| Message ID | 20211019183127.614175-9-arne@rfc2549.org |
|---|---|
| State | Superseded |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director15.mail.ord1d.rsapps.net ([172.28.255.1]) by backend30.mail.ord1d.rsapps.net with LMTP id +M5rNjEPb2GNQgAAIUCqbw (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 19 Oct 2021 14:32:17 -0400 Received: from proxy4.mail.ord1c.rsapps.net ([172.28.255.1]) by director15.mail.ord1d.rsapps.net with LMTP id QOQnNjEPb2GeCQAAIcMcQg (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 19 Oct 2021 14:32:17 -0400 Received: from smtp38.gate.ord1c ([172.28.255.1]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy4.mail.ord1c.rsapps.net with LMTPS id 2L3dCTEPb2FScQAAjcXvpA (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Tue, 19 Oct 2021 14:32:17 -0400 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp38.gate.ord1c.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dmarc=none (p=nil; dis=none) header.from=rfc2549.org X-Suspicious-Flag: YES X-Classification-ID: e2a5b5d4-310a-11ec-9c72-5452007bdf16-1-1 Received: from [216.105.38.7] ([216.105.38.7:55612] helo=lists.sourceforge.net) by smtp38.gate.ord1c.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id D5/85-05813-03F0F616; Tue, 19 Oct 2021 14:32:17 -0400 Received: from [127.0.0.1] (helo=sfs-ml-1.v29.lw.sourceforge.com) by sfs-ml-1.v29.lw.sourceforge.com with esmtp (Exim 4.90_1) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1mctti-0006Z6-M2; Tue, 19 Oct 2021 18:31:38 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-1.v29.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.90_1) (envelope-from <arne@kamera.blinkt.de>) id 1mcttf-0006Xt-C7 for openvpn-devel@lists.sourceforge.net; Tue, 19 Oct 2021 18:31:35 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-Id:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=C91FIl/LLaKtMjMU4nxipqP9Dskf5NcqBqlPJIaAAnA=; b=gRnDujppEm+5fjgw3/3MOwANOV s0O1U/9zjl49aLbnerHtlTUV/NVKQkKEdzcTcH3C9l7GMeaWNNTilSZmzoln0KVKebF+mQO0deOMP XC6z2A0zmNdid4gOHuuhWzGBbRXgitilfjMNHyXQ39niky3gRg0ETO0ykAcLDDOIGpqg=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-Id: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=C91FIl/LLaKtMjMU4nxipqP9Dskf5NcqBqlPJIaAAnA=; b=eAZGLezfHWczPpdcBGtunU5A37 /qetEdlNSkiPzHV+cFi//FvPkoqA5fpQw33Ifk4acktCJ6haQnynKUTGvtd8V0/HlDkIh6z/K/DmE Mqx/7sswCno96KDE7ja1v3omuSWbmjamBR7GVmXaSWDOiEtHK491N12AjSbfxmFbDEuI=; Received: from mail.blinkt.de ([192.26.174.232]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.3) id 1mctte-006U09-J3 for openvpn-devel@lists.sourceforge.net; Tue, 19 Oct 2021 18:31:35 +0000 Received: from kamera.blinkt.de ([2001:638:502:390:20c:29ff:fec8:535c]) by mail.blinkt.de with smtp (Exim 4.94.2 (FreeBSD)) (envelope-from <arne@kamera.blinkt.de>) id 1mcttX-0008i0-Jt for openvpn-devel@lists.sourceforge.net; Tue, 19 Oct 2021 20:31:27 +0200 Received: (nullmailer pid 614247 invoked by uid 10006); Tue, 19 Oct 2021 18:31:28 -0000 From: Arne Schwabe <arne@rfc2549.org> To: openvpn-devel@lists.sourceforge.net Date: Tue, 19 Oct 2021 20:31:14 +0200 Message-Id: <20211019183127.614175-9-arne@rfc2549.org> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20211019183127.614175-1-arne@rfc2549.org> References: <20211019183127.614175-1-arne@rfc2549.org> MIME-Version: 1.0 X-Spam-Report: Spam detection software, running on the system "util-spamd-1.v13.lw.sourceforge.com", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: EC_Key methods are deprecated in OpenSSL 3.0. Use EVP_PKEY_get_group_name instead to query the EC group name from an EVP_PKEY and add a compatibility function for older OpenSSL versions. Signed-off-by: Arne Schwabe <arne@rfc2549.org> --- src/openvpn/openssl_compat.h | 42 ++++++++++++++++++++++++++++++++++++ src/openvpn/ssl_openssl.c | 14 ++++++------ 2 files changed, 50 insertions(+), [...] Content analysis details: (0.3 points, 6.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 0.2 HEADER_FROM_DIFFERENT_DOMAINS From and EnvelopeFrom 2nd level mail domains are different 0.0 SPF_HELO_NONE SPF: HELO does not publish an SPF Record 0.0 SPF_NONE SPF: sender does not publish an SPF Record X-Headers-End: 1mctte-006U09-J3 Subject: [Openvpn-devel] [PATCH v3 08/21] [OSSL 3.0] Use EVP_PKEY_get_group_name to query group name X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
OpenSSL 3.0 improvements for OpenVPN
|
|
Commit Message
Arne Schwabe
Oct. 19, 2021, 7:31 a.m. UTC
EC_Key methods are deprecated in OpenSSL 3.0. Use
EVP_PKEY_get_group_name instead to query the EC group name from an
EVP_PKEY and add a compatibility function for older OpenSSL versions.
Signed-off-by: Arne Schwabe <arne@rfc2549.org>
---
src/openvpn/openssl_compat.h | 42 ++++++++++++++++++++++++++++++++++++
src/openvpn/ssl_openssl.c | 14 ++++++------
2 files changed, 50 insertions(+), 6 deletions(-)
Comments
Hi, I had looked at v1 of this so easy: On Tue, Oct 19, 2021 at 2:31 PM Arne Schwabe <arne@rfc2549.org> wrote: > EC_Key methods are deprecated in OpenSSL 3.0. Use > EVP_PKEY_get_group_name instead to query the EC group name from an > EVP_PKEY and add a compatibility function for older OpenSSL versions. > > Signed-off-by: Arne Schwabe <arne@rfc2549.org> > --- > src/openvpn/openssl_compat.h | 42 ++++++++++++++++++++++++++++++++++++ > src/openvpn/ssl_openssl.c | 14 ++++++------ > 2 files changed, 50 insertions(+), 6 deletions(-) > > diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h > index ce8e2b360..dda47d76c 100644 > --- a/src/openvpn/openssl_compat.h > +++ b/src/openvpn/openssl_compat.h > @@ -718,4 +718,46 @@ SSL_CTX_set_max_proto_version(SSL_CTX *ctx, long > tls_ver_max) > return 1; > } > #endif /* if OPENSSL_VERSION_NUMBER < 0x10100000L && > !defined(ENABLE_CRYPTO_WOLFSSL) */ > + > +/* Functionality missing in 1.1.1 */ > +#if OPENSSL_VERSION_NUMBER < 0x30000000L && !defined(OPENSSL_NO_EC) > + > +/* Note that this is not a perfect emulation of the new function but > + * is good enough for our case of printing certificate details during > + * handshake */ > +static inline > +int EVP_PKEY_get_group_name(EVP_PKEY *pkey, char *gname, size_t gname_sz, > + size_t *gname_len) > +{ > + const EC_KEY* ec = EVP_PKEY_get0_EC_KEY(pkey); > + if (ec == NULL) > + { > + return 0; > + } > + const EC_GROUP* group = EC_KEY_get0_group(ec); > + int nid = EC_GROUP_get_curve_name(group); > + > + if (nid == 0) > + { > + return 0; > + } > + const char *curve = OBJ_nid2sn(nid); > I would have preferred a curve !=NULL check here. Though very unlikely to happen, we do not want a segfault in strncpy. + > + strncpynt(gname, curve, gname_sz); > + *gname_len = min_int(strlen(curve), gname_sz); > gname_sz - 1 ? That said, our strncpynt ensures that strlen(curve) will be less than gname_sz, so this could be just strlen(curve) or left as is. > + return 1; > +} > +#endif > + > +/** Mimics SSL_CTX_new_ex for OpenSSL < 3 */ > +#if OPENSSL_VERSION_NUMBER < 0x30000000L > +static inline SSL_CTX * > +SSL_CTX_new_ex(void *libctx, const char *propq, const SSL_METHOD *method) > This looks like a spill-over from one of my xkey patches --- "git commit -p" malfunction? Unless the "unused functions police" objects, we can keep it. +{ > + (void) libctx; > + (void) propq; > + return SSL_CTX_new(method); > +} > +#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */ > + > #endif /* OPENSSL_COMPAT_H_ */ > diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c > index 92d8d0eeb..8ec96e66c 100644 > --- a/src/openvpn/ssl_openssl.c > +++ b/src/openvpn/ssl_openssl.c > @@ -2053,13 +2053,15 @@ print_cert_details(X509 *cert, char *buf, size_t > buflen) > int typeid = EVP_PKEY_id(pkey); > > #ifndef OPENSSL_NO_EC > - if (typeid == EVP_PKEY_EC && EVP_PKEY_get0_EC_KEY(pkey) != NULL) > + char groupname[256]; > + if (typeid == EVP_PKEY_EC) > { > - const EC_KEY *ec = EVP_PKEY_get0_EC_KEY(pkey); > - const EC_GROUP *group = EC_KEY_get0_group(ec); > - > - int nid = EC_GROUP_get_curve_name(group); > - if (nid == 0 || (curve = OBJ_nid2sn(nid)) == NULL) > + size_t len; > + if(EVP_PKEY_get_group_name(pkey, groupname, sizeof(groupname), > &len)) > + { > + curve = groupname; > + } > + else > { > curve = "(error getting curve name)"; > } > > Looks good otherwise and works as expected. Selva <div dir="ltr"><div dir="ltr">Hi,<div><br></div><div>I had looked at v1 of this so easy:</div></div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Tue, Oct 19, 2021 at 2:31 PM Arne Schwabe <<a href="mailto:arne@rfc2549.org" target="_blank">arne@rfc2549.org</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">EC_Key methods are deprecated in OpenSSL 3.0. Use<br> EVP_PKEY_get_group_name instead to query the EC group name from an<br> EVP_PKEY and add a compatibility function for older OpenSSL versions.<br> <br> Signed-off-by: Arne Schwabe <<a href="mailto:arne@rfc2549.org" target="_blank">arne@rfc2549.org</a>><br> ---<br> src/openvpn/openssl_compat.h | 42 ++++++++++++++++++++++++++++++++++++<br> src/openvpn/ssl_openssl.c | 14 ++++++------<br> 2 files changed, 50 insertions(+), 6 deletions(-)<br> <br> diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h<br> index ce8e2b360..dda47d76c 100644<br> --- a/src/openvpn/openssl_compat.h<br> +++ b/src/openvpn/openssl_compat.h<br> @@ -718,4 +718,46 @@ SSL_CTX_set_max_proto_version(SSL_CTX *ctx, long tls_ver_max)<br> return 1;<br> }<br> #endif /* if OPENSSL_VERSION_NUMBER < 0x10100000L && !defined(ENABLE_CRYPTO_WOLFSSL) */<br> +<br> +/* Functionality missing in 1.1.1 */<br> +#if OPENSSL_VERSION_NUMBER < 0x30000000L && !defined(OPENSSL_NO_EC)<br> +<br> +/* Note that this is not a perfect emulation of the new function but<br> + * is good enough for our case of printing certificate details during<br> + * handshake */<br> +static inline<br> +int EVP_PKEY_get_group_name(EVP_PKEY *pkey, char *gname, size_t gname_sz,<br> + size_t *gname_len)<br> +{<br> + const EC_KEY* ec = EVP_PKEY_get0_EC_KEY(pkey);<br> + if (ec == NULL)<br> + {<br> + return 0;<br> + }<br> + const EC_GROUP* group = EC_KEY_get0_group(ec);<br> + int nid = EC_GROUP_get_curve_name(group);<br> +<br> + if (nid == 0)<br> + {<br> + return 0;<br> + }<br> + const char *curve = OBJ_nid2sn(nid);<br></blockquote><div><br></div><div>I would have preferred a curve !=NULL check here. Though very unlikely to happen, we do not want a segfault in strncpy.</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> +<br> + strncpynt(gname, curve, gname_sz);<br> + *gname_len = min_int(strlen(curve), gname_sz);<br></blockquote><div><br></div><div>gname_sz - 1 ?</div><div><br></div><div>That said, our strncpynt ensures that strlen(curve) will be less than gname_sz, so this could be just strlen(curve) or left as is.</div><div> </div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> + return 1;<br> +}<br> +#endif<br> +<br> +/** Mimics SSL_CTX_new_ex for OpenSSL < 3 */<br> +#if OPENSSL_VERSION_NUMBER < 0x30000000L<br> +static inline SSL_CTX *<br> +SSL_CTX_new_ex(void *libctx, const char *propq, const SSL_METHOD *method)<br></blockquote><div><br></div><div>This looks like a spill-over from one of my xkey patches --- "git commit -p" malfunction? </div><div><br></div><div>Unless the "unused functions police" objects, we can keep it.</div><div><br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex"> +{<br> + (void) libctx;<br> + (void) propq;<br> + return SSL_CTX_new(method);<br> +}<br> +#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */<br> +<br> #endif /* OPENSSL_COMPAT_H_ */<br> diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c<br> index 92d8d0eeb..8ec96e66c 100644<br> --- a/src/openvpn/ssl_openssl.c<br> +++ b/src/openvpn/ssl_openssl.c<br> @@ -2053,13 +2053,15 @@ print_cert_details(X509 *cert, char *buf, size_t buflen)<br> int typeid = EVP_PKEY_id(pkey);<br> <br> #ifndef OPENSSL_NO_EC<br> - if (typeid == EVP_PKEY_EC && EVP_PKEY_get0_EC_KEY(pkey) != NULL)<br> + char groupname[256];<br> + if (typeid == EVP_PKEY_EC)<br> {<br> - const EC_KEY *ec = EVP_PKEY_get0_EC_KEY(pkey);<br> - const EC_GROUP *group = EC_KEY_get0_group(ec);<br> -<br> - int nid = EC_GROUP_get_curve_name(group);<br> - if (nid == 0 || (curve = OBJ_nid2sn(nid)) == NULL)<br> + size_t len;<br> + if(EVP_PKEY_get_group_name(pkey, groupname, sizeof(groupname), &len))<br> + {<br> + curve = groupname;<br> + }<br> + else<br> {<br> curve = "(error getting curve name)";<br> }<br><br></blockquote><div><br></div><div>Looks good otherwise and works as expected.</div><div><br></div><div>Selva</div></div></div>
On 19/10/2021 20:31, Arne Schwabe wrote: > EC_Key methods are deprecated in OpenSSL 3.0. Use > EVP_PKEY_get_group_name instead to query the EC group name from an > EVP_PKEY and add a compatibility function for older OpenSSL versions. > > Signed-off-by: Arne Schwabe <arne@rfc2549.org> > --- > src/openvpn/openssl_compat.h | 42 ++++++++++++++++++++++++++++++++++++ > src/openvpn/ssl_openssl.c | 14 ++++++------ > 2 files changed, 50 insertions(+), 6 deletions(-) > > diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h > index ce8e2b360..dda47d76c 100644 > --- a/src/openvpn/openssl_compat.h > +++ b/src/openvpn/openssl_compat.h > @@ -718,4 +718,46 @@ SSL_CTX_set_max_proto_version(SSL_CTX *ctx, long tls_ver_max) > return 1; > } > #endif /* if OPENSSL_VERSION_NUMBER < 0x10100000L && !defined(ENABLE_CRYPTO_WOLFSSL) */ > + > +/* Functionality missing in 1.1.1 */ > +#if OPENSSL_VERSION_NUMBER < 0x30000000L && !defined(OPENSSL_NO_EC) > + > +/* Note that this is not a perfect emulation of the new function but > + * is good enough for our case of printing certificate details during > + * handshake */ > +static inline > +int EVP_PKEY_get_group_name(EVP_PKEY *pkey, char *gname, size_t gname_sz, > + size_t *gname_len) > +{ > + const EC_KEY* ec = EVP_PKEY_get0_EC_KEY(pkey); > + if (ec == NULL) > + { > + return 0; > + } > + const EC_GROUP* group = EC_KEY_get0_group(ec); > + int nid = EC_GROUP_get_curve_name(group); > + > + if (nid == 0) > + { > + return 0; > + } > + const char *curve = OBJ_nid2sn(nid); The old code also has a curve == NULL check. Is that not necessary here?
diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h index ce8e2b360..dda47d76c 100644 --- a/src/openvpn/openssl_compat.h +++ b/src/openvpn/openssl_compat.h @@ -718,4 +718,46 @@ SSL_CTX_set_max_proto_version(SSL_CTX *ctx, long tls_ver_max) return 1; } #endif /* if OPENSSL_VERSION_NUMBER < 0x10100000L && !defined(ENABLE_CRYPTO_WOLFSSL) */ + +/* Functionality missing in 1.1.1 */ +#if OPENSSL_VERSION_NUMBER < 0x30000000L && !defined(OPENSSL_NO_EC) + +/* Note that this is not a perfect emulation of the new function but + * is good enough for our case of printing certificate details during + * handshake */ +static inline +int EVP_PKEY_get_group_name(EVP_PKEY *pkey, char *gname, size_t gname_sz, + size_t *gname_len) +{ + const EC_KEY* ec = EVP_PKEY_get0_EC_KEY(pkey); + if (ec == NULL) + { + return 0; + } + const EC_GROUP* group = EC_KEY_get0_group(ec); + int nid = EC_GROUP_get_curve_name(group); + + if (nid == 0) + { + return 0; + } + const char *curve = OBJ_nid2sn(nid); + + strncpynt(gname, curve, gname_sz); + *gname_len = min_int(strlen(curve), gname_sz); + return 1; +} +#endif + +/** Mimics SSL_CTX_new_ex for OpenSSL < 3 */ +#if OPENSSL_VERSION_NUMBER < 0x30000000L +static inline SSL_CTX * +SSL_CTX_new_ex(void *libctx, const char *propq, const SSL_METHOD *method) +{ + (void) libctx; + (void) propq; + return SSL_CTX_new(method); +} +#endif /* OPENSSL_VERSION_NUMBER < 0x30000000L */ + #endif /* OPENSSL_COMPAT_H_ */ diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c index 92d8d0eeb..8ec96e66c 100644 --- a/src/openvpn/ssl_openssl.c +++ b/src/openvpn/ssl_openssl.c @@ -2053,13 +2053,15 @@ print_cert_details(X509 *cert, char *buf, size_t buflen) int typeid = EVP_PKEY_id(pkey); #ifndef OPENSSL_NO_EC - if (typeid == EVP_PKEY_EC && EVP_PKEY_get0_EC_KEY(pkey) != NULL) + char groupname[256]; + if (typeid == EVP_PKEY_EC) { - const EC_KEY *ec = EVP_PKEY_get0_EC_KEY(pkey); - const EC_GROUP *group = EC_KEY_get0_group(ec); - - int nid = EC_GROUP_get_curve_name(group); - if (nid == 0 || (curve = OBJ_nid2sn(nid)) == NULL) + size_t len; + if(EVP_PKEY_get_group_name(pkey, groupname, sizeof(groupname), &len)) + { + curve = groupname; + } + else { curve = "(error getting curve name)"; }