[gnutls-dev] OpenCDK 0.5.10

Simon Josefsson jas at extundo.com
Wed Oct 11 17:03:42 CEST 2006


The OpenCDK library implement basic parts of the OpenPGP message
format.  Due to some possible security problems, the library also
implements parts of draft-ietf-openpgp-rfc2440bis-08.txt.

The aim of the library is *not* to replace any available OpenPGP
version.  There will be no real support for key management (sign,
revoke, alter preferences, ...) and some other parts are only
rudimentary available.  The main purpose is to handle and understand
OpenPGP packets and to use basic operations.  For example,
encrypt/decrypt, sign/verify and packet parsing routines.

Noteworthy changes in version 0.5.10 (2006-10-11)
------------------------------------------------

* Fix double-free in cdk_pklist_encrypt, reported by Adam Langley.

* Fix keydb_idx_search() to handle keys at offset 0, thanks to Adam Langley.

* A pkg-config script was added, thanks to Andreas Metzler.

* Autobuild time stamps are used, for easier build robot testing.

Commercial support contracts for OpenCDK are available, and they help
finance continued maintenance.  Simon Josefsson Datakonsult, a
Stockholm based privately held company, is currently funding OpenCDK
maintenance.  We are always looking for interesting development
projects.  See http://josefsson.org/ for more details.

If you need help to use OpenCDK, or want to help others, you are
invited to join our help-gnutls mailing list, see:
<http://lists.gnu.org/mailman/listinfo/help-gnutls>.

Here are the compressed sources (1.2MB):
  http://josefsson.org/gnutls/releases/opencdk/opencdk-0.5.10.tar.gz
  ftp://ftp.gnutls.org/pub/gnutls/opencdk/opencdk-0.5.10.tar.gz

Here are GPG detached signatures using key 0xB565716F:
  http://josefsson.org/gnutls/releases/opencdk/opencdk-0.5.10.tar.gz.sig
  ftp://ftp.gnutls.org/pub/gnutls/opencdk/opencdk-0.5.10.tar.gz.sig

The software is cryptographically signed by the author using an
OpenPGP key identified by the following information:

pub   1280R/B565716F 2002-05-05 [expires: 2007-02-15]
uid                  Simon Josefsson <jas at extundo.com>
uid                  Simon Josefsson <simon at josefsson.org>
sub   1280R/4D5D40AE 2002-05-05 [expires: 2007-02-15]
sub   1024R/09CC4670 2006-03-18 [expires: 2007-04-22]
sub   1024R/AABB1F7B 2006-03-18 [expires: 2007-04-22]
sub   1024R/A14C401A 2006-03-18 [expires: 2007-04-22]

The key is available from:
  http://josefsson.org/key.txt
  dns:b565716f.josefsson.org?TYPE=CERT

Here are the SHA-1 and SHA-224 checksums:

db4af36730dcbb2ab9ac93f6ce1ec27e5a36876f  opencdk-0.5.10.tar.gz
9259cdf60825d4e302349d6572b51f43ab4ff14d  opencdk-0.5.10.tar.gz.sig

a334e13b0b246c4af85d60936c73a453b73d482e915a09ae5cadb2e8  opencdk-0.5.10.tar.gz
8bce4e01c874a3197518970f95763367ed62112a781f97bc78a0ad99  opencdk-0.5.10.tar.gz.sig

Enjoy,
Timo, Nikos, Simon
-------------- next part --------------
A non-text attachment was scrubbed...
Name: not available
Type: application/pgp-signature
Size: 419 bytes
Desc: not available
URL: </pipermail/attachments/20061011/71f6d6b7/attachment.pgp>


More information about the Gnutls-devel mailing list