| Message ID | CAFHpkQFzOBMUC+qX7vV8jeHxg2MdP6_DCwiUZ=seX7r3DE=cBg@mail.gmail.com |
|---|---|
| State | Rejected |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director9.mail.ord1d.rsapps.net ([172.30.191.6]) by backend30.mail.ord1d.rsapps.net with LMTP id aBJVCDxiR2C1LwAAIUCqbw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 09 Mar 2021 06:55:40 -0500 Received: from proxy4.mail.ord1d.rsapps.net ([172.30.191.6]) by director9.mail.ord1d.rsapps.net with LMTP id +OlCCDxiR2DwWgAAalYnBA (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 09 Mar 2021 06:55:40 -0500 Received: from smtp10.gate.ord1d ([172.30.191.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy4.mail.ord1d.rsapps.net with LMTPS id 0IL6BzxiR2CJZQAAiYrejw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 09 Mar 2021 06:55:40 -0500 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp10.gate.ord1d.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (signature verification failed) header.d=gmail.com; dmarc=fail (p=none; dis=none) header.from=gmail.com X-Suspicious-Flag: YES X-Classification-ID: 5df70b40-80ce-11eb-aa43-52540013bccb-1-1 Received: from [216.105.38.7] ([216.105.38.7:42444] helo=lists.sourceforge.net) by smtp10.gate.ord1d.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id 47/28-24416-B3267406; Tue, 09 Mar 2021 06:55:39 -0500 Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1lJawd-00060J-R7; Tue, 09 Mar 2021 11:54:35 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from <chipitsine@gmail.com>) id 1lJawc-00060C-18 for openvpn-devel@lists.sourceforge.net; Tue, 09 Mar 2021 11:54:34 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Type:To:Subject:Message-ID:Date:From: MIME-Version:Sender:Reply-To:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=RZTg69R0Yidc/OU6mdydV3de9OcMSKuYBS4W4SP3LE4=; b=AbOYsqmaw8yFZQ3iTG2z2x6C0J KG1zJ4fXxevTD5mEksh9O/p2sY0Nreqf+Wgx/lN0ta5IFp2aPeyBNkF+gJaVU0Rr1prENts1sYS3N YmoSWD7rS5v37/RuosH0qbClIWyKMBnPKns3/uJFSQN82NGHsmvsfbR2Xoglq21tnYb8=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Type:To:Subject:Message-ID:Date:From:MIME-Version:Sender:Reply-To :Cc:Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=RZTg69R0Yidc/OU6mdydV3de9OcMSKuYBS4W4SP3LE4=; b=U zb2erbPY+WEcEuYbToZ72GYXWBxuchR5buJb6COpeznc5zVPV3Js8vtYBQ+GECToh9pH2QKd1D+sz CQvGQbFnUc5Glvb17+ST0xTT7FkNMuWp9NVoVjHIB27rLCdDZnHR2OBV1397HrjWnUsVRj4lBQMII koHK72dREr8wzV68=; Received: from mail-qk1-f177.google.com ([209.85.222.177]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.92.2) id 1lJawY-003tih-IK for openvpn-devel@lists.sourceforge.net; Tue, 09 Mar 2021 11:54:33 +0000 Received: by mail-qk1-f177.google.com with SMTP id x10so12602139qkm.8 for <openvpn-devel@lists.sourceforge.net>; Tue, 09 Mar 2021 03:54:30 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=mime-version:from:date:message-id:subject:to; bh=RZTg69R0Yidc/OU6mdydV3de9OcMSKuYBS4W4SP3LE4=; b=rd1sB0+uKzgKIMAzHXXxbhJBl5QTZVhbbvBHQYr31Hbu7KQcvc3kS2G89qnicoRkBZ 6YOb+68vsxZhBEXUKQiC5zLN5u2Po6McJiy2lf90AOU6towGy5iisx2avZMqQYR6x7wQ aG2OAdMLplPnmp+HAyRCbQVdTqbTi+kxXpliL3bpZlY9gL8MT/iHlVjx8QqYaOkzzPyn 1GSqTfmY6YH8RsxZD6vPA/wgSEJXaJld9oX6nQunW2pFk1v0S2Am3kFdH1J9FvkYPvZD yRx03gQVVU6VZxGb+RjybHNR4dpLVvV3WmqyFyyn3aQcpp9T1ZuPXzXk5gIhQxKIXLyr /Jpg== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:mime-version:from:date:message-id:subject:to; bh=RZTg69R0Yidc/OU6mdydV3de9OcMSKuYBS4W4SP3LE4=; b=HhQPl5ynjcbXb6JytqXW+FgnkS/s2ohrqHneQnf1AQncJgQ44Y2fBrHxA91hqy67RH pAKEP3qZ1L92c5Me+AuR8KoRNV+FvDHa2p3RzPTO/cdGCN5VC5PvV7aoBZmgFdgELvXm SZAXC5vkR9wkGkcrGvnpdu9sFau7PbVDEzmDqjkXm3925cSC9Fc29xchmmqnb1p3tsSW HYAWb+Wztw9iXnFEeCgdAq3aHxZBcaoSZXkwsYYQ1Cbu+pZN/HJ8xCdtlSGMB1EQxeKa rdoyIsroau93bnADUBHYgHtrnbxTPm2ad81wyBon1YYGDEkB8Q4pCFEVjKlhTDsCy9BG GAXw== X-Gm-Message-State: AOAM530RQyhpJkBsu9KsynsZggBEhObxva5ues5TieBm+8fVO/5PWzGL ZN1qYZsWLAsqdovqYrhsgWsIt1VpvfshW/tHJ1hvfkd0Jew= X-Google-Smtp-Source: ABdhPJwi5/Zmie+TSQaSJskqcBI6muucwVvL1RSBGYyOfoL4sQtlmblEUhcCkmJTtlOlbLXlkQ2sX3EYo2JAiymB3JQ= X-Received: by 2002:a37:9a96:: with SMTP id c144mr25394953qke.221.1615290864533; Tue, 09 Mar 2021 03:54:24 -0800 (PST) MIME-Version: 1.0 From: =?utf-8?b?0JjQu9GM0Y8g0KjQuNC/0LjRhtC40L0=?= <chipitsine@gmail.com> Date: Tue, 9 Mar 2021 16:54:13 +0500 Message-ID: <CAFHpkQFzOBMUC+qX7vV8jeHxg2MdP6_DCwiUZ=seX7r3DE=cBg@mail.gmail.com> To: openvpn-devel <openvpn-devel@lists.sourceforge.net> X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (chipitsine[at]gmail.com) -0.0 RCVD_IN_MSPIKE_H2 RBL: Average reputation (+2) [209.85.222.177 listed in wl.mailspike.net] -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at https://www.dnswl.org/, no trust [209.85.222.177 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record 1.0 HTML_MESSAGE BODY: HTML included in message -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid X-Headers-End: 1lJawY-003tih-IK Subject: [Openvpn-devel] using openssl feature wherever possible X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Content-Type: multipart/mixed; boundary="===============6887481428676423589==" Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
[Openvpn-devel] using openssl feature wherever possible
|
|
Commit Message
Илья Шипицин
March 9, 2021, 12:54 a.m. UTC
Hello, if nobody minds, I can send several patches that eliminates comparison of OPENSSL_VERSION, for example Ilya
Comments
Hi, On Tue, Mar 09, 2021 at 04:54:13PM +0500, ???????? ?????????????? wrote: > if nobody minds, I can send several patches that eliminates comparison of > OPENSSL_VERSION, for example We do mind. They are coded this way on purpose - so when we drop support for OpenSSL before 1.1.0, it is clear from the code which sections can be removed completely. gert
вт, 9 мар. 2021 г. в 17:47, Gert Doering <gert@greenie.muc.de>: > Hi, > > On Tue, Mar 09, 2021 at 04:54:13PM +0500, ???????? ?????????????? wrote: > > if nobody minds, I can send several patches that eliminates comparison of > > OPENSSL_VERSION, for example > > We do mind. They are coded this way on purpose - so when we drop support > for OpenSSL before 1.1.0, it is clear from the code which sections can > it is not much fun to catch things like https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h (BoringSSL claims itself as 1.1.0, accidentally decided "I'm 1.1.1 now") > be removed completely. > > gert > -- > "If was one thing all people took for granted, was conviction that if you > feed honest figures into a computer, honest figures come out. Never > doubted > it myself till I met a computer with a sense of humor." > Robert A. Heinlein, The Moon is a Harsh > Mistress > > Gert Doering - Munich, Germany > gert@greenie.muc.de > <div dir="ltr"><div dir="ltr"><br></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">вт, 9 мар. 2021 г. в 17:47, Gert Doering <<a href="mailto:gert@greenie.muc.de">gert@greenie.muc.de</a>>:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi,<br> <br> On Tue, Mar 09, 2021 at 04:54:13PM +0500, ???????? ?????????????? wrote:<br> > if nobody minds, I can send several patches that eliminates comparison of<br> > OPENSSL_VERSION, for example<br> <br> We do mind. They are coded this way on purpose - so when we drop support<br> for OpenSSL before 1.1.0, it is clear from the code which sections can<br></blockquote><div><br></div><div>it is not much fun to catch things like</div><div><a href="https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h">https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h</a></div><div><br></div><div>(BoringSSL claims itself as 1.1.0, accidentally decided "I'm 1.1.1 now")<br></div><div><br></div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> be removed completely.<br> <br> gert<br> -- <br> "If was one thing all people took for granted, was conviction that if you <br> feed honest figures into a computer, honest figures come out. Never doubted <br> it myself till I met a computer with a sense of humor."<br> Robert A. Heinlein, The Moon is a Harsh Mistress<br> <br> Gert Doering - Munich, Germany <a href="mailto:gert@greenie.muc.de" target="_blank">gert@greenie.muc.de</a><br> </blockquote></div></div>
Hi, On Tue, Mar 09, 2021 at 05:52:12PM +0500, ???????? ?????????????? wrote: > > On Tue, Mar 09, 2021 at 04:54:13PM +0500, ???????? ?????????????? wrote: > > > if nobody minds, I can send several patches that eliminates comparison of > > > OPENSSL_VERSION, for example > > > > We do mind. They are coded this way on purpose - so when we drop support > > for OpenSSL before 1.1.0, it is clear from the code which sections can > > it is not much fun to catch things like > https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h > > (BoringSSL claims itself as 1.1.0, accidentally decided "I'm 1.1.1 now") We do not support BoringSSL. (Or any other SSL library that claims "I am compatible with OpenSSL 1.1.1" but isn't, really - which is why the LibreSSL adjustments are always very minimal) We sort-of-support LibreSSL because it is the system SSL library on OpenBSD. Otherwise, the answer would be the same as for BoringSSL. gert
we may keep combo. both #ifdef EVP_PKEY_TLS1_PRF and comment related to supported openssl versions (to drop support if we decide) вт, 9 мар. 2021 г. в 17:56, Gert Doering <gert@greenie.muc.de>: > Hi, > > On Tue, Mar 09, 2021 at 05:52:12PM +0500, ???????? ?????????????? wrote: > > > On Tue, Mar 09, 2021 at 04:54:13PM +0500, ???????? ?????????????? > wrote: > > > > if nobody minds, I can send several patches that eliminates > comparison of > > > > OPENSSL_VERSION, for example > > > > > > We do mind. They are coded this way on purpose - so when we drop > support > > > for OpenSSL before 1.1.0, it is clear from the code which sections can > > > > it is not much fun to catch things like > > > https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h > > > > (BoringSSL claims itself as 1.1.0, accidentally decided "I'm 1.1.1 now") > > We do not support BoringSSL. > > (Or any other SSL library that claims "I am compatible with OpenSSL 1.1.1" > but isn't, really - which is why the LibreSSL adjustments are always very > minimal) > > We sort-of-support LibreSSL because it is the system SSL library on > OpenBSD. Otherwise, the answer would be the same as for BoringSSL. > > gert > -- > "If was one thing all people took for granted, was conviction that if you > feed honest figures into a computer, honest figures come out. Never > doubted > it myself till I met a computer with a sense of humor." > Robert A. Heinlein, The Moon is a Harsh > Mistress > > Gert Doering - Munich, Germany > gert@greenie.muc.de > <div dir="ltr"><div>we may keep combo.</div><div>both #ifdef EVP_PKEY_TLS1_PRF and comment related to supported openssl versions (to drop support if we decide)<br></div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">вт, 9 мар. 2021 г. в 17:56, Gert Doering <<a href="mailto:gert@greenie.muc.de">gert@greenie.muc.de</a>>:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi,<br> <br> On Tue, Mar 09, 2021 at 05:52:12PM +0500, ???????? ?????????????? wrote:<br> > > On Tue, Mar 09, 2021 at 04:54:13PM +0500, ???????? ?????????????? wrote:<br> > > > if nobody minds, I can send several patches that eliminates comparison of<br> > > > OPENSSL_VERSION, for example<br> > ><br> > > We do mind. They are coded this way on purpose - so when we drop support<br> > > for OpenSSL before 1.1.0, it is clear from the code which sections can<br> > <br> > it is not much fun to catch things like<br> > <a href="https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h" rel="noreferrer" target="_blank">https://boringssl.googlesource.com/boringssl/+/49e9f67d8b7cbeb3953b5548ad1009d15947a523%5E%21/include/openssl/base.h</a><br> > <br> > (BoringSSL claims itself as 1.1.0, accidentally decided "I'm 1.1.1 now")<br> <br> We do not support BoringSSL.<br> <br> (Or any other SSL library that claims "I am compatible with OpenSSL 1.1.1"<br> but isn't, really - which is why the LibreSSL adjustments are always very<br> minimal)<br> <br> We sort-of-support LibreSSL because it is the system SSL library on <br> OpenBSD. Otherwise, the answer would be the same as for BoringSSL.<br> <br> gert<br> -- <br> "If was one thing all people took for granted, was conviction that if you <br> feed honest figures into a computer, honest figures come out. Never doubted <br> it myself till I met a computer with a sense of humor."<br> Robert A. Heinlein, The Moon is a Harsh Mistress<br> <br> Gert Doering - Munich, Germany <a href="mailto:gert@greenie.muc.de" target="_blank">gert@greenie.muc.de</a><br> </blockquote></div>
Hi, On Tue, Mar 09, 2021 at 06:26:08PM +0500, ???????? ?????????????? wrote: > we may keep combo. > both #ifdef EVP_PKEY_TLS1_PRF and comment related to supported openssl > versions (to drop support if we decide) We could, but we won't. (I can see the benefits, but I'm not the one maintaining these code bits - Arne is, and he has stated a clear preference on doing it the way it is currently done) gert
On 09/03/2021 14:28, Gert Doering wrote: > Hi, > > On Tue, Mar 09, 2021 at 06:26:08PM +0500, ???????? ?????????????? wrote: >> we may keep combo. >> both #ifdef EVP_PKEY_TLS1_PRF and comment related to supported openssl >> versions (to drop support if we decide) > > We could, but we won't. > > (I can see the benefits, but I'm not the one maintaining these code > bits - Arne is, and he has stated a clear preference on doing it the > way it is currently done) > +1 ... This is really the right approach. Either these "wannabe OpenSSL" libraries gets their act together and really do fully support the OpenSSL API they claim to be compliant to - and everything will work out just fine. Otherwise they break with OpenVPN. If they start playing fun games with the version macros originally defined by OpenSSL, it will break. It's that easy. We won't spend (waste) time playing their compatibility games. If it breaks, it's their bug not ours.
Am 09.03.21 um 12:54 schrieb Илья Шипицин: > Hello, > > if nobody minds, I can send several patches that eliminates comparison > of OPENSSL_VERSION, for example > > > diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c > index 49698e4b..316cca6f 100644 > --- a/src/openvpn/crypto_openssl.c > +++ b/src/openvpn/crypto_openssl.c > @@ -51,7 +51,8 @@ > #include <openssl/rand.h> > #include <openssl/ssl.h> > > -#if (OPENSSL_VERSION_NUMBER >= 0x10100000L) && > !defined(LIBRESSL_VERSION_NUMBER) > +#ifdef EVP_PKEY_TLS1_PRF > #include <openssl/kdf.h> > #endif I do not really see a benefit here other than it a lot harder to drop support for OpenSSL 1.0.2 and not leaving dead code in the repository. The macro currently tells me exactly why the code is still there. The EVP_PKEY_TLS1_PRF is not clear. Is this an optional OpenSSL? Is it for an old version? Arne
diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 49698e4b..316cca6f 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -51,7 +51,8 @@ #include <openssl/rand.h> #include <openssl/ssl.h> -#if (OPENSSL_VERSION_NUMBER >= 0x10100000L) && !defined(LIBRESSL_VERSION_NUMBER) +#ifdef EVP_PKEY_TLS1_PRF #include <openssl/kdf.h> #endif