GnuTLS 2.7.4

Simon Josefsson simon at
Wed Jan 7 12:59:55 CET 2009

The GnuTLS 2.7.x branch is NOT what you want for your stable system.  It
is intended for developers and experienced users.

Here are the compressed sources: (5.8MB)

Here is the OpenPGP signature:

* Version 2.7.4 (released 2009-01-07)

** gnutls: deprecate X.509 validation chains using MD5 and MD2 signatures.
This is a bugfix -- the previous attempt to do this from internal x509
certificate verification procedures did not return the correct value
for certificates using a weak hash.  Reported by Daniel Kahn Gillmor
<dkg at> in
debugged and patch by Tomas Mraz <tmraz at> and Daniel Kahn
Gillmor <dkg at>.

** gnutls: New interface to get key id for certificate requests.
Patch from David Marín Carreño <davefx at> in

** gnutls: gnutls_x509_crq_print will now also print public key id.

** certtool: --verify-chain now prints results of using library verification.
Earlier, certtool --verify-chain used its own validation algorithm
which wasn't guaranteed to give the same result as the libgnutls
internal validation algorithm.  Now this command print a new final
line with header 'Chain verification output:' that contains the result
From using the internal verification algorithm on the same chain.

** tests: Add crq_key_id self-test of gnutls_x509_crq_get_key_id.

** API and ABI modifications:
gnutls_x509_crq_get_key_id: ADDED.
More information about the Gnutls-devel mailing list