INN commit: branches/2.6/doc/pod (news.pod)
INN Commit
rra at isc.org
Sun Nov 27 13:43:26 UTC 2016
Date: Sunday, November 27, 2016 @ 05:43:25
Author: iulius
Revision: 10127
Reorder compression-related items in NEWS
Modified:
branches/2.6/doc/pod/news.pod
----------+
news.pod | 18 ++++++++++--------
1 file changed, 10 insertions(+), 8 deletions(-)
Modified: news.pod
===================================================================
--- news.pod 2016-11-27 13:42:58 UTC (rev 10126)
+++ news.pod 2016-11-27 13:43:25 UTC (rev 10127)
@@ -17,7 +17,9 @@
described in draft-murchison-nntp-compress that extends the NNTP protocol
to allow a connection to be effectively and efficiently compressed.
News clients that also support that extension will be able to benefit
-from that bandwidth optimization and improvement in speed.
+from that bandwidth optimization and improvement in speed. Moreover,
+using COMPRESS is more secure than TLS-level compression, as far as
+authentication credentials are concerned.
=item *
@@ -28,6 +30,12 @@
=item *
+The I<tlscompression> parameter in F<inn.conf> now also permits to
+disable TLS-level compression with S<OpenSSL 0.9.8>. It previously
+had an effect only when S<OpenSSL 1.0.0> or later was used.
+
+=item *
+
B<rnews> no longer segfaults at startup when started setuid news.
Thanks to Marcus Jodorf for the bug report.
@@ -55,7 +63,7 @@
When an encryption layer is negotiated during a successful use of the
STARTTLS command, or after a successful authentication using a SASL
-mechanism which negotiates an encryption layer, B<nnrpd> now updates
+mechanism that negotiates an encryption layer, B<nnrpd> now updates
the permissions of the news client according to the new secure state
of his connection (that is to say auth blocks in F<readers.conf> using
the I<require_ssl> parameter are taken into account). Previously,
@@ -71,12 +79,6 @@
=item *
-The I<tlscompression> parameter in F<inn.conf> now also permits to
-disable TLS-level compression with S<OpenSSL 0.9.8>. It previously
-had an effect only when S<OpenSSL 1.0.0> or later was used.
-
-=item *
-
B<nntpsend> now correctly waits until all of the child B<innxmit>
processes exit before it does. It was causing B<nntpsend> to fail
to work properly on systems that use systemd, because when it exits
More information about the inn-committers
mailing list