[Openvpn-devel,v6,2/3] crypto_openssl: add initialization to pick up local configuration
| Message ID | 20200528225920.6983-3-James.Bottomley@HansenPartnership.com |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director9.mail.ord1d.rsapps.net ([172.27.255.59]) by backend30.mail.ord1d.rsapps.net with LMTP id yJGdOthC0F6yeAAAIUCqbw for <patchwork@openvpn.net>; Thu, 28 May 2020 19:01:45 -0400 Received: from proxy6.mail.iad3a.rsapps.net ([172.27.255.59]) by director9.mail.ord1d.rsapps.net with LMTP id aGNgONhC0F7UYgAAalYnBA ; Thu, 28 May 2020 19:01:45 -0400 Received: from smtp14.gate.iad3a ([172.27.255.59]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy6.mail.iad3a.rsapps.net with LMTP id qHx/M9hC0F6GIQAA8udqhg ; Thu, 28 May 2020 19:01:44 -0400 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp14.gate.iad3a.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (signature verification failed) header.d=hansenpartnership.com; dmarc=fail (p=none; dis=none) header.from=hansenpartnership.com X-Suspicious-Flag: YES X-Classification-ID: 32f255ca-a137-11ea-a2f2-5254005d41e3-1-1 Received: from [216.105.38.7] ([216.105.38.7:52822] helo=lists.sourceforge.net) by smtp14.gate.iad3a.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id 98/0A-20713-8D240DE5; Thu, 28 May 2020 19:01:44 -0400 Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1jeRWE-0002l6-AY; Thu, 28 May 2020 23:00:58 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from <James.Bottomley@HansenPartnership.com>) id 1jeRWD-0002l0-Gy for openvpn-devel@lists.sourceforge.net; Thu, 28 May 2020 23:00:57 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-Id:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=9J6953LBNtGhUg2eyEd11xAU0XhWcmBbZ/wcMzWQJ9E=; b=TSjOEkYbVervdP13HXXZIUQKDN bVm4ks9/1nBFOmWL2pSNvhWXjwcEknxJcCFhDLTjK78gcy1c9KVQDJTXw5j8zyJlSj/5u2DIGdkNX CxZeGICpw5yIelc6GYg5ThJuVPmmMd40TEhrrtcWo4dEdeG3VCKaYnNsn8aWk/vOpbxg=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-Id: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=9J6953LBNtGhUg2eyEd11xAU0XhWcmBbZ/wcMzWQJ9E=; b=nBrpkGcsAp31bz5ygFjzGh7RH4 vO104+2cO3q40dDgzp801tI0Rj0mdxpD2fZbd1pUw4p6vDNfmYLH2ovSjwyescjLgmN4JtnCmxhoS GitDRKlqK1DtMTK4GPQDLd6HewpOolwb/zMkbVTJrsPxnF0Za7IDobsVLEieMCU99uo8=; Received: from bedivere.hansenpartnership.com ([66.63.167.143]) by sfi-mx-4.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.2) id 1jeRWC-0021Mr-I1 for openvpn-devel@lists.sourceforge.net; Thu, 28 May 2020 23:00:57 +0000 Received: from localhost (localhost [127.0.0.1]) by bedivere.hansenpartnership.com (Postfix) with ESMTP id 5A56B8EE10F for <openvpn-devel@lists.sourceforge.net>; Thu, 28 May 2020 16:00:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=simple/simple; d=hansenpartnership.com; s=20151216; t=1590706851; bh=eYdNmcFGQze93gl5QT48HkmrpuHyoH01RQgY6v5u9aQ=; h=From:To:Subject:Date:In-Reply-To:References:From; b=o3d0wyXqgQOuUDU45ZYVafbBSMT54SHChzwCFxcd+usgqtwQHIi8vUF2qxRiVLuaY eu4gN/u807gn8cQ5IM3witjXAFAHbVscIjk3HFS6OtAoSSpq++K/FM2VjOrX8MVEqE 1ScAAI9XDCVv3DzlUnRb+JVhI+fV9gWMT4Ms5668= Received: from bedivere.hansenpartnership.com ([127.0.0.1]) by localhost (bedivere.hansenpartnership.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id aTJVohYtIC0t for <openvpn-devel@lists.sourceforge.net>; Thu, 28 May 2020 16:00:51 -0700 (PDT) Received: from jarvis.lan (jarvis.ext.hansenpartnership.com [153.66.160.226]) by bedivere.hansenpartnership.com (Postfix) with ESMTP id 0CEB78EE0F8 for <openvpn-devel@lists.sourceforge.net>; Thu, 28 May 2020 16:00:51 -0700 (PDT) From: James Bottomley <James.Bottomley@HansenPartnership.com> To: openvpn-devel@lists.sourceforge.net Date: Thu, 28 May 2020 15:59:19 -0700 Message-Id: <20200528225920.6983-3-James.Bottomley@HansenPartnership.com> X-Mailer: git-send-email 2.26.2 In-Reply-To: <20200528225920.6983-1-James.Bottomley@HansenPartnership.com> References: <20200528225920.6983-1-James.Bottomley@HansenPartnership.com> MIME-Version: 1.0 X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: hansenpartnership.com] -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1jeRWC-0021Mr-I1 Subject: [Openvpn-devel] [PATCH v6 2/3] crypto_openssl: add initialization to pick up local configuration X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
add support for engine keys
|
|
Commit Message
James Bottomley
May 28, 2020, 12:59 p.m. UTC
The test programme for the new openssl engine code requires overriding
the system default configuration file to point to the location of the
test engine. Add an initialization stanza that makes this behaviour
universal, so now anyone running openvpn configured with openssl can
specify their own configuration file with the OPENSSL_CONF environment
variable.
Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com>
---
src/openvpn/crypto_openssl.c | 5 +++++
1 file changed, 5 insertions(+)
Comments
Am 29.05.20 um 00:59 schrieb James Bottomley: > The test programme for the new openssl engine code requires overriding ^^^ Unrelated to this commit but I wondered about this spelling and it seems that the British programme spelling usually is a TV programme while program is used in computer context. AE just uses program for both. > the system default configuration file to point to the location of the > test engine. Add an initialization stanza that makes this behaviour > universal, so now anyone running openvpn configured with openssl can > specify their own configuration file with the OPENSSL_CONF environment > variable. Acked-By: Arne Schwabe <arne@rfc2549.org> I also tested that with a configuration file with an invalid statement this does not abort OpenVPN (the bug we had a few weeks ago) Arne
Your patch has been applied to the master branch.
commit a4071b20115c7d4e808df81169a986e65cec4efa
Author: James Bottomley
Date: Thu May 28 15:59:19 2020 -0700
crypto_openssl: add initialization to pick up local configuration
Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com>
Acked-by: Arne Schwabe <arne@rfc2549.org>
Message-Id: <20200528225920.6983-3-James.Bottomley@HansenPartnership.com>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg19936.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
Hi, > diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c > index 4ac77fde..fd57edd2 100644 > --- a/src/openvpn/crypto_openssl.c > +++ b/src/openvpn/crypto_openssl.c > @@ -149,6 +149,11 @@ crypto_init_lib_engine(const char *engine_name) > void > crypto_init_lib(void) > { > +#if (OPENSSL_VERSION_NUMBER >= 0x10100000L) > + OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, NULL); > +#else > + OPENSSL_config(NULL); > +#endif This is failing on some of the Travis builds, with the error message 1191 crypto_openssl.c: In function `crypto_init_lib': 1192 crypto_openssl.c:155:5: error: implicit declaration of function `OPENSSL_config'; did you mean `OPENSSL_init'? [-Werror=implicit-function-declaration] 1193 OPENSSL_config(NULL); 1194 ^~~~~~~~~~~~~~ https://travis-ci.org/github/OpenVPN/openvpn/builds/695633823 From what I can see, this is for the builds with "openssl 1.0.1u" and "openssl 1.0.2u" on Bionic. I'm not sure if we intend to support these versions, but this needs to be fixed - either the code needs to be adjusted or the travis build matrix (for master). gert
On Sun, 2020-06-07 at 13:11 +0200, Gert Doering wrote: > Hi, > > > diff --git a/src/openvpn/crypto_openssl.c > > b/src/openvpn/crypto_openssl.c > > index 4ac77fde..fd57edd2 100644 > > --- a/src/openvpn/crypto_openssl.c > > +++ b/src/openvpn/crypto_openssl.c > > @@ -149,6 +149,11 @@ crypto_init_lib_engine(const char > > *engine_name) > > void > > crypto_init_lib(void) > > { > > +#if (OPENSSL_VERSION_NUMBER >= 0x10100000L) > > + OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, NULL); > > +#else > > + OPENSSL_config(NULL); > > +#endif > > This is failing on some of the Travis builds, with the error message > > 1191 crypto_openssl.c: In function `crypto_init_lib': > 1192 crypto_openssl.c:155:5: error: implicit declaration of function > `OPENSSL_config'; did you mean `OPENSSL_init'? [-Werror=implicit- > function-declaration] > 1193 OPENSSL_config(NULL); > 1194 ^~~~~~~~~~~~~~ > > https://travis-ci.org/github/OpenVPN/openvpn/builds/695633823 > > From what I can see, this is for the builds with "openssl 1.0.1u" and > "openssl 1.0.2u" on Bionic. > > > I'm not sure if we intend to support these versions, but this needs > to be fixed - either the code needs to be adjusted or the travis > build matrix (for master). Sorry about that. Best guess is it's missing an include for openssl/conf.h. You don't need that today because pretty much every other openssl header includes it, but that may not always have been so. Does the below patch fix it? If it does, it should probably be folded into the other patch. It should be safe because openssl/conf.h has existed for every version of openssl you support. James ---8>8>8><8<8<8--- From: James Bottomley <James.Bottomley@HansenPartnership.com> Subject: [PATCH] crypto_openssl: add include for openssl/conf.h Fix build failure on older versions of openssl. Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com> --- src/openvpn/crypto_openssl.c | 1 + 1 file changed, 1 insertion(+) diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index fd57edd2..94b6d85b 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -43,6 +43,7 @@ #include "crypto_backend.h" #include "openssl_compat.h" +#include <openssl/conf.h> #include <openssl/des.h> #include <openssl/err.h> #include <openssl/evp.h>
> > Sorry about that. Best guess is it's missing an include for > openssl/conf.h. You don't need that today because pretty much every > other openssl header includes it, but that may not always have been so. > > Does the below patch fix it? If it does, it should probably be folded > into the other patch. It should be safe because openssl/conf.h has > existed for every version of openssl you support. I am also puzzeld by this. On my local machine the OpenSSL 1.0.2 buildis fine without this extra include. But I am ACKing this alone on the basis that including the conf.h header is the corect thing to do (the man page says it should be included) It fixes the travis build error (https://travis-ci.org/github/schwabe/openvpn/builds/695947378) but I do not really understand why OpenSSL behaves different there. So Acked-By: Arne Schwabe <arne@rfc2549.org> > > James > > ---8>8>8><8<8<8--- > From: James Bottomley <James.Bottomley@HansenPartnership.com> > Subject: [PATCH] crypto_openssl: add include for openssl/conf.h > > Fix build failure on older versions of openssl. > > Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com> > --- > src/openvpn/crypto_openssl.c | 1 + > 1 file changed, 1 insertion(+) > > diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c > index fd57edd2..94b6d85b 100644 > --- a/src/openvpn/crypto_openssl.c > +++ b/src/openvpn/crypto_openssl.c > @@ -43,6 +43,7 @@ > #include "crypto_backend.h" > #include "openssl_compat.h" > > +#include <openssl/conf.h> > #include <openssl/des.h> > #include <openssl/err.h> > #include <openssl/evp.h> >
пн, 8 июн. 2020 г. в 15:06, Arne Schwabe <arne@rfc2549.org>: > > > > > Sorry about that. Best guess is it's missing an include for > > openssl/conf.h. You don't need that today because pretty much every > > other openssl header includes it, but that may not always have been so. > > > > Does the below patch fix it? If it does, it should probably be folded > > into the other patch. It should be safe because openssl/conf.h has > > existed for every version of openssl you support. > > > I am also puzzeld by this. On my local machine the OpenSSL 1.0.2 buildis > fine without this extra include. > > But I am ACKing this alone on the basis that including the conf.h header > is the corect thing to do (the man page says it should be included) > > It fixes the travis build error > (https://travis-ci.org/github/schwabe/openvpn/builds/695947378) but I do > not really understand why OpenSSL behaves different there. > it might happen if includes are mixed from OS openssl and custom openssl. I'll have a look (what is include path in travis). > > So > > Acked-By: Arne Schwabe <arne@rfc2549.org> > > > > > James > > > > ---8>8>8><8<8<8--- > > From: James Bottomley <James.Bottomley@HansenPartnership.com> > > Subject: [PATCH] crypto_openssl: add include for openssl/conf.h > > > > Fix build failure on older versions of openssl. > > > > Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com> > > --- > > src/openvpn/crypto_openssl.c | 1 + > > 1 file changed, 1 insertion(+) > > > > diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c > > index fd57edd2..94b6d85b 100644 > > --- a/src/openvpn/crypto_openssl.c > > +++ b/src/openvpn/crypto_openssl.c > > @@ -43,6 +43,7 @@ > > #include "crypto_backend.h" > > #include "openssl_compat.h" > > > > +#include <openssl/conf.h> > > #include <openssl/des.h> > > #include <openssl/err.h> > > #include <openssl/evp.h> > > > > > _______________________________________________ > Openvpn-devel mailing list > Openvpn-devel@lists.sourceforge.net > https://lists.sourceforge.net/lists/listinfo/openvpn-devel > <div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">пн, 8 июн. 2020 г. в 15:06, Arne Schwabe <<a href="mailto:arne@rfc2549.org">arne@rfc2549.org</a>>:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"><br> > <br> > Sorry about that. Best guess is it's missing an include for<br> > openssl/conf.h. You don't need that today because pretty much every<br> > other openssl header includes it, but that may not always have been so.<br> > <br> > Does the below patch fix it? If it does, it should probably be folded<br> > into the other patch. It should be safe because openssl/conf.h has<br> > existed for every version of openssl you support.<br> <br> <br> I am also puzzeld by this. On my local machine the OpenSSL 1.0.2 buildis<br> fine without this extra include.<br> <br> But I am ACKing this alone on the basis that including the conf.h header<br> is the corect thing to do (the man page says it should be included)<br> <br> It fixes the travis build error<br> (<a href="https://travis-ci.org/github/schwabe/openvpn/builds/695947378" rel="noreferrer" target="_blank">https://travis-ci.org/github/schwabe/openvpn/builds/695947378</a>) but I do<br> not really understand why OpenSSL behaves different there.<br></blockquote><div><br></div><div>it might happen if includes are mixed from OS openssl and custom openssl.</div><div>I'll have a look (what is include path in travis).<br></div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> <br> So<br> <br> Acked-By: Arne Schwabe <<a href="mailto:arne@rfc2549.org" target="_blank">arne@rfc2549.org</a>><br> <br> > <br> > James<br> > <br> > ---8>8>8><8<8<8---<br> > From: James Bottomley <James.Bottomley@HansenPartnership.com><br> > Subject: [PATCH] crypto_openssl: add include for openssl/conf.h<br> > <br> > Fix build failure on older versions of openssl.<br> > <br> > Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com><br> > ---<br> > src/openvpn/crypto_openssl.c | 1 +<br> > 1 file changed, 1 insertion(+)<br> > <br> > diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c<br> > index fd57edd2..94b6d85b 100644<br> > --- a/src/openvpn/crypto_openssl.c<br> > +++ b/src/openvpn/crypto_openssl.c<br> > @@ -43,6 +43,7 @@<br> > #include "crypto_backend.h"<br> > #include "openssl_compat.h"<br> > <br> > +#include <openssl/conf.h><br> > #include <openssl/des.h><br> > #include <openssl/err.h><br> > #include <openssl/evp.h><br> > <br> <br> <br> _______________________________________________<br> Openvpn-devel mailing list<br> <a href="mailto:Openvpn-devel@lists.sourceforge.net" target="_blank">Openvpn-devel@lists.sourceforge.net</a><br> <a href="https://lists.sourceforge.net/lists/listinfo/openvpn-devel" rel="noreferrer" target="_blank">https://lists.sourceforge.net/lists/listinfo/openvpn-devel</a><br> </blockquote></div></div>
Your patch has been applied to the master branch.
commit 25266ebba97d7f4169f902b8b0d3c38eaa4c43a4
Author: James Bottomley
Date: Sun Jun 7 15:10:58 2020 -0700
crypto_openssl: add include for openssl/conf.h
Signed-off-by: James Bottomley <James.Bottomley@HansenPartnership.com>
Acked-by: Arne Schwabe <arne@rfc2549.org>
Message-Id: <1591567858.4011.15.camel@HansenPartnership.com>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg19996.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 4ac77fde..fd57edd2 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -149,6 +149,11 @@ crypto_init_lib_engine(const char *engine_name) void crypto_init_lib(void) { +#if (OPENSSL_VERSION_NUMBER >= 0x10100000L) + OPENSSL_init_crypto(OPENSSL_INIT_LOAD_CONFIG, NULL); +#else + OPENSSL_config(NULL); +#endif /* * If you build the OpenSSL library and OpenVPN with * CRYPTO_MDEBUG, you will get a listing of OpenSSL