What's Changed
- ci: fix openssh-master integration by @prasden in #3561
- Skip AEAD ConcurrentStability under Intel SDE; add deterministic context-immutability test by @justsmth in #3562
- Zeroize ChaCha20-Poly1305 key material by @nhatnghiho in #3552
- Record job settings for failed integrations by @prasden in #3569
- Restricting CI permissions so fork-PR code doesn't run CI with ECR push and shared S3 write permissions by @spwalgren in #3546
- Fix BIO socket error handling by @justsmth in #3459
- Reject [UNIVERSAL 0] elements with content as end-of-contents by @spwalgren in #3560
- Add OpenSSL-compatible rehash -compat support by @justsmth in #3563
- Harden a number of code-paths to avoid e.g. hangs and invalid input by @torben-hansen in #3543
- Guard against NULL attribute type names in X509_NAME_print_ex by @WillChilds-Klein in #3574
- Fail openssl ca when the issued certificate cannot be written by @WillChilds-Klein in #3568
- Gating PR auth checks on actor pushing the code instead of author by @spwalgren in #3567
- Seed groups and signature algorithms from the system crypto policy by @WillChilds-Klein in #3504
- Extend FIPS 3.x EOS to February 2030 by @samuel40791765 in #3539
- fix: Update Ruby (master) integration patch by @skmcgrail in #3590
- fix(acvp): place the IUT public key correctly in KAS-ECC fixedInfo by @prasden in #3597
- Support
pkcs12 -exportandreq -batchin the OpenSSL CLI by @justsmth in #3575 - feat(duvet): RFC 8032 (EdDSA) requirement coverage + annotation-regression CI by @dougch in #3477
- fix: Add patch for failing gRPC master branch by @skmcgrail in #3591
- Reject unoffered cipher suite in TLS 1.3 client by @spwalgren in #3537
- fix(ssl): Check buffer-view bounds before pointer arithmetic by @spwalgren in #3566
- fix(x509): Verify CSR proof-of-possession on -req by @spwalgren in #3592
- Remove nameRelativeToCRLIssuer CRL distribution point support by @justsmth in #3598
- Use the dummy key when a PKCS#7 content encryption key is the wrong length by @WillChilds-Klein in #3585
- Resize md_data when an HMAC EVP_MD_CTX changes digest by @WillChilds-Klein in #3586
- Support RSA encryption/decryption and additional ciphers in the OpenSSL CLI by @justsmth in #3605
- fix(ml_kem): Gate ML-KEM x86-64 on BMI2 in addition to AVX2 by @spwalgren in #3596
- fix(ci): restrict calls for autofix by @prasden in #3599
- Recognise known safe DH groups/primes and short-circuit Diffie-Hellman test by @torben-hansen in #3337
- Harden previous-finished* length in v1/v2 transfer by @spwalgren in #3595
- Prepare v5.11.0 by @skmcgrail in #3610
Full Changelog: v5.10.0...v5.11.0