We have released LibreSSL 4.3.3, which will be arriving in the LibreSSL directory of your local OpenBSD mirror soon. It includes the following changes from LibreSSL 4.3.2: * Portable changes - Added support for building on macOS Golden Gate, 27.0 - Fixed incorrect code generation by the MSVC ARM64 optimizer in constant-time bignum code. - Allow overriding TLS_DEFAULT_CA_FILE in CMake builds. - Windows socketpair() emulation now sets close-on-exec on the right handle. * Security and reliability fixes - Remove RelativeDistinguishedName support for CRL distribution points - Ensure verify callbacks always returning 1 can see a hostname mismatch - Correct botched size check in dtls1_preprocess_fragment() - Limit size of buffered DTLS handshake messages - Avoid potential overread on interrupted retransmission in DTLS - Fix OCSP responder authorization bypass in libtls and ocspcheck(8) The LibreSSL project continues improvement of the codebase to reflect modern, safe programming practices. We welcome feedback and improvements from the broader community. Thanks to all of the contributors who helped make this release possible.