[Openvpn-devel,v3] Do not try to use the encrypt-then-mac ciphers from OpenSSL 3.6.0
| Message ID | 20251023111138.25245-1-gert@greenie.muc.de |
|---|---|
| State | Accepted |
| Headers |
Return-Path: <openvpn-devel-bounces@lists.sourceforge.net>
Delivered-To: patchwork@openvpn.net
Received: by 2002:a05:7000:7d42:b0:72f:f16c:e055 with SMTP id
fr2csp7898396mab;
Thu, 23 Oct 2025 04:11:59 -0700 (PDT)
X-Forwarded-Encrypted: i=2;
AJvYcCUMUVRFLpElGRsmqVTWTOZI2YyaXKLt5mrJgAa59A/rzcNRFcYjJUiD8GRqhd4NTSu28cTLx0aXRwE=@openvpn.net
X-Google-Smtp-Source:
AGHT+IEVMD1my77bbiCbub3OwtmFvG8xBiExKe677Fa52l5OXftkJVzYZ5nKR0PynHOFRVjbYPhc
X-Received: by 2002:a05:6808:218a:b0:43f:4c84:abef with SMTP id
5614622812f47-44bd41666b1mr975582b6e.10.1761217919437;
Thu, 23 Oct 2025 04:11:59 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1761217919; cv=none;
d=google.com; s=arc-20240605;
b=NFa/Db1d3I06nbCNkekLx4z2bYSAGaphFf4py2QG8A6dVdK702An0ZwQghC6EYZ73G
KUmT7qCPuE+gP/TZEY5mjx8IMFL+sQ8Ha09X6MkYNCegzC7iQD6YjHYUrFuVtEY2v74I
K/jqS1l7zQ79weMylqsQXm4Me2UCRs1qWwRzy6sQ6WSZrfCFq4rsGER5D06nDNpAws9z
Uu5FVGQogI+OKR5dp0hhh7XMW3cgz09GKln4Lhq5cWmhk9iHB5u9Fv9dfFtHI+5QuIA8
rpocOvLi0BCP8PYO0tFnE6EtEHJBYslKXPWR+Ktwm8MaYaWPwa0+G7EFgTjyCPT/+/TJ
jJqw==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com;
s=arc-20240605;
h=errors-to:content-transfer-encoding:list-subscribe:list-help
:list-post:list-archive:list-unsubscribe:list-id:precedence:subject
:mime-version:references:in-reply-to:message-id:date:to:from
:dkim-signature:dkim-signature:dkim-signature;
bh=9mXiaCrYmJkAu/LIZZlMkdLwGeGbwdIUbqlZA/Rr2qc=;
fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=;
b=S/LyeqQlQ3XQPM6L8+4+oJU/QY/E2hGcBk9YQHnbuy7ikLj5pBkmR4WenUDYJnZ9f8
xnuGmvgeDbbB02t2jOca2eky41dvi8CCpIPMF+b47Obv7hppBMh66PN7RCqhfE9D0VVa
mbrqop0P/f8QhPPBAAJ5zVAZSvtzTo6uWIpYJcS4bswyn4xw52Ks0tDw/vzOREtNgeI6
IhWqj9gZYxoMKxy2xz5yXhFOkOParRy85Ba51Ayc8+WZ/AYFBDItcR7C3MAQq/GFTL0B
qhlrOC6chlc+pWkYJNS141MBS+mEsQSSBAly8SMaChbgcrJUckb7vzmPZrFbte/icDUf
FioA==;
dara=google.com
ARC-Authentication-Results: i=1; mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=iN6ubg96;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b="X4Md4/G/";
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=JcdfP2rM;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7])
by mx.google.com with ESMTPS id
5614622812f47-44bd44cf697si353111b6e.237.2025.10.23.04.11.58
(version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128);
Thu, 23 Oct 2025 04:11:59 -0700 (PDT)
Received-SPF: pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) client-ip=216.105.38.7;
Authentication-Results: mx.google.com;
dkim=pass header.i=@lists.sourceforge.net header.s=beta
header.b=iN6ubg96;
dkim=neutral (body hash did not verify) header.i=@sourceforge.net
header.s=x header.b="X4Md4/G/";
dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x
header.b=JcdfP2rM;
spf=pass (google.com: domain of
openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as
permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net;
dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type:
List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id:
Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender:
Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From:
Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner;
bh=9mXiaCrYmJkAu/LIZZlMkdLwGeGbwdIUbqlZA/Rr2qc=; b=iN6ubg96sve3zGfQeAHVKGDpT+
BjNdenQxGLIMAMclTEvo/E+GhT/v93LusI2jslDEuTVhVym4Q10LfmH9V/34YAObfX62DXx9MIlJh
zqXywQUmbxOFCszwpoUCUeAuBHHZQ60JTz9qhFTLCXgBFrdzWD4gRDc136Ky1iKQcZK4=;
Received: from [127.0.0.1] (helo=sfs-ml-2.v29.lw.sourceforge.com)
by sfs-ml-2.v29.lw.sourceforge.com with esmtp (Exim 4.95)
(envelope-from <openvpn-devel-bounces@lists.sourceforge.net>)
id 1vBtEZ-00032l-As;
Thu, 23 Oct 2025 11:11:56 +0000
Received: from [172.30.29.66] (helo=mx.sourceforge.net)
by sfs-ml-2.v29.lw.sourceforge.com with esmtps (TLS1.2) tls
TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95)
(envelope-from <gert@blue4.greenie.muc.de>) id 1vBtEV-00032U-Mz
for openvpn-devel@lists.sourceforge.net;
Thu, 23 Oct 2025 11:11:52 +0000
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References:
In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:
Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender:
Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:
List-Subscribe:List-Post:List-Owner:List-Archive;
bh=9c8I9wXTDPgPY9obSnXg4osU/bffKhqnDwuLaZbv3Qc=; b=X4Md4/G/JgYGDKREo/n44h9DwR
wytqlMRsRNO5rtLarykqP5s1jlweFBYFy0PX6sJBrg9EQHrsNczELiIPYKa5frfSbcTpo2OOHN/q8
xkrRO9RrzIIeM4J3O/wJkAxYAj+6qWYcNIYbIQ3pml7Dx8s9gM8TOawpKoxyWBZ0oCwY=;
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x
;
h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID:
Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID:
Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc
:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe:
List-Post:List-Owner:List-Archive;
bh=9c8I9wXTDPgPY9obSnXg4osU/bffKhqnDwuLaZbv3Qc=; b=JcdfP2rMVlVCvFHzX3EnJYgOwK
CCTBpocidONunoaFHlMtBeLn9hneFOC+XXwVHM5Adz22K/byCyEbfo9qwPr3SGP8TnhIN3lqYS54C
jIHQoBMBe/boYDiIegFyvxBAqJqSoZT9fSjq52MiVifJuiOHeI2vThkbeZSc2Pv3nJGw=;
Received: from [193.149.48.134] (helo=blue.greenie.muc.de)
by sfi-mx-2.v28.lw.sourceforge.com with esmtps
(TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95)
id 1vBtEV-0003fN-AV for openvpn-devel@lists.sourceforge.net;
Thu, 23 Oct 2025 11:11:52 +0000
Received: from blue.greenie.muc.de (localhost [127.0.0.1])
by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 59NBBduV025267
for <openvpn-devel@lists.sourceforge.net>; Thu, 23 Oct 2025 13:11:39 +0200
Received: (from gert@localhost)
by blue.greenie.muc.de (8.18.1/8.18.1/Submit) id 59NBBd99025266
for openvpn-devel@lists.sourceforge.net; Thu, 23 Oct 2025 13:11:39 +0200
From: Gert Doering <gert@greenie.muc.de>
To: openvpn-devel@lists.sourceforge.net
Date: Thu, 23 Oct 2025 13:11:33 +0200
Message-ID: <20251023111138.25245-1-gert@greenie.muc.de>
X-Mailer: git-send-email 2.49.1
In-Reply-To:
<gerrit.1761151453000.Iafe3c94b952cd3fbecf6f3d05816e5859f425e7d@gerrit.openvpn.net>
References:
<gerrit.1761151453000.Iafe3c94b952cd3fbecf6f3d05816e5859f425e7d@gerrit.openvpn.net>
MIME-Version: 1.0
X-Spam-Score: 1.3 (+)
X-Spam-Report: Spam detection software,
running on the system "sfi-spamd-1.hosts.colo.sdot.me",
has NOT identified this incoming email as spam. The original
message has been attached to this so you can view it or label
similar future email. If you have any questions, see
the administrator of that system for details.
Content preview: From: Arne Schwabe <arne@rfc2549.org> These ciphers claim
to be CBC but since they are also include an HMAC are more a mix of AEAD and
CBC. Nevertheless, we do not support these and also have no (good) reason
to support them.
Content analysis details: (1.3 points, 5.0 required)
pts rule name description
---- ----------------------
--------------------------------------------------
1.3 RDNS_NONE Delivered to internal network by a host with no rDNS
X-Headers-End: 1vBtEV-0003fN-AV
Subject: [Openvpn-devel] [PATCH v3] Do not try to use the encrypt-then-mac
ciphers from OpenSSL 3.6.0
X-BeenThere: openvpn-devel@lists.sourceforge.net
X-Mailman-Version: 2.1.21
Precedence: list
List-Id: <openvpn-devel.lists.sourceforge.net>
List-Unsubscribe: <https://lists.sourceforge.net/lists/options/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=unsubscribe>
List-Archive:
<http://sourceforge.net/mailarchive/forum.php?forum_name=openvpn-devel>
List-Post: <mailto:openvpn-devel@lists.sourceforge.net>
List-Help: <mailto:openvpn-devel-request@lists.sourceforge.net?subject=help>
List-Subscribe: <https://lists.sourceforge.net/lists/listinfo/openvpn-devel>,
<mailto:openvpn-devel-request@lists.sourceforge.net?subject=subscribe>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: openvpn-devel-bounces@lists.sourceforge.net
X-getmail-retrieved-from-mailbox: Inbox
X-GMAIL-THRID: =?utf-8?q?1846770841127214879?=
X-GMAIL-MSGID: =?utf-8?q?1846770841127214879?=
|
| Series |
[Openvpn-devel,v3] Do not try to use the encrypt-then-mac ciphers from OpenSSL 3.6.0
|
|
Commit Message
Gert Doering
Oct. 23, 2025, 11:11 a.m. UTC
From: Arne Schwabe <arne@rfc2549.org> These ciphers claim to be CBC but since they are also include an HMAC are more a mix of AEAD and CBC. Nevertheless, we do not support these and also have no (good) reason to support them. This patch defines the flag if the SSL library does not define the flag to also work when the SSL library is upgraded after OpenVPN has been compiled. Change-Id: Iafe3c94b952cd3fbecf6f3d05816e5859f425e7d Signed-off-by: Arne Schwabe <arne@rfc2549.org> Acked-by: Frank Lichtenheld <frank@lichtenheld.com> Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1294 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1294 This mail reflects revision 3 of this Change. Acked-by according to Gerrit (reflected above): Frank Lichtenheld <frank@lichtenheld.com>
Comments
Change and explanation make sense, and BB/GH confirms that macOS is now
happy again (this isn't a "macOS" problem but the GHA workers on macOS
discovered it first).
Your patch has been applied to the master branch.
commit a69d9b66502f13354750d8146cd038cc7a26a0bd
Author: Arne Schwabe
Date: Thu Oct 23 13:11:33 2025 +0200
Do not try to use the encrypt-then-mac ciphers from OpenSSL 3.6.0
Signed-off-by: Arne Schwabe <arne@rfc2549.org>
Acked-by: Frank Lichtenheld <frank@lichtenheld.com>
Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1294
Message-Id: <20251023111138.25245-1-gert@greenie.muc.de>
URL: https://www.mail-archive.com/openvpn-devel@lists.sourceforge.net/msg33846.html
Signed-off-by: Gert Doering <gert@greenie.muc.de>
--
kind regards,
Gert Doering
diff --git a/src/openvpn/crypto_openssl.c b/src/openvpn/crypto_openssl.c index 7688add..f596b8c 100644 --- a/src/openvpn/crypto_openssl.c +++ b/src/openvpn/crypto_openssl.c @@ -789,7 +789,8 @@ #ifdef EVP_CIPH_FLAG_CTS && !(EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_CTS) #endif - && !(EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER)); + && !(EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) + && !(EVP_CIPHER_flags(cipher) & EVP_CIPH_FLAG_ENC_THEN_MAC)); EVP_CIPHER_free(cipher); return ret; } diff --git a/src/openvpn/openssl_compat.h b/src/openvpn/openssl_compat.h index e3e7cf8..fb3c9b1 100644 --- a/src/openvpn/openssl_compat.h +++ b/src/openvpn/openssl_compat.h @@ -211,4 +211,9 @@ #endif #endif +/* Introduced in OpenSSL 3.6.0 */ +#ifndef EVP_CIPH_FLAG_ENC_THEN_MAC +#define EVP_CIPH_FLAG_ENC_THEN_MAC 0x10000000 +#endif + #endif /* OPENSSL_COMPAT_H_ */