ์‹ฌ๋ณผ๋ฆญ ๋งํฌ๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
    ์ƒ๊ฐ€์ฃฝ์˜ ์ข…์† ํŒจํ‚ค์ง€
  • ๋น ๋ฅธ ์ง€์› ์ถ”๊ฐ€(#428181)
  • ์„ค์ •ํ•˜์—ฌ zlib๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€๋Šฅ์„ฑ ์ถ”๊ฐ€
  • ํ…Œ์ŠคํŠธ ๋ชฉ์ ์œผ๋กœ fips ๋ชจ๋“œ ์ง€์› ์ถ”๊ฐ€
  • ์ผ๋ถ€ ์œ ํšจํ•˜์ง€ ์•Š์€ smime ํŒŒ์ผ์— ๋Œ€ํ•ด null ์—ญ์ฐธ์กฐ๋ฅผ ํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค.
  • ๋นŒ๋“œ๋ฅผ ์ถ”๊ฐ€ํ•˜๋ ค๋ฉด pkgconfig๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค(#479493).
  • ์ผ 2008๋…„ 8์›” 10์ผ Tomas Mraz [email protected] 0.9.8g-11
  • SSLv3์šฉ ์„œ๋ฒ„ hello์— tls ํ™•์žฅ์„ ์ถ”๊ฐ€ํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค.
  • 2008๋…„ 6์›” 2์ผ ์›” Joe Orton [email protected] 0.9.8g-10
  • ๋ฃจํŠธ CA ๋ฒˆ๋“ค์„ ca-certificates ํŒจํ‚ค์ง€๋กœ ์ด๋™
  • 2008๋…„ 5์›” 28์ผ ์ˆ˜ Tomas Mraz [email protected] 0.9.8g-9
  • CVE-2008-0891 ์ˆ˜์ • - ์„œ๋ฒ„ ์ด๋ฆ„ ํ™•์žฅ ์ถฉ๋Œ(#448492)
  • CVE-2008-1672 ์ˆ˜์ • - ์„œ๋ฒ„ ํ‚ค ๊ตํ™˜ ๋ฉ”์‹œ์ง€ ๋ˆ„๋ฝ ์ถฉ๋Œ(#448495)
  • 2008๋…„ 5์›” 27์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.8g-8
  • ์Šˆํผ H ์•„์น˜ ์ง€์›
  • gcc-4.3์—์„œ ์ˆ˜์ •๋˜์–ด์•ผ ํ•˜๋ฏ€๋กœ ๋ฒ„๊ทธ 199604์— ๋Œ€ํ•œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ• ์‚ญ์ œ
  • 2008๋…„ 5์›” 19์ผ ์›” Tom "spot" Callaway [email protected] 0.9.8g-7
  • ์ŠคํŒŒํฌ ์ฒ˜๋ฆฌ
  • 2008๋…„ 3์›” 10์ผ ์›” Joe Orton [email protected] 0.9.8g-6
  • mozilla.org(r1.45)์—์„œ ์ƒˆ ๋ฃจํŠธ CA ๋ฒˆ๋“ค๋กœ ์—…๋ฐ์ดํŠธ
  • 2008๋…„ 2์›” 20์ผ ์ˆ˜์š”์ผ Fedora Release Engineering [email protected] - 0.9.8g-5
  • GCC 4.3์šฉ ์ž๋™ ์žฌ๊ตฌ์ถ•
  • 2008๋…„ 1์›” 24์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8g-4
  • ๋ณ‘ํ•ฉ ๊ฒ€ํ†  ์ˆ˜์ • ์‚ฌํ•ญ(#226220)
  • ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ์ด๋ฆ„์„ ๋ฐ˜์˜ํ•˜๋„๋ก SHLIB_VERSION_NUMBER ์กฐ์ •(#429846)
  • 2007๋…„ 12์›” 13์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8g-3
  • ๋ช…์‹œ์  ๊ฒฝ๋กœ๊ฐ€ ์„ค์ •๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ ๊ธฐ๋ณธ ๊ฒฝ๋กœ ์„ค์ •(#418771)
  • SSLv3์šฉ ํด๋ผ์ด์–ธํŠธ hello์— tls ํ™•์žฅ์„ ์ถ”๊ฐ€ํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค(#422081).
  • 2007๋…„ 12์›” 4์ผ ํ™”์š”์ผ ํ† ๋งˆ์Šค ๋ฏ€๋ผ์ฆˆ [email protected] 0.9.8g-2
  • ๋ช‡ ๊ฐ€์ง€ ์ƒˆ๋กœ์šด ์•”ํ˜ธํ™” ์•Œ๊ณ ๋ฆฌ์ฆ˜ ๋ฐ ๊ธฐ๋Šฅ ํ™œ์„ฑํ™”
  • openssl CVS์—์„œ ๋” ์ค‘์š”ํ•œ ๋ฒ„๊ทธ ์ˆ˜์ • ์ถ”๊ฐ€
  • 2007๋…„ 12์›” 3์ผ ์›” Tomas Mraz [email protected] 0.9.8g-1
  • ์ตœ์‹  ์—…์ŠคํŠธ๋ฆผ ๋ฆด๋ฆฌ์Šค๋กœ ์—…๋ฐ์ดํŠธ, SONAME์ด 7๋กœ ๋ณ€๊ฒฝ๋จ
  • ์›” 2007๋…„ 10์›” 15์ผ Joe Orton [email protected] 0.9.8b-17
  • mozilla.org์—์„œ ์ƒˆ CA ๋ฒˆ๋“ค๋กœ ์—…๋ฐ์ดํŠธ
  • 2007๋…„ 10์›” 12์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 0.9.8b-16
  • CVE-2007-5135 - SSL_get_shared_ciphers์—์„œ ํ•˜๋‚˜์”ฉ ์ˆ˜์ •(#309801)
  • CVE-2007-4995 ์ˆ˜์ • - ์ˆœ์„œ๊ฐ€ ์ž˜๋ชป๋œ DTLS ์กฐ๊ฐ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ(#321191)
  • ์•ŒํŒŒ ํ•˜์œ„ ์•„์น˜ ์ถ”๊ฐ€(#296031)
  • 2007๋…„ 8์›” 21์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.8b-15
  • ์žฌ๊ฑดํ•˜๋‹ค
  • 2007๋…„ 8์›” 3์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 0.9.8b-14
  • testsuite์—์„œ localhost ์‚ฌ์šฉ, koji์˜ ๋Š๋ฆฐ ๋นŒ๋“œ ์ˆ˜์ •
  • CVE-2007-3108 - ๊ฐœ์ธ ํ‚ค์— ๋Œ€ํ•œ ์‚ฌ์ด๋“œ ์ฑ„๋„ ๊ณต๊ฒฉ ์ˆ˜์ •(#250577)
  • SSL ์„ธ์…˜ ์บ์‹œ ID๋ฅผ ์—„๊ฒฉํ•˜๊ฒŒ ์ผ์น˜์‹œํ‚ค์‹ญ์‹œ์˜ค(#233599).
  • 2007๋…„ 7์›” 25์ผ ์ˆ˜ Tomas Mraz [email protected] 0.9.8b-13
  • ARM ์•„ํ‚คํ…์ฒ˜์—์„œ ๋นŒ๋“œ ํ—ˆ์šฉ(#245417)
  • ์ฐธ์กฐ ํƒ€์ž„์Šคํƒฌํ”„๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ multilib ์ถฉ๋Œ ๋ฐฉ์ง€(#218064)
  • -devel ํŒจํ‚ค์ง€์—๋Š” pkgconfig๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค(#241031).
  • ์›” 2006๋…„ 12์›” 11์ผ Tomas Mraz [email protected] 0.9.8b-12
  • add_dir์—์„œ ์ค‘๋ณต์„ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ๊ฐ์ง€ํ•ฉ๋‹ˆ๋‹ค(#206346).
  • 2006๋…„ 11์›” 30์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8b-11
  • ์ด์ „ ๋ณ€๊ฒฝ์œผ๋กœ ์ธํ•ด ์—ฌ์ „ํžˆ X509_NAME_cmp๊ฐ€ ์ „์ด๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค.
  • 2006๋…„ 11์›” 23์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8b-10
  • X509_NAME_cmp๋ฅผ ์ „์ด์ ์œผ๋กœ ๋งŒ๋“ค์ง€ ์•Š์œผ๋ฉด ์ธ์ฆ์„œ ์กฐํšŒ
    ๊ณ ์žฅ๋‚ฌ์Šต๋‹ˆ๋‹ค(#216050)
  • 2006๋…„ 11์›” 2์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8b-9
  • ์—”์ง„ ๋กœ๋”ฉ์˜ ์•จ๋ฆฌ์–ด์‹ฑ ๋ฒ„๊ทธ, IBM ํŒจ์น˜(#213216)
  • 2006๋…„ 10์›” 2์ผ ์›” Tomas Mraz [email protected] 0.9.8b-8
  • CVE-2006-2940 ์ˆ˜์ • ์‚ฌํ•ญ์ด ์ž˜๋ชป๋˜์—ˆ์Šต๋‹ˆ๋‹ค(#208744).
  • ์›” 2006๋…„ 9์›” 25์ผ Tomas Mraz [email protected] 0.9.8b-7
  • CVE-2006-2937 ์ˆ˜์ • - ASN.1 ๊ตฌ๋ฌธ ๋ถ„์„์—์„œ ์ž˜๋ชป ์ฒ˜๋ฆฌ๋œ ์˜ค๋ฅ˜(#207276)
  • CVE-2006-2940 ์ˆ˜์ • - ๊ธฐ์ƒ ๊ณต๊ฐœ ํ‚ค DoS(#207274)
  • CVE-2006-3738 ์ˆ˜์ • - SSL_get_shared_ciphers์˜ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ(#206940)
  • CVE-2006-4343 - sslv2 ํด๋ผ์ด์–ธํŠธ DoS ์ˆ˜์ •(#206940)
  • 2006๋…„ 9์›” 5์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.8b-6
  • CVE-2006-4339 ์ˆ˜์ • - PKCS#1 v1.5 ์„œ๋ช…์— ๋Œ€ํ•œ ๊ณต๊ฒฉ ๋ฐฉ์ง€(#205180)
  • 2006๋…„ 8์›” 2์ผ ์ˆ˜ Tomas Mraz [email protected] - 0.9.8b-5
  • bufsize๊ฐ€ ์„ค์ •๋œ ๊ฒฝ์šฐ stdio/stdout FILE์—์„œ ๋ฒ„ํผ๋ง์„ ์—†์Œ์œผ๋กœ ์„ค์ •(#200580)
    IBM์˜ ํŒจ์น˜
  • 2006๋…„ 7์›” 28์ผ ๊ธˆ์š”์ผ Alexandre Oliva [email protected] - 0.9.8b-4.1
  • ์ƒˆ binutils๋กœ ๋‹ค์‹œ ๋นŒ๋“œ(#200330)
  • 2006๋…„ 7์›” 21์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] - 0.9.8b-4
  • s390์—์„œ sha512 ํ…Œ์ŠคํŠธ ์‹คํŒจ์— ๋Œ€ํ•œ ์ž„์‹œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ• ์ถ”๊ฐ€(#199604)
  • 2006๋…„ 7์›” 20์ผ ๋ชฉ Tomas Mraz [email protected]
  • s_client ๋ฐ s_server์— ipv6 ์ง€์› ์ถ”๊ฐ€(Jan Pazdziora ์ž‘์„ฑ)(#198737)
  • BN ์Šค๋ ˆ๋“œ ์•ˆ์ „์„ ์œ„ํ•œ ํŒจ์น˜ ์ถ”๊ฐ€, AES ์บ์‹œ ์ถฉ๋Œ ๊ณต๊ฒฉ ์œ„ํ—˜ ์ˆ˜์ • ๋ฐ
    ์—…์ŠคํŠธ๋ฆผ CVS์˜ pkcs7 ์ฝ”๋“œ memleak ์ˆ˜์ •
  • 2006๋…„ 7์›” 12์ผ ์ˆ˜์š”์ผ Jesse Keating [email protected] - 0.9.8b-3.1
  • ์žฌ๊ฑดํ•˜๋‹ค
  • 2006๋…„ 6์›” 21์ผ ์ˆ˜์š”์ผ Tomas Mraz [email protected] - 0.9.8b-3
  • ๋นŒ๋“œ์—์„œ libica ๋ฐ ica ์—”์ง„์„ ์‚ญ์ œํ–ˆ์Šต๋‹ˆ๋‹ค.
  • 2006๋…„ 6์›” 21์ผ ์ˆ˜ Joe Orton [email protected]
  • mozilla.org์—์„œ ์ƒˆ CA ๋ฒˆ๋“ค๋กœ ์—…๋ฐ์ดํŠธ CA ์ธ์ฆ์„œ ์ถ”๊ฐ€
    netlock.hu ๋ฐ startcom.org์—์„œ
  • 2006๋…„ 6์›” 5์ผ ์›” Tomas Mraz [email protected] - 0.9.8b-2
  • ๋ช‡ ๊ฐ€์ง€ rpmlint ๊ฒฝ๊ณ  ์ˆ˜์ •
  • ์—…์ŠคํŠธ๋ฆผ์—์„œ #173399์— ๋Œ€ํ•œ ๋” ๋‚˜์€ ์ˆ˜์ •
  • pkcs12์— ๋Œ€ํ•œ ์—…์ŠคํŠธ๋ฆผ ์ˆ˜์ •
  • 2006๋…„ 5์›” 11์ผ ๋ชฉ Tomas Mraz [email protected] - 0.9.8b-1
  • ์ƒˆ ๋ฒ„์ „์œผ๋กœ ์—…๊ทธ๋ ˆ์ด๋“œ, ABI ํ˜ธํ™˜ ์œ ์ง€
  • ๋” ์ด์ƒ linux/config.h๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค(์–ด์จŒ๋“  ๋น„์–ด ์žˆ์Œ)
  • 2006๋…„ 4์›” 4์ผ ํ™”์š”์ผ Tomas Mraz [email protected] - 0.9.8a-6
  • libica์˜ ์˜ค๋ž˜๋œ ์—ด๋ฆฐ ํ•ธ๋“ค ์ˆ˜์ •(#177155)
  • buildroot ๊ฒฝ๋กœ์—์„œ 'rand' ๋˜๋Š” 'passwd'์ธ ๊ฒฝ์šฐ ๋นŒ๋“œ ์ˆ˜์ •(#178782)
  • VIA Padlock ์—”์ง„ ์ดˆ๊ธฐํ™”(#186857)
  • 2006๋…„ 2์›” 10์ผ ๊ธˆ์š”์ผ Jesse Keating [email protected] - 0.9.8a-5.2
  • ppc(64)์˜ ์ด์ค‘ ๊ธด ๋ฒ„๊ทธ์— ๋Œ€ํ•ด ๋‹ค์‹œ ๋ฒ”ํ”„
  • 2006๋…„ 2์›” 7์ผ ํ™”์š”์ผ Jesse Keating [email protected] - 0.9.8a-5.1
  • ์ƒˆ๋กœ์šด gcc4.1 ์Šค๋ƒ…์ƒท ๋ฐ glibc ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ์œ„ํ•ด ์žฌ๊ตฌ์ถ•
  • 2005๋…„ 12์›” 15์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.8a-5
  • SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG๋ฅผ ํฌํ•จํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค.
    SSL_OP_ALL์—์„œ(#175779)
  • 2005๋…„ 12์›” 9์ผ ๊ธˆ์š”์ผ Jesse Keating [email protected]
  • ์žฌ๊ฑด
  • 2005๋…„ 11์›” 29์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.8a-4
  • ์—…๋ฐ์ดํŠธ๋œ libica์˜ ๋นŒ๋“œ ์ˆ˜์ •(-lcrypto๊ฐ€ ์ž˜๋ชป ์‚ญ์ œ๋จ)
  • ICA ์—”์ง„์„ 1.3.6-rc3์œผ๋กœ ์—…๋ฐ์ดํŠธํ–ˆ์Šต๋‹ˆ๋‹ค.
  • 2005๋…„ 11์›” 22์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.8a-3
  • ์ž‘๋™ํ•  ๋•Œ๊นŒ์ง€ ๋‚ด์žฅ ์••์ถ• ๋ฐฉ๋ฒ•์„ ๋น„ํ™œ์„ฑํ™”ํ•˜์‹ญ์‹œ์˜ค.
    ์ œ๋Œ€๋กœ (#173399)
  • 2005๋…„ 11์›” 16์ผ ์ˆ˜ Tomas Mraz [email protected] 0.9.8a-2
  • openssl ๋ฐ”์ด๋„ˆ๋ฆฌ์— ๋Œ€ํ•ด -rpath๋ฅผ ์„ค์ •ํ•˜์ง€ ๋งˆ์‹ญ์‹œ์˜ค.
  • 2005๋…„ 11์›” 8์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.8a-1
  • ์ƒˆ๋กœ์šด ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „
  • ๋ถ€๋ถ„์ ์œผ๋กœ ๋ฒˆํ˜ธ๊ฐ€ ๋‹ค์‹œ ๋งค๊ฒจ์ง„ ํŒจ์น˜
  • 2005๋…„ 10์›” 21์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 0.9.7f-11
  • ์ตœ์‹  ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธ๋œ IBM ICA ์—”์ง„ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ๋ฐ ํŒจ์น˜
  • ์ˆ˜ 2005๋…„ 10์›” 12์ผ Tomas Mraz [email protected] 0.9.7f-10
  • CAN-2005-2969 ์ˆ˜์ • - SSL_OP_MSIE_SSLV2_RSA_PADDING ์ œ๊ฑฐ
    SSLv2์—์„œ ์ค‘๊ฐ„์ž ๊ณต๊ฒฉ์— ๋Œ€ํ•œ ๋Œ€์ฑ…์„ ๋น„ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.
    (#169863)
  • CA ๋ฐ ์ธ์ฆ์„œ ์š”์ฒญ์— ๋Œ€ํ•ด sha1์„ ๊ธฐ๋ณธ๊ฐ’์œผ๋กœ ์‚ฌ์šฉ - CAN-2005-2946(#169803)
  • 2005๋…„ 8์›” 23์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.7f-9
  • /lib์— *.so.soversion์„ ์‹ฌ๋ณผ๋ฆญ ๋งํฌ๋กœ ์ถ”๊ฐ€(#165264)
  • ํŒจํ‚ค์ง€๋˜์ง€ ์•Š์€ ์‹ฌ๋ณผ๋ฆญ ๋งํฌ ์ œ๊ฑฐ(#159595)
  • ์—…์ŠคํŠธ๋ฆผ์—์„œ ์ˆ˜์ •(DSA์— ๋Œ€ํ•œ ์ผ์ • ์‹œ๊ฐ„ ์ˆ˜์ •,
    ppc ์•„์น˜์˜ bn ์–ด์…ˆ๋ธ”๋Ÿฌ div, realloc์—์„œ ๋ฉ”๋ชจ๋ฆฌ ์ดˆ๊ธฐํ™”)
  • 2005๋…„ 8์›” 11์ผ ๋ชฉ Phil Knirsch [email protected] 0.9.7f-8
  • ICA ์—”์ง„ IBM ํŒจ์น˜๋ฅผ ์ตœ์‹  ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธํ–ˆ์Šต๋‹ˆ๋‹ค.
  • 2005๋…„ 5์›” 19์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.7f-7
  • CAN-2005-0109 ์ˆ˜์ • - ์ผ์ •ํ•œ ์‹œ๊ฐ„/๋ฉ”๋ชจ๋ฆฌ ์•ก์„ธ์Šค mod_exp ์‚ฌ์šฉ
    ๋”ฐ๋ผ์„œ ๊ฐœ์ธ ํ‚ค ๋น„ํŠธ๊ฐ€ ์บ์‹œ ์ œ๊ฑฐ์— ์˜ํ•ด ๋ˆ„์ถœ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค(#157631).
  • ์—…์ŠคํŠธ๋ฆผ 0.9.7g์—์„œ ๋ช‡ ๊ฐ€์ง€ ์ถ”๊ฐ€ ์ˆ˜์ •
  • 2005๋…„ 4์›” 27์ผ ์ˆ˜ Tomas Mraz [email protected] 0.9.7f-6
  • ๋žœ๋“œ์—์„œ ์„ ํƒํ•˜๋Š” ๋Œ€์‹  ํˆฌํ‘œ๋ฅผ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค(#128285).
  • Makefile.certificate๊ฐ€ /etc/pki/tls๋ฅผ ๊ฐ€๋ฆฌํ‚ค๋„๋ก ์ˆ˜์ •
  • ASN1์˜ ๊ธฐ๋ณธ ๋ฌธ์ž์—ด ๋งˆ์Šคํฌ๋ฅผ PrintableString+UTF8String์œผ๋กœ ๋ณ€๊ฒฝ
  • ์›” 2005๋…„ 4์›” 25์ผ Joe Orton [email protected] 0.9.7f-5
  • Mozilla CA ๋ฒˆ๋“ค์˜ ๊ฐœ์ •ํŒ 1.37๋กœ ์—…๋ฐ์ดํŠธ
  • 2005๋…„ 4์›” 21์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.7f-4
  • ์ธ์ฆ์„œ๋ฅผ _sysconfdir/pki/tls๋กœ ์ด๋™(#143392)
  • CA ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ _sysconfdir/pki/CA๋กœ ์ด๋™
  • CA ์Šคํฌ๋ฆฝํŠธ์™€ ๊ธฐ๋ณธ ๊ตฌ์„ฑ์„ ํŒจ์น˜ํ•˜์—ฌ
    CA ๋””๋ ‰ํ† ๋ฆฌ
  • 2005๋…„ 4์›” 1์ผ ๊ธˆ์š”์ผ Tomas Mraz [email protected] 0.9.7f-3
  • ์ดˆ๊ธฐํ™”๋˜์ง€ ์•Š์€ ๋ณ€์ˆ˜๋Š” ์ธ๋ผ์ธ์—์„œ ์ž…๋ ฅ์œผ๋กœ ์‚ฌ์šฉํ•˜๋ฉด ์•ˆ ๋ฉ๋‹ˆ๋‹ค.
    ์ง‘ํšŒ
  • x86_64 ์–ด์…ˆ๋ธ”๋ฆฌ๋ฅผ ๋‹ค์‹œ ํ™œ์„ฑํ™”ํ•˜์‹ญ์‹œ์˜ค.
  • 2005๋…„ 3์›” 31์ผ ๋ชฉ Tomas Mraz [email protected] 0.9.7f-2
  • ABI๊ฐ€ ์†์ƒ๋˜์ง€ ์•Š๋„๋ก ia64 ๋ฐ x86_64์— RC4_CHAR๋ฅผ ๋‹ค์‹œ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
  • x86_64์—์„œ ๊นจ์ง„ bignum ์–ด์…ˆ๋ธ”๋ฆฌ ๋น„ํ™œ์„ฑํ™”
  • 2005๋…„ 3์›” 30์ผ ์ˆ˜ Tomas Mraz [email protected] 0.9.7f-1
  • ppc64์—์„œ ์ตœ์ ํ™”๋ฅผ ๋‹ค์‹œ ํ™œ์„ฑํ™”ํ•˜๊ณ  ia64์—์„œ ์–ด์…ˆ๋ธ”๋ฆฌ ์ฝ”๋“œ๋ฅผ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.
  • ์ƒˆ๋กœ์šด ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „์œผ๋กœ ์—…๊ทธ๋ ˆ์ด๋“œ(์†Œ์ด๋ฆ„ ๋ฒ”ํ”„ ํ•„์š” ์—†์Œ)
  • ์Šค๋ ˆ๋“œ ํ…Œ์ŠคํŠธ ๋น„ํ™œ์„ฑํ™” - ๋ฐฑํฌํŠธ๋ฅผ ํ…Œ์ŠคํŠธ ์ค‘์ด์—ˆ์Šต๋‹ˆ๋‹ค.
    RSA ๋ธ”๋ผ์ธ๋“œ - ๋” ์ด์ƒ ํ•„์š”ํ•˜์ง€ ์•Š์Œ
  • ์ผ๋ จ ๋ฒˆํ˜ธ ๋ณ€๊ฒฝ์— ๋Œ€ํ•œ ์ง€์› ์ถ”๊ฐ€
    Makefile.certificate(#151188)
  • ca-bundle.crt๋ฅผ ๊ตฌ์„ฑ ํŒŒ์ผ๋กœ ๋งŒ๋“ญ๋‹ˆ๋‹ค(#118903).
  • 2005๋…„ 3์›” 1์ผ ํ™”์š”์ผ Tomas Mraz [email protected] 0.9.7e-3
  • libcrypto๋Š” libkrb5์— ์˜์กดํ•ด์„œ๋Š” ์•ˆ ๋ฉ๋‹ˆ๋‹ค(#135961).
  • ์›” 2005๋…„ 2์›” 28์ผ Tomas Mraz [email protected] 0.9.7e-2
  • ์žฌ๊ฑดํ•˜๋‹ค
  • ์›” 2005๋…„ 2์›” 28์ผ Tomas Mraz [email protected] 0.9.7e-1
  • ์ƒˆ๋กœ์šด ์—…์ŠคํŠธ๋ฆผ ์†Œ์Šค, ์—…๋ฐ์ดํŠธ๋œ ํŒจ์น˜
  • ํŒจ์น˜๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ ๊ณง ์ถœ์‹œ๋  ABI์™€ ํ˜ธํ™˜๋˜๊ธฐ๋ฅผ ๋ฐ”๋ž๋‹ˆ๋‹ค.
    0.9.7f
  • 2005๋…„ 2์›” 10์ผ ๋ชฉ Tomas Mraz [email protected]
  • Makefile.certificate์—์„œ UTF-8 ๋ฌธ์ž ์ง‘ํ•ฉ ์ง€์›(#134944)
  • BuildPrereq์— cmp ์ถ”๊ฐ€
  • 2005๋…„ 1์›” 27์ผ ๋ชฉ Joe Orton [email protected] 0.9.7a -46
  • Mozilla certdata.txt(๊ฐœ์ •ํŒ 1.32)์—์„œ ์ƒˆ ca-bundle.crt ์ƒ์„ฑ
  • 2004๋…„ 12์›” 23์ผ ๋ชฉ Phil Knirsch [email protected] 0.9.7a -45
  • libica-1.3.4-urandom.patch ํŒจ์น˜ ์ˆ˜์ • ๋ฐ ์—…๋ฐ์ดํŠธ(#122967)
  • 2004๋…„ 11์›” 19์ผ ๊ธˆ์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -44
  • ์žฌ๊ฑดํ•˜๋‹ค
  • 2004๋…„ 11์›” 19์ผ ๊ธˆ์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -43
  • ์žฌ๊ฑดํ•˜๋‹ค
  • 2004๋…„ 11์›” 19์ผ ๊ธˆ์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -42
  • ์žฌ๊ฑดํ•˜๋‹ค
  • 2004๋…„ 11์›” 19์ผ ๊ธˆ์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -41
  • ์—…์ŠคํŠธ๋ฆผ cvs๊ฐ€ ์ˆ˜ํ–‰ํ•œ ๋Œ€๋กœ der_chop์„ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค(CAN-2004-0975, #140040).
  • 2004๋…„ 10์›” 5์ผ ํ™”์š”์ผ Phil Knirsch [email protected] 0.9.7a -40
  • ์ค‘์š”ํ•œ ๋ฒ„๊ทธ์ˆ˜์ •์ด ์žˆ๋Š” ์ตœ์‹  libica ๋ฒ„์ „ ํฌํ•จ
  • 2004๋…„ 6์›” 15์ผ ํ™”์š”์ผ Elliot Lee [email protected]
  • ์žฌ๊ฑด
  • 2004๋…„ 6์›” 14์ผ ์›” Phil Knirsch [email protected] 0.9.7a -38
  • ICA ์—”์ง„ IBM ํŒจ์น˜๋ฅผ ์ตœ์‹  ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „์œผ๋กœ ์—…๋ฐ์ดํŠธํ–ˆ์Šต๋‹ˆ๋‹ค.
  • 2004๋…„ 6์›” 7์ผ ์›” Nalin Dahyabhai [email protected] 0.9.7a -37
  • ์•ŒํŒŒ์—์„œ alpha-gcc ๋Œ€์‹  linux-alpha-gcc์šฉ์œผ๋กœ ๋นŒ๋“œ(Jeff Garzik)
  • 2004๋…„ 5์›” 25์ผ ํ™”์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -36
  • ์ค‘๊ฐ„์—์„œ %{_arch}=i486/i586/i686/athlon ์ผ€์ด์Šค ์ฒ˜๋ฆฌ
    ํ—ค๋”(#124303)
  • 2004๋…„ 3์›” 25์ผ ๋ชฉ Joe Orton [email protected] 0.9.7a -35
  • CAN-2004-0079, CAN-2004-0112์— ๋Œ€ํ•œ ๋ณด์•ˆ ์ˆ˜์ • ์‚ฌํ•ญ ์ถ”๊ฐ€
  • 2004๋…„ 3์›” 16์ผ ํ™”์š”์ผ Phil Knirsch [email protected]
  • libica ํŒŒ์ผ ์‚ฌ์–‘์„ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
  • 2004๋…„ 3์›” 11์ผ ๋ชฉ Nalin Dahyabhai [email protected] 0.9.7a -34
  • ppc/ppc64 ์ •์˜ powerpc / powerpc64 , ppc / ppc64 ์•„๋‹˜, ์ˆ˜์ •
    ์ค‘๊ฐ„ ํ—ค๋”
  • 2004๋…„ 3์›” 10์ผ ์ˆ˜์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -33
  • ์ค‘๊ฐ„์ฒด๋ฅผ ์ถ”๊ฐ€ํ•˜๋‹ค์˜ค๋ฅธ์ชฝ์„ ๊ฐ€๋ฆฌํ‚ค๋Š”
    multilib ์•„์น˜์˜ ์•„์น˜๋ณ„ opensslconf.h
  • 2004๋…„ 3์›” 2์ผ ํ™”์š”์ผ Elliot Lee [email protected]
  • ์žฌ๊ฑด
  • 2004๋…„ 2์›” 26์ผ ๋ชฉ Phil Knirsch [email protected] 0.9.7a -32
  • libica๋ฅผ ์ตœ์‹  ์—…์ŠคํŠธ๋ฆผ ๋ฒ„์ „ 1.3.5๋กœ ์—…๋ฐ์ดํŠธํ–ˆ์Šต๋‹ˆ๋‹ค.
  • 2004๋…„ 2์›” 17์ผ ํ™”์š”์ผ Phil Knirsch [email protected] 0.9.7a -31
  • IBM์—์„œ ์ตœ์‹  ๋ฒ„์ „์œผ๋กœ ICA ์•”ํ˜ธํ™” ์—”์ง„ ํŒจ์น˜๋ฅผ ์—…๋ฐ์ดํŠธํ•˜์‹ญ์‹œ์˜ค.
  • 2004๋…„ 2์›” 13์ผ ๊ธˆ์š”์ผ Elliot Lee [email protected]
  • ์žฌ๊ฑด
  • 2004๋…„ 2์›” 13์ผ ๊ธˆ์š”์ผ Phil Knirsch [email protected] 0.9.7a -29
  • ์žฌ๊ฑด
  • 2004๋…„ 2์›” 11์ผ ์ˆ˜์š”์ผ Phil Knirsch [email protected] 0.9.7a -28
  • ๊ณ ์ • ๋ฆฌ๋น„์นด ๋นŒ๋“œ.
  • 2004๋…„ 2์›” 4์ผ ์ˆ˜์š”์ผ Nalin Dahyabhai [email protected]
  • Linux-on-ARM์šฉ์œผ๋กœ ์ถ”๊ฐ€๋œ ๋งํฌ ํ”Œ๋ž˜๊ทธ์— "-ldl" ์ถ”๊ฐ€(#99313)
  • 2004๋…„ 2์›” 4์ผ ์ˆ˜ Joe Orton [email protected] 0.9.7a -27
  • ์—…๋ฐ์ดํŠธ๋œ ca-bundle.crt: ๋งŒ๋ฃŒ๋œ GeoTrust ๋ฃจํŠธ ์ œ๊ฑฐ, ์ถ”๊ฐ€๋จ
    freessl.com ๋ฃจํŠธ, ์ œ๊ฑฐ trustcenter.de ํด๋ž˜์Šค 0 ๋ฃจํŠธ
  • 2003๋…„ 11์›” 30์ผ ์ผ Tim Waugh [email protected] 0.9.7a -26
  • libssl์— ๋Œ€ํ•œ ๋งํฌ ๋ผ์ธ ์ˆ˜์ •(๋ฒ„๊ทธ #111154).
  • 2003๋…„ 10์›” 24์ผ ๊ธˆ์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -25
  • zlib์— ์˜์กดํ•˜๋Š” -devel ํŒจํ‚ค์ง€์— ๋Œ€ํ•ด zlib-devel์— ์˜์กด์„ฑ์„ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค.
    libssl์— ๋Œ€ํ•ด zlib๋ฅผ ํ™œ์„ฑํ™”ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๊ธฐํ˜ธ(#102962)
  • 2003๋…„ 10์›” 24์ผ ๊ธˆ์š”์ผ Phil Knirsch [email protected] 0.9.7a -24
  • libica์— PRNG ๋Œ€์‹  /dev/urandom์„ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค.
  • icalinux.c์˜ /dev/urandom์— libica-1.3.5 ์ˆ˜์ • ์‚ฌํ•ญ ์ ์šฉ
  • IBM์˜ ์ตœ์‹  ICA ์—”์ง„ ํŒจ์น˜๋ฅผ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค.
  • 2003๋…„ 10์›” 4์ผ ํ†  Nalin Dahyabhai [email protected] 0.9.7a -22.1
  • ์žฌ๊ฑดํ•˜๋‹ค
  • 2003๋…„ 10์›” 1์ผ ์ˆ˜์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -22
  • ์žฌ๊ตฌ์ถ• (22๋Š” ์‹ค์ œ๋กœ ๊ตฌ์ถ•๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค, ์žฌ๋ฏธ์žˆ์ฃ ?)
  • 2003๋…„ 9์›” 30์ผ ํ™”์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -23
  • ppc64์—์„œ ์ตœ์ ํ™” ๋‹ค์‹œ ๋น„ํ™œ์„ฑํ™”
  • 2003๋…„ 9์›” 30์ผ ํ™”์š”์ผ Joe Orton [email protected]
  • CVS์—์„œ 64๋น„ํŠธ ํ”Œ๋žซํผ์šฉ a_mbstr.c ์ˆ˜์ • ์ถ”๊ฐ€
  • 2003๋…„ 9์›” 30์ผ ํ™”์š”์ผ Nalin Dahyabhai [email protected] 0.9.7a -22
  • ์กฐ๋ฆฝ๋œ ๋ชจ๋“ˆ์— ํƒœ๊ทธ๊ฐ€ ์ง€์ •๋˜๋„๋ก RPM_OPT_FLAGS์— -Wa,--noexecstack ์ถ”๊ฐ€
    ์‹คํ–‰ ๊ฐ€๋Šฅํ•œ ์Šคํƒ์ด ํ•„์š”ํ•˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์—
  • ์›” 2003๋…„ 9์›” 29์ผ Nalin Dahyabhai [email protected] 0.9.7a -21
  • ์žฌ๊ฑดํ•˜๋‹ค
  • 2003๋…„ 9์›” 25์ผ ๋ชฉ Nalin Dahyabhai [email protected]
  • re-enable optimizations on ppc64
  • Thu Sep 25 2003 Nalin Dahyabhai [email protected]
  • remove exclusivearch
  • Wed Sep 24 2003 Nalin Dahyabhai [email protected] 0.9.7a-20
  • only parse a client cert if one was requested
  • temporarily exclusivearch for %{ix86}
  • Tue Sep 23 2003 Nalin Dahyabhai [email protected]
  • add security fixes for protocol parsing bugs (CAN-2003-0543, CAN-2003-0544)
    and heap corruption (CAN-2003-0545)
  • update RHNS-CA-CERT files
  • ease back on the number of threads used in the threading test
  • Wed Sep 17 2003 Matt Wilson [email protected] 0.9.7a-19
  • rebuild to fix gzipped file md5sums (#91211)
  • Mon Aug 25 2003 Phil Knirsch [email protected] 0.9.7a-18
  • Updated libica to version 1.3.4.
  • Thu Jul 17 2003 Nalin Dahyabhai [email protected] 0.9.7a-17
  • rebuild
  • Tue Jul 15 2003 Nalin Dahyabhai [email protected] 0.9.7a-10.9
  • free the kssl_ctx structure when we free an SSL structure (#99066)
  • Fri Jul 11 2003 Nalin Dahyabhai [email protected] 0.9.7a-16
  • rebuild
  • Thu Jul 10 2003 Nalin Dahyabhai [email protected] 0.9.7a-15
  • lower thread test count on s390x
  • Tue Jul 08 2003 Nalin Dahyabhai [email protected] 0.9.7a-14
  • rebuild
  • Thu Jun 26 2003 Nalin Dahyabhai [email protected] 0.9.7a-13
  • disable assembly on arches where it seems to conflict with threading
  • Thu Jun 26 2003 Phil Knirsch [email protected] 0.9.7a-12
  • Updated libica to latest upstream version 1.3.0
  • Wed Jun 11 2003 Nalin Dahyabhai [email protected] 0.9.7a-9.9
  • rebuild
  • Wed Jun 11 2003 Nalin Dahyabhai [email protected] 0.9.7a-11
  • rebuild
  • Tue Jun 10 2003 Nalin Dahyabhai [email protected] 0.9.7a-10
  • ubsec: don't stomp on output data which might also be input data
  • Tue Jun 10 2003 Nalin Dahyabhai [email protected] 0.9.7a-9
  • temporarily disable optimizations on ppc64
  • Mon Jun 09 2003 Nalin Dahyabhai [email protected]
  • backport fix for engine-used-for-everything from 0.9.7b
  • backport fix for prng not being seeded causing problems, also from 0.9.7b
  • add a check at build-time to ensure that RSA is thread-safe
  • keep perlpath from stomping on the libica configure scripts
  • Fri Jun 06 2003 Nalin Dahyabhai [email protected]
  • thread-safety fix for RSA blinding
  • Wed Jun 04 2003 Elliot Lee [email protected] 0.9.7a-8
  • rebuilt
  • Fri May 30 2003 Phil Knirsch [email protected] 0.9.7a-7
  • Added libica-1.2 to openssl (featurerequest).
  • Wed Apr 16 2003 Nalin Dahyabhai [email protected] 0.9.7a-6
  • fix building with incorrect flags on ppc64
  • Wed Mar 19 2003 Nalin Dahyabhai [email protected] 0.9.7a-5
  • add patch to harden against Klima-Pokorny-Rosa extension of Bleichenbacher's
    attack (CAN-2003-0131)
  • Mon Mar 17 2003 Nalin Dahyabhai [email protected] 0.9.7a-4
  • add patch to enable RSA blinding by default, closing a timing attack
    (CAN-2003-0147)
  • Wed Mar 05 2003 Nalin Dahyabhai [email protected] 0.9.7a-3
  • disable use of BN assembly module on x86_64, but continue to allow inline
    assembly (#83403)
  • Thu Feb 27 2003 Nalin Dahyabhai [email protected] 0.9.7a-2
  • disable EC algorithms
  • Wed Feb 19 2003 Nalin Dahyabhai [email protected] 0.9.7a-1
  • update to 0.9.7a
  • Wed Feb 19 2003 Nalin Dahyabhai [email protected] 0.9.7-8
  • add fix to guard against attempts to allocate negative amounts of memory
  • add patch for CAN-2003-0078, fixing a timing attack
  • Thu Feb 13 2003 Elliot Lee [email protected] 0.9.7-7
  • Add openssl-ppc64.patch
  • Mon Feb 10 2003 Nalin Dahyabhai [email protected] 0.9.7-6
  • EVP_DecryptInit should call EVP_CipherInit() instead of EVP_CipherInit_ex(),
    to get the right behavior when passed uninitialized context structures
    (#83766)
  • build with -mcpu=ev5 on alpha family (#83828)
  • Wed Jan 22 2003 Tim Powers [email protected]
  • rebuilt
  • Fri Jan 17 2003 Phil Knirsch [email protected] 0.9.7-4
  • Added IBM hw crypto support patch.
  • Wed Jan 15 2003 Nalin Dahyabhai [email protected]
  • add missing builddep on sed
  • Thu Jan 09 2003 Bill Nottingham [email protected] 0.9.7-3
  • debloat
  • fix broken manpage symlinks
  • Wed Jan 08 2003 Nalin Dahyabhai [email protected] 0.9.7-2
  • fix double-free in 'openssl ca'
  • Fri Jan 03 2003 Nalin Dahyabhai [email protected] 0.9.7-1
  • update to 0.9.7 final
  • Tue Dec 17 2002 Nalin Dahyabhai [email protected] 0.9.7-0
  • update to 0.9.7 beta6 (DO NOT USE UNTIL UPDATED TO FINAL 0.9.7)
  • Wed Dec 11 2002 Nalin Dahyabhai [email protected]
  • update to 0.9.7 beta5 (DO NOT USE UNTIL UPDATED TO FINAL 0.9.7)
  • Tue Oct 22 2002 Nalin Dahyabhai [email protected] 0.9.6b-30
  • add configuration stanza for x86_64 and use it on x86_64
  • build for linux-ppc on ppc
  • start running the self-tests again
  • Wed Oct 02 2002 Elliot Lee [email protected] 0.9.6b-29hammer.3
  • Merge fixes from previous hammer packages, including general x86-64 and
    multilib
  • Tue Aug 06 2002 Nalin Dahyabhai [email protected] 0.9.6b-29
  • rebuild
  • Thu Aug 01 2002 Nalin Dahyabhai [email protected] 0.9.6b-28
  • update asn patch to fix accidental reversal of a logic check
  • Wed Jul 31 2002 Nalin Dahyabhai [email protected] 0.9.6b-27
  • update asn patch to reduce chance that compiler optimization will remove
    one of the added tests
  • Wed Jul 31 2002 Nalin Dahyabhai [email protected] 0.9.6b-26
  • rebuild
  • Mon Jul 29 2002 Nalin Dahyabhai [email protected] 0.9.6b-25
  • add patch to fix ASN.1 vulnerabilities
  • Thu Jul 25 2002 Nalin Dahyabhai [email protected] 0.9.6b-24
  • add backport of Ben Laurie's patches for OpenSSL 0.9.6d
  • Wed Jul 17 2002 Nalin Dahyabhai [email protected] 0.9.6b-23
  • own {_datadir}/ssl/misc
  • Fri Jun 21 2002 Tim Powers [email protected]
  • automated rebuild
  • Sun May 26 2002 Tim Powers [email protected]
  • automated rebuild
  • Fri May 17 2002 Nalin Dahyabhai [email protected] 0.9.6b-20
  • free ride through the build system (whee!)
  • Thu May 16 2002 Nalin Dahyabhai [email protected] 0.9.6b-19
  • rebuild in new environment
  • Thu Apr 04 2002 Nalin Dahyabhai [email protected] 0.9.6b-17, 0.9.6b-18
  • merge RHL-specific bits into stronghold package, rename
  • Tue Apr 02 2002 Gary Benson [email protected] stronghold-0.9.6c-2
  • add support for Chrysalis Luna token
  • Tue Mar 26 2002 Gary Benson [email protected]
  • disable AEP random number generation, other AEP fixes
  • Fri Mar 15 2002 Nalin Dahyabhai [email protected] 0.9.6b-15
  • only build subpackages on primary arches
  • Thu Mar 14 2002 Nalin Dahyabhai [email protected] 0.9.6b-13
  • on ia32, only disable use of assembler on i386
  • enable assembly on ia64
  • Mon Jan 07 2002 Florian La Roche Florian. [email protected] 0.9.6b-11
  • fix sparcv9 entry
  • Mon Jan 07 2002 Gary Benson [email protected] stronghold-0.9.6c-1
  • upgrade to 0.9.6c
  • bump BuildArch to i686 and enable assembler on all platforms
  • synchronise with shrimpy and rawhide
  • bump soversion to 3
  • Wed Oct 10 2001 Florian La Roche Florian. [email protected]
  • delete BN_LLONG for s390x, patch from Oliver Paukstadt
  • Mon Sep 17 2001 Nalin Dahyabhai [email protected] 0.9.6b-9
  • update AEP driver patch
  • Mon Sep 10 2001 Nalin Dahyabhai [email protected]
  • adjust RNG disabling patch to match version of patch from Broadcom
  • Fri Sep 07 2001 Nalin Dahyabhai [email protected] 0.9.6b-8
  • disable the RNG in the ubsec engine driver
  • Tue Aug 28 2001 Nalin Dahyabhai [email protected] 0.9.6b-7
  • tweaks to the ubsec engine driver
  • Fri Aug 24 2001 Nalin Dahyabhai [email protected] 0.9.6b-6
  • tweaks to the ubsec engine driver
  • Thu Aug 23 2001 Nalin Dahyabhai [email protected] 0.9.6b-5
  • update ubsec engine driver from Broadcom
  • Fri Aug 10 2001 Nalin Dahyabhai [email protected] 0.9.6b-4
  • move man pages back to %{_mandir}/man?/foo.?ssl from
    %{_mandir}/man?ssl/foo.?
  • add an [ engine ] section to the default configuration file
  • Thu Aug 09 2001 Nalin Dahyabhai [email protected]
  • add a patch for selecting a default engine in SSL_library_init()
  • Mon Jul 23 2001 Nalin Dahyabhai [email protected] 0.9.6b-3
  • add patches for AEP hardware support
  • add patch to keep trying when we fail to load a cert from a file and
    there are more in the file
  • add missing prototype for ENGINE_ubsec() in engine_int.h
  • Wed Jul 18 2001 Nalin Dahyabhai [email protected] 0.9.6b-2
  • actually add hw_ubsec to the engine list
  • Tue Jul 17 2001 Nalin Dahyabhai [email protected]
  • add in the hw_ubsec driver from CVS
  • Wed Jul 11 2001 Nalin Dahyabhai [email protected] 0.9.6b-1
  • update to 0.9.6b
  • Thu Jul 05 2001 Nalin Dahyabhai [email protected]
  • move .so symlinks back to %{_libdir}
  • Tue Jul 03 2001 Nalin Dahyabhai [email protected]
  • move shared libraries to /lib (#38410)
  • Mon Jun 25 2001 Nalin Dahyabhai [email protected]
  • switch to engine code base
  • Mon Jun 18 2001 Nalin Dahyabhai [email protected]
  • add a script for creating dummy certificates
  • move man pages from %{_mandir}/man?/foo.?ssl to %{_mandir}/man?ssl/foo.?
  • Thu Jun 07 2001 Florian La Roche Florian. [email protected]
  • add s390x support
  • Fri Jun 01 2001 Nalin Dahyabhai [email protected]
  • change two memcpy() calls to memmove()
  • don't define L_ENDIAN on alpha
  • Wed May 23 2001 Joe Orton [email protected] stronghold-0.9.6a-1
  • Add 'stronghold-' prefix to package names.
  • Obsolete standard openssl packages.
  • Wed May 16 2001 Joe Orton [email protected]
  • Add BuildArch: i586 as per Nalin's advice.
  • Tue May 15 2001 Joe Orton [email protected]
  • Enable assembler on ix86 (using new .tar.bz2 which does
    include the asm directories).
  • Tue May 15 2001 Nalin Dahyabhai [email protected]
  • make subpackages depend on the main package
  • Tue May 01 2001 Nalin Dahyabhai [email protected]
  • adjust the hobble script to not disturb symlinks in include/ (fix from
    Joe Orton)
  • Fri Apr 27 2001 Nalin Dahyabhai [email protected]
  • drop the m2crypo patch we weren't using
  • Tue Apr 24 2001 Nalin Dahyabhai [email protected]
  • configure using "shared" as well
  • Sun Apr 08 2001 Nalin Dahyabhai [email protected]
  • update to 0.9.6a
  • use the build-shared target to build shared libraries
  • bump the soversion to 2 because we're no longer compatible with
    our 0.9.5a packages or our 0.9.6 packages
  • drop the patch for making rsatest a no-op when rsa null support is used
  • put all man pages into
    ssl instead of
  • break the m2crypto modules into a separate package
  • Tue Mar 13 2001 Nalin Dahyabhai [email protected]
  • use BN_LLONG on s390
  • Mon Mar 12 2001 Nalin Dahyabhai [email protected]
  • fix the s390 changes for 0.9.6 (isn't supposed to be marked as 64-bit)
  • Sat Mar 03 2001 Nalin Dahyabhai [email protected]
  • move c_rehash to the perl subpackage, because it's a perl script now
  • Fri Mar 02 2001 Nalin Dahyabhai [email protected]
  • update to 0.9.6
  • enable MD2
  • use the libcrypto.so and libssl.so targets to build shared libs with
  • bump the soversion to 1 because we're no longer compatible with any of
    the various 0.9.5a packages circulating around, which provide lib*.so.0
  • Wed Feb 28 2001 Florian La Roche Florian. [email protected]
  • change hobble-openssl for disabling MD2 again
  • Tue Feb 27 2001 Nalin Dahyabhai [email protected]
  • re-disable MD2 -- the EVP_MD_CTX structure would grow from 100 to 152
    bytes or so, causing EVP_DigestInit() to zero out stack variables in
    apps built against a version of the library without it
  • Mon Feb 26 2001 Nalin Dahyabhai [email protected]
  • disable some inline assembly, which on x86 is Pentium-specific
  • re-enable MD2 (see http://www.ietf.org/ietf/IPR/RSA-MD-all)
  • Thu Feb 08 2001 Florian La Roche Florian. [email protected]
  • fix s390 patch
  • Fri Dec 08 2000 Than Ngo [email protected]
  • added support s390
  • Mon Nov 20 2000 Nalin Dahyabhai [email protected]
  • remove -Wa,* and -m* compiler flags from the default Configure file (#20656)
  • add the CA.pl man page to the perl subpackage
  • Thu Nov 02 2000 Nalin Dahyabhai [email protected]
  • always build with -mcpu=ev5 on alpha
  • Tue Oct 31 2000 Nalin Dahyabhai [email protected]
  • add a symlink from cert.pem to ca-bundle.crt
  • Wed Oct 25 2000 Nalin Dahyabhai [email protected]
  • add a ca-bundle file for packages like Samba to reference for CA certificates
  • Tue Oct 24 2000 Nalin Dahyabhai [email protected]
  • remove libcrypto's crypt(), which doesn't handle md5crypt (#19295)
  • Mon Oct 02 2000 Nalin Dahyabhai [email protected]
  • add unzip as a buildprereq (#17662)
  • update m2crypto to 0.05-snap4
  • Tue Sep 26 2000 Bill Nottingham [email protected]
  • fix some issues in building when it's not installed
  • Wed Sep 06 2000 Nalin Dahyabhai [email protected]
  • make sure the headers we include are the ones we built with (aaaaarrgh!)
  • Fri Sep 01 2000 Nalin Dahyabhai [email protected]
  • add Richard Henderson's patch for BN on ia64
  • clean up the changelog
  • Tue Aug 29 2000 Nalin Dahyabhai [email protected]
  • fix the building of python modules without openssl-devel already installed
  • Wed Aug 23 2000 Nalin Dahyabhai [email protected]
  • byte-compile python extensions without the build-root
  • adjust the makefile to not remove temporary files (like .key files when
    building .csr files) by marking them as .PRECIOUS
  • Sat Aug 19 2000 Nalin Dahyabhai [email protected]
  • break out python extensions into a subpackage
  • Mon Jul 17 2000 Nalin Dahyabhai [email protected]
  • tweak the makefile some more
  • Tue Jul 11 2000 Nalin Dahyabhai [email protected]
  • disable MD2 support
  • Thu Jul 06 2000 Nalin Dahyabhai [email protected]
  • disable MDC2 support
  • Sun Jul 02 2000 Nalin Dahyabhai [email protected]
  • tweak the disabling of RC5, IDEA support
  • tweak the makefile
  • Thu Jun 29 2000 Nalin Dahyabhai [email protected]
  • strip binaries and libraries
  • rework certificate makefile to have the right parts for Apache
  • Wed Jun 28 2000 Nalin Dahyabhai [email protected]
  • use %{_perl} instead of /usr/bin/perl
  • disable alpha until it passes its own test suite
  • Fri Jun 09 2000 Nalin Dahyabhai [email protected]
  • move the passwd.1 man page out of the passwd package's way
  • Fri Jun 02 2000 Nalin Dahyabhai [email protected]
  • update to 0.9.5a, modified for US
  • add perl as a build-time requirement
  • move certificate makefile to another package
  • disable RC5, IDEA, RSA support
  • remove optimizations for now
  • Wed Mar 01 2000 Florian La Roche Florian. [email protected]
  • Bero told me to move the Makefile into this package
  • Wed Mar 01 2000 Florian La Roche Florian. [email protected]
  • add lib*.so symlinks to link dynamically against shared libs
  • Tue Feb 29 2000 Florian La Roche Florian. [email protected]
  • update to 0.9.5
  • run ldconfig directly in post/postun
  • add FAQ
  • Sat Dec 18 1999 Bernhard Rosenkrdnzer [email protected]
  • Fix build on non-x86 platforms
  • Fri Nov 12 1999 Bernhard Rosenkrdnzer [email protected]
  • move /usr/share/ssl/* from -devel to main package
  • Tue Oct 26 1999 Bernhard Rosenkrdnzer [email protected]
  • inital packaging
  • changes from base:

    • Move /usr/local/ssl to /usr/share/ssl for FHS compliance

    • handle RPM_OPT_FLAGS

@Lekinho ๊ฐ€ github ๊ณ„์ •์„ ์‚ญ์ œํ•œ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๊นŒ? ๋ฌธ์ œ๊ฐ€ ์žˆ๋Š” ๋‹ค์Œ ์‚ฌ๋žŒ์˜ ๊ฒฝ์šฐ OpenSsl ๋˜๋Š” Python ์—…๊ทธ๋ ˆ์ด๋“œ๋กœ ์ธํ•ด ์ผ๋ถ€ ์ปดํŒŒ์ผ๋œ c ๋ฐ”์ธ๋”ฉ์ด ์†์ƒ๋˜์—ˆ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ์—…๊ทธ๋ ˆ์ด๋“œ๊ฐ€ ์žˆ์„ ๋•Œ๋งˆ๋‹ค virtualenv ๋˜๋Š” ๋ชจ๋“  ํŒจํ‚ค์ง€๋ฅผ ํ๊ธฐํ•œ ๋‹ค์Œ ์ƒˆ ํŒจํ‚ค์ง€๋ฅผ ๋นŒ๋“œํ•ฉ๋‹ˆ๋‹ค.

@jvanasco ์•„์ง ์—ฌ๊ธฐ ์žˆ์–ด์š”.
๋‚˜๋Š” ์ด๊ฒƒ์„ ํ…Œ์ŠคํŠธํ•  ์ˆ˜ ์žˆ๋Š” ๊ณต๊ฐœ URL์ด ์žˆ๋Š”์ง€ ๊ถ๊ธˆํ•ฉ๋‹ˆ๋‹ค. ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์ด ์‹ค์ œ๋กœ ํ™•์ธ๋œ ์‚ฌ๋ก€์— ๋Œ€ํ•œ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๋Š”์ง€ ํ™•์ธํ•˜๊ณ  ์‹ถ์Šต๋‹ˆ๋‹ค(์ด๋Š” ๋‚ด๊ฐ€ ์‹œ๋„ํ•˜๋Š” ๋™์•ˆ ๋ญ”๊ฐ€๋ฅผ ๋ง์น˜์ง€ ์•Š์•˜์Œ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค)

@๋ฃจ์นด์‚ฌ

์ž‘์—… ๋ฒ„์ „๊ณผ ์—…๋ฐ์ดํŠธ๋œ ๋ฒ„์ „ ๊ฐ„์˜ ๋ณ€๊ฒฝ ์ง‘ํ•ฉ์˜ ํ•˜์œ„ ์ง‘ํ•ฉ:+1:
2016๋…„ 5์›” 2์ผ ์›”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-48.1
CVE-2016-2105 ์ˆ˜์ • - base64 ์ธ์ฝ”๋”ฉ์—์„œ ๊ฐ€๋Šฅํ•œ ์˜ค๋ฒ„ํ”Œ๋กœ
CVE-2016-2106 ์ˆ˜์ • - EVP_EncryptUpdate()์—์„œ ๊ฐ€๋Šฅํ•œ ์˜ค๋ฒ„ํ”Œ๋กœ
CVE-2016-2107 ์ˆ˜์ • - ์Šคํ‹ฐ์น˜๋œ AES-NI CBC-MAC์˜ ํŒจ๋”ฉ ์˜ค๋ผํด
CVE-2016-2108 ์ˆ˜์ • - ASN.1 ์ธ์ฝ”๋”์˜ ๋ฉ”๋ชจ๋ฆฌ ์†์ƒ
CVE-2016-2109 ์ˆ˜์ • - BIO์—์„œ ASN.1 ๋ฐ์ดํ„ฐ๋ฅผ ์ฝ์„ ๋•Œ DoS ๊ฐ€๋Šฅ
CVE-2016-0799 ์ˆ˜์ • - BIO_printf์˜ ๋ฉ”๋ชจ๋ฆฌ ๋ฌธ์ œ

2016๋…„ 2์›” 24์ผ ์ˆ˜์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-48

CVE-2016-0702 ์ˆ˜์ • - ๋ชจ๋“ˆ์‹ ์ง€์ˆ˜์— ๋Œ€ํ•œ ๋ถ€์ฑ„๋„ ๊ณต๊ฒฉ
CVE-2016-0705 ์ˆ˜์ • - DSA ๊ฐœ์ธ ํ‚ค ๊ตฌ๋ฌธ ๋ถ„์„์—์„œ ์ด์ค‘ ๋ฌด๋ฃŒ
CVE-2016-0797 ์ˆ˜์ • - BN_hex2bn ๋ฐ BN_dec2bn์˜ ํž™ ์†์ƒ

2016๋…„ 2์›” 16์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-47

CVE-2015-3197 ์ˆ˜์ • - SSLv2 ์•”ํ˜ธ ์ œํ’ˆ๊ตฐ ์‹œํ–‰
์ผ๋ฐ˜ TLS ๋ฐฉ๋ฒ•์—์„œ SSLv2 ๋น„ํ™œ์„ฑํ™”

2016๋…„ 1์›” 15์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-46

pkcs12 ๊ตฌ๋ฌธ ๋ถ„์„์—์„œ 1๋ฐ”์ดํŠธ ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜ ์ˆ˜์ •(#1229871)
์†๋„ ๋ช…๋ น์˜ ์ผ๋ถ€ ์˜ต์…˜ ๋ฌธ์„œํ™”(#1197095)

2016๋…„ 1์›” 14์ผ ๋ชฉ Tomรกลก Mrรกz [email protected] 1.0.1e-45

ํƒ€์ž„์Šคํƒฌํ”„ ๊ธฐ๊ด€์—์„œ ๊ณ ์ •๋ฐ€ ํƒ€์ž„์Šคํƒฌํ”„ ์ˆ˜์ •

2015๋…„ 12์›” 21์ผ ์›” Tomรกลก Mrรกz [email protected] 1.0.1e-44

CVE-2015-7575 ์ˆ˜์ • - TLS1.2์—์„œ MD5 ์‚ฌ์šฉ ๊ธˆ์ง€

2015๋…„ 12์›” 4์ผ ๊ธˆ์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-43

CVE-2015-3194 ์ˆ˜์ • - PSS ๋งค๊ฐœ๋ณ€์ˆ˜๊ฐ€ ๋ˆ„๋ฝ๋œ ์ธ์ฆ์„œ ํ™•์ธ ์ถฉ๋Œ
CVE-2015-3195 - X509_ATTRIBUTE ๋ฉ”๋ชจ๋ฆฌ ๋ˆ„์ˆ˜ ์ˆ˜์ •
CVE-2015-3196 ์ˆ˜์ • - PSK ID ํžŒํŠธ ์ฒ˜๋ฆฌ ์‹œ ๊ฒฝ์Ÿ ์กฐ๊ฑด

2015๋…„ 6์›” 23์ผ ํ™”์š”์ผ Tomรกลก Mrรกz [email protected] 1.0.1e-42

์—…๋ฐ์ดํŠธ :
๊ทธ๋ž˜์„œ ์ด๊ฒƒ์— ๋Œ€ํ•œ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์„ ์ฐพ์•˜์Šต๋‹ˆ๋‹ค.
๊ธฐ๋ณธ์ ์œผ๋กœ ํ•œ ๋™๋ฃŒ๊ฐ€ ์ด ๋ฌธ์ œ๋ฅผ ์ฝ๊ณ  ์žˆ์—ˆ๊ณ  ์–ด๋–ค ์ด์œ ๋กœ๋“  ECC/ECDH ์•”ํ˜ธ์— ๋Œ€ํ•œ RHEL openssl ์ง€์›์ด 100%๊ฐ€ ์•„๋‹ˆ๋ผ๋Š” ๊ฒŒ์‹œ๋ฌผ์„ ๋ณด์•˜์Šต๋‹ˆ๋‹ค.

๋ช…์‹œ์ ์œผ๋กœ ECDH ์•”ํ˜ธ๋ฅผ ๋น„ํ™œ์„ฑํ™”ํ•˜์—ฌ URL์— ๋Œ€ํ•œ ์š”์ฒญ์„ ์‹œ๋„ํ–ˆ์Šต๋‹ˆ๋‹ค(openssl ์Šคํฌ๋ฆฝํŠธ ์ž์ฒด์˜ ๋ถ€์ • ์ถ”๊ฐ€, ์ฆ‰ openssl s_client -connect 10.85.103.218:8443 -cipher 'DEFAULT:!ECDH')

์„ฑ๊ณต์ ์œผ๋กœ ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

๋‹ค์Œ์€ ์šฐ๋ถ„ํˆฌ 14.04์˜ openssl์— ๋Œ€ํ•œ ๊ธฐ๋ณธ ์•”ํ˜ธ ๋ชฉ๋ก์ž…๋‹ˆ๋‹ค.
ECDH+ AESGCM:DH+AESGCM :ECDH+AES256:DH+AES256:ECDH+AES128:DH+ AES:ECDH+HIGH :DH+ HIGH:ECDH+3DES :DH+3 DES:RSA+AESGCM :RSA+ AES:RSA+HIGH :RSA +3DES:!aNULL:!eNULL:!MD5

๊ทธ๋ž˜์„œ ๊ทธ ์ง€์‹์œผ๋กœ pyopenssl์„ ์‚ฌ์šฉํ•˜์—ฌ ๊ธฐ๋ณธ SSL ์•”ํ˜ธ๋ฅผ ์ธ์‡„ํ•˜๊ณ  ๋ฌธ์ž์—ด์—์„œ ๋ชจ๋“  ECDH ์•”ํ˜ธ๋ฅผ ๋ช…์‹œ์ ์œผ๋กœ ์ œ๊ฑฐํ–ˆ์Šต๋‹ˆ๋‹ค. ์š”์ฒญ ํŒจํ‚ค์ง€์—์„œ urllib3์„ ๊ฐ€์ ธ์˜ค๊ธฐ ์œ„ํ•ด ๋ธ”๋ก์—์„œ ์ด ์ž‘์—…์„ ์ˆ˜ํ–‰ํ–ˆ์Šต๋‹ˆ๊นŒ(์ฆ‰, ์‹ค์ œ ์š”์ฒญ์„ ์‹œ์ž‘ํ•˜๊ธฐ ์ „์—) ๋‹ค์Œ๊ณผ ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค.
https://github.com/kennethreitz/requests/issues/1308

๋‚˜๋Š” ์ด ํ–‰๋™์— ๋ณด์•ˆ ์œ„ํ—˜์ด ์žˆ์„ ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ๊ณ  ์žˆ์ง€๋งŒ ์ ์–ด๋„ ์ด๊ฒƒ์€ ์šฐ๋ฆฌ๋ฅผ ์›€์ง์ด๊ฒŒ ํ•˜๊ณ  ๋” ๋งŽ์€ ๋น›์„ ๋น„์ถฐ์ค๋‹ˆ๋‹ค.

์ด๋Ÿฌํ•œ ํŠน์ • ์•”ํ˜ธ๊ฐ€ RHEL์— ๋ฌธ์ œ๋กœ ๋‚˜ํƒ€๋‚˜๋Š” ์ด์œ ๋Š” ์ž˜ ๋ชจ๋ฅด๊ฒ ์Šต๋‹ˆ๋‹ค.

ํŠน์ • RHEL ๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ์ด๋ฅผ ๋„์ž…ํ–ˆ๋Š”์ง€ ํ™•์ธํ•˜๊ณ  ๋ชฉ์ ์— ๋Œ€ํ•ด ๋” ์ฝ์„ ์ˆ˜ ์žˆ๋Š” ์‹œ๊ฐ„์ด ๋” ์žˆ์„ ๋•Œ ์‹œ๋„ํ•  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

๋ˆ„๊ตฌ๋‚˜ ์ผ๋ฐ˜์ ์œผ๋กœ ์•”ํ˜ธ์— ๋Œ€ํ•ด ๋” ๋งŽ์ด ์•Œ๊ณ  ์žˆ์Šต๋‹ˆ๊นŒ?

๊ฐ™์€ ๋ฌธ์ œ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค ... ARG ...

@lukas-gitl ์ขŒ์ ˆ์€ ๋ฌธ์ œ ํ•ด๊ฒฐ์— ๋„์›€์ด ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ท€ํ•˜์˜ ํ™˜๊ฒฝ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•˜๋Š” ๊ฒƒ์ด ๋„์›€์ด ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

@sigmavirus24 ์‚ฌ๊ณผ๋“œ๋ฆฝ๋‹ˆ๋‹ค. ๋” ๋งŽ์€ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•˜๊ณ  ์‹ถ์—ˆ์ง€๋งŒ (์‹œ๊ฐ„์ด ์—†์—ˆ๊ธฐ ๋•Œ๋ฌธ์—) ๋ถ€์ˆ˜์ ์ธ ์ถ”์ ์„ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค. ์ €๋Š” Ubuntu 14.04, python 2.7.6 ๋ฐ pip์—์„œ ์ตœ์‹  ์š”์ฒญ ๋ฒ„์ „์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ API Gateway ์—”๋“œํฌ์ธํŠธ๋กœ ์•ก์„ธ์Šคํ•˜๋ ค๊ณ  ํ•  ๋•Œ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค(๋งค์šฐ ์ œํ•œ์ ์ผ ์ˆ˜ ์žˆ์Œ).

virtualenv๋ฅผ ์ œ๊ฑฐํ•˜๊ณ  ์žฌ์ƒ์„ฑ์„ ์‹œ๋„ํ–ˆ์ง€๋งŒ ๋ถˆํ–‰ํžˆ๋„ ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค.

๊ทธ ๋ฐ–์— ๋ฌด์—‡์ด ํ•„์š”ํ•œ์ง€ ์•Œ๋ ค์ฃผ์‹ญ์‹œ์˜ค. ํ•œ๋™์•ˆ nodejs๋กœ ์ „ํ™˜ํ–ˆ์ง€๋งŒ ํ•ด๊ฒฐ์— ๋„์›€์ด ๋˜์—ˆ์œผ๋ฉด ํ•ฉ๋‹ˆ๋‹ค.

@lukas-gitl ์—ฐ๊ฒฐํ•˜๋ ค๋Š” ์„œ๋ฒ„์— ์ œ๊ณตํ•˜์ง€ ์•Š๋Š” ์•”ํ˜ธ ๋˜๋Š” ์ œ๊ณตํ•˜์ง€ ์•Š๋Š” TLS ๋ฒ„์ „์ด ํ•„์š”ํ•  ๊ฐ€๋Šฅ์„ฑ์ด ํฝ๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ ์„ค์น˜ํ•œ OpenSSL๊ณผ ๊ด€๋ จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. pip install requests[security] ์‹คํ–‰๋„ ์‹œ๋„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. SNI์— ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์˜ˆ, ์ €๋„ ์ด๋ฏธ ์‹œ๋„ํ–ˆ์Šต๋‹ˆ๋‹ค. ์šฐ๋ฆฌ๊ฐ€ ๊ฐ™์€ ํŽ˜์ด์ง€์— ์žˆ๋„๋ก ๋น ๋ฅธ ํ…Œ์ŠคํŠธ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์—ฌ๊ธฐ์— ํ•จ๊ป˜ ๋„ฃ์–ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค.

๊ฐ€์ƒ ํ™˜๊ฒฝ -p /usr/bin/python2.7 ํ™˜๊ฒฝ
์†Œ์Šค ํ™˜๊ฒฝ/๋นˆ/ํ™œ์„ฑํ™”
ํ• ์„ค์น˜ ์š”์ฒญ
pip ์„ค์น˜ ์š”์ฒญ[๋ณด์•ˆ]
echo '์š”์ฒญ ๊ฐ€์ ธ์˜ค๊ธฐ' >> test.py
echo 'requests.get("https://API_ID.execute-api.us-west-2.amazonaws.com/ENV/ENPOINT")' >> test.py
ํŒŒ์ด์ฌ test.py

๊ทธ๋ฆฌ๊ณ  ์–ด๋–ค ํŠน์ • ์˜ค๋ฅ˜๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๊นŒ?

.../env/local/lib/python2.7/site-packages/requests/packages/urllib3/util/ssl_.py:318: SNIMissingWarning: An HTTPS request has been made, but the SNI (Subject Name Indication) extension to TLS is not available on this platform. This may cause the server to present an incorrect TLS certificate, which can cause validation failures. You can upgrade to a newer version of Python to solve this. For more information, see https://urllib3.readthedocs.org/en/latest/security.html#snimissingwarning. SNIMissingWarning .../env/local/lib/python2.7/site-packages/requests/packages/urllib3/util/ssl_.py:122: InsecurePlatformWarning: A true SSLContext object is not available. This prevents urllib3 from configuring SSL appropriately and may cause certain SSL connections to fail. You can upgrade to a newer version of Python to solve this. For more information, see https://urllib3.readthedocs.org/en/latest/security.html#insecureplatformwarning. InsecurePlatformWarning Traceback (most recent call last): File "test.py", line 2, in <module> requests.get("https://sbsz8eqowe.execute-api.us-west-2.amazonaws.com/dev/segment_to_s3_webhook") File ".../env/local/lib/python2.7/site-packages/requests/api.py", line 71, in get return request('get', url, params=params, **kwargs) File ".../env/local/lib/python2.7/site-packages/requests/api.py", line 57, in request return session.request(method=method, url=url, **kwargs) File ".../env/local/lib/python2.7/site-packages/requests/sessions.py", line 475, in request resp = self.send(prep, **send_kwargs) File ".../env/local/lib/python2.7/site-packages/requests/sessions.py", line 585, in send r = adapter.send(request, **kwargs) File ".../env/local/lib/python2.7/site-packages/requests/adapters.py", line 477, in send raise SSLError(e, request=request) requests.exceptions.SSLError: [Errno 1] _ssl.c:510: error:14077410:SSL routines:SSL23_GET_SERVER_HELLO:sslv3 alert handshake failure```

๊ทธ๋ž˜์„œ ๊ธฐ๋ณธ์ ์œผ๋กœ ์ตœ์‹  ๋ฒ„์ „์˜ Python์œผ๋กœ ์—…๋ฐ์ดํŠธํ•ด์•ผ ํ•ฉ๋‹ˆ๊นŒ?

์ข‹์Šต๋‹ˆ๋‹ค. ๋‘ ๊ฒฝ๊ณ  ๋ชจ๋‘ ๊ท€ํ•˜์˜ ์š”์ฒญ์ด ์‹ค์ œ๋กœ requests[security]์˜ ํ™•์žฅ์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์ง€ ์•Š์Œ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ์‹คํ–‰ ์ค‘์ธ Python์ด ๊ฐ€์ƒ ํ™˜๊ฒฝ์— ์„ค์น˜ํ•œ Python์ด _์•„๋‹˜_์ด ์•„๋‹˜์„ ๊ฐ•๋ ฅํžˆ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค. requests[security] ํ™•์žฅ์€ ์ด๋Ÿฌํ•œ ๊ฒฝ๊ณ ๋ฅผ ์ œ๊ฑฐํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

@lukas-gitl ์œ„์˜ ๋‚ด ๋ฉ”๋ชจ๋ฅผ ์ฐธ์กฐํ•˜์‹ญ์‹œ์˜ค.
์„œ๋ฒ„์— ์•ก์„ธ์Šคํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ? ์„œ๋ฒ„์™€ ํด๋ผ์ด์–ธํŠธ์— ๋Œ€ํ•œ ๊ธฐ๋ณธ ์•”ํ˜ธ ๋ชฉ๋ก์„ ๋น„๊ตํ•ฉ๋‹ˆ๋‹ค.
๊ทธ๋“ค ์ค‘ ํ•˜๋‚˜๊ฐ€ ๋‹ค๋ฅธ ํ•˜๋‚˜์˜ ์ฒซ ๋ฒˆ์งธ ์•”ํ˜ธ ์„ธํŠธ๋ฅผ ์ง€์›ํ•˜์ง€ ์•Š์„ ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์œผ๋ฏ€๋กœ ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

์—ฌ๊ธฐ์—์„œ ์‚ฌ์šฉํ•œ ๊ฒƒ๊ณผ ๊ฐ™์€ ๊ฐ„๋‹จํ•œ ์Šคํฌ๋ฆฝํŠธ๋กœ ๊ธฐ๋ณธ ์•”ํ˜ธ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

!/usr/bin/python

์ˆ˜์ž… ์‹œ์Šคํ…œ
์ˆ˜์ž… OS
SSL ๊ฐ€์ ธ์˜ค๊ธฐ
์ธ์‡„(ssl.OPENSSL_VERSION)
sys.path.insert(1, os.path.abspath(os.path.join(os.getcwd(), 'lib')))
sys.path.append('/usr/local/lib/python2.7/dist-packages')
๊ฐ€์ ธ์˜ค๊ธฐ ์š”์ฒญ
requests.packages.urllib3.contrib์—์„œ pyopenssl ๊ฐ€์ ธ์˜ค๊ธฐ
pyopenssl.inject_into_urllib3()
pyopenssl.DEFAULT_SSL_CIPHER_LIST ์ธ์‡„

์ž, ์ด์ œ ์ •๋ง ํ˜ผ๋ž€์Šค๋Ÿฝ์Šต๋‹ˆ๋‹ค. ๊ฐ€์ƒ ํ™˜๊ฒฝ์—์„œ ์˜ค๋ฅ˜ ๋ฉ”์‹œ์ง€๊ฐ€ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ํŒŒ์ด์ฌ ํ™˜๊ฒฝ์—์„œ ์‹คํ–‰ํ•˜๋Š” ๋™์•ˆ ์–ด๋–ป๊ฒŒ ๊ฑฐ๊ธฐ์—์„œ ์˜ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?

๊ทธ๋ž˜์„œ $ pip install requests[security] pip install pyopenssl ndg-httpsclient pyasn1 ๋ฅผ ์‹œ๋„ํ–ˆ๋Š”๋ฐ ํšจ๊ณผ๊ฐ€ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค...

์•„ํ•˜, ๊ท€ํ•˜์˜ ํ•์ด ์—‘์ŠคํŠธ๋ผ๋ฅผ ์ฒ˜๋ฆฌํ•˜๊ธฐ์—๋Š” ๋„ˆ๋ฌด ์˜ค๋ž˜๋œ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค.

์•„, ์  ์žฅ. ๊ทธ๊ฒƒ์€ ๋งŽ์€ ๊ฒƒ์„ ์„ค๋ช…ํ•ฉ๋‹ˆ๋‹ค. ๋‹น์‹ ์˜ ๋„์›€์„ ์ฃผ์…”์„œ ๋Œ€๋‹จํžˆ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค!

์—ฌ๊ธฐ์„œ ๋™์ผํ•œ ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ ์ฝ”๋“œ๋กœ GET ์š”์ฒญ์„ ๋ณด๋‚ด์•ผ ํ–ˆ์Šต๋‹ˆ๋‹ค.
requests.get('https://mdskip.taobao.com/core/initItemDetail.htm?itemId=530444505608&showShopProm=false&queryMemberRight=true&isRegionLevel=false&tmallBuySupport=true&addressLevel=2&sellerPreview=false&isForbidBuyItem=false&cachedTimestamp=1466835924196&offlineShop=false&household=false&tryBeforeBuy=false&isSecKill=false&service3C=false&isApparel=true&isUseInventoryCenter=false&cartEnable=true&isAreaSell=false&callback=setMdskip&timestamp=1466841669969&isg=Al9faN3XWRpIf6UEoQ88UH/1b7np0rNm&ref=https%3A%2F%2Fs.taobao.com%2Fsearch%3Fq%3D%25E6%258B%2589%25E5%25A4%258F%25E8%25B4%259D%25E5%25B0%2594%26imgfile%3D%26commend%3Dall%26ssid%3Ds5-e%26search_type%3Ditem%26sourceId%3Dtb.index%26spm%3Da21bo.50862.201856-taobao-item.1%26ie%3Dutf8%26initiative_id%3Dtbindexz_20160625')

๋ถˆํ–‰ํžˆ๋„ ๋‚˜๋Š” ์˜ค๋ฅ˜ ์ •๋ณด๋ฅผ ๋ฐ›์•˜์Šต๋‹ˆ๋‹ค:
Traceback (most recent call last): File "<stdin>", line 1, in <module> File "/Library/Python/2.7/site-packages/requests/api.py", line 71, in get return request('get', url, params=params, **kwargs) File "/Library/Python/2.7/site-packages/requests/api.py", line 57, in request return session.request(method=method, url=url, **kwargs) File "/Library/Python/2.7/site-packages/requests/sessions.py", line 475, in request resp = self.send(prep, **send_kwargs) File "/Library/Python/2.7/site-packages/requests/sessions.py", line 585, in send r = adapter.send(request, **kwargs) File "/Library/Python/2.7/site-packages/requests/adapters.py", line 477, in send raise SSLError(e, request=request) requests.exceptions.SSLError: ("bad handshake: Error([('SSL routines', 'SSL23_GET_SERVER_HELLO', 'sslv3 alert handshake failure')],)",)

๋‚˜๋Š” brew install openssl, brew upgrade openssl, pip install --upgrade pip, pip install requests, pip install request[security]๋ฅผ ์‹œ๋„ํ–ˆ์ง€๋งŒ ์ž‘๋™ํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ openssl version I get OpenSSL 0.9.8zh 14 Jan 2016 ์„ ์ž…๋ ฅํ•˜๋ฉด ๊ดœ์ฐฎ์€์ง€ ๋ชจ๋ฅด๊ฒ ์Šต๋‹ˆ๋‹ค.

์ €๋ฅผ ๋„์™€์ค„ ์ˆ˜ ์žˆ๋Š” ์‚ฌ๋žŒ์ด ์žˆ์Šต๋‹ˆ๊นŒ?

@jschwinger23 pip install pyopenssl ndg-httpsclient pyasn1 ๋„ ์‹คํ–‰ํ•ด ์ฃผ์‹ค ์ˆ˜ ์žˆ๋‚˜์š”?

@Lukasa ๋‹ต๋ณ€ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ์„ค์น˜ํ–ˆ์Œ์„ ์žฌํ™•์ธํ–ˆ์Šต๋‹ˆ๋‹ค.

$ pip install pyopenssl ndg-httpsclient pyasn1 Requirement already satisfied (use --upgrade to upgrade): pyopenssl in /System/Library/Frameworks/Python.framework/Versions/2.7/Extras/lib/python Requirement already satisfied (use --upgrade to upgrade): ndg-httpsclient in /Library/Python/2.7/site-packages Requirement already satisfied (use --upgrade to upgrade): pyasn1 in /Library/Python/2.7/site-packages

๊ทธ๋Ÿฌ๋‚˜ ์ฝ”๋“œ๋Š” ์—ฌ์ „ํžˆ ๋‹ค์šด๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

์–ด์จŒ๋“  Python3์—์„œ๋Š” ๋ชจ๋“  ๊ฒƒ์ด ์ž˜ ๋œ๋‹ค๋Š” ๊ฒƒ์„ ์•Œ๊ฒŒ ๋˜์—ˆ๊ณ , python3์—์„œ ์ฝ”๋”ฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜์–ด ๊ธฐ์ฉ๋‹ˆ๋‹ค.
๋งค์šฐ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

์œ„์˜ ์ง€์นจ์„ ๋”ฐ๋ž์ง€๋งŒ ์—ฌ์ „ํžˆ ์ด ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

``` Traceback (most recent call last): File "<stdin>", line 1, in <module> File "/Library/Python/2.7/site-packages/requests/api.py", line 71, in get return request('get', url, params=params, **kwargs) File "/Library/Python/2.7/site-packages/requests/api.py", line 57, in request return session.request(method=method, url=url, **kwargs) File "/Library/Python/2.7/site-packages/requests/sessions.py", line 475, in request resp = self.send(prep, **send_kwargs) File "/Library/Python/2.7/site-packages/requests/sessions.py", line 585, in send r = adapter.send(request, **kwargs) File "/Library/Python/2.7/site-packages/requests/adapters.py", line 477, in send raise SSLError(e, request=request) requests.exceptions.SSLError: ("bad handshake: Error([('SSL routines', 'SSL23_GET_SERVER_HELLO', 'sslv3 alert handshake failure')],)",)

์–ด๋–ค ์•„์ด๋””์–ด?
``````

@rohanpai ์•”ํ˜ธ ๊ฒน์นจ์ด ์—†๊ฑฐ๋‚˜ ์›๊ฒฉ ์„œ๋ฒ„๊ฐ€ ์ œ๊ณตํ•˜๋Š” ๋ฒ„์ „์— ๋งŒ์กฑํ•˜์ง€ ์•Š๊ฑฐ๋‚˜ ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ์„œ๋ฅผ ์ œ๊ณตํ•ด์•ผ ํ•˜์ง€๋งŒ ์ œ๊ณตํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋” ๊ตฌ์ฒด์ ์ธ ์กฐ์–ธ์„ ๋“œ๋ฆฌ๊ธฐ๋Š” ์–ด๋ ต์Šต๋‹ˆ๋‹ค. ๋ฌธ์ œ๋ฅผ ์กฐ์‚ฌํ•˜๋ ค๋ฉด ์ด๊ฒƒ์„ ์‹œ๋„ํ•˜์‹ญ์‹œ์˜ค.

์šฐ๋ถ„ํˆฌ 14.04LTS์—์„œ ๋‚˜๋Š” ์ด๊ฒƒ์„ํ•ด์•ผํ–ˆ์Šต๋‹ˆ๋‹ค :

sudo pip install ndg-httpsclient pyasn1 --upgrade

Ubuntu์—์„œ๋Š” pyopenssl ๊ฐ€ OS ์†Œ์œ ์ด๋ฏ€๋กœ ์—…๊ทธ๋ ˆ์ด๋“œ/์ œ๊ฑฐํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค.

markstrefford์˜ ์†”๋ฃจ์…˜์€ mac os sierra์—์„œ๋„ ์ €์—๊ฒŒ ํšจ๊ณผ์ ์ด์—ˆ์Šต๋‹ˆ๋‹ค.

@markstrefford ์˜ ์†”๋ฃจ์…˜๋„ ์ €์—๊ฒŒ ํšจ๊ณผ์ ์ด์—ˆ์Šต๋‹ˆ๋‹ค.

OpenSSL 1.1์„ ์‚ฌ์šฉํ•˜๋Š” ๋ชจ๋“  ์‚ฌ๋žŒ์„ ์œ„ํ•ด ์ฃผ์˜ํ•˜์‹ญ์‹œ์˜ค.
์›๊ฒฉ ์„œ๋ฒ„๊ฐ€ ์ฒซ ๋ฒˆ์งธ ์˜ต์…˜์œผ๋กœ ํƒ€์› ๊ณก์„ ์„ ์ œ๊ณตํ•  ๋•Œ TLS ์–ด๋Œ‘ํ„ฐ๋ฅผ ๊ฐ•์ œ ์‹คํ–‰ํ•˜๋Š” ๊ฒฝ์šฐ์—๋„ ์ด ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.
์›์ธ์€ http://bugs.python.org/issue29697 ์ž…๋‹ˆ๋‹ค.

์–˜๋“ค ์•„! ๋‹ค์Œ ์„œ๋ฒ„ https://34.200.105.231/SID/Service.svc?wsdl ์— ๋™์ผํ•œ ๋ฌธ์ œ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‚˜๋Š” ๋ชจ๋“  ๊ฒƒ์„ ์‹œ๋„ํ–ˆ๊ณ  ๋™์ผํ•œ 2๊ฐœ์˜ ์˜ค๋ฅ˜์—์„œ ์ ํ”„ํ–ˆ์Šต๋‹ˆ๋‹ค.

  • requests.exceptions.SSLError: ("bad handshake: SysCallError(-1, 'Unexpected EOF')",)
  • requests.exceptions.SSLError: EOF occurred in violation of protocol (_ssl.c:661)

์–ด๋–ค ์•„์ด๋””์–ด? @Lukasa , ์ธ์ฆ์„œ์— ๋ช‡ ๊ฐ€์ง€ ๋ฌธ์ œ๊ฐ€ ์žˆ์ง€๋งŒ ๊ทธ๋ ‡๊ฒŒ ๋‚˜์˜์ง€๋Š” ์•Š์€ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. https://sslanalyzer.comodoca.com/?url=34.200.105.231

์ธ์ฆ์„œ๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ ์ด ๋ฌธ์ œ๋ฅผ ์ผ์œผํ‚ค์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด ๋ฌธ์ œ๋Š” ์šฐ๋ฆฌ์—๊ฒŒ ์ „ํ™”๋ฅผ ๋Š์€ ์„œ๋ฒ„ ๋กœ ์ธํ•ด ๋ฐœ์ƒํ•˜๋ฏ€๋กœ ์ผ๋ฐ˜์ ์œผ๋กœ ์•”ํ˜ธ ์ œํ’ˆ๊ตฐ ๋ถˆ์ผ์น˜์˜ ๊ฒฐ๊ณผ์ž…๋‹ˆ๋‹ค. ์ด ๊ฒฝ์šฐ ์—ฌ๊ธฐ์—์„œ ๋ณผ ์ˆ˜ ์žˆ๋Š” ๊ฒƒ๊ณผ ๊ฐ™์€ ์ƒํ™ฉ์ด ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

์ด๊ฒƒ์€ ์†”์งํžˆ ๊ณต๊ฐœ๋œ ์ธํ„ฐ๋„ท์— ์ ˆ๋Œ€ ๋…ธ์ถœ๋˜์–ด์„œ๋Š” ์•ˆ ๋˜๋Š” ์„œ๋ฒ„์ž…๋‹ˆ๋‹ค. ์ด ์„œ๋ฒ„์™€ ํ†ต์‹ ํ•˜๋Š” ์•ˆ์ „ํ•œ ๋ฐฉ๋ฒ•์€ ์—†์Šต๋‹ˆ๋‹ค. ์—†์Œ, 0์ž…๋‹ˆ๋‹ค. ์ด๊ฒƒ์ด ํ•ธ๋“œ์…ฐ์ดํฌ๊ฐ€ ์‹คํŒจํ•˜๋Š” ์ด์œ ์ž…๋‹ˆ๋‹ค. ์š”์ฒญ์€ ์ตœ์‹  ์•”ํ˜ธ ์ œํ’ˆ๊ตฐ๋งŒ ํ—ˆ์šฉํ•˜๋ฉฐ ์ด ์„œ๋ฒ„์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ตœ์‹  ์•”ํ˜ธ ์ œํ’ˆ๊ตฐ์€ ์—†์Šต๋‹ˆ๋‹ค. ๊ฐ€์žฅ ์ข‹์€ ์˜ต์…˜์€ TLS_RSA_WITH_3DES_EDE_CBC_SHA ์ด๋ฉฐ ๋Œ€๊ทœ๋ชจ ๋ฐ์ดํ„ฐ ์ „์†ก์— ๋Œ€ํ•œ ์‹ค์ œ ๊ณต๊ฒฉ์— ์ทจ์•ฝํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ œ๊ฑฐํ•œ ์˜ต์…˜์ž…๋‹ˆ๋‹ค.

์ด ์„œ๋ฒ„๊ฐ€ ๊ท€ํ•˜์˜ ๊ฒƒ์ด๋ผ๋ฉด ๋” ๋‚˜์€ TLS ๊ตฌํ˜„์œผ๋กœ ์—…๊ทธ๋ ˆ์ด๋“œํ•˜๊ฑฐ๋‚˜ ์„ค์ •์„ ๋ณ€๊ฒฝ ํ•˜์‹ญ์‹œ์˜ค . ๊ทธ๋ ‡์ง€ ์•Š๋‹ค๋ฉด, ์ œ ์ฒซ ๋ฒˆ์งธ ์กฐ์–ธ์€ ์ด ์„œ๋ฒ„์™€ ๋Œ€ํ™”ํ•˜๋Š” ๊ฒƒ์„ ์žฌ๊ณ ํ•˜๋ผ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ํ•„์š”ํ•œ ๊ฒฝ์šฐ ์—ฌ๊ธฐ ์—์„œ ์ฝ”๋“œ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์ง€๋งŒ ์„œ๋ฒ„ ์šด์˜์ž์—๊ฒŒ ์ด ํ˜ผ๋ž€์„ ํ•ด๊ฒฐํ•˜๋„๋ก ์••๋ ฅ์„ ๊ฐ€ํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค .

@Lukasa -- ๋ชจ๋‘์™€ ํ•จ๊ป˜ ์ž‘์—…ํ•ด์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค! ๋‚˜๋Š” ์ด๊ฒƒ์˜ ๋Œ€๋ถ€๋ถ„์„ ์ฝ๊ณ  ์‹œ๋„ํ–ˆ์Šต๋‹ˆ๋‹ค

๋ฌธ์ œ

Windows์—์„œ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•˜๋ฉด ๋ชจ๋‘ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.
OSX์—์„œ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•  ๋•Œ ๋‹ค์Œ์„ ์ˆ˜์‹ ํ•ฉ๋‹ˆ๋‹ค.

raise SSLError(e, request=request)
requests.exceptions.SSLError: ("bad handshake: SysCallError(-1, 'Unexpected EOF')",)

๋‚˜๋Š” ๊ทธ๊ฒƒ์ด ์„œ๋ฒ„ ์ž์ฒด๊ฐ€ ์•„๋‹ˆ๋ผ๊ณ  ํ™•์‹ ํ•˜์ง€๋งŒ, ์ด ํ† ๋ผ ๊ตฌ๋ฉ์—์„œ ๋‚˜๋ฅผ ํ™•์ธ ๋ฐ/๋˜๋Š” ๊บผ๋‚ด๊ธฐ ์œ„ํ•ด ์ถ”๊ฐ€ ๋„์›€์„ ์ฃผ์‹œ๋ฉด ๊ฐ์‚ฌํ•˜๊ฒ ์Šต๋‹ˆ๋‹ค. ๊ทธ๊ฒƒ์„ ์ž‘๋™์‹œํ‚ค๋Š” ๋ฐ ํฐ ์Šน๋ฆฌ๊ฐ€ ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

OSX ์‚ฌ์–‘:

  • ํŒŒ์ด์ฌ ํŒŒ์ด์ฌ 2.7.10
  • OpenSSL OpenSSL 1.1.1-dev xx XXX xxxx(GitHub์„ ํ†ตํ•ด ์ปดํŒŒ์ผ๋จ)
  • PIP๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„ค์น˜

์‹œ๋„

  • ์ œ๊ฑฐ๋œ pyopenssl, ์š”์ฒญ, ์š”์ฒญ[๋ณด์•ˆ], ์•”ํ˜ธํ™”
  • env ARCHFLAGS="-arch x86_64" LDFLAGS="-L/usr/local/opt/openssl/lib" CFLAGS="-I/usr/local/opt/openssl/include" pip install --force-reinstall --no-cache-dir {PACKAGE} ์— ๋Œ€ํ•ด ์„ค์น˜๋จ

๋‚˜๋Š” openssl์— ๋Œ€ํ•œ ์„ค์น˜๊ฐ€ ์‹ค์ œ๋กœ ์•„๋ฌด ๊ฒƒ๋„ ํ•˜์ง€ ์•Š์•˜๋‹ค๊ณ  100% ํ™•์‹ ํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค(์˜ˆ: ์†๋„์™€ ๋ฉ”์‹œ์ง•์ด ๋ชจ๋‘ ๋™์ผํ•˜๊ฒŒ ๋‚˜ํƒ€๋‚จ).

openSSL appears ๋ฅผ ํ†ตํ•ด ์ง์ ‘ ์—ฐ๊ฒฐํ•˜๋Š” ๋‹ค๋ฅธ ์Šค๋ ˆ๋“œ(์œ„)์—์„œ ์ง€์‹œํ•œ ๋Œ€๋กœ ํ–‰๋ณตํ• ๊นŒ์š”?

openssl s_client -connect XXX.102.7.147:443
CONNECTED(00000003)
write:errno=0
---
no peer certificate available
---
No client certificate CA names sent
---
SSL handshake has read 0 bytes and written 198 bytes
Verification: OK
---
New, (NONE), Cipher is (NONE)
Secure Renegotiation IS NOT supported
Compression: NONE
Expansion: NONE
No ALPN negotiated
SSL-Session:
    Protocol  : TLSv1.2
    Cipher    : 0000
    Session-ID:
    Session-ID-ctx:
    Master-Key:
    PSK identity: None
    PSK identity hint: None
    SRP username: None
    Start Time: 1493384325
    Timeout   : 7200 (sec)
    Verify return code: 0 (ok)
    Extended master secret: no
---

์–ด...OpenSSL์€ ๊ธฐ์ˆ ์ ์œผ๋กœ ๊ดœ์ฐฎ์ง€๋งŒ OpenSSL์€ ์•”ํ˜ธ๋ฅผ ํ˜‘์ƒํ•˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค(์ฆ‰, SSL_NULL_WITH_NULL_NULL ํ˜‘์ƒํ•œ ๊ฒƒ์œผ๋กœ ๋ณด์ž…๋‹ˆ๋‹ค. ์„œ๋ฒ„์— ๋Œ€ํ•ด ssllabs๋ฅผ ์‹คํ–‰ํ•˜๊ณ  ์ง€์›ํ•˜๋Š” ์•”ํ˜ธ ์ œํ’ˆ๊ตฐ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๊นŒ?

@Lukasa ์ธํ„ฐ๋„ท์— ๋…ธ์ถœ๋˜์ง€ ์•Š์•˜์Šต๋‹ˆ๋‹ค. ์ ์ ˆํ•œ ํ†ต์ฐฐ๋ ฅ์„ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ๋Š” ๋ช‡ ๊ฐ€์ง€ ๋ช…๋ น์ค„ ์กฐ์‚ฌ๊ฐ€ ์žˆ์Šต๋‹ˆ๊นŒ?

cipherscan ์„ ์‹œ๋„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

@Lukasa ๊ฐ€ ์„ค์น˜ํ–ˆ์Šต๋‹ˆ๋‹ค ... ์ž‘๋™์ด ๋ถˆ์•ˆ์ •ํ•ฉ๋‹ˆ๋‹ค(์ถœ๋ ฅ ์—†์Œ, ๋ณด๊ณ  ์žˆ์Œ) ... ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์ด ์žˆ์œผ๋ฉด ๋‹ค์‹œ ๊ฒŒ์‹œํ•ฉ๋‹ˆ๋‹ค. ์•ˆ๋‚ดํ•ด์ฃผ์…”์„œ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค!

@Lukasa ๋„์›€์„ ์ฃผ์…”์„œ ๋Œ€๋‹จํžˆ ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ์‹ค์ œ๋กœ ์•”ํ˜ธ ์Šค์บ”์ด ์ž‘๋™ํ•˜์ง€ ์•Š์•˜์ง€๋งŒ ๋ฌธ์ œ๋ฅผ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ ์ด๊ฒƒ๊ณผ ์•„๋ฌด ๊ด€๋ จ์ด ์—†์—ˆ๊ณ  ์šฐ๋ฆฌ ํ™˜๊ฒฝ ์ „๋ฐ˜์— ๊ฑธ์นœ ์–ด๋ฆฌ์„์€ IP ๋ถˆ์ผ์น˜์˜€์Šต๋‹ˆ๋‹ค... ๊ตํ›ˆ์„ ์–ป์—ˆ์Šต๋‹ˆ๋‹ค! ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค ...

์ „ํ˜€ ๋ฌธ์ œ๊ฐ€ ์—†์Šต๋‹ˆ๋‹ค. ์ •๋ฆฌ๊ฐ€ ๋˜์…จ๋‹ค๋‹ˆ ๋‹คํ–‰์ž…๋‹ˆ๋‹ค!

streamlink -l ๋””๋ฒ„๊ทธ h ttpstream ://https ://www.arconaitv.us/stream.php?id=43 ์ตœ์•…
[cli][info] streamlink๊ฐ€ ๋ฃจํŠธ๋กœ ์‹คํ–‰ ์ค‘์ž…๋‹ˆ๋‹ค! ์กฐ์‹ฌํ•˜์„ธ์š”!
[cli][๋””๋ฒ„๊ทธ] OS: Linux-4.14.0-041400-generic-x86_64-with-Ubuntu-14.04-trusty
[cli][๋””๋ฒ„๊ทธ] ํŒŒ์ด์ฌ: 2.7.6
[cli][๋””๋ฒ„๊ทธ] ์ŠคํŠธ๋ฆผ๋งํฌ: 0.13.0+27.g2ff314c
[cli][๋””๋ฒ„๊ทธ] Requests(2.19.1), Socks(1.6.7), Websocket(0.48.0)
[cli][info] URL h ttpstream ://https ://www.arconaitv.us/stream.php?id=43์— ๋Œ€ํ•ด ์ผ์น˜ํ•˜๋Š” ํ”Œ๋Ÿฌ๊ทธ์ธ http๋ฅผ ์ฐพ์•˜์Šต๋‹ˆ๋‹ค.
[ํ”Œ๋Ÿฌ๊ทธ์ธ.http][๋””๋ฒ„๊ทธ] URL= https://www.arconaitv.us/stream.php?id=43; ๋งค๊ฐœ๋ณ€์ˆ˜={}
[cli][info] ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์ŠคํŠธ๋ฆผ: ๋ผ์ด๋ธŒ(์ตœ์•…, ์ตœ๊ณ )
[cli][info] ์˜คํ”„๋‹ ์ŠคํŠธ๋ฆผ: ๋ผ์ด๋ธŒ(http)
[cli][๋””๋ฒ„๊ทธ] ์‚ฌ์ „ ๋ฒ„ํผ๋ง 8192๋ฐ”์ดํŠธ
[cli][info] ์‹œ์ž‘ ํ”Œ๋ ˆ์ด์–ด: /usr/bin/vlc
[cli][๋””๋ฒ„๊ทธ] ์ถœ๋ ฅ์— ์ŠคํŠธ๋ฆผ ์“ฐ๊ธฐ
[cli][info] ์ŠคํŠธ๋ฆผ ์ข…๋ฃŒ
[cli][info] ํ˜„์žฌ ์—ด๋ ค ์žˆ๋Š” ์ŠคํŠธ๋ฆผ์„ ๋‹ซ์Šต๋‹ˆ๋‹ค..

์‹œ๋„ํ–ˆ์ง€๋งŒ ์šด์ด ์—†๋‹ค

atlast๋Š” ๋กœ์ปฌ PC์—์„œ ์ž‘๋™ํ•˜๋Š” tvplayer๋ฅผ ์–ป์—ˆ์Šต๋‹ˆ๋‹ค. ๋‚ด ๋กœ์ปฌ PC์— tinyproxy๋ฅผ ์„ค์น˜ํ–ˆ์ง€๋งŒ vps httpproxy xxxx๊ฐ€ ์ž‘๋™ํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
tinyproxy๋Š” ๊ดœ์ฐฎ์Šต๋‹ˆ๋‹ค. ์•„๋‹ˆ๋ฉด ๋กœ์ปฌ PC์— ์„ค์น˜ํ•  ๋‹ค๋ฅธ ํ”„๋ก์‹œ ์„œ๋ฒ„๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

์ž‘์€ ํ”„๋ก์‹œ.txt

@maanich ์•ˆ๋…•ํ•˜์„ธ์š”. ์ด๊ฒƒ์€ ์ด ๋ฌธ์ œ์™€ ์ง์ ‘์ ์ธ ๊ด€๋ จ์ด ์—†๊ฑฐ๋‚˜ ์ด ๋ฌธ์ œ ์ถ”์ ๊ธฐ๊ฐ€ ์˜ˆ์•ฝ๋˜์–ด ์žˆ๋Š” Requests์— ๋Œ€ํ•œ ๊ฒฐํ•จ ๋ณด๊ณ ์„œ๋กœ ๋ณด์ด์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์‹œ์Šคํ…œ ๊ตฌ์„ฑ์— ๋Œ€ํ•œ ์งˆ๋ฌธ์ด ์žˆ๋Š” ๊ฒฝ์šฐ StackOverflow ์™€ ๊ฐ™์€ ํ”Œ๋žซํผ์—์„œ ๊ฐ€์žฅ ์ž˜ ํ•ด๊ฒฐ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ฐ์‚ฌ ํ•ด์š”!

streamlink --https-proxy " http://8xxxx :8000/" --tvplayer-email [email protected] --tvplayer-password vcvdf3 --http-no-ssl-verify https://tvplayer.com/watch /itv ๋ฒ ์ŠคํŠธ --player-no-close --stdout | /var/tmp/youtube/ffmpeg -y -i ํŒŒ์ดํ”„:0 -vcodec ๋ณต์‚ฌ -acodec ๋ณต์‚ฌ -flags -global_header -hls_flags delete_segments -hls_time 10 -hls_list_size 6 /mnt/hls/arc.m3u8
ffmpeg ๋ฒ„์ „ 4.0-์ •์  https://johnvansickle.com/ffmpeg/ Copyright (c) 2000-2018 FFmpeg ๊ฐœ๋ฐœ์ž
gcc 6.3.0์œผ๋กœ ๋นŒ๋“œ(Debian 6.3.0-18+deb9u1) 20170516
๊ตฌ์„ฑ: --enable-gpl --enable-version3 --enable-static --disable-debug --disable-ffplay --disable-indev=sndio --disable-outdev=sndio --cc=gcc-6 -- enable-libxml2 --enable-fontconfig --enable-frei0r --enable-gnutls --enable-gray --enable-libaom --enable-libfribidi --enable-libass --enable-libfreetype --enable-libmp3lame -- enable-libopencore-amrnb --enable-libopencore-amrwb --enable-libopenjpeg --enable-librubberband --enable-libsoxr --enable-libspeex --enable-libvorbis --enable-libopus --enable-libtheora --enable -libvidstab --enable-libvo-amrwbenc --enable-libvpx --enable-libwebp --enable-libx264 --enable-libx265 --enable-libxml2 --enable-libxvid --enable-libzimg
libavutil 56. 14.100 / 56. 14.100
๋ฆฌ๋ฐ”๋ธŒ์ฝ”๋ฑ 58. 18.100 / 58. 18.100
๋ฆฌ๋ฐ”๋ธŒํฌ๋งท 58. 12.100 / 58. 12.100
๋ฆฌ๋ฐ”๋ธŒ์žฅ์น˜ 58. 3.100 / 58. 3.100
๋ฆฌ๋ฐ”๋ธŒํ•„ํ„ฐ 7. 16.100 / 7. 16.100
libswscale 5. 1.100 / 5. 1.100
libswresample 3. 1.100 / 3. 1.100
libpostproc 55. 1.100 / 55. 1.100
[์ฝ˜์†”][์ •๋ณด] streamlink๊ฐ€ ๋ฃจํŠธ๋กœ ์‹คํ–‰ ์ค‘์ž…๋‹ˆ๋‹ค! ์กฐ์‹ฌํ•˜์„ธ์š”!
[์ฝ˜์†”][์ •๋ณด] URL https://tvplayer.com/watch/itv ์— ๋Œ€ํ•ด ์ผ์น˜ํ•˜๋Š” ํ”Œ๋Ÿฌ๊ทธ์ธ tvplayer๋ฅผ ์ฐพ์•˜์Šต๋‹ˆ๋‹ค.
์˜ค๋ฅ˜ : ์—ด๋ ค์žˆ๋Š” URL์— ์—†์Šต๋‹ˆ๋‹ค https://live.tvplayer.com/stream.m3u8?id=204&Policy=eyJTdGF0ZW1lbnQiOlt7IlJlc291cmNlIjoiaHR0cCo6XC9cL2xpdmUudHZwbGF5ZXIuY29tXC9zdHJlYW0ubTN1OD9pZD0yMDQiLCJDb25kaXRpb24iOnsiRGF0ZUxlc3NUaGFuIjp7IkFXUzpFcG9jaFRpbWUiOjE1MjkwNTc0OTR9LCJJcEFkZHJlc3MiOnsiQVdTOlNvdXJjZUlwIjoiNjIuMjEwLjE0Mi42NlwvMzIifX19XX0_&Signature=mHOteYcUu4QsbGD n0e ~ 7meDUGT8VN7bVOBAHa-0Mk6ROA9XHYx3aIAZMAo3dFjOGuWk-3MszJzRFHdv ~ -CCsmX3D8XQa2zvzfuIWfMAT ~ yDshroXBN25iW6ZJ0-7lGla00jMTUpm5sW-uDy18OkiBWgGvDVas2Lz-EW ~ 5 LTw2YWvEpqkvRB9OpcsHJj9RRQLuDVjwYKXwKvHTJmB1J ~sGE3aigaL7AZyBaIAUMcpk-xYMpDuPV9BsBN9AT397lFfRPFt155u~yeBHZ4JlUN2GINUBt0-CzGuYVq3dsO kYYEZJo9cQTVhArpo7ek03VbDP5egtCM8obN63VbDP5egtCM8obN63์˜ค๋ฅ˜์šฉ ํด๋ผ์ด์–ธํŠธ
pipe:0 : ์ž…๋ ฅ์„ ์ฒ˜๋ฆฌํ•  ๋•Œ ์ž˜๋ชป๋œ ๋ฐ์ดํ„ฐ๊ฐ€ ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์ŠคํŠธ๋ฆผ๋งํฌ์— ์–ด๋–ค ํ”„๋ก์‹œ ์„œ๋ฒ„๊ฐ€ ์ข‹์€์ง€ ์กฐ์–ธ ๋ถ€ํƒ๋“œ๋ฆฝ๋‹ˆ๋‹ค.

์ด ํŽ˜์ด์ง€๊ฐ€ ๋„์›€์ด ๋˜์—ˆ๋‚˜์š”?
0 / 5 - 0 ๋“ฑ๊ธ‰