| Message ID | 20220119182126.56880-1-openvpn@sf.lists.topphemmelig.net |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net> Delivered-To: patchwork@openvpn.net Delivered-To: patchwork@openvpn.net Received: from director14.mail.ord1d.rsapps.net ([172.31.255.6]) by backend41.mail.ord1d.rsapps.net with LMTP id 0FEoGv1W6GGTUwAAqwncew (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Wed, 19 Jan 2022 13:22:53 -0500 Received: from proxy6.mail.iad3b.rsapps.net ([172.31.255.6]) by director14.mail.ord1d.rsapps.net with LMTP id cHTyHv1W6GH8YgAAeJ7fFg (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Wed, 19 Jan 2022 13:22:53 -0500 Received: from smtp34.gate.iad3b ([172.31.255.6]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) by proxy6.mail.iad3b.rsapps.net with LMTPS id wBBcGf1W6GGfEgAARawThA (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) for <patchwork@openvpn.net>; Wed, 19 Jan 2022 13:22:53 -0500 X-Spam-Threshold: 95 X-Spam-Score: 0 X-Spam-Flag: NO X-Virus-Scanned: OK X-Orig-To: openvpnslackdevel@openvpn.net X-Originating-Ip: [216.105.38.7] Authentication-Results: smtp34.gate.iad3b.rsapps.net; iprev=pass policy.iprev="216.105.38.7"; spf=pass smtp.mailfrom="openvpn-devel-bounces@lists.sourceforge.net" smtp.helo="lists.sourceforge.net"; dkim=fail (signature verification failed) header.d=sourceforge.net; dkim=fail (signature verification failed) header.d=sf.net; dkim=fail (signature verification failed) header.d=sf.lists.topphemmelig.net; dmarc=fail (p=none; dis=none) header.from=sf.lists.topphemmelig.net X-Suspicious-Flag: YES X-Classification-ID: d0563f10-7954-11ec-a204-5254005e8ddb-1-1 Received: from [216.105.38.7] ([216.105.38.7:56834] helo=lists.sourceforge.net) by smtp34.gate.iad3b.rsapps.net (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) (ecelerity 4.2.38.62370 r(:)) with ESMTPS (cipher=DHE-RSA-AES256-GCM-SHA384) id 88/E6-02284-CF658E16; Wed, 19 Jan 2022 13:22:52 -0500 Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.94.2) (envelope-from <openvpn-devel-bounces@lists.sourceforge.net>) id 1nAFam-0004br-By; Wed, 19 Jan 2022 18:21:55 +0000 Received: from [172.30.20.202] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.94.2) (envelope-from <openvpn@sf.lists.topphemmelig.net>) id 1nAFal-0004a1-1v for openvpn-devel@lists.sourceforge.net; Wed, 19 Jan 2022 18:21:53 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:Content-Type:MIME-Version :Message-Id:Date:Subject:To:From:Sender:Reply-To:Cc:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:In-Reply-To:References:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=2ScjCkb/54Ni2ZAt1gbQRAYIrWB0zVqiwjXe9GVu7Gg=; b=MIG51Pl2wp0UzDXp00j1nSGgfM RbrUC/PNsizyKlockc76M6rMUc5480Bd3V9f46IfLg2cE2GGK3kHQwor1NO9ofgH7Ae3vo1KOVjmG P+U09UHrYN4EfnjxLk4CNxnqTHehYDsp/M0wRibRL07HmWFa12Q0KwFmgMdGtnMxaWE0=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:Content-Type:MIME-Version:Message-Id:Date: Subject:To:From:Sender:Reply-To:Cc:Content-ID:Content-Description:Resent-Date :Resent-From:Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:In-Reply-To: References:List-Id:List-Help:List-Unsubscribe:List-Subscribe:List-Post: List-Owner:List-Archive; bh=2ScjCkb/54Ni2ZAt1gbQRAYIrWB0zVqiwjXe9GVu7Gg=; b=B Y7l9b3LvVGAuzKaLI1mZWhZEGlzm01Qd5RlK4/jQMV6Pm0rhkBnanWM/aGw6wa5Ee5tXyUAgDAfnn w1qnNQ2yoI7v2/erkVRI1dpjQvLOqjw9WSdLWJnonTBH8S2COZehx9Fw0J9U7LPG7kTePAISKpxCR pGhW2Ym5R6imq8Nk=; Received: from mx1.basenordic.cloud ([217.170.196.134]) by sfi-mx-1.v28.lw.sourceforge.com with esmtps (TLSv1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.92.3) id 1nAFai-0040os-O7 for openvpn-devel@lists.sourceforge.net; Wed, 19 Jan 2022 18:21:53 +0000 Received: from localhost (unknown [127.0.0.1]) by mx1.basenordic.cloud (Postfix) with ESMTP id BCE90E713 for <openvpn-devel@lists.sourceforge.net>; Wed, 19 Jan 2022 18:21:43 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=sf.lists.topphemmelig.net; s=inouz9eefah2too5; t=1642616503; bh=2ScjCkb/54Ni2ZAt1gbQRAYIrWB0zVqiwjXe9GVu7Gg=; h=From:To:Subject:Date:From; b=WkX795DdwuB0jukwDDUO3D+BsU1pmECPaAYu72lVOUJo0gvPbMMK7R2z2ywlREHo2 /Wa8D50nV7hOVCaroZiQwOqpDqqC0R0XNtmcb4J8eGta2q7g0+CDf7BPt2cn35UYYR P2OYX1+pZKsYJ7XkAW37eueMvbHWHyJB30FZMErfqJUvJ8KPDeJj6XMdZc1oo+2Inn IXkcKirXkUGcb9Dkn+iXecoWFh0a8dhHZ4J5J7FzvgFIQBCY4ONYPZxrbF54sKO0/t 6sGiU1dQsMsCFCjoU5JAfJTEpWL7qrnAR0UNtSp1eU2xKrEZJCW1DNafxngATlTDir ybX217S+TDtsw== Received: from mx1.basenordic.cloud ([127.0.0.1]) by localhost (mx1.basenordic.cloud [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id tBVXV6tQP_I2 for <openvpn-devel@lists.sourceforge.net>; Wed, 19 Jan 2022 19:21:43 +0100 (CET) Received: from xplorer.net (xplorer.sommerseth.xyz [10.35.7.11]) by mx1.basenordic.cloud (Postfix) with ESMTP id 18D77E712 for <openvpn-devel@lists.sourceforge.net>; Wed, 19 Jan 2022 19:21:43 +0100 (CET) From: David Sommerseth <openvpn@sf.lists.topphemmelig.net> To: openvpn-devel@lists.sourceforge.net Date: Wed, 19 Jan 2022 19:21:26 +0100 Message-Id: <20220119182126.56880-1-openvpn@sf.lists.topphemmelig.net> X-Mailer: git-send-email 2.27.0 MIME-Version: 1.0 X-Spam-Report: Spam detection software, running on the system "util-spamd-1.v13.lw.sourceforge.com", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: David Sommerseth <davids@openvpn.net> On Fedora and RHEL/CentOS, the standard OpenSSL library has the FIPS module enabled by default. On these platforms, the OPENSSL_FIPS macro is always defined via /usr/include/openssl/opensslconf-*.h. Content analysis details: (-2.4 points, 6.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- -0.0 SPF_HELO_PASS SPF: HELO matches SPF record -0.0 SPF_PASS SPF: sender matches SPF record -2.3 RCVD_IN_DNSWL_MED RBL: Sender listed at https://www.dnswl.org/, medium trust [217.170.196.134 listed in list.dnswl.org] -0.1 DKIM_VALID_AU Message has a valid DKIM or DK signature from author's domain 0.1 DKIM_SIGNED Message has a DKIM or DK signature, not necessarily valid -0.1 DKIM_VALID Message has at least one valid DKIM or DK signature X-Headers-End: 1nAFai-0040os-O7 Subject: [Openvpn-devel] [PATCH v3] crypto: Fix OPENSSL_FIPS enabled builds X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: <openvpn-devel.lists.sourceforge.net> List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe> List-Archive: <http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel> List-Post: <mailto:openvpn-devel@lists.sourceforge.net> List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help> List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>, <mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe> Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: base64 Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox |
| Series |
[Openvpn-devel,v3] crypto: Fix OPENSSL_FIPS enabled builds
|
|
Commit Message
David Sommerseth
Jan. 19, 2022, 7:21 a.m. UTC
From: David Sommerseth <davids@openvpn.net> On Fedora and RHEL/CentOS, the standard OpenSSL library has the FIPS module enabled by default. On these platforms, the OPENSSL_FIPS macro is always defined via /usr/include/openssl/opensslconf-*.h. Without this fix, the following compilation error appears: ./src/openvpn/crypto.c: In function ‘print_cipher’: ./src/openvpn/crypto.c:1707:43: error: ‘cipher’ undeclared (first use in this function); did you mean ‘iphdr’? if (FIPS_mode() && !(EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_FIPS)) ^~~~~~ The EVP_CIPHER_fetch() and EVP_CIPHER_free() methods are also provided via the openssl_compat.h for older than OpenSSL 3.0. Signed-off-by: David Sommerseth <davids@openvpn.net> --- src/openvpn/crypto.c | 8 +++++++- 1 file changed, 7 insertions(+), 1 deletion(-)
Comments
Acked-by: Gert Doering <gert@greenie.muc.de> We'll add build tests on Fedora / CentOS, as soon as September brings the new buildbot infrastructure... so we get the "looks like FIPS but isn't" stuff tested as well. (cipher) changed as instructed on IRC. Your patch has been applied to the master branch. commit 544330fefedc87a74b4e17e105ad9151b8ad1dc9 Author: David Sommerseth Date: Wed Jan 19 19:21:26 2022 +0100 crypto: Fix OPENSSL_FIPS enabled builds Signed-off-by: David Sommerseth <davids@openvpn.net> Acked-by: Gert Doering <gert@greenie.muc.de> Message-Id: <20220119182126.56880-1-openvpn@sf.lists.topphemmelig.net> URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg23570.html Signed-off-by: Gert Doering <gert@greenie.muc.de> -- kind regards, Gert Doering
Hi, On Wed, Jan 19, 2022 at 07:21:26PM +0100, David Sommerseth wrote: > index 5626e2b6..eb0b1254 100644 > --- a/src/openvpn/crypto.c > +++ b/src/openvpn/crypto.c > @@ -34,6 +34,7 @@ > #include "error.h" > #include "integer.h" > #include "platform.h" > +#include "openssl_compat.h" > > #include "memdbg.h" This breaks compilation for mbedtls builds, depending on which version of OpenSSL happens to be installed on the system (if any). In this particular case, mbedtls build with a system openssl of 0.9.8, it blows up with In file included from crypto.c:37: openssl_compat.h: In function 'SSL_CTX_get_min_proto_version': openssl_compat.h:635: error: 'SSL_OP_NO_TLSv1_1' undeclared (first use in this (and more of this) which is unsurprising - it's not supposed to pull in these headers in the first place. I wondered about this header, but did not wonder enough to verify that it indeed must not be included for non-openssl-builds. gert
Hi On Fri, Jan 21, 2022 at 12:10 PM Gert Doering <gert@greenie.muc.de> wrote: > Hi, > > On Wed, Jan 19, 2022 at 07:21:26PM +0100, David Sommerseth wrote: > > index 5626e2b6..eb0b1254 100644 > > --- a/src/openvpn/crypto.c > > +++ b/src/openvpn/crypto.c > > @@ -34,6 +34,7 @@ > > #include "error.h" > > #include "integer.h" > > #include "platform.h" > > +#include "openssl_compat.h" > > > > #include "memdbg.h" > > This breaks compilation for mbedtls builds, depending on which version > of OpenSSL happens to be installed on the system (if any). > > In this particular case, mbedtls build with a system openssl of 0.9.8, > it blows up with > > In file included from crypto.c:37: > openssl_compat.h: In function 'SSL_CTX_get_min_proto_version': > openssl_compat.h:635: error: 'SSL_OP_NO_TLSv1_1' undeclared > (first use in this > > (and more of this) > > which is unsurprising - it's not supposed to pull in these headers > in the first place. > Looking back at it, the patch and the problem it's trying to solve are both misplaced in crypto.c. That file should be ssl-lib agnostic and openssl related bits should go to crypto_openssl.c... I think we need to remove that OPENSSL_FIPS clause and think of providing that extra info somewhere else if possible. Selva <div dir="ltr"><div>Hi</div><br><div class="gmail_quote"><div dir="ltr" class="gmail_attr">On Fri, Jan 21, 2022 at 12:10 PM Gert Doering <<a href="mailto:gert@greenie.muc.de">gert@greenie.muc.de</a>> wrote:<br></div><blockquote class="gmail_quote" style="margin:0px 0px 0px 0.8ex;border-left:1px solid rgb(204,204,204);padding-left:1ex">Hi,<br> <br> On Wed, Jan 19, 2022 at 07:21:26PM +0100, David Sommerseth wrote:<br> > index 5626e2b6..eb0b1254 100644<br> > --- a/src/openvpn/crypto.c<br> > +++ b/src/openvpn/crypto.c<br> > @@ -34,6 +34,7 @@<br> > #include "error.h"<br> > #include "integer.h"<br> > #include "platform.h"<br> > +#include "openssl_compat.h"<br> > <br> > #include "memdbg.h"<br> <br> This breaks compilation for mbedtls builds, depending on which version<br> of OpenSSL happens to be installed on the system (if any).<br> <br> In this particular case, mbedtls build with a system openssl of 0.9.8,<br> it blows up with<br> <br> In file included from crypto.c:37:<br> openssl_compat.h: In function 'SSL_CTX_get_min_proto_version':<br> openssl_compat.h:635: error: 'SSL_OP_NO_TLSv1_1' undeclared <br> (first use in this<br> <br> (and more of this)<br> <br> which is unsurprising - it's not supposed to pull in these headers<br> in the first place.<br></blockquote><div><br></div><div>Looking back at it, the patch and the problem it's trying to solve are both misplaced in crypto.c. That file should be ssl-lib agnostic and openssl related bits should go to crypto_openssl.c...</div><div><br></div><div>I think we need to remove that OPENSSL_FIPS clause and think of providing that extra info somewhere else if possible.<br></div><div><br></div><div>Selva</div></div></div>
diff --git a/src/openvpn/crypto.c b/src/openvpn/crypto.c index 5626e2b6..eb0b1254 100644 --- a/src/openvpn/crypto.c +++ b/src/openvpn/crypto.c @@ -34,6 +34,7 @@ #include "error.h" #include "integer.h" #include "platform.h" +#include "openssl_compat.h" #include "memdbg.h" @@ -1704,10 +1705,15 @@ print_cipher(const char *ciphername) printf(", TLS client/server mode only"); } #ifdef OPENSSL_FIPS - if (FIPS_mode() && !(EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_FIPS)) + evp_cipher_type *cipher = EVP_CIPHER_fetch(NULL, ciphername, NULL); + + if (FIPS_mode() + && (NULL != cipher) + && !(EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_FIPS)) { printf(", disabled by FIPS mode"); } + EVP_CIPHER_free(cipher); #endif printf(")\n");