| Message ID | E1lSJph-0004I0-FL@sfs-ml-2.v29.lw.sourceforge.com |
|---|---|
| State | Changes Requested |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director13.mail.ord1d.rsapps.net ([172.30.191.6]) by backend30.mail.ord1d.rsapps.net with LMTP id GKxqIQQcZ2DeNQAAIUCqbw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Fri, 02 Apr 2021 09:28:36 -0400 Received: from proxy10.mail.ord1d.rsapps.net ([172.30.191.6]) by director13.mail.ord1d.rsapps.net with LMTP id MDopIQQcZ2DTUAAA91zNiA (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Fri, 02 Apr 2021 09:28:36 -0400 Received: from smtp38.gate.ord1d ([172.30.191.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy10.mail.ord1d.rsapps.net with LMTPS id sDvLIAQcZ2DJYwAAfSg8FQ (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Fri, 02 Apr 2021 09:28:36 -0400 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp38.gate.ord1d.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (key not found in DNS) header.d=foxcrypto.com; dmarc=fail (p=none; dis=none) header.from=foxcrypto.com X-Suspicious-Flag: YES X-Classification-ID: 53abbd56-93b7-11eb-8115-525400f6a58b-1-1 Received: from [216.105.38.7] ([216.105.38.7:42836] helo=lists.sourceforge.net) by smtp38.gate.ord1d.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id E4/B7-02713-40C17606; Fri, 02 Apr 2021 09:28:36 -0400 Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com) by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.92.3) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1lSJph-0004I0-FL; Fri, 02 Apr 2021 13:27:29 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.3) (envelope-from <maximilian.fillinger@foxcrypto.com>) id 1lSJpg-0004Ht-1d for openvpn-devel@lists.sourceforge.net; Fri, 02 Apr 2021 13:27:28 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Type:MIME-Version:Date:Subject:To:From: Sender:Reply-To:Message-ID:Cc:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=vKzfEjRjek/z+2QWciRk8cSDIEK3r8UG1lI4LkEho2k=; b=m5EHqpIeseYUngGjTngp2tQhJE kxf1/ZP+ILnLGFvUOvCwB1nU6wBSAptxx8zxfNfq1qYPZRyk9im/aBaWF2HcNEade0KXxg6kxbnrM iFeVU5qF6tnMTgsUe1pYMNICrSqNH/DI1rGXRfSUcKnPKbFAdZDqQea49ItdHVNItNLc=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Type:MIME-Version:Date:Subject:To:From:Sender:Reply-To:Message-ID :Cc:Content-Transfer-Encoding:Content-ID:Content-Description:Resent-Date: Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=vKzfEjRjek/z+2QWciRk8cSDIEK3r8UG1lI4LkEho2k=; b=A TuBFTpbdkErn+XWxV1/yixCDG/dX5Na+Lgq8QRulr5YKI2gqwDkSq7QCLZbGcwMgH9aXg4y2Wx0lI Z+VEy2H8Z6imUCQz+db+5Xn9rRomamFgWHJ76ps+X7MfEUtaTKnAtES7EkyCNHf/JcBMBdTdTTo7F SGVh5wR5yCizaqWI=; Received: from nl-dft-mx-01.fox-it.com ([178.250.144.135]) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.3) id 1lSJp7-0001VR-AZ for openvpn-devel@lists.sourceforge.net; Fri, 02 Apr 2021 13:27:27 +0000 From: Max Fillinger <maximilian.fillinger@foxcrypto.com> To: <openvpn-devel@lists.sourceforge.net> Date: Fri, 2 Apr 2021 15:26:23 +0200 X-Mailer: git-send-email 2.11.0 MIME-Version: 1.0 X-ClientProxiedBy: FOXDFT1EX01.FOX.local (10.0.0.129) To FOXDFT1EX01.FOX.local (10.0.0.129) DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; d=foxcrypto.com; s=NL-DFT-MX-01; c=relaxed/relaxed; h=from:to:subject:date:mime-version:content-type; bh=vKzfEjRjek/z+2QWciRk8cSDIEK3r8UG1lI4LkEho2k=; b=2JD7MROCiSzqweWhmaC4XNNfuYp5KW8FRq3kUyhTT7l1dIUtUp7zvnULWv/poLMa9qIGAURE9kRl E4vF71fJNNHfGRmYVP4bqqjtteEsDWgQ42wfmH1VNSwhsSnm4hay1KDMU9+6ZLTnH/wCL9aiS8m5 ybQLQflJdPT2BcXUSujrELCSAMma9DXPcjsrlq8CayShwT4eoyZS54BWFkv617FZNDk4GeNLGw6g v2nsA1/RWfFsO4wqgYMxqzEry3y4ei4bN38fWa9b0sxrc0awOUVMG5Qr6feRuPDqPwh0x6Z1HkXl jcdo+qRO7bcLM9OlnVVgI1P2TOj8zefVtps6fQ== X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. 0.0 URIBL_BLOCKED ADMINISTRATOR NOTICE: The query to URIBL was blocked. See http://wiki.apache.org/spamassassin/DnsBlocklists#dnsbl-block for more information. [URIs: fox-it.com] 0.0 TIME_LIMIT_EXCEEDED Exceeded time limit / deadline X-Headers-End: 1lSJp7-0001VR-AZ Subject: [Openvpn-devel] [PATCH] Change CTR DRBG update function call to new mbedtls 2.16.0 API X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: openvpn-devel-bounces@lists.sourceforge.net Message-Id: <E1lSJph-0004I0-FL@sfs-ml-2.v29.lw.sourceforge.com> X-getmail-retrieved-from-mailbox: Inbox |
| Series |
[Openvpn-devel] Change CTR DRBG update function call to new mbedtls 2.16.0 API
|
|
Commit Message
Maximilian Fillinger
April 2, 2021, 2:26 a.m. UTC
From: Uipko Berghuis <uipko.berghuis@fox-it.com>
In mbedtls 2.16.0 mbedtls_ctr_drbg_update() changed to
mbedtls_ctr_drbg_update_ret(). Change the function name and handle
the new return value error code.
---
src/openvpn/ssl_mbedtls.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
Comments
Am 02.04.21 um 15:26 schrieb Max Fillinger: > From: Uipko Berghuis <uipko.berghuis@fox-it.com> > > In mbedtls 2.16.0 mbedtls_ctr_drbg_update() changed to > mbedtls_ctr_drbg_update_ret(). Change the function name and handle > the new return value error code. > --- > src/openvpn/ssl_mbedtls.c | 5 ++++- > 1 file changed, 4 insertions(+), 1 deletion(-) > > diff --git a/src/openvpn/ssl_mbedtls.c b/src/openvpn/ssl_mbedtls.c > index 5d7af351..56e9f045 100644 > --- a/src/openvpn/ssl_mbedtls.c > +++ b/src/openvpn/ssl_mbedtls.c > @@ -950,7 +950,10 @@ tls_ctx_personalise_random(struct tls_root_ctx *ctx) > > if (0 != memcmp(old_sha256_hash, sha256_hash, sizeof(sha256_hash))) > { > - mbedtls_ctr_drbg_update(cd_ctx, sha256_hash, 32); > + if (!mbed_ok(mbedtls_ctr_drbg_update_ret(cd_ctx, sha256_hash, 32))) > + { > + msg(M_WARN, "WARNING: failed to personalise random, could not update CTR_DRBG"); > + } > memcpy(old_sha256_hash, sha256_hash, sizeof(old_sha256_hash)); > } > } > This change will break compilation with anything that is < 2.16.0. Arne
> Am 02.04.21 um 15:26 schrieb Max Fillinger: > > From: Uipko Berghuis <uipko.berghuis@fox-it.com> > > > > In mbedtls 2.16.0 mbedtls_ctr_drbg_update() changed to > > mbedtls_ctr_drbg_update_ret(). Change the function name and handle the > > new return value error code. > > --- > > src/openvpn/ssl_mbedtls.c | 5 ++++- > > 1 file changed, 4 insertions(+), 1 deletion(-) > > > > diff --git a/src/openvpn/ssl_mbedtls.c b/src/openvpn/ssl_mbedtls.c > > index 5d7af351..56e9f045 100644 > > --- a/src/openvpn/ssl_mbedtls.c > > +++ b/src/openvpn/ssl_mbedtls.c > > @@ -950,7 +950,10 @@ tls_ctx_personalise_random(struct tls_root_ctx > > *ctx) > > > > if (0 != memcmp(old_sha256_hash, sha256_hash, > sizeof(sha256_hash))) > > { > > - mbedtls_ctr_drbg_update(cd_ctx, sha256_hash, 32); > > + if (!mbed_ok(mbedtls_ctr_drbg_update_ret(cd_ctx, > sha256_hash, 32))) > > + { > > + msg(M_WARN, "WARNING: failed to personalise random, > could not update CTR_DRBG"); > > + } > > memcpy(old_sha256_hash, sha256_hash, > sizeof(old_sha256_hash)); > > } > > } > > > > This change will break compilation with anything that is < 2.16.0. This function is deprecated in 2.16. I don't mind keeping this change to OpenVPN-NL for now, but for future reference, what's the best solution when a new version of mbedtls removes the function?
Hi, On Tue, Apr 06, 2021 at 10:55:52AM +0000, Maximilian Fillinger wrote: > > This change will break compilation with anything that is < 2.16.0. > > This function is deprecated in 2.16. I don't mind keeping this change to > OpenVPN-NL for now, but for future reference, what's the best solution > when a new version of mbedtls removes the function? It's still available in 2.26.0... so when they decide to really remove it, we'll have to see - what is the oldest mbedtls version we aim to support - if that is "2.16 or later", we can just apply the change as is - if that is "before 2.16", we need to add compat code - either #ifdef on mbedTLS version (if possible), or adding function detection to configure.ac (as we do for OpenSSL). Both is somewhat annoying. Now... what *is* the oldest mbedtls version we should reasonably support? For OpenSSL, we're stuck to 1.0.2 for the time being as that's still the primary (and bugfix-backported) version on FreeBSD 11 and on RHEL versions still supported. For mbedTLS I have no idea. gert
Hi, On 06/04/2021 13:14, Gert Doering wrote: > Now... what *is* the oldest mbedtls version we should reasonably support? > > For OpenSSL, we're stuck to 1.0.2 for the time being as that's still > the primary (and bugfix-backported) version on FreeBSD 11 and on RHEL > versions still supported. For mbedTLS I have no idea. Good question. I was wondering the same. Debian 10 (stable) is on mbedtls-2.16.0 CentOS 8 is on mbedtls-2.16.9 Fedora EPEL 8 (and up to Fedora 35) is on mbedtls-2.16.9 ** Ubuntu 18.04 is on mbedtls-2.8.0 ** Ubuntu 20.04 is on mbedtls-2.16.4 At this point I believe that assuming mbedtls >= 2.16.0 is meaningful. Distros shipping something older are probably not going to ship a recent OpenVPN either. Opinions? Cheers,
Am 06.04.21 um 13:51 schrieb Antonio Quartulli: > Hi, > > On 06/04/2021 13:14, Gert Doering wrote: >> Now... what *is* the oldest mbedtls version we should reasonably support? >> >> For OpenSSL, we're stuck to 1.0.2 for the time being as that's still >> the primary (and bugfix-backported) version on FreeBSD 11 and on RHEL >> versions still supported. For mbedTLS I have no idea. > > Good question. I was wondering the same. > > Debian 10 (stable) is on mbedtls-2.16.0 > CentOS 8 is on mbedtls-2.16.9 > Fedora EPEL 8 (and up to Fedora 35) is on mbedtls-2.16.9 > > ** Ubuntu 18.04 is on mbedtls-2.8.0 ** > Ubuntu 20.04 is on mbedtls-2.16.4 > > At this point I believe that assuming mbedtls >= 2.16.0 is meaningful. > > Distros shipping something older are probably not going to ship a recent > OpenVPN either. > > Opinions? > If we adjust the minimum mbed TLS version we should also change the check in configure.ac that checks for the minimum version as well. mbed TLS 2.16.0 has been released end of 2018, so that version is "only" a bit over two years old. Currently mbed TLS 2.7 is still a supported LTS release, so if it is not too much effort, I think we should still support it. Arne
Hi, On 06-04-2021 12:55, Maximilian Fillinger wrote: >> Am 02.04.21 um 15:26 schrieb Max Fillinger: >>> From: Uipko Berghuis <uipko.berghuis@fox-it.com> >>> >>> In mbedtls 2.16.0 mbedtls_ctr_drbg_update() changed to >>> mbedtls_ctr_drbg_update_ret(). Change the function name and handle the >>> new return value error code. >>> --- >>> src/openvpn/ssl_mbedtls.c | 5 ++++- >>> 1 file changed, 4 insertions(+), 1 deletion(-) >>> >>> diff --git a/src/openvpn/ssl_mbedtls.c b/src/openvpn/ssl_mbedtls.c >>> index 5d7af351..56e9f045 100644 >>> --- a/src/openvpn/ssl_mbedtls.c >>> +++ b/src/openvpn/ssl_mbedtls.c >>> @@ -950,7 +950,10 @@ tls_ctx_personalise_random(struct tls_root_ctx >>> *ctx) >>> >>> if (0 != memcmp(old_sha256_hash, sha256_hash, >> sizeof(sha256_hash))) >>> { >>> - mbedtls_ctr_drbg_update(cd_ctx, sha256_hash, 32); >>> + if (!mbed_ok(mbedtls_ctr_drbg_update_ret(cd_ctx, >> sha256_hash, 32))) >>> + { >>> + msg(M_WARN, "WARNING: failed to personalise random, >> could not update CTR_DRBG"); >>> + } >>> memcpy(old_sha256_hash, sha256_hash, >> sizeof(old_sha256_hash)); >>> } >>> } >>> >> >> This change will break compilation with anything that is < 2.16.0. > > This function is deprecated in 2.16. I don't mind keeping this change to > OpenVPN-NL for now, but for future reference, what's the best solution > when a new version of mbedtls removes the function? I'd say add a compat-wrapper, like we have many for openssl. Possibly in compat-mbedtls.h (mimicing the openssl code) or just in crypto_mbedtls.h if we don't have many. Something like (untested/"pseudo"code): #if MBEDTLS_VERSION < 2.16 static inline int mbedtls_ctr_drbg_update_ret(ctx, h, len) { mbedtls_ctr_drbg_update(ctx, h, len); return 0; } #endif -Steffan
diff --git a/src/openvpn/ssl_mbedtls.c b/src/openvpn/ssl_mbedtls.c index 5d7af351..56e9f045 100644 --- a/src/openvpn/ssl_mbedtls.c +++ b/src/openvpn/ssl_mbedtls.c @@ -950,7 +950,10 @@ tls_ctx_personalise_random(struct tls_root_ctx *ctx) if (0 != memcmp(old_sha256_hash, sha256_hash, sizeof(sha256_hash))) { - mbedtls_ctr_drbg_update(cd_ctx, sha256_hash, 32); + if (!mbed_ok(mbedtls_ctr_drbg_update_ret(cd_ctx, sha256_hash, 32))) + { + msg(M_WARN, "WARNING: failed to personalise random, could not update CTR_DRBG"); + } memcpy(old_sha256_hash, sha256_hash, sizeof(old_sha256_hash)); } }