… | |
… | |
32 | - the pid-file now accepts %s as nodename as elsewhere. |
32 | - the pid-file now accepts %s as nodename as elsewhere. |
33 | - switch to counter mode (only aes supported at the moment in |
33 | - switch to counter mode (only aes supported at the moment in |
34 | openssl). this gets rid of the need to generate a random iv, |
34 | openssl). this gets rid of the need to generate a random iv, |
35 | is likely more secure (and, as a side effect, gets rid of |
35 | is likely more secure (and, as a side effect, gets rid of |
36 | slow randomness generation. counter mode is often faster |
36 | slow randomness generation. counter mode is often faster |
37 | then cbc mode as well). |
37 | then cbc mode as well, and packets are smaller). |
38 | - no longer use RAND_bytes to generate session keys - you NEED |
38 | - no longer use RAND_bytes to generate session keys - you NEED |
39 | a real source of entropy now (e.g. egd or /dev/random - see the |
39 | a real source of entropy now (e.g. egd or /dev/random - see the |
40 | openssl documentation). |
40 | openssl documentation). |
41 | - multiple node statements for the same node are now supported |
41 | - multiple node statements for the same node are now supported |
42 | and will be merged. |
42 | and will be merged. |