| Message ID | 1516423647-21932-1-git-send-email-selva.nair@gmail.com |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director2.mail.ord1d.rsapps.net ([172.30.191.6]) by backend31.mail.ord1d.rsapps.net (Dovecot) with LMTP id 0/WWEUzKYlqWGQAAgoeIoA for <patchwork@openvpn.net>; Fri, 19 Jan 2018 23:49:16 -0500 Received: from proxy12.mail.ord1d.rsapps.net ([172.30.191.6]) by director2.mail.ord1d.rsapps.net (Dovecot) with LMTP id M+eBEUzKYlqgJAAAgYhSiA ; Fri, 19 Jan 2018 23:49:16 -0500 Received: from smtp48.gate.ord1c ([172.30.191.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy12.mail.ord1d.rsapps.net (Dovecot) with LMTP id UogSEEzKYlqfSgAA7PHxkg ; Fri, 19 Jan 2018 23:49:16 -0500 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.34.181.88] Authentication-Results: smtp48.gate.ord1c.rsapps.net; iprev=pass policy.iprev="216.34.181.88"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (signature verification failed) header.d=gmail.com; dmarc=fail (p=none; dis=none) header.from=gmail.com X-Classification-ID: 4492b6d4-fd9d-11e7-898f-b8ca3a5fc420-1-1 Received: from [216.34.181.88] ([216.34.181.88:50550] helo=lists.sourceforge.net) by smtp48.gate.ord1c.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.1.56364 r(Core:4.2.1.14)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id D6/24-44524-C4AC26A5; Fri, 19 Jan 2018 23:49:16 -0500 Received: from localhost ([127.0.0.1] helo=sfs-ml-1.v29.ch3.sourceforge.com) by sfs-ml-1.v29.ch3.sourceforge.com with esmtp (Exim 4.89) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1ecl4D-0005qL-CV; Sat, 20 Jan 2018 04:47:45 +0000 Received: from sfi-mx-3.v28.ch3.sourceforge.com ([172.29.28.193] helo=mx.sourceforge.net) by sfs-ml-1.v29.ch3.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.89) (envelope-from <selva.nair@gmail.com>) id 1ecl4B-0005qF-GZ for openvpn-devel@lists.sourceforge.net; Sat, 20 Jan 2018 04:47:43 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Message-Id:Date:Subject:Cc:To:From:Sender:Reply-To: MIME-Version:Content-Type:Content-Transfer-Encoding:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=SQB55BPKwBM4eToeOWRt4MKgHfUBqHTrg6ImrFEkX1w=; b=B67OLc1tunC6s/HiM39MQ6yM9b 8cIrJY3mgfUsoSeRZXm9s2ogPHag+K4RSXIbD3OFpvXcU07ZPKEcxywU3bKDs9Lxdo3oyTEMac91B Q1beOfRPS1VzTQxLpvPHzwTcwot5IglAPgDpZhuzJ0dQWLj6ls7y/2m0b27+KLJ2XsQU=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Message-Id:Date:Subject:Cc:To:From:Sender:Reply-To:MIME-Version: Content-Type:Content-Transfer-Encoding:Content-ID:Content-Description: Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID: In-Reply-To:References:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=SQB55BPKwBM4eToeOWRt4MKgHfUBqHTrg6ImrFEkX1w=; b=UKr+IJ+fNBhOfn9AYY+BBw/g3x omPzTzelhOQTuPdCeTiHikUr/SAJeMRVQCfnDESpmakSFWiaAfLsv1pQ0rnZv/7nOWk59cJSft4v1 YyEsbonXkaOIunXRvA4emRfhXJRBY1tQ3/QFD/gk1Tjn8HWZjurpX1/HDOpUVcEqY3xI=; Received: from mail-io0-f194.google.com ([209.85.223.194]) by sfi-mx-3.v28.ch3.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES128-GCM-SHA256:128) (Exim 4.89) id 1ecl49-0001cp-B4 for openvpn-devel@lists.sourceforge.net; Sat, 20 Jan 2018 04:47:43 +0000 Received: by mail-io0-f194.google.com with SMTP id f89so4266928ioj.4 for <openvpn-devel@lists.sourceforge.net>; Fri, 19 Jan 2018 20:47:41 -0800 (PST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=from:to:cc:subject:date:message-id; bh=SQB55BPKwBM4eToeOWRt4MKgHfUBqHTrg6ImrFEkX1w=; b=BtAWfHChqiaafSle2PP3i5KImqswi5AmKBF+wBOI//h2+sHBCiYWZKLv3+jyjrNSkp c6CVkicBJ2ptE1954VJ4uY//SspgirMGWFmmEZ3pgeRuPjKWC24UFbl9U3uW5bslo444 ob4d1xtV7xMt2YqEKeawA9kPaVvJy53XK8j+YqejC/zFRk9BgsG+7PVCNhidlEUmL2mI 7Nw+mo/Q7wLixZYjrBGCjqhK9LuvbDCjjE72BOwf30ydnm1pi+xTdYSF1grfG03sX3yU ypbhBv13ecxFu0IKWFkAMlE7XqEWYsxiR6SzLyKfnmv7DdTcbsjcAAnaPtQsnqWoCJt5 DloA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:from:to:cc:subject:date:message-id; bh=SQB55BPKwBM4eToeOWRt4MKgHfUBqHTrg6ImrFEkX1w=; b=oeZv8eQzyxrbPEfGuZgJzMhCf+iGtMLvWu6SHE+p3l0cBhcxxNPtHCnmp4hhMii8FG Gd2iTUUuHTupM+Lg2Mv6deuJp3IsZ8Ytc30tgjilsZmYP/hJRJ8Lt3Yn51C7cgFcPkMC WFfqV/Pnxn9AeR1fuZcsFV9HkhiqFS84xMyeNoyHvYNt4nHvcBLBE/Tms6wzRhNgQOLE OZbUgKHX3t2bpUE4mUuuVelsFdM7mxbrMIIi3z/YOVuiWDCOO09+rj3GYmSUcok+jBNw SZMuPd1aIZJhjk1NKpKr6B5ueVqqvlQl8TU3hPT6OBjZWrd44DQ9tMJzRuNojQ8CMRwv WvVg== X-Gm-Message-State: AKwxytdMQONzuJF6ixXWWbxV9t/yMlaKHXDp3tiCW9qR0DvyCadzyoUK K/B7+ziTCuv38mkug5vTjfeA7rW9 X-Google-Smtp-Source: AH8x225J//OqULH5OxtH8IMUrs9e+n+VdBEnj/ehf2N8rdYl7qaiGugYGnojcg63/SRLdPKIWARxwA== X-Received: by 10.107.17.27 with SMTP id z27mr815115ioi.254.1516423655697; Fri, 19 Jan 2018 20:47:35 -0800 (PST) Received: from saturn.home.sansel.ca (CPE40167ea0e1c2-CM788df74daaa0.cpe.net.cable.rogers.com. [99.228.215.92]) by smtp.gmail.com with ESMTPSA id u128sm1564289itb.1.2018.01.19.20.47.34 (version=TLS1_2 cipher=ECDHE-RSA-AES128-SHA bits=128/128); Fri, 19 Jan 2018 20:47:35 -0800 (PST) From: selva.nair@gmail.com To: openvpn-devel@lists.sourceforge.net Date: Fri, 19 Jan 2018 23:47:27 -0500 Message-Id: <1516423647-21932-1-git-send-email-selva.nair@gmail.com> X-Mailer: git-send-email 2.1.4 X-Spam-Report: Spam Filtering performed by mx.sourceforge.net. See http://spamassassin.org/tag/ for more details. 0.0 FREEMAIL_FROM Sender email is commonly abused enduser mail provider (selva.nair[at]gmail.com) -0.0 RCVD_IN_DNSWL_NONE RBL: Sender listed at http://www.dnswl.org/, no trust [209.85.223.194 listed in list.dnswl.org] -0.0 SPF_PASS SPF: sender matches SPF record -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1ecl49-0001cp-B4 Subject: [Openvpn-devel] [PATCH] Add SSL_CTX_get_max_proto_version() not in openssl 1.0 X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
[Openvpn-devel] Add SSL_CTX_get_max_proto_version() not in openssl 1.0
|
|
Commit Message
Selva Nair
Jan. 19, 2018, 5:47 p.m. UTC
From: Selva Nair <selva.nair@gmail.com> - No change in functionality. This is used in a subsequent patch for extending TLS1.2 support with cryptoapicert Signed-off-by: Selva Nair <selva.nair@gmail.com> --- src/openvpn/openssl_compat.h | 23 +++++++++++++++++++++++ 1 file changed, 23 insertions(+)
Comments
Hi, On 20-01-18 05:47, selva.nair@gmail.com wrote: > From: Selva Nair <selva.nair@gmail.com> > > - No change in functionality. This is used in a subsequent > patch for extending TLS1.2 support with cryptoapicert > > Signed-off-by: Selva Nair <selva.nair@gmail.com> > --- > src/openvpn/openssl_compat.h | 23 +++++++++++++++++++++++ > 1 file changed, 23 insertions(+) > > diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h > index 9f1e92a..c94341a 100644 > --- a/src/openvpn/openssl_compat.h > +++ b/src/openvpn/openssl_compat.h > @@ -670,6 +670,29 @@ SSL_CTX_get_min_proto_version(SSL_CTX *ctx) > } > #endif /* SSL_CTX_get_min_proto_version */ > > +#ifndef SSL_CTX_get_max_proto_version > +/** Return the max SSL protocol version currently enabled in the context. > + * If no valid version >= TLS1.0 is found, return 0. */ > +static inline int > +SSL_CTX_get_max_proto_version(SSL_CTX *ctx) > +{ > + long sslopt = SSL_CTX_get_options(ctx); > + if (!(sslopt & SSL_OP_NO_TLSv1_2)) > + { > + return TLS1_2_VERSION; > + } > + if (!(sslopt & SSL_OP_NO_TLSv1_1)) > + { > + return TLS1_1_VERSION; > + } > + if (!(sslopt & SSL_OP_NO_TLSv1)) > + { > + return TLS1_VERSION; > + } > + return 0; > +} > +#endif /* SSL_CTX_get_max_proto_version */ > + > #ifndef SSL_CTX_set_min_proto_version > /** Mimics SSL_CTX_set_min_proto_version for OpenSSL < 1.1 */ > static inline int > Looks good and compiles fine. Acked-by: Steffan Karger <steffan@karger.me> -Steffan ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
Hi, On 20-01-18 10:50, Steffan Karger wrote: > On 20-01-18 05:47, selva.nair@gmail.com wrote: >> From: Selva Nair <selva.nair@gmail.com> >> >> - No change in functionality. This is used in a subsequent >> patch for extending TLS1.2 support with cryptoapicert >> >> Signed-off-by: Selva Nair <selva.nair@gmail.com> >> --- >> src/openvpn/openssl_compat.h | 23 +++++++++++++++++++++++ >> 1 file changed, 23 insertions(+) >> >> diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h >> index 9f1e92a..c94341a 100644 >> --- a/src/openvpn/openssl_compat.h >> +++ b/src/openvpn/openssl_compat.h >> @@ -670,6 +670,29 @@ SSL_CTX_get_min_proto_version(SSL_CTX *ctx) >> } >> #endif /* SSL_CTX_get_min_proto_version */ >> >> +#ifndef SSL_CTX_get_max_proto_version >> +/** Return the max SSL protocol version currently enabled in the context. >> + * If no valid version >= TLS1.0 is found, return 0. */ >> +static inline int >> +SSL_CTX_get_max_proto_version(SSL_CTX *ctx) >> +{ >> + long sslopt = SSL_CTX_get_options(ctx); >> + if (!(sslopt & SSL_OP_NO_TLSv1_2)) >> + { >> + return TLS1_2_VERSION; >> + } >> + if (!(sslopt & SSL_OP_NO_TLSv1_1)) >> + { >> + return TLS1_1_VERSION; >> + } >> + if (!(sslopt & SSL_OP_NO_TLSv1)) >> + { >> + return TLS1_VERSION; >> + } >> + return 0; >> +} >> +#endif /* SSL_CTX_get_max_proto_version */ >> + >> #ifndef SSL_CTX_set_min_proto_version >> /** Mimics SSL_CTX_set_min_proto_version for OpenSSL < 1.1 */ >> static inline int >> > > Looks good and compiles fine. > > Acked-by: Steffan Karger <steffan@karger.me> Sorry, one more thing: the current patch is only okay for master, as 2.4 still supports openssl 0.9.8 and 1.0.0, which do not have the SSL_OP_NO_TLSv1_1 and SSL_OP_NO_TLSv1_2 defines (the TLSx_VERSION ones *are* available though). If you want this patch backported to release/2.4, it needs #ifdefs like get_min_proto_version has. -Steffan ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
Hi, On Sat, Jan 20, 2018 at 5:14 AM, Steffan Karger <steffan@karger.me> wrote: > Hi, > > On 20-01-18 10:50, Steffan Karger wrote: >> On 20-01-18 05:47, selva.nair@gmail.com wrote: >>> From: Selva Nair <selva.nair@gmail.com> >>> >>> - No change in functionality. This is used in a subsequent >>> patch for extending TLS1.2 support with cryptoapicert >>> >>> Signed-off-by: Selva Nair <selva.nair@gmail.com> >>> --- >>> src/openvpn/openssl_compat.h | 23 +++++++++++++++++++++++ >>> 1 file changed, 23 insertions(+) >>> >>> diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h >>> index 9f1e92a..c94341a 100644 >>> --- a/src/openvpn/openssl_compat.h >>> +++ b/src/openvpn/openssl_compat.h >>> @@ -670,6 +670,29 @@ SSL_CTX_get_min_proto_version(SSL_CTX *ctx) >>> } >>> #endif /* SSL_CTX_get_min_proto_version */ >>> >>> +#ifndef SSL_CTX_get_max_proto_version >>> +/** Return the max SSL protocol version currently enabled in the context. >>> + * If no valid version >= TLS1.0 is found, return 0. */ >>> +static inline int >>> +SSL_CTX_get_max_proto_version(SSL_CTX *ctx) >>> +{ >>> + long sslopt = SSL_CTX_get_options(ctx); >>> + if (!(sslopt & SSL_OP_NO_TLSv1_2)) >>> + { >>> + return TLS1_2_VERSION; >>> + } >>> + if (!(sslopt & SSL_OP_NO_TLSv1_1)) >>> + { >>> + return TLS1_1_VERSION; >>> + } >>> + if (!(sslopt & SSL_OP_NO_TLSv1)) >>> + { >>> + return TLS1_VERSION; >>> + } >>> + return 0; >>> +} >>> +#endif /* SSL_CTX_get_max_proto_version */ >>> + >>> #ifndef SSL_CTX_set_min_proto_version >>> /** Mimics SSL_CTX_set_min_proto_version for OpenSSL < 1.1 */ >>> static inline int >>> >> >> Looks good and compiles fine. >> >> Acked-by: Steffan Karger <steffan@karger.me> > > Sorry, one more thing: the current patch is only okay for master, as > 2.4 still supports openssl 0.9.8 and 1.0.0, which do not have the > SSL_OP_NO_TLSv1_1 and SSL_OP_NO_TLSv1_2 defines (the TLSx_VERSION ones > *are* available though). If you want this patch backported to > release/2.4, it needs #ifdefs like get_min_proto_version has. Yeah, I meant it to go into master only (hence no ifdefs). Is it good to have it in 2.4 too? If so I will send a back-ported patch. Selva ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
Your patch has been applied to the master branch.
commit 9e272106029a41b2110c10334ba8cae0f4afb1b4
Author: Selva Nair
Date: Fri Jan 19 23:47:27 2018 -0500
Add SSL_CTX_get_max_proto_version() not in openssl 1.0
Signed-off-by: Selva Nair <selva.nair@gmail.com>
Acked-by: Steffan Karger <steffan.karger@fox-it.com>
Message-Id: <1516423647-21932-1-git-send-email-selva.nair@gmail.com>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg16287.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
------------------------------------------------------------------------------
Check out the vibrant tech community on one of the world's most
engaging tech sites, Slashdot.org! http://sdm.link/slashdot
Hi, If/when the TLS1.2+ support for cryptoapicert is ready for merge, is it a candidate for 2.4? Technically its a new feature but considering the "popular belief" that TLS1.1 needs to be shunned, and 2.5 is still far away, its worth considering.. In that case this patch would need to be backported to 2.4, so good to know what's the general consensus. Thanks, Selva ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
Hi On Sat, Jan 20, 2018 at 09:05:50AM -0500, Selva Nair wrote: > If/when the TLS1.2+ support for cryptoapicert is ready for merge, is > it a candidate for 2.4? Technically its a new feature but considering > the "popular belief" that TLS1.1 needs to be shunned, and 2.5 is still > far away, its worth considering.. > > In that case this patch would need to be backported to 2.4, so good to > know what's the general consensus. I would argue that TLS 1.2 is officially supported by 2.4, and as such it's a bug if cryptoapicert doesn't :-) Given that the changes are fairly well localized and will not affect other platforms, and are likely to not affect users that do not use cryptoapicert, I would tend to "make sure that all we offer works with TLS 1.2" -> include in 2.4 But I let Steffan or David overrule me here if they find the patch too intrusive. gert
Hi, On 20-01-18 17:52, Gert Doering wrote: > On Sat, Jan 20, 2018 at 09:05:50AM -0500, Selva Nair wrote: >> If/when the TLS1.2+ support for cryptoapicert is ready for merge, is >> it a candidate for 2.4? Technically its a new feature but considering >> the "popular belief" that TLS1.1 needs to be shunned, and 2.5 is still >> far away, its worth considering.. >> >> In that case this patch would need to be backported to 2.4, so good to >> know what's the general consensus. > > I would argue that TLS 1.2 is officially supported by 2.4, and as such > it's a bug if cryptoapicert doesn't :-) > > Given that the changes are fairly well localized and will not affect > other platforms, and are likely to not affect users that do not use > cryptoapicert, I would tend to "make sure that all we offer works with > TLS 1.2" -> include in 2.4 Completely agree. I would like to see this backported to 2.4. -Steffan ------------------------------------------------------------------------------ Check out the vibrant tech community on one of the world's most engaging tech sites, Slashdot.org! http://sdm.link/slashdot
diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h index 9f1e92a..c94341a 100644 --- a/src/openvpn/openssl_compat.h +++ b/src/openvpn/openssl_compat.h @@ -670,6 +670,29 @@ SSL_CTX_get_min_proto_version(SSL_CTX *ctx) } #endif /* SSL_CTX_get_min_proto_version */ +#ifndef SSL_CTX_get_max_proto_version +/** Return the max SSL protocol version currently enabled in the context. + * If no valid version >= TLS1.0 is found, return 0. */ +static inline int +SSL_CTX_get_max_proto_version(SSL_CTX *ctx) +{ + long sslopt = SSL_CTX_get_options(ctx); + if (!(sslopt & SSL_OP_NO_TLSv1_2)) + { + return TLS1_2_VERSION; + } + if (!(sslopt & SSL_OP_NO_TLSv1_1)) + { + return TLS1_1_VERSION; + } + if (!(sslopt & SSL_OP_NO_TLSv1)) + { + return TLS1_VERSION; + } + return 0; +} +#endif /* SSL_CTX_get_max_proto_version */ + #ifndef SSL_CTX_set_min_proto_version /** Mimics SSL_CTX_set_min_proto_version for OpenSSL < 1.1 */ static inline int