From patchwork Thu Aug 13 18:52:51 2026 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Gert Doering X-Patchwork-Id: 5235 Return-Path: Delivered-To: patchwork@openvpn.net Received: by 2002:a05:7000:5508:b0:87d:ab56:3700 with SMTP id e8csp1272727mah; Thu, 13 Aug 2026 11:53:15 -0700 (PDT) X-Forwarded-Encrypted: i=2; AHgh+RotxXh0soGfxJ41FJNxYcjhKYlRUc41dqy7BE8W2PLFB2HA8JjKJioHoWfgWj7mnySBbcjBIPA5/rQ=@openvpn.net X-Received: by 2002:a05:6830:82ba:b0:7e7:9493:dc3e with SMTP id 46e09a7af769-7f3ca64bc98mr7815546a34.3.1786647195741; Thu, 13 Aug 2026 11:53:15 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1786647195; cv=none; d=google.com; s=arc-20260327; b=f9+Ja+oiZgymerH8Om1oU+2AQWsk5O3PZ/wNqfv0NNgCkmoqF2XjabvkwuhDZtjdUS VsuqzTlvN5c4WV3ky7TMXcuGQyxlbjt0bg52fJfeoHVnvYbZHE9FGuNjjKAfGCwA/KNi IRuR5AfIxJtlQNZaDFSKylWluKGyZT3nzFaJv3h4dz18VY0ZA914NUGL/4ftq3TYQzVl G2dkaR8eFO7U96/1M17SZr0nrv5LdaCoKxtUkD3ymBBLIHqMEc3f+mW6znDfprYt4ZnU hpMrwg0GCX79TmlrvUewkICLwSYbcP7pZQyfb4iCqzyWXeZ8xKCbg9wKqHTHlWvCJl58 BNrg== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=errors-to:content-transfer-encoding:list-subscribe:list-help :list-post:list-archive:list-unsubscribe:list-id:precedence:subject :mime-version:references:in-reply-to:message-id:date:to:from :dkim-signature:dkim-signature:dkim-signature; bh=H4OeRV42Di3pvvV9WVPoQPlrJgaoI2oxWXtfaowOxkk=; fh=4NbAC/LsuMLI0S0hprUlLSLCiHwg6SCAifhH718Jh0Q=; b=HEohtb2s2J/wpwEa8tWIFePahmy8ZTRAzdvK2MaL9p6z7YTuFtCUwOr8w1BKvz3KUo OJbaAVA+aBu/szWgIGzDzPjY4gyWx1eyCh+4bcnKEOn7H+m9ITJAa5/6aZ64g9eOiqKF 5GS8btrkp5w+6MuV1QWab/sg+AoTfDQyIQ8sFfoRItudXJkS6lrD4suX+7T9t/DWRFWf ZTvnlXn58MhFIplyD3sjpyweC2eTjfUXTyVBpuoxOeoi8JXA3w67RiIqT4e4XpJmZXcO Qj9y0SSKzCckNSw66n61MHbWhWgdC9wAiYY2oym0BH9QE1T/6bbANh/loRvgL3/nBIrx tPUw==; dara=google.com ARC-Authentication-Results: i=1; mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=NFHYPdTy; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=FS9QZltJ; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=exymqtw3; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de Received: from lists.sourceforge.net (lists.sourceforge.net. [216.105.38.7]) by mx.google.com with ESMTPS id 46e09a7af769-7f3c99df857si7074466a34.7.2026.08.13.11.53.15 (version=TLS1_2 cipher=ECDHE-ECDSA-AES128-GCM-SHA256 bits=128/128); Thu, 13 Aug 2026 11:53:15 -0700 (PDT) Received-SPF: pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) client-ip=216.105.38.7; Authentication-Results: mx.google.com; dkim=pass header.i=@lists.sourceforge.net header.s=beta header.b=NFHYPdTy; dkim=neutral (body hash did not verify) header.i=@sourceforge.net header.s=x header.b=FS9QZltJ; dkim=neutral (body hash did not verify) header.i=@sf.net header.s=x header.b=exymqtw3; spf=pass (google.com: domain of openvpn-devel-bounces@lists.sourceforge.net designates 216.105.38.7 as permitted sender) smtp.mailfrom=openvpn-devel-bounces@lists.sourceforge.net; dmarc=fail (p=NONE sp=NONE dis=NONE) header.from=muc.de DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=lists.sourceforge.net; s=beta; h=Content-Transfer-Encoding:Content-Type: List-Subscribe:List-Help:List-Post:List-Archive:List-Unsubscribe:List-Id: Subject:MIME-Version:References:In-Reply-To:Message-ID:Date:To:From:Sender: Reply-To:Cc:Content-ID:Content-Description:Resent-Date:Resent-From: Resent-Sender:Resent-To:Resent-Cc:Resent-Message-ID:List-Owner; bh=H4OeRV42Di3pvvV9WVPoQPlrJgaoI2oxWXtfaowOxkk=; b=NFHYPdTy9Mt0s6xmHUmrwqlGR7 BtYiMP+AbwYkRSj+sHOMMrtoF9qyOb5izcq37QV0fiEWRueo9fOqc7oZlfmGykD7U9X+85N5pwC21 euAbNdXRbqJdTeWAgFs9CrjNjcbXoJh2pwx0Y5VTkf2R3bHSDngnLFshTdmO74ySMBko=; Received: from [127.0.0.1] (helo=sfs-ml-4.v29.lw.sourceforge.com) by sfs-ml-4.v29.lw.sourceforge.com with esmtp (Exim 4.95) (envelope-from ) id 1wuaYC-0006Ch-Lj; Thu, 13 Aug 2026 18:53:12 +0000 Received: from [172.30.29.66] (helo=mx.sourceforge.net) by sfs-ml-4.v29.lw.sourceforge.com with esmtps (TLS1.2) tls TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384 (Exim 4.95) (envelope-from ) id 1wuaY7-0006CX-3r for openvpn-devel@lists.sourceforge.net; Thu, 13 Aug 2026 18:53:07 +0000 DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sourceforge.net; s=x; h=Content-Transfer-Encoding:MIME-Version:References: In-Reply-To:Message-ID:Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type: Content-ID:Content-Description:Resent-Date:Resent-From:Resent-Sender: Resent-To:Resent-Cc:Resent-Message-ID:List-Id:List-Help:List-Unsubscribe: List-Subscribe:List-Post:List-Owner:List-Archive; bh=Su9HSQ4/mLr8uScFtBgr2OcdfNN+vfdn3rdokM2meNs=; b=FS9QZltJMPyfr6SLaoSBOT7VaP XX1JhM6+gj3PUJmZuLNa2UXikbtmP9dnFpyAsdQEqsI4nS/9Mz41Vr7ORRBzrqfR697vYzbzTk3kE V0rPnp3RzJfiZvQXeTovjmdCxhw6Dv0ioN1MIr3zmk4ksSuSV+9VHgixTdFU3dzVqPD4=; DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed; d=sf.net; s=x ; h=Content-Transfer-Encoding:MIME-Version:References:In-Reply-To:Message-ID: Date:Subject:To:From:Sender:Reply-To:Cc:Content-Type:Content-ID: Content-Description:Resent-Date:Resent-From:Resent-Sender:Resent-To:Resent-Cc :Resent-Message-ID:List-Id:List-Help:List-Unsubscribe:List-Subscribe: List-Post:List-Owner:List-Archive; bh=Su9HSQ4/mLr8uScFtBgr2OcdfNN+vfdn3rdokM2meNs=; b=exymqtw3ML9rLv+l5i3ME4fc/u NhBkyNWycGRpH6+jpZACQ+yYfIeudFxfedy+Knuk9IrS2WWralUjtFnZEYOyO5B7OcGRgUz7hxbVw Bmw4V5UOGJkUg25dQ1XtOxBJTCHwRoQy8n7qdYhdimzfnCM67eRVgxv2ZPSClhDFuWw0=; Received: from [193.149.48.129] (helo=blue.greenie.muc.de) by sfi-mx-2.v28.lw.sourceforge.com with esmtps (TLS1.2:ECDHE-RSA-AES256-GCM-SHA384:256) (Exim 4.95) id 1wuaY5-0000R8-8B for openvpn-devel@lists.sourceforge.net; Thu, 13 Aug 2026 18:53:07 +0000 Received: from blue.greenie.muc.de (localhost [127.0.0.1]) by blue.greenie.muc.de (8.18.1/8.18.1) with ESMTP id 67DIqwIO007098 for ; Thu, 13 Aug 2026 20:52:58 +0200 Received: (from gert@localhost) by blue.greenie.muc.de (8.18.2/8.18.1/Submit) id 67DIqwns007097 for openvpn-devel@lists.sourceforge.net; Thu, 13 Aug 2026 20:52:58 +0200 From: Gert Doering To: openvpn-devel@lists.sourceforge.net Date: Thu, 13 Aug 2026 20:52:51 +0200 Message-ID: <20260813185258.7084-1-gert@greenie.muc.de> X-Mailer: git-send-email 2.53.0 In-Reply-To: References: MIME-Version: 1.0 X-Spam-Score: 1.3 (+) X-Spam-Report: Spam detection software, running on the system "sfi-spamd-1.hosts.colo.sdot.me", has NOT identified this incoming email as spam. The original message has been attached to this so you can view it or label similar future email. If you have any questions, see the administrator of that system for details. Content preview: From: Arne Schwabe OpenSSL has the quite curious way of allowing to create contexts that allow only server or only client. This creates extra complications when we want to use both server and client SSL objects and does [...] Content analysis details: (1.3 points, 5.0 required) pts rule name description ---- ---------------------- -------------------------------------------------- 1.3 RDNS_NONE Delivered to internal network by a host with no rDNS X-Headers-End: 1wuaY5-0000R8-8B Subject: [Openvpn-devel] [PATCH v6] Do not differentiate TLS server and client context initialisation X-BeenThere: openvpn-devel@lists.sourceforge.net X-Mailman-Version: 2.1.21 Precedence: list List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: openvpn-devel-bounces@lists.sourceforge.net X-getmail-retrieved-from-mailbox: Inbox X-GMAIL-THRID: 1873435369919807406 X-GMAIL-MSGID: 1873435369919807406 From: Arne Schwabe OpenSSL has the quite curious way of allowing to create contexts that allow only server or only client. This creates extra complications when we want to use both server and client SSL objects and does not seem to have any advantages. We later explicitly tell OpenSSL to initialise the SSL objects to be a server or client object in key_state_ssl_init via SSL_set_accept_state or SSL_set_connect_state. If this is mismatched we end up getting an error from OpenSSL ("called a function you should not call") that ends up calling a function that is not defined in that TLS_method. Looking into the OpenSSL source (IMPLEMENT_tls_meth_func) the main difference between the methods is whether they have a proper accept/connect or have the ssl_undefined_function that triggers the "called a function you should not call". Our mbed TLS code basically does not give the TLS context any personality of client or server until we are in the same area in which the OpenSSL code calls SSL_set_accept_state/SSL_set_connect_state. This also modifies the mbedTLS backend to make the decision to use client or server TLS context personality in key_state_ssl_init. same as the OpenSSL backend. Change-Id: Iaf1f3475e4f27a920c028cd73b1a2497953583d0 Signed-off-by: Arne Schwabe Acked-by: Frank Lichtenheld Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1728 --- This change was reviewed on Gerrit and approved by at least one developer. I request to merge it to master. Gerrit URL: https://gerrit.openvpn.net/c/openvpn/+/1728 This mail reflects revision 6 of this Change. Acked-by according to Gerrit (reflected above): Frank Lichtenheld diff --git a/src/openvpn/ssl.c b/src/openvpn/ssl.c index ccd8264..17808f7 100644 --- a/src/openvpn/ssl.c +++ b/src/openvpn/ssl.c @@ -525,18 +525,11 @@ struct tls_root_ctx *new_ctx; ALLOC_OBJ_CLEAR(new_ctx, struct tls_root_ctx); - if (options->tls_server) - { - tls_ctx_server_new(new_ctx); + tls_ctx_new(new_ctx); - if (options->dh_file) - { - tls_ctx_load_dh_params(new_ctx, options->dh_file, options->dh_file_inline); - } - } - else /* if client */ + if (options->tls_server && options->dh_file) { - tls_ctx_client_new(new_ctx); + tls_ctx_load_dh_params(new_ctx, options->dh_file, options->dh_file_inline); } /* Restrict allowed certificate crypto algorithms */ diff --git a/src/openvpn/ssl_backend.h b/src/openvpn/ssl_backend.h index 816fb9c..a6d57f2 100644 --- a/src/openvpn/ssl_backend.h +++ b/src/openvpn/ssl_backend.h @@ -117,18 +117,11 @@ int tls_version_max(void); /** - * Initialise a library-specific TLS context for a server. + * Initialise a library-specific TLS context. * * @param ctx TLS context to initialise */ -void tls_ctx_server_new(struct tls_root_ctx *ctx); - -/** - * Initialises a library-specific TLS context for a client. - * - * @param ctx TLS context to initialise - */ -void tls_ctx_client_new(struct tls_root_ctx *ctx); +void tls_ctx_new(struct tls_root_ctx *ctx); /** * Frees the library-specific TLSv1 context diff --git a/src/openvpn/ssl_mbedtls.c b/src/openvpn/ssl_mbedtls.c index 07caf08..6d7ac04 100644 --- a/src/openvpn/ssl_mbedtls.c +++ b/src/openvpn/ssl_mbedtls.c @@ -88,7 +88,7 @@ } void -tls_ctx_server_new(struct tls_root_ctx *ctx) +tls_ctx_new(struct tls_root_ctx *ctx) { ASSERT(NULL != ctx); CLEAR(*ctx); @@ -99,24 +99,9 @@ ALLOC_OBJ_CLEAR(ctx->ca_chain, mbedtls_x509_crt); - ctx->endpoint = MBEDTLS_SSL_IS_SERVER; ctx->initialised = true; } -void -tls_ctx_client_new(struct tls_root_ctx *ctx) -{ - ASSERT(NULL != ctx); - CLEAR(*ctx); - -#if MBEDTLS_VERSION_NUMBER < 0x04000000 - ALLOC_OBJ_CLEAR(ctx->dhm_ctx, mbedtls_dhm_context); -#endif - ALLOC_OBJ_CLEAR(ctx->ca_chain, mbedtls_x509_crt); - - ctx->endpoint = MBEDTLS_SSL_IS_CLIENT; - ctx->initialised = true; -} void tls_ctx_free(struct tls_root_ctx *ctx) @@ -1141,7 +1126,8 @@ /* Initialise SSL config */ ALLOC_OBJ_CLEAR(ks_ssl->ssl_config, mbedtls_ssl_config); mbedtls_ssl_config_init(ks_ssl->ssl_config); - mbedtls_ssl_config_defaults(ks_ssl->ssl_config, ssl_ctx->endpoint, MBEDTLS_SSL_TRANSPORT_STREAM, + int endpoint = is_server ? MBEDTLS_SSL_IS_SERVER : MBEDTLS_SSL_IS_CLIENT; + mbedtls_ssl_config_defaults(ks_ssl->ssl_config, endpoint, MBEDTLS_SSL_TRANSPORT_STREAM, MBEDTLS_SSL_PRESET_DEFAULT); #ifdef MBEDTLS_DEBUG_C /* We only want to have mbed TLS generate debug level logging when we would @@ -1530,7 +1516,7 @@ struct tls_root_ctx tls_ctx; const int *ciphers = mbedtls_ssl_list_ciphersuites(); - tls_ctx_server_new(&tls_ctx); + tls_ctx_new(&tls_ctx); tls_ctx_set_cert_profile(&tls_ctx, tls_cert_profile); tls_ctx_restrict_ciphers(&tls_ctx, cipher_list); diff --git a/src/openvpn/ssl_mbedtls.h b/src/openvpn/ssl_mbedtls.h index 6b678b2..32d4f60 100644 --- a/src/openvpn/ssl_mbedtls.h +++ b/src/openvpn/ssl_mbedtls.h @@ -114,8 +114,6 @@ { bool initialised; /**< True if the context has been initialised */ - int endpoint; /**< Whether or not this is a server or a client */ - #if MBEDTLS_VERSION_NUMBER < 0x04000000 mbedtls_dhm_context *dhm_ctx; /**< Diffie-Helmann-Merkle context */ #endif diff --git a/src/openvpn/ssl_openssl.c b/src/openvpn/ssl_openssl.c index 32b13db..e4e78e9 100644 --- a/src/openvpn/ssl_openssl.c +++ b/src/openvpn/ssl_openssl.c @@ -100,37 +100,19 @@ } void -tls_ctx_server_new(struct tls_root_ctx *ctx) +tls_ctx_new(struct tls_root_ctx *ctx) { ASSERT(NULL != ctx); - ctx->ctx = SSL_CTX_new_ex(tls_libctx, NULL, SSLv23_server_method()); + ctx->ctx = SSL_CTX_new_ex(tls_libctx, NULL, TLS_method()); if (ctx->ctx == NULL) { - crypto_msg(M_FATAL, "SSL_CTX_new SSLv23_server_method"); + crypto_msg(M_FATAL, "SSL_CTX_new TLS_method"); } if (ERR_peek_error() != 0) { - crypto_msg(M_WARN, "Warning: TLS server context initialisation " - "has warnings."); - } -} - -void -tls_ctx_client_new(struct tls_root_ctx *ctx) -{ - ASSERT(NULL != ctx); - - ctx->ctx = SSL_CTX_new_ex(tls_libctx, NULL, SSLv23_client_method()); - - if (ctx->ctx == NULL) - { - crypto_msg(M_FATAL, "SSL_CTX_new SSLv23_client_method"); - } - if (ERR_peek_error() != 0) - { - crypto_msg(M_WARN, "Warning: TLS client context initialisation " + crypto_msg(M_WARN, "Warning: TLS context initialisation " "has warnings."); } } diff --git a/tests/unit_tests/openvpn/test_ssl.c b/tests/unit_tests/openvpn/test_ssl.c index d473d67..54d52a0 100644 --- a/tests/unit_tests/openvpn/test_ssl.c +++ b/tests/unit_tests/openvpn/test_ssl.c @@ -175,7 +175,7 @@ struct gc_arena gc = gc_new(); struct tls_root_ctx ctx = { 0 }; - tls_ctx_client_new(&ctx); + tls_ctx_new(&ctx); tls_ctx_load_cert_file(&ctx, unittest_cert, true); openvpn_x509_cert_t *cert = NULL; @@ -208,13 +208,13 @@ /* test loading of inlined cert and key. * loading the key also checks that it matches the loaded certificate */ - tls_ctx_client_new(&ctx); + tls_ctx_new(&ctx); tls_ctx_load_cert_file(&ctx, unittest_cert, true); assert_int_equal(tls_ctx_load_priv_file(&ctx, unittest_key, true), 0); tls_ctx_free(&ctx); /* test loading of cert and key from file */ - tls_ctx_client_new(&ctx); + tls_ctx_new(&ctx); tls_ctx_load_cert_file(&ctx, global_state.certfile, false); assert_int_equal(tls_ctx_load_priv_file(&ctx, global_state.keyfile, false), 0); tls_ctx_free(&ctx); @@ -252,7 +252,7 @@ string_mod(BSTR(&keyuri), CC_ANY, CC_BACKSLASH, '/'); #endif /* _WIN32 */ - tls_ctx_client_new(&ctx); + tls_ctx_new(&ctx); tls_ctx_load_cert_file(&ctx, BSTR(&certuri), false); assert_int_equal(tls_ctx_load_priv_file(&ctx, BSTR(&keyuri), false), 0); tls_ctx_free(&ctx);