@@ -66,10 +66,10 @@
(1) TUN and/or TAP driver to allow user-space programs to control
a virtual point-to-point IP or Ethernet device.
See TUN/TAP Driver References section below for more info.
- (2a) OpenSSL library, necessary for encryption, version 1.1.0 or higher
+ (2a) OpenSSL library, necessary for encryption, version 1.1.1 or higher
required, available from https://www.openssl.org/
or
- (2b) mbed TLS library, an alternative for encryption, version 2.0 or higher
+ (2b) mbed TLS library, an alternative for encryption, version 3.2.1 or higher
required, available from https://tls.mbed.org/
(3) on Linux, "libnl-gen" is required for kernel netlink support
(4) on Linux, "libcap-ng" is required for Linux capability handling
@@ -776,7 +776,7 @@
# if the user did not explicitly specify flags, try to autodetect
PKG_CHECK_MODULES(
[OPENSSL],
- [openssl >= 1.1.0],
+ [openssl >= 1.1.1],
[have_openssl="yes"],
[AC_MSG_WARN([OpenSSL not found by pkg-config ${pkg_config_found}])] # If this fails, we will do another test next
)
@@ -799,7 +799,7 @@
]],
[[
/* Version encoding: MNNFFPPS - see opensslv.h for details */
-#if OPENSSL_VERSION_NUMBER < 0x10100000L
+#if OPENSSL_VERSION_NUMBER < 0x10101000L
#error OpenSSL too old
#endif
]]
@@ -26,9 +26,9 @@
* OpenSSL compatibility stub
*
* This file provide compatibility stubs for the OpenSSL libraries
- * prior to version 1.1. This version introduces many changes in the
- * library interface, including the fact that various objects and
- * structures are not fully opaque.
+ * prior to the current major version. Newer versions may introduce changes
+ * in the library interface, including replacing functions or enforcing
+ * various objects and structures as fully opaque.
*/
#ifndef OPENSSL_COMPAT_H_
@@ -62,11 +62,6 @@
#endif
-/* Functionality missing in 1.1.0 */
-#if OPENSSL_VERSION_NUMBER < 0x10101000L && !defined(ENABLE_CRYPTO_WOLFSSL)
-#define SSL_CTX_set1_groups SSL_CTX_set1_curves
-#endif
-
/* Functionality missing in LibreSSL before 3.5 */
#if defined(LIBRESSL_VERSION_NUMBER) && LIBRESSL_VERSION_NUMBER < 0x3050000fL
#define EVP_CTRL_AEAD_SET_TAG EVP_CTRL_GCM_SET_TAG
@@ -200,42 +200,12 @@
/*
* Return maximum TLS version supported by local OpenSSL library.
- * Assume that presence of SSL_OP_NO_TLSvX macro indicates that
- * TLSvX is supported.
+ * We only support OpenSSL versions that support TLS 1.3.
*/
int
tls_version_max(void)
{
-#if defined(TLS1_3_VERSION)
- /* If this is defined we can safely assume TLS 1.3 support */
return TLS_VER_1_3;
-#elif OPENSSL_VERSION_NUMBER >= 0x10100000L
- /*
- * If TLS_VER_1_3 is not defined, we were compiled against a version that
- * did not support TLS 1.3.
- *
- * However, the library we are *linked* against might be OpenSSL 1.1.1
- * and therefore supports TLS 1.3. This needs to be checked at runtime
- * since we can be compiled against 1.1.0 and then the library can be
- * upgraded to 1.1.1.
- * We only need to check this for OpenSSL versions that can be
- * upgraded to 1.1.1 without recompile (>= 1.1.0)
- */
- if (OpenSSL_version_num() >= 0x1010100fL)
- {
- return TLS_VER_1_3;
- }
- else
- {
- return TLS_VER_1_2;
- }
-#elif defined(TLS1_2_VERSION) || defined(SSL_OP_NO_TLSv1_2)
- return TLS_VER_1_2;
-#elif defined(TLS1_1_VERSION) || defined(SSL_OP_NO_TLSv1_1)
- return TLS_VER_1_1;
-#else /* if defined(TLS1_3_VERSION) */
- return TLS_VER_1_0;
-#endif
}
/** Convert internal version number to openssl version number */
@@ -256,22 +226,7 @@
}
else if (ver == TLS_VER_1_3)
{
- /*
- * Supporting the library upgraded to TLS1.3 without recompile
- * is enough to support here with a simple constant that the same
- * as in the TLS 1.3, so spec it is very unlikely that OpenSSL
- * will change this constant
- */
-#ifndef TLS1_3_VERSION
- /*
- * We do not want to define TLS_VER_1_3 if not defined
- * since other parts of the code use the existance of this macro
- * as proxy for TLS 1.3 support
- */
- return 0x0304;
-#else
return TLS1_3_VERSION;
-#endif
}
return 0;
}
@@ -491,8 +446,8 @@
*/
if (strlen(ciphers) >= (len - 1))
{
- msg(M_FATAL, "Failed to set restricted TLS 1.3 cipher list, too long (>%d).",
- (int)(len - 1));
+ msg(M_FATAL, "Failed to set restricted TLS 1.3 cipher list, too long (>%zd).",
+ len - 1);
}
strncpy(openssl_ciphers, ciphers, len);
@@ -511,17 +466,11 @@
{
if (ciphers == NULL)
{
- /* default cipher list of OpenSSL 1.1.1 is sane, do not set own
+ /* default cipher list of OpenSSL is sane, do not set own
* default as we do with tls-cipher */
return;
}
-#if !defined(TLS1_3_VERSION)
- crypto_msg(M_WARN,
- "Not compiled with OpenSSL 1.1.1 or higher. "
- "Ignoring TLS 1.3 only tls-ciphersuites '%s' setting.",
- ciphers);
-#else
ASSERT(NULL != ctx);
char openssl_ciphers[4096];
@@ -531,14 +480,12 @@
{
crypto_msg(M_FATAL, "Failed to set restricted TLS 1.3 cipher list: %s", openssl_ciphers);
}
-#endif
}
void
tls_ctx_set_cert_profile(struct tls_root_ctx *ctx, const char *profile)
{
-#if OPENSSL_VERSION_NUMBER > 0x10100000L \
- && (!defined(LIBRESSL_VERSION_NUMBER) || LIBRESSL_VERSION_NUMBER > 0x3060000fL) \
+#if (!defined(LIBRESSL_VERSION_NUMBER) || LIBRESSL_VERSION_NUMBER > 0x3060000fL) \
&& !defined(OPENSSL_IS_AWSLC)
/* OpenSSL does not have certificate profiles, but a complex set of
* callbacks that we could try to implement to achieve something similar.
@@ -565,7 +512,7 @@
{
msg(M_FATAL, "ERROR: Invalid cert profile: %s", profile);
}
-#else /* if OPENSSL_VERSION_NUMBER > 0x10100000L */
+#else
if (profile)
{
msg(M_WARN,
@@ -573,7 +520,7 @@
"support --tls-cert-profile, ignoring user-set profile: '%s'",
profile);
}
-#endif /* if OPENSSL_VERSION_NUMBER > 0x10100000L */
+#endif
}
void
@@ -2597,14 +2544,12 @@
crypto_msg(M_FATAL, "Cannot create SSL_CTX object");
}
-#if defined(TLS1_3_VERSION)
if (tls13)
{
SSL_CTX_set_min_proto_version(tls_ctx.ctx, TLS1_3_VERSION);
tls_ctx_restrict_ciphers_tls13(&tls_ctx, cipher_list);
}
else
-#endif
{
SSL_CTX_set_max_proto_version(tls_ctx.ctx, TLS1_2_VERSION);
tls_ctx_restrict_ciphers(&tls_ctx, cipher_list);
@@ -2618,7 +2563,7 @@
crypto_msg(M_FATAL, "Cannot create SSL object");
}
-#if OPENSSL_VERSION_NUMBER < 0x1010000fL || defined(OPENSSL_IS_AWSLC) || defined(ENABLE_CRYPTO_WOLFSSL)
+#if defined(OPENSSL_IS_AWSLC) || defined(ENABLE_CRYPTO_WOLFSSL)
STACK_OF(SSL_CIPHER) *sk = SSL_get_ciphers(ssl);
#else
STACK_OF(SSL_CIPHER) *sk = SSL_get1_supported_ciphers(ssl);
@@ -2646,9 +2591,7 @@
printf("%s\n", pair->iana_name);
}
}
-#if (OPENSSL_VERSION_NUMBER >= 0x1010000fL)
sk_SSL_CIPHER_free(sk);
-#endif
SSL_free(ssl);
SSL_CTX_free(tls_ctx.ctx);
}
@@ -110,7 +110,7 @@
assert_string_equal(mutate_ncp_cipher_list("AES-256-GCM:?AES-128-CCM:AES-128-GCM", &gc),
aes_ciphers);
- /* For testing that with OpenSSL 1.1.0+ that also accepts ciphers in
+ /* For testing that with OpenSSL that also accepts ciphers in
* a different spelling the normalised cipher output is the same */
bool have_chacha_mixed_case = cipher_valid("ChaCha20-Poly1305");
if (have_chacha_mixed_case)