Compare commits
No commits in common. "master" and "feature/acert-cli" have entirely different histories.
master
...
feature/ac
3766 changed files with 259273 additions and 342895 deletions
1433
.clang-format
1433
.clang-format
File diff suppressed because it is too large
Load diff
457
.codespellrc
457
.codespellrc
|
|
@ -1,457 +0,0 @@
|
|||
[codespell]
|
||||
ignore-regex = \b[a-zA-Z][a-zA-Z]\b
|
||||
|
||||
uri-ignore-words-list =
|
||||
standarts
|
||||
|
||||
ignore-words-list =
|
||||
aas,
|
||||
Aas,
|
||||
AAS,
|
||||
abd,
|
||||
ABD,
|
||||
accreting,
|
||||
ADDAD,
|
||||
addin,
|
||||
adin,
|
||||
ADn,
|
||||
AFAIR,
|
||||
afile,
|
||||
afterAll,
|
||||
AfterAll,
|
||||
Ake,
|
||||
ALine,
|
||||
allEdges,
|
||||
alloced,
|
||||
alloco,
|
||||
allws,
|
||||
alo,
|
||||
Alo,
|
||||
alow,
|
||||
ALS,
|
||||
alsptd,
|
||||
ang,
|
||||
ans,
|
||||
anS,
|
||||
ANS,
|
||||
aNULL,
|
||||
archType,
|
||||
arithmetics,
|
||||
assertIn,
|
||||
ategory,
|
||||
atLeast,
|
||||
AtLeast,
|
||||
atMost,
|
||||
biom,
|
||||
bion,
|
||||
bootup,
|
||||
BRE,
|
||||
Buda,
|
||||
buildd,
|
||||
bve,
|
||||
CAF,
|
||||
cann,
|
||||
CANN,
|
||||
cant,
|
||||
Chang,
|
||||
checkin,
|
||||
childs,
|
||||
ciph,
|
||||
circularly,
|
||||
Circularly,
|
||||
claus,
|
||||
Claus,
|
||||
clen,
|
||||
CLOS,
|
||||
co-ordinate,
|
||||
co-ordinates,
|
||||
Collet,
|
||||
Collison,
|
||||
compilability,
|
||||
compileTime,
|
||||
CompileTime,
|
||||
complies,
|
||||
COMPLIES,
|
||||
configury,
|
||||
consumation,
|
||||
couldn,
|
||||
couter,
|
||||
crasher,
|
||||
crashers,
|
||||
crate,
|
||||
Crate,
|
||||
CRATE,
|
||||
creat,
|
||||
CREAT,
|
||||
CrOS,
|
||||
crypted,
|
||||
CRYPTED,
|
||||
currentY,
|
||||
DAA,
|
||||
datas,
|
||||
debbugs,
|
||||
Debbugs,
|
||||
DELET,
|
||||
dependancies,
|
||||
dependancy,
|
||||
dependant,
|
||||
deque,
|
||||
Deque,
|
||||
dota,
|
||||
doubleclick,
|
||||
doubleClick,
|
||||
DoubleClick,
|
||||
dout,
|
||||
Dout,
|
||||
DOUT,
|
||||
dum,
|
||||
dur,
|
||||
Dur,
|
||||
Durin,
|
||||
ect,
|
||||
ECT,
|
||||
ede,
|
||||
EDE,
|
||||
endianess,
|
||||
endin,
|
||||
engineerr,
|
||||
ENGINEerr,
|
||||
equest,
|
||||
equests,
|
||||
FileTest,
|
||||
FILETEST,
|
||||
filetests,
|
||||
flate,
|
||||
Flate,
|
||||
FLATE,
|
||||
fpr,
|
||||
FPR,
|
||||
FPT,
|
||||
gord,
|
||||
gost,
|
||||
Gost,
|
||||
GOST,
|
||||
Hart,
|
||||
hashin,
|
||||
hasTable,
|
||||
hel,
|
||||
hist,
|
||||
HIST,
|
||||
HSI,
|
||||
htmp,
|
||||
ifset,
|
||||
igest,
|
||||
iif,
|
||||
IIF,
|
||||
implementor,
|
||||
Implementor,
|
||||
implementors,
|
||||
Implementors,
|
||||
inactivate,
|
||||
inbrace,
|
||||
indention,
|
||||
indx,
|
||||
ine,
|
||||
informat,
|
||||
inh,
|
||||
inout,
|
||||
inOut,
|
||||
InOut,
|
||||
INOUT,
|
||||
ISCONNECTION,
|
||||
isnt,
|
||||
ist,
|
||||
IST,
|
||||
keep-alives,
|
||||
keypair,
|
||||
keyPair,
|
||||
Keypair,
|
||||
KeyPair,
|
||||
KEYPAIR,
|
||||
keypairs,
|
||||
keyPairs,
|
||||
Keypairs,
|
||||
KeyPairs,
|
||||
keyserver,
|
||||
LAMDA,
|
||||
larg,
|
||||
leapYear,
|
||||
LOd,
|
||||
LOD,
|
||||
Maked,
|
||||
Manger,
|
||||
Manuel,
|
||||
ment,
|
||||
Merget,
|
||||
minimise,
|
||||
mis,
|
||||
Mis,
|
||||
MIS,
|
||||
mitre,
|
||||
Mitre,
|
||||
MITRE,
|
||||
mmaped,
|
||||
msdos,
|
||||
MSDOS,
|
||||
nam,
|
||||
Nam,
|
||||
NAM,
|
||||
nclusion,
|
||||
Ned,
|
||||
nin,
|
||||
Nin,
|
||||
nmake,
|
||||
NMake,
|
||||
NMAKE,
|
||||
NOo,
|
||||
notin,
|
||||
Notin,
|
||||
NotIn,
|
||||
numer,
|
||||
OCE,
|
||||
offsetp,
|
||||
ois,
|
||||
onText,
|
||||
OnText,
|
||||
openin,
|
||||
OptIn,
|
||||
OPTIO,
|
||||
origN,
|
||||
outin,
|
||||
paeth,
|
||||
Paeth,
|
||||
PAETH,
|
||||
parm,
|
||||
pARM,
|
||||
Parm,
|
||||
PARM,
|
||||
parms,
|
||||
pARMS,
|
||||
Parms,
|
||||
PARMs,
|
||||
PARMS,
|
||||
pass-thru,
|
||||
passin,
|
||||
poping,
|
||||
pres,
|
||||
Pres,
|
||||
prevEnd,
|
||||
pris,
|
||||
PullRequest,
|
||||
que,
|
||||
re-usable,
|
||||
Re-usable,
|
||||
re-use,
|
||||
Re-use,
|
||||
re-used,
|
||||
Re-used,
|
||||
re-uses,
|
||||
Re-uses,
|
||||
re-using,
|
||||
Re-using,
|
||||
readd,
|
||||
Readd,
|
||||
readded,
|
||||
Readded,
|
||||
regArg,
|
||||
regArgs,
|
||||
requestor,
|
||||
Requestor,
|
||||
requestors,
|
||||
rewinded,
|
||||
roperties,
|
||||
sav,
|
||||
SEH,
|
||||
ser,
|
||||
Ser,
|
||||
SER,
|
||||
servent,
|
||||
sHolder,
|
||||
shouldBe,
|
||||
shouldnot,
|
||||
SHS,
|
||||
siz,
|
||||
SIZ,
|
||||
SME,
|
||||
SOM,
|
||||
Sorce,
|
||||
sover,
|
||||
splitted,
|
||||
statics,
|
||||
Statics,
|
||||
strRange,
|
||||
succes,
|
||||
technics,
|
||||
testss,
|
||||
therefor,
|
||||
Therefor,
|
||||
therefrom,
|
||||
Thi,
|
||||
thirdparty,
|
||||
thirdParty,
|
||||
Thirdparty,
|
||||
ThirdParty,
|
||||
THIRDPARTY,
|
||||
thru,
|
||||
Thur,
|
||||
THUR,
|
||||
tmplate,
|
||||
tne,
|
||||
tolen,
|
||||
tthe,
|
||||
ture,
|
||||
uis,
|
||||
UIs,
|
||||
upto,
|
||||
upTo,
|
||||
uptodate,
|
||||
upToDate,
|
||||
UpToDate,
|
||||
useable,
|
||||
Useable,
|
||||
userA,
|
||||
UserA,
|
||||
usign,
|
||||
varN,
|
||||
vertexes,
|
||||
vew,
|
||||
vor,
|
||||
WAN,
|
||||
wasn,
|
||||
Widgits,
|
||||
Wirth,
|
||||
wont,
|
||||
WRONLY,
|
||||
WTH
|
||||
|
||||
skip =
|
||||
[cC]hange.[lL]og*,
|
||||
[cC]hange[lL]og*,
|
||||
[cC]hanges,
|
||||
[cC]hanges[._-]*,
|
||||
*__*__*.html,
|
||||
*_8h_source.html,
|
||||
*_8h.html,
|
||||
*.asc,
|
||||
*.bin,
|
||||
*.crt,
|
||||
*.csr,
|
||||
*.css.map,
|
||||
*.eps,
|
||||
*.fr.utf-8,
|
||||
*.git,
|
||||
*.html.de,
|
||||
*.html.es,
|
||||
*.html.fr,
|
||||
*.html.ko.euc-kr,
|
||||
*.html.pt-br,
|
||||
*.info_[0-9],
|
||||
*.ipynb,
|
||||
*.ja.utf8,
|
||||
*.js.map,
|
||||
*.min.js,
|
||||
*.pdf,
|
||||
*.pem,
|
||||
*.po,
|
||||
*.ppm,
|
||||
*.ps,
|
||||
*.rtf,
|
||||
*.sum,
|
||||
*.svg,
|
||||
*.svn,
|
||||
*.tr.utf8,
|
||||
*.xpm,
|
||||
*.zh-cn.utf8,
|
||||
*.zlib,
|
||||
*[._-][cC]hanges,
|
||||
*[._-]CHANGES,
|
||||
*/.mailmap,
|
||||
*/.versions/*,
|
||||
*/[eE]ncode/*,
|
||||
*/[eE]ncodings/*,
|
||||
*/[lL]ang/*,
|
||||
*/[lL]anguage/*,
|
||||
*/[lL]anguages/*,
|
||||
*/[lL]ocale,
|
||||
*/[mM]ath[jJ]ax/*,
|
||||
*/[tT]hird*[pP]arty/*,
|
||||
*/[tT]ranslation/*,
|
||||
*/[tT]ranslations/*,
|
||||
*/*.desktop,
|
||||
*/*.desktop.in,
|
||||
*/*[^a/]test/*,
|
||||
*/*[^a/]tests/*,
|
||||
*/*[lL]ocal[ei]*/*,
|
||||
*/3rd*[pP]arty/*,
|
||||
*/aspell/*,
|
||||
*/AUTHORS*,
|
||||
*/charsets/*,
|
||||
*/chrtrans/*,
|
||||
*/codepage/*,
|
||||
*/data/*,
|
||||
*/deps/*,
|
||||
*/dict/*,
|
||||
*/dictionaries/*,
|
||||
*/doc*/[a-df-z][a-z]/*,
|
||||
*/doc*/[a-z][a-z][_-][a-zA-Z][a-zA-Z]/*,
|
||||
*/doc*/e[a-mo-z]/*,
|
||||
*/extern/*,
|
||||
*/external/*,
|
||||
*/externals/*,
|
||||
*/help/[a-df-z][a-z]/*,
|
||||
*/help/[a-z][a-z]_[A-Z][A-Z]/*,
|
||||
*/help/es/*,
|
||||
*/i18n/*,
|
||||
*/icu/*,
|
||||
*/info/[a-df-z][a-z]/*,
|
||||
*/info/[a-z][a-z]_[A-Z][A-Z]/*,
|
||||
*/info/es/*,
|
||||
*/intl/*,
|
||||
*/l10n/*,
|
||||
*/langmap/*,
|
||||
*/langs/*,
|
||||
*/LICENSE,
|
||||
*/man*/[a-df-z][a-z]/*,
|
||||
*/man*/[a-z][a-z][_-][a-zA-Z][a-zA-Z]/*,
|
||||
*/man*/e[a-mo-z]/*,
|
||||
*/messages[_./][a-df-z][a-z][_./]*,
|
||||
*/messages[_./][a-z][a-z]_[A-Z][A-Z][_./]*,
|
||||
*/messages[_./]es[_./]*,
|
||||
*/rfc[1-9]*.txt,
|
||||
*/runtime/*,
|
||||
*/searchindex.js,
|
||||
*/test*/*,
|
||||
*/test/danetest.in,
|
||||
*/test/data2.bin,
|
||||
*/test/recipes/30-test_evp_data/evppkey_kas.txt,
|
||||
*/test/recipes/30-test_evp_data/evppkey.txt,
|
||||
*/unicode/*,
|
||||
*/Unicode/*,
|
||||
*/unicore/*,
|
||||
*/vendor/*,
|
||||
*/vendors/*,
|
||||
*/yarn.lock,
|
||||
*codespell-check.sh,
|
||||
*lorem-ipsum*,
|
||||
*man[12345657]/*
|
||||
/fonts/*,
|
||||
ABOUT-NLS,
|
||||
authors.xml,
|
||||
CHANGE.log*,
|
||||
CHANGELOG*,
|
||||
CHANGES,
|
||||
CHANGES[._-]*,
|
||||
CONTRIBUTORS*,
|
||||
CREDITS,
|
||||
CREDITS.TXT,
|
||||
DONATIONS,
|
||||
external/*,
|
||||
jquery.js,
|
||||
jquery.min.map,
|
||||
localization*-[a-z][a-z]_[a-zA-Z][a-zA-Z].*,
|
||||
localization*-[a-z][a-z].*,
|
||||
MAINTAINERS,
|
||||
NormalizationTest.txt,
|
||||
package-lock.json,
|
||||
THANKS*,
|
||||
UnicodeData.txt
|
||||
|
|
@ -1,5 +1,5 @@
|
|||
#
|
||||
# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2023 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -10,3 +10,4 @@
|
|||
# List file names or patterns you want ctags to ignore.
|
||||
--exclude=.ctags.d
|
||||
--exclude=test
|
||||
--exclude=check-format-test-positives.c
|
||||
|
|
|
|||
|
|
@ -1,4 +1,2 @@
|
|||
# Run util/openssl-format-source -v -c .
|
||||
0f113f3ee4d629ef9a4a30911b22b224772085e5
|
||||
# 4.0-POST-CLANG-FORMAT-WEBKIT
|
||||
2fab90bb5e1937f1c2125eab144f7f6c39e70087
|
||||
|
|
|
|||
1
.github/CODEOWNERS
vendored
1
.github/CODEOWNERS
vendored
|
|
@ -1 +0,0 @@
|
|||
/.github/workflows/ @quarckster
|
||||
6
.github/PULL_REQUEST_TEMPLATE.md
vendored
6
.github/PULL_REQUEST_TEMPLATE.md
vendored
|
|
@ -3,11 +3,7 @@ Thank you for your pull request. Please review these requirements:
|
|||
|
||||
Contributors guide: https://github.com/openssl/openssl/blob/master/CONTRIBUTING.md
|
||||
|
||||
Include a clear description of the issue or feature above this comment if not already provided. This should briefly outline the issue or feature being addressed, along with any relevant implementation details. For performance improvements, include benchmark results as well.
|
||||
|
||||
Please always add meaningful commit messages. Commit message titles (the first line of each commit message which should be separated by an empty line from the rest of the message) should be kept to 50-70 characters if possible. Further details and Fixes #issue number annotations should be placed in the commit message body (i.e, after the empty line).
|
||||
|
||||
Pull requests and commits should be self-contained, allowing readers to understand what changed and why without needing to reference related issues or having prior knowledge. Individual commit messages should include all relevant details to ensure future contributors can easily follow the git history. Clearly explain what is changing and why, and feel free to include detailed (long) descriptions when beneficial to understanding.
|
||||
Other than that, provide a description above this comment if there isn't one already
|
||||
|
||||
If this fixes a GitHub issue, make sure to have a line saying 'Fixes #XXXX' (without quotes) in the commit message.
|
||||
-->
|
||||
|
|
|
|||
5
.github/ci-deps.json
vendored
5
.github/ci-deps.json
vendored
|
|
@ -1,5 +0,0 @@
|
|||
{
|
||||
"jom-1.1.7.exe": "8435dbf96eb9ee65395d46d04dc3af2ff6b2618aefbc7964eeede9be669e8bd6",
|
||||
"nasm-3.01-installer-x64.exe": "7881e9febc8b6558581041019b7890f109bef0694d93ed82c9589794c7b5a600",
|
||||
"nasm-3.01-installer-x86.exe": "2e3041dd2abe36cb7e9938057c3cf090dd2eac42d3280957359f87c4d83b9ed0"
|
||||
}
|
||||
2
.github/dependabot.yml
vendored
2
.github/dependabot.yml
vendored
|
|
@ -13,5 +13,3 @@ updates:
|
|||
- "approval: review pending"
|
||||
reviewers:
|
||||
- "openssl/committers"
|
||||
cooldown:
|
||||
default-days: 7
|
||||
|
|
|
|||
202
.github/workflows/aarch64-more-cross-compiles.yml
vendored
202
.github/workflows/aarch64-more-cross-compiles.yml
vendored
|
|
@ -1,202 +0,0 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: Cross Compile for AArch64 Extensions
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, reopened, edited, synchronize]
|
||||
push:
|
||||
schedule:
|
||||
- cron: '05 03 * * *'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
cross-compilation-aarch64:
|
||||
# pull request title contains 'aarch64'
|
||||
# pull request title contains 'arm64'
|
||||
# pull request body contains '[aarch64 ci]'
|
||||
# push event commit message contains '[aarch64 ci]'
|
||||
# cron job
|
||||
# manual dispatch
|
||||
if: contains(github.event.pull_request.title, 'aarch64') || contains(github.event.pull_request.title, 'AArch64') || contains(github.event.pull_request.title, 'arm64') || contains(github.event.pull_request.body, '[aarch64 ci]') || contains(github.event.head_commit.message, '[aarch64 ci]') || (github.event_name == 'schedule' && github.repository == 'openssl/openssl') || github.event_name == 'workflow_dispatch'
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
# The platform matrix specifies:
|
||||
# arch: the architecture to build for, this defines the tool-chain
|
||||
# prefix {arch}- and the Debian compiler package gcc-{arch}
|
||||
# name.
|
||||
# libs: the Debian package for the necessary link/runtime libraries.
|
||||
# target: the OpenSSL configuration target to use, this is passed
|
||||
# directly to the config command line.
|
||||
# fips: set to "no" to disable building FIPS, leave unset to
|
||||
# build the FIPS provider.
|
||||
# tests: omit this to run all the tests using QEMU, set it to "none"
|
||||
# to never run the tests, otherwise its value is passed to
|
||||
# the "make test" command to allow selective disabling of
|
||||
# tests.
|
||||
# qemucpu: optional; string that describes CPU properties.
|
||||
# The string will be used to set the QEMU_CPU variable.
|
||||
# opensslcapsname: optional; string that describes the postfix of the
|
||||
# OpenSSL environment variable that defines CPU
|
||||
# capabilities. E.g. "foo" will result in an
|
||||
# environment variable with the name OPENSSL_foo.
|
||||
# opensslcaps: optional; if opensslcapsname (see above) is set, then
|
||||
# this string will be used as content for the OpenSSL
|
||||
# capabilities variable.
|
||||
# capslabel: label used for artifacts.
|
||||
platform: [
|
||||
{
|
||||
# Baseline Armv8 crypto extensions:
|
||||
# include/crypto/aes_platform.h
|
||||
# providers/implementations/ciphers/cipher_aes_hw_armv8.inc
|
||||
# crypto/sha/asm/sha1-armv8.pl
|
||||
# crypto/aes/asm/aes-sha256-armv8.pl
|
||||
arch: aarch64-linux-gnu,
|
||||
libs: libc6-dev-arm64-cross,
|
||||
target: linux-aarch64,
|
||||
fips: no,
|
||||
qemucpu: max,
|
||||
opensslcapsname: armcap, # OPENSSL_armcap
|
||||
opensslcaps: "0x1d",
|
||||
capslabel: armv8-crypto
|
||||
}, {
|
||||
# PMULL-enabled AES-GCM / GHASH:
|
||||
# include/crypto/aes_platform.h
|
||||
# crypto/modes/asm/aes-gcm-armv8_64.pl
|
||||
# crypto/modes/asm/ghashv8-armx.pl
|
||||
arch: aarch64-linux-gnu,
|
||||
libs: libc6-dev-arm64-cross,
|
||||
target: linux-aarch64,
|
||||
fips: no,
|
||||
qemucpu: max,
|
||||
opensslcapsname: armcap, # OPENSSL_armcap
|
||||
opensslcaps: "0x3d",
|
||||
capslabel: armv8-pmull
|
||||
}, {
|
||||
# SHA512 extension:
|
||||
# crypto/aes/asm/aes-sha512-armv8.pl
|
||||
arch: aarch64-linux-gnu,
|
||||
libs: libc6-dev-arm64-cross,
|
||||
target: linux-aarch64,
|
||||
fips: no,
|
||||
qemucpu: max,
|
||||
opensslcapsname: armcap, # OPENSSL_armcap
|
||||
opensslcaps: "0x7d",
|
||||
capslabel: armv8-sha512
|
||||
}, {
|
||||
# SHA3-accelerated path. Since OPENSSL_armcap short-circuits runtime
|
||||
# detection, include the derived "worth using" and unroll bits too:
|
||||
# crypto/sha/sha3.c
|
||||
# providers/implementations/digests/sha3_prov.c
|
||||
# providers/implementations/ciphers/cipher_aes_gcm_hw_armv8.inc
|
||||
# providers/implementations/ciphers/cipher_aes_hw_armv8.inc
|
||||
arch: aarch64-linux-gnu,
|
||||
libs: libc6-dev-arm64-cross,
|
||||
target: linux-aarch64,
|
||||
fips: no,
|
||||
qemucpu: max,
|
||||
opensslcapsname: armcap, # OPENSSL_armcap
|
||||
opensslcaps: "0x1987d",
|
||||
capslabel: armv8-sha3
|
||||
}, {
|
||||
# SVE2 Poly1305 path. OPENSSL_armcap requires the derived
|
||||
# ARMV9_SVE2_POLY1305 bit to be set explicitly when capability
|
||||
# probing is overridden:
|
||||
# crypto/poly1305/asm/poly1305-armv8.pl
|
||||
# crypto/chacha/asm/chacha-armv8-sve.pl
|
||||
arch: aarch64-linux-gnu,
|
||||
libs: libc6-dev-arm64-cross,
|
||||
target: linux-aarch64,
|
||||
fips: no,
|
||||
qemucpu: max,
|
||||
opensslcapsname: armcap, # OPENSSL_armcap
|
||||
opensslcaps: "0x2601d",
|
||||
capslabel: armv9-sve2-poly1305
|
||||
}
|
||||
]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: install packages
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install \
|
||||
gcc-${{ matrix.platform.arch }} \
|
||||
${{ matrix.platform.libs }}
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
|
||||
- name: config with FIPS
|
||||
if: matrix.platform.fips != 'no'
|
||||
run: |
|
||||
./config --banner=Configured --strict-warnings enable-fips enable-lms \
|
||||
--cross-compile-prefix=${{ matrix.platform.arch }}- \
|
||||
${{ matrix.platform.target }}
|
||||
- name: config without FIPS
|
||||
if: matrix.platform.fips == 'no'
|
||||
run: |
|
||||
./config --banner=Configured --strict-warnings enable-lms \
|
||||
--cross-compile-prefix=${{ matrix.platform.arch }}- \
|
||||
${{ matrix.platform.target }}
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
|
||||
- name: install qemu
|
||||
if: matrix.platform.tests != 'none'
|
||||
run: sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install qemu-user
|
||||
|
||||
- name: Set QEMU environment
|
||||
if: matrix.platform.qemucpu != ''
|
||||
run: echo "QEMU_CPU=${{ matrix.platform.qemucpu }}" >> $GITHUB_ENV
|
||||
|
||||
- name: Set OpenSSL caps environment
|
||||
if: matrix.platform.opensslcapsname != ''
|
||||
run: echo "OPENSSL_${{ matrix.platform.opensslcapsname }}=\
|
||||
${{ matrix.platform.opensslcaps }}" >> $GITHUB_ENV
|
||||
|
||||
- name: get cpu info
|
||||
run: cat /proc/cpuinfo
|
||||
|
||||
- name: get openssl cpu info
|
||||
if: matrix.platform.tests != 'none'
|
||||
run: QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} ./util/opensslwrap.sh info -cpusettings
|
||||
|
||||
- name: make all tests
|
||||
if: github.event_name == 'push' && matrix.platform.tests == ''
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="-test_afalg" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: make some tests
|
||||
if: github.event_name == 'push' && matrix.platform.tests != 'none' && matrix.platform.tests != ''
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="${{ matrix.platform.tests }} -test_afalg" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: make evp tests
|
||||
if: github.event_name == 'pull_request' && matrix.platform.tests != 'none'
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="test_evp*" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
with:
|
||||
name: "cross-compiles-aarch64@${{ matrix.platform.capslabel }}"
|
||||
path: artifacts.tar.gz
|
||||
if-no-files-found: ignore
|
||||
167
.github/workflows/avx512-sde.yml
vendored
167
.github/workflows/avx512-sde.yml
vendored
|
|
@ -1,167 +0,0 @@
|
|||
# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright (c) 2026 Intel Corporation. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
# Run AVX512-specific tests under Intel SDE.
|
||||
#
|
||||
# GitHub Actions runners currently do not have AVX512 hardware.
|
||||
# Intel SDE emulates AVX512 instructions and spoofs CPUID,
|
||||
# so AVX512 code paths are exercised.
|
||||
#
|
||||
# To update Intel SDE: find the new mirror ID and file date from
|
||||
# https://www.intel.com/content/www/us/en/download/684897
|
||||
# and update the three env vars below.
|
||||
|
||||
name: AVX512 tests via Intel SDE
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '30 02 * * *'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
SDE_VERSION: 10.8.0
|
||||
SDE_DATE: 2026-03-15
|
||||
SDE_MIRROR_ID: 915934
|
||||
|
||||
jobs:
|
||||
linux:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: install NASM
|
||||
run: sudo apt-get install -y nasm
|
||||
|
||||
- name: install Intel SDE
|
||||
run: |
|
||||
SDE_URL="https://downloadmirror.intel.com/${SDE_MIRROR_ID}/sde-external-${SDE_VERSION}-${SDE_DATE}-lin.tar.xz"
|
||||
SDE_SHA256="50b320cd226acef7a491f5b321fc1be3c3c7984f9e27a456e64894b5b0979dd3"
|
||||
curl -fsSL -o /tmp/sde.tar.xz "$SDE_URL"
|
||||
echo "$SDE_SHA256 /tmp/sde.tar.xz" | sha256sum -c -
|
||||
mkdir /tmp/sde
|
||||
tar -xf /tmp/sde.tar.xz -C /tmp/sde/
|
||||
sudo mv /tmp/sde/sde-external-${SDE_VERSION}-${SDE_DATE}-lin /opt/sde
|
||||
echo "/opt/sde" >> "$GITHUB_PATH"
|
||||
|
||||
- name: config
|
||||
run: |
|
||||
./config --banner=Configured --strict-warnings no-shared enable-fips
|
||||
|
||||
- name: build
|
||||
run: make -j4
|
||||
|
||||
- name: show CPU and OpenSSL build info
|
||||
run: |
|
||||
cat /proc/cpuinfo | grep -m1 "model name"
|
||||
sde64 -icx -- ./apps/openssl version -c
|
||||
|
||||
- name: ml_dsa_internal_test (AVX512 via SDE)
|
||||
run: sde64 -icx -- ./test/ml_dsa_internal_test
|
||||
|
||||
- name: sha3_x4_internal_test (AVX512 via SDE)
|
||||
run: sde64 -icx -- ./test/sha3_x4_internal_test
|
||||
|
||||
- name: fipsinstall (FIPS KAT via SDE)
|
||||
run: sde64 -icx -- ./apps/openssl fipsinstall -module ./providers/fips.so -out /tmp/fipsmodule.cnf -provider_name fips
|
||||
|
||||
windows:
|
||||
runs-on: windows-2022
|
||||
env:
|
||||
VCVARS: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: install nasm
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-x64.exe"
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer
|
||||
$actual = (Get-FileHash $installer -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" }
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
"C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install nasm (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-x64.exe"
|
||||
Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win64/$installer" -OutFile $installer
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
"C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
|
||||
- name: install jom
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe'
|
||||
$actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" }
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip
|
||||
Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
|
||||
- name: install Intel SDE
|
||||
run: |
|
||||
$url = "https://downloadmirror.intel.com/$env:SDE_MIRROR_ID/sde-external-$env:SDE_VERSION-$env:SDE_DATE-win.tar.xz"
|
||||
$expected = "176F87C80EB42BB91B73E1428F4A0FD067DF322F901F9B4359B20B86B92C2BAE"
|
||||
curl.exe -fsSL -o sde-win.tar.xz $url
|
||||
$actual = (Get-FileHash sde-win.tar.xz -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SDE SHA256 mismatch: got $actual" }
|
||||
& "C:\Program Files\7-Zip\7z.exe" x sde-win.tar.xz -so | & "C:\Program Files\7-Zip\7z.exe" x -si -ttar -o"C:\sde"
|
||||
$sdeRoot = "C:\sde\sde-external-$env:SDE_VERSION-$env:SDE_DATE-win"
|
||||
if (-not (Test-Path "$sdeRoot\sde.exe")) { throw "sde.exe not found in $sdeRoot" }
|
||||
"$sdeRoot" | Out-File -FilePath $env:GITHUB_PATH -Append
|
||||
|
||||
- name: prepare build directory
|
||||
run: mkdir _build
|
||||
|
||||
- name: config
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "%VCVARS%"
|
||||
perl ..\Configure --banner=Configured --strict-warnings no-shared enable-fips no-makedepend
|
||||
|
||||
- name: build
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "%VCVARS%"
|
||||
jom /j4 /S
|
||||
|
||||
- name: show CPU and OpenSSL build info
|
||||
working-directory: _build
|
||||
run: sde -icx -- apps\openssl.exe version -c
|
||||
|
||||
- name: ml_dsa_internal_test (AVX512 via SDE)
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: sde -icx -- test\ml_dsa_internal_test.exe
|
||||
|
||||
- name: sha3_x4_internal_test (AVX512 via SDE)
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: sde -icx -- test\sha3_x4_internal_test.exe
|
||||
|
||||
- name: fipsinstall (FIPS KAT via SDE)
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: sde -icx -- apps\openssl.exe fipsinstall -module providers\fips.dll -out fipsmodule.cnf -provider_name fips
|
||||
64
.github/workflows/backport.yml
vendored
64
.github/workflows/backport.yml
vendored
|
|
@ -1,64 +0,0 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: Backports CI
|
||||
|
||||
on: [pull_request]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
check_backports:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
release: [
|
||||
{
|
||||
branch: '4.0',
|
||||
cppflags: ''
|
||||
}, {
|
||||
branch: '3.6',
|
||||
cppflags: ''
|
||||
}, {
|
||||
branch: '3.5',
|
||||
cppflags: 'CPPFLAGS=-ansi'
|
||||
}, {
|
||||
branch: '3.4',
|
||||
cppflags: 'CPPFLAGS=-ansi'
|
||||
}, {
|
||||
branch: '3.0',
|
||||
cppflags: 'CPPFLAGS=-ansi'
|
||||
}
|
||||
]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
if: ${{ contains(join(github.event.pull_request.labels.*.name,','),matrix.release.branch) }}
|
||||
with:
|
||||
ref: ${{ github.event.pull_request.head.sha }}
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: cherry-pick
|
||||
if: ${{ contains(join(github.event.pull_request.labels.*.name,','),matrix.release.branch) }}
|
||||
run: |
|
||||
REFEND=$(git rev-parse HEAD)
|
||||
REFSTART=$(git rev-parse $REFEND~${{ github.event.pull_request.commits }})
|
||||
git checkout ${{ format('openssl-{0}', matrix.release.branch) }}
|
||||
git config user.name "OpenSSL Machine"
|
||||
git config user.email "openssl-machine@openssl.org"
|
||||
echo Cherry-picking $REFSTART..$REFEND
|
||||
git cherry-pick $REFSTART..$REFEND || { git diff | head -n1000; exit 1; }
|
||||
- name: config
|
||||
if: ${{ contains(join(github.event.pull_request.labels.*.name,','),matrix.release.branch) }}
|
||||
run: ${{ matrix.release.cppflags }} ./config --strict-warnings --banner=Configured no-asm enable-fips --strict-warnings -D_DEFAULT_SOURCE && perl configdata.pm --dump
|
||||
- name: make
|
||||
if: ${{ contains(join(github.event.pull_request.labels.*.name,','),matrix.release.branch) }}
|
||||
run: make -s -j4
|
||||
- name: make test
|
||||
if: ${{ contains(join(github.event.pull_request.labels.*.name,','),matrix.release.branch) }}
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
26
.github/workflows/build_quic_interop_container.yml
vendored
Normal file
26
.github/workflows/build_quic_interop_container.yml
vendored
Normal file
|
|
@ -0,0 +1,26 @@
|
|||
name: "Build openssl interop container from master"
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '40 02 * * *'
|
||||
workflow_dispatch:
|
||||
|
||||
jobs:
|
||||
update_quay_container:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
- name: "log in to quay.io"
|
||||
run: |
|
||||
docker login -u openssl-ci+machine -p ${{ secrets.QUAY_IO_PASSWORD }} quay.io
|
||||
- name: "Build container"
|
||||
run: |
|
||||
cd test/quic-openssl-docker/
|
||||
docker build -t quay.io/openssl-ci/openssl-quic-interop:latest .
|
||||
- name: "Push to quay"
|
||||
run: |
|
||||
docker push quay.io/openssl-ci/openssl-quic-interop:latest
|
||||
|
||||
105
.github/workflows/check-news-changes.yml
vendored
105
.github/workflows/check-news-changes.yml
vendored
|
|
@ -1,105 +0,0 @@
|
|||
# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: "Scan to check for NEWS/CHANGES suggestions"
|
||||
|
||||
on: pull_request
|
||||
env:
|
||||
NEED_NEWS_CHANGES: "no"
|
||||
SKIP_NEWS_CHECK: "no"
|
||||
PR_NUMBER: ${{ github.event.number }}
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
scan_for_news_changes:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
fetch-depth: 0
|
||||
- name: "Check if we have the label to skip this test"
|
||||
run: |
|
||||
SKIP_TEST=$(gh pr view $PR_NUMBER --json labels --jq '.labels[] | select(.name == "no_news_changes_needed") | .name')
|
||||
if [ -n "$SKIP_TEST" ]; then
|
||||
echo "SKIP_NEWS_CHECK=yes" >> $GITHUB_ENV
|
||||
fi
|
||||
|
||||
- name: "Check if we already have a NEWS/CHANGES entry"
|
||||
if: ${{ env.SKIP_NEWS_CHECK == 'no' }}
|
||||
run: |
|
||||
git diff --name-only ${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }} > ./names.txt
|
||||
echo "changed files between ${{ github.event.pull_request.base.sha }} and ${{ github.event.pull_request.head.sha }}"
|
||||
cat ./names.txt
|
||||
set +e
|
||||
grep -q "NEWS\.md" names.txt
|
||||
if [ $? -eq 0 ]; then
|
||||
echo "FOUND_NEWS_CHANGES_ADDITION=yes" >> $GITHUB_ENV
|
||||
else
|
||||
grep -q "CHANGES\.md" names.txt
|
||||
if [ $? -eq 0 ]; then
|
||||
echo "FOUND_NEWS_CHANGES_ADDITION=yes" >> $GITHUB_ENV
|
||||
else
|
||||
echo "FOUND_NEWS_CHANGES_ADDITION=no" >> $GITHUB_ENV
|
||||
fi
|
||||
fi
|
||||
- name: "Check if this PR affects a CVE"
|
||||
if: ${{ env.FOUND_NEWS_CHANGES_ADDITION == 'no' && env.SKIP_NEWS_CHECK == 'no' }}
|
||||
run: |
|
||||
git log ${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }} > ./log.txt
|
||||
set +e
|
||||
grep -q "CVE-" ./log.txt
|
||||
if [ $? -eq 0 ]; then
|
||||
echo "Changes in this PR reference a CVE"
|
||||
echo "NEED_NEWS_CHANGES=yes" >> $GITHUB_ENV
|
||||
fi
|
||||
- name: "Check if this PR impacts a public API"
|
||||
if: ${{ env.FOUND_NEWS_CHANGES_ADDITION == 'no' && env.SKIP_NEWS_CHECK == 'no' }}
|
||||
run: |
|
||||
set +e
|
||||
git diff --name-only ${{ github.event.pull_request.base.sha }}..${{ github.event.pull_request.head.sha }} > ./names.txt
|
||||
echo "changed files between ${{ github.event.pull_request.base.sha }} and ${{ github.event.pull_request.head.sha }}"
|
||||
cat ./names.txt
|
||||
grep -q "include/openssl" ./names.txt
|
||||
if [ $? -eq 0 ]; then
|
||||
echo "Changes in this PR may impact public APIS's"
|
||||
echo "NEED_NEWS_CHANGES=yes" >> $GITHUB_ENV
|
||||
fi
|
||||
- name: "Check if this is a feature branch merge"
|
||||
if: ${{ env.FOUND_NEWS_CHANGES_ADDITION == 'no' && env.SKIP_NEWS_CHECK == 'no' }}
|
||||
run: |
|
||||
set +e
|
||||
echo ${{ github.head_ref }} | grep -q "feature"
|
||||
if [ $? -eq 0 ]; then
|
||||
echo "Feature branch found"
|
||||
echo "NEED_NEWS_CHANGES=yes" >> $GITHUB_ENV
|
||||
fi
|
||||
- name: "Check if configuration options have changed"
|
||||
if: ${{ env.FOUND_NEWS_CHANGES_ADDITION == 'no' && env.SKIP_NEWS_CHECK == 'no' }}
|
||||
run: |
|
||||
git checkout ${{ github.event.pull_request.base.sha }}
|
||||
set +e
|
||||
./Configure --help > ./before.txt 2>&1
|
||||
git checkout ${{ github.event.pull_request.head.sha }}
|
||||
./Configure --help > ./after.txt 2>&1
|
||||
set -e
|
||||
CONF_CHANGE=$(diff ./before.txt ./after.txt | wc -l)
|
||||
if [ $CONF_CHANGE -ne 0 ]; then
|
||||
echo "Configuration options changes"
|
||||
echo "NEED_NEWS_CHANGES=yes" >> $GITHUB_ENV
|
||||
fi
|
||||
- name: "Report Results"
|
||||
if: ${{ env.SKIP_NEWS_CHECK == 'no' }}
|
||||
run: |
|
||||
if [ "${{ env.NEED_NEWS_CHANGES }}" == "yes" ]; then
|
||||
echo "Suggest that you add a NEWS/CHANGES entry for this PR"
|
||||
echo "Alternatively, quiet this suggestion by applying the no_news_changes_needed label"
|
||||
exit 1
|
||||
fi
|
||||
|
||||
|
||||
125
.github/workflows/ci-doc-changes.yml
vendored
125
.github/workflows/ci-doc-changes.yml
vendored
|
|
@ -1,125 +0,0 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: Documentation and Installability CI
|
||||
|
||||
on: [pull_request, push]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
OSSL_RUN_CI_TESTS: 1
|
||||
|
||||
jobs:
|
||||
check_docs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump
|
||||
- name: make build_generated
|
||||
run: make -s build_generated
|
||||
- name: make doc-nits
|
||||
run: make doc-nits
|
||||
- name: make help
|
||||
run: make help
|
||||
- name: make md-nits
|
||||
run: |
|
||||
sudo gem install mdl
|
||||
make md-nits
|
||||
|
||||
# out-of-source-and-install checks multiple things at the same time:
|
||||
# - That building, testing and installing works from an out-of-source
|
||||
# build tree
|
||||
# - That building, testing and installing works with a read-only source
|
||||
# tree
|
||||
out-of-readonly-source-and-install-ubuntu:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
path: ./source
|
||||
persist-credentials: false
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
working-directory: ./source
|
||||
- name: make source read-only
|
||||
run: chmod -R a-w ./source
|
||||
- name: create build and install directories
|
||||
run: |
|
||||
mkdir ./build
|
||||
mkdir ./install
|
||||
- name: config
|
||||
run: |
|
||||
../source/config --banner=Configured enable-demos enable-h3demo enable-fips enable-lms enable-quic enable-acvp-tests --strict-warnings --prefix=$(cd ../install; pwd)
|
||||
perl configdata.pm --dump
|
||||
working-directory: ./build
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
working-directory: ./build
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
working-directory: ./build
|
||||
- name: make test
|
||||
run: ../source/.github/workflows/make-test
|
||||
working-directory: ./build
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
with:
|
||||
name: "ci@out-of-readonly-source-and-install-ubuntu"
|
||||
path: build/artifacts.tar.gz
|
||||
- name: make install
|
||||
run: make install
|
||||
working-directory: ./build
|
||||
|
||||
out-of-readonly-source-and-install-macos:
|
||||
runs-on: macos-15
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
path: ./source
|
||||
persist-credentials: false
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
working-directory: ./source
|
||||
- name: make source read-only
|
||||
run: chmod -R a-w ./source
|
||||
- name: create build and install directories
|
||||
run: |
|
||||
mkdir ./build
|
||||
mkdir ./install
|
||||
- name: config
|
||||
run: |
|
||||
../source/config --banner=Configured enable-fips enable-lms enable-demos enable-h3demo enable-quic enable-acvp-tests --strict-warnings --prefix=$(cd ../install; pwd)
|
||||
perl configdata.pm --dump
|
||||
working-directory: ./build
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
working-directory: ./build
|
||||
- name: get cpu info
|
||||
run: |
|
||||
sysctl machdep.cpu
|
||||
./util/opensslwrap.sh version -c
|
||||
working-directory: ./build
|
||||
- name: make test
|
||||
run: ../source/.github/workflows/make-test
|
||||
working-directory: ./build
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
with:
|
||||
name: "ci@out-of-readonly-source-and-install-macos-15"
|
||||
path: build/artifacts.tar.gz
|
||||
- name: make install
|
||||
run: make install
|
||||
working-directory: ./build
|
||||
522
.github/workflows/ci.yml
vendored
522
.github/workflows/ci.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -7,25 +7,7 @@
|
|||
|
||||
name: GitHub CI
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
push:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
on: [pull_request, push]
|
||||
|
||||
# for some reason, this does not work:
|
||||
# variables:
|
||||
|
|
@ -49,11 +31,10 @@ jobs:
|
|||
- name: install unifdef
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install unifdef
|
||||
- uses: actions/checkout@v6
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --force-yes install unifdef
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump
|
||||
- name: make build_generated
|
||||
|
|
@ -63,38 +44,49 @@ jobs:
|
|||
- name: git diff
|
||||
run: git diff --exit-code
|
||||
|
||||
check_docs:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump
|
||||
- name: make build_generated
|
||||
run: make -s build_generated
|
||||
- name: make doc-nits
|
||||
run: make doc-nits
|
||||
- name: make help
|
||||
run: make help
|
||||
- name: make md-nits
|
||||
run: |
|
||||
sudo gem install mdl
|
||||
make md-nits
|
||||
|
||||
# This checks that we use ANSI C language syntax and semantics.
|
||||
# We are not as strict with libraries, but rather adapt to what's
|
||||
# expected to be available in a certain version of each platform.
|
||||
check-c99:
|
||||
check-ansi:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
run: CPPFLAGS='-std=c99 -D_XOPEN_SOURCE=1 -D_POSIX_C_SOURCE=200809L' ./config --strict-warnings --banner=Configured enable-sslkeylog no-asm no-secure-memory no-makedepend enable-buildtest-c++ enable-fips enable-lms && perl configdata.pm --dump
|
||||
run: CPPFLAGS='-ansi -D_XOPEN_SOURCE=1 -D_POSIX_C_SOURCE=200809L' ./config --strict-warnings --banner=Configured enable-sslkeylog no-asm no-secure-memory no-makedepend enable-buildtest-c++ enable-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
|
||||
basic_gcc:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: localegen
|
||||
run: sudo locale-gen tr_TR.UTF-8
|
||||
- name: cmocka
|
||||
run: sudo apt-get -y install libcmocka-dev
|
||||
- name: fipsvendor
|
||||
# Make one fips build use a customized FIPS vendor
|
||||
run: echo "FIPS_VENDOR=CI" >> VERSION.dat
|
||||
- name: config
|
||||
# enable-quic is on by default, but we leave it here to check we're testing the explicit enable somewhere
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ec_explicit_curves enable-sslkeylog enable-fips enable-quic enable-lms enable-unit-tests && perl configdata.pm --dump
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-sslkeylog enable-fips enable-quic && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -108,7 +100,7 @@ jobs:
|
|||
util/wrap.pl -fips apps/openssl list -providers | grep 'name: CI FIPS Provider for OpenSSL$'
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@basic-gcc"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -116,9 +108,7 @@ jobs:
|
|||
basic_clang:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -133,19 +123,17 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@basic-clang"
|
||||
path: artifacts.tar.gz
|
||||
|
||||
linux-arm64:
|
||||
runs-on: ubuntu-24.04-arm
|
||||
runs-on: ${{ github.repository == 'openssl/openssl' && 'linux-arm64' || 'ubuntu-24.04-arm' }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
run: ./config --strict-warnings enable-demos enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
run: ./config --strict-warnings enable-demos enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -158,108 +146,40 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@linux-arm64"
|
||||
path: artifacts.tar.gz
|
||||
|
||||
gcc-min-version:
|
||||
runs-on: ubuntu-latest
|
||||
container:
|
||||
image: docker.io/gcc:9
|
||||
timeout-minutes: 90
|
||||
strategy:
|
||||
fail-fast: false
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: print gcc version
|
||||
run: |
|
||||
gcc --version
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: .github/workflows/make-test
|
||||
|
||||
linux-x86:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: run container
|
||||
run: |
|
||||
CONTAINER_ID=$(podman run -d -v $(pwd):/mnt -w /mnt --platform=linux/i386 docker.io/i386/debian:13 sleep infinity)
|
||||
echo "CONTAINER_ID=$CONTAINER_ID" >> "$GITHUB_ENV"
|
||||
- name: install dependencies
|
||||
run:
|
||||
podman exec -t $CONTAINER_ID sh -c "apt-get update && apt-get install -y gcc perl make"
|
||||
- name: config
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-trace"
|
||||
- name: config dump
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"./configdata.pm --dump"
|
||||
- name: make
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"make -j"
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"./util/opensslwrap.sh version -c"
|
||||
- name: make test
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
".github/workflows/make-test"
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
with:
|
||||
name: "ci@linux-x86"
|
||||
path: artifacts.tar.gz
|
||||
|
||||
freebsd-x86_64:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
uses: cross-platform-actions/action@v0.26.0
|
||||
with:
|
||||
operating_system: freebsd
|
||||
version: "13.4"
|
||||
shutdown_vm: false
|
||||
run: |
|
||||
sudo pkg install -y gcc perl5
|
||||
./config --strict-warnings enable-fips enable-lms enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
- name: config dump
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
uses: cross-platform-actions/action@v0.26.0
|
||||
with:
|
||||
operating_system: freebsd
|
||||
version: "13.4"
|
||||
shutdown_vm: false
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
uses: cross-platform-actions/action@v0.26.0
|
||||
with:
|
||||
operating_system: freebsd
|
||||
version: "13.4"
|
||||
shutdown_vm: false
|
||||
run: make -j4
|
||||
- name: make test
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
uses: cross-platform-actions/action@v0.26.0
|
||||
with:
|
||||
operating_system: freebsd
|
||||
version: "13.4"
|
||||
|
|
@ -268,7 +188,7 @@ jobs:
|
|||
.github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@BSD-x86_64"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -276,13 +196,11 @@ jobs:
|
|||
minimal:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-bulk no-pic no-asm no-lms -DOPENSSL_NO_SECURE_MEMORY -DOPENSSL_SMALL_FOOTPRINT && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-bulk no-pic no-asm -DOPENSSL_NO_SECURE_MEMORY -DOPENSSL_SMALL_FOOTPRINT && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -j4 # verbose, so no -s here
|
||||
- name: get cpu info
|
||||
|
|
@ -293,7 +211,7 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@minimal"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -301,9 +219,7 @@ jobs:
|
|||
no-deprecated:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -318,7 +234,7 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@no-deprecated"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -326,9 +242,7 @@ jobs:
|
|||
no-shared-ubuntu:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -343,17 +257,19 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@no-shared-ubuntu"
|
||||
path: artifacts.tar.gz
|
||||
|
||||
no-shared-macos:
|
||||
runs-on: macos-14
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [macos-13, macos-14]
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -368,17 +284,15 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@no-shared-macos-14"
|
||||
name: "ci@no-shared-${{ matrix.os }}"
|
||||
path: artifacts.tar.gz
|
||||
|
||||
non-caching:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
@ -397,7 +311,7 @@ jobs:
|
|||
run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 TESTS="-test_fuzz* -test_ssl_* -test_sslapi -test_evp -test_cmp_http -test_verify -test_cms -test_store -test_enc -[01][0-9]"
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@non-caching"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -405,9 +319,7 @@ jobs:
|
|||
address_ub_sanitizer:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
@ -415,7 +327,7 @@ jobs:
|
|||
sudo cat /proc/sys/vm/mmap_rnd_bits
|
||||
sudo sysctl -w vm.mmap_rnd_bits=28
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo enable-asan enable-ec_explicit_curves enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-fips enable-lms && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo enable-asan enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -426,7 +338,7 @@ jobs:
|
|||
run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@address_ub_sanitizer"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -434,9 +346,7 @@ jobs:
|
|||
fuzz_tests:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
@ -444,7 +354,7 @@ jobs:
|
|||
sudo cat /proc/sys/vm/mmap_rnd_bits
|
||||
sudo sysctl -w vm.mmap_rnd_bits=28
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION enable-asan enable-ec_explicit_curves enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-weak-ssl-ciphers enable-nextprotoneg && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured --debug -DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION enable-asan enable-ubsan enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-weak-ssl-ciphers enable-ssl3 enable-ssl3-method enable-nextprotoneg && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -455,52 +365,16 @@ jobs:
|
|||
run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 TESTS="test_fuzz*"
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@fuzz_tests"
|
||||
path: artifacts.tar.gz
|
||||
if-no-files-found: ignore
|
||||
|
||||
fuzz_tests_mfail:
|
||||
runs-on: ubuntu-latest
|
||||
timeout-minutes: 30
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
run: sudo sysctl -w vm.mmap_rnd_bits=28
|
||||
- name: config
|
||||
run: |
|
||||
./config --strict-warnings --banner=Configured --debug \
|
||||
-DPEDANTIC -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION \
|
||||
enable-asan enable-ec_explicit_curves enable-ubsan \
|
||||
enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 \
|
||||
enable-weak-ssl-ciphers enable-nextprotoneg
|
||||
perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: make test (fuzz with mfail)
|
||||
env:
|
||||
OSSL_FUZZ_TEST_BUDGET: 1200
|
||||
OSSL_FUZZ_TEST_JOBS: 4
|
||||
run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0 TESTS="test_fuzz*"
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
with:
|
||||
name: "ci@fuzz_tests_mfail"
|
||||
path: artifacts.tar.gz
|
||||
if-no-files-found: ignore
|
||||
|
||||
memory_sanitizer:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
@ -509,7 +383,7 @@ jobs:
|
|||
sudo sysctl -w vm.mmap_rnd_bits=28
|
||||
- name: config
|
||||
# --debug -O1 is to produce a debug build that runs in a reasonable amount of time
|
||||
run: CC=clang ./config --strict-warnings --banner=Configured --debug no-shared -O1 -fsanitize=memory -DOSSL_SANITIZE_MEMORY -fno-optimize-sibling-calls enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-ec_explicit_curves enable-fips enable-lms no-slh-dsa && perl configdata.pm --dump
|
||||
run: CC=clang ./config --strict-warnings --banner=Configured --debug no-shared -O1 -fsanitize=memory -DOSSL_SANITIZE_MEMORY -fno-optimize-sibling-calls enable-rc5 enable-md2 enable-ec_nistp_64_gcc_128 enable-fips no-slh-dsa && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -520,7 +394,7 @@ jobs:
|
|||
run: .github/workflows/make-test OPENSSL_TEST_RAND_ORDER=0
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@memory_sanitizer"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -528,9 +402,7 @@ jobs:
|
|||
threads_sanitizer:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
@ -549,7 +421,7 @@ jobs:
|
|||
run: .github/workflows/make-test V=1 TESTS="test_lhash test_threads test_internal_provider test_provfetch test_provider test_pbe test_evp_kdf test_pkcs12 test_store test_evp test_quic*"
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@threads_sanitizer"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -557,15 +429,13 @@ jobs:
|
|||
enable_non-default_options:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: modprobe tls
|
||||
run: sudo modprobe tls
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-ec enable-ssl-trace enable-zlib enable-zlib-dynamic enable-crypto-mdebug enable-egd enable-ktls enable-fips enable-lms no-threads && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-ec enable-ssl-trace enable-zlib enable-zlib-dynamic enable-crypto-mdebug enable-egd enable-ktls enable-fips no-threads && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -576,7 +446,7 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@enable_non-default_options"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -584,9 +454,7 @@ jobs:
|
|||
full_featured:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: modprobe tls
|
||||
|
|
@ -598,7 +466,7 @@ jobs:
|
|||
- name: install extra config support
|
||||
run: sudo apt-get -y install libsctp-dev abigail-tools libzstd-dev zstd
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ec_explicit_curves enable-ktls enable-fips enable-lms enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-weak-ssl-ciphers enable-trace enable-zlib enable-zstd && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo enable-ktls enable-fips enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-trace enable-zlib enable-zstd && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -609,7 +477,7 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@full_featured"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -617,13 +485,11 @@ jobs:
|
|||
no-legacy:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-legacy enable-fips enable-lms && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured enable-demos enable-h3demo no-legacy enable-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -634,7 +500,7 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@no-legacy"
|
||||
path: artifacts.tar.gz
|
||||
|
|
@ -642,13 +508,11 @@ jobs:
|
|||
legacy:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-demos enable-h3demo no-shared enable-crypto-mdebug enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-ec_explicit_curves no-fips && perl configdata.pm --dump
|
||||
run: ./config --strict-warnings --banner=Configured --debug no-afalgeng enable-demos enable-h3demo no-shared enable-crypto-mdebug enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
|
|
@ -659,59 +523,151 @@ jobs:
|
|||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@legacy"
|
||||
path: artifacts.tar.gz
|
||||
|
||||
external-tests-misc:
|
||||
# out-of-source-and-install checks multiple things at the same time:
|
||||
# - That building, testing and installing works from an out-of-source
|
||||
# build tree
|
||||
# - That building, testing and installing works with a read-only source
|
||||
# tree
|
||||
out-of-readonly-source-and-install-ubuntu:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
submodules: recursive
|
||||
persist-credentials: false
|
||||
- name: package installs
|
||||
path: ./source
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
working-directory: ./source
|
||||
- name: make source read-only
|
||||
run: chmod -R a-w ./source
|
||||
- name: create build and install directories
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq install bison gettext keyutils ldap-utils libldap2-dev libkeyutils-dev python3 python3-paste python3-pyrad slapd tcsh python3-virtualenv virtualenv python3-kdcproxy gdb libtls-dev wget gpg
|
||||
- name: setup hostname workaround
|
||||
run: sudo hostname localhost
|
||||
mkdir ./build
|
||||
mkdir ./install
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-external-tests no-fips && perl configdata.pm --dump
|
||||
run: |
|
||||
../source/config --banner=Configured enable-demos enable-h3demo enable-fips enable-quic enable-acvp-tests --strict-warnings --prefix=$(cd ../install; pwd)
|
||||
perl configdata.pm --dump
|
||||
working-directory: ./build
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- uses: dtolnay/rust-toolchain@0f44b27771c32bda9f458f75a1e241b09791b331
|
||||
with:
|
||||
toolchain: stable
|
||||
working-directory: ./build
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: test failure when selecting non-existing test case
|
||||
working-directory: ./build
|
||||
- name: make test
|
||||
run: ../source/.github/workflows/make-test
|
||||
working-directory: ./build
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@out-of-readonly-source-and-install-ubuntu"
|
||||
path: build/artifacts.tar.gz
|
||||
- name: make install
|
||||
run: make install
|
||||
working-directory: ./build
|
||||
|
||||
out-of-readonly-source-and-install-macos:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [macos-13, macos-14]
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
path: ./source
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
working-directory: ./source
|
||||
- name: make source read-only
|
||||
run: chmod -R a-w ./source
|
||||
- name: create build and install directories
|
||||
run: |
|
||||
! make test TESTS="test_external_gost_engine"
|
||||
mkdir ./build
|
||||
mkdir ./install
|
||||
- name: config
|
||||
run: |
|
||||
../source/config --banner=Configured enable-fips enable-demos enable-h3demo enable-quic enable-acvp-tests --strict-warnings --prefix=$(cd ../install; pwd)
|
||||
perl configdata.pm --dump
|
||||
working-directory: ./build
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
working-directory: ./build
|
||||
- name: get cpu info
|
||||
run: |
|
||||
sysctl machdep.cpu
|
||||
./util/opensslwrap.sh version -c
|
||||
working-directory: ./build
|
||||
- name: make test
|
||||
run: ../source/.github/workflows/make-test
|
||||
working-directory: ./build
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "ci@out-of-readonly-source-and-install-${{ matrix.os }}"
|
||||
path: build/artifacts.tar.gz
|
||||
- name: make install
|
||||
run: make install
|
||||
working-directory: ./build
|
||||
|
||||
external-tests-misc:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
submodules: recursive
|
||||
- name: package installs
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq install bison gettext keyutils ldap-utils libldap2-dev libkeyutils-dev python3 python3-paste python3-pyrad slapd tcsh python3-virtualenv virtualenv python3-kdcproxy gdb
|
||||
- name: install cpanm and Test2::V0 for gost_engine testing
|
||||
uses: perl-actions/install-with-cpanm@stable
|
||||
with:
|
||||
install: Test2::V0
|
||||
- name: setup hostname workaround
|
||||
run: sudo hostname localhost
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug no-afalgeng enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-external-tests no-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- uses: dtolnay/rust-toolchain@stable
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: test external gost-engine
|
||||
run: make test TESTS="test_external_gost_engine"
|
||||
- name: test external krb5
|
||||
run: make test TESTS="test_external_krb5"
|
||||
- name: test external tlsfuzzer
|
||||
run: make test TESTS="test_external_tlsfuzzer"
|
||||
- name: test external Cloudflare quiche
|
||||
run: make test TESTS="test_external_cf_quiche" VERBOSE=1
|
||||
- name: test external rpki client
|
||||
run: make test TESTS="test_external_rpki-client-portable"
|
||||
- name: test ability to produce debuginfo files
|
||||
run: |
|
||||
make debuginfo
|
||||
gdb < <(echo -e "file ./libcrypto.so.4\nquit") > ./results
|
||||
grep -q "Reading symbols from.*libcrypto\.so\.4\.debug" results
|
||||
gdb < <(echo -e "file ./libcrypto.so.3\nquit") > ./results
|
||||
grep -q "Reading symbols from.*libcrypto\.so\.3\.debug" results
|
||||
|
||||
external-tests-oqs-provider:
|
||||
external-tests-providers:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
submodules: recursive
|
||||
persist-credentials: false
|
||||
- name: package installs
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq install meson pkg-config gnutls-bin libnss3-tools libnss3-dev libsofthsm2 opensc expect
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-external-tests && perl configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -722,37 +678,9 @@ jobs:
|
|||
./util/opensslwrap.sh version -c
|
||||
- name: test external oqs-provider
|
||||
run: make test TESTS="test_external_oqsprovider"
|
||||
|
||||
external-tests-pkcs11-provider:
|
||||
runs-on: ubuntu-latest
|
||||
container: fedora:latest
|
||||
steps:
|
||||
- name: package installs
|
||||
run: |
|
||||
dnf install -y perl-FindBin perl-IPC-Cmd perl-File-Compare perl-File-Copy perl-Test-Simple perl-Test-Harness python3 make g++ perl git meson opensc expect kryoptic xxd
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: checkout fuzz/corpora and pkcs11-provider submodule
|
||||
run: |
|
||||
git config --global --add safe.directory "$GITHUB_WORKSPACE"
|
||||
git submodule update --init --depth 1 fuzz/corpora
|
||||
git submodule update --init --depth 1 pkcs11-provider
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-external-tests no-fips && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
# Run all tests except external tests to make sure they work fine on Fedora because
|
||||
# this is the only job running on Fedora, only then execute pkcs11-provider external
|
||||
# test.
|
||||
- name: test (except external tests)
|
||||
run: make test TESTS="-test_external_*"
|
||||
- name: test external pkcs11-provider
|
||||
run: make test TESTS="test_external_pkcs11_provider" VERBOSE=1
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
# Disabled temporarily: https://github.com/latchset/pkcs11-provider/pull/525#discussion_r1982805969
|
||||
# - name: test external pkcs11-provider
|
||||
# run: make test TESTS="test_external_pkcs11_provider" VERBOSE=1
|
||||
|
||||
external-tests-pyca:
|
||||
runs-on: ubuntu-latest
|
||||
|
|
@ -761,10 +689,9 @@ jobs:
|
|||
PYTHON:
|
||||
- 3.9
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
submodules: recursive
|
||||
persist-credentials: false
|
||||
- name: package installs
|
||||
run: |
|
||||
sudo apt-get update
|
||||
|
|
@ -774,62 +701,15 @@ jobs:
|
|||
- name: make
|
||||
run: make -s -j4
|
||||
- name: Setup Python
|
||||
uses: actions/setup-python@v6.0.0
|
||||
uses: actions/setup-python@v5.3.0
|
||||
with:
|
||||
python-version: ${{ matrix.PYTHON }}
|
||||
- uses: dtolnay/rust-toolchain@0f44b27771c32bda9f458f75a1e241b09791b331
|
||||
- uses: dtolnay/rust-toolchain@stable
|
||||
with:
|
||||
toolchain: stable
|
||||
toolchain: stable
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: test external pyca
|
||||
run: make test TESTS="test_external_pyca" VERBOSE=1
|
||||
|
||||
external-test-bssl:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Configure OpenSSL
|
||||
run: ./config enable-external-tests
|
||||
- name: Build OpenSSL
|
||||
run: make -s -j4
|
||||
- name: Clone BoringSSL 0.20260211.0
|
||||
run: git clone --depth 1 --branch 0.20260211.0 https://boringssl.googlesource.com/boringssl
|
||||
- name: Configure and Build BoringSSL
|
||||
run: |
|
||||
cd boringssl
|
||||
mkdir build
|
||||
cd build
|
||||
cmake -DCMAKE_INSTALL_PREFIX=../../boringssl/.local ..
|
||||
make -s -j4
|
||||
make install
|
||||
cd ../..
|
||||
- name: Test ECH with BoringSSL
|
||||
run: make test TESTS='test_external_ech_bssl' V=1
|
||||
|
||||
external-test-nss:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Configure OpenSSL
|
||||
run: ./config enable-external-tests
|
||||
- name: Build OpenSSL
|
||||
run: make -s -j4
|
||||
- name: Clone and Build NSS
|
||||
run: |
|
||||
mkdir nss
|
||||
cd nss
|
||||
git clone --depth 1 --branch NSS_3_112_3_RTM https://github.com/nss-dev/nss.git
|
||||
hg clone https://hg.mozilla.org/projects/nspr -r NSPR_4_36_BRANCH
|
||||
cd nss
|
||||
USE_64=1 make nss_build_all
|
||||
USE_64=1 make install
|
||||
cd ../..
|
||||
- name: Test ECH with NSS
|
||||
run: make test TESTS='test_external_ech_nss' V=1
|
||||
|
|
|
|||
130
.github/workflows/compiler-zoo.yml
vendored
130
.github/workflows/compiler-zoo.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -13,63 +13,99 @@ permissions:
|
|||
contents: read
|
||||
|
||||
jobs:
|
||||
gcc:
|
||||
compiler:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
gcc: [gcc-9, gcc-10, gcc-11, gcc-12, gcc-13, gcc-14]
|
||||
runs-on: ubuntu-24.04
|
||||
zoo: [
|
||||
{
|
||||
cc: gcc-9,
|
||||
distro: ubuntu-22.04
|
||||
}, {
|
||||
cc: gcc-10,
|
||||
distro: ubuntu-22.04
|
||||
}, {
|
||||
cc: gcc-11,
|
||||
distro: ubuntu-22.04
|
||||
}, {
|
||||
cc: gcc-12,
|
||||
distro: ubuntu-22.04
|
||||
}, {
|
||||
cc: gcc-13,
|
||||
distro: ubuntu-22.04,
|
||||
gcc-ppa-name: ubuntu-toolchain-r/test
|
||||
}, {
|
||||
cc: clang-11,
|
||||
distro: ubuntu-22.04
|
||||
}, {
|
||||
cc: clang-12,
|
||||
distro: ubuntu-22.04
|
||||
}, {
|
||||
cc: clang-13,
|
||||
distro: ubuntu-22.04
|
||||
}, {
|
||||
cc: clang-14,
|
||||
distro: ubuntu-22.04
|
||||
}, {
|
||||
cc: clang-15,
|
||||
distro: ubuntu-22.04,
|
||||
llvm-ppa-name: jammy
|
||||
}, {
|
||||
cc: clang-16,
|
||||
distro: ubuntu-22.04,
|
||||
llvm-ppa-name: jammy
|
||||
}, {
|
||||
cc: clang-17,
|
||||
distro: ubuntu-22.04,
|
||||
llvm-ppa-name: jammy
|
||||
}
|
||||
]
|
||||
# We set per-compiler now to allow testing with both older and newer sets
|
||||
# Often, the full range of oldest->newest compilers we want aren't available
|
||||
# in a single version of Ubuntu.
|
||||
runs-on: ${{ matrix.zoo.distro }}
|
||||
steps:
|
||||
- name: install packages
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -y install ${{ matrix.gcc }}
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
env:
|
||||
CC: ${{ matrix.gcc }}
|
||||
run: |
|
||||
./config --strict-warnings --banner=Configured no-shared enable-fips
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
gcc_ppa_name="${{ matrix.zoo.gcc-ppa-name }}"
|
||||
llvm_ppa_name="${{ matrix.zoo.llvm-ppa-name }}"
|
||||
|
||||
clang:
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
clang: [clang-11, clang-12, clang-13, clang-14, clang-15, clang-16, clang-17, clang-18, clang-19, clang-20, clang-21]
|
||||
runs-on: ubuntu-22.04
|
||||
steps:
|
||||
- name: install packages
|
||||
run: |
|
||||
set -euo pipefail
|
||||
VERSION=$(awk -F- '{print $NF}' <<< ${{ matrix.clang }})
|
||||
wget -qO- https://apt.llvm.org/llvm-snapshot.gpg.key | sudo tee /etc/apt/trusted.gpg.d/apt.llvm.org.asc
|
||||
echo "deb http://apt.llvm.org/jammy/ llvm-toolchain-jammy-$VERSION main" | sudo tee -a /etc/apt/sources.list
|
||||
sudo apt-get update || true
|
||||
sudo apt-get -y install ${{ matrix.clang }}
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
# In the Matrix above:
|
||||
# - we set gcc-ppc-name if the GCC version isn't part of the Ubuntu version we're using (see https://launchpad.net/~ubuntu-toolchain-r/+archive/ubuntu/test).
|
||||
# - we set llvm-ppa-name if an LLVM version isn't part of the Ubuntu version we're using (see https://apt.llvm.org/).
|
||||
# This is especially needed because even new Ubuntu LTSes aren't available
|
||||
# until a while after release on Github Actions.
|
||||
if [[ -n ${gcc_ppa_name} ]] ; then
|
||||
sudo add-apt-repository ppa:ubuntu-toolchain-r/test
|
||||
sudo apt-get update
|
||||
elif [[ -n ${llvm_ppa_name} ]] ; then
|
||||
wget -O - https://apt.llvm.org/llvm-snapshot.gpg.key |\
|
||||
gpg --dearmor |\
|
||||
sudo tee /usr/share/keyrings/llvm-snapshot.gpg.key > /dev/null
|
||||
|
||||
clang_version="${{ matrix.zoo.cc }}"
|
||||
clang_version="${clang_version/clang-}"
|
||||
|
||||
echo "deb [signed-by=/usr/share/keyrings/llvm-snapshot.gpg.key] http://apt.llvm.org/${{ matrix.zoo.llvm-ppa-name }}/ llvm-toolchain-${{ matrix.zoo.llvm-ppa-name }}-${clang_version} main" \
|
||||
| sudo tee /etc/apt/sources.list.d/llvm.list
|
||||
echo "deb-src [signed-by=/usr/share/keyrings/llvm-snapshot.gpg.key] http://apt.llvm.org/${{ matrix.zoo.llvm-ppa-name }}/ llvm-toolchain-${{ matrix.zoo.llvm-ppa-name }}-${clang_version} main" \
|
||||
| sudo tee -a /etc/apt/sources.list.d/llvm.list
|
||||
|
||||
cat /etc/apt/sources.list.d/llvm.list
|
||||
fi
|
||||
|
||||
sudo apt-get update
|
||||
sudo apt-get -y install ${{ matrix.zoo.cc }}
|
||||
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
|
||||
- name: config
|
||||
env:
|
||||
CC: ${{ matrix.clang }}
|
||||
run: |
|
||||
./config --strict-warnings --banner=Configured no-shared enable-fips
|
||||
CC=${{ matrix.zoo.cc }} ./config --strict-warnings --banner=Configured \
|
||||
no-shared enable-fips
|
||||
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
|
|||
43
.github/workflows/coveralls.yml
vendored
43
.github/workflows/coveralls.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -31,38 +31,38 @@ jobs:
|
|||
steps:
|
||||
- name: Define branches
|
||||
id: branches
|
||||
env:
|
||||
GITHUB_EVENT_INPUTS_BRANCH: ${{ github.event.inputs.branch }}
|
||||
GITHUB_EVENT_INPUTS_EXTRA_CONFIG: ${{ github.event.inputs.extra_config }}
|
||||
run: |
|
||||
if [ "${{ github.event_name}}" = "workflow_dispatch" ]; then
|
||||
MATRIX=$(cat << EOF
|
||||
[{
|
||||
"branch": "${GITHUB_EVENT_INPUTS_BRANCH}",
|
||||
"extra_config": "${GITHUB_EVENT_INPUTS_EXTRA_CONFIG}"
|
||||
"branch": "${{ github.event.inputs.branch }}",
|
||||
"extra_config": "${{ github.event.inputs.extra_config }}"
|
||||
}]
|
||||
EOF
|
||||
)
|
||||
else
|
||||
MATRIX=$(cat << EOF
|
||||
[{
|
||||
"branch": "master",
|
||||
"extra_config": "enable-fips enable-tfo enable-lms enable-crypto-mdebug enable-unit-tests"
|
||||
}, {
|
||||
"branch": "openssl-4.0",
|
||||
"extra_config": "enable-fips enable-tfo enable-lms enable-crypto-mdebug"
|
||||
},{
|
||||
"branch": "openssl-3.6",
|
||||
"extra_config": "no-afalgeng enable-fips enable-tfo enable-lms"
|
||||
},{
|
||||
"branch": "openssl-3.5",
|
||||
"extra_config": "no-afalgeng enable-fips enable-tfo"
|
||||
},{
|
||||
"branch": "openssl-3.4",
|
||||
"extra_config": "no-afalgeng enable-fips enable-tfo"
|
||||
}, {
|
||||
"branch": "openssl-3.3",
|
||||
"extra_config": "no-afalgeng enable-fips enable-tfo"
|
||||
}, {
|
||||
"branch": "openssl-3.2",
|
||||
"extra_config": "no-afalgeng enable-fips enable-tfo"
|
||||
}, {
|
||||
"branch": "openssl-3.1",
|
||||
"extra_config": "no-afalgeng enable-fips"
|
||||
}, {
|
||||
"branch": "openssl-3.0",
|
||||
"extra_config": "no-afalgeng enable-fips"
|
||||
}, {
|
||||
"branch": "master",
|
||||
"extra_config": "no-afalgeng enable-fips enable-tfo"
|
||||
}]
|
||||
EOF
|
||||
)
|
||||
|
|
@ -70,7 +70,6 @@ jobs:
|
|||
echo "branches<<EOF"$'\n'"$MATRIX"$'\n'EOF >> "$GITHUB_OUTPUT"
|
||||
|
||||
coverage:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
needs: define-matrix
|
||||
permissions:
|
||||
checks: write # for coverallsapp/github-action to create new checks
|
||||
|
|
@ -81,11 +80,10 @@ jobs:
|
|||
branches: ${{ fromJSON(needs.define-matrix.outputs.branches) }}
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
submodules: recursive
|
||||
ref: ${{ matrix.branches.branch }}
|
||||
persist-credentials: false
|
||||
- name: cache commit id
|
||||
run: |
|
||||
echo "githubid=`/usr/bin/git log -1 --format='%H'`" >>$GITHUB_ENV
|
||||
|
|
@ -93,15 +91,15 @@ jobs:
|
|||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq install lcov
|
||||
sudo apt-get -yq install bison gettext keyutils ldap-utils libcmocka-dev libldap2-dev libkeyutils-dev python3 python3-paste python3-pyrad slapd tcsh python3-virtualenv virtualenv python3-kdcproxy
|
||||
sudo apt-get -yq install bison gettext keyutils ldap-utils libldap2-dev libkeyutils-dev python3 python3-paste python3-pyrad slapd tcsh python3-virtualenv virtualenv python3-kdcproxy
|
||||
- name: install Test2::V0 for gost_engine testing
|
||||
uses: perl-actions/install-with-cpanm@10d60f00b4073f484fc29d45bfbe2f776397ab3d #v1.7
|
||||
uses: perl-actions/install-with-cpanm@stable
|
||||
with:
|
||||
install: Test2::V0
|
||||
- name: setup hostname workaround
|
||||
run: sudo hostname localhost
|
||||
- name: config
|
||||
run: CC=gcc ./config --debug --coverage ${{ matrix.branches.extra_config }} no-asm enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-buildtest-c++ enable-ssl-trace enable-trace
|
||||
run: CC=gcc ./config --debug --coverage ${{ matrix.branches.extra_config }} no-asm enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 enable-buildtest-c++ enable-ssl-trace enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -118,10 +116,9 @@ jobs:
|
|||
--exclude "${PWD}/fuzz/*"
|
||||
--exclude "/usr/include/*"
|
||||
--ignore-errors mismatch
|
||||
--branch-coverage
|
||||
-o ./lcov.info
|
||||
- name: Coveralls upload
|
||||
uses: coverallsapp/github-action@648a8eb78e6d50909eff900e4ec85cab4524a45b #v2.3.6
|
||||
uses: coverallsapp/github-action@v2.3.2
|
||||
with:
|
||||
github-token: ${{ secrets.github_token }}
|
||||
git-branch: ${{ matrix.branches.branch }}
|
||||
|
|
|
|||
54
.github/workflows/cross-compiles.yml
vendored
54
.github/workflows/cross-compiles.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -7,35 +7,13 @@
|
|||
|
||||
name: Cross Compile
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
push:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
on: [pull_request, push]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
cross-compilation:
|
||||
# Run the full test suite on push, and on pull requests labelled with
|
||||
# 'extended tests'. Other pull requests only run the EVP tests.
|
||||
env:
|
||||
EXTENDED: ${{ github.event_name == 'push' || contains(github.event.pull_request.labels.*.name, 'extended tests') }}
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
|
|
@ -135,7 +113,7 @@ jobs:
|
|||
}, {
|
||||
arch: s390x-linux-gnu,
|
||||
libs: libc6-dev-s390x-cross,
|
||||
target: linux64-s390x,
|
||||
target: linux64-s390x -Wno-stringop-overflow,
|
||||
fips: no
|
||||
}, {
|
||||
arch: sh4-linux-gnu,
|
||||
|
|
@ -187,25 +165,23 @@ jobs:
|
|||
- name: install packages
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install \
|
||||
sudo apt-get -yq --force-yes install \
|
||||
gcc-${{ matrix.platform.arch }} \
|
||||
${{ matrix.platform.libs }}
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
|
||||
- name: config with FIPS
|
||||
if: matrix.platform.fips != 'no'
|
||||
run: |
|
||||
./config --banner=Configured --strict-warnings enable-fips enable-lms \
|
||||
./config --banner=Configured --strict-warnings enable-fips \
|
||||
--cross-compile-prefix=${{ matrix.platform.arch }}- \
|
||||
${{ matrix.platform.target }}
|
||||
- name: config without FIPS
|
||||
if: matrix.platform.fips == 'no'
|
||||
run: |
|
||||
./config --banner=Configured --strict-warnings enable-lms \
|
||||
./config --banner=Configured --strict-warnings \
|
||||
--cross-compile-prefix=${{ matrix.platform.arch }}- \
|
||||
${{ matrix.platform.target }}
|
||||
- name: config dump
|
||||
|
|
@ -216,7 +192,7 @@ jobs:
|
|||
|
||||
- name: install qemu
|
||||
if: matrix.platform.tests != 'none'
|
||||
run: sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install qemu-user
|
||||
run: sudo apt-get -yq --force-yes install qemu-user
|
||||
|
||||
- name: Set QEMU environment
|
||||
if: matrix.platform.qemucpu != ''
|
||||
|
|
@ -228,31 +204,29 @@ jobs:
|
|||
${{ matrix.platform.opensslcaps }}" >> $GITHUB_ENV
|
||||
|
||||
- name: get cpu info
|
||||
if: matrix.platform.tests != 'none'
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} ./util/opensslwrap.sh version -c
|
||||
run: cat /proc/cpuinfo
|
||||
|
||||
- name: make all tests
|
||||
if: env.EXTENDED == 'true' && matrix.platform.tests == ''
|
||||
if: github.event_name == 'push' && matrix.platform.tests == ''
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="-test_afalg" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: make some tests
|
||||
if: env.EXTENDED == 'true' && matrix.platform.tests != 'none' && matrix.platform.tests != ''
|
||||
if: github.event_name == 'push' && matrix.platform.tests != 'none' && matrix.platform.tests != ''
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="${{ matrix.platform.tests }} -test_afalg" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: make evp tests
|
||||
if: env.EXTENDED != 'true' && matrix.platform.tests != 'none'
|
||||
if: github.event_name == 'pull_request' && matrix.platform.tests != 'none'
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="test_evp*" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: "cross-compiles@${{ matrix.platform.arch }}"
|
||||
path: artifacts.tar.gz
|
||||
|
|
|
|||
110
.github/workflows/ct-validation-daily.yml
vendored
110
.github/workflows/ct-validation-daily.yml
vendored
|
|
@ -1,110 +0,0 @@
|
|||
# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: Constant-time validation (daily)
|
||||
# Verifies that several algorithms needing constant-time execution do not
|
||||
# branch on secret data.
|
||||
#
|
||||
# The library is built with enable-ct-validation, which defines
|
||||
# OPENSSL_CONSTANT_TIME_VALIDATION and causes secret regions to be marked
|
||||
# as "uninitialised" from Valgrind memcheck's perspective. The tests are
|
||||
# then run via "make test" with OSSL_VALGRIND_CT=yes, which makes
|
||||
# OpenSSL::Test::test() wrap every test binary with:
|
||||
#
|
||||
# valgrind --tool=memcheck --track-origins=yes --error-exitcode=1
|
||||
#
|
||||
# The wrapper chain (util/wrap.pl -> util/shlib_wrap.sh) is preserved, so
|
||||
# LD_LIBRARY_PATH is set correctly for shared-library builds. Any
|
||||
# control-flow branch or memory index that depends on secret data causes
|
||||
# valgrind to exit with code 1, which propagates back through the test
|
||||
# harness and fails the job.
|
||||
#
|
||||
# See include/internal/constant_time.h for the CONSTTIME_SECRET /
|
||||
# CONSTTIME_DECLASSIFY macro documentation.
|
||||
#
|
||||
# Architecture note: Valgrind's memcheck supports x86_64, aarch64, s390x,
|
||||
# and ppc64 well. GitHub Actions provides hosted runners for x86_64
|
||||
# (ubuntu-latest) and aarch64 (ubuntu-24.04-arm); we test both here.
|
||||
# s390x and ppc64 runners are not available in the public GitHub Actions
|
||||
# fleet, so they are not included.
|
||||
#
|
||||
# Package note: on Debian/Ubuntu the valgrind package bundles the C headers
|
||||
# (valgrind/memcheck.h) — no separate -dev package is required. On Fedora
|
||||
# the headers are in valgrind-devel; see Configure for the full list.
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '45 03 * * *'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
ct-validation:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
# Constant-timeness is a property of the generated machine code, which
|
||||
# the compiler derives differently per architecture. Therefore we verify
|
||||
# both the assembly and C implementations on every architecture we can
|
||||
# run Valgrind on.
|
||||
include:
|
||||
# Default builds use assembler implementations (when available)
|
||||
- name: linux-x86_64
|
||||
runs-on: ubuntu-latest
|
||||
config_extra: ""
|
||||
- name: linux-aarch64
|
||||
runs-on: ubuntu-24.04-arm
|
||||
config_extra: ""
|
||||
|
||||
# no-asm builds always use C implementations
|
||||
- name: linux-x86_64-no-asm
|
||||
runs-on: ubuntu-latest
|
||||
config_extra: no-asm
|
||||
- name: linux-aarch64-no-asm
|
||||
runs-on: ubuntu-24.04-arm
|
||||
config_extra: no-asm
|
||||
|
||||
name: CT validation (${{ matrix.name }})
|
||||
runs-on: ${{ matrix.runs-on }}
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
|
||||
- name: Install valgrind
|
||||
# On Debian/Ubuntu the main 'valgrind' package includes
|
||||
# /usr/include/valgrind/memcheck.h — no separate -dev package needed.
|
||||
run: |
|
||||
sudo apt-get -y update
|
||||
sudo apt-get -y install valgrind
|
||||
|
||||
- name: Configure with CT validation enabled
|
||||
run: |
|
||||
./Configure enable-ct-validation ${{ matrix.config_extra }}
|
||||
./configdata.pm --dump
|
||||
|
||||
- name: Build
|
||||
run: make -j$(nproc)
|
||||
|
||||
- name: Run CT validation under Valgrind
|
||||
# OSSL_VALGRIND_CT=yes causes OpenSSL::Test::test() to wrap each
|
||||
# test binary with valgrind --track-origins=yes --error-exitcode=1.
|
||||
# util/wrap.pl -> util/shlib_wrap.sh sets LD_LIBRARY_PATH first, so
|
||||
# the shared libraries are found correctly.
|
||||
#
|
||||
# Algorithms covered:
|
||||
# - memcmp: test_crypto_memcmp
|
||||
# - ML-KEM: test_internal_ml_kem
|
||||
# - ML-DSA: test_internal_ml_dsa
|
||||
run: |
|
||||
make TESTS="test_internal_ml_kem test_internal_ml_dsa test_crypto_memcmp" \
|
||||
OSSL_VALGRIND_CT=yes \
|
||||
test
|
||||
|
|
@ -8,8 +8,6 @@ on:
|
|||
paths:
|
||||
- "doc/man*/**"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
trigger:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
|
|
@ -17,7 +15,7 @@ jobs:
|
|||
steps:
|
||||
- name: "Trigger deployment workflow"
|
||||
run: |
|
||||
gh workflow run -f branch=${GITHUB_REF_NAME} deploy-site.yaml
|
||||
gh workflow run -f branch=${{ github.ref_name }} deploy-site.yaml
|
||||
sleep 3
|
||||
RUN_ID=$(gh run list -w deploy-site.yaml -L 1 --json databaseId -q ".[0].databaseId")
|
||||
gh run watch ${RUN_ID} --exit-status
|
||||
|
|
|
|||
31
.github/workflows/fips-checksums.yml
vendored
31
.github/workflows/fips-checksums.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -6,16 +6,7 @@
|
|||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: FIPS Check and ABIDIFF
|
||||
on:
|
||||
pull_request:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
on: [pull_request]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
|
@ -27,7 +18,7 @@ jobs:
|
|||
- name: install unifdef
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install unifdef
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --force-yes install unifdef
|
||||
- name: create build dirs
|
||||
run: |
|
||||
mkdir ./build-pristine
|
||||
|
|
@ -35,12 +26,11 @@ jobs:
|
|||
mkdir ./build
|
||||
mkdir ./source
|
||||
mkdir ./artifact
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
repository: ${{ github.event.pull_request.base.repo.full_name }}
|
||||
ref: ${{ github.event.pull_request.base.ref }}
|
||||
path: source-pristine
|
||||
persist-credentials: false
|
||||
- name: config pristine
|
||||
run: ../source-pristine/config enable-fips
|
||||
working-directory: ./build-pristine
|
||||
|
|
@ -53,10 +43,9 @@ jobs:
|
|||
- name: make fips-checksums pristine
|
||||
run: make fips-checksums
|
||||
working-directory: ./build-pristine
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
path: source
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ../source/config enable-fips
|
||||
working-directory: ./build
|
||||
|
|
@ -88,7 +77,7 @@ jobs:
|
|||
compute-abidiff:
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
BUILD_OPTS: -g --strict-warnings enable-ktls enable-fips enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-trace enable-zlib enable-zstd
|
||||
BUILD_OPTS: -g --strict-warnings enable-ktls enable-fips enable-egd enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-sctp enable-ssl3 enable-ssl3-method enable-trace enable-zlib enable-zstd
|
||||
steps:
|
||||
- name: create build dirs
|
||||
run: |
|
||||
|
|
@ -99,22 +88,20 @@ jobs:
|
|||
mkdir ./artifact
|
||||
- name: install extra config support
|
||||
run: sudo apt-get -y install libsctp-dev abigail-tools libzstd-dev zstd
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
repository: ${{ github.event.pull_request.base.repo.full_name }}
|
||||
ref: ${{ github.event.pull_request.base.ref }}
|
||||
path: source-pristine
|
||||
persist-credentials: false
|
||||
- name: config pristine
|
||||
run: ../source-pristine/config --banner=Configured $BUILD_OPTS && perl configdata.pm --dump
|
||||
working-directory: ./build-pristine
|
||||
- name: make pristine
|
||||
run: make -s -j4
|
||||
working-directory: ./build-pristine
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
path: source
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ../source/config --banner=Configured $BUILD_OPTS && perl configdata.pm --dump
|
||||
working-directory: ./build
|
||||
|
|
@ -126,7 +113,7 @@ jobs:
|
|||
- name: save PR number
|
||||
run: echo ${{ github.event.number }} > ./artifact/pr_num
|
||||
- name: save artifact
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: abidiff
|
||||
path: artifact/
|
||||
|
|
|
|||
8
.github/workflows/fips-label.yml
vendored
8
.github/workflows/fips-label.yml
vendored
|
|
@ -25,7 +25,7 @@ jobs:
|
|||
steps:
|
||||
- name: 'Download fipscheck artifact'
|
||||
if: ${{ github.event.workflow_run.conclusion == 'success' }}
|
||||
uses: actions/github-script@v8
|
||||
uses: actions/github-script@v7
|
||||
with:
|
||||
script: |
|
||||
var artifacts = await github.rest.actions.listWorkflowRunArtifacts({
|
||||
|
|
@ -48,7 +48,7 @@ jobs:
|
|||
if: ${{ github.event.workflow_run.conclusion == 'success' }}
|
||||
- name: 'Check artifact and apply'
|
||||
if: ${{ github.event.workflow_run.conclusion == 'success' }}
|
||||
uses: actions/github-script@v8
|
||||
uses: actions/github-script@v7
|
||||
with:
|
||||
github-token: ${{secrets.GITHUB_TOKEN}}
|
||||
script: |
|
||||
|
|
@ -85,7 +85,7 @@ jobs:
|
|||
|
||||
- name: 'Download abidiff artifact'
|
||||
if: ${{ github.event.workflow_run.conclusion == 'success' }}
|
||||
uses: actions/github-script@v8
|
||||
uses: actions/github-script@v7
|
||||
with:
|
||||
script: |
|
||||
var artifacts = await github.rest.actions.listWorkflowRunArtifacts({
|
||||
|
|
@ -108,7 +108,7 @@ jobs:
|
|||
if: ${{ github.event.workflow_run.conclusion == 'success' }}
|
||||
- name: 'Check artifact and apply'
|
||||
if: ${{ github.event.workflow_run.conclusion == 'success' }}
|
||||
uses: actions/github-script@v8
|
||||
uses: actions/github-script@v7
|
||||
with:
|
||||
github-token: ${{secrets.GITHUB_TOKEN}}
|
||||
script: |
|
||||
|
|
|
|||
10
.github/workflows/fuzz-checker.yml
vendored
10
.github/workflows/fuzz-checker.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -35,7 +35,7 @@ jobs:
|
|||
name: libFuzzer+,
|
||||
config: enable-fuzz-libfuzzer enable-asan enable-ubsan -fno-sanitize=function -fsanitize-coverage=trace-cmp -DFUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION,
|
||||
libs: --with-fuzzer-lib=/usr/lib/llvm-18/lib/libFuzzer.a --with-fuzzer-include=/usr/include/clang/18/include/fuzzer,
|
||||
extra: enable-fips enable-lms enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment enable-tls1_3 enable-weak-ssl-ciphers enable-rc5 enable-md2 enable-nextprotoneg,
|
||||
extra: enable-fips enable-ec_nistp_64_gcc_128 -fno-sanitize=alignment enable-tls1_3 enable-weak-ssl-ciphers enable-rc5 enable-md2 enable-ssl3 enable-ssl3-method enable-nextprotoneg,
|
||||
install: libfuzzer-18-dev,
|
||||
cc: clang-18,
|
||||
linker: clang++-18,
|
||||
|
|
@ -47,14 +47,12 @@ jobs:
|
|||
- name: install packages
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install ${{ matrix.fuzzy.install }}
|
||||
sudo apt-get -yq --force-yes install ${{ matrix.fuzzy.install }}
|
||||
- name: Adjust ASLR for sanitizer
|
||||
run: |
|
||||
sudo cat /proc/sys/vm/mmap_rnd_bits
|
||||
sudo sysctl -w vm.mmap_rnd_bits=28
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: config
|
||||
run: |
|
||||
|
|
|
|||
68
.github/workflows/interop-tests.yml
vendored
68
.github/workflows/interop-tests.yml
vendored
|
|
@ -3,20 +3,17 @@
|
|||
# filesystem for this job can be reached. Please note that any changes made to
|
||||
# this job involving file system paths should be made prefixed with, or relative
|
||||
# to that directory
|
||||
name: Interoperability tests with GnuTLS, NSS and OpenSSH
|
||||
name: Interoperability tests with GnuTLS and NSS
|
||||
on:
|
||||
schedule:
|
||||
- cron: '55 02 * * *'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
test:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-22.04
|
||||
container:
|
||||
image: docker.io/fedora:43
|
||||
image: docker.io/fedora:40
|
||||
options: --sysctl net.ipv6.conf.lo.disable_ipv6=0
|
||||
timeout-minutes: 90
|
||||
strategy:
|
||||
|
|
@ -26,33 +23,29 @@ jobs:
|
|||
env:
|
||||
COMPONENT: ${{ matrix.COMPONENT }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: Display environment
|
||||
run: export
|
||||
- name : Install needed tools
|
||||
run: |
|
||||
dnf -y install perl gcc make \
|
||||
rpmdevtools dnf-utils \
|
||||
tmt-all beakerlib \
|
||||
crypto-policies-scripts
|
||||
dnf -y install perl gcc rpmdevtools dnf-utils make tmt-all beakerlib \
|
||||
fips-mode-setup crypto-policies-scripts
|
||||
- name: install interop tests
|
||||
run: |
|
||||
cd ${GITHUB_WORKSPACE}
|
||||
git clone --branch=openssl-v0.2 --depth=1 https://gitlab.com/redhat-crypto/tests/interop.git
|
||||
git clone --branch=openssl-v0.1 --depth=1 https://gitlab.com/redhat-crypto/tests/interop.git
|
||||
- name: build openssl as an rpm
|
||||
run: |
|
||||
mkdir -p /build/SPECS && cd /build && echo -e "%_topdir /build\n%_lto_cflags %{nil}" >~/.rpmmacros && rpmdev-setuptree
|
||||
cd /build && cp ${GITHUB_WORKSPACE}/interop/openssl/openssl.spec SPECS/ && \
|
||||
cd SPECS/ && source ${GITHUB_WORKSPACE}/VERSION.dat && \
|
||||
sed -i "s/SOVERSION/$SHLIB_VERSION/" openssl.spec && \
|
||||
sed -i "s/^Version: .*\$/Version: $MAJOR.$MINOR.$PATCH/" openssl.spec
|
||||
sed -i "s/^Version: .*\$/Version: $MAJOR.$MINOR.$PATCH/" openssl.spec && \
|
||||
sed -i 's/^Release: .*$/Release: dev/' openssl.spec
|
||||
yum-builddep -y /build/SPECS/openssl.spec # just for sure nothing is missing
|
||||
mkdir -p /build/SOURCES
|
||||
tar --transform "s/^__w\/openssl\/openssl/openssl-$MAJOR.$MINOR.$PATCH/" -czf /build/SOURCES/openssl-$MAJOR.$MINOR.$PATCH.tar.gz "$GITHUB_WORKSPACE"
|
||||
tar --transform "s/^__w\/openssl\/openssl/openssl-$MAJOR.$MINOR.$PATCH/" -czf /build/SOURCES/openssl-$MAJOR.$MINOR.$PATCH.tar.gz /__w/openssl/openssl/
|
||||
rpmbuild -bb /build/SPECS/openssl.spec
|
||||
rpm -i --force /build/RPMS/x86_64/openssl-*
|
||||
dnf install -y /build/RPMS/x86_64/openssl-*
|
||||
cp ${GITHUB_WORKSPACE}/interop/openssl/openssl.cnf /etc/pki/tls/openssl.cnf
|
||||
- name: Run interop tests
|
||||
run: |
|
||||
|
|
@ -60,44 +53,3 @@ jobs:
|
|||
tmt run -av plans -n interop tests -f "tag: interop-openssl & tag: interop-$COMPONENT" provision -h local --feeling-safe execute -h tmt --interactive
|
||||
openssl version
|
||||
echo "Finished - important to prevent unwanted output truncating"
|
||||
openssh_interop:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
name: "openssh interop ${{ matrix.branch.openssl }}"
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
branch: [
|
||||
{ openssl: 'master', openssh: 'openssl-master', openssl_config: 'no-docs'},
|
||||
{ openssl: 'openssl-4.0', openssh: 'openssl-4.0', openssl_config: 'no-docs'},
|
||||
{ openssl: 'openssl-3.6', openssh: 'openssl-3.6', openssl_config: 'no-docs'},
|
||||
{ openssl: 'openssl-3.5', openssh: 'openssl-3.5', openssl_config: 'no-docs'},
|
||||
{ openssl: 'openssl-3.4', openssh: 'openssl-3.4', openssl_config: 'no-docs'},
|
||||
{ openssl: 'openssl-3.0', openssh: 'openssl-3.0', openssl_config: ''}
|
||||
]
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
EPHEMERAL_VM: yes
|
||||
TEST_SSH_UNSAFE_PERMISSIONS: 1
|
||||
TEST_SSH_HOSTBASED_AUTH: yes
|
||||
steps:
|
||||
- name: install dependencies
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq install autoconf zlib1g-dev
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
repository: openssh/openssh-portable
|
||||
fetch-depth: 1
|
||||
- name: setup ci
|
||||
run: sh ./.github/setup_ci.sh ${{ matrix.branch.openssh }} ubuntu-latest
|
||||
- name: autoreconf
|
||||
run: autoreconf
|
||||
- name: configure
|
||||
run: sh ./.github/configure.sh ${{ matrix.branch.openssh }}
|
||||
- name: make
|
||||
run: |
|
||||
make clean
|
||||
make -s -j4
|
||||
- name: run tests
|
||||
run: sh ./.github/run_test.sh
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -6,23 +6,14 @@
|
|||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: CIFuzz
|
||||
on:
|
||||
schedule:
|
||||
- cron: '50 01 * * *'
|
||||
workflow_dispatch:
|
||||
on: [pull_request, push]
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
Fuzzing:
|
||||
if: github.event_name != 'schedule' || github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Clear unnecessary files
|
||||
run: |
|
||||
df
|
||||
sudo rm -rf /usr/share/dotnet /usr/share/swift /usr/local/.ghcup /usr/local/share/powershell /usr/local/share/chromium /usr/local/lib/android /usr/local/lib/node_modules
|
||||
df
|
||||
- name: Build Fuzzers
|
||||
uses: google/oss-fuzz/infra/cifuzz/actions/build_fuzzers@master
|
||||
with:
|
||||
|
|
@ -35,7 +26,7 @@ jobs:
|
|||
fuzz-seconds: 600
|
||||
dry-run: false
|
||||
- name: Upload Crash
|
||||
uses: actions/upload-artifact@v5
|
||||
uses: actions/upload-artifact@v4
|
||||
if: failure()
|
||||
with:
|
||||
name: artifacts
|
||||
42
.github/workflows/make-release.yml
vendored
Normal file
42
.github/workflows/make-release.yml
vendored
Normal file
|
|
@ -0,0 +1,42 @@
|
|||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: "Make release"
|
||||
|
||||
on:
|
||||
push:
|
||||
tags:
|
||||
- "openssl-*"
|
||||
|
||||
jobs:
|
||||
release:
|
||||
runs-on: "releaser"
|
||||
steps:
|
||||
- name: "Checkout"
|
||||
uses: "actions/checkout@v4"
|
||||
with:
|
||||
fetch-depth: 1
|
||||
ref: ${{ github.ref_name }}
|
||||
github-server-url: "https://github.openssl.org/"
|
||||
repository: "openssl/openssl"
|
||||
token: ${{ secrets.GHE_TOKEN }}
|
||||
path: ${{ github.ref_name }}
|
||||
- name: "Prepare assets"
|
||||
run: |
|
||||
cd ${{ github.ref_name }}
|
||||
./util/mktar.sh
|
||||
mkdir assets && mv ${{ github.ref_name }}.tar.gz assets/ && cd assets
|
||||
openssl sha1 -r ${{ github.ref_name }}.tar.gz > ${{ github.ref_name }}.tar.gz.sha1
|
||||
openssl sha256 -r ${{ github.ref_name }}.tar.gz > ${{ github.ref_name }}.tar.gz.sha256
|
||||
gpg -u ${{ vars.signing_key_uid }} -o ${{ github.ref_name }}.tar.gz.asc -sba ${{ github.ref_name }}.tar.gz
|
||||
- name: "Create release"
|
||||
env:
|
||||
GITHUB_TOKEN: ${{ secrets.GH_TOKEN }}
|
||||
run: |
|
||||
VERSION=$(echo ${{ github.ref_name }} | cut -d "-" -f 2-)
|
||||
PRE_RELEASE=$([[ ${{ github.ref_name }} =~ alpha|beta ]] && echo "-p" || echo "")
|
||||
gh release create ${{ github.ref_name }} $PRE_RELEASE -t "OpenSSL $VERSION" -d --notes " " -R ${{ github.repository }} ${{ github.ref_name }}/assets/*
|
||||
2
.github/workflows/make-test
vendored
2
.github/workflows/make-test
vendored
|
|
@ -19,7 +19,7 @@ export OSSL_CI_ARTIFACTS_PATH="$(cd "$OSSL_CI_ARTIFACTS_PATH"; pwd)"
|
|||
|
||||
# Run the tests. This might fail, but we need to capture artifacts anyway.
|
||||
set +e
|
||||
make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16} "$@"
|
||||
make test HARNESS_JOBS=${HARNESS_JOBS:-4} "$@"
|
||||
RESULT=$?
|
||||
set -e
|
||||
|
||||
|
|
|
|||
229
.github/workflows/os-zoo.yml
vendored
229
.github/workflows/os-zoo.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -17,7 +17,6 @@ permissions:
|
|||
|
||||
jobs:
|
||||
alpine:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
|
|
@ -36,9 +35,7 @@ jobs:
|
|||
steps:
|
||||
- name: install packages
|
||||
run: apk --no-cache add build-base perl linux-headers ${{ matrix.cc }}
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
run: |
|
||||
./config --strict-warnings --banner=Configured no-shared enable-fips \
|
||||
|
|
@ -52,29 +49,26 @@ jobs:
|
|||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16}
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
linux:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
zoo:
|
||||
- image: docker.io/library/debian:10
|
||||
install: apt-get update && apt-get install -y gcc make perl
|
||||
- image: docker.io/library/debian:11
|
||||
install: apt-get update && apt-get install -y gcc make perl
|
||||
- image: docker.io/library/debian:12
|
||||
install: apt-get update && apt-get install -y gcc make perl
|
||||
- image: docker.io/library/debian:trixie
|
||||
install: apt-get update && apt-get install -y gcc make perl
|
||||
- image: docker.io/library/ubuntu:20.04
|
||||
install: apt-get update && apt-get install -y gcc make perl
|
||||
- image: docker.io/library/ubuntu:22.04
|
||||
install: apt-get update && apt-get install -y gcc make perl
|
||||
- image: docker.io/library/ubuntu:24.04
|
||||
install: apt-get update && apt-get install -y gcc make perl
|
||||
- image: docker.io/library/fedora:41
|
||||
- image: docker.io/library/fedora:38
|
||||
install: dnf install -y gcc make perl-core
|
||||
- image: docker.io/library/fedora:42
|
||||
- image: docker.io/library/fedora:39
|
||||
install: dnf install -y gcc make perl-core
|
||||
- image: docker.io/library/centos:8
|
||||
install: |
|
||||
|
|
@ -88,9 +82,7 @@ jobs:
|
|||
runs-on: ubuntu-latest
|
||||
container: ${{ matrix.zoo.image }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: install packages
|
||||
run: ${{ matrix.zoo.install }}
|
||||
- name: config
|
||||
|
|
@ -104,23 +96,20 @@ jobs:
|
|||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16}
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
macos:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
os: [macos-14, macos-15, macos-15-intel]
|
||||
os: [macos-13, macos-14, macos-15]
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured enable-fips enable-demos enable-h3demo
|
||||
run: ./config --strict-warnings --banner=Configured enable-fips
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -130,61 +119,39 @@ jobs:
|
|||
sysctl machdep.cpu
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16}
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
windows:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
platform:
|
||||
- os: windows-2022
|
||||
vcvars: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat
|
||||
- os: windows-2025
|
||||
vcvars: C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat
|
||||
runs-on: ${{ matrix.platform.os }}
|
||||
os: [windows-2019, windows-2022]
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- uses: ilammy/msvc-dev-cmd@v1
|
||||
- name: install nasm
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-x64.exe"
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer
|
||||
$actual = (Get-FileHash $installer -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" }
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
choco install nasm
|
||||
"C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe'
|
||||
$actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" }
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: prepare the build directory
|
||||
run: mkdir _build
|
||||
- name: config
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "${{ matrix.platform.vcvars }}"
|
||||
perl ..\Configure --banner=Configured --strict-warnings no-makedepend enable-fips
|
||||
perl configdata.pm --dump
|
||||
run: perl ..\Configure --banner=Configured no-makedepend enable-fips
|
||||
- name: config dump
|
||||
working-directory: _build
|
||||
run: ./configdata.pm --dump
|
||||
- name: build
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "${{ matrix.platform.vcvars }}"
|
||||
jom /j4 /S
|
||||
run: nmake /S
|
||||
- name: download coreinfo
|
||||
run: |
|
||||
mkdir _build\coreinfo
|
||||
Invoke-WebRequest -Uri "https://download.sysinternals.com/files/Coreinfo.zip" -outfile "_build\coreinfo\Coreinfo.zip"
|
||||
uses: suisei-cn/actions-download-file@v1.6.0
|
||||
with:
|
||||
url: "https://download.sysinternals.com/files/Coreinfo.zip"
|
||||
target: _build/coreinfo/
|
||||
- name: get cpu info
|
||||
working-directory: _build
|
||||
run: |
|
||||
|
|
@ -193,19 +160,14 @@ jobs:
|
|||
apps/openssl.exe version -c
|
||||
- name: test
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "${{ matrix.platform.vcvars }}"
|
||||
jom test VERBOSE_FAILURE=yes HARNESS_JOBS=4 LHASH_WORKERS=16
|
||||
run: nmake test VERBOSE_FAILURE=yes HARNESS_JOBS=4
|
||||
|
||||
linux-arm64:
|
||||
runs-on: ubuntu-24.04-arm
|
||||
runs-on: linux-arm64
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -213,58 +175,14 @@ jobs:
|
|||
- name: get cpu info
|
||||
run: ./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16}
|
||||
|
||||
linux-x86:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: run container
|
||||
run: |
|
||||
CONTAINER_ID=$(podman run -d -v $(pwd):/mnt -w /mnt --platform=linux/i386 docker.io/i386/debian:13 sleep infinity)
|
||||
echo "CONTAINER_ID=$CONTAINER_ID" >> "$GITHUB_ENV"
|
||||
- name: install dependencies
|
||||
run:
|
||||
podman exec -t $CONTAINER_ID sh -c "apt-get update && apt-get install -y gcc perl make"
|
||||
- name: config
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"./config --strict-warnings linux-x86 enable-demos enable-fips enable-lms enable-md2 enable-rc5 enable-trace"
|
||||
- name: config dump
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"./configdata.pm --dump"
|
||||
- name: make
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"make -j"
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
"./util/opensslwrap.sh version -c"
|
||||
- name: make test
|
||||
run: |
|
||||
podman exec -t $CONTAINER_ID sh -c \
|
||||
".github/workflows/make-test"
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
with:
|
||||
name: "ci@linux-x86"
|
||||
path: artifacts.tar.gz
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
linux-ppc64le:
|
||||
runs-on: linux-ppc64le
|
||||
if: github.repository == 'openssl/openssl'
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
run: ./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -274,17 +192,14 @@ jobs:
|
|||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16}
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
linux-s390x:
|
||||
runs-on: linux-s390x
|
||||
if: github.repository == 'openssl/openssl'
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
run: ./config --strict-warnings enable-fips enable-md2 enable-rc5 enable-trace
|
||||
run: ./config --strict-warnings -Wno-stringop-overflow enable-fips enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -294,17 +209,14 @@ jobs:
|
|||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16}
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
linux-riscv64:
|
||||
runs-on: linux-riscv64
|
||||
if: github.repository == 'openssl/openssl'
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
run: ./config enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
run: ./config enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
|
|
@ -313,86 +225,41 @@ jobs:
|
|||
run: ./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
env:
|
||||
OPENSSL_riscvcap: RV64GC_ZBA_ZBB_ZBC_ZBS_ZKT_V
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} LHASH_WORKERS=${LHASH_WORKERS:-16}
|
||||
OPENSSL_riscvcap: ZBA_ZBB_ZBC_ZBS_ZKT
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
freebsd-x86_64:
|
||||
runs-on: ubuntu-latest
|
||||
if: github.repository == 'openssl/openssl'
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: config
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
uses: cross-platform-actions/action@v0.26.0
|
||||
with:
|
||||
operating_system: freebsd
|
||||
version: "13.4"
|
||||
shutdown_vm: false
|
||||
run: |
|
||||
sudo pkg install -y gcc perl5
|
||||
./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-trace
|
||||
- name: config dump
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
uses: cross-platform-actions/action@v0.26.0
|
||||
with:
|
||||
operating_system: freebsd
|
||||
version: "13.4"
|
||||
shutdown_vm: false
|
||||
run: ./configdata.pm --dump
|
||||
- name: make
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
uses: cross-platform-actions/action@v0.26.0
|
||||
with:
|
||||
operating_system: freebsd
|
||||
version: "13.4"
|
||||
shutdown_vm: false
|
||||
run: make -j4
|
||||
- name: make test
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
uses: cross-platform-actions/action@v0.26.0
|
||||
with:
|
||||
operating_system: freebsd
|
||||
version: "13.4"
|
||||
run: |
|
||||
./util/opensslwrap.sh version -c
|
||||
.github/workflows/make-test
|
||||
|
||||
openbsd-x86_64:
|
||||
runs-on: ubuntu-latest
|
||||
if: github.repository == 'openssl/openssl'
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- name: config
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
with:
|
||||
operating_system: openbsd
|
||||
architecture: x86-64
|
||||
version: '7.7'
|
||||
shutdown_vm: false
|
||||
run: |
|
||||
./config --strict-warnings enable-fips enable-ec_nistp_64_gcc_128 enable-md2 enable-rc5 enable-trace
|
||||
- name: config dump
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
with:
|
||||
operating_system: openbsd
|
||||
architecture: x86-64
|
||||
version: '7.7'
|
||||
shutdown_vm: false
|
||||
run: |
|
||||
./configdata.pm --dump
|
||||
- name: make
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
with:
|
||||
operating_system: openbsd
|
||||
architecture: x86-64
|
||||
version: '7.7'
|
||||
shutdown_vm: false
|
||||
run: |
|
||||
make -j4
|
||||
- name: make test
|
||||
uses: cross-platform-actions/action@46e8d7fb25520a8d6c64fd2b7a1192611da98eda #v0.30.0
|
||||
with:
|
||||
operating_system: openbsd
|
||||
architecture: x86-64
|
||||
version: '7.7'
|
||||
run: |
|
||||
./util/opensslwrap.sh version -c
|
||||
.github/workflows/make-test
|
||||
|
|
|
|||
71
.github/workflows/perl-minimal-checker.yml
vendored
71
.github/workflows/perl-minimal-checker.yml
vendored
|
|
@ -1,71 +0,0 @@
|
|||
# Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
# Jobs run per pull request submission
|
||||
name: Perl-minimal-checker CI
|
||||
on:
|
||||
pull_request:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
push:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
perl-minimal-checker:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: Install perl 5.10
|
||||
run: |
|
||||
pushd /tmp
|
||||
mkdir perl
|
||||
wget https://www.cpan.org/src/5.0/perl-5.10.1.tar.bz2
|
||||
tar xf perl-5.10.1.tar.bz2
|
||||
cd perl-5.10.1
|
||||
./Configure -des -Dprefix=/tmp/perl -A ccflags='-Wno-incompatible-pointer-types' -A define:malloctype='void *' -A define:freetype='void' -Dlibs='-ldl -lm -lutil -lc'
|
||||
make -j $(nproc) perl
|
||||
make install
|
||||
popd
|
||||
- name: Install Test::More 0.96
|
||||
run: |
|
||||
pushd /tmp
|
||||
wget https://cpan.metacpan.org/authors/id/M/MS/MSCHWERN/Test-Simple-0.96.tar.gz
|
||||
tar xf Test-Simple-0.96.tar.gz
|
||||
cd Test-Simple-0.96
|
||||
PATH="/tmp/perl/bin:$PATH"
|
||||
perl Makefile.PL
|
||||
make -j$(nproc) && make install
|
||||
perl -MTest::More -e 'print "$Test::More::VERSION\n"'
|
||||
popd
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Build openssl
|
||||
run: ./config && make -j $(nproc)
|
||||
- name: Install sed
|
||||
run: sudo apt update && sudo apt install sed
|
||||
- name: Check minimal version compliance
|
||||
run: |
|
||||
PM_FILES=($(find . -name "*.pm"))
|
||||
perl -v
|
||||
status=0
|
||||
for p in "${PM_FILES[@]}"; do perl -I"$(pwd)/util/perl" -I"$(pwd)" -I"$(pwd)/external/perl/Text-Template-1.56/lib" -c "$p" | sed -n '/@INC/{p; q1}' || status=1; done;
|
||||
exit $status
|
||||
92
.github/workflows/prov-compat-label.yml
vendored
92
.github/workflows/prov-compat-label.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -10,22 +10,13 @@
|
|||
|
||||
name: Provider compatibility for PRs
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
on: [pull_request]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
env:
|
||||
opts: enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib
|
||||
opts: enable-rc5 enable-md2 enable-ssl3 enable-weak-ssl-ciphers enable-zlib
|
||||
|
||||
jobs:
|
||||
fips-releases:
|
||||
|
|
@ -98,7 +89,7 @@ jobs:
|
|||
-providers
|
||||
working-directory: ${{ matrix.release.dir }}
|
||||
|
||||
- uses: actions/upload-artifact@v5
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: ${{ matrix.release.tgz }}
|
||||
path: ${{ matrix.release.tgz }}
|
||||
|
|
@ -118,54 +109,46 @@ jobs:
|
|||
name: '',
|
||||
dir: PR,
|
||||
tgz: PR.tar.gz,
|
||||
extra_config: "enable-lms enable-tls-deprecated-ec",
|
||||
}, {
|
||||
name: openssl-3.0,
|
||||
dir: branch-3.0,
|
||||
tgz: branch-3.0.tar.gz,
|
||||
extra_config: "",
|
||||
}, {
|
||||
name: openssl-3.2,
|
||||
dir: branch-3.2,
|
||||
tgz: branch-3.2.tar.gz,
|
||||
}, {
|
||||
name: openssl-3.3,
|
||||
dir: branch-3.3,
|
||||
tgz: branch-3.3.tar.gz,
|
||||
}, {
|
||||
name: openssl-3.4,
|
||||
dir: branch-3.4,
|
||||
tgz: branch-3.4.tar.gz,
|
||||
extra_config: "",
|
||||
}, {
|
||||
name: openssl-3.5,
|
||||
dir: branch-3.5,
|
||||
tgz: branch-3.5.tar.gz,
|
||||
extra_config: "",
|
||||
}, {
|
||||
name: openssl-3.6,
|
||||
dir: branch-3.6,
|
||||
tgz: branch-3.6.tar.gz,
|
||||
extra_config: "enable-lms",
|
||||
}, {
|
||||
name: openssl-4.0,
|
||||
dir: branch-4.0,
|
||||
tgz: branch-4.0.tar.gz,
|
||||
extra_config: "enable-lms enable-tls-deprecated-ec",
|
||||
}, {
|
||||
name: master,
|
||||
dir: branch-master,
|
||||
tgz: branch-master.tar.gz,
|
||||
extra_config: "enable-lms enable-tls-deprecated-ec",
|
||||
},
|
||||
]
|
||||
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
path: ${{ matrix.branch.dir }}
|
||||
repository: openssl/openssl
|
||||
ref: ${{ matrix.branch.name }}
|
||||
persist-credentials: false
|
||||
- name: localegen
|
||||
run: sudo locale-gen tr_TR.UTF-8
|
||||
|
||||
- name: config branch
|
||||
run: |
|
||||
./config --banner=Configured enable-shared enable-fips ${{ env.opts }} ${{ matrix.branch.extra_config }}
|
||||
./config --banner=Configured enable-shared enable-fips ${{ env.opts }}
|
||||
working-directory: ${{ matrix.branch.dir }}
|
||||
- name: config dump current
|
||||
run: ./configdata.pm --dump
|
||||
|
|
@ -195,7 +178,7 @@ jobs:
|
|||
./util/opensslwrap.sh version -c
|
||||
working-directory: ${{ matrix.branch.dir }}
|
||||
|
||||
- uses: actions/upload-artifact@v5
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: ${{ matrix.branch.tgz }}
|
||||
path: ${{ matrix.branch.tgz }}
|
||||
|
|
@ -214,63 +197,58 @@ jobs:
|
|||
# Note that releases are not used as a test environment for
|
||||
# later providers. Problems in these situations ought to be
|
||||
# caught by cross branch testing before the release.
|
||||
tree_a: [ branch-4.0, branch-3.6, branch-3.5, branch-3.4, branch-3.0,
|
||||
tree_a: [ branch-3.5, branch-3.4, branch-3.3, branch-3.2, branch-3.0,
|
||||
openssl-3.0.0, openssl-3.0.8, openssl-3.0.9, openssl-3.1.2 ]
|
||||
tree_b: [ PR ]
|
||||
include:
|
||||
- tree_a: PR
|
||||
tree_b: branch-master
|
||||
- tree_a: PR
|
||||
tree_b: branch-4.0
|
||||
- tree_a: PR
|
||||
tree_b: branch-3.6
|
||||
- tree_a: PR
|
||||
tree_b: branch-3.5
|
||||
- tree_a: PR
|
||||
tree_b: branch-3.4
|
||||
- tree_a: PR
|
||||
tree_b: branch-3.3
|
||||
- tree_a: PR
|
||||
tree_b: branch-3.2
|
||||
- tree_a: PR
|
||||
tree_b: branch-3.0
|
||||
steps:
|
||||
- name: early exit checks
|
||||
id: early_exit
|
||||
env:
|
||||
B_BRANCH: ${{ matrix.tree_b }}
|
||||
PR_LABELS: ${{ toJson(github.event.pull_request.labels.*.name) }}
|
||||
run: |
|
||||
b_ver=${B_BRANCH#branch-}
|
||||
b_label="branch: $b_ver"
|
||||
if [[ "$PR_LABELS" == *"$b_label"* ]]; then
|
||||
echo "Skipping branches modified by the PR"
|
||||
echo "skip=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "skip=false" >> "$GITHUB_OUTPUT"
|
||||
if [ "${{ matrix.tree_a }}" = "${{ matrix.tree_b }}" ]; \
|
||||
then \
|
||||
echo "Skipping because both are the same version"; \
|
||||
exit 1; \
|
||||
fi
|
||||
continue-on-error: true
|
||||
|
||||
- uses: actions/download-artifact@v6.0.0
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
- uses: actions/download-artifact@v4.1.8
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
with:
|
||||
name: ${{ matrix.tree_a }}.tar.gz
|
||||
- name: unpack first build
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: tar xzf "${{ matrix.tree_a }}.tar.gz"
|
||||
|
||||
- uses: actions/download-artifact@v6.0.0
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
- uses: actions/download-artifact@v4.1.8
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
with:
|
||||
name: ${{ matrix.tree_b }}.tar.gz
|
||||
- name: unpack second build
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: tar xzf "${{ matrix.tree_b }}.tar.gz"
|
||||
|
||||
- name: set up cross validation of FIPS from A with tree from B
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: |
|
||||
cp providers/fips.so ../${{ matrix.tree_b }}/providers/
|
||||
cp providers/fipsmodule.cnf ../${{ matrix.tree_b }}/providers/
|
||||
working-directory: ${{ matrix.tree_a }}
|
||||
|
||||
- name: show module versions from cross validation
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: |
|
||||
./util/wrap.pl -fips apps/openssl list -provider-path providers \
|
||||
-provider base \
|
||||
|
|
@ -281,14 +259,14 @@ jobs:
|
|||
working-directory: ${{ matrix.tree_b }}
|
||||
|
||||
- name: get cpu info
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
working-directory: ${{ matrix.tree_b }}
|
||||
|
||||
- name: run cross validation tests of FIPS from A with tree from B
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: |
|
||||
make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
working-directory: ${{ matrix.tree_b }}
|
||||
|
|
|
|||
77
.github/workflows/provider-compatibility.yml
vendored
77
.github/workflows/provider-compatibility.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2023-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2023-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -24,11 +24,10 @@ permissions:
|
|||
contents: read
|
||||
|
||||
env:
|
||||
opts: enable-rc5 enable-md2 enable-weak-ssl-ciphers enable-zlib
|
||||
opts: enable-rc5 enable-md2 enable-ssl3 enable-weak-ssl-ciphers enable-zlib
|
||||
|
||||
jobs:
|
||||
fips-releases:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
matrix:
|
||||
release: [
|
||||
|
|
@ -97,14 +96,13 @@ jobs:
|
|||
-providers
|
||||
working-directory: ${{ matrix.release.dir }}
|
||||
|
||||
- uses: actions/upload-artifact@v5
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: ${{ matrix.release.tgz }}
|
||||
path: ${{ matrix.release.tgz }}
|
||||
retention-days: 7
|
||||
|
||||
development-branches:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
matrix:
|
||||
branch: [
|
||||
|
|
@ -113,54 +111,46 @@ jobs:
|
|||
# `dir' directory that will be used to build and test in.
|
||||
# `tgz' is the name of the tarball use to keep the artifacts of
|
||||
# the build.
|
||||
# `extra_config` adds extra config build option for the branch.
|
||||
{
|
||||
name: openssl-3.0,
|
||||
dir: branch-3.0,
|
||||
tgz: branch-3.0.tar.gz,
|
||||
extra_config: "",
|
||||
}, {
|
||||
name: openssl-3.2,
|
||||
dir: branch-3.2,
|
||||
tgz: branch-3.2.tar.gz,
|
||||
}, {
|
||||
name: openssl-3.3,
|
||||
dir: branch-3.3,
|
||||
tgz: branch-3.3.tar.gz,
|
||||
}, {
|
||||
name: openssl-3.4,
|
||||
dir: branch-3.4,
|
||||
tgz: branch-3.4.tar.gz,
|
||||
extra_config: "",
|
||||
}, {
|
||||
name: openssl-3.5,
|
||||
dir: branch-3.5,
|
||||
tgz: branch-3.5.tar.gz,
|
||||
extra_config: "",
|
||||
}, {
|
||||
name: openssl-3.6,
|
||||
dir: branch-3.6,
|
||||
tgz: branch-3.6.tar.gz,
|
||||
extra_config: "enable-lms",
|
||||
}, {
|
||||
name: openssl-4.0,
|
||||
dir: branch-4.0,
|
||||
tgz: branch-4.0.tar.gz,
|
||||
extra_config: "enable-lms enable-tls-deprecated-ec",
|
||||
}, {
|
||||
name: master,
|
||||
dir: branch-master,
|
||||
tgz: branch-master.tar.gz,
|
||||
extra_config: "enable-lms enable-tls-deprecated-ec",
|
||||
},
|
||||
]
|
||||
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
path: ${{ matrix.branch.dir }}
|
||||
repository: openssl/openssl
|
||||
ref: ${{ matrix.branch.name }}
|
||||
persist-credentials: false
|
||||
- name: localegen
|
||||
run: sudo locale-gen tr_TR.UTF-8
|
||||
|
||||
- name: config branch
|
||||
run: |
|
||||
./config --banner=Configured enable-shared enable-fips ${{ env.opts }} ${{ matrix.branch.extra_config }}
|
||||
./config --banner=Configured enable-shared enable-fips ${{ env.opts }}
|
||||
working-directory: ${{ matrix.branch.dir }}
|
||||
- name: config dump current
|
||||
run: ./configdata.pm --dump
|
||||
|
|
@ -194,14 +184,13 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
working-directory: ${{ matrix.branch.dir }}
|
||||
|
||||
- uses: actions/upload-artifact@v5
|
||||
- uses: actions/upload-artifact@v4
|
||||
with:
|
||||
name: ${{ matrix.branch.tgz }}
|
||||
path: ${{ matrix.branch.tgz }}
|
||||
retention-days: 7
|
||||
|
||||
cross-testing:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
needs: [fips-releases, development-branches]
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
|
|
@ -213,47 +202,47 @@ jobs:
|
|||
# Note that releases are not used as a test environment for
|
||||
# later providers. Problems in these situations ought to be
|
||||
# caught by cross branch testing before the release.
|
||||
tree_a: [ branch-master, branch-4.0, branch-3.6, branch-3.5, branch-3.4,
|
||||
branch-3.0,
|
||||
tree_a: [ branch-master, branch-3.5, branch-3.4, branch-3.3,
|
||||
branch-3.2, branch-3.0,
|
||||
openssl-3.0.0, openssl-3.0.8, openssl-3.0.9, openssl-3.1.2 ]
|
||||
tree_b: [ branch-master, branch-4.0, branch-3.6, branch-3.5, branch-3.4,
|
||||
branch-3.0 ]
|
||||
tree_b: [ branch-master, branch-3.5, branch-3.4, branch-3.3,
|
||||
branch-3.2, branch-3.0 ]
|
||||
steps:
|
||||
- name: early exit checks
|
||||
id: early_exit
|
||||
run: |
|
||||
if [ "${{ matrix.tree_a }}" = "${{ matrix.tree_b }}" ]; then
|
||||
echo "Skipping because both are the same version"
|
||||
echo "skip=true" >> "$GITHUB_OUTPUT"
|
||||
else
|
||||
echo "skip=false" >> "$GITHUB_OUTPUT"
|
||||
if [ "${{ matrix.tree_a }}" = "${{ matrix.tree_b }}" ]; \
|
||||
then \
|
||||
echo "Skipping because both are the same version"; \
|
||||
exit 1; \
|
||||
fi
|
||||
continue-on-error: true
|
||||
|
||||
- uses: actions/download-artifact@v6.0.0
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
- uses: actions/download-artifact@v4.1.8
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
with:
|
||||
name: ${{ matrix.tree_a }}.tar.gz
|
||||
- name: unpack first build
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: tar xzf "${{ matrix.tree_a }}.tar.gz"
|
||||
|
||||
- uses: actions/download-artifact@v6.0.0
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
- uses: actions/download-artifact@v4.1.8
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
with:
|
||||
name: ${{ matrix.tree_b }}.tar.gz
|
||||
- name: unpack second build
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: tar xzf "${{ matrix.tree_b }}.tar.gz"
|
||||
|
||||
- name: set up cross validation of FIPS from A with tree from B
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: |
|
||||
cp providers/fips.so ../${{ matrix.tree_b }}/providers/
|
||||
cp providers/fipsmodule.cnf ../${{ matrix.tree_b }}/providers/
|
||||
working-directory: ${{ matrix.tree_a }}
|
||||
|
||||
- name: show module versions from cross validation
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: |
|
||||
./util/wrap.pl -fips apps/openssl list -provider-path providers \
|
||||
-provider base \
|
||||
|
|
@ -264,14 +253,14 @@ jobs:
|
|||
working-directory: ${{ matrix.tree_b }}
|
||||
|
||||
- name: get cpu info
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
working-directory: ${{ matrix.tree_b }}
|
||||
|
||||
- name: run cross validation tests of FIPS from A with tree from B
|
||||
if: steps.early_exit.outputs.skip != 'true'
|
||||
if: steps.early_exit.outcome == 'success'
|
||||
run: |
|
||||
make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
working-directory: ${{ matrix.tree_b }}
|
||||
|
|
|
|||
334
.github/workflows/riscv-more-cross-compiles.yml
vendored
334
.github/workflows/riscv-more-cross-compiles.yml
vendored
|
|
@ -1,334 +0,0 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: Cross Compile for RISC-V Extensions
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
types: [opened, reopened, edited, synchronize]
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
push:
|
||||
schedule:
|
||||
- cron: '35 02 * * *'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
cross-compilation-riscv:
|
||||
# pull request title contains 'riscv'
|
||||
# pull request title contains 'RISC-V'
|
||||
# pull request body contains '[riscv ci]'
|
||||
# push event commit message contains '[riscv ci]'
|
||||
# cron job
|
||||
# manual dispatch
|
||||
if: contains(github.event.pull_request.title, 'riscv') || contains(github.event.pull_request.title, 'RISC-V') || contains(github.event.pull_request.body, '[riscv ci]') || contains(github.event.head_commit.message, '[riscv ci]') || (github.event_name == 'schedule' && github.repository == 'openssl/openssl') || github.event_name == 'workflow_dispatch'
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
# The platform matrix specifies:
|
||||
# arch: the architecture to build for, this defines the tool-chain
|
||||
# prefix {arch}- and the Debian compiler package gcc-{arch}
|
||||
# name.
|
||||
# libs: the Debian package for the necessary link/runtime libraries.
|
||||
# target: the OpenSSL configuration target to use, this is passed
|
||||
# directly to the config command line.
|
||||
# fips: set to "no" to disable building FIPS, leave unset to
|
||||
# build the FIPS provider.
|
||||
# tests: omit this to run all the tests using QEMU, set it to "none"
|
||||
# to never run the tests, otherwise its value is passed to
|
||||
# the "make test" command to allow selective disabling of
|
||||
# tests.
|
||||
# qemucpu: optional; string that describes CPU properties.
|
||||
# The string will be used to set the QEMU_CPU variable.
|
||||
# opensslcapsname: optional; string that describes the postfix of the
|
||||
# OpenSSL environment variable that defines CPU
|
||||
# capabilities. E.g. "foo" will result in an
|
||||
# environment variable with the name OPENSSL_foo.
|
||||
# opensslcaps: optional; if opensslcapsname (see above) is set, then
|
||||
# this string will be used as content for the OpenSSL
|
||||
# capabilities variable.
|
||||
# capscheck: optional; ERE pattern passed to grep -E to assert that
|
||||
# "openssl info -cpusettings" output contains expected
|
||||
# capabilities when using the hwprobe detection path.
|
||||
# ppa: Launchpad PPA repository to download packages from.
|
||||
platform: [
|
||||
# Scalar Crypto
|
||||
{
|
||||
# RV64GC with bitmanip and scalar crypto extensions
|
||||
# crypto/aes/asm/aes-riscv64-zkn.pl
|
||||
# crypto/modes/gcm128.c
|
||||
# The following paths only use ZBB
|
||||
# crypto/sha/asm/sha256-riscv64-zbb.pl
|
||||
# crypto/sha/asm/sha512-riscv64-zbb.pl
|
||||
# crypto/sm3/asm/sm3-riscv64-zbb.pl
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,zbb=true,zbc=true,zbkb=true,zknd=true,zkne=true",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_zbb_zbc_zbkb_zknd_zkne"
|
||||
}, {
|
||||
# RV64GC ZBC ZBB, but without ZBKB
|
||||
# crypto/modes/gcm128.c
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,zbc=true,zbb=true,zbkb=false",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_zbc_zbb"
|
||||
}, {
|
||||
# RV64GC ZBC, but without ZBB/ZBKB
|
||||
# crypto/modes/gcm128.c
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,zbc=true,zbb=false,zbkb=false",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_zbc"
|
||||
}, {
|
||||
# Vector Crypto
|
||||
# RV64GC V ZBB, but without ZVKB
|
||||
# For chacha20 vector-only path from #24069
|
||||
# crypto/chacha/asm/chacha-riscv64-v-zbb.pl
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,v=true,vlen=128,zbb=true,zvbb=false,zvkb=false",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_v_zbb"
|
||||
}, {
|
||||
# RV64GC V ZVKG, but without ZVKB
|
||||
# crypto/modes/gcm128.c
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
# do not use zvkb flag for qemucpu as ubuntu-latest (24.04) uses QEMU 8.2.2
|
||||
# see https://lists.nongnu.org/archive/html/qemu-devel/2024-05/msg02231.html
|
||||
# Should be zvkg=true,zvbb=false,zvkb=false
|
||||
qemucpu: "rv64,v=true,vlen=128,zvkg=true,zvbb=false",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_v_zvkg"
|
||||
}, {
|
||||
# RV64GC V ZVKB ZVBC, but without ZVKG
|
||||
# crypto/modes/gcm128.c
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
# do not use zvkb flag for qemucpu as ubuntu-latest (24.04) uses QEMU 8.2.2
|
||||
# see https://lists.nongnu.org/archive/html/qemu-devel/2024-05/msg02231.html
|
||||
# Should be zvkb=true,zvbc=true,zvkg=false
|
||||
qemucpu: "rv64,v=true,vlen=128,zvbb=true,zvbc=true,zvkg=false",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_v_zvkb_zvbc"
|
||||
}, {
|
||||
# RV64GC V ZVKNED, but without ZVBB/ZVKB/ZVKG
|
||||
# crypto/aes/asm/aes-riscv64-zvkned.pl
|
||||
# providers/implementations/ciphers/cipher_aes_xts_hw.c
|
||||
# providers/implementations/ciphers/cipher_aes_hw_rv64i.inc
|
||||
# providers/implementations/ciphers/cipher_aes_gcm_hw_rv64i.inc
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,v=true,vlen=128,zvkned=true,zvbb=false,zvkb=false,zvkg=false",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_v_zvkned"
|
||||
}, {
|
||||
# RV64GC with all currently OpenSSL-supported extensions
|
||||
# crypto/chacha/chacha_riscv.c (with ZVKB)
|
||||
# crypto/modes/gcm128.c (with ZVKG/ZVKB)
|
||||
# crypto/sm3/asm/sm3-riscv64-zvksh.pl
|
||||
# crypto/sm4/asm/sm4-riscv64-zvksed.pl
|
||||
# crypto/aes/asm/aes-riscv64-zvbb-zvkg-zvkned.pl
|
||||
# crypto/aes/asm/aes-riscv64-zvkb-zvkned.pl
|
||||
# crypto/modes/asm/ghash-riscv64-zvkg.pl
|
||||
# crypto/modes/asm/aes-gcm-riscv64-zvkb-zvkg-zvkned.pl
|
||||
# crypto/modes/asm/ghash-riscv64-zvkb-zvbc.pl
|
||||
# crypto/sha/asm/sha256-riscv64-zvkb-zvknha_or_zvknhb.pl
|
||||
# crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,zba=true,zbb=true,zbc=true,zbs=true,zbkb=true,zbkc=true,zbkx=true,zknd=true,zkne=true,zknh=true,zksed=true,zksh=true,zkr=true,zkt=true,v=true,vlen=128,zvbb=true,zvbc=true,zvkb=true,zvkg=true,zvkned=true,zvknha=true,zvknhb=true,zvksed=true,zvksh=true",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_zba_zbb_zbc_zbs_zbkb_zbkc_zbkx_zknd_zkne_zknh_zksed_zksh_zkr_zkt_v_zvbb_zvbc_zvkb_zvkg_zvkned_zvknha_zvknhb_zvksed_zvksh"
|
||||
}, {
|
||||
# RV64GC with all currently OpenSSL-supported extensions, with zvl256
|
||||
# crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl
|
||||
# crypto/sm3/asm/sm3-riscv64-zvksh.pl
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,zba=true,zbb=true,zbc=true,zbs=true,zbkb=true,zbkc=true,zbkx=true,zknd=true,zkne=true,zknh=true,zksed=true,zksh=true,zkr=true,zkt=true,v=true,vlen=256,zvbb=true,zvbc=true,zvkb=true,zvkg=true,zvkned=true,zvknha=true,zvknhb=true,zvksed=true,zvksh=true",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_zba_zbb_zbc_zbs_zbkb_zbkc_zbkx_zknd_zkne_zknh_zksed_zksh_zkr_zkt_v_zvbb_zvbc_zvkb_zvkg_zvkned_zvknha_zvknhb_zvksed_zvksh_zvl256"
|
||||
}, {
|
||||
# RV64GC with all currently OpenSSL-supported extensions, with zvl512
|
||||
# crypto/sha/asm/sha512-riscv64-zvkb-zvknhb.pl
|
||||
# crypto/sm3/asm/sm3-riscv64-zvksh.pl
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,zba=true,zbb=true,zbc=true,zbs=true,zbkb=true,zbkc=true,zbkx=true,zknd=true,zkne=true,zknh=true,zksed=true,zksh=true,zkr=true,zkt=true,v=true,vlen=512,zvbb=true,zvbc=true,zvkb=true,zvkg=true,zvkned=true,zvknha=true,zvknhb=true,zvksed=true,zvksh=true",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_zba_zbb_zbc_zbs_zbkb_zbkc_zbkx_zknd_zkne_zknh_zksed_zksh_zkr_zkt_v_zvbb_zvbc_zvkb_zvkg_zvkned_zvknha_zvknhb_zvksed_zvksh_zvl512"
|
||||
}, {
|
||||
# Inline asm
|
||||
# zbb/zbkb:
|
||||
# include/crypto/md32_common.h
|
||||
# include/crypto/modes.h
|
||||
# crypto/chacha/chacha_enc.c
|
||||
# crypto/des/des_local.h
|
||||
# zknh (zbt/zpn not available in QEMU):
|
||||
# crypto/sha/sha512.c
|
||||
# crypto/sha/sha256.c
|
||||
# zksh:
|
||||
# crypto/sm3/sm3_local.h
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: -march=rv64gc_zbb_zbkb_zknh_zksh linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,zbb=true,zbkb=true,zknh=true,zksh=true",
|
||||
opensslcapsname: riscvcap, # OPENSSL_riscvcap
|
||||
opensslcaps: "rv64gc_inlineasm" # for uploading artifact
|
||||
}, {
|
||||
# hwprobe path: RV64GC without V, no OPENSSL_riscvcap override.
|
||||
# Forces the hwprobe_to_cap() code path (skipped when OPENSSL_riscvcap is set).
|
||||
# V is absent so AT_HWCAP V bit is clear (VECTOR_CAPABLE=false).
|
||||
# The rv64 CPU model includes ZBB/ZBC/ZBS/ZBKB by default.
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,zbb=true,zbc=true,zbs=true,zbkb=true,v=false",
|
||||
# No opensslcapsname: hwprobe is used for capability detection.
|
||||
opensslcaps: "rv64gc_novector_hwprobe",
|
||||
# ZBB must be detected
|
||||
capscheck: "_ZBB",
|
||||
}, {
|
||||
# hwprobe path: RV64GC + V + ZVKNED (vlen=128), no OPENSSL_riscvcap override.
|
||||
# Forces the hwprobe_to_cap() code path (skipped when OPENSSL_riscvcap is set).
|
||||
# V is present so AT_HWCAP V bit is set (VECTOR_CAPABLE=true).
|
||||
arch: riscv64-linux-gnu,
|
||||
libs: libc6-dev-riscv64-cross,
|
||||
target: linux64-riscv64,
|
||||
fips: no,
|
||||
qemucpu: "rv64,v=true,vlen=128,zvkned=true",
|
||||
# No opensslcapsname: hwprobe is used for capability detection.
|
||||
opensslcaps: "rv64gc_v_zvkned_hwprobe",
|
||||
# V must be detected. ZVKNED is not reported by QEMU 8.2.2 (ubuntu-latest)
|
||||
# via hwprobe despite being set in QEMU_CPU; tighten once CI moves to a
|
||||
# newer QEMU that reports all Zvk* extensions via hwprobe.
|
||||
capscheck: "_V",
|
||||
}
|
||||
]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: install package repository
|
||||
if: matrix.platform.ppa != ''
|
||||
run: |
|
||||
sudo add-apt-repository ppa:${{ matrix.platform.ppa }}
|
||||
- name: install packages
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install \
|
||||
gcc-${{ matrix.platform.arch }} \
|
||||
${{ matrix.platform.libs }}
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
|
||||
- name: config with FIPS
|
||||
if: matrix.platform.fips != 'no'
|
||||
run: |
|
||||
./config --banner=Configured --strict-warnings enable-fips enable-lms \
|
||||
--cross-compile-prefix=${{ matrix.platform.arch }}- \
|
||||
${{ matrix.platform.target }}
|
||||
- name: config without FIPS
|
||||
if: matrix.platform.fips == 'no'
|
||||
run: |
|
||||
./config --banner=Configured --strict-warnings enable-lms \
|
||||
--cross-compile-prefix=${{ matrix.platform.arch }}- \
|
||||
${{ matrix.platform.target }}
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
|
||||
- name: install qemu
|
||||
if: matrix.platform.tests != 'none'
|
||||
run: sudo apt-get -yq --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install qemu-user
|
||||
|
||||
- name: Set QEMU environment
|
||||
if: matrix.platform.qemucpu != ''
|
||||
run: echo "QEMU_CPU=${{ matrix.platform.qemucpu }}" >> $GITHUB_ENV
|
||||
|
||||
- name: Set OpenSSL caps environment
|
||||
if: matrix.platform.opensslcapsname != ''
|
||||
run: echo "OPENSSL_${{ matrix.platform.opensslcapsname }}=\
|
||||
${{ matrix.platform.opensslcaps }}" >> $GITHUB_ENV
|
||||
|
||||
- name: get cpu info
|
||||
run: cat /proc/cpuinfo
|
||||
|
||||
- name: get openssl cpu info
|
||||
if: matrix.platform.tests != 'none'
|
||||
run: QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} ./util/opensslwrap.sh info -cpusettings
|
||||
|
||||
- name: check detected capabilities
|
||||
if: matrix.platform.capscheck != ''
|
||||
run: |
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }} \
|
||||
./util/opensslwrap.sh info -cpusettings | \
|
||||
grep -qE "${{ matrix.platform.capscheck }}"
|
||||
|
||||
- name: make all tests
|
||||
if: github.event_name == 'push' && matrix.platform.tests == ''
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="-test_afalg" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: make some tests
|
||||
if: github.event_name == 'push' && matrix.platform.tests != 'none' && matrix.platform.tests != ''
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="${{ matrix.platform.tests }} -test_afalg" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: make evp tests
|
||||
if: github.event_name == 'pull_request' && matrix.platform.tests != 'none'
|
||||
run: |
|
||||
.github/workflows/make-test \
|
||||
TESTS="test_evp*" \
|
||||
QEMU_LD_PREFIX=/usr/${{ matrix.platform.arch }}
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
with:
|
||||
name: "cross-compiles-riscv@${{ matrix.platform.opensslcaps }}"
|
||||
path: artifacts.tar.gz
|
||||
if-no-files-found: ignore
|
||||
32
.github/workflows/run-checker-ci.yml
vendored
32
.github/workflows/run-checker-ci.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -7,25 +7,7 @@
|
|||
|
||||
# Jobs run per pull request submission
|
||||
name: Run-checker CI
|
||||
on:
|
||||
pull_request:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
push:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
on: [pull_request, push]
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
|
|
@ -50,7 +32,7 @@ jobs:
|
|||
no-http,
|
||||
no-legacy,
|
||||
no-sock,
|
||||
no-sm2,
|
||||
no-ssl-trace,
|
||||
no-stdio,
|
||||
no-threads,
|
||||
no-thread-pool,
|
||||
|
|
@ -59,14 +41,12 @@ jobs:
|
|||
no-tls1_2,
|
||||
no-tls1_3,
|
||||
enable-trace enable-fips,
|
||||
no-quic,
|
||||
-DOPENSSL_USE_IPV6=0
|
||||
no-ui,
|
||||
no-quic
|
||||
]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
|
|||
144
.github/workflows/run-checker-daily.yml
vendored
144
.github/workflows/run-checker-daily.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -18,18 +18,18 @@ permissions:
|
|||
|
||||
jobs:
|
||||
run-checker:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
fail-fast: false
|
||||
matrix:
|
||||
opt: [
|
||||
386,
|
||||
no-afalgeng,
|
||||
no-apps,
|
||||
no-argon2,
|
||||
no-aria,
|
||||
no-asan,
|
||||
no-asm,
|
||||
no-async,
|
||||
no-atexit,
|
||||
no-autoalginit,
|
||||
no-autoerrinit,
|
||||
no-autoload-config,
|
||||
|
|
@ -39,23 +39,29 @@ jobs:
|
|||
no-bulk,
|
||||
no-cached-fetch,
|
||||
no-camellia,
|
||||
no-capieng,
|
||||
no-cast,
|
||||
no-chacha,
|
||||
no-cmac,
|
||||
no-comp,
|
||||
enable-crypto-mdebug,
|
||||
enable-crypto-mdebug-backtrace,
|
||||
no-ct,
|
||||
enable-demos,
|
||||
no-deprecated,
|
||||
no-des,
|
||||
# enable-devcryptoeng, # Cannot work on Linux
|
||||
no-docs,
|
||||
no-dsa,
|
||||
no-dtls1,
|
||||
no-dtls1_2,
|
||||
no-dtls1_2-method,
|
||||
no-dtls1-method,
|
||||
no-ecdh,
|
||||
no-ecdsa,
|
||||
enable-ec_nistp_64_gcc_128,
|
||||
enable-egd,
|
||||
no-engine,
|
||||
# enable-external-tests, # Requires extra setup
|
||||
enable-fips,
|
||||
enable-fips enable-acvp-tests,
|
||||
|
|
@ -65,14 +71,11 @@ jobs:
|
|||
# enable-fuzz-libfuzzer, # Requires extra setup
|
||||
no-gost,
|
||||
enable-h3demo,
|
||||
enable-heartbeats,
|
||||
enable-hqinterop,
|
||||
no-hmac-drbg-kdf,
|
||||
no-hw,
|
||||
no-hw-padlock,
|
||||
no-idea,
|
||||
no-ikev2kdf,
|
||||
no-kbkdf,
|
||||
no-krb5kdf,
|
||||
enable-lms,
|
||||
no-makedepend,
|
||||
enable-md2,
|
||||
no-md4,
|
||||
|
|
@ -81,11 +84,11 @@ jobs:
|
|||
no-multiblock,
|
||||
no-nextprotoneg,
|
||||
no-ocb,
|
||||
no-padlockeng,
|
||||
no-pic,
|
||||
no-poly1305,
|
||||
no-posix-io,
|
||||
no-psk,
|
||||
no-pvkkdf,
|
||||
no-rc2,
|
||||
enable-rc5,
|
||||
no-rdrand,
|
||||
|
|
@ -98,19 +101,17 @@ jobs:
|
|||
no-shared,
|
||||
no-siphash,
|
||||
no-siv,
|
||||
no-sm2,
|
||||
no-sm2-precomp,
|
||||
no-sm3,
|
||||
no-sm4,
|
||||
no-snmpkdf,
|
||||
no-sock,
|
||||
no-srtpkdf,
|
||||
no-sse2,
|
||||
no-sshkdf,
|
||||
no-sskdf,
|
||||
no-ssl,
|
||||
no-ssl-trace,
|
||||
enable-ssl3,
|
||||
enable-ssl3-method,
|
||||
enable-sslkeylog,
|
||||
no-shared,
|
||||
no-static-engine no-shared,
|
||||
no-tests,
|
||||
enable-tfo,
|
||||
no-tls1,
|
||||
|
|
@ -125,8 +126,6 @@ jobs:
|
|||
no-uplink,
|
||||
no-weak-ssl-ciphers,
|
||||
no-whirlpool,
|
||||
no-x942kdf,
|
||||
no-x963kdf,
|
||||
enable-zlib-dynamic,
|
||||
-DOPENSSL_PEDANTIC_ZEROIZATION,
|
||||
-DOPENSSL_PEDANTIC_ZEROIZATION enable-fips,
|
||||
|
|
@ -136,9 +135,7 @@ jobs:
|
|||
]
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -155,12 +152,9 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
run-checker-sctp:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Install Dependencies for sctp option
|
||||
|
|
@ -197,17 +191,14 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
enable_brotli_dynamic:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: install brotli
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install brotli libbrotli1 libbrotli-dev
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --force-yes install brotli libbrotli1 libbrotli-dev
|
||||
- name: checkout openssl
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -222,17 +213,14 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
enable_zstd_dynamic:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: install zstd
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install zstd libzstd1 libzstd-dev
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --force-yes install zstd libzstd1 libzstd-dev
|
||||
- name: checkout openssl
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -247,18 +235,15 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
enable_brotli_and_zstd_dynamic:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: install brotli and zstd
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install brotli libbrotli1 libbrotli-dev
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install zstd libzstd1 libzstd-dev
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --force-yes install brotli libbrotli1 libbrotli-dev
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --force-yes install zstd libzstd1 libzstd-dev
|
||||
- name: checkout openssl
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -272,43 +257,15 @@ jobs:
|
|||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
malloc_failure_testing:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: checkout openssl
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Adjust ASLR for sanitizer
|
||||
run: |
|
||||
sudo cat /proc/sys/vm/mmap_rnd_bits
|
||||
sudo sysctl -w vm.mmap_rnd_bits=28
|
||||
- name: config
|
||||
run: ./config --strict-warnings --banner=Configured --debug enable-asan enable-crypto-mdebug enable-allocfail-tests && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -s -j4
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
continue-on-error: true
|
||||
run: |
|
||||
make TESTS="test_memfail" test
|
||||
|
||||
enable_brotli_and_asan_ubsan:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: install brotli
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install brotli libbrotli1 libbrotli-dev
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --force-yes install brotli libbrotli1 libbrotli-dev
|
||||
- name: checkout openssl
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
@ -327,17 +284,14 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} OPENSSL_TEST_RAND_ORDER=0
|
||||
|
||||
enable_zstd_and_asan_ubsan:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: install zstd
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --allow-unauthenticated --allow-downgrades --allow-remove-essential --allow-change-held-packages install zstd libzstd1 libzstd-dev
|
||||
sudo apt-get -yq --no-install-suggests --no-install-recommends --force-yes install zstd libzstd1 libzstd-dev
|
||||
- name: checkout openssl
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
@ -356,15 +310,12 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} OPENSSL_TEST_RAND_ORDER=0
|
||||
|
||||
enable_tfo:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
strategy:
|
||||
matrix:
|
||||
os: [ubuntu-latest, macos-15, macos-15-intel]
|
||||
os: [ ubuntu-latest, macos-13, macos-14 ]
|
||||
runs-on: ${{matrix.os}}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -377,12 +328,9 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
enable_buildtest:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -397,12 +345,9 @@ jobs:
|
|||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4}
|
||||
|
||||
memory_sanitizer_slh_dsa:
|
||||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
@ -420,26 +365,3 @@ jobs:
|
|||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: make test HARNESS_JOBS=${HARNESS_JOBS:-4} OPENSSL_TEST_RAND_ORDER=0
|
||||
|
||||
bn_debug:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: config
|
||||
run: ./config --debug --strict-warnings -DBN_DEBUG --banner=Configured -DOPENSSL_NO_SECURE_MEMORY && perl configdata.pm --dump
|
||||
- name: make
|
||||
run: make -j4 # verbose, so no -s here
|
||||
- name: get cpu info
|
||||
run: |
|
||||
cat /proc/cpuinfo
|
||||
./util/opensslwrap.sh version -c
|
||||
- name: make test
|
||||
run: .github/workflows/make-test
|
||||
- name: save artifacts
|
||||
if: success() || failure()
|
||||
uses: actions/upload-artifact@v5
|
||||
with:
|
||||
name: "ci@bn_debug"
|
||||
path: artifacts.tar.gz
|
||||
|
|
|
|||
21
.github/workflows/run-checker-merge.yml
vendored
21
.github/workflows/run-checker-merge.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -20,8 +20,9 @@ jobs:
|
|||
opt: [
|
||||
enable-asan enable-ubsan no-shared no-asm -DOPENSSL_SMALL_FOOTPRINT -fno-sanitize=function,
|
||||
no-dso,
|
||||
no-dynamic-engine,
|
||||
no-ec2m enable-fips,
|
||||
no-shared,
|
||||
no-engine no-shared,
|
||||
no-err,
|
||||
no-filenames,
|
||||
enable-ubsan no-asm -DOPENSSL_SMALL_FOOTPRINT -fno-sanitize=function,
|
||||
|
|
@ -31,7 +32,6 @@ jobs:
|
|||
no-srp,
|
||||
no-srtp,
|
||||
no-ts,
|
||||
no-ui,
|
||||
no-integrity-only-ciphers,
|
||||
enable-weak-ssl-ciphers,
|
||||
enable-zlib,
|
||||
|
|
@ -43,9 +43,7 @@ jobs:
|
|||
run: |
|
||||
sudo cat /proc/sys/vm/mmap_rnd_bits
|
||||
sudo sysctl -w vm.mmap_rnd_bits=28
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: config
|
||||
|
|
@ -65,16 +63,13 @@ jobs:
|
|||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- name: checkout openssl
|
||||
uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
uses: actions/checkout@v4
|
||||
- name: checkout jitter
|
||||
uses: actions/checkout@v6
|
||||
uses: actions/checkout@v4
|
||||
with:
|
||||
repository: smuellerDD/jitterentropy-library
|
||||
ref: v3.5.0
|
||||
path: jitter
|
||||
persist-credentials: false
|
||||
- name: build jitter
|
||||
run: make -C jitter/
|
||||
- name: checkout fuzz/corpora submodule
|
||||
|
|
@ -93,9 +88,7 @@ jobs:
|
|||
threads_sanitizer_atomic_fallback:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: Adjust ASLR for sanitizer
|
||||
|
|
|
|||
208
.github/workflows/run_quic_interop.yml
vendored
208
.github/workflows/run_quic_interop.yml
vendored
|
|
@ -1,203 +1,71 @@
|
|||
name: "Run openssl quic interop testing"
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '40 02 * * *'
|
||||
workflow_run:
|
||||
workflows: ["Build openssl interop container from master"]
|
||||
types: [completed]
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
only_interop:
|
||||
type: boolean
|
||||
required: false
|
||||
default: false
|
||||
description: "Run only interop jobs (skip building/pushing containers)"
|
||||
|
||||
permissions: {}
|
||||
|
||||
jobs:
|
||||
update_quay_container:
|
||||
if: ${{ github.repository == 'openssl/openssl' && !inputs.only_interop }}
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: "log in to quay.io"
|
||||
run: |
|
||||
docker login -u openssl-ci+machine -p ${{ secrets.QUAY_IO_PASSWORD }} quay.io
|
||||
- name: "Build container"
|
||||
run: |
|
||||
cd test/quic-openssl-docker/
|
||||
docker build -t quay.io/openssl-ci/openssl-quic-interop:latest .
|
||||
- name: "Push to quay"
|
||||
run: |
|
||||
docker push quay.io/openssl-ci/openssl-quic-interop:latest
|
||||
|
||||
update_msquic_quay_container:
|
||||
if: ${{ github.repository == 'openssl/openssl' && !inputs.only_interop }}
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
repository: microsoft/msquic
|
||||
ref: main
|
||||
submodules: recursive
|
||||
persist-credentials: false
|
||||
- name: "log in to quay.io"
|
||||
run: |
|
||||
docker login -u openssl-ci+machine -p ${{ secrets.QUAY_IO_PASSWORD }} quay.io
|
||||
- name: Patch qns.Dockerfile
|
||||
run: |
|
||||
sed -i 's/RUN cmake -DQUIC_BUILD_TOOLS=on -DQUIC_ENABLE_LOGGING=on ../RUN cmake -DQUIC_BUILD_TOOLS=on -DQUIC_ENABLE_LOGGING=on -DQUIC_TLS_LIB=openssl ../' ./scripts/qns.Dockerfile
|
||||
if grep -q "RUN cmake -DQUIC_BUILD_TOOLS=on -DQUIC_ENABLE_LOGGING=on -DQUIC_TLS_LIB=openssl .." ./scripts/qns.Dockerfile; then echo "Patched successfully"; else exit 1; fi
|
||||
- name: "Build container"
|
||||
run: |
|
||||
docker build -f ./scripts/qns.Dockerfile -t quay.io/openssl-ci/msquic-openssl:latest .
|
||||
- name: "Push to quay"
|
||||
run: |
|
||||
docker push quay.io/openssl-ci/msquic-openssl:latest
|
||||
|
||||
run_quic_interop_openssl_client:
|
||||
if: ${{ !inputs.only_interop }}
|
||||
needs: [update_quay_container, update_msquic_quay_container]
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
tests: [http3, transfer, handshake, retry, chacha20, resumption, multiplexing, ipv6]
|
||||
servers: [quic-go, ngtcp2, mvfst, quiche, nginx, msquic, haproxy, msquic-openssl]
|
||||
servers: [quic-go, ngtcp2, mvfst, quiche, nginx, msquic, haproxy]
|
||||
exclude:
|
||||
- servers: msquic
|
||||
tests: retry
|
||||
- servers: msquic-openssl
|
||||
tests: retry
|
||||
fail-fast: false
|
||||
steps: &client_steps
|
||||
- uses: actions/checkout@v6
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
repository: 'quic-interop/quic-interop-runner'
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Install python requirements
|
||||
repository: 'quic-interop/quic-interop-runner'
|
||||
fetch-depth: 0
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
for i in {1..3}; do pip install -r requirements.txt && break; sleep 10; done
|
||||
- name: Add tshark repo
|
||||
run: |
|
||||
for i in {1..3}; do sudo add-apt-repository ppa:wireshark-dev/stable && break; sleep 10; done
|
||||
- name: Update apt repos
|
||||
run: |
|
||||
for i in {1..3}; do sudo apt-get update && break; sleep 10; done
|
||||
- name: Install tshark
|
||||
run: |
|
||||
for i in {1..3}; do sudo apt-get install -y tshark && break; sleep 10; done
|
||||
pip install -r requirements.txt
|
||||
sudo add-apt-repository ppa:wireshark-dev/stable
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y tshark
|
||||
- name: Patch implementations file
|
||||
run: |
|
||||
jq '. + {
|
||||
"openssl": { image: "quay.io/openssl-ci/openssl-quic-interop"
|
||||
, url: "https://github.com/openssl/openssl"
|
||||
, role: "both"
|
||||
},
|
||||
"msquic-openssl": { image: "quay.io/openssl-ci/msquic-openssl"
|
||||
, url: "https://github.com/microsoft/msquic"
|
||||
, role: "both"
|
||||
}}' ./implementations_quic.json > ./implementations.tmp
|
||||
mv ./implementations.tmp implementations_quic.json
|
||||
- name: Set up docker
|
||||
uses: docker/setup-docker-action@efe9e3891a4f7307e689f2100b33a155b900a608 # v4.5.0
|
||||
with:
|
||||
version: "28.1.1"
|
||||
- name: Set up docker compose
|
||||
uses: docker/setup-compose-action@364cc21a5de5b1ee4a7f5f9d3fa374ce0ccde746 # v1.2.0
|
||||
with:
|
||||
version: "v2.36.2"
|
||||
- name: Check docker version
|
||||
run: |
|
||||
docker version
|
||||
docker compose version
|
||||
- name: "Run interop with openssl client"
|
||||
jq '.openssl = { image: "quay.io/openssl-ci/openssl-quic-interop"
|
||||
, url: "https://github.com/openssl/openssl"
|
||||
, role: "both"
|
||||
}' ./implementations.json > ./implementations.tmp
|
||||
mv ./implementations.tmp implementations.json
|
||||
- name: "run interop with openssl client"
|
||||
run: |
|
||||
python3 ./run.py -c openssl -t ${{ matrix.tests }} -s ${{ matrix.servers }} --log-dir ./logs-client -d
|
||||
|
||||
run_quic_interop_openssl_server:
|
||||
if: ${{ !inputs.only_interop }}
|
||||
needs: [update_quay_container, update_msquic_quay_container]
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
tests: [http3, transfer, handshake, retry, chacha20, resumption, amplificationlimit, ipv6]
|
||||
clients: [quic-go, ngtcp2, mvfst, quiche, msquic, openssl, chrome, msquic-openssl]
|
||||
clients: [quic-go, ngtcp2, mvfst, quiche, msquic, openssl, chrome]
|
||||
exclude:
|
||||
- clients: mvfst
|
||||
tests: amplificationlimit
|
||||
fail-fast: false
|
||||
steps: &server_steps
|
||||
- uses: actions/checkout@v6
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
repository: 'quic-interop/quic-interop-runner'
|
||||
fetch-depth: 0
|
||||
persist-credentials: false
|
||||
- name: Install python requirements
|
||||
repository: 'quic-interop/quic-interop-runner'
|
||||
fetch-depth: 0
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
for i in {1..3}; do pip install -r requirements.txt && break; done
|
||||
- name: Add tshark repo
|
||||
run: |
|
||||
for i in {1..3}; do sudo add-apt-repository ppa:wireshark-dev/stable && break; done
|
||||
- name: Update apt repos
|
||||
run: |
|
||||
for i in {1..3}; do sudo apt-get update && break; done
|
||||
- name: Install tshark
|
||||
run: |
|
||||
for i in {1..3}; do sudo apt-get install -y tshark && break; done
|
||||
pip install -r requirements.txt
|
||||
sudo add-apt-repository ppa:wireshark-dev/stable
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y tshark
|
||||
- name: Patch implementations file
|
||||
run: |
|
||||
jq '. + {
|
||||
"openssl": { image: "quay.io/openssl-ci/openssl-quic-interop"
|
||||
, url: "https://github.com/openssl/openssl"
|
||||
, role: "both"
|
||||
},
|
||||
"msquic-openssl": { image: "quay.io/openssl-ci/msquic-openssl"
|
||||
, url: "https://github.com/microsoft/msquic"
|
||||
, role: "both"
|
||||
}}' ./implementations_quic.json > ./implementations.tmp
|
||||
mv ./implementations.tmp implementations_quic.json
|
||||
- name: Set up docker
|
||||
uses: docker/setup-docker-action@efe9e3891a4f7307e689f2100b33a155b900a608 # v4.5.0
|
||||
with:
|
||||
version: "28.1.1"
|
||||
- name: Set up docker compose
|
||||
uses: docker/setup-compose-action@364cc21a5de5b1ee4a7f5f9d3fa374ce0ccde746 # v1.2.0
|
||||
with:
|
||||
version: "v2.36.2"
|
||||
- name: Check docker version
|
||||
jq '.openssl = { image: "quay.io/openssl-ci/openssl-quic-interop"
|
||||
, url: "https://github.com/openssl/openssl"
|
||||
, role: "both"
|
||||
}' ./implementations.json > ./implementations.tmp
|
||||
mv ./implementations.tmp implementations.json
|
||||
- name: "run interop with openssl server"
|
||||
run: |
|
||||
docker version
|
||||
docker compose version
|
||||
- name: "Run interop with openssl server"
|
||||
run: |
|
||||
python3 ./run.py -s openssl -t "${{ matrix.tests }}" -c "${{ matrix.clients }}" --log-dir ./logs-server -d
|
||||
|
||||
run_quic_interop_openssl_client_only:
|
||||
if: ${{ inputs.only_interop }}
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
tests: [http3, transfer, handshake, retry, chacha20, resumption, multiplexing, ipv6]
|
||||
servers: [quic-go, ngtcp2, mvfst, quiche, nginx, msquic, haproxy, msquic-openssl]
|
||||
exclude:
|
||||
- servers: msquic
|
||||
tests: retry
|
||||
- servers: msquic-openssl
|
||||
tests: retry
|
||||
fail-fast: false
|
||||
steps: *client_steps
|
||||
|
||||
run_quic_interop_openssl_server_only:
|
||||
if: ${{ inputs.only_interop }}
|
||||
runs-on: ubuntu-latest
|
||||
strategy:
|
||||
matrix:
|
||||
tests: [http3, transfer, handshake, retry, chacha20, resumption, amplificationlimit, ipv6]
|
||||
clients: [quic-go, ngtcp2, mvfst, quiche, msquic, openssl, chrome, msquic-openssl]
|
||||
exclude:
|
||||
- clients: mvfst
|
||||
tests: amplificationlimit
|
||||
fail-fast: false
|
||||
steps: *server_steps
|
||||
python3 ./run.py -s openssl -t ${{ matrix.tests }} -c ${{ matrix.clients }} --log-dir ./logs-server -d
|
||||
|
|
|
|||
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -27,11 +27,9 @@ jobs:
|
|||
run: |
|
||||
echo ${{ secrets.COVERITY_AUTH_KEY }} | base64 -d > /auth_key_file.txt
|
||||
chmod 0600 /auth_key_file.txt
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: Config
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-fips enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC
|
||||
- name: Config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: Make
|
||||
|
|
|
|||
8
.github/workflows/static-analysis.yml
vendored
8
.github/workflows/static-analysis.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2023 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -21,16 +21,14 @@ jobs:
|
|||
if: github.repository == 'openssl/openssl'
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: tool download
|
||||
run: |
|
||||
wget https://scan.coverity.com/download/linux64 \
|
||||
--post-data "token=${{ secrets.COVERITY_TOKEN }}&project=openssl%2Fopenssl" \
|
||||
--progress=dot:giga -O coverity_tool.tgz
|
||||
- name: config
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-lms enable-fips enable-rc5 enable-md2 enable-nextprotoneg enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC
|
||||
run: CC=gcc ./config --strict-warnings --banner=Configured --debug enable-fips enable-rc5 enable-md2 enable-ssl3 enable-nextprotoneg enable-ssl3-method enable-weak-ssl-ciphers enable-zlib enable-ec_nistp_64_gcc_128 no-shared enable-buildtest-c++ enable-external-tests -DPEDANTIC
|
||||
- name: config dump
|
||||
run: ./configdata.pm --dump
|
||||
- name: tool install
|
||||
|
|
|
|||
65
.github/workflows/style-checks.yml
vendored
65
.github/workflows/style-checks.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -7,33 +7,46 @@
|
|||
|
||||
name: Coding style validation
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
on: [pull_request]
|
||||
|
||||
env:
|
||||
PR_NUMBER: ${{ github.event.number }}
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
check-style:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
- uses: actions/setup-python@v6
|
||||
- name: "Get changed files"
|
||||
env:
|
||||
NUMBER: ${{ github.event.pull_request.number }}
|
||||
GH_TOKEN: ${{ github.token }}
|
||||
run: |
|
||||
{
|
||||
echo 'CHANGED_FILES<<EOF'
|
||||
gh pr view $NUMBER --json files --jq '.files.[].path'
|
||||
echo EOF
|
||||
} >> "$GITHUB_ENV"
|
||||
- uses: pre-commit/action@2c7b3805fd2a0fd8c1884dcaebf91fc102a13ecd #v3.0.1
|
||||
with:
|
||||
extra_args: "--files $CHANGED_FILES"
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
path: openssl
|
||||
- name: check style for each commit
|
||||
working-directory: openssl
|
||||
shell: bash
|
||||
run: |
|
||||
ERRORS_FOUND=0
|
||||
git fetch origin $GITHUB_BASE_REF:$GITHUB_BASE_REF
|
||||
REFSTART=$(git rev-parse $GITHUB_BASE_REF)
|
||||
REFEND=$(git rev-parse HEAD)
|
||||
echo "Checking from $REFSTART to $REFEND"
|
||||
echo "::group::Style report for commits $REFSTART..$REFEND"
|
||||
set +e
|
||||
./util/check-format-commit.sh $REFSTART..$REFEND
|
||||
if [ $? -ne 0 ]
|
||||
then
|
||||
ERRORS_FOUND=1
|
||||
fi
|
||||
set -e
|
||||
echo "::endgroup::"
|
||||
SKIP_TEST=$(gh pr view $PR_NUMBER --json labels --jq '.labels[] | select(.name == "style: waived") | .name')
|
||||
if [ -z "$SKIP_TEST" ]
|
||||
then
|
||||
exit $ERRORS_FOUND
|
||||
else
|
||||
echo "PR $PR_NUMBER is marked with style: waived, waiving style check errors"
|
||||
exit 0
|
||||
fi
|
||||
|
|
|
|||
66
.github/workflows/valgrind-daily.yml
vendored
66
.github/workflows/valgrind-daily.yml
vendored
|
|
@ -1,66 +0,0 @@
|
|||
# Copyright 2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
# in the file LICENSE in the source distribution or at
|
||||
# https://www.openssl.org/source/license.html
|
||||
|
||||
name: Test valgrind suppression file
|
||||
# Jobs run daily
|
||||
|
||||
on:
|
||||
schedule:
|
||||
- cron: '30 02 * * *'
|
||||
workflow_dispatch:
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
||||
jobs:
|
||||
check-valgrind-suppressions:
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: Install valgrind
|
||||
run: |
|
||||
sudo apt-get -y update
|
||||
sudo apt-get -y install valgrind
|
||||
- name: Get parse suppressions script
|
||||
run: |
|
||||
wget https://raw.githubusercontent.com/coqui-ai/STT/refs/tags/v1.4.0/parse_valgrind_suppressions.sh
|
||||
echo "7414fcb9405f8bd1632442a0b66ffb35457994c6b8b49b2aa91530cf9a7ff645 ./parse_valgrind_suppressions.sh" > ./valgrind_suppressions.sha256
|
||||
sha256sum -c ./valgrind_suppressions.sha256
|
||||
chmod 755 ./parse_valgrind_suppressions.sh
|
||||
- name: Configure
|
||||
run: |
|
||||
./Configure -DOPENSSL_VALGRIND_TEST
|
||||
./configdata.pm --dump
|
||||
- name: Make
|
||||
run: |
|
||||
make -j
|
||||
- name: Make test
|
||||
run: |
|
||||
# The quic radix and multistream test times out under valgrind in ci
|
||||
make TESTS="-test_quic_radix -test_quic_multistream" OSSL_USE_VALGRIND=yes test
|
||||
- name: Check for leaks
|
||||
run: |
|
||||
set +e
|
||||
NUM_LOGS=$(find . -name 'valgrind.log.*' | wc -l)
|
||||
echo "Found $NUM_LOGS valgrind logs"
|
||||
if [ $NUM_LOGS == 0 ]; then
|
||||
echo "No logs found!"
|
||||
exit 1
|
||||
fi
|
||||
for i in $(find . -name 'valgrind.log.*'); do
|
||||
./parse_valgrind_suppressions.sh $i >> ./new_suppressions.txt
|
||||
done
|
||||
NEW_SUPPRESSION_LINES=$(cat ./new_suppressions.txt | wc -l)
|
||||
if [ $NEW_SUPPRESSION_LINES != 0 ]; then
|
||||
echo "New Suppressions Found that need to be addressed!"
|
||||
cat ./new_suppressions.txt
|
||||
exit 1
|
||||
fi
|
||||
echo "No new suppressions found"
|
||||
exit 0
|
||||
364
.github/workflows/windows.yml
vendored
364
.github/workflows/windows.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2021-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2021-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -7,26 +7,7 @@
|
|||
|
||||
name: Windows GitHub CI
|
||||
|
||||
on:
|
||||
pull_request:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
push:
|
||||
paths-ignore:
|
||||
- 'doc/**'
|
||||
- '*.md'
|
||||
- '*.pod'
|
||||
- 'README*'
|
||||
- 'funding.json'
|
||||
- 'LICENSE.txt'
|
||||
- 'VERSION.dat'
|
||||
|
||||
on: [pull_request, push]
|
||||
|
||||
permissions:
|
||||
contents: read
|
||||
|
|
@ -37,77 +18,42 @@ jobs:
|
|||
strategy:
|
||||
matrix:
|
||||
platform:
|
||||
- arch: amd64
|
||||
- arch: win64
|
||||
os: windows-2019
|
||||
config: enable-fips
|
||||
- arch: win64
|
||||
os: windows-2022
|
||||
config: enable-lms enable-fips
|
||||
vcvars: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat
|
||||
- arch: amd64
|
||||
os: windows-2025
|
||||
config: enable-lms enable-fips no-thread-pool no-quic
|
||||
vcvars: C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat
|
||||
- arch: x86
|
||||
config: enable-fips no-thread-pool no-quic
|
||||
- arch: win32
|
||||
os: windows-2022
|
||||
config: no-fips enable-lms
|
||||
vcvars: C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars32.bat
|
||||
config: --strict-warnings no-fips
|
||||
runs-on: ${{ matrix.platform.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- uses: ilammy/msvc-dev-cmd@v1
|
||||
with:
|
||||
arch: ${{ matrix.platform.arch }}
|
||||
- name: install nasm
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-${{ matrix.platform.arch == 'x86' && 'x86' || 'x64' }}.exe"
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer
|
||||
$actual = (Get-FileHash $installer -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" }
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
"C:\Program Files${{ matrix.platform.arch == 'x86' && ' (x86)' || '' }}\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install nasm (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-${{ matrix.platform.arch == 'x86' && 'x86' || 'x64' }}.exe"
|
||||
Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win${{ matrix.platform.arch == 'x86' && '32' || '64' }}/$installer" -OutFile $installer
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
"C:\Program Files${{ matrix.platform.arch == 'x86' && ' (x86)' || '' }}\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe'
|
||||
$actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" }
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip
|
||||
Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
choco install nasm ${{ matrix.platform.arch == 'win32' && '--x86' || '' }}
|
||||
"C:\Program Files${{ matrix.platform.arch == 'win32' && ' (x86)' || '' }}\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: prepare the build directory
|
||||
run: mkdir _build
|
||||
- name: config
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "${{ matrix.platform.vcvars }}"
|
||||
perl ..\Configure --banner=Configured --strict-warnings no-makedepend -DOSSL_WINCTX=openssl ${{ matrix.platform.config }}
|
||||
perl ..\Configure --banner=Configured no-makedepend -DOSSL_WINCTX=openssl ${{ matrix.platform.config }}
|
||||
perl configdata.pm --dump
|
||||
- name: build
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "${{ matrix.platform.vcvars }}"
|
||||
jom /j4 /S
|
||||
run: nmake /S
|
||||
- name: download coreinfo
|
||||
run: |
|
||||
mkdir _build\coreinfo
|
||||
Invoke-WebRequest -Uri "https://download.sysinternals.com/files/Coreinfo.zip" -outfile "_build\coreinfo\Coreinfo.zip"
|
||||
uses: suisei-cn/actions-download-file@v1.6.0
|
||||
with:
|
||||
url: "https://download.sysinternals.com/files/Coreinfo.zip"
|
||||
target: _build/coreinfo/
|
||||
- name: Gather openssl version info
|
||||
working-directory: _build
|
||||
run: |
|
||||
|
|
@ -115,12 +61,12 @@ jobs:
|
|||
apps/openssl.exe version -v | %{($_ -split '\s+')[1]}
|
||||
apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+\.[0-9]+)(\..*)','$1'}
|
||||
echo "OSSL_VERSION=$(apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+\.[0-9]+)(\..*)','$1'})" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append
|
||||
echo "OSSL_MAJOR=$(apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+)\.[0-9]+(\..*)','$1'})" | Out-File -FilePath $Env:GITHUB_ENV -Encoding utf8 -Append
|
||||
- name: Set registry keys
|
||||
working-directory: _build
|
||||
run: |
|
||||
echo ${Env:OSSL_VERSION}
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v OPENSSLDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v ENGINESDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v MODULESDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe query HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v OPENSSLDIR /reg:32
|
||||
- name: get cpu info
|
||||
|
|
@ -132,69 +78,44 @@ jobs:
|
|||
./apps/openssl.exe version -c
|
||||
- name: Check platform symbol usage
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "${{ matrix.platform.vcvars }}"
|
||||
perl ../util/checkplatformsyms.pl ../util/platform_symbols/windows-symbols.txt libcrypto-%OSSL_MAJOR%${{ matrix.platform.arch == 'amd64' && '-x64' || '' }}.dll ./libssl-%OSSL_MAJOR%${{ matrix.platform.arch == 'amd64' && '-x64' || '' }}.dll
|
||||
run: perl ../util/checkplatformsyms.pl ../util/platform_symbols/windows-symbols.txt libcrypto-3-x64.dll ./libssl-3-x64.dll
|
||||
- name: test
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "${{ matrix.platform.vcvars }}"
|
||||
jom test VERBOSE_FAILURE=yes TESTS=-test_fuzz* HARNESS_JOBS=4
|
||||
run: nmake test VERBOSE_FAILURE=yes TESTS=-test_fuzz* HARNESS_JOBS=4
|
||||
- name: install
|
||||
# Run on 64 bit only as 32 bit is slow enough already
|
||||
if: ${{ matrix.platform.arch == 'amd64' }}
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
if: ${{ matrix.platform.arch == 'win64' }}
|
||||
run: |
|
||||
call "${{ matrix.platform.vcvars }}"
|
||||
mkdir _dest
|
||||
jom /j4 install DESTDIR=_dest
|
||||
|
||||
nmake install DESTDIR=_dest
|
||||
working-directory: _build
|
||||
plain:
|
||||
runs-on: windows-2022
|
||||
strategy:
|
||||
matrix:
|
||||
os:
|
||||
# Reducing CI footprint - windows-2019
|
||||
- windows-2022
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- uses: ilammy/msvc-dev-cmd@v1
|
||||
- name: prepare the build directory
|
||||
run: mkdir _build
|
||||
- name: install jom
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe'
|
||||
$actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" }
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip
|
||||
Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: config
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
perl ..\Configure --banner=Configured --strict-warnings enable-demos no-makedepend no-shared no-fips enable-md2 enable-rc5 enable-weak-ssl-ciphers enable-trace enable-crypto-mdebug -DOSSL_WINCTX=openssl VC-WIN64A-masm
|
||||
perl ..\Configure --banner=Configured enable-demos no-makedepend no-shared no-fips enable-md2 enable-rc5 enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-trace enable-crypto-mdebug -DOSSL_WINCTX=openssl VC-WIN64A-masm
|
||||
perl configdata.pm --dump
|
||||
- name: build
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom /j4 /S
|
||||
run: nmake /S
|
||||
- name: download coreinfo
|
||||
run: |
|
||||
mkdir _build\coreinfo
|
||||
Invoke-WebRequest -Uri "https://download.sysinternals.com/files/Coreinfo.zip" -outfile "_build\coreinfo\Coreinfo.zip"
|
||||
uses: suisei-cn/actions-download-file@v1.6.0
|
||||
with:
|
||||
url: "https://download.sysinternals.com/files/Coreinfo.zip"
|
||||
target: _build/coreinfo/
|
||||
- name: get cpu info
|
||||
working-directory: _build
|
||||
continue-on-error: true
|
||||
|
|
@ -204,107 +125,34 @@ jobs:
|
|||
./apps/openssl.exe version -c
|
||||
- name: test
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
nmake test VERBOSE_FAILURE=yes HARNESS_JOBS=4
|
||||
|
||||
unit-tests:
|
||||
runs-on: windows-2022
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- name: install jom
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe'
|
||||
$actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" }
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip
|
||||
Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install cmocka and detours via vcpkg
|
||||
shell: pwsh
|
||||
run: |
|
||||
& "$env:VCPKG_INSTALLATION_ROOT\vcpkg.exe" install cmocka:x64-windows-static-md detours:x64-windows-static-md
|
||||
"VCPKG_INST=$env:VCPKG_INSTALLATION_ROOT\installed\x64-windows-static-md" | Out-File -FilePath $env:GITHUB_ENV -Append
|
||||
- name: prepare the build directory
|
||||
run: mkdir _build
|
||||
- name: config
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
perl ..\Configure VC-WIN64A --banner=Configured --strict-warnings no-makedepend no-asm enable-unit-tests ^
|
||||
--with-cmocka-include=%VCPKG_INST%\include --with-cmocka-lib=%VCPKG_INST%\lib ^
|
||||
--with-detours-include=%VCPKG_INST%\include --with-detours-lib=%VCPKG_INST%\lib
|
||||
perl configdata.pm --dump
|
||||
- name: build
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom /j4 /S
|
||||
- name: test
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom test VERBOSE=1 TESTS=test_unit
|
||||
|
||||
run: nmake test VERBOSE_FAILURE=yes HARNESS_JOBS=4
|
||||
minimal:
|
||||
runs-on: windows-2022
|
||||
strategy:
|
||||
matrix:
|
||||
os:
|
||||
- windows-2019
|
||||
# Reducing CI footprint - windows-2022
|
||||
runs-on: ${{ matrix.os }}
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- uses: ilammy/msvc-dev-cmd@v1
|
||||
- name: prepare the build directory
|
||||
run: mkdir _build
|
||||
- name: install jom
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe'
|
||||
$actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" }
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip
|
||||
Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: config
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
perl ..\Configure --banner=Configured --strict-warnings enable-demos no-makedepend no-bulk no-deprecated no-fips no-asm no-threads -DOPENSSL_SMALL_FOOTPRINT -DOSSL_WINCTX=openssl
|
||||
perl ..\Configure --banner=Configured enable-demos no-makedepend no-bulk no-deprecated no-fips no-asm no-threads -DOPENSSL_SMALL_FOOTPRINT -DOSSL_WINCTX=openssl
|
||||
perl configdata.pm --dump
|
||||
- name: build
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom /j4 /S
|
||||
run: nmake # verbose, so no /S here
|
||||
- name: download coreinfo
|
||||
run: |
|
||||
mkdir _build\coreinfo
|
||||
Invoke-WebRequest -Uri "https://download.sysinternals.com/files/Coreinfo.zip" -outfile "_build\coreinfo\Coreinfo.zip"
|
||||
uses: suisei-cn/actions-download-file@v1.6.0
|
||||
with:
|
||||
url: "https://download.sysinternals.com/files/Coreinfo.zip"
|
||||
target: _build/coreinfo/
|
||||
- name: get cpu info
|
||||
working-directory: _build
|
||||
continue-on-error: true
|
||||
|
|
@ -314,17 +162,15 @@ jobs:
|
|||
./apps/openssl.exe version -c
|
||||
- name: test
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\2022\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom test VERBOSE_FAILURE=yes TESTS=-test_fuzz* HARNESS_JOBS=4
|
||||
|
||||
run: nmake test VERBOSE_FAILURE=yes TESTS=-test_fuzz* HARNESS_JOBS=4
|
||||
cygwin:
|
||||
# Run a job for each of the specified target architectures:
|
||||
strategy:
|
||||
matrix:
|
||||
os:
|
||||
- windows-2022
|
||||
- windows-2019
|
||||
# really worth while running, too? cygwin should mask this
|
||||
# - windows-2022
|
||||
platform:
|
||||
- arch: win64
|
||||
config: -DCMAKE_C_COMPILER=gcc --strict-warnings enable-demos no-fips
|
||||
|
|
@ -339,10 +185,8 @@ jobs:
|
|||
MAKE_PARAMS: -j 4
|
||||
steps:
|
||||
# Checkout before cygwin can mess with PATH...
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: cygwin/cygwin-install-action@f2009323764960f80959895c7bc3bb30210afe4d #v6
|
||||
- uses: actions/checkout@v4
|
||||
- uses: cygwin/cygwin-install-action@master
|
||||
with:
|
||||
packages: perl git make gcc-core
|
||||
- name: Check repo
|
||||
|
|
@ -353,89 +197,7 @@ jobs:
|
|||
# - name: Clone repo
|
||||
# run: bash -c "pwd && git clone --branch ${{ github.ref_name }} --depth 1 https://github.com/${{ github.repository }}.git"
|
||||
- name: Full build
|
||||
shell: bash
|
||||
run: |
|
||||
gcc --version
|
||||
./config ${{ matrix.platform.config }}
|
||||
make $MAKE_PARAMS
|
||||
run: bash -c "gcc --version && ./config ${{ matrix.platform.config }} && make $MAKE_PARAMS"
|
||||
# Disable testing for now. TBD: Need local cygwin installation to debug .
|
||||
# - name: Run openssl tests
|
||||
# run: bash -c "cd openssl && make V=1 test"
|
||||
|
||||
mingw64:
|
||||
strategy:
|
||||
matrix:
|
||||
platform:
|
||||
- arch: mingw64
|
||||
target: x86_64
|
||||
# Avoid MINGW bug in headers. Remove when CI is upgraded.
|
||||
config: enable-demos -Wno-array-bounds
|
||||
- arch: mingw
|
||||
target: i686
|
||||
config: -Wno-array-bounds -Wno-stringop-overflow
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
CC: ${{ matrix.platform.target }}-w64-mingw32-gcc
|
||||
CXX: ${{ matrix.platform.target }}-w64-mingw32-g++
|
||||
AR: ${{ matrix.platform.target }}-w64-mingw32-ar
|
||||
RANLIB: ${{ matrix.platform.target }}-w64-mingw32-ranlib
|
||||
RC: ${{ matrix.platform.target }}-w64-mingw32-windres
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: install MINGW64
|
||||
run: sudo apt-get install -y mingw-w64
|
||||
- name: config
|
||||
run: ./config ${{ matrix.platform.arch }} --strict-warnings --banner=Configured ${{ matrix.platform.config }}
|
||||
- name: make
|
||||
run: make -j4 -s
|
||||
|
||||
msys2-mingw64:
|
||||
strategy:
|
||||
matrix:
|
||||
platform:
|
||||
- arch: UCRT64
|
||||
cc: gcc
|
||||
pkgs: mingw-w64-ucrt-x86_64-gcc
|
||||
config: mingw64 enable-demos
|
||||
- arch: CLANG64
|
||||
cc: clang
|
||||
pkgs: mingw-w64-clang-x86_64-clang
|
||||
config: mingw64
|
||||
runs-on: windows-latest
|
||||
env:
|
||||
CC: ${{ matrix.platform.cc }}
|
||||
MSYSTEM: ${{ matrix.platform.arch }}
|
||||
CHERE_INVOKING: 'yes'
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- name: install MSYS2
|
||||
run: |
|
||||
$url = 'https://github.com/msys2/msys2-installer/releases/download/nightly-x86_64/msys2-base-x86_64-latest.sfx.exe'
|
||||
(New-Object System.Net.WebClient).DownloadFile($url, 'msys2.exe')
|
||||
# Remove preinstalled MSYS2
|
||||
if (Test-Path C:\msys64) { Remove-Item -Recurse -Force C:\msys64 }
|
||||
.\msys2.exe -y -oC:\
|
||||
Remove-Item msys2.exe
|
||||
|
||||
- name: update MSYS2
|
||||
run: |
|
||||
C:\msys64\usr\bin\bash.exe -lc ' '
|
||||
# Update core and then normal update
|
||||
C:\msys64\usr\bin\bash.exe -lc 'pacman --noconfirm -Syuu'
|
||||
C:\msys64\usr\bin\bash.exe -lc 'pacman --noconfirm -Syuu'
|
||||
|
||||
- name: install dependencies
|
||||
run: C:\msys64\usr\bin\bash.exe -lc 'pacman --noconfirm -S --needed perl git make ${{ matrix.platform.pkgs }}'
|
||||
|
||||
- name: config
|
||||
run: C:\msys64\usr\bin\bash.exe -lc './config --strict-warnings --banner=Configured ${{ matrix.platform.config }}'
|
||||
|
||||
- name: make
|
||||
run: C:\msys64\usr\bin\bash.exe -lc 'make -j4 -s'
|
||||
# Tests are broken for now
|
||||
# - name: test
|
||||
# run: C:\msys64\usr\bin\bash.exe -lc 'make test'
|
||||
|
|
|
|||
130
.github/workflows/windows_comp.yml
vendored
130
.github/workflows/windows_comp.yml
vendored
|
|
@ -1,4 +1,4 @@
|
|||
# Copyright 2022-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2022-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -23,66 +23,32 @@ jobs:
|
|||
zstd:
|
||||
runs-on: windows-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- uses: ilammy/msvc-dev-cmd@v1
|
||||
- name: install nasm
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-x64.exe"
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer
|
||||
$actual = (Get-FileHash $installer -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" }
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
choco install nasm
|
||||
"C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install nasm (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-x64.exe"
|
||||
Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win64/$installer" -OutFile $installer
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
"C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe'
|
||||
$actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" }
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip
|
||||
Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: prepare the build directory
|
||||
run: mkdir _build
|
||||
- name: Get zstd
|
||||
working-directory: _build
|
||||
run: |
|
||||
vcpkg install zstd:x64-windows
|
||||
"C:\vcpkg\packages\zstd_x64-windows\bin" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: config
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
perl ..\Configure --strict-warnings enable-comp enable-zstd --with-zstd-include=C:\vcpkg\packages\zstd_x64-windows\include --with-zstd-lib=C:\vcpkg\packages\zstd_x64-windows\lib\zstd.lib no-makedepend -DOSSL_WINCTX=openssl VC-WIN64A
|
||||
perl ..\Configure enable-comp enable-zstd --with-zstd-include=C:\vcpkg\packages\zstd_x64-windows\include --with-zstd-lib=C:\vcpkg\packages\zstd_x64-windows\lib\zstd.lib no-makedepend -DOSSL_WINCTX=openssl VC-WIN64A
|
||||
perl configdata.pm --dump
|
||||
- name: build
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom /j4 /S
|
||||
run: nmake
|
||||
- name: Gather openssl version info
|
||||
working-directory: _build
|
||||
run: |
|
||||
$env:Path+=";C:\vcpkg\packages\zstd_x64-windows\bin"
|
||||
apps/openssl.exe version -v
|
||||
apps/openssl.exe version -v | %{($_ -split '\s+')[1]}
|
||||
apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+\.[0-9]+)(\..*)','$1'}
|
||||
|
|
@ -92,89 +58,59 @@ jobs:
|
|||
run: |
|
||||
echo ${Env:OSSL_VERSION}
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v OPENSSLDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v ENGINESDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v MODULESDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe query HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v OPENSSLDIR /reg:32
|
||||
- name: download coreinfo
|
||||
run: |
|
||||
mkdir _build\coreinfo
|
||||
Invoke-WebRequest -Uri "https://download.sysinternals.com/files/Coreinfo.zip" -outfile "_build\coreinfo\Coreinfo.zip"
|
||||
uses: suisei-cn/actions-download-file@v1.6.0
|
||||
with:
|
||||
url: "https://download.sysinternals.com/files/Coreinfo.zip"
|
||||
target: _build/coreinfo/
|
||||
- name: get cpu info
|
||||
working-directory: _build
|
||||
continue-on-error: true
|
||||
run: |
|
||||
$env:Path+=";C:\vcpkg\packages\zstd_x64-windows\bin"
|
||||
7z.exe x coreinfo/Coreinfo.zip
|
||||
./Coreinfo64.exe -accepteula -f
|
||||
./apps/openssl.exe version -c
|
||||
- name: Check platform symbol usage
|
||||
run: |
|
||||
perl ./util/checkplatformsyms.pl ./util/platform_symbols/windows-symbols.txt libcrypto-3-x64.dll ./libssl-3-x64.dll
|
||||
- name: test
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom test VERBOSE_FAILURE=yes TESTS="-test_fuzz* -test_fipsload" HARNESS_JOBS=4
|
||||
|
||||
$env:Path+=";C:\vcpkg\packages\zstd_x64-windows\bin"
|
||||
nmake test VERBOSE_FAILURE=yes TESTS="-test_fuzz* -test_fipsload" HARNESS_JOBS=4
|
||||
brotli:
|
||||
runs-on: windows-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v6
|
||||
with:
|
||||
persist-credentials: false
|
||||
- uses: actions/checkout@v4
|
||||
- name: checkout fuzz/corpora submodule
|
||||
run: git submodule update --init --depth 1 fuzz/corpora
|
||||
- uses: ilammy/msvc-dev-cmd@v1
|
||||
- name: install nasm
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-x64.exe"
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/$installer" -OutFile $installer
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).$installer
|
||||
$actual = (Get-FileHash $installer -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for $installer (expected $expected, got $actual)" }
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
choco install nasm
|
||||
"C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install nasm (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
$installer = "nasm-3.01-installer-x64.exe"
|
||||
Invoke-WebRequest -Uri "https://www.nasm.us/pub/nasm/releasebuilds/3.01/win64/$installer" -OutFile $installer
|
||||
Start-Process -FilePath ".\$installer" -ArgumentList '/S' -Wait
|
||||
"C:\Program Files\NASM" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom
|
||||
if: github.repository == 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://openssl-library.org/ci-deps/jom-1.1.7.exe" -OutFile C:\jom\jom.exe
|
||||
$expected = (Get-Content "$env:GITHUB_WORKSPACE\.github\ci-deps.json" -Raw | ConvertFrom-Json).'jom-1.1.7.exe'
|
||||
$actual = (Get-FileHash C:\jom\jom.exe -Algorithm SHA256).Hash
|
||||
if ($actual -ne $expected) { throw "SHA256 mismatch for jom.exe (expected $expected, got $actual)" }
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: install jom (forks)
|
||||
if: github.repository != 'openssl/openssl'
|
||||
run: |
|
||||
mkdir C:\jom
|
||||
Invoke-WebRequest -Uri "https://download.qt.io/official_releases/jom/jom_1_1_7.zip" -OutFile C:\jom\jom.zip
|
||||
Expand-Archive -Path C:\jom\jom.zip -DestinationPath C:\jom
|
||||
"C:\jom" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: prepare the build directory
|
||||
run: mkdir _build
|
||||
- name: Get brotli
|
||||
working-directory: _build
|
||||
run: |
|
||||
vcpkg install brotli:x64-windows
|
||||
"C:\vcpkg\packages\brotli_x64-windows\bin" | Out-File -FilePath "$env:GITHUB_PATH" -Append
|
||||
- name: config
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
perl ..\Configure --strict-warnings enable-comp enable-brotli --with-brotli-include=C:\vcpkg\packages\brotli_x64-windows\include --with-brotli-lib=C:\vcpkg\packages\brotli_x64-windows\lib no-makedepend -DOSSL_WINCTX=openssl VC-WIN64A
|
||||
perl ..\Configure enable-comp enable-brotli --with-brotli-include=C:\vcpkg\packages\brotli_x64-windows\include --with-brotli-lib=C:\vcpkg\packages\brotli_x64-windows\lib no-makedepend -DOSSL_WINCTX=openssl VC-WIN64A
|
||||
perl configdata.pm --dump
|
||||
- name: build
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom /j4 /S
|
||||
run: nmake
|
||||
- name: Gather openssl version info
|
||||
working-directory: _build
|
||||
run: |
|
||||
$env:Path+=";C:\vcpkg\packages\brotli_x64-windows\bin"
|
||||
apps/openssl.exe version -v
|
||||
apps/openssl.exe version -v | %{($_ -split '\s+')[1]}
|
||||
apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+\.[0-9]+)(\..*)','$1'}
|
||||
|
|
@ -184,22 +120,24 @@ jobs:
|
|||
run: |
|
||||
echo ${Env:OSSL_VERSION}
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v OPENSSLDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v ENGINESDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe add HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v MODULESDIR /t REG_EXPAND_SZ /d TESTOPENSSLDIR /reg:32
|
||||
reg.exe query HKLM\SOFTWARE\OpenSSL-${Env:OSSL_VERSION}-openssl /v OPENSSLDIR /reg:32
|
||||
- name: download coreinfo
|
||||
run: |
|
||||
mkdir _build\coreinfo
|
||||
Invoke-WebRequest -Uri "https://download.sysinternals.com/files/Coreinfo.zip" -outfile "_build\coreinfo\Coreinfo.zip"
|
||||
uses: suisei-cn/actions-download-file@v1.6.0
|
||||
with:
|
||||
url: "https://download.sysinternals.com/files/Coreinfo.zip"
|
||||
target: _build/coreinfo/
|
||||
- name: get cpu info
|
||||
working-directory: _build
|
||||
continue-on-error: true
|
||||
run: |
|
||||
$env:Path+=";C:\vcpkg\packages\brotli_x64-windows\bin"
|
||||
7z.exe x coreinfo/Coreinfo.zip
|
||||
./Coreinfo64.exe -accepteula -f
|
||||
./apps/openssl.exe version -c
|
||||
- name: test
|
||||
working-directory: _build
|
||||
shell: cmd
|
||||
run: |
|
||||
call "C:\Program Files\Microsoft Visual Studio\18\Enterprise\VC\Auxiliary\Build\vcvars64.bat"
|
||||
jom test VERBOSE_FAILURE=yes TESTS="-test_fuzz* -test_fipsload" HARNESS_JOBS=4
|
||||
$env:Path+=";C:\vcpkg\packages\brotli_x64-windows\bin"
|
||||
nmake test VERBOSE_FAILURE=yes TESTS="-test_fuzz* -test_fipsload" HARNESS_JOBS=4
|
||||
|
|
|
|||
120
.gitignore
vendored
120
.gitignore
vendored
|
|
@ -58,8 +58,7 @@
|
|||
/include/openssl/x509_acert.h
|
||||
/include/openssl/x509_vfy.h
|
||||
/include/openssl/core_names.h
|
||||
|
||||
/apps/include/configuration.h
|
||||
/include/internal/param_names.h
|
||||
|
||||
# Auto generated parameter name files
|
||||
/crypto/params_idx.c
|
||||
|
|
@ -77,7 +76,6 @@ providers/common/der/der_rsa_gen.c
|
|||
providers/common/der/der_wrap_gen.c
|
||||
providers/common/der/der_sm2_gen.c
|
||||
providers/common/der/der_ml_dsa_gen.c
|
||||
providers/common/der/der_hkdf_gen.c
|
||||
providers/common/include/prov/der_slh_dsa.h
|
||||
providers/common/include/prov/der_dsa.h
|
||||
providers/common/include/prov/der_ec.h
|
||||
|
|
@ -87,104 +85,6 @@ providers/common/include/prov/der_digests.h
|
|||
providers/common/include/prov/der_wrap.h
|
||||
providers/common/include/prov/der_sm2.h
|
||||
providers/common/include/prov/der_ml_dsa.h
|
||||
providers/common/include/prov/der_hkdf.h
|
||||
providers/fips/fipsparams.inc
|
||||
providers/implementations/asymciphers/rsa_enc.inc
|
||||
providers/implementations/asymciphers/sm2_enc.inc
|
||||
providers/implementations/exchange/dh_exch.inc
|
||||
providers/implementations/exchange/ecdh_exch.inc
|
||||
providers/implementations/exchange/ecx_exch.inc
|
||||
providers/implementations/encode_decode/decode_der2key.inc
|
||||
providers/implementations/encode_decode/decode_epki2pki.inc
|
||||
providers/implementations/encode_decode/decode_pem2der.inc
|
||||
providers/implementations/encode_decode/decode_pvk2key.inc
|
||||
providers/implementations/encode_decode/decode_spki2typespki.inc
|
||||
providers/implementations/encode_decode/encode_key2any.inc
|
||||
providers/implementations/encode_decode/encode_key2ms.inc
|
||||
providers/implementations/kdfs/argon2.inc
|
||||
providers/implementations/kdfs/hkdf.inc
|
||||
providers/implementations/kdfs/hmacdrbg_kdf.inc
|
||||
providers/implementations/kdfs/ikev2kdf.inc
|
||||
providers/implementations/kdfs/kbkdf.inc
|
||||
providers/implementations/kdfs/krb5kdf.inc
|
||||
providers/implementations/kdfs/pbkdf1.inc
|
||||
providers/implementations/kdfs/pbkdf2.inc
|
||||
providers/implementations/kdfs/pkcs12kdf.inc
|
||||
providers/implementations/kdfs/pvkkdf.inc
|
||||
providers/implementations/kdfs/scrypt.inc
|
||||
providers/implementations/kdfs/snmpkdf.inc
|
||||
providers/implementations/kdfs/srtpkdf.inc
|
||||
providers/implementations/kdfs/sshkdf.inc
|
||||
providers/implementations/kdfs/sskdf.inc
|
||||
providers/implementations/kdfs/tls1_prf.inc
|
||||
providers/implementations/kdfs/x942kdf.inc
|
||||
providers/implementations/kdfs/x963kdf.inc
|
||||
providers/implementations/kem/ec_kem.inc
|
||||
providers/implementations/kem/ecx_kem.inc
|
||||
providers/implementations/kem/ml_kem_kem.inc
|
||||
providers/implementations/kem/rsa_kem.inc
|
||||
providers/implementations/keymgmt/ml_dsa_kmgmt.inc
|
||||
providers/implementations/keymgmt/ml_kem_kmgmt.inc
|
||||
providers/implementations/keymgmt/mlx_kmgmt.inc
|
||||
providers/implementations/signature/dsa_sig.inc
|
||||
providers/implementations/signature/ecdsa_sig.inc
|
||||
providers/implementations/keymgmt/dh_kmgmt.inc
|
||||
providers/implementations/keymgmt/dsa_kmgmt.inc
|
||||
providers/implementations/keymgmt/ecx_kmgmt.inc
|
||||
providers/implementations/keymgmt/lms_kmgmt.inc
|
||||
providers/implementations/keymgmt/mac_legacy_kmgmt.inc
|
||||
providers/implementations/keymgmt/ml_dsa_kmgmt.inc
|
||||
providers/implementations/keymgmt/ml_kem_kmgmt.inc
|
||||
providers/implementations/keymgmt/mlx_kmgmt.inc
|
||||
providers/implementations/keymgmt/slh_dsa_kmgmt.inc
|
||||
providers/implementations/keymgmt/template_kmgmt.inc
|
||||
providers/implementations/signature/eddsa_sig.inc
|
||||
providers/implementations/signature/mac_legacy_sig.inc
|
||||
providers/implementations/signature/ml_dsa_sig.inc
|
||||
providers/implementations/signature/rsa_sig.inc
|
||||
providers/implementations/signature/slh_dsa_sig.inc
|
||||
providers/implementations/signature/sm2_sig.inc
|
||||
providers/implementations/skeymgmt/generic.inc
|
||||
providers/implementations/storemgmt/file_store_any2obj.inc
|
||||
providers/implementations/storemgmt/file_store.inc
|
||||
providers/implementations/storemgmt/winstore_store.inc
|
||||
providers/implementations/ciphers/cipher_aes_cbc_hmac_sha.inc
|
||||
providers/implementations/ciphers/cipher_aes_cbc_hmac_sha_etm.inc
|
||||
providers/implementations/ciphers/cipher_aes_gcm_siv.inc
|
||||
providers/implementations/ciphers/cipher_aes_ocb.inc
|
||||
providers/implementations/ciphers/cipher_aes_siv.inc
|
||||
providers/implementations/ciphers/cipher_aes_wrp.inc
|
||||
providers/implementations/ciphers/cipher_aes_xts.inc
|
||||
providers/implementations/ciphers/ciphercommon.inc
|
||||
providers/implementations/ciphers/ciphercommon_ccm.inc
|
||||
providers/implementations/ciphers/ciphercommon_gcm.inc
|
||||
providers/implementations/ciphers/cipher_chacha20.inc
|
||||
providers/implementations/ciphers/cipher_chacha20_poly1305.inc
|
||||
providers/implementations/ciphers/cipher_null.inc
|
||||
providers/implementations/ciphers/cipher_rc4_hmac_md5.inc
|
||||
providers/implementations/ciphers/cipher_sm2_xts.c
|
||||
providers/implementations/ciphers/cipher_sm4_xts.inc
|
||||
providers/implementations/digests/blake2_prov.inc
|
||||
providers/implementations/digests/digestcommon.inc
|
||||
providers/implementations/digests/mdc2_prov.inc
|
||||
providers/implementations/digests/sha2_prov.inc
|
||||
providers/implementations/digests/sha3_prov.inc
|
||||
providers/implementations/digests/ml_dsa_mu_prov.inc
|
||||
providers/implementations/digests/cshake_prov.inc
|
||||
providers/implementations/include/prov/blake2_params.inc
|
||||
providers/implementations/macs/cmac_prov.inc
|
||||
providers/implementations/macs/gmac_prov.inc
|
||||
providers/implementations/macs/hmac_prov.inc
|
||||
providers/implementations/macs/kmac_prov.inc
|
||||
providers/implementations/macs/poly1305_prov.inc
|
||||
providers/implementations/macs/siphash_prov.inc
|
||||
providers/implementations/rands/drbg_ctr.inc
|
||||
providers/implementations/rands/drbg_hash.inc
|
||||
providers/implementations/rands/drbg_hmac.inc
|
||||
providers/implementations/rands/fips_crng_test.inc
|
||||
providers/implementations/rands/seed_src.inc
|
||||
providers/implementations/rands/seed_src_jitter.inc
|
||||
providers/implementations/rands/test_rng.inc
|
||||
|
||||
# error code files
|
||||
/crypto/err/openssl.txt.old
|
||||
|
|
@ -200,7 +100,6 @@ providers/implementations/rands/test_rng.inc
|
|||
/test/gost2814789t
|
||||
/test/ssltest_old
|
||||
/test/*test
|
||||
/test/*memfail
|
||||
/test/fips_aesavs
|
||||
/test/fips_desmovs
|
||||
/test/fips_dhvs
|
||||
|
|
@ -255,14 +154,11 @@ providers/implementations/rands/test_rng.inc
|
|||
/demos/guide/quic-client-non-block
|
||||
/demos/guide/quic-hq-interop
|
||||
/demos/guide/quic-multi-stream
|
||||
/demos/guide/quic-server-block
|
||||
/demos/guide/quic-server-non-block
|
||||
/demos/guide/tls-client-block
|
||||
/demos/guide/tls-client-non-block
|
||||
/demos/http3/libnghttp3.pc
|
||||
/demos/http3/nghttp3/
|
||||
/demos/http3/ossl-nghttp3-demo
|
||||
/demos/http3/ossl-nghttp3-demo-server
|
||||
/demos/kdf/argon2
|
||||
/demos/kdf/hkdf
|
||||
/demos/kdf/pbkdf2
|
||||
|
|
@ -278,8 +174,6 @@ providers/implementations/rands/test_rng.inc
|
|||
/demos/pkey/EVP_PKEY_DSA_paramvalidate
|
||||
/demos/pkey/EVP_PKEY_EC_keygen
|
||||
/demos/pkey/EVP_PKEY_RSA_keygen
|
||||
/demos/quic/server/server
|
||||
/demos/quic/poll-server/quic-server-ssl-poll-http
|
||||
/demos/signature/EVP_DSA_Signature_demo
|
||||
/demos/signature/EVP_EC_Signature_demo
|
||||
/demos/signature/EVP_ED_Signature_demo
|
||||
|
|
@ -311,6 +205,8 @@ providers/implementations/rands/test_rng.inc
|
|||
|
||||
# Misc auto generated files
|
||||
/doc/man7/openssl_user_macros.pod
|
||||
/tools/c_rehash
|
||||
/tools/c_rehash.pl
|
||||
/util/shlib_wrap.sh
|
||||
/util/wrap.pl
|
||||
/tags
|
||||
|
|
@ -374,7 +270,7 @@ providers/implementations/rands/test_rng.inc
|
|||
# Auto generated assembly language source files
|
||||
*.s
|
||||
!/crypto/*/asm/*.s
|
||||
/crypto/*.S
|
||||
/crypto/arm*.S
|
||||
/crypto/*/*.S
|
||||
*.asm
|
||||
!/crypto/*/asm/*.asm
|
||||
|
|
@ -431,11 +327,3 @@ doc-nits
|
|||
# LSP (Language Server Protocol) support
|
||||
.cache/
|
||||
compile_commands.json
|
||||
|
||||
# coverage files
|
||||
*.gcda
|
||||
*.gcno
|
||||
lcov.info
|
||||
run_tests
|
||||
depend
|
||||
|
||||
|
|
|
|||
|
|
@ -1,19 +0,0 @@
|
|||
repos:
|
||||
- repo: "https://github.com/codespell-project/codespell"
|
||||
rev: "v2.4.1"
|
||||
hooks:
|
||||
- id: "codespell"
|
||||
args: ["--config=.codespellrc"]
|
||||
- repo: "https://github.com/pre-commit/mirrors-clang-format"
|
||||
rev: "v21.1.6"
|
||||
hooks:
|
||||
- id: "clang-format"
|
||||
types_or: []
|
||||
files: '\.c\.in$|\.h\.in$|\.c$|\.h$'
|
||||
args: ["--style=file"]
|
||||
exclude: |
|
||||
(?x)^(
|
||||
crypto/objects/obj_dat.h|
|
||||
crypto/objects/obj_xref.h|
|
||||
include/openssl/obj_mac.h
|
||||
)$
|
||||
2591
CHANGES.md
2591
CHANGES.md
File diff suppressed because it is too large
Load diff
122
CONTRIBUTING.md
122
CONTRIBUTING.md
|
|
@ -19,36 +19,6 @@ open an issue for it before starting work, to get comments from the community.
|
|||
Someone may be already working on the same thing,
|
||||
or there may be special reasons why a feature is not implemented.
|
||||
|
||||
Similarly, if you plan to submit many pull requests, please start with
|
||||
a representative sample (no more than 3 or 4) and open an issue
|
||||
explaining your process. The OpenSSL project has limited resources,
|
||||
especially when it comes to reviewers, so we appreciate advanced
|
||||
communication before submitting many pull requests. In addition,
|
||||
contributors should personally evaluate potential patches generated by
|
||||
automated tools.
|
||||
|
||||
Provide a clear description of the issue or feature being addressed,
|
||||
including any relevant implementation details and, for performance
|
||||
improvements, benchmark results.
|
||||
|
||||
Pull requests and commits should be self-contained, enabling readers to
|
||||
understand what changed and why without needing to reference related
|
||||
issues or having prior knowledge. Commit messages should include all
|
||||
relevant details to help future contributors follow the git history,
|
||||
with clear explanations of what is changing and why. Long descriptions
|
||||
are encouraged if they aid understanding. Commit message titles (their
|
||||
first line) should be kept to 50-70 characters if possible.
|
||||
|
||||
Pull Requests (PR's) go through multiple phases before they are merged. In the
|
||||
first phase the label 'approval: review pending' is added. Once you receive 2 or
|
||||
more approvals from [Committers] the label is changed to 'approval: done' and
|
||||
24 hours after this the label changes to 'approval: ready to merge'. At some time
|
||||
after this your PR will be merged and the PR is closed. Reviewers may ask you to
|
||||
make changes at any phase before the Pull Request is merged, and any changes
|
||||
(that are not just a rebase) will require re-approval.
|
||||
|
||||
[Committers]: https://openssl-library.org/about/committers/index.html
|
||||
|
||||
To make it easier to review and accept your pull request, please follow these
|
||||
guidelines:
|
||||
|
||||
|
|
@ -80,37 +50,7 @@ guidelines:
|
|||
git push -f [<repository> [<branch>]]
|
||||
```
|
||||
|
||||
2. Similarly, if a non-trivial portion of a contribution was created
|
||||
using an AI tool, you must declare which agent and model were used.
|
||||
This is done by adding `Assisted-by: {agent}:{model}` below the commit
|
||||
message:
|
||||
|
||||
```
|
||||
One-line summary of change with AI-generated portions
|
||||
|
||||
Assisted-by: Claude:claude-sonnet-4-6
|
||||
```
|
||||
|
||||
Multiple Assisted-by trailers can be included if multiple tools were used:
|
||||
|
||||
```
|
||||
Assisted-by: Claude:claude-sonnet-4-6
|
||||
Assisted-by: ChatGPT:gpt-4o
|
||||
Assisted-by: GitHub Copilot:gpt-4.1
|
||||
```
|
||||
|
||||
You will need to have signed a v1.1 or later CLA in order to
|
||||
include AI-generated content in your contribution. CLAs signed
|
||||
after June 2026 will have the requisite clauses.
|
||||
|
||||
Consult the [OpenSSL AI Code and Documentation Contribution
|
||||
Policy] if an AI model assisted with the creation of your
|
||||
contribution.
|
||||
|
||||
[OpenSSL AI Code and Documentation Contribution
|
||||
Policy]: <https://openssl-library.org/policies/general/ai-policy/>
|
||||
|
||||
3. All source files should start with the following text (with
|
||||
2. All source files should start with the following text (with
|
||||
appropriate comment characters at the start of each line and the
|
||||
year(s) updated):
|
||||
|
||||
|
|
@ -123,37 +63,33 @@ guidelines:
|
|||
https://www.openssl.org/source/license.html
|
||||
```
|
||||
|
||||
4. Patches should be as current as possible; expect to have to rebase
|
||||
3. Patches should be as current as possible; expect to have to rebase
|
||||
often. We do not accept merge commits, you will have to remove them
|
||||
(usually by rebasing) before it will be acceptable.
|
||||
|
||||
5. Code provided should follow our [coding style](STYLE.md) and
|
||||
[documentation policy](DOCUMENTATION.md) and compile without warnings when
|
||||
using a --strict-warnings configuration.
|
||||
|
||||
Consistent formatting is enforced by using `clang-format` with configuration
|
||||
stored in [.clang-format](.clang-format). OpenSSL uses `WebKit` style.
|
||||
You can configure git pre-commit to automatically reformat your code with
|
||||
[.pre-commit-config.yaml](.pre-commit-config.yaml) configuration.
|
||||
There is also a [Perl tool](util/reformat-patches.sh) to help with
|
||||
reformatting existing patches.
|
||||
|
||||
4. Code provided should follow our [coding style] and [documentation policy]
|
||||
and compile without warnings.
|
||||
There is a [Perl tool](util/check-format.pl) that helps
|
||||
finding code formatting mistakes and other coding style nits.
|
||||
Where `gcc` or `clang` is available, you should use the
|
||||
`--strict-warnings` `Configure` option. OpenSSL compiles on many varied
|
||||
platforms: try to ensure you only use portable features.
|
||||
Clean builds via GitHub Actions are required. They are started automatically
|
||||
whenever a PR is created or updated by committers.
|
||||
|
||||
6. When at all possible, code contributions should include tests. These can
|
||||
[coding style]: https://openssl-library.org/policies/technical/coding-style/
|
||||
[documentation policy]: https://openssl-library.org/policies/technical/documentation-policy/
|
||||
|
||||
5. When at all possible, code contributions should include tests. These can
|
||||
either be added to an existing test, or completely new. Please see
|
||||
[test/README.md](test/README.md) for information on the test framework.
|
||||
|
||||
7. New features or changed functionality must include
|
||||
6. New features or changed functionality must include
|
||||
documentation. Please look at the `.pod` files in `doc/man[1357]` for
|
||||
examples of our style. Run `make doc-nits` to make sure that your
|
||||
documentation changes are clean.
|
||||
|
||||
8. For user visible changes (API changes, behaviour changes, ...),
|
||||
7. For user visible changes (API changes, behaviour changes, ...),
|
||||
consider adding a note in [CHANGES.md](CHANGES.md).
|
||||
This could be a summarising description of the change, and could
|
||||
explain the grander details.
|
||||
|
|
@ -164,37 +100,5 @@ guidelines:
|
|||
with a specific release without having to sift through the higher
|
||||
noise ratio in git-log.
|
||||
|
||||
9. Guidelines on how to integrate error output of new crypto library modules
|
||||
8. Guidelines on how to integrate error output of new crypto library modules
|
||||
can be found in [crypto/err/README.md](crypto/err/README.md).
|
||||
|
||||
10. Once your Pull Request gets to the stage of being reviewed fixup commits
|
||||
should be used where possible. Fixup commits are squashed when the PR is
|
||||
finally merged. Fixup commits are done in the following way:
|
||||
|
||||
```
|
||||
|
||||
# Add one or more updated files that needed changes
|
||||
git add <filename>
|
||||
|
||||
# Do a fixup commit
|
||||
# <commit-id> is the id of a previous commit that you want to fix up.
|
||||
git commit --fixup <commit-id>
|
||||
|
||||
# Do a non forced push
|
||||
git push
|
||||
```
|
||||
|
||||
To view commit-id's use:
|
||||
|
||||
```
|
||||
git log
|
||||
```
|
||||
|
||||
11. If a Pull Request addresses an [issue](https://github.com/openssl/openssl/issues/)
|
||||
the commit should include the line:
|
||||
|
||||
```
|
||||
Fixes: LINK
|
||||
```
|
||||
|
||||
where LINK is the https link to the issue in github.
|
||||
|
|
|
|||
|
|
@ -47,7 +47,7 @@ my %targets=(
|
|||
|
||||
defines =>
|
||||
sub {
|
||||
my @defs = ();
|
||||
my @defs = ( 'OPENSSL_BUILDING_OPENSSL' );
|
||||
push @defs, "BROTLI" unless $disabled{brotli};
|
||||
push @defs, "BROTLI_SHARED" unless $disabled{"brotli-dynamic"};
|
||||
push @defs, "ZLIB" unless $disabled{zlib};
|
||||
|
|
|
|||
|
|
@ -5,8 +5,7 @@
|
|||
my $vc_win64a_info = {};
|
||||
sub vc_win64a_info {
|
||||
unless (%$vc_win64a_info) {
|
||||
# Minimum NASM version is 2.09 otherwise SHA3 might be miscompiled
|
||||
if (`nasm -v 2>NUL` =~ /NASM version ([0-9]+)\.([0-9]+)/ && ($1 > 2 || ($1 == 2 && $2 >= 9))) {
|
||||
if (`nasm -v 2>NUL` =~ /NASM version ([0-9]+\.[0-9]+)/ && $1 >= 2.0) {
|
||||
$vc_win64a_info = { AS => "nasm",
|
||||
ASFLAGS => "-g",
|
||||
asflags => "-Ox -f win64 -DNEAR",
|
||||
|
|
@ -61,6 +60,70 @@ sub vc_win32_info {
|
|||
return $vc_win32_info;
|
||||
}
|
||||
|
||||
my $vc_wince_info = {};
|
||||
sub vc_wince_info {
|
||||
unless (%$vc_wince_info) {
|
||||
# sanity check
|
||||
$die->('%OSVERSION% is not defined') if (!defined(env('OSVERSION')));
|
||||
$die->('%PLATFORM% is not defined') if (!defined(env('PLATFORM')));
|
||||
$die->('%TARGETCPU% is not defined') if (!defined(env('TARGETCPU')));
|
||||
|
||||
#
|
||||
# Idea behind this is to mimic flags set by eVC++ IDE...
|
||||
#
|
||||
my $wcevers = env('OSVERSION'); # WCENNN
|
||||
my $wcevernum;
|
||||
my $wceverdotnum;
|
||||
if ($wcevers =~ /^WCE([1-9])([0-9]{2})$/) {
|
||||
$wcevernum = "$1$2";
|
||||
$wceverdotnum = "$1.$2";
|
||||
} else {
|
||||
$die->('%OSVERSION% value is insane');
|
||||
$wcevernum = "{unknown}";
|
||||
$wceverdotnum = "{unknown}";
|
||||
}
|
||||
my $wcecdefs = "-D_WIN32_WCE=$wcevernum -DUNDER_CE=$wcevernum"; # -D_WIN32_WCE=NNN
|
||||
my $wcelflag = "/subsystem:windowsce,$wceverdotnum"; # ...,N.NN
|
||||
|
||||
my $wceplatf = env('PLATFORM');
|
||||
|
||||
$wceplatf =~ tr/a-z0-9 /A-Z0-9_/;
|
||||
$wcecdefs .= " -DWCE_PLATFORM_$wceplatf";
|
||||
|
||||
my $wcetgt = env('TARGETCPU'); # just shorter name...
|
||||
SWITCH: for($wcetgt) {
|
||||
/^X86/ && do { $wcecdefs.=" -Dx86 -D_X86_ -D_i386_ -Di_386_";
|
||||
$wcelflag.=" /machine:X86"; last; };
|
||||
/^ARMV4[IT]/ && do { $wcecdefs.=" -DARM -D_ARM_ -D$wcetgt";
|
||||
$wcecdefs.=" -DTHUMB -D_THUMB_" if($wcetgt=~/T$/);
|
||||
$wcecdefs.=" -QRarch4T -QRinterwork-return";
|
||||
$wcelflag.=" /machine:THUMB"; last; };
|
||||
/^ARM/ && do { $wcecdefs.=" -DARM -D_ARM_ -D$wcetgt";
|
||||
$wcelflag.=" /machine:ARM"; last; };
|
||||
/^MIPSIV/ && do { $wcecdefs.=" -DMIPS -D_MIPS_ -DR4000 -D$wcetgt";
|
||||
$wcecdefs.=" -D_MIPS64 -QMmips4 -QMn32";
|
||||
$wcelflag.=" /machine:MIPSFPU"; last; };
|
||||
/^MIPS16/ && do { $wcecdefs.=" -DMIPS -D_MIPS_ -DR4000 -D$wcetgt";
|
||||
$wcecdefs.=" -DMIPSII -QMmips16";
|
||||
$wcelflag.=" /machine:MIPS16"; last; };
|
||||
/^MIPSII/ && do { $wcecdefs.=" -DMIPS -D_MIPS_ -DR4000 -D$wcetgt";
|
||||
$wcecdefs.=" -QMmips2";
|
||||
$wcelflag.=" /machine:MIPS"; last; };
|
||||
/^R4[0-9]{3}/ && do { $wcecdefs.=" -DMIPS -D_MIPS_ -DR4000";
|
||||
$wcelflag.=" /machine:MIPS"; last; };
|
||||
/^SH[0-9]/ && do { $wcecdefs.=" -D$wcetgt -D_${wcetgt}_ -DSHx";
|
||||
$wcecdefs.=" -Qsh4" if ($wcetgt =~ /^SH4/);
|
||||
$wcelflag.=" /machine:$wcetgt"; last; };
|
||||
{ $wcecdefs.=" -D$wcetgt -D_${wcetgt}_";
|
||||
$wcelflag.=" /machine:$wcetgt"; last; };
|
||||
}
|
||||
|
||||
$vc_wince_info = { cppflags => $wcecdefs,
|
||||
lflags => $wcelflag };
|
||||
}
|
||||
return $vc_wince_info;
|
||||
}
|
||||
|
||||
# Helper functions for the VMS configs
|
||||
my $vms_info = {};
|
||||
sub vms_info {
|
||||
|
|
@ -616,13 +679,13 @@ my %targets = (
|
|||
CXX => "g++",
|
||||
CFLAGS => picker(default => "-Wall",
|
||||
debug => "-O0 -g",
|
||||
release => "-O3",
|
||||
pgo => "-O3 -fprofile-use -Wno-coverage-mismatch"),
|
||||
release => "-O3"),
|
||||
CXXFLAGS => picker(default => "-Wall",
|
||||
debug => "-O0 -g",
|
||||
release => "-O3"),
|
||||
cflags => threads("-pthread"),
|
||||
cxxflags => combine("-std=c++11", threads("-pthread")),
|
||||
lib_cppflags => "-DOPENSSL_USE_NODELETE",
|
||||
ex_libs => add("-ldl", threads("-pthread")),
|
||||
bn_ops => "BN_LLONG RC4_CHAR",
|
||||
thread_scheme => "pthreads",
|
||||
|
|
@ -630,6 +693,7 @@ my %targets = (
|
|||
shared_target => "linux-shared",
|
||||
shared_cflag => "-fPIC",
|
||||
shared_ldflag => sub { $disabled{pinshared} ? () : "-Wl,-znodelete" },
|
||||
enable => [ "afalgeng" ],
|
||||
},
|
||||
"linux-latomic" => {
|
||||
inherit_from => [ "linux-generic32" ],
|
||||
|
|
@ -906,6 +970,7 @@ my %targets = (
|
|||
perlasm_scheme => 'void',
|
||||
},
|
||||
"linux64-sparcv9" => {
|
||||
# GCC 3.1 is a requirement
|
||||
inherit_from => [ "linux-generic64" ],
|
||||
cflags => add("-m64 -mcpu=ultrasparc"),
|
||||
cxxflags => add("-m64 -mcpu=ultrasparc"),
|
||||
|
|
@ -961,6 +1026,7 @@ my %targets = (
|
|||
cflags => threads("-pthread"),
|
||||
cppflags => threads("-D_THREAD_SAFE -D_REENTRANT"),
|
||||
ex_libs => add(threads("-pthread")),
|
||||
enable => add("devcryptoeng"),
|
||||
bn_ops => "BN_LLONG",
|
||||
thread_scheme => "pthreads",
|
||||
dso_scheme => "dlfcn",
|
||||
|
|
@ -1134,6 +1200,7 @@ my %targets = (
|
|||
cflags => threads("-pthread"),
|
||||
cppflags => threads("-D_THREAD_SAFE -D_REENTRANT"),
|
||||
ex_libs => add(threads("-pthread")),
|
||||
enable => add("devcryptoeng"),
|
||||
bn_ops => "BN_LLONG",
|
||||
thread_scheme => "pthreads",
|
||||
dso_scheme => "dlfcn",
|
||||
|
|
@ -1434,7 +1501,7 @@ my %targets = (
|
|||
|
||||
#### Visual C targets
|
||||
#
|
||||
# Win64 target, WIN64A denotes AMD64
|
||||
# Win64 targets, WIN64I denotes IA-64/Itanium and WIN64A - AMD64
|
||||
#
|
||||
# Note about /wd4090, disable warning C4090. This warning returns false
|
||||
# positives in some situations. Disabling it altogether masks both
|
||||
|
|
@ -1476,10 +1543,10 @@ my %targets = (
|
|||
"UNICODE", "_UNICODE",
|
||||
"_CRT_SECURE_NO_DEPRECATE",
|
||||
"_WINSOCK_DEPRECATED_NO_WARNINGS"),
|
||||
lib_cflags => add("/Z7"),
|
||||
lib_cflags => add("/Zi /Fdossl_static.pdb"),
|
||||
lib_defines => add("L_ENDIAN"),
|
||||
dso_cflags => "/Z7",
|
||||
bin_cflags => "/Z7",
|
||||
dso_cflags => "/Zi /Fddso.pdb",
|
||||
bin_cflags => "/Zi /Fdapp.pdb",
|
||||
# def_flag made to empty string so a .def file gets generated
|
||||
shared_defflag => '',
|
||||
shared_ldflag => "/dll",
|
||||
|
|
@ -1501,11 +1568,11 @@ my %targets = (
|
|||
cflags => add(picker(default => '/Gs0 /GF /Gy',
|
||||
debug =>
|
||||
sub {
|
||||
($disabled{shared} ? "" : ($disabled{"static-vcruntime"} ? "/MDd" : ($disabled{threads} ? "" : "/MTd")));
|
||||
($disabled{shared} ? "" : "/MDd");
|
||||
},
|
||||
release =>
|
||||
sub {
|
||||
($disabled{shared} ? "" : ($disabled{"static-vcruntime"} ? "/MD": ($disabled{threads} ? "" : "/MT")));
|
||||
($disabled{shared} ? "" : "/MD");
|
||||
})),
|
||||
defines => add(picker(default => [], # works as type cast
|
||||
debug => [ "DEBUG", "_DEBUG" ])),
|
||||
|
|
@ -1542,6 +1609,17 @@ my %targets = (
|
|||
}),
|
||||
bn_ops => add("SIXTY_FOUR_BIT"),
|
||||
},
|
||||
"VC-WIN64I" => {
|
||||
inherit_from => [ "VC-WIN64-common" ],
|
||||
AS => "ias",
|
||||
ASFLAGS => "-d debug",
|
||||
asoutflag => "-o ",
|
||||
sys_id => "WIN64I",
|
||||
uplink_arch => 'ia64',
|
||||
asm_arch => 'ia64',
|
||||
perlasm_scheme => "ias",
|
||||
multilib => "-ia64",
|
||||
},
|
||||
"VC-WIN64A" => {
|
||||
inherit_from => [ "VC-WIN64-common" ],
|
||||
AS => sub { vc_win64a_info()->{AS} },
|
||||
|
|
@ -1569,6 +1647,53 @@ my %targets = (
|
|||
# some installation path heuristics in windows-makefile.tmpl...
|
||||
build_scheme => add("VC-WOW", { separator => undef }),
|
||||
},
|
||||
"VC-CE" => {
|
||||
inherit_from => [ "VC-common" ],
|
||||
CFLAGS => add(picker(debug => "/Od",
|
||||
release => "/O1i")),
|
||||
CPPDEFINES => picker(debug => [ "DEBUG", "_DEBUG" ]),
|
||||
LDFLAGS => add("/nologo /opt:ref"),
|
||||
cflags =>
|
||||
combine('/GF /Gy',
|
||||
sub { vc_wince_info()->{cflags}; },
|
||||
sub { `cl 2>&1` =~ /Version ([0-9]+)\./ && $1>=14
|
||||
? ($disabled{shared} ? " /MT" : " /MD")
|
||||
: " /MC"; }),
|
||||
cppflags => sub { vc_wince_info()->{cppflags}; },
|
||||
lib_defines => add("NO_CHMOD", "OPENSSL_SMALL_FOOTPRINT"),
|
||||
lib_cppflags => sub { vc_wince_info()->{cppflags}; },
|
||||
includes =>
|
||||
add(combine(sub { defined(env('WCECOMPAT'))
|
||||
? '$(WCECOMPAT)/include' : (); },
|
||||
sub { defined(env('PORTSDK_LIBPATH'))
|
||||
? '$(PORTSDK_LIBPATH)/../../include'
|
||||
: (); })),
|
||||
lflags => add(combine(sub { vc_wince_info()->{lflags}; },
|
||||
sub { defined(env('PORTSDK_LIBPATH'))
|
||||
? "/entry:mainCRTstartup" : (); })),
|
||||
sys_id => "WINCE",
|
||||
bn_ops => add("BN_LLONG"),
|
||||
ex_libs => add(sub {
|
||||
my @ex_libs = ();
|
||||
push @ex_libs, 'ws2.lib' unless $disabled{sock};
|
||||
push @ex_libs, 'crypt32.lib';
|
||||
if (defined(env('WCECOMPAT'))) {
|
||||
my $x = '$(WCECOMPAT)/lib';
|
||||
if (-f "$x/env('TARGETCPU')/wcecompatex.lib") {
|
||||
$x .= '/$(TARGETCPU)/wcecompatex.lib';
|
||||
} else {
|
||||
$x .= '/wcecompatex.lib';
|
||||
}
|
||||
push @ex_libs, $x;
|
||||
}
|
||||
push @ex_libs, '$(PORTSDK_LIBPATH)/portlib.lib'
|
||||
if (defined(env('PORTSDK_LIBPATH')));
|
||||
push @ex_libs, '/nodefaultlib coredll.lib corelibc.lib'
|
||||
if (env('TARGETCPU') =~ /^X86|^ARMV4[IT]/);
|
||||
return join(" ", @ex_libs);
|
||||
}),
|
||||
},
|
||||
|
||||
#### MinGW
|
||||
"mingw-common" => {
|
||||
inherit_from => [ 'BASE_unix' ],
|
||||
|
|
@ -1580,7 +1705,7 @@ my %targets = (
|
|||
cppflags => combine("-DUNICODE -D_UNICODE -DWIN32_LEAN_AND_MEAN",
|
||||
threads("-D_MT")),
|
||||
lib_cppflags => "-DL_ENDIAN",
|
||||
ex_libs => add("-lws2_32 -lgdi32 -lcrypt32 -lbcrypt"),
|
||||
ex_libs => add("-lws2_32 -lgdi32 -lcrypt32"),
|
||||
thread_scheme => "winthreads",
|
||||
dso_scheme => "win32",
|
||||
shared_target => "mingw-shared",
|
||||
|
|
@ -1621,18 +1746,6 @@ my %targets = (
|
|||
multilib => "64",
|
||||
},
|
||||
|
||||
"mingwarm64" => {
|
||||
inherit_from => [ "mingw-common" ],
|
||||
cflags => "",
|
||||
sys_id => "MINGWARM64",
|
||||
bn_ops => add("SIXTY_FOUR_BIT"),
|
||||
asm_arch => 'aarch64',
|
||||
uplink_arch => 'armv8',
|
||||
perlasm_scheme => "win64",
|
||||
shared_rcflag => "",
|
||||
multilib => "-arm64",
|
||||
},
|
||||
|
||||
#### UEFI
|
||||
"UEFI" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
|
|
@ -1733,6 +1846,37 @@ my %targets = (
|
|||
shared_cflag => "-fPIC",
|
||||
shared_extension => ".\$(SHLIB_VERSION_NUMBER).dylib",
|
||||
},
|
||||
# Option "freeze" such as -std=gnu9x can't negatively interfere
|
||||
# with future defaults for below two targets, because MacOS X
|
||||
# for PPC has no future, it was discontinued by vendor in 2009.
|
||||
"darwin-ppc-cc" => { inherit_from => [ "darwin-ppc" ] }, # Historic alias
|
||||
"darwin-ppc" => {
|
||||
inherit_from => [ "darwin-common" ],
|
||||
cflags => add("-arch ppc -std=gnu9x -Wa,-force_cpusubtype_ALL"),
|
||||
lib_cppflags => add("-DB_ENDIAN"),
|
||||
shared_cflag => add("-fno-common"),
|
||||
asm_arch => 'ppc32',
|
||||
perlasm_scheme => "osx32",
|
||||
},
|
||||
"darwin64-ppc-cc" => { inherit_from => [ "darwin64-ppc" ] }, # Historic alias
|
||||
"darwin64-ppc" => {
|
||||
inherit_from => [ "darwin-common" ],
|
||||
cflags => add("-arch ppc64 -std=gnu9x"),
|
||||
lib_cppflags => add("-DB_ENDIAN"),
|
||||
bn_ops => "SIXTY_FOUR_BIT_LONG RC4_CHAR",
|
||||
asm_arch => 'ppc64',
|
||||
perlasm_scheme => "osx64",
|
||||
},
|
||||
"darwin-i386-cc" => { inherit_from => [ "darwin-i386" ] }, # Historic alias
|
||||
"darwin-i386" => {
|
||||
inherit_from => [ "darwin-common" ],
|
||||
CFLAGS => add(picker(release => "-fomit-frame-pointer")),
|
||||
cflags => add("-arch i386"),
|
||||
lib_cppflags => add("-DL_ENDIAN"),
|
||||
bn_ops => "BN_LLONG RC4_INT",
|
||||
asm_arch => 'x86',
|
||||
perlasm_scheme => "macosx",
|
||||
},
|
||||
"darwin64-x86_64-cc" => { inherit_from => [ "darwin64-x86_64" ] }, # Historic alias
|
||||
"darwin64-x86_64" => {
|
||||
inherit_from => [ "darwin-common" ],
|
||||
|
|
@ -1804,6 +1948,109 @@ my %targets = (
|
|||
multilib => "64",
|
||||
},
|
||||
|
||||
##### VxWorks for various targets
|
||||
"vxworks-ppc60x" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "ccppc",
|
||||
CFLAGS => "-O2 -Wall -fstrength-reduce",
|
||||
cflags => "-mrtp -mhard-float -mstrict-align -fno-implicit-fp -fno-builtin -fno-strict-aliasing",
|
||||
cppflags => combine("-D_REENTRANT -DPPC32_fp60x -DCPU=PPC32",
|
||||
"_DTOOL_FAMILY=gnu -DTOOL=gnu",
|
||||
"-I\$(WIND_BASE)/target/usr/h",
|
||||
"-I\$(WIND_BASE)/target/usr/h/wrn/coreip"),
|
||||
sys_id => "VXWORKS",
|
||||
lflags => add("-L \$(WIND_BASE)/target/usr/lib/ppc/PPC32/common"),
|
||||
ex_libs => add("-Wl,--defsym,__wrs_rtp_base=0xe0000000"),
|
||||
},
|
||||
"vxworks-ppcgen" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "ccppc",
|
||||
CFLAGS => "-O1 -Wall",
|
||||
cflags => "-mrtp -msoft-float -mstrict-align -fno-builtin -fno-strict-aliasing",
|
||||
cppflags => combine("-D_REENTRANT -DPPC32 -DCPU=PPC32",
|
||||
"-DTOOL_FAMILY=gnu -DTOOL=gnu",
|
||||
"-I\$(WIND_BASE)/target/usr/h",
|
||||
"-I\$(WIND_BASE)/target/usr/h/wrn/coreip"),
|
||||
sys_id => "VXWORKS",
|
||||
lflags => add("-L \$(WIND_BASE)/target/usr/lib/ppc/PPC32/sfcommon"),
|
||||
ex_libs => add("-Wl,--defsym,__wrs_rtp_base=0xe0000000"),
|
||||
},
|
||||
"vxworks-ppc405" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "ccppc",
|
||||
CFLAGS => "-g",
|
||||
cflags => "-msoft-float -mlongcall",
|
||||
cppflags => combine("-D_REENTRANT -DPPC32 -DCPU=PPC405",
|
||||
"-DTOOL_FAMILY=gnu -DTOOL=gnu",
|
||||
"-I\$(WIND_BASE)/target/h"),
|
||||
sys_id => "VXWORKS",
|
||||
lflags => add("-r"),
|
||||
},
|
||||
"vxworks-ppc750" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "ccppc",
|
||||
CFLAGS => "-ansi -fvolatile -Wall \$(DEBUG_FLAG)",
|
||||
cflags => "-nostdinc -fno-builtin -fno-for-scope -fsigned-char -msoft-float -mlongcall",
|
||||
cppflags => combine("-DPPC750 -D_REENTRANT -DCPU=PPC604",
|
||||
"-I\$(WIND_BASE)/target/h"),
|
||||
sys_id => "VXWORKS",
|
||||
lflags => add("-r"),
|
||||
},
|
||||
"vxworks-ppc750-debug" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "ccppc",
|
||||
CFLAGS => "-ansi -fvolatile -Wall -g",
|
||||
cflags => "-nostdinc -fno-builtin -fno-for-scope -fsigned-char -msoft-float -mlongcall",
|
||||
cppflags => combine("-DPPC750 -D_REENTRANT -DCPU=PPC604",
|
||||
"-DPEDANTIC -DDEBUG",
|
||||
"-I\$(WIND_BASE)/target/h"),
|
||||
sys_id => "VXWORKS",
|
||||
lflags => add("-r"),
|
||||
},
|
||||
"vxworks-ppc860" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "ccppc",
|
||||
cflags => "-nostdinc -msoft-float",
|
||||
cppflags => combine("-DCPU=PPC860 -DNO_STRINGS_H",
|
||||
"-I\$(WIND_BASE)/target/h"),
|
||||
sys_id => "VXWORKS",
|
||||
lflags => add("-r"),
|
||||
},
|
||||
"vxworks-simlinux" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "ccpentium",
|
||||
cflags => "-B\$(WIND_BASE)/host/\$(WIND_HOST_TYPE)/lib/gcc-lib/ -fno-builtin -fno-defer-pop",
|
||||
cppflags => combine("-D_VSB_CONFIG_FILE=\"\$(WIND_BASE)/target/lib/h/config/vsbConfig.h\"",
|
||||
"-DL_ENDIAN -DCPU=SIMLINUX -DNO_STRINGS_H",
|
||||
"-DTOOL_FAMILY=gnu -DTOOL=gnu",
|
||||
"-DOPENSSL_NO_HW_PADLOCK",
|
||||
"-I\$(WIND_BASE)/target/h",
|
||||
"-I\$(WIND_BASE)/target/h/wrn/coreip"),
|
||||
sys_id => "VXWORKS",
|
||||
lflags => add("-r"),
|
||||
ranlib => "ranlibpentium",
|
||||
},
|
||||
"vxworks-mips" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "ccmips",
|
||||
CFLAGS => "-O -G 0",
|
||||
cflags => "-mrtp -mips2 -B\$(WIND_BASE)/host/\$(WIND_HOST_TYPE)/lib/gcc-lib/ -msoft-float -mno-branch-likely -fno-builtin -fno-defer-pop",
|
||||
cppflags => combine("-D_VSB_CONFIG_FILE=\"\$(WIND_BASE)/target/lib/h/config/vsbConfig.h\"",
|
||||
"-DCPU=MIPS32 -DNO_STRINGS_H",
|
||||
"-DTOOL_FAMILY=gnu -DTOOL=gnu",
|
||||
"-DOPENSSL_NO_HW_PADLOCK",
|
||||
threads("-D_REENTRANT"),
|
||||
"-I\$(WIND_BASE)/target/h",
|
||||
"-I\$(WIND_BASE)/target/h/wrn/coreip"),
|
||||
sys_id => "VXWORKS",
|
||||
lflags => add("-L \$(WIND_BASE)/target/usr/lib/mips/MIPSI32/sfcommon"),
|
||||
ex_libs => add("-Wl,--defsym,__wrs_rtp_base=0xe0000000"),
|
||||
thread_scheme => "pthreads",
|
||||
asm_arch => 'mips32',
|
||||
perlasm_scheme => "o32",
|
||||
ranlib => "ranlibmips",
|
||||
},
|
||||
|
||||
#### uClinux
|
||||
"uClinux-dist" => {
|
||||
inherit_from => [ "BASE_unix" ],
|
||||
|
|
@ -1850,7 +2097,8 @@ my %targets = (
|
|||
? "/WARNINGS=DISABLE=(".join(",",@warnings).")" : (); }),
|
||||
cflag_incfirst => '/FIRST_INCLUDE=',
|
||||
lib_defines =>
|
||||
add("_XOPEN_SOURCE", "_XOPEN_SOURCE_EXTENDED=1",
|
||||
add("OPENSSL_USE_NODELETE",
|
||||
"_XOPEN_SOURCE", "_XOPEN_SOURCE_EXTENDED=1",
|
||||
sub {
|
||||
return vms_info()->{def_zlib}
|
||||
? "LIBZ=\"\"\"".vms_info()->{def_zlib}."\"\"\"" : ();
|
||||
|
|
@ -1883,7 +2131,7 @@ my %targets = (
|
|||
asflags => sub { vms_info()->{asflags} },
|
||||
perlasm_scheme => sub { vms_info()->{perlasm_scheme} },
|
||||
|
||||
disable => add('pinshared'),
|
||||
disable => add('pinshared', 'loadereng'),
|
||||
|
||||
},
|
||||
|
||||
|
|
|
|||
|
|
@ -232,7 +232,6 @@ my %targets = (
|
|||
bn_ops => add("RC4_CHAR"),
|
||||
asm_arch => 'aarch64',
|
||||
perlasm_scheme => "linux64",
|
||||
shared_ldflag => add("-Wl,-z,max-page-size=16384"),
|
||||
},
|
||||
|
||||
"android-mips" => {
|
||||
|
|
@ -270,7 +269,6 @@ my %targets = (
|
|||
bn_ops => add("RC4_INT"),
|
||||
asm_arch => 'x86_64',
|
||||
perlasm_scheme => "elf",
|
||||
shared_ldflag => add("-Wl,-z,max-page-size=16384"),
|
||||
},
|
||||
|
||||
"android-riscv64" => {
|
||||
|
|
|
|||
|
|
@ -7,9 +7,9 @@ my %targets = (
|
|||
inherit_from => [ "BASE_unix" ],
|
||||
CC => "gcc",
|
||||
CFLAGS => "-fomit-frame-pointer -O2 -Wall",
|
||||
cflags => "-I\$(WATT_ROOT)/inc -DTERMIOS -DL_ENDIAN",
|
||||
cflags => "-I/dev/env/WATT_ROOT/inc -DTERMIOS -DL_ENDIAN",
|
||||
sys_id => "MSDOS",
|
||||
lflags => add("-L\$(WATT_ROOT)/lib"),
|
||||
lflags => add("-L/dev/env/WATT_ROOT/lib"),
|
||||
ex_libs => add("-lwatt"),
|
||||
bn_ops => "BN_LLONG",
|
||||
asm_arch => 'x86',
|
||||
|
|
|
|||
|
|
@ -18,6 +18,5 @@ my %targets = (
|
|||
uplink_arch => 'x86_64',
|
||||
asm_arch => 'x86_64',
|
||||
perlasm_scheme => "masm",
|
||||
multilib => "-x64",
|
||||
},
|
||||
);
|
||||
|
|
|
|||
|
|
@ -22,6 +22,7 @@
|
|||
ex_libs => add('-lrld'),
|
||||
enable => ['egd'],
|
||||
# Not currently inherited
|
||||
disable => ['atexit'],
|
||||
dso_scheme => 'DLFCN',
|
||||
sys_id => 'TANDEM',
|
||||
},
|
||||
|
|
@ -167,7 +168,6 @@
|
|||
# Build models
|
||||
'nonstop-model-put' => {
|
||||
template => 1,
|
||||
disable => ['secure-memory'],
|
||||
defines => ['_PUT_MODEL_',
|
||||
'_REENTRANT', '_THREAD_SUPPORT_FUNCTIONS'],
|
||||
ex_libs => '-lput',
|
||||
|
|
@ -177,7 +177,6 @@
|
|||
# Build models
|
||||
'nonstop-model-klt' => {
|
||||
template => 1,
|
||||
disable => ['secure-memory'],
|
||||
defines => ['_KLT_MODEL_',
|
||||
'_REENTRANT', '_THREAD_SUPPORT_FUNCTIONS'],
|
||||
ex_libs => '-lklt',
|
||||
|
|
@ -190,7 +189,7 @@
|
|||
'nonstop-archenv-x86_64-oss',
|
||||
'nonstop-ilp32',
|
||||
'nonstop-efloat-x86_64' ],
|
||||
disable => ['threads'],
|
||||
disable => ['threads','atexit'],
|
||||
},
|
||||
'nonstop-nsx_put' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
|
|
@ -200,6 +199,7 @@
|
|||
'nonstop-model-put' ],
|
||||
multilib => '-put',
|
||||
multibin => '-put',
|
||||
disable => ['atexit'],
|
||||
},
|
||||
'nonstop-nsx_64' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
|
|
@ -208,7 +208,7 @@
|
|||
'nonstop-efloat-x86_64' ],
|
||||
multilib => '64',
|
||||
multibin => '64',
|
||||
disable => ['threads'],
|
||||
disable => ['threads','atexit'],
|
||||
},
|
||||
'nonstop-nsx_64_put' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
|
|
@ -218,6 +218,7 @@
|
|||
'nonstop-model-put' ],
|
||||
multilib => '64-put',
|
||||
multibin => '64-put',
|
||||
disable => ['atexit'],
|
||||
},
|
||||
'nonstop-nsx_64_klt' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
|
|
@ -227,18 +228,19 @@
|
|||
'nonstop-model-klt' ],
|
||||
multilib => '64-klt',
|
||||
multibin => '64-klt',
|
||||
disable => ['atexit'],
|
||||
},
|
||||
'nonstop-nsx_g' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
'nonstop-archenv-x86_64-guardian',
|
||||
'nonstop-ilp32', 'nonstop-nfloat-x86_64' ],
|
||||
disable => ['threads'],
|
||||
disable => ['threads','atexit'],
|
||||
},
|
||||
'nonstop-nsx_g_tandem' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
'nonstop-archenv-x86_64-guardian',
|
||||
'nonstop-ilp32', 'nonstop-tfloat-x86_64' ],
|
||||
disable => ['threads'],
|
||||
disable => ['threads','atexit'],
|
||||
},
|
||||
'nonstop-nsv' => {
|
||||
inherit_from => [ 'nonstop-nsx' ],
|
||||
|
|
@ -248,7 +250,7 @@
|
|||
'nonstop-archenv-itanium-oss',
|
||||
'nonstop-ilp32',
|
||||
'nonstop-efloat-itanium' ],
|
||||
disable => ['threads'],
|
||||
disable => ['threads','atexit'],
|
||||
},
|
||||
'nonstop-nse_put' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
|
|
@ -258,6 +260,7 @@
|
|||
'nonstop-model-put' ],
|
||||
multilib => '-put',
|
||||
multibin => '-put',
|
||||
disable => ['atexit'],
|
||||
},
|
||||
'nonstop-nse_64' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
|
|
@ -266,7 +269,7 @@
|
|||
'nonstop-efloat-itanium' ],
|
||||
multilib => '64',
|
||||
multibin => '64',
|
||||
disable => ['threads'],
|
||||
disable => ['threads','atexit'],
|
||||
},
|
||||
'nonstop-nse_64_put' => {
|
||||
inherit_from => [ 'nonstop-common',
|
||||
|
|
@ -276,4 +279,5 @@
|
|||
'nonstop-model-put' ],
|
||||
multilib => '64-put',
|
||||
multibin => '64-put',
|
||||
disable => ['atexit'],
|
||||
},
|
||||
|
|
|
|||
|
|
@ -502,7 +502,7 @@ The build-file template is processed with the perl module
|
|||
Text::Template, using `{-` and `-}` as delimiters that enclose the
|
||||
perl code fragments that generate configuration-dependent content.
|
||||
Those perl fragments have access to all the hash variables from
|
||||
configdata.pm.
|
||||
configdata.pem.
|
||||
|
||||
The build-file template is expected to define at least the following
|
||||
perl functions in a perl code fragment enclosed with `{-` and `-}`.
|
||||
|
|
|
|||
|
|
@ -56,8 +56,13 @@
|
|||
map { platform->sharedname($_) // () }
|
||||
grep { !$unified_info{attributes}->{libraries}->{$_}->{noinst} }
|
||||
@{$unified_info{libraries}};
|
||||
our @install_engines =
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst}
|
||||
&& $unified_info{attributes}->{modules}->{$_}->{engine} }
|
||||
@{$unified_info{modules}};
|
||||
our @install_modules =
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst}
|
||||
&& !$unified_info{attributes}->{modules}->{$_}->{engine}
|
||||
&& !$unified_info{attributes}->{modules}->{$_}->{fips} }
|
||||
@{$unified_info{modules}};
|
||||
our @install_fipsmodules =
|
||||
|
|
@ -104,6 +109,7 @@
|
|||
@{$config{lib_defines}}, @{$config{shared_defines}},
|
||||
@cnf_defines,
|
||||
'OPENSSLDIR="""$(OPENSSLDIR_C)"""',
|
||||
'ENGINESDIR="""$(ENGINESDIR_C)"""',
|
||||
'MODULESDIR="""$(MODULESDIR_C)"""'
|
||||
)
|
||||
. '$(DEFINES)'
|
||||
|
|
@ -347,6 +353,7 @@ GENERATED={- # common0.tmpl provides @generated
|
|||
|
||||
INSTALL_LIBS={- join(", ", map { "-\n\t".$_.".OLB" } @install_libs) -}
|
||||
INSTALL_SHLIBS={- join(", ", map { "-\n\t".$_.".EXE" } @install_shlibs) -}
|
||||
INSTALL_ENGINES={- join(", ", map { "-\n\t".$_.".EXE" } @install_engines) -}
|
||||
INSTALL_MODULES={- join(", ", map { "-\n\t".$_.".EXE" } @install_modules) -}
|
||||
INSTALL_FIPSMODULE={- join(", ", map { "-\n\t".$_.".EXE" } @install_fipsmodules) -}
|
||||
INSTALL_FIPSMODULECONF=[.providers]fipsmodule.cnf
|
||||
|
|
@ -380,6 +387,8 @@ OPENSSLDIR={- catdir($config{openssldir}) or
|
|||
: "SYS\$COMMON:[OPENSSL-COMMON]" -}
|
||||
# The same, but for C
|
||||
OPENSSLDIR_C={- platform->osslprefix() -}DATAROOT:[000000]
|
||||
# Where installed ENGINE modules reside, for C
|
||||
ENGINESDIR_C={- platform->osslprefix() -}ENGINES{- $sover_dirname.$target{pointer_size} -}:
|
||||
# Where modules reside, for C
|
||||
MODULESDIR_C={- platform->osslprefix() -}MODULES{- $target{pointer_size} -}:
|
||||
|
||||
|
|
@ -482,8 +491,6 @@ NODEBUG=@
|
|||
{- dependmagic('build_libs'); -} : build_libs_nodep
|
||||
{- dependmagic('build_modules'); -} : build_modules_nodep
|
||||
{- dependmagic('build_programs'); -} : build_programs_nodep
|
||||
{- dependmagic('build_inst_sw'); -} : build_libs_nodep, build_modules_nodep, build_inst_programs_nodep
|
||||
{- dependmagic('build_inst_programs'); -} : build_inst_programs_nodep
|
||||
|
||||
build_generated_pods : $(GENERATED_PODS)
|
||||
build_docs : build_html_docs
|
||||
|
|
@ -493,7 +500,6 @@ build_generated : $(GENERATED_MANDATORY)
|
|||
build_libs_nodep : $(LIBS), $(SHLIBS)
|
||||
build_modules_nodep : $(MODULES)
|
||||
build_programs_nodep : $(PROGRAMS), $(SCRIPTS)
|
||||
build_inst_programs_nodep : $(INSTALL_PROGRAMS), $(SCRIPTS)
|
||||
|
||||
# Kept around for backward compatibility
|
||||
build_apps build_tests : build_programs
|
||||
|
|
@ -589,10 +595,10 @@ depend : descrip.mms
|
|||
|
||||
# Install helper targets #############################################
|
||||
|
||||
install_sw : install_dev install_modules -
|
||||
install_sw : install_dev install_engines install_modules -
|
||||
install_runtime install_startup install_ivp
|
||||
|
||||
uninstall_sw : uninstall_dev uninstall_modules -
|
||||
uninstall_sw : uninstall_dev uninstall_modules uninstall_engines -
|
||||
uninstall_runtime uninstall_startup uninstall_ivp
|
||||
|
||||
install_docs : install_html_docs
|
||||
|
|
@ -600,7 +606,7 @@ install_docs : install_html_docs
|
|||
uninstall_docs : uninstall_html_docs
|
||||
|
||||
{- output_off() if $disabled{fips}; "" -}
|
||||
install_fips : build_inst_sw $(INSTALL_FIPSMODULECONF)
|
||||
install_fips : build_sw $(INSTALL_FIPSMODULECONF)
|
||||
@ WRITE SYS$OUTPUT "*** Installing FIPS module"
|
||||
- CREATE/DIR ossl_installroot:[MODULES{- $target{pointer_size} -}.'arch']
|
||||
- CREATE/DIR/PROT=(S:RWED,O:RWE,G:RE,W:RE) OSSL_DATAROOT:[000000]
|
||||
|
|
@ -651,6 +657,15 @@ install_dev : check_INSTALLTOP install_runtime_libs
|
|||
map { "COPY/PROT=W:R $_.OLB ossl_installroot:[LIB.'arch']" }
|
||||
@install_libs) -}
|
||||
|
||||
install_engines : check_INSTALLTOP install_runtime_libs build_modules
|
||||
@ {- output_off() unless scalar @install_engines; "" -} !
|
||||
@ WRITE SYS$OUTPUT "*** Installing engines"
|
||||
- CREATE/DIR ossl_installroot:[ENGINES{- $sover_dirname.$target{pointer_size} -}.'arch']
|
||||
{- join("\n ",
|
||||
map { "COPY/PROT=W:RE $_.EXE ossl_installroot:[ENGINES$sover_dirname$target{pointer_size}.'arch']" }
|
||||
@install_engines) -}
|
||||
@ {- output_on() unless scalar @install_engines; "" -} !
|
||||
|
||||
install_modules : check_INSTALLTOP install_runtime_libs build_modules
|
||||
@ {- output_off() unless scalar @install_modules; "" -} !
|
||||
@ WRITE SYS$OUTPUT "*** Installing modules"
|
||||
|
|
@ -672,7 +687,7 @@ install_runtime_libs : check_INSTALLTOP build_libs
|
|||
@install_shlibs) -}
|
||||
@ {- output_on() if $disabled{shared}; "" -} !
|
||||
|
||||
install_programs : check_INSTALLTOP install_runtime_libs build_inst_programs
|
||||
install_programs : check_INSTALLTOP install_runtime_libs build_programs
|
||||
@ {- output_off() if $disabled{apps}; "" -} !
|
||||
@ ! Install the main program
|
||||
- CREATE/DIR ossl_installroot:[EXE.'arch']
|
||||
|
|
@ -932,9 +947,7 @@ EOF
|
|||
} elsif (-f $inprologue) {
|
||||
my $local_scripture .= <<"EOF";
|
||||
$outprologue : $inprologue
|
||||
IF F$SEARCH("$outprologue") .EQS. "" SET FILE/PROT=(O:RWD) $outprologue
|
||||
COPY $inprologue $outprologue
|
||||
SET FILE/PROT=(O:RD) $outprologue
|
||||
EOF
|
||||
$includefile_cache{$outprologue} = $local_scripture;
|
||||
|
||||
|
|
@ -946,9 +959,7 @@ EOF
|
|||
} elsif (-f $inepilogue) {
|
||||
my $local_scripture .= <<"EOF";
|
||||
$outepilogue : $inepilogue
|
||||
IF F$SEARCH("$outepilogue") .EQS. "" SET FILE/PROT=(O:RWD) $outepilogue
|
||||
COPY $inepilogue $outepilogue
|
||||
SET FILE/PROT=(O:RD) $outepilogue
|
||||
EOF
|
||||
$includefile_cache{$outepilogue} = $local_scripture;
|
||||
|
||||
|
|
@ -1102,9 +1113,7 @@ EOF
|
|||
|
||||
return <<"EOF";
|
||||
$args{src} : $gen0 $deps
|
||||
IF F$SEARCH("\$\@") .EQS. "" SET FILE/PROT=(O:RWD) \$\@
|
||||
\$(PERL)$perlmodules $dofile "-o$target{build_file}" $gen0$gen_args > \$\@
|
||||
SET FILE/PROT=(O:RD) \$\@
|
||||
$decc_include_scripture
|
||||
EOF
|
||||
} elsif (grep { $_ eq $gen0 } @{$unified_info{programs}}) {
|
||||
|
|
@ -1467,11 +1476,10 @@ EOF
|
|||
rel2abs($config{builddir}));
|
||||
return <<"EOF";
|
||||
$script : $sources configdata.pm
|
||||
IF F$SEARCH("$script") .EQS. "" SET FILE/PROT=(S:RWED,O:RWED,G:RE,W:RE) $script
|
||||
\$(PERL) "-I\$(BLDDIR)" "-Mconfigdata" $dofile -
|
||||
\$(PERL) "-I\$(BLDDIR)" "-Mconfigdata" $dofile -
|
||||
"-o$target{build_file}" $sources > $script
|
||||
SET FILE/PROT=(S:RWED,O:RE,G:RE,W:RE) $script
|
||||
PURGE $script
|
||||
SET FILE/PROT=(S:RWED,O:RWED,G:RE,W:RE) $script
|
||||
PURGE $script
|
||||
EOF
|
||||
}
|
||||
"" # Important! This becomes part of the template result.
|
||||
|
|
|
|||
|
|
@ -3,15 +3,12 @@
|
|||
##
|
||||
## {- join("\n## ", @autowarntext) -}
|
||||
{-
|
||||
use Time::Piece;
|
||||
|
||||
use OpenSSL::Util;
|
||||
|
||||
our $makedep_scheme = $config{makedep_scheme};
|
||||
our $makedepcmd = platform->makedepcmd();
|
||||
|
||||
sub windowsdll { $config{target} =~ /^(?:Cygwin|mingw)/ }
|
||||
sub run_on_windows { $^O =~ /^(?:cygwin|msys|MSWin32)/ }
|
||||
|
||||
# Shared AIX support is special. We put libcrypto[64].so.ver into
|
||||
# libcrypto.a and use libcrypto_a.a as static one, unless using
|
||||
|
|
@ -73,20 +70,10 @@ OPTIONS={- $config{options} -}
|
|||
CONFIGURE_ARGS=({- join(", ",quotify_l(@{$config{perlargv}})) -})
|
||||
SRCDIR={- $config{sourcedir} -}
|
||||
BLDDIR={- $config{builddir} -}
|
||||
RESULT_D=$(BLDDIR)/test-runs
|
||||
FIPSKEY={- $config{FIPSKEY} -}
|
||||
|
||||
VERSION={- "$config{full_version}" -}
|
||||
VERSION_NUMBER={- "$config{version}" -}
|
||||
RELEASE_DATE={- my $t = localtime;
|
||||
if ($config{"release_date"}) {
|
||||
# Provide the user with a more meaningful error message
|
||||
# than the default internal parsing error from
|
||||
# `Time::Piece->strptime(..)`.
|
||||
eval { $t = Time::Piece->strptime($config{"release_date"}, "%d %b %Y"); } ||
|
||||
die "Parsing \$config{release_date} ('$config{release_date}') failed: $@";
|
||||
}
|
||||
$t->strftime("%Y-%m-%d") -}
|
||||
MAJOR={- $config{major} -}
|
||||
MINOR={- $config{minor} -}
|
||||
SHLIB_VERSION_NUMBER={- $config{shlib_version} -}
|
||||
|
|
@ -185,11 +172,20 @@ INSTALL_SHLIB_INFO={-
|
|||
grep { !$unified_info{attributes}->{libraries}->{$_}->{noinst} }
|
||||
@{$unified_info{libraries}}))
|
||||
-}
|
||||
INSTALL_ENGINES={-
|
||||
join(" \\\n" . ' ' x 16,
|
||||
fill_lines(" ", $COLUMNS - 16,
|
||||
map { platform->dso($_) }
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst}
|
||||
&& $unified_info{attributes}->{modules}->{$_}->{engine} }
|
||||
@{$unified_info{modules}}))
|
||||
-}
|
||||
INSTALL_MODULES={-
|
||||
join(" \\\n" . ' ' x 16,
|
||||
fill_lines(" ", $COLUMNS - 16,
|
||||
map { platform->dso($_) }
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst}
|
||||
&& !$unified_info{attributes}->{modules}->{$_}->{engine}
|
||||
&& !$unified_info{attributes}->{modules}->{$_}->{fips} }
|
||||
@{$unified_info{modules}}))
|
||||
-}
|
||||
|
|
@ -326,6 +322,7 @@ LIBDIR={- our $libdir = $config{libdir};
|
|||
# $(libdir) is chosen to be compatible with the GNU coding standards
|
||||
libdir={- file_name_is_absolute($libdir)
|
||||
? $libdir : '$(INSTALLTOP)/$(LIBDIR)' -}
|
||||
ENGINESDIR=$(libdir)/engines-{- $sover_dirname -}
|
||||
MODULESDIR=$(libdir)/ossl-modules
|
||||
|
||||
# Convenience variable for those who want to set the rpath in shared
|
||||
|
|
@ -442,6 +439,7 @@ LIB_CPPFLAGS={- our $lib_cppflags =
|
|||
join(' ', $lib_cppflags,
|
||||
(map { '-D'.$_ }
|
||||
'OPENSSLDIR="\"$(OPENSSLDIR)\""',
|
||||
'ENGINESDIR="\"$(ENGINESDIR)\""',
|
||||
'MODULESDIR="\"$(MODULESDIR)\""'),
|
||||
'$(CNF_CPPFLAGS)', '$(CPPFLAGS)') -}
|
||||
LIB_CFLAGS={- join(' ', $target{lib_cflags} || (),
|
||||
|
|
@ -504,9 +502,6 @@ BIN_LDFLAGS={- join(' ', $target{bin_lflags} || (),
|
|||
'$(CNF_LDFLAGS)', '$(LDFLAGS)') -}
|
||||
BIN_EX_LIBS=$(CNF_EX_LIBS) $(EX_LIBS)
|
||||
|
||||
CMOCKA_LIBS={- $config{cmocka_libs} // '' -}
|
||||
DETOURS_LIBS={- $config{detours_libs} // '' -}
|
||||
|
||||
# CPPFLAGS_Q is used for one thing only: to build up buildinf.h
|
||||
CPPFLAGS_Q={- $cppflags1 =~ s|([\\"])|\\$1|g;
|
||||
$cppflags2 =~ s|([\\"])|\\$1|g;
|
||||
|
|
@ -535,10 +530,8 @@ LANG=C
|
|||
|
||||
{- dependmagic('build_sw', 'Build all the software (default target)'); -}: build_libs_nodep build_modules_nodep build_programs_nodep link-utils
|
||||
{- dependmagic('build_libs', 'Build the libraries libssl and libcrypto'); -}: build_libs_nodep
|
||||
{- dependmagic('build_modules', 'Build the modules (i.e. providers)'); -}: build_modules_nodep
|
||||
{- dependmagic('build_programs', 'Build the openssl executables, scripts and all other programs as configured (e.g. tests or demos)'); -}: build_programs_nodep
|
||||
{- dependmagic('build_inst_sw', 'Build all the software to be installed'); -}: build_libs_nodep build_modules_nodep build_inst_programs_nodep link-utils
|
||||
{- dependmagic('build_inst_programs', 'Build only the installable openssl executables and scripts'); -}: build_inst_programs_nodep
|
||||
{- dependmagic('build_modules', 'Build the modules (i.e. providers and engines)'); -}: build_modules_nodep
|
||||
{- dependmagic('build_programs', 'Build the openssl executables and scripts'); -}: build_programs_nodep
|
||||
|
||||
all: build_sw {- "build_docs" if !$disabled{docs}; -} ## Build software and documentation
|
||||
debuginfo: $(SHLIBS)
|
||||
|
|
@ -547,9 +540,6 @@ debuginfo: $(SHLIBS)
|
|||
$(OBJCOPY) --strip-debug --add-gnu-debuglink=$$i.debug $$i; \
|
||||
done;
|
||||
|
||||
cov-report: $(SHLIBS)
|
||||
@set -e; gcovr -r . --txt-metric=branch --html --html-details -o openssl-metrics.html
|
||||
|
||||
##@ Documentation
|
||||
build_generated_pods: $(GENERATED_PODS)
|
||||
build_docs: build_man_docs build_html_docs ## Create documentation
|
||||
|
|
@ -560,7 +550,6 @@ build_generated: $(GENERATED_MANDATORY)
|
|||
build_libs_nodep: $(LIBS) {- join(" ",map { platform->sharedlib_simple($_) // platform->sharedlib_import($_) // platform->sharedlib($_) // () } @{$unified_info{libraries}}) -}
|
||||
build_modules_nodep: $(MODULES)
|
||||
build_programs_nodep: $(PROGRAMS) $(SCRIPTS)
|
||||
build_inst_programs_nodep: $(INSTALL_PROGRAMS) $(SCRIPTS)
|
||||
|
||||
# Kept around for backward compatibility
|
||||
build_apps build_tests: build_programs
|
||||
|
|
@ -604,12 +593,6 @@ list-tests: ## List available tests that can be invoked via "make test TESTS=<na
|
|||
|
||||
##@ Workspace cleaning
|
||||
|
||||
cov-clean: ## Remove all coverage data files
|
||||
-find . \( -name '*.gcda' -o -name '*.gcno' \) \! -type d | xargs $(RM)
|
||||
|
||||
cov-reset: ## Remove runtime coverage counters
|
||||
-find . -name '*.gcda' \! -type d | xargs $(RM)
|
||||
|
||||
libclean:
|
||||
@set -e; for s in $(SHLIB_INFO); do \
|
||||
if [ "$$s" = ";" ]; then continue; fi; \
|
||||
|
|
@ -644,32 +627,15 @@ clean: libclean ## Clean the workspace, keep the configuration
|
|||
$(RM) $(MANDOCS7)
|
||||
$(RM) $(PROGRAMS) $(TESTPROGS) $(MODULES) $(FIPSMODULE) $(SCRIPTS)
|
||||
$(RM) $(GENERATED_MANDATORY) $(GENERATED)
|
||||
-find . -name '*{- platform->depext() -}' \! -name '.*' \! -type d -exec $(RM) {} \;
|
||||
-find . -name '*{- platform->objext() -}' \! -name '.*' \! -type d -exec $(RM) {} \;
|
||||
$(RM) core
|
||||
$(RM) tags TAGS doc-nits md-nits
|
||||
$(RM) -r $(RESULT_D)
|
||||
$(RM) -r test/test-runs
|
||||
$(RM) providers/fips*.new
|
||||
# Remove the generated dependency files, object files, and symlinks
|
||||
# in a single pass, avoid descending into submodules.
|
||||
-find . \( -path './cloudflare-quiche' \
|
||||
-o -path './fuzz/corpora' \
|
||||
-o -path './gost-engine' \
|
||||
-o -path './krb5' \
|
||||
-o -path './oqs-provider' \
|
||||
-o -path './pkcs11-provider' \
|
||||
-o -path './pyca-cryptography' \
|
||||
-o -path './python-ecdsa' \
|
||||
-o -path './tlsfuzzer' \
|
||||
-o -path './tlslite-ng' \
|
||||
-o -path './wycheproof' \) \
|
||||
-prune \
|
||||
-o \! -type d \
|
||||
\( -name '*{- platform->depext() -}' \
|
||||
-o -name '*{- platform->objext() -}' \
|
||||
-o -type l \) \
|
||||
\! -name '.*' \
|
||||
-exec $(RM) '{}' +
|
||||
-find . -type l \! -name '.*' -exec $(RM) {} \;
|
||||
|
||||
distclean: clean cov-clean ## Clean and remove the configuration
|
||||
distclean: clean ## Clean and remove the configuration
|
||||
$(RM) include/openssl/configuration.h
|
||||
$(RM) configdata.pm
|
||||
$(RM) Makefile
|
||||
|
|
@ -692,9 +658,9 @@ install: Makefile ## Install software and documentation, create OpenSSL director
|
|||
|
||||
uninstall: {- "uninstall_docs" if !$disabled{docs}; -} uninstall_sw {- $disabled{fips} ? "" : "uninstall_fips" -} ## Uninstall software and documentation
|
||||
|
||||
install_sw: install_dev install_modules install_runtime ## Install just the software and libraries
|
||||
install_sw: install_dev install_engines install_modules install_runtime ## Install just the software and libraries
|
||||
|
||||
uninstall_sw: uninstall_runtime uninstall_modules uninstall_dev ## Uninstall the software and libraries
|
||||
uninstall_sw: uninstall_runtime uninstall_modules uninstall_engines uninstall_dev ## Uninstall the software and libraries
|
||||
|
||||
install_docs: install_man_docs install_html_docs ## Install manpages and HTML documentation
|
||||
|
||||
|
|
@ -702,7 +668,7 @@ uninstall_docs: uninstall_man_docs uninstall_html_docs ## Uninstall manpages and
|
|||
$(RM) -r "$(DESTDIR)$(DOCDIR)"
|
||||
|
||||
{- output_off() if $disabled{fips}; "" -}
|
||||
install_fips: build_inst_sw $(INSTALL_FIPSMODULECONF)
|
||||
install_fips: build_sw $(INSTALL_FIPSMODULECONF)
|
||||
@[ -n "$(INSTALLTOP)" ] || (echo INSTALLTOP should not be empty; exit 1)
|
||||
@$(PERL) $(SRCDIR)/util/mkdir-p.pl "$(DESTDIR)$(MODULESDIR)"
|
||||
@$(PERL) $(SRCDIR)/util/mkdir-p.pl "$(DESTDIR)$(OPENSSLDIR)"
|
||||
|
|
@ -907,11 +873,34 @@ uninstall_dev: uninstall_runtime_libs
|
|||
done
|
||||
-$(RMDIR) "$(DESTDIR)$(PKGCONFIGDIR)"
|
||||
-$(RMDIR) "$(DESTDIR)$(CMAKECONFIGDIR)"
|
||||
-$(RMDIR) "$(DESTDIR)$(libdir)/cmake"
|
||||
-$(RMDIR) "$(DESTDIR)$(libdir)"
|
||||
|
||||
_install_modules_deps: install_runtime_libs build_modules
|
||||
|
||||
install_engines: _install_modules_deps
|
||||
@[ -n "$(INSTALLTOP)" ] || (echo INSTALLTOP should not be empty; exit 1)
|
||||
@$(PERL) $(SRCDIR)/util/mkdir-p.pl "$(DESTDIR)$(ENGINESDIR)/"
|
||||
@$(ECHO) "*** Installing engines"
|
||||
@set -e; for e in dummy $(INSTALL_ENGINES); do \
|
||||
if [ "$$e" = "dummy" ]; then continue; fi; \
|
||||
fn=`basename $$e`; \
|
||||
$(ECHO) "install $$e -> $(DESTDIR)$(ENGINESDIR)/$$fn"; \
|
||||
cp $$e "$(DESTDIR)$(ENGINESDIR)/$$fn.new"; \
|
||||
chmod 755 "$(DESTDIR)$(ENGINESDIR)/$$fn.new"; \
|
||||
mv -f "$(DESTDIR)$(ENGINESDIR)/$$fn.new" \
|
||||
"$(DESTDIR)$(ENGINESDIR)/$$fn"; \
|
||||
done
|
||||
|
||||
uninstall_engines:
|
||||
@$(ECHO) "*** Uninstalling engines"
|
||||
@set -e; for e in dummy $(INSTALL_ENGINES); do \
|
||||
if [ "$$e" = "dummy" ]; then continue; fi; \
|
||||
fn=`basename $$e`; \
|
||||
$(ECHO) "$(RM) $(DESTDIR)$(ENGINESDIR)/$$fn"; \
|
||||
$(RM) "$(DESTDIR)$(ENGINESDIR)/$$fn"; \
|
||||
done
|
||||
-$(RMDIR) "$(DESTDIR)$(ENGINESDIR)"
|
||||
|
||||
install_modules: _install_modules_deps
|
||||
@[ -n "$(INSTALLTOP)" ] || (echo INSTALLTOP should not be empty; exit 1)
|
||||
@$(PERL) $(SRCDIR)/util/mkdir-p.pl "$(DESTDIR)$(MODULESDIR)/"
|
||||
|
|
@ -964,7 +953,7 @@ install_runtime_libs: build_libs
|
|||
: {- output_on() if windowsdll(); "" -}; \
|
||||
done
|
||||
|
||||
install_programs: install_runtime_libs build_inst_programs
|
||||
install_programs: install_runtime_libs build_programs
|
||||
@[ -n "$(INSTALLTOP)" ] || (echo INSTALLTOP should not be empty; exit 1)
|
||||
@$(PERL) $(SRCDIR)/util/mkdir-p.pl "$(DESTDIR)$(bindir)"
|
||||
@$(ECHO) "*** Installing runtime programs"
|
||||
|
|
@ -1188,7 +1177,7 @@ generate_buildinfo: generate_doc_buildinfo
|
|||
|
||||
.PHONY: doc-nits md-nits
|
||||
doc-nits: build_generated_pods ## Evaluate OpenSSL documentation
|
||||
$(PERL) $(SRCDIR)/util/find-doc-nits -c -n -l -e -i -a
|
||||
$(PERL) $(SRCDIR)/util/find-doc-nits -c -n -l -e -i
|
||||
|
||||
# This uses "mdl", the markdownlint application, which is written in ruby.
|
||||
# The source is at https://github.com/markdownlint/markdownlint
|
||||
|
|
@ -1209,18 +1198,10 @@ lint: ## Evaluate C code via "splint"
|
|||
echo splint -DLINT -posixlib -preproc -D__gnuc_va_list=void \
|
||||
-I. -Iinclude -Iapps/include $(CRYPTOHEADERS) $(SSLHEADERS) $(SRCS) )
|
||||
|
||||
CLANG_FORMAT_DIFF = clang-format-diff
|
||||
|
||||
.PHONY: check-format check-clang-format-diff-cmd
|
||||
check-clang-format-diff-cmd:
|
||||
@if ! command -v "$(CLANG_FORMAT_DIFF)" >/dev/null; then \
|
||||
echo "Unable to find ${CLANG_FORMAT_DIFF}";\
|
||||
echo "Please set the CLANG_FORMAT_DIFF variable to your clang-format-diff command";\
|
||||
exit 1;\
|
||||
fi
|
||||
|
||||
check-format: check-clang-format-diff-cmd ## Evaluate C code according to OpenSSL coding standards
|
||||
( cd $(SRCDIR); git diff -U0 --no-prefix --no-color | $(CLANG_FORMAT_DIFF) )
|
||||
.PHONY: check-format
|
||||
check-format: ## Evaluate C code according to OpenSSL coding standards
|
||||
( cd $(SRCDIR); $(PERL) util/check-format.pl \
|
||||
$(SRCS) \$(CRYPTOHEADERS) $(SSLHEADERS) )
|
||||
|
||||
generate_apps:
|
||||
( cd $(SRCDIR); $(PERL) VMS/VMSify-conf.pl \
|
||||
|
|
@ -1317,14 +1298,11 @@ providers/fips.module.sources.new: configdata.pm
|
|||
for x in crypto/bn/asm/*.pl crypto/bn/asm/*.S \
|
||||
crypto/aes/asm/*.pl crypto/aes/asm/*.S \
|
||||
crypto/ec/asm/*.pl \
|
||||
crypto/ml_dsa/asm/*.pl \
|
||||
crypto/ml_kem/asm/*.pl \
|
||||
crypto/modes/asm/*.pl \
|
||||
crypto/sha/asm/*.pl \
|
||||
crypto/slh_dsa/asm/*.pl \
|
||||
crypto/*cpuid.pl crypto/*cpuid.S \
|
||||
crypto/*cap.c; do \
|
||||
test -e "$$x" && echo "$$x"; \
|
||||
echo "$$x"; \
|
||||
done \
|
||||
) | grep -v sm2p256 | sort | uniq > providers/fips.module.sources.new
|
||||
rm -rf sources-tmp
|
||||
|
|
@ -1335,6 +1313,13 @@ errors:
|
|||
( b=`pwd`; set -e; cd $(SRCDIR); \
|
||||
$(PERL) util/ck_errf.pl -strict -internal; \
|
||||
$(PERL) -I$$b util/mkerr.pl $(ERROR_REBUILD) -internal )
|
||||
( b=`pwd`; set -e; cd $(SRCDIR)/engines; \
|
||||
for E in *.ec ; do \
|
||||
$(PERL) ../util/ck_errf.pl -strict \
|
||||
-conf $$E `basename $$E .ec`.c; \
|
||||
$(PERL) -I$$b ../util/mkerr.pl $(ERROR_REBUILD) -static \
|
||||
-conf $$E `basename $$E .ec`.c ; \
|
||||
done )
|
||||
|
||||
{- use File::Basename;
|
||||
|
||||
|
|
@ -1347,8 +1332,7 @@ errors:
|
|||
include/openssl/dtls1.h
|
||||
include/openssl/srtp.h
|
||||
include/openssl/quic.h
|
||||
include/openssl/sslerr_legacy.h
|
||||
include/openssl/ech.h);
|
||||
include/openssl/sslerr_legacy.h );
|
||||
my @cryptoheaders_tmpl =
|
||||
qw( include/internal/dso.h
|
||||
include/internal/o_dir.h
|
||||
|
|
@ -1360,7 +1344,6 @@ errors:
|
|||
my @cryptoskipheaders = ( @sslheaders_tmpl,
|
||||
qw( include/openssl/conf_api.h
|
||||
include/openssl/ebcdic.h
|
||||
include/openssl/engine.h
|
||||
include/openssl/opensslconf.h
|
||||
include/openssl/symhacks.h ) );
|
||||
our %cryptoheaders = ();
|
||||
|
|
@ -1433,10 +1416,10 @@ ordinals: build_generated
|
|||
test_ordinals:
|
||||
"$(MAKE)" run_tests TESTS=test_ordinals
|
||||
|
||||
tags TAGS: FORCE build_generated
|
||||
tags TAGS: FORCE
|
||||
rm -f TAGS tags
|
||||
-( cd $(SRCDIR); util/ctags.sh )
|
||||
-etags `find . -name '*.[ch]' -o -name '*.pm' -o -name '*.inc'`
|
||||
-etags `find . -name '*.[ch]' -o -name '*.pm'`
|
||||
|
||||
providers/fips.checksum.new: providers/fips.module.sources.new
|
||||
@which unifdef > /dev/null || \
|
||||
|
|
@ -1583,24 +1566,11 @@ EOF
|
|||
my $section = $1;
|
||||
my $name = uc basename($args{src}, ".$section");
|
||||
my $pod = $gen0;
|
||||
|
||||
if ($config{manpage_format} eq "mdoc") {
|
||||
return <<"EOF";
|
||||
$args{src}: $pod
|
||||
pod2mdoc -n $name -s $section\$(MANSUFFIX) \\
|
||||
-d \$(RELEASE_DATE) \\
|
||||
$pod >\$\@
|
||||
EOF
|
||||
} elsif ($config{manpage_format} eq "roff") {
|
||||
return <<"EOF";
|
||||
return <<"EOF";
|
||||
$args{src}: $pod
|
||||
pod2man --name=$name --section=$section\$(MANSUFFIX) --center=OpenSSL \\
|
||||
--date=\$(RELEASE_DATE) --release=\$(VERSION) \\
|
||||
$pod >\$\@
|
||||
--release=\$(VERSION) $pod >\$\@
|
||||
EOF
|
||||
} else {
|
||||
die "Unhandled manpage format: $config{manpage_format}";
|
||||
}
|
||||
} elsif (platform->isdef($args{src})) {
|
||||
#
|
||||
# Linker script-ish generator
|
||||
|
|
@ -1695,9 +1665,7 @@ EOF
|
|||
|
||||
return <<"EOF";
|
||||
$args{src}: $gen0 $deps
|
||||
if [ -r "\$@" ]; then chmod u+w \$@; fi
|
||||
\$(PERL)$perlmodules "$dofile" "-o$target{build_file}" $gen0$gen_args > \$@
|
||||
chmod a-w \$@
|
||||
EOF
|
||||
} elsif (grep { $_ eq $gen0 } @{$unified_info{programs}}) {
|
||||
#
|
||||
|
|
@ -1911,27 +1879,13 @@ $import: $full
|
|||
EOF
|
||||
}
|
||||
}
|
||||
if (!run_on_windows()) {
|
||||
$recipe .= <<"EOF";
|
||||
$recipe .= <<"EOF";
|
||||
$full: $fulldeps
|
||||
\$(CC) \$(LIB_CFLAGS) $linkflags\$(LIB_LDFLAGS)$shared_soname$shared_imp \\
|
||||
-o $full$shared_def \\
|
||||
$fullobjs \\
|
||||
$linklibs \$(LIB_EX_LIBS)
|
||||
EOF
|
||||
} else {
|
||||
$recipe .= <<"EOF";
|
||||
$full: $fulldeps
|
||||
\$(file >\$@.lst, \\
|
||||
$fullobjs \\
|
||||
)
|
||||
\$(CC) \$(LIB_CFLAGS) $linkflags\$(LIB_LDFLAGS)$shared_soname$shared_imp \\
|
||||
-o $full$shared_def \\
|
||||
@\$@.lst \\
|
||||
$linklibs \$(LIB_EX_LIBS)
|
||||
rm -f \$@.lst
|
||||
EOF
|
||||
}
|
||||
if (windowsdll()) {
|
||||
$recipe .= <<"EOF";
|
||||
rm -f apps/$full
|
||||
|
|
@ -2036,15 +1990,6 @@ EOF
|
|||
push @linkdirs, $d unless grep { $d eq $_ } @linkdirs;
|
||||
}
|
||||
}
|
||||
my $wrapflags = '';
|
||||
if (defined $unified_info{wraps}->{$args{bin}}) {
|
||||
$wrapflags = ' ' . join(' ',
|
||||
map { "-Wl,--wrap=$_" }
|
||||
@{$unified_info{wraps}->{$args{bin}}});
|
||||
}
|
||||
my $utlibs = $unified_info{unit_test_libs}->{$args{bin}};
|
||||
$utlibs = $utlibs ne '' ? ' ' . $utlibs : '' if defined $utlibs;
|
||||
$utlibs //= '';
|
||||
my $linkflags = join("", map { $_." " } @linkdirs);
|
||||
my $linklibs = join("", map { $_." " } @linklibs);
|
||||
my $cmd = '$(CC)';
|
||||
|
|
@ -2062,10 +2007,10 @@ EOF
|
|||
return <<"EOF";
|
||||
$bin: $deps
|
||||
rm -f $bin
|
||||
\$\${LDCMD:-$cmd} $cmdflags $linkflags\$(BIN_LDFLAGS)$wrapflags \\
|
||||
\$\${LDCMD:-$cmd} $cmdflags $linkflags\$(BIN_LDFLAGS) \\
|
||||
-o $bin \\
|
||||
$objs \\
|
||||
$linklibs\$(BIN_EX_LIBS)$utlibs
|
||||
$linklibs\$(BIN_EX_LIBS)
|
||||
EOF
|
||||
}
|
||||
sub in2script {
|
||||
|
|
@ -2077,11 +2022,10 @@ EOF
|
|||
rel2abs($config{builddir}));
|
||||
return <<"EOF";
|
||||
$script: $sources configdata.pm
|
||||
if [ -r "$script" ]; then chmod u+w $script; fi
|
||||
\$(RM) "$script"
|
||||
\$(PERL) "-I\$(BLDDIR)" -Mconfigdata "$dofile" \\
|
||||
"-o$target{build_file}" $sources > "$script"
|
||||
chmod a+x,a-w $script
|
||||
chmod a+x $script
|
||||
EOF
|
||||
}
|
||||
sub generatedir {
|
||||
|
|
|
|||
|
|
@ -38,7 +38,6 @@
|
|||
PLATFORM={- $config{target} -}
|
||||
SRCDIR={- $config{sourcedir} -}
|
||||
BLDDIR={- $config{builddir} -}
|
||||
RESULT_D=$(BLDDIR)\test-runs
|
||||
FIPSKEY={- $config{FIPSKEY} -}
|
||||
|
||||
VERSION={- "$config{full_version}" -}
|
||||
|
|
@ -102,15 +101,29 @@ INSTALL_SHLIBPDBS={-
|
|||
grep { !$unified_info{attributes}->{libraries}->{$_}->{noinst} }
|
||||
@{$unified_info{libraries}})
|
||||
-}
|
||||
INSTALL_ENGINES={-
|
||||
join(" ", map { quotify1(platform->dso($_)) }
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst}
|
||||
&& $unified_info{attributes}->{modules}->{$_}->{engine} }
|
||||
@{$unified_info{modules}})
|
||||
-}
|
||||
INSTALL_ENGINEPDBS={-
|
||||
join(" ", map { quotify1(platform->dsopdb($_)) }
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst}
|
||||
&& $unified_info{attributes}->{modules}->{$_}->{engine} }
|
||||
@{$unified_info{modules}})
|
||||
-}
|
||||
INSTALL_MODULES={-
|
||||
join(" ", map { quotify1(platform->dso($_)) }
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst}
|
||||
&& !$unified_info{attributes}->{modules}->{$_}->{engine}
|
||||
&& !$unified_info{attributes}->{modules}->{$_}->{fips} }
|
||||
@{$unified_info{modules}})
|
||||
-}
|
||||
INSTALL_MODULEPDBS={-
|
||||
join(" ", map { quotify1(platform->dsopdb($_)) }
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst} }
|
||||
grep { !$unified_info{attributes}->{modules}->{$_}->{noinst}
|
||||
&& !$unified_info{attributes}->{modules}->{$_}->{engine} }
|
||||
@{$unified_info{modules}})
|
||||
-}
|
||||
INSTALL_FIPSMODULE={-
|
||||
|
|
@ -209,7 +222,7 @@ OPENSSLDIR_dir={- canonpath($openssldir_dir) -}
|
|||
LIBDIR={- our $libdir = $config{libdir} || "lib";
|
||||
file_name_is_absolute($libdir) ? "" : $libdir -}
|
||||
MODULESDIR_dev={- use File::Spec::Functions qw(:DEFAULT splitpath catpath);
|
||||
our $modulesprefix = file_name_is_absolute($libdir) ? $libdir : catdir($prefix,$libdir);
|
||||
our $modulesprefix = catdir($prefix,$libdir);
|
||||
our ($modulesprefix_dev, $modulesprefix_dir,
|
||||
$modulesprefix_file) =
|
||||
splitpath($modulesprefix, 1);
|
||||
|
|
@ -217,15 +230,23 @@ MODULESDIR_dev={- use File::Spec::Functions qw(:DEFAULT splitpath catpath);
|
|||
our $modulesdir_dir =
|
||||
catdir($modulesprefix_dir, "ossl-modules");
|
||||
our $modulesdir = catpath($modulesdir_dev, $modulesdir_dir);
|
||||
our $enginesdir_dev = $modulesprefix_dev;
|
||||
our $enginesdir_dir =
|
||||
catdir($modulesprefix_dir, "engines-$sover_dirname");
|
||||
our $enginesdir = catpath($enginesdir_dev, $enginesdir_dir);
|
||||
$modulesdir_dev -}
|
||||
MODULESDIR_dir={- canonpath($modulesdir_dir) -}
|
||||
ENGINESDIR_dev={- $enginesdir_dev -}
|
||||
ENGINESDIR_dir={- canonpath($enginesdir_dir) -}
|
||||
!IF "$(DESTDIR)" != ""
|
||||
INSTALLTOP=$(DESTDIR)$(INSTALLTOP_dir)
|
||||
OPENSSLDIR=$(DESTDIR)$(OPENSSLDIR_dir)
|
||||
ENGINESDIR=$(DESTDIR)$(ENGINESDIR_dir)
|
||||
MODULESDIR=$(DESTDIR)$(MODULESDIR_dir)
|
||||
!ELSE
|
||||
INSTALLTOP=$(INSTALLTOP_dev)$(INSTALLTOP_dir)
|
||||
OPENSSLDIR=$(OPENSSLDIR_dev)$(OPENSSLDIR_dir)
|
||||
ENGINESDIR=$(ENGINESDIR_dev)$(ENGINESDIR_dir)
|
||||
MODULESDIR=$(MODULESDIR_dev)$(MODULESDIR_dir)
|
||||
!ENDIF
|
||||
|
||||
|
|
@ -323,6 +344,7 @@ LIB_CPPFLAGS={- our $lib_cppflags =
|
|||
join(' ', $lib_cppflags,
|
||||
(map { '-D'.quotify1($_) }
|
||||
"OPENSSLDIR=\"$openssldir\"",
|
||||
"ENGINESDIR=\"$enginesdir\"",
|
||||
"MODULESDIR=\"$modulesdir\""),
|
||||
'$(CNF_CPPFLAGS)', '$(CPPFLAGS)') -}
|
||||
LIB_CFLAGS={- join(' ', $target{lib_cflags} || (),
|
||||
|
|
@ -380,9 +402,6 @@ BIN_LDFLAGS={- join(' ', $target{bin_lflags} || (),
|
|||
'$(CNF_LDFLAGS)', '$(LDFLAGS)') -}
|
||||
BIN_EX_LIBS=$(CNF_EX_LIBS) $(EX_LIBS)
|
||||
|
||||
CMOCKA_LIBS={- $config{cmocka_libs} // '' -}
|
||||
DETOURS_LIBS={- $config{detours_libs} // '' -}
|
||||
|
||||
# CPPFLAGS_Q is used for one thing only: to build up buildinf.h
|
||||
CPPFLAGS_Q={- $cppflags1 =~ s|([\\"])|\\$1|g;
|
||||
$cppflags2 =~ s|([\\"])|\\$1|g;
|
||||
|
|
@ -399,8 +418,6 @@ PROCESSOR= {- $config{processor} -}
|
|||
{- dependmagic('build_libs'); -}: build_libs_nodep
|
||||
{- dependmagic('build_modules'); -}: build_modules_nodep
|
||||
{- dependmagic('build_programs'); -}: build_programs_nodep
|
||||
{- dependmagic('build_inst_sw'); -}: build_libs_nodep build_modules_nodep build_inst_programs_nodep copy-utils
|
||||
{- dependmagic('build_inst_programs'); -}: build_inst_programs_nodep
|
||||
|
||||
build_docs: build_html_docs
|
||||
build_html_docs: $(HTMLDOCS1) $(HTMLDOCS3) $(HTMLDOCS5) $(HTMLDOCS7)
|
||||
|
|
@ -413,8 +430,6 @@ build_modules_nodep: $(MODULES)
|
|||
@
|
||||
build_programs_nodep: $(PROGRAMS) $(SCRIPTS)
|
||||
@
|
||||
build_inst_programs_nodep: $(INSTALL_PROGRAMS) $(SCRIPTS)
|
||||
@
|
||||
|
||||
# Kept around for backward compatibility
|
||||
build_apps build_tests: build_programs
|
||||
|
|
@ -453,22 +468,23 @@ uninstall: {- "uninstall_docs" if !$disabled{docs}; -} uninstall_sw {- $disabled
|
|||
|
||||
libclean:
|
||||
"$(PERL)" -e "map { m/(.*)\.dll$$/; unlink glob """{.,apps,test,fuzz}/$$1.*"""; } @ARGV" $(SHLIBS)
|
||||
-del /Q /F $(LIBS) libcrypto.* libssl.*
|
||||
-del /Q /F $(LIBS) libcrypto.* libssl.* ossl_static.pdb
|
||||
|
||||
clean: libclean
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS1) || "\@rem" -}
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS3) || "\@rem" -}
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS5) || "\@rem" -}
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @HTMLDOCS7) || "\@rem" -}
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @PROGRAMS) || "\@rem" -}
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @MODULES) || "\@rem" -}
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @SCRIPTS) || "\@rem" -}
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @GENERATED_MANDATORY) || "\@rem" -}
|
||||
{- join("\n\t", map { "-if exist $_ del /Q /F $_" } @GENERATED) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @HTMLDOCS1) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @HTMLDOCS3) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @HTMLDOCS5) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @HTMLDOCS7) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @PROGRAMS) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @MODULES) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @SCRIPTS) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @GENERATED_MANDATORY) || "\@rem" -}
|
||||
{- join("\n\t", map { "-del /Q /F $_" } @GENERATED) || "\@rem" -}
|
||||
-del /Q /S /F *.d *.obj *.pdb *.ilk *.manifest
|
||||
-del /Q /S /F engines\*.lib engines\*.exp
|
||||
-del /Q /S /F apps\*.lib apps\*.rc apps\*.res apps\*.exp
|
||||
-del /Q /S /F test\*.exp
|
||||
-@if exist "$(RESULT_D)" rd /Q /S "$(RESULT_D)"
|
||||
-rd /Q /S test\test-runs
|
||||
|
||||
distclean: clean
|
||||
-del /Q /F include\openssl\configuration.h
|
||||
|
|
@ -482,16 +498,16 @@ depend: makefile
|
|||
|
||||
# Install helper targets #############################################
|
||||
|
||||
install_sw: install_dev install_modules install_runtime
|
||||
install_sw: install_dev install_engines install_modules install_runtime
|
||||
|
||||
uninstall_sw: uninstall_runtime uninstall_modules uninstall_dev
|
||||
uninstall_sw: uninstall_runtime uninstall_modules uninstall_engines uninstall_dev
|
||||
|
||||
install_docs: install_html_docs
|
||||
|
||||
uninstall_docs: uninstall_html_docs
|
||||
|
||||
{- output_off() if $disabled{fips}; "" -}
|
||||
install_fips: build_inst_sw $(INSTALL_FIPSMODULECONF)
|
||||
install_fips: build_sw $(INSTALL_FIPSMODULECONF)
|
||||
# @[ -n "$(INSTALLTOP)" ] || (echo INSTALLTOP should not be empty; exit 1)
|
||||
@"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(MODULESDIR)"
|
||||
@"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(OPENSSLDIR)"
|
||||
|
|
@ -548,6 +564,8 @@ install_dev: install_runtime_libs
|
|||
"$(INSTALLTOP)\include\openssl"
|
||||
@"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(libdir)"
|
||||
@"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_LIBS) "$(libdir)"
|
||||
@if "$(SHLIBS)"=="" \
|
||||
"$(PERL)" "$(SRCDIR)\util\copy.pl" ossl_static.pdb "$(libdir)"
|
||||
@"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(CMAKECONFIGDIR)"
|
||||
@"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_EXPORTERS_CMAKE) "$(CMAKECONFIGDIR)"
|
||||
|
||||
|
|
@ -555,6 +573,17 @@ uninstall_dev:
|
|||
|
||||
_install_modules_deps: install_runtime_libs build_modules
|
||||
|
||||
install_engines: _install_modules_deps
|
||||
@if "$(INSTALLTOP)"=="" ( $(ECHO) "INSTALLTOP should not be empty" & exit 1 )
|
||||
@$(ECHO) "*** Installing engines"
|
||||
@"$(PERL)" "$(SRCDIR)\util\mkdir-p.pl" "$(ENGINESDIR)"
|
||||
@if not "$(INSTALL_ENGINES)"=="" \
|
||||
"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_ENGINES) "$(ENGINESDIR)"
|
||||
@if not "$(INSTALL_ENGINES)"=="" \
|
||||
"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_ENGINEPDBS) "$(ENGINESDIR)"
|
||||
|
||||
uninstall_engines:
|
||||
|
||||
install_modules: _install_modules_deps
|
||||
@if "$(INSTALLTOP)"=="" ( $(ECHO) "INSTALLTOP should not be empty" & exit 1 )
|
||||
@$(ECHO) "*** Installing modules"
|
||||
|
|
@ -578,7 +607,7 @@ install_runtime_libs: build_libs
|
|||
"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_SHLIBPDBS) \
|
||||
"$(INSTALLTOP)\bin"
|
||||
|
||||
install_programs: install_runtime_libs build_inst_programs
|
||||
install_programs: install_runtime_libs build_programs
|
||||
@if "$(INSTALLTOP)"=="" ( $(ECHO) "INSTALLTOP should not be empty" & exit 1 )
|
||||
@$(ECHO) "*** Installing runtime programs"
|
||||
@if not "$(INSTALL_PROGRAMS)"=="" \
|
||||
|
|
@ -586,10 +615,10 @@ install_programs: install_runtime_libs build_inst_programs
|
|||
@if not "$(INSTALL_PROGRAMS)"=="" \
|
||||
"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_PROGRAMS) \
|
||||
"$(INSTALLTOP)\bin"
|
||||
@if not "$(INSTALL_PROGRAMPDBS)"=="" \
|
||||
@if not "$(INSTALL_PROGRAMS)"=="" \
|
||||
"$(PERL)" "$(SRCDIR)\util\copy.pl" $(INSTALL_PROGRAMPDBS) \
|
||||
"$(INSTALLTOP)\bin"
|
||||
@if not "$(BIN_SCRIPTS)"=="" \
|
||||
@if not "$(INSTALL_PROGRAMS)"=="" \
|
||||
"$(PERL)" "$(SRCDIR)\util\copy.pl" $(BIN_SCRIPTS) \
|
||||
"$(INSTALLTOP)\bin"
|
||||
|
||||
|
|
@ -812,9 +841,7 @@ EOF
|
|||
|
||||
return <<"EOF";
|
||||
$args{src}: "$gen0" $deps
|
||||
if exist \$@ attrib -r \$@
|
||||
"\$(PERL)"$perlmodules "$dofile" "-o$target{build_file}" "$gen0"$gen_args > \$@
|
||||
attrib +r \$@
|
||||
EOF
|
||||
} elsif (grep { $_ eq $gen0 } @{$unified_info{programs}}) {
|
||||
#
|
||||
|
|
@ -1004,14 +1031,11 @@ EOF
|
|||
my $ress = join($target{ld_resp_delim}, @ress);
|
||||
my $linklibs = join("", map { "$_$target{ld_resp_delim}" } @deps);
|
||||
my $deps = join(" ", @objs, @ress, @deps);
|
||||
my $utlibs = $unified_info{unit_test_libs}->{$args{bin}};
|
||||
$utlibs = (defined $utlibs && $utlibs ne '')
|
||||
? "$utlibs$target{ld_resp_delim}" : '';
|
||||
return <<"EOF";
|
||||
$bin: $deps
|
||||
IF EXIST $bin.manifest DEL /F /Q $bin.manifest
|
||||
\$(LD) \$(LDFLAGS) \$(BIN_LDFLAGS) @<<
|
||||
$objs$target{ld_resp_delim}\$(LDOUTFLAG)$bin$target{ldpostoutflag}$target{ld_resp_delim}$utlibs$linklibs\$(BIN_EX_LIBS)$target{ldresflag}$target{ldresflag}$ress
|
||||
$objs$target{ld_resp_delim}\$(LDOUTFLAG)$bin$target{ldpostoutflag}$target{ld_resp_delim}$linklibs\$(BIN_EX_LIBS)$target{ldresflag}$target{ldresflag}$ress
|
||||
<<
|
||||
IF EXIST $bin.manifest \\
|
||||
\$(MT) \$(MTFLAGS) \$(MTINFLAG)$bin.manifest \$(MTOUTFLAG)$bin
|
||||
|
|
@ -1026,10 +1050,8 @@ EOF
|
|||
rel2abs($config{builddir}));
|
||||
return <<"EOF";
|
||||
$script: $sources configdata.pm
|
||||
if exist $script attrib -r $script
|
||||
"\$(PERL)" "-I\$(BLDDIR)" -Mconfigdata "$dofile" \\
|
||||
"-o$target{build_file}" $sources > \$@
|
||||
attrib +r $script
|
||||
EOF
|
||||
}
|
||||
sub generatedir {
|
||||
|
|
|
|||
194
DOCUMENTATION.md
194
DOCUMENTATION.md
|
|
@ -1,194 +0,0 @@
|
|||
OpenSSL Documentation Policy
|
||||
============================
|
||||
|
||||
This document describes the code documentation and commenting requirements
|
||||
for the OpenSSL project.
|
||||
|
||||
The project's documentation is about making the libraries and tools more
|
||||
accessible to our users and making the code more maintainable. This policy
|
||||
applies to new submissions; existing code does not uniformly conform to it
|
||||
and will be brought up to standard gradually.
|
||||
|
||||
Any non-trivial change to existing code must bring the affected code into
|
||||
conformance with this policy as part of the same change. In particular,
|
||||
renaming or relocating functions, changes to public APIs, and any change
|
||||
that would render an existing POD page or in-source comment inaccurate
|
||||
require the corresponding documentation to be updated. This includes
|
||||
adding documentation that was previously absent where the change brings
|
||||
the affected code within the scope of this policy.
|
||||
|
||||
The form and style of code comments themselves -- comment markers, layout,
|
||||
the use of `/**` and `/*-` blocks, doxygen markup, the structure of the
|
||||
sample multi-line comment, and similar -- are described in
|
||||
[STYLE.md](STYLE.md). This file describes what *must* be documented and
|
||||
where; [STYLE.md](STYLE.md) describes how code comments look.
|
||||
|
||||
Command line commands and arguments
|
||||
-----------------------------------
|
||||
|
||||
All new commands, as well as new or modified arguments to existing
|
||||
commands, must be documented in the `doc/man1` directory. This
|
||||
documentation is in POD format.
|
||||
|
||||
Public symbols in the libraries
|
||||
-------------------------------
|
||||
|
||||
All new public symbols must be documented in a POD manual page in the
|
||||
`doc/man3` directory. This includes types, macros, and functions.
|
||||
|
||||
The allowed exceptions are:
|
||||
|
||||
- guard macros preventing a header file being included twice
|
||||
- new symbols generated automatically via `make update` (errors, objects, etc.)
|
||||
|
||||
Each public function's declaration in its public header must carry a
|
||||
doxygen comment block. The block's `@see` must include the function's
|
||||
own manual page (`name(3)`) and may include additional manual pages
|
||||
that a caller needs to use the function correctly. The doxygen block
|
||||
is a navigation aid pointing to the canonical reference documentation
|
||||
in the corresponding POD file; see [STYLE.md](STYLE.md) for the
|
||||
doxygen form.
|
||||
|
||||
Overviews, conventions, et al
|
||||
-----------------------------
|
||||
|
||||
Where additional user-facing information is required, it should be
|
||||
included in the `doc/man7` section. This includes, but is not limited to:
|
||||
|
||||
- algorithm descriptions and parameters
|
||||
- architectural and subsystem overviews
|
||||
- user guides and tutorials
|
||||
- conventions and reference material (environment variables, glossary,
|
||||
threading rules, file format conventions)
|
||||
|
||||
Internal functions, structures, globals and macros
|
||||
--------------------------------------------------
|
||||
|
||||
Internal functions, structures, globals and macros are non-public
|
||||
items declared in any header that is not part of the public API.
|
||||
These include items declared in:
|
||||
|
||||
- `include/internal/` (shared across subsystems);
|
||||
- `include/crypto/` (cryptographic internals);
|
||||
- per-directory local headers (for example, `crypto/asn1/asn1_local.h`)
|
||||
shared between source files in a single subdirectory.
|
||||
|
||||
These should all be documented at the declaration site -- that is,
|
||||
in the header that declares them -- using a doxygen-style comment
|
||||
block. For functions, this places the comment at the prototype,
|
||||
where editor tooling (clangd and similar) can surface it to readers
|
||||
at every call site. The comment should describe the purpose and,
|
||||
for functions, the input and output arguments and the return value.
|
||||
See [STYLE.md](STYLE.md) for the doxygen conventions used by OpenSSL.
|
||||
|
||||
For *trivial* items, where their operation is obvious from their
|
||||
implementation, the documentation requirement is not mandated. The
|
||||
following are generally representative of trivial items, however it is
|
||||
quite possible for any of these to be non-trivial in specific instances
|
||||
and therefore require documentation:
|
||||
|
||||
- `OSSL_DISPATCH` tables
|
||||
- upref functions
|
||||
- free functions
|
||||
- simple getter/setter functions
|
||||
- wrappers for other functions (a function that calls a more recent
|
||||
`_ex` variant or a group of functions that call a common internal
|
||||
routine)
|
||||
|
||||
For structures, each of the fields should be commented stating its
|
||||
purpose. Again, a *trivial* exception applies where the purpose is
|
||||
obvious. Some representative examples:
|
||||
|
||||
- `OSSL_LIB_CTX *ctx;` where there is only one library context referenced
|
||||
in the structure.
|
||||
- `struct *next;` in a linked list implementation.
|
||||
- `CRYPTO_REF_COUNT refcnt;`
|
||||
|
||||
File-local items
|
||||
----------------
|
||||
|
||||
These are functions, structures, globals, and macros that are local
|
||||
to a single C file: `static` functions, file-scope variables,
|
||||
structures, and macros defined inside a `.c` file with no declaration
|
||||
in any header.
|
||||
|
||||
These should all be documented at the point of definition. Follow the
|
||||
same rules and exceptions as for internal items above. In some cases
|
||||
slightly more leniency with respect to *trivial* can be tolerated.
|
||||
|
||||
Code comments
|
||||
-------------
|
||||
|
||||
The form, style, and content guidance for code comments are described in
|
||||
[STYLE.md](STYLE.md). Comments are required at the points described in
|
||||
the internal and static sections above, subject to the *trivial*
|
||||
exception, and at the additional points described in
|
||||
[STYLE.md](STYLE.md).
|
||||
|
||||
Assembly code
|
||||
-------------
|
||||
|
||||
Assembly code should include a good description of the algorithm and
|
||||
approach being used. This should be followed by a performance comparison
|
||||
and then the assembly code itself. The assembly code should be well
|
||||
commented, but it is not necessary to comment every line. A comment
|
||||
describing each block of code suffices.
|
||||
|
||||
For pure-assembly modules (`.s` files and the perlasm scripts that
|
||||
generate them), comments use the native syntax of the assembler or
|
||||
generator (typically `#`). Doxygen-style markup does not apply here;
|
||||
the algorithm description, performance comparison, and per-block
|
||||
comments described above are still required.
|
||||
|
||||
For assembly that appears inline inside a C file (within an `asm()`
|
||||
statement, for example), the surrounding C function is documented
|
||||
with doxygen-style C comments as for any other C code; see
|
||||
[STYLE.md](STYLE.md). Comments inside the `asm()` body itself use
|
||||
plain C `/* */` comments.
|
||||
|
||||
There are no *trivial* exceptions for assembly code.
|
||||
|
||||
Configure options
|
||||
-----------------
|
||||
|
||||
New options added to the configuration scripts must be documented in the
|
||||
[INSTALL.md](INSTALL.md) file.
|
||||
|
||||
Changes and news
|
||||
----------------
|
||||
|
||||
Significant modifications should be documented in the
|
||||
[CHANGES.md](CHANGES.md) file.
|
||||
|
||||
Very significant features and changes should be documented in the
|
||||
[NEWS.md](NEWS.md) file.
|
||||
|
||||
In both cases, the added note should be short and to the point, and
|
||||
should be written for users of the library, focusing on impact rather
|
||||
than implementation details.
|
||||
|
||||
Automated sanity checking
|
||||
-------------------------
|
||||
|
||||
The `make doc-nits` command should be run before submitting a pull
|
||||
request and any problems it locates must be addressed.
|
||||
|
||||
Language
|
||||
--------
|
||||
|
||||
The language used for documentation shall be *British English*.
|
||||
|
||||
In general the language, abbreviations, layout and formatting should also
|
||||
correspond to the
|
||||
[LDP](https://openssl-library.org/policies/general/glossary/#ldp)
|
||||
guidelines.
|
||||
|
||||
Common sense
|
||||
------------
|
||||
|
||||
Comments and documentation are to improve readability and comprehension.
|
||||
Where the code is obvious, there is no need to include a comment.
|
||||
However, common sense applies: always err in favour of including more
|
||||
comments than less or none. Code that you have just written that is
|
||||
*obvious* will not necessarily be to someone else two years later. See
|
||||
[STYLE.md](STYLE.md) for the form and content of code comments.
|
||||
33
HACKING.md
Normal file
33
HACKING.md
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
MODIFYING OPENSSL SOURCE
|
||||
========================
|
||||
|
||||
This document describes the way to add custom modifications to OpenSSL sources.
|
||||
|
||||
If you are adding new public functions to the custom library build, you need to
|
||||
either add a prototype in one of the existing OpenSSL header files;
|
||||
or provide a new header file and edit
|
||||
[Configurations/unix-Makefile.tmpl](Configurations/unix-Makefile.tmpl)
|
||||
to pick up that file.
|
||||
|
||||
After that, perform the following steps:
|
||||
|
||||
./Configure -Werror --strict-warnings [your-options]
|
||||
make update
|
||||
make
|
||||
make test
|
||||
|
||||
`make update` ensures that your functions declarations are added to
|
||||
`util/libcrypto.num` or `util/libssl.num`.
|
||||
If you plan to submit the changes you made to OpenSSL
|
||||
(see [CONTRIBUTING.md](CONTRIBUTING.md)), it's worth running:
|
||||
|
||||
make doc-nits
|
||||
|
||||
after running `make update` to ensure that documentation has correct format.
|
||||
|
||||
`make update` also generates files related to OIDs (in the `crypto/objects/`
|
||||
folder) and errors.
|
||||
If a merge error occurs in one of these generated files, then the
|
||||
generated files need to be removed and regenerated using `make update`.
|
||||
To aid in this process, the generated files can be committed separately
|
||||
so they can be removed easily.
|
||||
8
HOWTO.md
8
HOWTO.md
|
|
@ -1,8 +0,0 @@
|
|||
MODIFYING OPENSSL SOURCE
|
||||
========================
|
||||
|
||||
This is a collection of pointers to parts of the documentation that will help
|
||||
people doing modifications.
|
||||
|
||||
* [doc/HOWTO/adding-functions.md](Adding new Functions)
|
||||
* [doc/HOWTO/documenting-functions-macros.md](Documenting Functions and Macros)
|
||||
247
INSTALL.md
247
INSTALL.md
|
|
@ -51,7 +51,7 @@ To install OpenSSL, you will need:
|
|||
* A "make" implementation
|
||||
* Perl 5 with core modules (please read [NOTES-PERL.md](NOTES-PERL.md))
|
||||
* The Perl module `Text::Template` (please read [NOTES-PERL.md](NOTES-PERL.md))
|
||||
* a C-99 compiler
|
||||
* an ANSI C compiler
|
||||
* POSIX C library (at least POSIX.1-2008), or compatible types and
|
||||
functionality.
|
||||
* a development environment in the form of development libraries and C
|
||||
|
|
@ -169,11 +169,13 @@ issue the following commands to build OpenSSL.
|
|||
$ nmake test
|
||||
|
||||
As mentioned in the [Choices](#choices) section, you need to pick one
|
||||
of the Configure targets in the first command.
|
||||
of the four Configure targets in the first command.
|
||||
|
||||
Most likely you will be using the `VC-WIN64A`/`VC-WIN64A-HYBRIDCRT` target for
|
||||
64bit Windows binaries (AMD64) or `VC-WIN32`/`VC-WIN32-HYBRIDCRT` for 32bit
|
||||
Windows binaries (X86).
|
||||
The other two options are `VC-WIN64I` (Intel IA64, Itanium) and
|
||||
`VC-CE` (Windows CE) are rather uncommon nowadays.
|
||||
|
||||
Installing OpenSSL
|
||||
------------------
|
||||
|
|
@ -333,14 +335,6 @@ Build OpenSSL with debugging symbols and zero optimization level.
|
|||
|
||||
Build OpenSSL without debugging symbols. This is the default.
|
||||
|
||||
--coverage
|
||||
|
||||
Build OpenSSL with gcov profiling information included
|
||||
|
||||
--pgo
|
||||
|
||||
Build OpenSSL optimized using gcov data obtained from --coverage build
|
||||
|
||||
Directories
|
||||
-----------
|
||||
|
||||
|
|
@ -426,22 +420,6 @@ The names of the libraries are:
|
|||
* brotlidec.lib
|
||||
* brotlienc.lib
|
||||
|
||||
### with-cmocka-include
|
||||
|
||||
--with-cmocka-include=DIR
|
||||
|
||||
The directory for the location of the cmocka include file. This option is only
|
||||
necessary if [enable-unit-tests](#enable-unit-tests) is used and the include
|
||||
file is not already on the system include path.
|
||||
|
||||
### with-cmocka-lib
|
||||
|
||||
--with-cmocka-lib=DIR
|
||||
|
||||
The directory containing the cmocka library. This option is only necessary if
|
||||
[enable-unit-tests](#enable-unit-tests) is used and the library is not already
|
||||
on the system library path.
|
||||
|
||||
### with-zlib-include
|
||||
|
||||
--with-zlib-include=DIR
|
||||
|
|
@ -598,14 +576,11 @@ In the following list, always the non-default variant is documented: if
|
|||
feature `xxxx` is disabled by default then `enable-xxxx` is documented and
|
||||
if feature `xxxx` is enabled by default then `no-xxxx` is documented.
|
||||
|
||||
### enable-static-vcruntime
|
||||
### no-afalgeng
|
||||
|
||||
Build binaries that do not require that VC runtimes are installed
|
||||
Don't build the AFALG engine.
|
||||
|
||||
This option will produce binaries that are "self contained", that do not
|
||||
depend upon VC runtime libraries being installed, so can be used on any
|
||||
computer running MS Windows. Without this option, the build will produce
|
||||
binaries that rely on the VC runtimes being installed and available.
|
||||
This option will be forced on a platform that does not support AFALG.
|
||||
|
||||
### enable-ktls
|
||||
|
||||
|
|
@ -657,10 +632,9 @@ Do not build support for async operations.
|
|||
|
||||
Do not use `atexit()` in libcrypto builds.
|
||||
|
||||
Before version 4.0, OpenSSL used to set `atexit()` handler for cleaning up
|
||||
global data, and this option allowed to disable that functionality. `atexit()`
|
||||
handler setup was removed in OpenSSL 4.0, so `no-atexit` option is retained
|
||||
for compatibility reasons only, always present, and does nothing.
|
||||
`atexit()` has varied semantics between platforms and can cause SIGSEGV in some
|
||||
circumstances. This option disables the atexit registration of OPENSSL_cleanup.
|
||||
By default, NonStop configurations use `no-atexit`.
|
||||
|
||||
### no-autoalginit
|
||||
|
||||
|
|
@ -733,6 +707,12 @@ this option will reduce run-time memory usage but it also introduces a
|
|||
significant performance penalty. This option is primarily designed to help
|
||||
with detecting incorrect reference counting.
|
||||
|
||||
### no-capieng
|
||||
|
||||
Don't build the CAPI engine.
|
||||
|
||||
This option will be forced if on a platform that does not support CAPI.
|
||||
|
||||
### no-cmp
|
||||
|
||||
Don't build support for Certificate Management Protocol (CMP)
|
||||
|
|
@ -753,10 +733,9 @@ the zlib or `zlib-dynamic` options are also chosen.
|
|||
|
||||
This now only enables the `failed-malloc` feature.
|
||||
|
||||
### enable-allocfail-tests
|
||||
### enable-crypto-mdebug-backtrace
|
||||
|
||||
This option enables testing that leverages the use of the crypto-mdebug feature
|
||||
to test error paths resulting from failed memory allocations.
|
||||
This is a no-op; the project uses the compiler's address/leak sanitizer instead.
|
||||
|
||||
### no-ct
|
||||
|
||||
|
|
@ -781,22 +760,33 @@ Don't build and install documentation, i.e. manual pages in various forms.
|
|||
|
||||
Don't build support for loading Dynamic Shared Objects (DSO)
|
||||
|
||||
### enable-tls-deprecated-ec
|
||||
### enable-devcryptoeng
|
||||
|
||||
Enable legacy TLS EC groups that were deprecated in RFC8422. These are the
|
||||
Build the `/dev/crypto` engine.
|
||||
|
||||
This option is automatically selected on the BSD platform, in which case it can
|
||||
be disabled with `no-devcryptoeng`.
|
||||
|
||||
### no-dynamic-engine
|
||||
|
||||
Don't build the dynamically loaded engines.
|
||||
|
||||
This only has an effect in a shared build.
|
||||
|
||||
### no-ec
|
||||
|
||||
Don't build support for Elliptic Curves.
|
||||
|
||||
### no-ec2m
|
||||
|
||||
Don't build support for binary Elliptic Curves
|
||||
|
||||
### no-tls-deprecated-ec
|
||||
|
||||
Disable legacy TLS EC groups that were deprecated in RFC8422. These are the
|
||||
Koblitz curves, B<secp160r1>, B<secp160r2>, B<secp192r1>, B<secp224r1>, and the
|
||||
binary Elliptic curves that would also be disabled by C<no-ec2m>.
|
||||
|
||||
### enable-ec_expicit_curves
|
||||
|
||||
Enable support for explictitly specified elliptic curves not matching the
|
||||
well-known ones. Until this option is on, such curves can't be instantiated
|
||||
from ASN.1 formats.
|
||||
|
||||
### no-ech
|
||||
|
||||
Don't build support for Encrypted Client Hello (ECH) extension.
|
||||
|
||||
### enable-ec_nistp_64_gcc_128
|
||||
|
||||
Enable support for optimised implementations of some commonly used NIST
|
||||
|
|
@ -814,6 +804,10 @@ This option is only supported on platforms:
|
|||
|
||||
Build support for gathering entropy from the Entropy Gathering Daemon (EGD).
|
||||
|
||||
### no-engine
|
||||
|
||||
Don't build support for loading engines.
|
||||
|
||||
### no-err
|
||||
|
||||
Don't compile in any error strings.
|
||||
|
|
@ -832,12 +826,6 @@ external test suites are currently supported:
|
|||
See the file [test/README-external.md](test/README-external.md)
|
||||
for further details.
|
||||
|
||||
### enable-unit-tests
|
||||
|
||||
Enable building and running unit tests.
|
||||
|
||||
This works only on platforms supporting ld `--wrap` option like Linux and BSD.
|
||||
|
||||
### no-filenames
|
||||
|
||||
Don't compile in filename and line number information (e.g. for errors and
|
||||
|
|
@ -889,13 +877,6 @@ Note that if this feature is enabled then GOST ciphersuites are only available
|
|||
if the GOST algorithms are also available through loading an externally supplied
|
||||
engine.
|
||||
|
||||
### no-engine, no-static-engine, no-dynamic-engine
|
||||
|
||||
The `no-engine` option is always present. These options are deprecated and do
|
||||
nothing, and are retained for backwards compatibility only. The ENGINE API was
|
||||
deprecated in OpenSSL 3.0 and removed in OpenSSL 4.0, so applications should
|
||||
transition to using providers instead.
|
||||
|
||||
### no-http
|
||||
|
||||
Disable HTTP support.
|
||||
|
|
@ -910,9 +891,21 @@ Disabling this also disables the legacy algorithms: MD2 (already disabled by def
|
|||
|
||||
Don't generate dependencies.
|
||||
|
||||
### no-ml-dsa
|
||||
|
||||
Disable Module-Lattice-Based Digital Signature Standard (ML-DSA) support.
|
||||
ML-DSA is based on CRYSTALS-DILITHIUM. See [FIPS 204].
|
||||
|
||||
### no-ml-kem
|
||||
|
||||
Disable Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)
|
||||
support. ML-KEM is based on CRYSTALS-KYBER. See [FIPS 203].
|
||||
|
||||
### no-module
|
||||
|
||||
Don't build any dynamically loadable modules.
|
||||
Don't build any dynamically loadable engines.
|
||||
|
||||
This also implies `no-dynamic-engine`.
|
||||
|
||||
### no-multiblock
|
||||
|
||||
|
|
@ -928,6 +921,14 @@ Don't build support for the Next Protocol Negotiation (NPN) TLS extension.
|
|||
|
||||
Don't build support for Online Certificate Status Protocol (OCSP).
|
||||
|
||||
### no-padlockeng
|
||||
|
||||
Don't build the padlock engine.
|
||||
|
||||
### no-hw-padlock
|
||||
|
||||
As synonym for `no-padlockeng`. Deprecated and should not be used.
|
||||
|
||||
### no-pic
|
||||
|
||||
Don't build with support for Position Independent Code.
|
||||
|
|
@ -940,17 +941,17 @@ Build with support for Position Independent Execution.
|
|||
|
||||
Don't pin the shared libraries.
|
||||
|
||||
By default, on supported platforms (such as Linux and GNU Hurd), OpenSSL
|
||||
is built with linker options (e.g., `-Wl,-znodelete`) that prevent the
|
||||
operating system from unloading the libcrypto and libssl shared libraries
|
||||
from memory, even if the application explicitly unloads them using
|
||||
`dlclose()`. On platforms that do not support these options, this feature
|
||||
is disabled by default.
|
||||
By default OpenSSL will attempt to stay in memory until the process exits.
|
||||
This is so that libcrypto and libssl can be properly cleaned up automatically
|
||||
via an `atexit()` handler. The handler is registered by libcrypto and cleans
|
||||
up both libraries. On some platforms the `atexit()` handler will run on unload of
|
||||
libcrypto (if it has been dynamically loaded) rather than at process exit.
|
||||
|
||||
This option prevents the addition of those linker flags, allowing the
|
||||
shared libraries to be completely unloaded from the process address space.
|
||||
This is useful for applications that dynamically load and unload OpenSSL
|
||||
plugins to conserve memory.
|
||||
This option can be used to stop OpenSSL from attempting to stay in memory until the
|
||||
process exits. This could lead to crashes if either libcrypto or libssl have
|
||||
already been unloaded at the point that the atexit handler is invoked, e.g. on a
|
||||
platform which calls `atexit()` on unload of the library, and libssl is unloaded
|
||||
before libcrypto then a crash is likely to happen.
|
||||
|
||||
Note that shared library pinning is not automatically disabled for static builds,
|
||||
i.e., `no-shared` does not imply `no-pinshared`. This may come as a surprise when
|
||||
|
|
@ -958,6 +959,10 @@ linking libcrypto statically into a shared third-party library, because in this
|
|||
case the shared library will be pinned. To prevent this behaviour, you need to
|
||||
configure the static build using `no-shared` and `no-pinshared` together.
|
||||
|
||||
Applications can suppress running of the `atexit()` handler at run time by
|
||||
using the `OPENSSL_INIT_NO_ATEXIT` option to `OPENSSL_init_crypto()`.
|
||||
See the man page for it for further details.
|
||||
|
||||
### no-posix-io
|
||||
|
||||
Don't use POSIX IO capabilities.
|
||||
|
|
@ -985,6 +990,11 @@ Do not create shared libraries, only static ones.
|
|||
|
||||
See [Notes on shared libraries](#notes-on-shared-libraries) below.
|
||||
|
||||
### no-slh-dsa
|
||||
|
||||
Disable Stateless Hash Based Digital Signature Standard support.
|
||||
(SLH-DSA is based on SPHINCS+. See [FIPS 205])
|
||||
|
||||
### no-sm2-precomp
|
||||
|
||||
Disable using the SM2 precomputed table on aarch64 to make the library smaller.
|
||||
|
|
@ -1025,6 +1035,12 @@ This removes the `-trace` option from `s_client` and `s_server`, and omits the
|
|||
|
||||
Disabling `ssl-trace` may provide a small reduction in libssl binary size.
|
||||
|
||||
### no-static-engine
|
||||
|
||||
Don't build the statically linked engines.
|
||||
|
||||
This only has an impact when not built "shared".
|
||||
|
||||
### no-stdio
|
||||
|
||||
Don't use anything from the C header file `stdio.h` that makes use of the `FILE`
|
||||
|
|
@ -1115,12 +1131,10 @@ The User Interface console method enables text based console prompts.
|
|||
|
||||
### enable-unit-test
|
||||
|
||||
Enable exposing SSL_test_functions for overwriting ssl_init_wbio_buffer.
|
||||
Enable additional unit test APIs.
|
||||
|
||||
This should not typically be used in production deployments.
|
||||
|
||||
This option is deprecated and will be removed in OpenSSL 5.0.
|
||||
|
||||
### no-uplink
|
||||
|
||||
Don't build support for UPLINK interface.
|
||||
|
|
@ -1177,8 +1191,8 @@ Don't build support for negotiating the specified SSL/TLS protocol.
|
|||
|
||||
If `no-tls` is selected then all of `tls1`, `tls1_1`, `tls1_2` and `tls1_3`
|
||||
are disabled.
|
||||
Similarly `no-dtls` will disable `dtls1` and `dtls1_2`.
|
||||
`no-ssl` and `no-ssl3` are deprecated and do nothing.
|
||||
Similarly `no-dtls` will disable `dtls1` and `dtls1_2`. The `no-ssl` option is
|
||||
synonymous with `no-ssl3`. Note this only affects version negotiation.
|
||||
OpenSSL will still provide the methods for applications to explicitly select
|
||||
the individual protocol versions.
|
||||
|
||||
|
|
@ -1194,37 +1208,28 @@ Analogous to `no-{protocol}` but in addition do not build the methods for
|
|||
applications to explicitly select individual protocol versions. Note that there
|
||||
is no `no-tls1_3-method` option because there is no application method for
|
||||
TLSv1.3.
|
||||
`no-ssl3` is deprecated and does nothing.
|
||||
|
||||
Using individual protocol methods directly is deprecated. Applications should
|
||||
use `TLS_method()` instead.
|
||||
|
||||
### enable-{algorithm}
|
||||
|
||||
enable-{md2|rc5|lms}
|
||||
enable-{md2|rc5}
|
||||
|
||||
Build with support for the specified algorithm.
|
||||
|
||||
The `lms` algorithm support is currently limited to verification only as per
|
||||
[SP 800-208](https://csrc.nist.gov/pubs/sp/800/208/final).
|
||||
|
||||
### no-{algorithm}
|
||||
|
||||
no-{aria|bf|blake2|camellia|cast|chacha|cmac|
|
||||
des|dh|dsa|
|
||||
ec|ec2m|ecdh|ecdsa|hmac-drbg-kdf|idea|ikev2kdf|kbkdf|krb5kdf|
|
||||
md4|mdc2|
|
||||
ml-dsa|ml-kem|
|
||||
ocb|poly1305|pvkkdf|rc2|rc4|rmd160|scrypt|
|
||||
seed|siphash|siv|slh-dsa|sm2|sm3|sm4|snmpkdf|srtpkdf|sshkdf|sskdf|
|
||||
x942kdf|x963kdf|whirlpool}
|
||||
des|dh|dsa|ecdh|ecdsa|idea|md4|mdc2|ml-dsa|
|
||||
ml-kem|ocb|poly1305|rc2|rc4|rmd160|scrypt|
|
||||
seed|siphash|siv|sm2|sm3|sm4|whirlpool}
|
||||
|
||||
Build without support for the specified algorithm.
|
||||
|
||||
The `ripemd` algorithm is deprecated and if used is synonymous with `rmd160`.
|
||||
|
||||
Compiler-specific options
|
||||
-------------------------
|
||||
### Compiler-specific options
|
||||
|
||||
-Dxxx, -Ixxx, -Wp, -lxxx, -Lxxx, -Wl, -rpath, -R, -framework, -static
|
||||
|
||||
|
|
@ -1255,17 +1260,7 @@ encoding.
|
|||
Take note of the [Environment Variables](#environment-variables) documentation
|
||||
below and how these flags interact with those variables.
|
||||
|
||||
Miscellaneous options
|
||||
---------------------
|
||||
|
||||
### --manpage-format
|
||||
|
||||
Specify a specific output manpage format. The supported output types are mandoc
|
||||
and *roff. The *roff output format is the default for legacy and portability
|
||||
reasons.
|
||||
|
||||
Environment Variables
|
||||
---------------------
|
||||
### Environment Variables
|
||||
|
||||
VAR=value
|
||||
|
||||
|
|
@ -1342,18 +1337,10 @@ If `CC` is set, it is advisable to also set `CXX` to ensure both the C and C++
|
|||
compiler are in the same "family". This becomes relevant with
|
||||
`enable-external-tests` and `enable-buildtest-c++`.
|
||||
|
||||
Reconfigure
|
||||
-----------
|
||||
### Reconfigure
|
||||
|
||||
### Make targets
|
||||
|
||||
`$ make reconf`
|
||||
|
||||
or
|
||||
|
||||
`$ make reconfigure`
|
||||
|
||||
### Description
|
||||
reconf
|
||||
reconfigure
|
||||
|
||||
Reconfigure from earlier data.
|
||||
|
||||
|
|
@ -1542,6 +1529,7 @@ its default):
|
|||
to build your own programs that use libcrypto
|
||||
or libssl.
|
||||
lib Contains the OpenSSL library files.
|
||||
lib/engines Contains the OpenSSL dynamically loadable engines.
|
||||
|
||||
share/man/man1 Contains the OpenSSL command line man-pages.
|
||||
share/man/man3 Contains the OpenSSL library calls man-pages.
|
||||
|
|
@ -1567,6 +1555,8 @@ its default):
|
|||
to build your own programs that use libcrypto
|
||||
or libssl.
|
||||
[.LIB.'arch'] Contains the OpenSSL library files.
|
||||
[.ENGINES'sover''pz'.'arch']
|
||||
Contains the OpenSSL dynamically loadable engines.
|
||||
[.SYS$STARTUP] Contains startup, login and shutdown scripts.
|
||||
These define appropriate logical names and
|
||||
command symbols.
|
||||
|
|
@ -1587,7 +1577,7 @@ for you convenience:
|
|||
|
||||
The installation directory should be appropriately protected to ensure
|
||||
unprivileged users cannot make changes to OpenSSL binaries or files, or
|
||||
install providers. If you already have a pre-installed version of OpenSSL as
|
||||
install engines. If you already have a pre-installed version of OpenSSL as
|
||||
part of your Operating System it is recommended that you do not overwrite
|
||||
the system version and instead install to somewhere else.
|
||||
|
||||
|
|
@ -1971,8 +1961,9 @@ on Cygwin, shared libraries are named `cygcrypto-1.1.dll` and `cygssl-1.1.dll`
|
|||
with import libraries `libcrypto.dll.a` and `libssl.dll.a`.
|
||||
|
||||
On Windows build with MSVC or using MingW, shared libraries are named
|
||||
`libcrypto-1_1.dll` and `libssl-1_1.dll` for 32-bit Windows, and
|
||||
`libcrypto-1_1-x64.dll` and `libssl-1_1-x64.dll` for 64-bit x86_64 Windows.
|
||||
`libcrypto-1_1.dll` and `libssl-1_1.dll` for 32-bit Windows,
|
||||
`libcrypto-1_1-x64.dll` and `libssl-1_1-x64.dll` for 64-bit x86_64 Windows,
|
||||
and `libcrypto-1_1-ia64.dll` and `libssl-1_1-ia64.dll` for IA64 Windows.
|
||||
With MSVC, the import libraries are named `libcrypto.lib` and `libssl.lib`,
|
||||
while with MingW, they are named `libcrypto.dll.a` and `libssl.dll.a`.
|
||||
|
||||
|
|
@ -2042,24 +2033,6 @@ around the problem by forcing the build procedure to use the following script:
|
|||
instead of the real clang. In which case it doesn't matter what clang version
|
||||
is used, as it is the version of the GNU assembler that will be checked.
|
||||
|
||||
Notes on profile guided optimization
|
||||
------------------------------------
|
||||
|
||||
Some compilers support the concept of profile guided optimization. This feature
|
||||
allows a user to build openssl and use profiling data gathered while running an
|
||||
application such that it can then be rebuilt in a way that is optimized specifically
|
||||
for that application, increasing performance. Currently this feature is built into
|
||||
the openssl build system for x86_64 only.
|
||||
|
||||
1) Configure openssl with the --coverage option. This will configure the compiler to
|
||||
record profiling data for the libcrypto and libssl libraries
|
||||
2) Run the application(s) which you wish to optimize for, ensuring that they use
|
||||
the libraries compiled in step (1) (note this may entail the use of LD_LIBRARY_PATH)
|
||||
3) Clean the openssl build with make clean. Note that the profile data (the .gcda and .gcno
|
||||
files are retained through the clean operation). This is intentional.
|
||||
4) Configure openssl again, but this time select the --pgo build type. This will use the
|
||||
profiled data to optimize code layout for the application in question.
|
||||
|
||||
---
|
||||
|
||||
<!-- Links -->
|
||||
|
|
|
|||
767
NEWS.md
767
NEWS.md
|
|
@ -7,9 +7,6 @@ release. For more details please read the CHANGES file.
|
|||
OpenSSL Releases
|
||||
----------------
|
||||
|
||||
- [OpenSSL 4.1](#openssl-41)
|
||||
- [OpenSSL 4.0](#openssl-40)
|
||||
- [OpenSSL 3.6](#openssl-36)
|
||||
- [OpenSSL 3.5](#openssl-35)
|
||||
- [OpenSSL 3.4](#openssl-34)
|
||||
- [OpenSSL 3.3](#openssl-33)
|
||||
|
|
@ -23,361 +20,14 @@ OpenSSL Releases
|
|||
- [OpenSSL 1.0.0](#openssl-100)
|
||||
- [OpenSSL 0.9.x](#openssl-09x)
|
||||
|
||||
OpenSSL 4.1
|
||||
-----------
|
||||
|
||||
### Major changes between OpenSSL 4.0 and OpenSSL 4.1 [under development]
|
||||
|
||||
* API calls `CRYPTO_atomic_load_ptr`, `CRYPTO_atomic_store_ptr`, and
|
||||
`CRYPTO_atomic_cmp_exch_ptr` have been added.
|
||||
|
||||
* Fixed verification of DSA certificates signed with SHA-384 or SHA-512.
|
||||
|
||||
OpenSSL 4.0
|
||||
-----------
|
||||
|
||||
### Major changes between OpenSSL 4.0.0 and OpenSSL 4.0.1 [9 Jun 2026]
|
||||
|
||||
OpenSSL 4.0.1 is a security patch release. The most severe CVE fixed
|
||||
in this release is High.
|
||||
|
||||
This release incorporates the following bug fixes and mitigations:
|
||||
|
||||
* Fixed heap use-after-free in `PKCS7_verify()`.
|
||||
([CVE-2026-45447])
|
||||
|
||||
* Fixed CMS `AuthEnvelopedData` processing may accept forged messages.
|
||||
([CVE-2026-34182])
|
||||
|
||||
* Fixed unbounded memory growth in the QUIC `PATH_CHALLENGE` handler.
|
||||
([CVE-2026-34183])
|
||||
|
||||
* Fixed double-free when checking OCSP stapled response.
|
||||
([CVE-2026-35188])
|
||||
|
||||
* Fixed NULL pointer dereference in QUIC server initial packet handling.
|
||||
([CVE-2026-42764])
|
||||
|
||||
* Fixed AES-OCB IV ignored on `EVP_Cipher()` path.
|
||||
([CVE-2026-45445])
|
||||
|
||||
* Fixed possible heap buffer overflow in ASN.1 multibyte string conversion.
|
||||
([CVE-2026-7383])
|
||||
|
||||
* Fixed out-of-bounds read in CMS password-based decryption.
|
||||
([CVE-2026-9076])
|
||||
|
||||
* Fixed heap buffer over-read in ASN.1 content parsing.
|
||||
([CVE-2026-34180])
|
||||
|
||||
* Fixed PKCS#12 files with PBMAC1 are accepted with short HMAC keys.
|
||||
([CVE-2026-34181])
|
||||
|
||||
* Fixed NULL dereference in certificate verification with OCSP Checking.
|
||||
([CVE-2026-42765])
|
||||
|
||||
* Fixed possible NULL dereference in password-dased CMS decryption.
|
||||
([CVE-2026-42766])
|
||||
|
||||
* Fixed NULL pointer dereference in CRMF `EncryptedValue` decryption.
|
||||
([CVE-2026-42767])
|
||||
|
||||
* Fixed multi-`RecipientInfo` Bleichenbacher Oracle in `CMS_decrypt()`
|
||||
and `PKCS7_decrypt()`.
|
||||
([CVE-2026-42768])
|
||||
|
||||
* Fixed trust anchor substitution via `cert`/`issuer` typo in CMP
|
||||
`rootCaKeyUpdate`.
|
||||
([CVE-2026-42769])
|
||||
|
||||
* Fixed FFC-DH peer validation uses attacker-supplied `q`.
|
||||
([CVE-2026-42770])
|
||||
|
||||
* Fixed possible out of bounds read in `X509_VERIFY_PARAM_set1_email()`.
|
||||
([CVE-2026-42771])
|
||||
|
||||
* Fixed incorrect tag processing for empty messages in AES-GCM-SIV
|
||||
and AES-SIV modes.
|
||||
([CVE-2026-45446])
|
||||
|
||||
* Fixed a regression introduced in 4.0.0 that led to a `openssl pkey`
|
||||
command crash when it was invoked to encrypt a private key with password
|
||||
being provided interactively.
|
||||
|
||||
* Fixed a regression introduced in 4.0.0 that led to `openssl s_client -adv`
|
||||
command prematurely terminating a session when reading input of 16384 bytes
|
||||
in one `read()` call.
|
||||
|
||||
### Major changes between OpenSSL 3.6 and OpenSSL 4.0.0 [14 Apr 2026]
|
||||
|
||||
OpenSSL 4.0.0 is a feature release adding significant new functionality
|
||||
to OpenSSL.
|
||||
|
||||
This release incorporates the following potentially significant or incompatible
|
||||
changes:
|
||||
|
||||
* Removed extra leading '00:' when printing key data such as an RSA modulus
|
||||
in hexadecimal format where the first (most significant) byte is >= 0x80.
|
||||
|
||||
* Standardized the width of hexadecimal dumps to 24 bytes for signatures
|
||||
(to stay within the 80 characters limit) and 16 bytes for everything else.
|
||||
|
||||
* Lower bounds checks are now enforced when using `PKCS5_PBKDF2_HMAC` API
|
||||
with FIPS provider.
|
||||
|
||||
* Added AKID verification checks when `X509_V_FLAG_X509_STRICT` is set.
|
||||
|
||||
* Augmented CRL verification process with several additional checks.
|
||||
|
||||
* `libcrypto` no longer cleans up globally allocated data via `atexit()`.
|
||||
|
||||
* `BIO_snprintf()` now uses `snprintf()` provided by libc instead of internal
|
||||
implementation.
|
||||
|
||||
* `OPENSSL_cleanup()` now runs in a global destructor, or not at all
|
||||
by default.
|
||||
|
||||
* `ASN1_STRING` has been made opaque.
|
||||
|
||||
* Signatures of numerous API functions, including those that are related
|
||||
to X509 processing, are changed to include `const` qualifiers for argument
|
||||
and return types, where suitable.
|
||||
|
||||
* Deprecated `X509_cmp_time()`, `X509_cmp_current_time()`,
|
||||
and `X509_cmp_timeframe()` in favor of `X509_check_certificate_times()`.
|
||||
|
||||
* Removed support for the SSLv2 Client Hello.
|
||||
|
||||
* Removed support for SSLv3. SSLv3 has been deprecated since 2015,
|
||||
and OpenSSL had it disabled by default since version 1.1.0 (2016).
|
||||
|
||||
* Removed support for engines. The `no-engine` build option
|
||||
and the `OPENSSL_NO_ENGINE` macro are always present.
|
||||
|
||||
* Support of deprecated elliptic curves in TLS according to [RFC 8422] was
|
||||
disabled at compile-time by default. To enable it, use the
|
||||
`enable-tls-deprecated-ec` configuration option.
|
||||
|
||||
* Support of explicit EC curves was disabled at compile-time by default.
|
||||
To enable it, use the `enable-ec_explicit_curves` configuration option.
|
||||
|
||||
* Removed `c_rehash` script tool. Use `openssl rehash` instead.
|
||||
|
||||
* Removed the deprecated `msie-hack` option from the `openssl ca` command.
|
||||
|
||||
* Removed `BIO_f_reliable()` implementation without replacement.
|
||||
It was broken since 3.0 release without any complaints.
|
||||
|
||||
* Removed deprecated support for custom `EVP_CIPHER`, `EVP_MD`, `EVP_PKEY`,
|
||||
and `EVP_PKEY_ASN1` methods.
|
||||
|
||||
* Removed deprecated fixed SSL/TLS version method functions.
|
||||
|
||||
* Removed deprecated functions `ERR_get_state()`, `ERR_remove_state()`
|
||||
and `ERR_remove_thread_state()`. The `ERR_STATE` object is now always
|
||||
opaque.
|
||||
|
||||
* Dropped `darwin-i386{,-cc}` and `darwin-ppc{,64}{,-cc}` targets
|
||||
from Configurations.
|
||||
|
||||
This release adds the following new features:
|
||||
|
||||
* Support for Encrypted Client Hello (ECH, [RFC 9849]).
|
||||
See `doc/designs/ech-api.md` for details.
|
||||
|
||||
* Support for [RFC 8998], signature algorithm `sm2sig_sm3`, key exchange
|
||||
group `curveSM2`, and [tls-hybrid-sm2-mlkem] post-quantum group
|
||||
`curveSM2MLKEM768`.
|
||||
|
||||
* cSHAKE function support as per [SP 800-185].
|
||||
|
||||
* "ML-DSA-MU" digest algorithm support.
|
||||
|
||||
* Support for SNMP KDF and SRTP KDF.
|
||||
|
||||
* FIPS self tests can now be deferred and run as needed when installing
|
||||
the FIPS module with the `-defer_tests` option of the `openssl fipsinstall`
|
||||
command.
|
||||
|
||||
* Support for using either static or dynamic VC runtime linkage
|
||||
on Windows.
|
||||
|
||||
* Support for negotiated FFDHE key exchange in TLS 1.2 in accordance
|
||||
with [RFC 7919].
|
||||
|
||||
OpenSSL 3.6
|
||||
-----------
|
||||
|
||||
### Major changes between OpenSSL 3.6.1 and OpenSSL 3.6.2 [7 Apr 2026]
|
||||
|
||||
OpenSSL 3.6.2 is a security patch release. The most severe CVE fixed in this
|
||||
release is Moderate.
|
||||
|
||||
This release incorporates the following bug fixes and mitigations:
|
||||
|
||||
* Fixed incorrect failure handling in RSA KEM RSASVE encapsulation.
|
||||
([CVE-2026-31790])
|
||||
|
||||
* Fixed loss of key agreement group tuple structure when the `DEFAULT` keyword
|
||||
is used in the server-side configuration of the key-agreement group list.
|
||||
([CVE-2026-2673])
|
||||
|
||||
* Fixed out-of-bounds read in AES-CFB-128 on x86-64 CPUs with AVX-512 support.
|
||||
([CVE-2026-28386])
|
||||
|
||||
* Fixed potential use-after-free in DANE client code.
|
||||
([CVE-2026-28387])
|
||||
|
||||
* Fixed NULL pointer dereference when processing a delta CRL.
|
||||
([CVE-2026-28388])
|
||||
|
||||
* Fixed possible NULL dereference when processing CMS KeyAgreeRecipientInfo.
|
||||
([CVE-2026-28389])
|
||||
|
||||
* Fixed possible NULL dereference when processing CMS
|
||||
KeyTransportRecipientInfo.
|
||||
([CVE-2026-28390])
|
||||
|
||||
* Fixed heap buffer overflow in hexadecimal conversion.
|
||||
([CVE-2026-31789])
|
||||
|
||||
### Major changes between OpenSSL 3.6.0 and OpenSSL 3.6.1 [27 Jan 2026]
|
||||
|
||||
OpenSSL 3.6.1 is a security patch release. The most severe CVE fixed in this
|
||||
release is High.
|
||||
|
||||
This release incorporates the following bug fixes and mitigations:
|
||||
|
||||
* Fixed Improper validation of PBMAC1 parameters in PKCS#12 MAC verification.
|
||||
([CVE-2025-11187])
|
||||
|
||||
* Fixed Stack buffer overflow in CMS `AuthEnvelopedData` parsing.
|
||||
([CVE-2025-15467])
|
||||
|
||||
* Fixed NULL dereference in `SSL_CIPHER_find()` function on unknown cipher ID.
|
||||
([CVE-2025-15468])
|
||||
|
||||
* Fixed `openssl dgst` one-shot codepath silently truncates inputs >16 MiB.
|
||||
([CVE-2025-15469])
|
||||
|
||||
* Fixed TLS 1.3 `CompressedCertificate` excessive memory allocation.
|
||||
([CVE-2025-66199])
|
||||
|
||||
* Fixed Heap out-of-bounds write in `BIO_f_linebuffer` on short writes.
|
||||
([CVE-2025-68160])
|
||||
|
||||
* Fixed Unauthenticated/unencrypted trailing bytes with low-level OCB
|
||||
function calls.
|
||||
([CVE-2025-69418])
|
||||
|
||||
* Fixed Out of bounds write in `PKCS12_get_friendlyname()` UTF-8 conversion.
|
||||
([CVE-2025-69419])
|
||||
|
||||
* Fixed Missing `ASN1_TYPE` validation in `TS_RESP_verify_response()`
|
||||
function.
|
||||
([CVE-2025-69420])
|
||||
|
||||
* Fixed NULL Pointer Dereference in `PKCS12_item_decrypt_d2i_ex()` function.
|
||||
([CVE-2025-69421])
|
||||
|
||||
* Fixed Missing `ASN1_TYPE` validation in PKCS#12 parsing.
|
||||
([CVE-2026-22795])
|
||||
|
||||
* Fixed `ASN1_TYPE` Type Confusion in the `PKCS7_digest_from_attributes()`
|
||||
function.
|
||||
([CVE-2026-22796])
|
||||
|
||||
* Fixed a regression in `X509_V_FLAG_CRL_CHECK_ALL` flag handling by
|
||||
restoring its pre-3.6.0 behaviour.
|
||||
|
||||
* Fixed a regression in handling stapled OCSP responses causing handshake
|
||||
failures for OpenSSL 3.6.0 servers with various client implementations.
|
||||
|
||||
### Major changes between OpenSSL 3.5 and OpenSSL 3.6.0 [1 Oct 2025]
|
||||
|
||||
OpenSSL 3.6.0 is a feature release adding significant new functionality
|
||||
to OpenSSL.
|
||||
|
||||
This release incorporates the following potentially significant or incompatible
|
||||
changes:
|
||||
|
||||
* Added NIST security categories for PKEY objects.
|
||||
|
||||
* Added support for `EVP_SKEY` opaque symmetric key objects to the key
|
||||
derivation and key exchange provider methods. Added `EVP_KDF_CTX_set_SKEY()`,
|
||||
`EVP_KDF_derive_SKEY()`, and `EVP_PKEY_derive_SKEY()` functions.
|
||||
|
||||
* Added LMS signature verification support as per [SP 800-208].
|
||||
This support is present in both the FIPS and default providers.
|
||||
|
||||
* An ANSI-C toolchain is no longer sufficient for building OpenSSL.
|
||||
The code should be built using compilers supporting C-99 features.
|
||||
|
||||
* Support for the VxWorks platforms has been removed.
|
||||
|
||||
* Added an `openssl configutl` utility for processing the OpenSSL
|
||||
configuration file and dumping the equal configuration file.
|
||||
|
||||
* Added support for FIPS 186-5 deterministic ECDSA signature
|
||||
generation to the FIPS provider.
|
||||
|
||||
* Deprecated `EVP_PKEY_ASN1_METHOD`-related functions.
|
||||
|
||||
OpenSSL 3.5
|
||||
-----------
|
||||
|
||||
### Major changes between OpenSSL 3.5.3 and OpenSSL 3.5.4 [30 Sep 2025]
|
||||
### Major changes between OpenSSL 3.5 and OpenSSL 3.6 [under development]
|
||||
|
||||
OpenSSL 3.5.4 is a security patch release. The most severe CVE fixed in this
|
||||
release is Moderate.
|
||||
* none
|
||||
|
||||
This release incorporates the following bug fixes and mitigations:
|
||||
|
||||
* Fix Out-of-bounds read & write in RFC 3211 KEK Unwrap.
|
||||
([CVE-2025-9230])
|
||||
|
||||
* Fix Timing side-channel in SM2 algorithm on 64 bit ARM.
|
||||
([CVE-2025-9231])
|
||||
|
||||
* Fix Out-of-bounds read in HTTP client no_proxy handling.
|
||||
([CVE-2025-9232])
|
||||
|
||||
* Reverted the synthesised `OPENSSL_VERSION_NUMBER` change for the release
|
||||
builds, as it broke some exiting applications that relied on the previous
|
||||
3.x semantics, as documented in `OpenSSL_version(3)`.
|
||||
|
||||
### Major changes between OpenSSL 3.5.2 and OpenSSL 3.5.3 [16 Sep 2025]
|
||||
|
||||
OpenSSL 3.5.3 is a bug fix release.
|
||||
|
||||
This release incorporates the following bug fixes and mitigations:
|
||||
|
||||
* Added FIPS 140-3 PCT on DH key generation.
|
||||
|
||||
* Fixed the synthesised `OPENSSL_VERSION_NUMBER`.
|
||||
|
||||
* Removed PCT on key import in the FIPS provider as it is not required by
|
||||
the standard.
|
||||
|
||||
### Major changes between OpenSSL 3.5.1 and OpenSSL 3.5.2 [5 Aug 2025]
|
||||
|
||||
OpenSSL 3.5.2 is a bug fix release.
|
||||
|
||||
This release incorporates the following bug fixes and mitigations:
|
||||
|
||||
* The FIPS provider now performs a PCT on key import for RSA, EC and ECX.
|
||||
|
||||
### Major changes between OpenSSL 3.5.0 and OpenSSL 3.5.1 [1 Jul 2025]
|
||||
|
||||
OpenSSL 3.5.1 is a security patch release. The most severe CVE fixed in this
|
||||
release is Low.
|
||||
|
||||
This release incorporates the following bug fixes and mitigations:
|
||||
|
||||
* Fix x509 application adds trusted use instead of rejected use.
|
||||
([CVE-2025-4575])
|
||||
|
||||
### Major changes between OpenSSL 3.4 and OpenSSL 3.5.0 [8 Apr 2025]
|
||||
### Major changes between OpenSSL 3.4 and OpenSSL 3.5 [under development]
|
||||
|
||||
OpenSSL 3.5.0 is a feature release adding significant new functionality to
|
||||
OpenSSL.
|
||||
|
|
@ -610,7 +260,7 @@ This release adds the following new features:
|
|||
* Added X509_STORE_get1_objects to avoid issues with the existing
|
||||
X509_STORE_get0_objects API in multi-threaded applications.
|
||||
|
||||
* Support for using certificate profiles and extended delayed delivery in CMP
|
||||
* Support for using certificate profiles and extened delayed delivery in CMP
|
||||
|
||||
This release incorporates the following potentially significant or incompatible
|
||||
changes:
|
||||
|
|
@ -886,8 +536,6 @@ OpenSSL 3.0
|
|||
|
||||
### Major changes between OpenSSL 3.0.0 and OpenSSL 3.0.1 [14 Dec 2021]
|
||||
|
||||
* Fixed carry bug in BN_mod_exp which may produce incorrect results on MIPS
|
||||
([CVE-2021-4160])
|
||||
* Fixed invalid handling of X509_verify_cert() internal errors in libssl
|
||||
([CVE-2021-4044])
|
||||
* Allow fetching an operation from the provider that owns an unexportable key
|
||||
|
|
@ -1015,7 +663,7 @@ OpenSSL 1.1.1
|
|||
|
||||
### Major changes between OpenSSL 1.1.1d and OpenSSL 1.1.1e [17 Mar 2020]
|
||||
|
||||
* Fixed an overflow bug in the x86_64 Montgomery squaring procedure
|
||||
* Fixed an overflow bug in the x64_64 Montgomery squaring procedure
|
||||
used in exponentiation with 512-bit moduli ([CVE-2019-1551])
|
||||
|
||||
### Major changes between OpenSSL 1.1.1c and OpenSSL 1.1.1d [10 Sep 2019]
|
||||
|
|
@ -2245,233 +1893,186 @@ OpenSSL 0.9.x
|
|||
* Support for various new platforms
|
||||
|
||||
<!-- Links -->
|
||||
[CHANGES.md]: ./CHANGES.md
|
||||
[CMVP]: https://csrc.nist.gov/projects/cryptographic-module-validation-program
|
||||
[CVE-2005-2969]: https://openssl-library.org/news/vulnerabilities/#CVE-2005-2969
|
||||
[CVE-2006-2937]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-2937
|
||||
[CVE-2006-2940]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-2940
|
||||
[CVE-2006-3737]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-3737
|
||||
[CVE-2006-4339]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-4339
|
||||
[CVE-2006-4343]: https://openssl-library.org/news/vulnerabilities/#CVE-2006-4343
|
||||
[CVE-2008-5077]: https://openssl-library.org/news/vulnerabilities/#CVE-2008-5077
|
||||
[CVE-2009-0590]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0590
|
||||
[CVE-2009-0591]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0591
|
||||
[CVE-2009-0789]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-0789
|
||||
[CVE-2009-3555]: https://openssl-library.org/news/vulnerabilities/#CVE-2009-3555
|
||||
[CVE-2010-0433]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-0433
|
||||
[CVE-2010-0740]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-0740
|
||||
[CVE-2010-1633]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-1633
|
||||
[CVE-2010-2939]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-2939
|
||||
[CVE-2010-3864]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-3864
|
||||
[CVE-2010-4180]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-4180
|
||||
[CVE-2010-4252]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-4252
|
||||
[CVE-2010-5298]: https://openssl-library.org/news/vulnerabilities/#CVE-2010-5298
|
||||
[CVE-2011-0014]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-0014
|
||||
[CVE-2011-3207]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-3207
|
||||
[CVE-2011-3210]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-3210
|
||||
[CVE-2011-4108]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4108
|
||||
[CVE-2011-4576]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4576
|
||||
[CVE-2011-4577]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4577
|
||||
[CVE-2011-4619]: https://openssl-library.org/news/vulnerabilities/#CVE-2011-4619
|
||||
[CVE-2012-0027]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0027
|
||||
[CVE-2012-0050]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0050
|
||||
[CVE-2012-0884]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-0884
|
||||
[CVE-2012-2110]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2110
|
||||
[CVE-2012-2333]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2333
|
||||
[CVE-2012-2686]: https://openssl-library.org/news/vulnerabilities/#CVE-2012-2686
|
||||
[CVE-2013-0166]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-0166
|
||||
[CVE-2013-0169]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-0169
|
||||
[CVE-2013-4353]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-4353
|
||||
[CVE-2013-6449]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-6449
|
||||
[CVE-2013-6450]: https://openssl-library.org/news/vulnerabilities/#CVE-2013-6450
|
||||
[CVE-2014-0076]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0076
|
||||
[CVE-2014-0160]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0160
|
||||
[CVE-2014-0195]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0195
|
||||
[CVE-2014-0198]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0198
|
||||
[CVE-2014-0221]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0221
|
||||
[CVE-2014-0224]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-0224
|
||||
[CVE-2014-3470]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3470
|
||||
[CVE-2014-3505]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3505
|
||||
[CVE-2014-3506]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3506
|
||||
[CVE-2014-3507]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3507
|
||||
[CVE-2014-3508]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3508
|
||||
[CVE-2014-3509]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3509
|
||||
[CVE-2014-3510]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3510
|
||||
[CVE-2014-3511]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3511
|
||||
[CVE-2014-3512]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3512
|
||||
[CVE-2014-3513]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3513
|
||||
[CVE-2014-3566]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3566
|
||||
[CVE-2014-3567]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3567
|
||||
[CVE-2014-3568]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3568
|
||||
[CVE-2014-3569]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3569
|
||||
[CVE-2014-3570]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3570
|
||||
[CVE-2014-3571]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3571
|
||||
[CVE-2014-3572]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-3572
|
||||
[CVE-2014-5139]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-5139
|
||||
[CVE-2014-8275]: https://openssl-library.org/news/vulnerabilities/#CVE-2014-8275
|
||||
[CVE-2015-0204]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0204
|
||||
[CVE-2015-0205]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0205
|
||||
[CVE-2015-0206]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0206
|
||||
[CVE-2015-0207]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0207
|
||||
[CVE-2015-0208]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0208
|
||||
[CVE-2015-0209]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0209
|
||||
[CVE-2015-0285]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0285
|
||||
[CVE-2015-0286]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0286
|
||||
[CVE-2015-0287]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0287
|
||||
[CVE-2015-0288]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0288
|
||||
[CVE-2015-0289]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0289
|
||||
[CVE-2015-0290]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0290
|
||||
[CVE-2015-0291]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0291
|
||||
[CVE-2015-0293]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-0293
|
||||
[CVE-2015-1787]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1787
|
||||
[CVE-2015-1788]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1788
|
||||
[CVE-2015-1789]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1789
|
||||
[CVE-2015-1790]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1790
|
||||
[CVE-2015-1791]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1791
|
||||
[CVE-2015-1792]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1792
|
||||
[CVE-2015-1793]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-1793
|
||||
[CVE-2015-3193]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3193
|
||||
[CVE-2015-3194]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3194
|
||||
[CVE-2015-3195]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3195
|
||||
[CVE-2015-3196]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3196
|
||||
[CVE-2015-3197]: https://openssl-library.org/news/vulnerabilities/#CVE-2015-3197
|
||||
[CVE-2016-0701]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0701
|
||||
[CVE-2016-0702]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0702
|
||||
[CVE-2016-0705]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0705
|
||||
[CVE-2016-0797]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0797
|
||||
[CVE-2016-0798]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0798
|
||||
[CVE-2016-0799]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0799
|
||||
[CVE-2016-0800]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-0800
|
||||
[CVE-2016-2105]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2105
|
||||
[CVE-2016-2106]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2106
|
||||
[CVE-2016-2107]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2107
|
||||
[CVE-2016-2109]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2109
|
||||
[CVE-2016-2176]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2176
|
||||
[CVE-2016-2177]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2177
|
||||
[CVE-2016-2178]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2178
|
||||
[CVE-2016-2179]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2179
|
||||
[CVE-2016-2180]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2180
|
||||
[CVE-2016-2181]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2181
|
||||
[CVE-2016-2182]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2182
|
||||
[CVE-2016-2183]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-2183
|
||||
[CVE-2016-6302]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6302
|
||||
[CVE-2016-6303]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6303
|
||||
[CVE-2016-6304]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6304
|
||||
[CVE-2016-6305]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6305
|
||||
[CVE-2016-6306]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6306
|
||||
[CVE-2016-6307]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6307
|
||||
[CVE-2016-6308]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6308
|
||||
[CVE-2016-6309]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-6309
|
||||
[CVE-2016-7052]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7052
|
||||
[CVE-2016-7053]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7053
|
||||
[CVE-2016-7054]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7054
|
||||
[CVE-2016-7055]: https://openssl-library.org/news/vulnerabilities/#CVE-2016-7055
|
||||
[CVE-2017-3730]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3730
|
||||
[CVE-2017-3731]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3731
|
||||
[CVE-2017-3732]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3732
|
||||
[CVE-2017-3733]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3733
|
||||
[CVE-2017-3735]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3735
|
||||
[CVE-2017-3736]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3736
|
||||
[CVE-2017-3737]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3737
|
||||
[CVE-2017-3738]: https://openssl-library.org/news/vulnerabilities/#CVE-2017-3738
|
||||
[CVE-2018-0732]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0732
|
||||
[CVE-2018-0733]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0733
|
||||
[CVE-2018-0734]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0734
|
||||
[CVE-2018-0735]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0735
|
||||
[CVE-2018-0737]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0737
|
||||
[CVE-2018-0739]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-0739
|
||||
[CVE-2018-5407]: https://openssl-library.org/news/vulnerabilities/#CVE-2018-5407
|
||||
[CVE-2019-1543]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1543
|
||||
[CVE-2019-1547]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1547
|
||||
[CVE-2019-1549]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1549
|
||||
[CVE-2019-1551]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1551
|
||||
[CVE-2019-1552]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1552
|
||||
[CVE-2019-1559]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1559
|
||||
[CVE-2019-1563]: https://openssl-library.org/news/vulnerabilities/#CVE-2019-1563
|
||||
[CVE-2020-1967]: https://openssl-library.org/news/vulnerabilities/#CVE-2020-1967
|
||||
[CVE-2020-1971]: https://openssl-library.org/news/vulnerabilities/#CVE-2020-1971
|
||||
[CVE-2022-2097]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-2097
|
||||
[CVE-2022-2274]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-2274
|
||||
[CVE-2022-3996]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-3996
|
||||
[CVE-2022-4203]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4203
|
||||
[CVE-2022-4304]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4304
|
||||
[CVE-2022-4450]: https://openssl-library.org/news/vulnerabilities/#CVE-2022-4450
|
||||
[CVE-2023-0215]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0215
|
||||
[CVE-2023-0216]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0216
|
||||
[CVE-2023-0217]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0217
|
||||
[CVE-2023-0286]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0286
|
||||
[CVE-2023-0401]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0401
|
||||
[CVE-2023-0464]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0464
|
||||
[CVE-2023-0465]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0465
|
||||
[CVE-2023-0466]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-0466
|
||||
[CVE-2023-1255]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-1255
|
||||
[CVE-2023-2650]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-2650
|
||||
[CVE-2023-2975]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-2975
|
||||
[CVE-2023-3446]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-3446
|
||||
[CVE-2023-3817]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-3817
|
||||
[CVE-2023-4807]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-4807
|
||||
[CVE-2023-5363]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-5363
|
||||
[CVE-2023-5678]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-5678
|
||||
[CVE-2023-6129]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-6129
|
||||
[CVE-2023-6237]: https://openssl-library.org/news/vulnerabilities/#CVE-2023-6237
|
||||
[CVE-2024-0727]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-0727
|
||||
[CVE-2024-2511]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-2511
|
||||
[CVE-2024-4603]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-4603
|
||||
[CVE-2024-4741]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-4741
|
||||
[CVE-2024-5535]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-5535
|
||||
[CVE-2024-6119]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-6119
|
||||
[CVE-2024-9143]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-9143
|
||||
[CVE-2024-13176]: https://openssl-library.org/news/vulnerabilities/#CVE-2024-13176
|
||||
[CVE-2025-4575]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-4575
|
||||
[CVE-2025-9230]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9230
|
||||
[CVE-2025-9231]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9231
|
||||
[CVE-2025-9232]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-9232
|
||||
[CVE-2025-11187]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-11187
|
||||
[CVE-2025-15467]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15467
|
||||
[CVE-2025-15468]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15468
|
||||
[CVE-2025-15469]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-15469
|
||||
[CVE-2025-66199]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-66199
|
||||
[CVE-2025-68160]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-68160
|
||||
[CVE-2025-69418]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69418
|
||||
[CVE-2025-69419]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69419
|
||||
[CVE-2025-69420]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69420
|
||||
[CVE-2025-69421]: https://openssl-library.org/news/vulnerabilities/#CVE-2025-69421
|
||||
[CVE-2026-2673]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-2673
|
||||
[CVE-2026-7383]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-7383
|
||||
[CVE-2026-9076]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-9076
|
||||
[CVE-2026-22795]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-22795
|
||||
[CVE-2026-22796]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-22796
|
||||
[CVE-2026-28386]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28386
|
||||
[CVE-2026-28387]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28387
|
||||
[CVE-2026-28388]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28388
|
||||
[CVE-2026-28389]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28389
|
||||
[CVE-2026-28390]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-28390
|
||||
[CVE-2026-31789]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-31789
|
||||
[CVE-2026-31790]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-31790
|
||||
[CVE-2026-34180]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34180
|
||||
[CVE-2026-34181]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34181
|
||||
[CVE-2026-34182]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34182
|
||||
[CVE-2026-34183]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-34183
|
||||
[CVE-2026-35188]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-35188
|
||||
[CVE-2026-42764]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42764
|
||||
[CVE-2026-42765]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42765
|
||||
[CVE-2026-42766]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42766
|
||||
[CVE-2026-42767]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42767
|
||||
[CVE-2026-42768]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42768
|
||||
[CVE-2026-42769]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42769
|
||||
[CVE-2026-42770]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42770
|
||||
[CVE-2026-42771]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-42771
|
||||
[CVE-2026-45445]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45445
|
||||
[CVE-2026-45446]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45446
|
||||
[CVE-2026-45447]: https://openssl-library.org/news/vulnerabilities/#CVE-2026-45447
|
||||
[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations
|
||||
|
||||
[CVE-2024-13176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-13176
|
||||
[CVE-2024-9143]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-9143
|
||||
[CVE-2024-6119]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-6119
|
||||
[CVE-2024-5535]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-5535
|
||||
[CVE-2024-4741]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4741
|
||||
[CVE-2024-4603]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-4603
|
||||
[CVE-2024-2511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-2511
|
||||
[CVE-2024-0727]: https://www.openssl.org/news/vulnerabilities.html#CVE-2024-0727
|
||||
[CVE-2023-6237]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-6237
|
||||
[CVE-2023-6129]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-6129
|
||||
[CVE-2023-5678]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5678
|
||||
[CVE-2023-5363]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-5363
|
||||
[CVE-2023-4807]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-4807
|
||||
[CVE-2023-3817]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3817
|
||||
[CVE-2023-3446]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-3446
|
||||
[CVE-2023-2975]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-2975
|
||||
[CVE-2023-2650]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-2650
|
||||
[CVE-2023-1255]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-1255
|
||||
[CVE-2023-0466]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0466
|
||||
[CVE-2023-0465]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0465
|
||||
[CVE-2023-0464]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0464
|
||||
[CVE-2023-0401]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0401
|
||||
[CVE-2023-0286]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0286
|
||||
[CVE-2023-0217]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0217
|
||||
[CVE-2023-0216]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0216
|
||||
[CVE-2023-0215]: https://www.openssl.org/news/vulnerabilities.html#CVE-2023-0215
|
||||
[CVE-2022-4450]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4450
|
||||
[CVE-2022-4304]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4304
|
||||
[CVE-2022-4203]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-4203
|
||||
[CVE-2022-3996]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-3996
|
||||
[CVE-2022-2274]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-2274
|
||||
[CVE-2022-2097]: https://www.openssl.org/news/vulnerabilities.html#CVE-2022-2097
|
||||
[CVE-2020-1971]: https://www.openssl.org/news/vulnerabilities.html#CVE-2020-1971
|
||||
[CVE-2020-1967]: https://www.openssl.org/news/vulnerabilities.html#CVE-2020-1967
|
||||
[CVE-2019-1563]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1563
|
||||
[CVE-2019-1559]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1559
|
||||
[CVE-2019-1552]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1552
|
||||
[CVE-2019-1551]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1551
|
||||
[CVE-2019-1549]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1549
|
||||
[CVE-2019-1547]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1547
|
||||
[CVE-2019-1543]: https://www.openssl.org/news/vulnerabilities.html#CVE-2019-1543
|
||||
[CVE-2018-5407]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-5407
|
||||
[CVE-2018-0739]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0739
|
||||
[CVE-2018-0737]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0737
|
||||
[CVE-2018-0735]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0735
|
||||
[CVE-2018-0734]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0734
|
||||
[CVE-2018-0733]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0733
|
||||
[CVE-2018-0732]: https://www.openssl.org/news/vulnerabilities.html#CVE-2018-0732
|
||||
[CVE-2017-3738]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3738
|
||||
[CVE-2017-3737]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3737
|
||||
[CVE-2017-3736]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3736
|
||||
[CVE-2017-3735]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3735
|
||||
[CVE-2017-3733]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3733
|
||||
[CVE-2017-3732]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3732
|
||||
[CVE-2017-3731]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3731
|
||||
[CVE-2017-3730]: https://www.openssl.org/news/vulnerabilities.html#CVE-2017-3730
|
||||
[CVE-2016-7055]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7055
|
||||
[CVE-2016-7054]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7054
|
||||
[CVE-2016-7053]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7053
|
||||
[CVE-2016-7052]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-7052
|
||||
[CVE-2016-6309]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6309
|
||||
[CVE-2016-6308]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6308
|
||||
[CVE-2016-6307]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6307
|
||||
[CVE-2016-6306]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6306
|
||||
[CVE-2016-6305]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6305
|
||||
[CVE-2016-6304]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6304
|
||||
[CVE-2016-6303]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6303
|
||||
[CVE-2016-6302]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-6302
|
||||
[CVE-2016-2183]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2183
|
||||
[CVE-2016-2182]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2182
|
||||
[CVE-2016-2181]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2181
|
||||
[CVE-2016-2180]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2180
|
||||
[CVE-2016-2179]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2179
|
||||
[CVE-2016-2178]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2178
|
||||
[CVE-2016-2177]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2177
|
||||
[CVE-2016-2176]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2176
|
||||
[CVE-2016-2109]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2109
|
||||
[CVE-2016-2107]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2107
|
||||
[CVE-2016-2106]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2106
|
||||
[CVE-2016-2105]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-2105
|
||||
[CVE-2016-0800]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0800
|
||||
[CVE-2016-0799]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0799
|
||||
[CVE-2016-0798]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0798
|
||||
[CVE-2016-0797]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0797
|
||||
[CVE-2016-0705]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0705
|
||||
[CVE-2016-0702]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0702
|
||||
[CVE-2016-0701]: https://www.openssl.org/news/vulnerabilities.html#CVE-2016-0701
|
||||
[CVE-2015-3197]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3197
|
||||
[CVE-2015-3196]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3196
|
||||
[CVE-2015-3195]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3195
|
||||
[CVE-2015-3194]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3194
|
||||
[CVE-2015-3193]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-3193
|
||||
[CVE-2015-1793]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1793
|
||||
[CVE-2015-1792]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1792
|
||||
[CVE-2015-1791]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1791
|
||||
[CVE-2015-1790]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1790
|
||||
[CVE-2015-1789]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1789
|
||||
[CVE-2015-1788]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1788
|
||||
[CVE-2015-1787]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-1787
|
||||
[CVE-2015-0293]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0293
|
||||
[CVE-2015-0291]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0291
|
||||
[CVE-2015-0290]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0290
|
||||
[CVE-2015-0289]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0289
|
||||
[CVE-2015-0288]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0288
|
||||
[CVE-2015-0287]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0287
|
||||
[CVE-2015-0286]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0286
|
||||
[CVE-2015-0285]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0285
|
||||
[CVE-2015-0209]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0209
|
||||
[CVE-2015-0208]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0208
|
||||
[CVE-2015-0207]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0207
|
||||
[CVE-2015-0206]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0206
|
||||
[CVE-2015-0205]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0205
|
||||
[CVE-2015-0204]: https://www.openssl.org/news/vulnerabilities.html#CVE-2015-0204
|
||||
[CVE-2014-8275]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-8275
|
||||
[CVE-2014-5139]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-5139
|
||||
[CVE-2014-3572]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3572
|
||||
[CVE-2014-3571]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3571
|
||||
[CVE-2014-3570]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3570
|
||||
[CVE-2014-3569]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3569
|
||||
[CVE-2014-3568]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3568
|
||||
[CVE-2014-3567]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3567
|
||||
[CVE-2014-3566]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3566
|
||||
[CVE-2014-3513]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3513
|
||||
[CVE-2014-3512]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3512
|
||||
[CVE-2014-3511]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3511
|
||||
[CVE-2014-3510]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3510
|
||||
[CVE-2014-3509]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3509
|
||||
[CVE-2014-3508]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3508
|
||||
[CVE-2014-3507]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3507
|
||||
[CVE-2014-3506]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3506
|
||||
[CVE-2014-3505]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3505
|
||||
[CVE-2014-3470]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-3470
|
||||
[CVE-2014-0224]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0224
|
||||
[CVE-2014-0221]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0221
|
||||
[CVE-2014-0198]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0198
|
||||
[CVE-2014-0195]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0195
|
||||
[CVE-2014-0160]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0160
|
||||
[CVE-2014-0076]: https://www.openssl.org/news/vulnerabilities.html#CVE-2014-0076
|
||||
[CVE-2013-6450]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-6450
|
||||
[CVE-2013-6449]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-6449
|
||||
[CVE-2013-4353]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-4353
|
||||
[CVE-2013-0169]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-0169
|
||||
[CVE-2013-0166]: https://www.openssl.org/news/vulnerabilities.html#CVE-2013-0166
|
||||
[CVE-2012-2686]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2686
|
||||
[CVE-2012-2333]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2333
|
||||
[CVE-2012-2110]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-2110
|
||||
[CVE-2012-0884]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0884
|
||||
[CVE-2012-0050]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0050
|
||||
[CVE-2012-0027]: https://www.openssl.org/news/vulnerabilities.html#CVE-2012-0027
|
||||
[CVE-2011-4619]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4619
|
||||
[CVE-2011-4577]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4577
|
||||
[CVE-2011-4576]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4576
|
||||
[CVE-2011-4108]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-4108
|
||||
[CVE-2011-3210]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-3210
|
||||
[CVE-2011-3207]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-3207
|
||||
[CVE-2011-0014]: https://www.openssl.org/news/vulnerabilities.html#CVE-2011-0014
|
||||
[CVE-2010-5298]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-5298
|
||||
[CVE-2010-4252]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-4252
|
||||
[CVE-2010-4180]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-4180
|
||||
[CVE-2010-3864]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-3864
|
||||
[CVE-2010-2939]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-2939
|
||||
[CVE-2010-1633]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-1633
|
||||
[CVE-2010-0740]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-0740
|
||||
[CVE-2010-0433]: https://www.openssl.org/news/vulnerabilities.html#CVE-2010-0433
|
||||
[CVE-2009-3555]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-3555
|
||||
[CVE-2009-0789]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0789
|
||||
[CVE-2009-0591]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0591
|
||||
[CVE-2009-0590]: https://www.openssl.org/news/vulnerabilities.html#CVE-2009-0590
|
||||
[CVE-2008-5077]: https://www.openssl.org/news/vulnerabilities.html#CVE-2008-5077
|
||||
[CVE-2006-4343]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-4343
|
||||
[CVE-2006-4339]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-4339
|
||||
[CVE-2006-3737]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-3737
|
||||
[CVE-2006-2940]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-2940
|
||||
[CVE-2006-2937]: https://www.openssl.org/news/vulnerabilities.html#CVE-2006-2937
|
||||
[CVE-2005-2969]: https://www.openssl.org/news/vulnerabilities.html#CVE-2005-2969
|
||||
[OpenSSL Guide]: https://docs.openssl.org/master/man7/ossl-guide-introduction
|
||||
[CHANGES.md]: ./CHANGES.md
|
||||
[README-QUIC.md]: ./README-QUIC.md
|
||||
[RFC 7919]: https://datatracker.ietf.org/doc/html/rfc7919
|
||||
[RFC 8422]: https://datatracker.ietf.org/doc/html/rfc8422
|
||||
[RFC 8998]: https://datatracker.ietf.org/doc/html/rfc8998#name-iana-considerations
|
||||
[RFC 9849]: https://datatracker.ietf.org/doc/html/rfc9849
|
||||
[SP 800-185]: https://csrc.nist.gov/pubs/sp/800/185/final
|
||||
[SP 800-208]: https://csrc.nist.gov/pubs/sp/800/208/final
|
||||
[issue tracker]: https://github.com/openssl/openssl/issues
|
||||
[CMVP]: https://csrc.nist.gov/projects/cryptographic-module-validation-program
|
||||
[ESV]: https://csrc.nist.gov/Projects/cryptographic-module-validation-program/entropy-validations
|
||||
[jitterentropy-library]: https://github.com/smuellerDD/jitterentropy-library
|
||||
|
|
|
|||
33
NOTES-ANSI.md
Normal file
33
NOTES-ANSI.md
Normal file
|
|
@ -0,0 +1,33 @@
|
|||
Notes on ANSI C
|
||||
===============
|
||||
|
||||
When building for pure ANSI C (C89/C90), you must configure with at least
|
||||
the following configuration settings:
|
||||
|
||||
- `no-asm`
|
||||
|
||||
There are cases of `asm()` calls in our C source, which isn't supported
|
||||
in pure ANSI C.
|
||||
|
||||
- `no-secure-memory`
|
||||
|
||||
The secure memory calls aren't supported with ANSI C.
|
||||
|
||||
- `-D_XOPEN_SOURCE=1`
|
||||
|
||||
This macro enables the use of the following types, functions and global
|
||||
variables:
|
||||
|
||||
- `timezone`
|
||||
|
||||
- `-D_POSIX_C_SOURCE=200809L`
|
||||
|
||||
This macro enables the use of the following types, functions and global
|
||||
variables:
|
||||
|
||||
- `ssize_t`
|
||||
- `strdup()`
|
||||
|
||||
It's arguable that with gcc and clang, all of these issues are removed when
|
||||
defining the macro `_DEFAULT_SOURCE`. However, that effectively sets the C
|
||||
language level to C99, which isn't ANSI C.
|
||||
49
NOTES-C99.md
49
NOTES-C99.md
|
|
@ -1,49 +0,0 @@
|
|||
Notes on C-99
|
||||
=============
|
||||
|
||||
This file contains a list of C-99 features we don't allow for OpenSSL.
|
||||
Starting with 3.6 OpenSSL project is going to gradually adopt C-99 features.
|
||||
The plan is to bring those features in small steps. Either with new
|
||||
code where particular C-99 construct makes sense (think of designated initializers),
|
||||
or when refactoring existing code and using C-99 language feature improves
|
||||
readability/maintainability of the code. C-99 seems to be implemented by major
|
||||
compilers ([clang](https://clang.llvm.org/c_status.html#c99), [gcc](https://gcc.gnu.org/c99status.html), [msvc](https://learn.microsoft.com/en-us/cpp/overview/visual-cpp-language-conformance?view=msvc-170)), therefore we can opt
|
||||
for permissive policy to adopt C-99 standard. This approach means OpenSSL
|
||||
project accepts all C-99 features except those explicitly listed here.
|
||||
The list here is going to be updated by features we either
|
||||
|
||||
- find not useful (or not a good match) for OpenSSL
|
||||
|
||||
- the feature is not implemented by some non-mainstream compiler which
|
||||
we need to keep supported for benefit of OpenSSL users
|
||||
|
||||
The list of C-99 features we don't support in OpenSSL project follows:
|
||||
|
||||
- do not use `//` for comments, stick to `/* ... */`
|
||||
|
||||
- do not use `<complex.h>`. MSVC doesn't quite implement it to standard.
|
||||
|
||||
- do not use variable length arrays, i.e. arrays where the size is
|
||||
determined by another variable. MSVC doesn't implement it at all.
|
||||
For clarity, this is an example of such an array:
|
||||
|
||||
``` C
|
||||
int fun(size_t n)
|
||||
{
|
||||
char s[n]; /* variable size array */
|
||||
...
|
||||
}
|
||||
```
|
||||
|
||||
Exit status macros (`EXIT_SUCCESS`, `EXIT_FAILURE`)
|
||||
---------------------------------------------------
|
||||
|
||||
These macros from `<stdlib.h>` represent *process* exit status. Do not use
|
||||
them as return values from internal APIs (any function that is not `main()`).
|
||||
Use them only as the return value from `main()` or as the argument to
|
||||
`exit(3)` (or equivalent, such as `_exit()`).
|
||||
|
||||
Elsewhere, be consistent with the rest of the codebase: return a positive
|
||||
value for success (often `1`), and `0` or a non-positive value for failure,
|
||||
or `bool` when that improves clarity. See
|
||||
<https://github.com/openssl/openssl/issues/30562>.
|
||||
|
|
@ -37,7 +37,8 @@ for each on the TNS/X (L-Series) platform:
|
|||
The KLT threading model is a newly released model on NonStop. It implements
|
||||
kernel-level threading. KLT provides much closer threading to what OpenSSL
|
||||
uses for Linux-like threading models. KLT continues to use the pthread library
|
||||
API. There is no supported 32-bit or Guardian builds for KLT.
|
||||
API. There is no supported 32-bit or Guardian builds for KLT. Note: KLT is
|
||||
not currently available but is planned for post-2024.
|
||||
|
||||
The SPT threading model is no longer supported as of OpenSSL 3.2.
|
||||
|
||||
|
|
@ -52,14 +53,25 @@ instead of `nsx` in the set above.
|
|||
You cannot build for TNS/E for FIPS, so you must specify the `no-fips`
|
||||
option to `./Configure`.
|
||||
|
||||
TNS/E has moved to a limited support state, so fixes for this platform will not
|
||||
be guaranteed in future.
|
||||
Linking and Loading Considerations
|
||||
----------------------------------
|
||||
|
||||
Secure Memory
|
||||
-------------
|
||||
Because of how the NonStop Common Runtime Environment (CRE) works, there are
|
||||
restrictions on how programs can link and load with OpenSSL libraries.
|
||||
On current NonStop platforms, programs cannot both statically link OpenSSL
|
||||
libraries and dynamically load OpenSSL shared libraries concurrently. If this
|
||||
is done, there is a high probability of encountering a SIGSEGV condition
|
||||
relating to `atexit()` processing when a shared library is unloaded and when
|
||||
the program terminates. This limitation applies to all OpenSSL shared library
|
||||
components.
|
||||
|
||||
The mechanism used by OpenSSL for secure memory is not supported on NonStop.
|
||||
Use the `no-secure-memory` option when running `Configure`.
|
||||
A control has been added as of 3.3.x to disable calls to `atexit()` within the
|
||||
`libcrypto` builds (specifically in `crypto/init.c`). This switch can be
|
||||
controlled using `disable-atexit` or `enable-atexit`, and is disabled by default
|
||||
for NonStop builds. If you need to have `atexit()` functionality, set
|
||||
`enabled-atexit` when configuring OpenSSL to enable the `atexit()` call to
|
||||
register `OPENSSL_cleanup()` automatically. Preferably, you can explicitly call
|
||||
`OPENSSL_cleanup()` from your application.
|
||||
|
||||
About Prefix and OpenSSLDir
|
||||
---------------------------
|
||||
|
|
@ -167,7 +179,7 @@ the following variables. The following set of compiler defines are required:
|
|||
### Optional Build Variables
|
||||
|
||||
DBGFLAG="--debug"
|
||||
CIPHENABLES="enable-weak-ssl-ciphers enable-rc4"
|
||||
CIPHENABLES="enable-ssl3 enable-ssl3-method enable-weak-ssl-ciphers enable-rc4"
|
||||
|
||||
### Internal Known TNS/X to TNS/E Cross Compile Variables
|
||||
|
||||
|
|
|
|||
|
|
@ -70,76 +70,3 @@ with the `VERBOSE` or `VF` or `VFP` options to gather additional information.
|
|||
|
||||
$ make test VERBOSE=1 TESTS=test_test EXE_SHELL="$(/bin/pwd)/util/wrap.pl \
|
||||
valgrind --error-exitcode=1 --leak-check=full -q" OPENSSL_ia32cap=":0"
|
||||
|
||||
Still reachable memory
|
||||
======================
|
||||
|
||||
OpenSSL 4.0 no longer arms `OPENSSL_cleanup()` function as an `atexit(3)`
|
||||
handler. So, unless the application explicitly calls `OPENSSL_cleanup()`, valgrind and
|
||||
similar memory leak detectors may report `still reachable` memory blocks
|
||||
as memory leaks. An example of a valgrind report reads as follows:
|
||||
|
||||
# valgrind ./pkeyread -f pem -k dh 8
|
||||
==280439== Memcheck, a memory error detector
|
||||
==280439== Copyright (C) 2002-2024, and GNU GPL'd, by Julian Seward et al.
|
||||
==280439== Using Valgrind-3.24.0 and LibVEX; rerun with -h for copyright info
|
||||
==280439== Command: ./pkeyread -f pem -k dh 8
|
||||
==280439==
|
||||
Average time per pem(dh) call: 506329.113924us
|
||||
==280439==
|
||||
==280439== HEAP SUMMARY:
|
||||
==280439== in use at exit: 239,521 bytes in 4,137 blocks
|
||||
==280439== total heap usage: 21,841 allocs, 17,704 frees, 4,089,104 bytes allocated
|
||||
==280439==
|
||||
==280439== LEAK SUMMARY:
|
||||
==280439== definitely lost: 0 bytes in 0 blocks
|
||||
==280439== indirectly lost: 0 bytes in 0 blocks
|
||||
==280439== possibly lost: 0 bytes in 0 blocks
|
||||
==280439== still reachable: 239,521 bytes in 4,137 blocks
|
||||
==280439== suppressed: 0 bytes in 0 blocks
|
||||
==280439== Rerun with --leak-check=full to see details of leaked memory
|
||||
==280439==
|
||||
==280439== For lists of detected and suppressed errors, rerun with: -s
|
||||
==280439== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0)
|
||||
|
||||
The valgrind output above reports there are 239,521 of reachable memory
|
||||
when process exits. That memory is not regarded as a true memory leak
|
||||
as the OS will reclaim that memory on process exit, rendering calls to libc
|
||||
`free()` within `OPENSSL_cleanup()` useless. Also calling `OPENSSL_cleanup()`
|
||||
is discouraged when libcrypto is being linked with process to satisfy more
|
||||
than one dependency paths. If it is the case then calling `OPENSSL_cleanup()`
|
||||
may lead to spurious application crashes during exit.
|
||||
|
||||
If memory leaks caused by _still reachable memory_ are still an issue,
|
||||
then preferred way is to suppress those reports using the suppression
|
||||
file [1] instead of changing exiting code by adding a call to `OPENSSL_cleanup()`.
|
||||
The suppression file for OpenSSL is shipped within the OpenSSL sources and
|
||||
can be found at`$OPENSSL_SRCS/util/valgrind.suppressions` where `OPENSSL_SRCS`
|
||||
is an environment variable containing path to the OpenSSL source
|
||||
tree. To use it, just add `--suppressions` option to the valgrind command:
|
||||
`valgrind --suppressions="$OPENSSL_SRCS/util/valgrind.suppression" ...`
|
||||
For `pkeyread` the command and output reads as follows:
|
||||
|
||||
# valgrind --suppressions=$OPENSSL_SRCS/util/valgrind.suppression ./pkeyread -f pem -k dh 8
|
||||
==280896== Memcheck, a memory error detector
|
||||
==280896== Copyright (C) 2002-2024, and GNU GPL'd, by Julian Seward et al.
|
||||
==280896== Using Valgrind-3.24.0 and LibVEX; rerun with -h for copyright info
|
||||
==280896== Command: ./pkeyread -f pem -k dh 8
|
||||
==280896==
|
||||
Average time per pem(dh) call: 476190.476190us
|
||||
==280896==
|
||||
==280896== HEAP SUMMARY:
|
||||
==280896== in use at exit: 239,521 bytes in 4,137 blocks
|
||||
==280896== total heap usage: 22,816 allocs, 18,679 frees, 4,325,714 bytes allocated
|
||||
==280896==
|
||||
==280896== LEAK SUMMARY:
|
||||
==280896== definitely lost: 0 bytes in 0 blocks
|
||||
==280896== indirectly lost: 0 bytes in 0 blocks
|
||||
==280896== possibly lost: 0 bytes in 0 blocks
|
||||
==280896== still reachable: 0 bytes in 0 blocks
|
||||
==280896== suppressed: 239,521 bytes in 4,137 blocks
|
||||
==280896==
|
||||
==280896== For lists of detected and suppressed errors, rerun with: -s
|
||||
==280896== ERROR SUMMARY: 0 errors from 0 contexts (suppressed: 0 from 0)
|
||||
|
||||
[1] <https://valgrind.org/docs/manual/manual-core.html#manual-core.suppress>
|
||||
|
|
|
|||
|
|
@ -7,8 +7,6 @@ Notes for Windows platforms
|
|||
- [Native builds using MinGW](#native-builds-using-mingw)
|
||||
- [Linking native applications](#linking-native-applications)
|
||||
- [Hosted builds using Cygwin](#hosted-builds-using-cygwin)
|
||||
- [Hosted builds using Windows Subsystem for Linux (WSL)](
|
||||
#hosted-builds-using-windows-subsystem-for-linux-wsl)
|
||||
|
||||
There are various options to build and run OpenSSL on the Windows platforms.
|
||||
|
||||
|
|
@ -25,7 +23,7 @@ or
|
|||
|
||||
"Hosted" OpenSSL relies on an external POSIX compatibility layer
|
||||
for building (using GNU/Unix shell, compiler, and tools) and at run time.
|
||||
For this option, you can use Cygwin or the Windows Subsystem for Linux (WSL).
|
||||
For this option, you can use Cygwin.
|
||||
|
||||
Native builds using Visual C++
|
||||
==============================
|
||||
|
|
@ -89,18 +87,6 @@ Quick start
|
|||
on the Universal CRT or
|
||||
- `perl Configure` to let Configure figure out the platform
|
||||
|
||||
a. If you don't plan to develop OpenSSL yourself and don't need to rebuild,
|
||||
in other words, if you always do a new build, turning off the build
|
||||
dependency feature can speed up build times by up to 50%:
|
||||
`perl Configure no-makedepend`
|
||||
|
||||
b. If you want the OpenSSL binaries to be "self contained", usable on any
|
||||
computer running MS Windows, use 'perl Configure enable-static-vcruntime'.
|
||||
Otherwise, build will produce binaries that depend on the VC runtime
|
||||
libraries being installed and available, and will not work on computers
|
||||
that do not have them. (This option adds 1 MB to the total size of the
|
||||
two dll's.)
|
||||
|
||||
6. `nmake`
|
||||
|
||||
7. `nmake test`
|
||||
|
|
@ -121,10 +107,11 @@ install it to a variety of locations.
|
|||
The following keys:
|
||||
|
||||
`\\HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\OpenSSL-<version>-<ctx>\OPENSSLDIR`
|
||||
`\\HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\OpenSSL-<version>-<ctx>\ENGINESDIR`
|
||||
`\\HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\OpenSSL-<version>-<ctx>\MODULESDIR`
|
||||
|
||||
Can be administratively set, and openssl will take the paths found there as the
|
||||
values for OPENSSLDIR and MODULESDIR respectively.
|
||||
values for OPENSSLDIR, ENGINESDIR and MODULESDIR respectively.
|
||||
|
||||
To enable the reading of registry keys from windows builds, add
|
||||
`-DOSSL_WINCTX=<string>`to the Configure command line. This define is used
|
||||
|
|
@ -133,7 +120,7 @@ format:
|
|||
`\\HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432node\OpenSSL-<version>-<ctx>`
|
||||
|
||||
Where `<version>` is the major.minor version of the library being
|
||||
built, and `<ctx>` is the value specified by `-DOSSL_WINCTX`. This allows
|
||||
built, and `<ctx>` is the value specified by `-DOPENSSL_WINCTX`. This allows
|
||||
for multiple openssl builds to be created and installed on a single system, in
|
||||
which each library can use its own set of registry keys.
|
||||
|
||||
|
|
@ -296,71 +283,3 @@ NOTE: `make test` and normal file operations may fail in directories
|
|||
mounted as text (i.e. `mount -t c:\somewhere /home`) due to Cygwin
|
||||
stripping of carriage returns. To avoid this, ensure that a binary
|
||||
mount is used, e.g. `mount -b c:\somewhere /home`.
|
||||
|
||||
Hosted builds using Windows Subsystem for Linux (WSL)
|
||||
======================================================
|
||||
|
||||
WSL provides a Linux-compatible environment directly on Windows, allowing
|
||||
OpenSSL to be built using standard GNU/Unix tools. The resulting OpenSSL
|
||||
runs within the WSL environment and relies on the WSL compatibility layer
|
||||
at run time.
|
||||
|
||||
1. Install WSL and a Linux distribution (e.g. Ubuntu), see
|
||||
<https://learn.microsoft.com/windows/wsl/install>
|
||||
|
||||
2. Ensure your distribution is up to date:
|
||||
|
||||
sudo apt update && sudo apt upgrade
|
||||
|
||||
3. Install the required build dependencies. On Debian/Ubuntu-based
|
||||
distributions:
|
||||
|
||||
sudo apt install build-essential perl make
|
||||
|
||||
4. Optionally install the NASM assembler for optimised assembly routines:
|
||||
|
||||
sudo apt install nasm
|
||||
|
||||
5. Run the WSL shell (e.g. Ubuntu) from the Start menu or by running
|
||||
`wsl` from a Windows command prompt
|
||||
|
||||
6. From the root of the OpenSSL source directory, configure the build:
|
||||
|
||||
./Configure
|
||||
|
||||
or specify a prefix and openssldir explicitly:
|
||||
|
||||
./Configure --prefix=/usr/local/ssl --openssldir=/usr/local/ssl
|
||||
|
||||
7. Build, test, and install:
|
||||
|
||||
make
|
||||
make test
|
||||
make install
|
||||
|
||||
Apart from the setup steps above, follow the Unix / Linux instructions
|
||||
in INSTALL.md and the shared library path guidance in NOTES-UNIX.md.
|
||||
|
||||
NOTE: The OpenSSL source tree should reside on the Linux filesystem
|
||||
(e.g. under `~/`) rather than on a mounted Windows path such as
|
||||
`/mnt/c/`. Building from a mounted Windows path can result in
|
||||
significantly slower build times and occasional failures due to
|
||||
filesystem permission and interoperability differences between NTFS
|
||||
and the Linux layer. If your source is on the Windows filesystem,
|
||||
copy it into the WSL home directory first:
|
||||
|
||||
cp -r /mnt/c/path/to/openssl ~/openssl
|
||||
|
||||
NOTE: If you do build from a mounted Windows path (e.g. /mnt/c/), be aware
|
||||
that Windows line endings (CRLF) in source or script files can cause
|
||||
configure and build scripts to fail. In this case, run dos2unix on the
|
||||
affected files before building:
|
||||
|
||||
dos2unix Configure # removes all \r (carriage return) characters
|
||||
dos2unix config # does the same, but for the config script
|
||||
dos2unix *.sh # runs dos2unix on all shell scripts in the directory,
|
||||
# ensuring every .sh file has correct Unix line endings
|
||||
|
||||
dos2unix can be installed via:
|
||||
|
||||
sudo apt install dos2unix
|
||||
|
|
|
|||
317
README-ENGINES.md
Normal file
317
README-ENGINES.md
Normal file
|
|
@ -0,0 +1,317 @@
|
|||
Engines
|
||||
=======
|
||||
|
||||
Deprecation Note
|
||||
----------------
|
||||
|
||||
The ENGINE API was introduced in OpenSSL version 0.9.6 as a low level
|
||||
interface for adding alternative implementations of cryptographic
|
||||
primitives, most notably for integrating hardware crypto devices.
|
||||
|
||||
The ENGINE interface has its limitations and it has been superseded
|
||||
by the [PROVIDER API](README-PROVIDERS.md), it is deprecated in OpenSSL
|
||||
version 3.0. The following documentation is retained as an aid for
|
||||
users who need to maintain or support existing ENGINE implementations.
|
||||
Support for new hardware devices or new algorithms should be added
|
||||
via providers, and existing engines should be converted to providers
|
||||
as soon as possible.
|
||||
|
||||
Built-in ENGINE implementations
|
||||
-------------------------------
|
||||
|
||||
There are currently built-in ENGINE implementations for the following
|
||||
crypto devices:
|
||||
|
||||
- Microsoft CryptoAPI
|
||||
- VIA Padlock
|
||||
- nCipher CHIL
|
||||
|
||||
In addition, dynamic binding to external ENGINE implementations is now
|
||||
provided by a special ENGINE called "dynamic". See the "DYNAMIC ENGINE"
|
||||
section below for details.
|
||||
|
||||
At this stage, a number of things are still needed and are being worked on:
|
||||
|
||||
1. Integration of EVP support.
|
||||
2. Configuration support.
|
||||
3. Documentation!
|
||||
|
||||
Integration of EVP support
|
||||
--------------------------
|
||||
|
||||
With respect to EVP, this relates to support for ciphers and digests in
|
||||
the ENGINE model so that alternative implementations of existing
|
||||
algorithms/modes (or previously unimplemented ones) can be provided by
|
||||
ENGINE implementations.
|
||||
|
||||
Configuration support
|
||||
---------------------
|
||||
|
||||
Configuration support currently exists in the ENGINE API itself, in the
|
||||
form of "control commands". These allow an application to expose to the
|
||||
user/admin the set of commands and parameter types a given ENGINE
|
||||
implementation supports, and for an application to directly feed string
|
||||
based input to those ENGINEs, in the form of name-value pairs. This is an
|
||||
extensible way for ENGINEs to define their own "configuration" mechanisms
|
||||
that are specific to a given ENGINE (eg. for a particular hardware
|
||||
device) but that should be consistent across *all* OpenSSL-based
|
||||
applications when they use that ENGINE. Work is in progress (or at least
|
||||
in planning) for supporting these control commands from the CONF (or
|
||||
NCONF) code so that applications using OpenSSL's existing configuration
|
||||
file format can have ENGINE settings specified in much the same way.
|
||||
Presently however, applications must use the ENGINE API itself to provide
|
||||
such functionality. To see first hand the types of commands available
|
||||
with the various compiled-in ENGINEs (see further down for dynamic
|
||||
ENGINEs), use the "engine" openssl utility with full verbosity, i.e.:
|
||||
|
||||
openssl engine -vvvv
|
||||
|
||||
Documentation
|
||||
-------------
|
||||
|
||||
Documentation? Volunteers welcome! The source code is reasonably well
|
||||
self-documenting, but some summaries and usage instructions are needed -
|
||||
moreover, they are needed in the same POD format the existing OpenSSL
|
||||
documentation is provided in. Any complete or incomplete contributions
|
||||
would help make this happen.
|
||||
|
||||
STABILITY & BUG-REPORTS
|
||||
=======================
|
||||
|
||||
What already exists is fairly stable as far as it has been tested, but
|
||||
the test base has been a bit small most of the time. For the most part,
|
||||
the vendors of the devices these ENGINEs support have contributed to the
|
||||
development and/or testing of the implementations, and *usually* (with no
|
||||
guarantees) have experience in using the ENGINE support to drive their
|
||||
devices from common OpenSSL-based applications. Bugs and/or inexplicable
|
||||
behaviour in using a specific ENGINE implementation should be sent to the
|
||||
author of that implementation (if it is mentioned in the corresponding C
|
||||
file), and in the case of implementations for commercial hardware
|
||||
devices, also through whatever vendor support channels are available. If
|
||||
none of this is possible, or the problem seems to be something about the
|
||||
ENGINE API itself (ie. not necessarily specific to a particular ENGINE
|
||||
implementation) then you should mail complete details to the relevant
|
||||
OpenSSL mailing list. For a definition of "complete details", refer to
|
||||
the OpenSSL "README" file. As for which list to send it to:
|
||||
|
||||
- openssl-users: if you are *using* the ENGINE abstraction, either in an
|
||||
pre-compiled application or in your own application code.
|
||||
|
||||
- openssl-dev: if you are discussing problems with OpenSSL source code.
|
||||
|
||||
USAGE
|
||||
=====
|
||||
|
||||
The default "openssl" ENGINE is always chosen when performing crypto
|
||||
operations unless you specify otherwise. You must actively tell the
|
||||
openssl utility commands to use anything else through a new command line
|
||||
switch called "-engine". Also, if you want to use the ENGINE support in
|
||||
your own code to do something similar, you must likewise explicitly
|
||||
select the ENGINE implementation you want.
|
||||
|
||||
Depending on the type of hardware, system, and configuration, "settings"
|
||||
may need to be applied to an ENGINE for it to function as expected/hoped.
|
||||
The recommended way of doing this is for the application to support
|
||||
ENGINE "control commands" so that each ENGINE implementation can provide
|
||||
whatever configuration primitives it might require and the application
|
||||
can allow the user/admin (and thus the hardware vendor's support desk
|
||||
also) to provide any such input directly to the ENGINE implementation.
|
||||
This way, applications do not need to know anything specific to any
|
||||
device, they only need to provide the means to carry such user/admin
|
||||
input through to the ENGINE in question. Ie. this connects *you* (and
|
||||
your helpdesk) to the specific ENGINE implementation (and device), and
|
||||
allows application authors to not get buried in hassle supporting
|
||||
arbitrary devices they know (and care) nothing about.
|
||||
|
||||
A new "openssl" utility, "openssl engine", has been added in that allows
|
||||
for testing and examination of ENGINE implementations. Basic usage
|
||||
instructions are available by specifying the "-?" command line switch.
|
||||
|
||||
DYNAMIC ENGINES
|
||||
===============
|
||||
|
||||
The new "dynamic" ENGINE provides a low-overhead way to support ENGINE
|
||||
implementations that aren't pre-compiled and linked into OpenSSL-based
|
||||
applications. This could be because existing compiled-in implementations
|
||||
have known problems and you wish to use a newer version with an existing
|
||||
application. It could equally be because the application (or OpenSSL
|
||||
library) you are using simply doesn't have support for the ENGINE you
|
||||
wish to use, and the ENGINE provider (eg. hardware vendor) is providing
|
||||
you with a self-contained implementation in the form of a shared-library.
|
||||
The other use-case for "dynamic" is with applications that wish to
|
||||
maintain the smallest foot-print possible and so do not link in various
|
||||
ENGINE implementations from OpenSSL, but instead leaves you to provide
|
||||
them, if you want them, in the form of "dynamic"-loadable
|
||||
shared-libraries. It should be possible for hardware vendors to provide
|
||||
their own shared-libraries to support arbitrary hardware to work with
|
||||
applications based on OpenSSL 0.9.7 or later. If you're using an
|
||||
application based on 0.9.7 (or later) and the support you desire is only
|
||||
announced for versions later than the one you need, ask the vendor to
|
||||
backport their ENGINE to the version you need.
|
||||
|
||||
How does "dynamic" work?
|
||||
------------------------
|
||||
|
||||
The dynamic ENGINE has a special flag in its implementation such that
|
||||
every time application code asks for the 'dynamic' ENGINE, it in fact
|
||||
gets its own copy of it. As such, multi-threaded code (or code that
|
||||
multiplexes multiple uses of 'dynamic' in a single application in any
|
||||
way at all) does not get confused by 'dynamic' being used to do many
|
||||
independent things. Other ENGINEs typically don't do this so there is
|
||||
only ever 1 ENGINE structure of its type (and reference counts are used
|
||||
to keep order). The dynamic ENGINE itself provides absolutely no
|
||||
cryptographic functionality, and any attempt to "initialise" the ENGINE
|
||||
automatically fails. All it does provide are a few "control commands"
|
||||
that can be used to control how it will load an external ENGINE
|
||||
implementation from a shared-library. To see these control commands,
|
||||
use the command-line;
|
||||
|
||||
openssl engine -vvvv dynamic
|
||||
|
||||
The "SO_PATH" control command should be used to identify the
|
||||
shared-library that contains the ENGINE implementation, and "NO_VCHECK"
|
||||
might possibly be useful if there is a minor version conflict and you
|
||||
(or a vendor helpdesk) is convinced you can safely ignore it.
|
||||
"ID" is probably only needed if a shared-library implements
|
||||
multiple ENGINEs, but if you know the engine id you expect to be using,
|
||||
it doesn't hurt to specify it (and this provides a sanity check if
|
||||
nothing else). "LIST_ADD" is only required if you actually wish the
|
||||
loaded ENGINE to be discoverable by application code later on using the
|
||||
ENGINE's "id". For most applications, this isn't necessary - but some
|
||||
application authors may have nifty reasons for using it. The "LOAD"
|
||||
command is the only one that takes no parameters and is the command
|
||||
that uses the settings from any previous commands to actually *load*
|
||||
the shared-library ENGINE implementation. If this command succeeds, the
|
||||
(copy of the) 'dynamic' ENGINE will magically morph into the ENGINE
|
||||
that has been loaded from the shared-library. As such, any control
|
||||
commands supported by the loaded ENGINE could then be executed as per
|
||||
normal. For instance, if ENGINE "foo" is implemented in the shared-library
|
||||
"libfoo.so" and it supports some special control command "CMD_FOO", the
|
||||
following code would load and use it (NB: obviously this code has no
|
||||
error checking);
|
||||
|
||||
ENGINE *e = ENGINE_by_id("dynamic");
|
||||
ENGINE_ctrl_cmd_string(e, "SO_PATH", "/lib/libfoo.so", 0);
|
||||
ENGINE_ctrl_cmd_string(e, "ID", "foo", 0);
|
||||
ENGINE_ctrl_cmd_string(e, "LOAD", NULL, 0);
|
||||
ENGINE_ctrl_cmd_string(e, "CMD_FOO", "some input data", 0);
|
||||
|
||||
For testing, the "openssl engine" utility can be useful for this sort
|
||||
of thing. For example the above code excerpt would achieve much the
|
||||
same result as;
|
||||
|
||||
openssl engine dynamic \
|
||||
-pre SO_PATH:/lib/libfoo.so \
|
||||
-pre ID:foo \
|
||||
-pre LOAD \
|
||||
-pre "CMD_FOO:some input data"
|
||||
|
||||
Or to simply see the list of commands supported by the "foo" ENGINE;
|
||||
|
||||
openssl engine -vvvv dynamic \
|
||||
-pre SO_PATH:/lib/libfoo.so \
|
||||
-pre ID:foo \
|
||||
-pre LOAD
|
||||
|
||||
Applications that support the ENGINE API and more specifically, the
|
||||
"control commands" mechanism, will provide some way for you to pass
|
||||
such commands through to ENGINEs. As such, you would select "dynamic"
|
||||
as the ENGINE to use, and the parameters/commands you pass would
|
||||
control the *actual* ENGINE used. Each command is actually a name-value
|
||||
pair and the value can sometimes be omitted (eg. the "LOAD" command).
|
||||
Whilst the syntax demonstrated in "openssl engine" uses a colon to
|
||||
separate the command name from the value, applications may provide
|
||||
their own syntax for making that separation (eg. a win32 registry
|
||||
key-value pair may be used by some applications). The reason for the
|
||||
"-pre" syntax in the "openssl engine" utility is that some commands
|
||||
might be issued to an ENGINE *after* it has been initialised for use.
|
||||
Eg. if an ENGINE implementation requires a smart-card to be inserted
|
||||
during initialisation (or a PIN to be typed, or whatever), there may be
|
||||
a control command you can issue afterwards to "forget" the smart-card
|
||||
so that additional initialisation is no longer possible. In
|
||||
applications such as web-servers, where potentially volatile code may
|
||||
run on the same host system, this may provide some arguable security
|
||||
value. In such a case, the command would be passed to the ENGINE after
|
||||
it has been initialised for use, and so the "-post" switch would be
|
||||
used instead. Applications may provide a different syntax for
|
||||
supporting this distinction, and some may simply not provide it at all
|
||||
("-pre" is almost always what you're after, in reality).
|
||||
|
||||
How do I build a "dynamic" ENGINE?
|
||||
----------------------------------
|
||||
|
||||
This question is trickier - currently OpenSSL bundles various ENGINE
|
||||
implementations that are statically built in, and any application that
|
||||
calls the "ENGINE_load_builtin_engines()" function will automatically
|
||||
have all such ENGINEs available (and occupying memory). Applications
|
||||
that don't call that function have no ENGINEs available like that and
|
||||
would have to use "dynamic" to load any such ENGINE - but on the other
|
||||
hand such applications would only have the memory footprint of any
|
||||
ENGINEs explicitly loaded using user/admin provided control commands.
|
||||
The main advantage of not statically linking ENGINEs and only using
|
||||
"dynamic" for hardware support is that any installation using no
|
||||
"external" ENGINE suffers no unnecessary memory footprint from unused
|
||||
ENGINEs. Likewise, installations that do require an ENGINE incur the
|
||||
overheads from only *that* ENGINE once it has been loaded.
|
||||
|
||||
Sounds good? Maybe, but currently building an ENGINE implementation as
|
||||
a shared-library that can be loaded by "dynamic" isn't automated in
|
||||
OpenSSL's build process. It can be done manually quite easily however.
|
||||
Such a shared-library can either be built with any OpenSSL code it
|
||||
needs statically linked in, or it can link dynamically against OpenSSL
|
||||
if OpenSSL itself is built as a shared library. The instructions are
|
||||
the same in each case, but in the former (statically linked any
|
||||
dependencies on OpenSSL) you must ensure OpenSSL is built with
|
||||
position-independent code ("PIC"). The default OpenSSL compilation may
|
||||
already specify the relevant flags to do this, but you should consult
|
||||
with your compiler documentation if you are in any doubt.
|
||||
|
||||
This example will show building the "atalla" ENGINE in the
|
||||
crypto/engine/ directory as a shared-library for use via the "dynamic"
|
||||
ENGINE.
|
||||
|
||||
1. "cd" to the crypto/engine/ directory of a pre-compiled OpenSSL
|
||||
source tree.
|
||||
|
||||
2. Recompile at least one source file so you can see all the compiler
|
||||
flags (and syntax) being used to build normally. Eg;
|
||||
|
||||
touch hw_atalla.c ; make
|
||||
|
||||
will rebuild "hw_atalla.o" using all such flags.
|
||||
|
||||
3. Manually enter the same compilation line to compile the
|
||||
"hw_atalla.c" file but with the following two changes;
|
||||
|
||||
- add "-DENGINE_DYNAMIC_SUPPORT" to the command line switches,
|
||||
- change the output file from "hw_atalla.o" to something new,
|
||||
eg. "tmp_atalla.o"
|
||||
|
||||
4. Link "tmp_atalla.o" into a shared-library using the top-level
|
||||
OpenSSL libraries to resolve any dependencies. The syntax for doing
|
||||
this depends heavily on your system/compiler and is a nightmare
|
||||
known well to anyone who has worked with shared-library portability
|
||||
before. 'gcc' on Linux, for example, would use the following syntax;
|
||||
|
||||
gcc -shared -o dyn_atalla.so tmp_atalla.o -L../.. -lcrypto
|
||||
|
||||
5. Test your shared library using "openssl engine" as explained in the
|
||||
previous section. Eg. from the top-level directory, you might try
|
||||
|
||||
apps/openssl engine -vvvv dynamic \
|
||||
-pre SO_PATH:./crypto/engine/dyn_atalla.so -pre LOAD
|
||||
|
||||
If the shared-library loads successfully, you will see both "-pre"
|
||||
commands marked as "SUCCESS" and the list of control commands
|
||||
displayed (because of "-vvvv") will be the control commands for the
|
||||
*atalla* ENGINE (ie. *not* the 'dynamic' ENGINE). You can also add
|
||||
the "-t" switch to the utility if you want it to try and initialise
|
||||
the atalla ENGINE for use to test any possible hardware/driver issues.
|
||||
|
||||
PROBLEMS
|
||||
========
|
||||
|
||||
It seems like the ENGINE part doesn't work too well with CryptoSwift on Win32.
|
||||
A quick test done right before the release showed that trying "openssl speed
|
||||
-engine cswift" generated errors. If the DSO gets enabled, an attempt is made
|
||||
to write at memory address 0x00000002.
|
||||
|
|
@ -18,7 +18,7 @@ See <https://www.openssl.org/source/> for information related to OpenSSL
|
|||
FIPS certificates and Security Policies.
|
||||
|
||||
Newer OpenSSL Releases that include security or bug fixes can be used to build
|
||||
all other components (such as the core APIs, TLS and the default, base and
|
||||
all other components (such as the core API's, TLS and the default, base and
|
||||
legacy providers) without any restrictions, but the FIPS provider must be built
|
||||
as specified in the Security Policy (normally with a different version of the
|
||||
source code).
|
||||
|
|
@ -109,19 +109,19 @@ which versions are FIPS validated. For this example we use OpenSSL 3.1.2.
|
|||
Download and build the latest release of OpenSSL
|
||||
------------------------------------------------
|
||||
|
||||
We use OpenSSL 3.6.0 here, (but you could also use the latest 3.6.X)
|
||||
We use OpenSSL 3.5.0 here, (but you could also use the latest 3.5.X)
|
||||
|
||||
$ wget https://www.openssl.org/source/openssl-3.6.0.tar.gz
|
||||
$ tar -xf openssl-3.6.0.tar.gz
|
||||
$ cd openssl-3.6.0
|
||||
$ wget https://www.openssl.org/source/openssl-3.5.0.tar.gz
|
||||
$ tar -xf openssl-3.5.0.tar.gz
|
||||
$ cd openssl-3.5.0
|
||||
$ ./Configure enable-fips
|
||||
$ make
|
||||
|
||||
Use the OpenSSL FIPS provider for testing
|
||||
-----------------------------------------
|
||||
|
||||
We do this by replacing the artifact for the OpenSSL 3.6.0 FIPS provider.
|
||||
Note that the OpenSSL 3.6.0 FIPS provider has not been validated
|
||||
We do this by replacing the artifact for the OpenSSL 3.5.0 FIPS provider.
|
||||
Note that the OpenSSL 3.5.0 FIPS provider has not been validated
|
||||
so it must not be used for FIPS purposes.
|
||||
|
||||
$ cp ../openssl-3.1.2/providers/fips.so providers/.
|
||||
|
|
@ -147,7 +147,7 @@ Copy the FIPS provider artifacts (`fips.so` & `fipsmodule.cnf`) to known locatio
|
|||
Check that the correct FIPS provider is being used
|
||||
--------------------------------------------------
|
||||
|
||||
$ cd ../openssl-3.6.0
|
||||
$ cd ../openssl-3.5.0
|
||||
$./util/wrap.pl -fips apps/openssl list -provider-path providers \
|
||||
-provider fips -providers
|
||||
|
||||
|
|
@ -155,7 +155,7 @@ Check that the correct FIPS provider is being used
|
|||
Providers:
|
||||
base
|
||||
name: OpenSSL Base Provider
|
||||
version: 3.6.0
|
||||
version: 3.5.0
|
||||
status: active
|
||||
fips
|
||||
name: OpenSSL FIPS Provider
|
||||
|
|
|
|||
|
|
@ -12,7 +12,7 @@ some of the following resources:
|
|||
- The [OpenSSL Guide] incorporates various code samples. The complete source
|
||||
for these can be [found in the source tree under `demos/guide`](./demos/guide/).
|
||||
- The [openssl-quic(7) manual page], which provides a basic reference overview
|
||||
of QUIC functionality and how the use of QUIC differs from the use of TLS with regard
|
||||
of QUIC functionality and how use of QUIC differs from use of TLS with regard
|
||||
to our API.
|
||||
- The [Demo-Driven Design (DDD)][DDD] demos, which demonstrate the use of QUIC
|
||||
using simple examples. These can be [found in the source tree under
|
||||
|
|
@ -61,7 +61,7 @@ $ openssl s_client -quic -alpn myalpn -connect host:port
|
|||
|
||||
In the above example replace `host` with the hostname of the server (e.g.
|
||||
`www.example.com`) and `port` with the port for the server (e.g. `443`). Replace
|
||||
`myalpn` with the Application Layer Protocol to use (e.g. `h3` represents
|
||||
`myalpn` with the Application Layer Protocol to use (e.g.`h3` represents
|
||||
HTTP/3). IANA maintains a standard list of [ALPN ids] that can be used.
|
||||
|
||||
This example connects to a QUIC server and opens a single bidirectional stream.
|
||||
|
|
|
|||
22
README.md
22
README.md
|
|
@ -4,14 +4,13 @@ Welcome to the OpenSSL Project
|
|||
[![openssl logo]][www.openssl.org]
|
||||
|
||||
[![github actions ci badge]][github actions ci]
|
||||
[](https://github.com/openssl/openssl/actions/workflows/os-zoo.yml)
|
||||
[](https://github.com/openssl/openssl/actions/workflows/provider-compatibility.yml)
|
||||
[](https://github.com/openssl/openssl/actions/workflows/run_quic_interop.yml)
|
||||
[](https://github.com/openssl/openssl/actions/workflows/run-checker-daily.yml)
|
||||
[](https://insights.linuxfoundation.org/project/openssl)
|
||||

|
||||

|
||||

|
||||

|
||||
|
||||
OpenSSL is a robust, commercial-grade, full-featured Open Source Toolkit
|
||||
for the Transport Layer Security (TLS, formerly SSL), Datagram TLS (DTLS), and QUIC protocols.
|
||||
for the TLS (formerly SSL), DTLS and QUIC protocols.
|
||||
|
||||
The protocol implementations are based on a full-strength general purpose
|
||||
cryptographic library, which can also be used stand-alone. Also included is a
|
||||
|
|
@ -49,7 +48,7 @@ The OpenSSL toolkit includes:
|
|||
basis of the TLS implementation, but can also be used independently.
|
||||
|
||||
- **openssl**
|
||||
the OpenSSL command line tool, a Swiss Army knife for cryptographic tasks,
|
||||
the OpenSSL command line tool, a swiss army knife for cryptographic tasks,
|
||||
testing and analyzing. It can be used for
|
||||
- creation of key parameters
|
||||
- creation of X.509 certificates, CSRs and CRLs
|
||||
|
|
@ -136,6 +135,7 @@ containing additional information on specific topics.
|
|||
* [Information about the OpenSSL QUIC protocol implementation](README-QUIC.md)
|
||||
* [Information about the OpenSSL Provider architecture](README-PROVIDERS.md)
|
||||
* [Information about using the OpenSSL FIPS validated module](README-FIPS.md)
|
||||
* [Information about the legacy OpenSSL Engine architecture](README-ENGINES.md)
|
||||
|
||||
The OpenSSL Guide
|
||||
-----------------
|
||||
|
|
@ -150,10 +150,10 @@ The manual pages for the master branch and all current stable releases are
|
|||
available online.
|
||||
|
||||
- [OpenSSL master](https://docs.openssl.org/master/)
|
||||
- [OpenSSL 4.0](https://docs.openssl.org/4.0/)
|
||||
- [OpenSSL 3.6](https://docs.openssl.org/3.6/)
|
||||
- [OpenSSL 3.5](https://docs.openssl.org/3.5/)
|
||||
- [OpenSSL 3.4](https://docs.openssl.org/3.4/)
|
||||
- [OpenSSL 3.3](https://docs.openssl.org/3.3/)
|
||||
- [OpenSSL 3.2](https://docs.openssl.org/3.2/)
|
||||
- [OpenSSL 3.0](https://docs.openssl.org/3.0/)
|
||||
|
||||
Demos
|
||||
|
|
@ -198,7 +198,7 @@ attempting to develop or distribute cryptographic code.
|
|||
Copyright
|
||||
=========
|
||||
|
||||
Copyright (c) 1998-2026 The OpenSSL Project Authors
|
||||
Copyright (c) 1998-2025 The OpenSSL Project Authors
|
||||
|
||||
Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson
|
||||
|
||||
|
|
@ -250,7 +250,7 @@ All rights reserved.
|
|||
"GitHub Actions CI Status"
|
||||
|
||||
[github actions ci]:
|
||||
<https://github.com/openssl/openssl/actions/workflows/ci.yml>
|
||||
<https://github.com/openssl/openssl/actions?query=workflow%3A%22GitHub+CI%22>
|
||||
"GitHub Actions CI"
|
||||
|
||||
[appveyor badge]:
|
||||
|
|
|
|||
|
|
@ -1,7 +1,7 @@
|
|||
MAJOR=4
|
||||
MINOR=1
|
||||
MAJOR=3
|
||||
MINOR=6
|
||||
PATCH=0
|
||||
PRE_RELEASE_TAG=dev
|
||||
BUILD_METADATA=
|
||||
RELEASE_DATE=""
|
||||
SHLIB_VERSION=4
|
||||
SHLIB_VERSION=3
|
||||
|
|
|
|||
|
|
@ -10,7 +10,7 @@
|
|||
use strict;
|
||||
use warnings;
|
||||
|
||||
my @directory_vars = ( "dir", "certs", "new_certs_dir" );
|
||||
my @directory_vars = ( "dir", "certs", "crl_dir", "new_certs_dir" );
|
||||
my @file_vars = ( "database", "certificate", "serial", "crlnumber",
|
||||
"crl", "private_key", "RANDFILE" );
|
||||
while(<STDIN>) {
|
||||
|
|
|
|||
|
|
@ -5,3 +5,10 @@ $ v := {- sprintf "%02d", split(/\./, $config{version}) -}
|
|||
$
|
||||
$ OPENSSL'v' :== $OSSL$EXE:OPENSSL'v'
|
||||
$ OPENSSL :== $OSSL$EXE:OPENSSL'v'
|
||||
$
|
||||
$ IF F$TYPE(PERL) .EQS. "STRING"
|
||||
$ THEN
|
||||
$ C_REHASH :== 'PERL' OSSL$EXE:c_rehash.pl
|
||||
$ ELSE
|
||||
$ WRITE SYS$ERROR "NOTE: no perl => no C_REHASH"
|
||||
$ ENDIF
|
||||
|
|
|
|||
262
apps/CA.pl.in
262
apps/CA.pl.in
|
|
@ -1,5 +1,5 @@
|
|||
#!{- $config{HASHBANGPERL} -}
|
||||
# Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
# Copyright 2000-2021 The OpenSSL Project Authors. All Rights Reserved.
|
||||
#
|
||||
# Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
# this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -19,17 +19,14 @@ my @OPENSSL_CMDS = ("req", "ca", "pkcs12", "x509", "verify");
|
|||
|
||||
my $openssl = $ENV{'OPENSSL'} // "openssl";
|
||||
$ENV{'OPENSSL'} = $openssl;
|
||||
my @openssl = split_val($openssl);
|
||||
|
||||
my $OPENSSL_CONFIG = $ENV{"OPENSSL_CONFIG"} // "";
|
||||
my @OPENSSL_CONFIG = split_val($OPENSSL_CONFIG);
|
||||
|
||||
# Command invocations.
|
||||
my @REQ = (@openssl, "req", @OPENSSL_CONFIG);
|
||||
my @CA = (@openssl, "ca", @OPENSSL_CONFIG);
|
||||
my @VERIFY = (@openssl, "verify");
|
||||
my @X509 = (@openssl, "x509");
|
||||
my @PKCS12 = (@openssl, "pkcs12");
|
||||
my $REQ = "$openssl req $OPENSSL_CONFIG";
|
||||
my $CA = "$openssl ca $OPENSSL_CONFIG";
|
||||
my $VERIFY = "$openssl verify";
|
||||
my $X509 = "$openssl x509";
|
||||
my $PKCS12 = "$openssl pkcs12";
|
||||
|
||||
# Default values for various configuration settings.
|
||||
my $CATOP = "./demoCA";
|
||||
|
|
@ -37,10 +34,10 @@ my $CAKEY = "cakey.pem";
|
|||
my $CAREQ = "careq.pem";
|
||||
my $CACERT = "cacert.pem";
|
||||
my $CACRL = "crl.pem";
|
||||
my @DAYS = qw(-days 365);
|
||||
my @CADAYS = qw(-days 1095); # 3 years
|
||||
my @EXTENSIONS = qw(-extensions v3_ca);
|
||||
my @POLICY = qw(-policy policy_anything);
|
||||
my $DAYS = "-days 365";
|
||||
my $CADAYS = "-days 1095"; # 3 years
|
||||
my $EXTENSIONS = "-extensions v3_ca";
|
||||
my $POLICY = "-policy policy_anything";
|
||||
my $NEWKEY = "newkey.pem";
|
||||
my $NEWREQ = "newreq.pem";
|
||||
my $NEWCERT = "newcert.pem";
|
||||
|
|
@ -48,177 +45,31 @@ my $NEWP12 = "newcert.p12";
|
|||
|
||||
# Commandline parsing
|
||||
my %EXTRA;
|
||||
my $WHAT = shift @ARGV // "";
|
||||
my $WHAT = shift @ARGV || "";
|
||||
@ARGV = parse_extra(@ARGV);
|
||||
my $RET = 0;
|
||||
|
||||
sub split_val {
|
||||
return split_val_win32(@_) if ($^O eq 'MSWin32');
|
||||
my ($val) = @_;
|
||||
my (@ret, @frag);
|
||||
|
||||
# Skip leading whitespace
|
||||
$val =~ m{\A[ \t]*}ogc;
|
||||
|
||||
# Unix shell-compatible split
|
||||
#
|
||||
# Handles backslash escapes outside quotes and
|
||||
# in double-quoted strings. Parameter and
|
||||
# command-substitution is silently ignored.
|
||||
# Bare newlines outside quotes and (trailing) backslashes are disallowed.
|
||||
|
||||
while (1) {
|
||||
last if (pos($val) == length($val));
|
||||
|
||||
# The first char is never a SPACE or TAB. Possible matches are:
|
||||
# 1. Ordinary string fragment
|
||||
# 2. Single-quoted string
|
||||
# 3. Double-quoted string
|
||||
# 4. Backslash escape
|
||||
# 5. Bare backlash or newline (rejected)
|
||||
#
|
||||
if ($val =~ m{\G([^'" \t\n\\]+)}ogc) {
|
||||
# Ordinary string
|
||||
push @frag, $1;
|
||||
} elsif ($val =~ m{\G'([^']*)'}ogc) {
|
||||
# Single-quoted string
|
||||
push @frag, $1;
|
||||
} elsif ($val =~ m{\G"}ogc) {
|
||||
# Double-quoted string
|
||||
push @frag, "";
|
||||
while (1) {
|
||||
last if ($val =~ m{\G"}ogc);
|
||||
if ($val =~ m{\G([^"\\]+)}ogcs) {
|
||||
# literals
|
||||
push @frag, $1;
|
||||
} elsif ($val =~ m{\G.(["\`\$\\])}ogc) {
|
||||
# backslash-escaped special
|
||||
push @frag, $1;
|
||||
} elsif ($val =~ m{\G.(.)}ogcs) {
|
||||
# backslashed non-special
|
||||
push @frag, "\\$1" unless $1 eq "\n";
|
||||
} else {
|
||||
die sprintf("Malformed quoted string: %s\n", $val);
|
||||
}
|
||||
}
|
||||
} elsif ($val =~ m{\G\\(.)}ogc) {
|
||||
# Backslash is unconditional escape outside quoted strings
|
||||
push @frag, $1 unless $1 eq "\n";
|
||||
} else {
|
||||
die sprintf("Bare backslash or newline in: '%s'\n", $val);
|
||||
}
|
||||
# Done if at SPACE, TAB or end, otherwise continue current fragment
|
||||
#
|
||||
next unless ($val =~ m{\G(?:[ \t]+|\z)}ogcs);
|
||||
push @ret, join("", splice(@frag)) if (@frag > 0);
|
||||
}
|
||||
# Handle final fragment
|
||||
push @ret, join("", splice(@frag)) if (@frag > 0);
|
||||
return @ret;
|
||||
}
|
||||
|
||||
sub split_val_win32 {
|
||||
my ($val) = @_;
|
||||
my (@ret, @frag);
|
||||
|
||||
# Skip leading whitespace
|
||||
$val =~ m{\A[ \t]*}ogc;
|
||||
|
||||
# Windows-compatible split
|
||||
# See: "Parsing C++ command-line arguments" in:
|
||||
# https://learn.microsoft.com/en-us/cpp/cpp/main-function-command-line-args?view=msvc-170
|
||||
#
|
||||
# Backslashes are special only when followed by a double-quote
|
||||
# Pairs of double-quotes make a single double-quote.
|
||||
# Closing double-quotes may be omitted.
|
||||
|
||||
while (1) {
|
||||
last if (pos($val) == length($val));
|
||||
|
||||
# The first char is never a SPACE or TAB.
|
||||
# 1. Ordinary string fragment
|
||||
# 2. Double-quoted string
|
||||
# 3. Backslashes preceding a double-quote
|
||||
# 4. Literal backslashes
|
||||
# 5. Bare newline (rejected)
|
||||
#
|
||||
if ($val =~ m{\G([^" \t\n\\]+)}ogc) {
|
||||
# Ordinary string
|
||||
push @frag, $1;
|
||||
} elsif ($val =~ m{\G"}ogc) {
|
||||
# Double-quoted string
|
||||
push @frag, "";
|
||||
while (1) {
|
||||
if ($val =~ m{\G("+)}ogc) {
|
||||
# Two double-quotes make one literal double-quote
|
||||
my $l = length($1);
|
||||
push @frag, q{"} x int($l/2) if ($l > 1);
|
||||
next if ($l % 2 == 0);
|
||||
last;
|
||||
}
|
||||
if ($val =~ m{\G([^"\\]+)}ogc) {
|
||||
push @frag, $1;
|
||||
} elsif ($val =~ m{\G((?>[\\]+))(?=")}ogc) {
|
||||
# Backslashes before a double-quote are escapes
|
||||
my $l = length($1);
|
||||
push @frag, q{\\} x int($l / 2);
|
||||
if ($l % 2 == 1) {
|
||||
++pos($val);
|
||||
push @frag, q{"};
|
||||
}
|
||||
} elsif ($val =~ m{\G((?:(?>[\\]+)[^"\\]+)+)}ogc) {
|
||||
# Backslashes not before a double-quote are not special
|
||||
push @frag, $1;
|
||||
} else {
|
||||
# Tolerate missing closing double-quote
|
||||
last;
|
||||
}
|
||||
}
|
||||
} elsif ($val =~ m{\G((?>[\\]+))(?=")}ogc) {
|
||||
my $l = length($1);
|
||||
push @frag, q{\\} x int($l / 2);
|
||||
if ($l % 2 == 1) {
|
||||
++pos($val);
|
||||
push @frag, q{"};
|
||||
}
|
||||
} elsif ($val =~ m{\G([\\]+)}ogc) {
|
||||
# Backslashes not before a double-quote are not special
|
||||
push @frag, $1;
|
||||
} else {
|
||||
die sprintf("Bare newline in: '%s'\n", $val);
|
||||
}
|
||||
# Done if at SPACE, TAB or end, otherwise continue current fragment
|
||||
#
|
||||
next unless ($val =~ m{\G(?:[ \t]+|\z)}ogcs);
|
||||
push @ret, join("", splice(@frag)) if (@frag > 0);
|
||||
}
|
||||
# Handle final fragment
|
||||
push @ret, join("", splice(@frag)) if (@frag);
|
||||
return @ret;
|
||||
}
|
||||
|
||||
# Split out "-extra-CMD value", and return new |@ARGV|. Fill in
|
||||
# |EXTRA{CMD}| with list of values.
|
||||
sub parse_extra
|
||||
{
|
||||
my @args;
|
||||
foreach ( @OPENSSL_CMDS ) {
|
||||
$EXTRA{$_} = [];
|
||||
$EXTRA{$_} = '';
|
||||
}
|
||||
while (@_) {
|
||||
my $arg = shift(@_);
|
||||
if ( $arg !~ m{^-extra-(\w+)$} ) {
|
||||
push @args, split_val($arg);
|
||||
|
||||
my @result;
|
||||
while ( scalar(@_) > 0 ) {
|
||||
my $arg = shift;
|
||||
if ( $arg !~ m/-extra-([a-z0-9]+)/ ) {
|
||||
push @result, $arg;
|
||||
next;
|
||||
}
|
||||
$arg = $1;
|
||||
die "Unknown \"-extra-${arg}\" option, exiting\n"
|
||||
unless grep { $arg eq $_ } @OPENSSL_CMDS;
|
||||
die "Missing \"-extra-${arg}\" option value, exiting\n"
|
||||
unless (@_ > 0);
|
||||
push @{$EXTRA{$arg}}, split_val(shift(@_));
|
||||
$arg =~ s/-extra-//;
|
||||
die("Unknown \"-${arg}-extra\" option, exiting")
|
||||
unless scalar grep { $arg eq $_ } @OPENSSL_CMDS;
|
||||
$EXTRA{$arg} .= " " . shift;
|
||||
}
|
||||
return @args;
|
||||
return @result;
|
||||
}
|
||||
|
||||
|
||||
|
|
@ -261,9 +112,9 @@ sub copy_pemfile
|
|||
# Wrapper around system; useful for debugging. Returns just the exit status
|
||||
sub run
|
||||
{
|
||||
my ($cmd, @args) = @_;
|
||||
print "====\n$cmd @args\n" if $verbose;
|
||||
my $status = system {$cmd} $cmd, @args;
|
||||
my $cmd = shift;
|
||||
print "====\n$cmd\n" if $verbose;
|
||||
my $status = system($cmd);
|
||||
print "==> $status\n====\n" if $verbose;
|
||||
return $status >> 8;
|
||||
}
|
||||
|
|
@ -282,15 +133,17 @@ EOF
|
|||
|
||||
if ($WHAT eq '-newcert' ) {
|
||||
# create a certificate
|
||||
$RET = run(@REQ, qw(-new -x509 -keyout), $NEWKEY, "-out", $NEWCERT, @DAYS, @{$EXTRA{req}});
|
||||
$RET = run("$REQ -new -x509 -keyout $NEWKEY -out $NEWCERT $DAYS"
|
||||
. " $EXTRA{req}");
|
||||
print "Cert is in $NEWCERT, private key is in $NEWKEY\n" if $RET == 0;
|
||||
} elsif ($WHAT eq '-precert' ) {
|
||||
# create a pre-certificate
|
||||
$RET = run(@REQ, qw(-x509 -precert -keyout), $NEWKEY, "-out", $NEWCERT, @DAYS, @{$EXTRA{req}});
|
||||
$RET = run("$REQ -x509 -precert -keyout $NEWKEY -out $NEWCERT $DAYS"
|
||||
. " $EXTRA{req}");
|
||||
print "Pre-cert is in $NEWCERT, private key is in $NEWKEY\n" if $RET == 0;
|
||||
} elsif ($WHAT =~ /^\-newreq(\-nodes)?$/ ) {
|
||||
# create a certificate request
|
||||
$RET = run(@REQ, "-new", (defined $1 ? ($1,) : ()), "-keyout", $NEWKEY, "-out", $NEWREQ, @{$EXTRA{req}});
|
||||
$RET = run("$REQ -new" . (defined $1 ? " $1" : "") . " -keyout $NEWKEY -out $NEWREQ $EXTRA{req}");
|
||||
print "Request is in $NEWREQ, private key is in $NEWKEY\n" if $RET == 0;
|
||||
} elsif ($WHAT eq '-newca' ) {
|
||||
# create the directory hierarchy
|
||||
|
|
@ -323,45 +176,48 @@ if ($WHAT eq '-newcert' ) {
|
|||
copy_pemfile($FILE,"${CATOP}/$CACERT", "CERTIFICATE");
|
||||
} else {
|
||||
print "Making CA certificate ...\n";
|
||||
$RET = run(@REQ, qw(-new -keyout), "${CATOP}/private/$CAKEY",
|
||||
"-out", "${CATOP}/$CAREQ", @{$EXTRA{req}});
|
||||
$RET = run(@CA, qw(-create_serial -out), "${CATOP}/$CACERT", @CADAYS,
|
||||
qw(-batch -keyfile), "${CATOP}/private/$CAKEY", "-selfsign",
|
||||
@EXTENSIONS, "-infiles", "${CATOP}/$CAREQ", @{$EXTRA{ca}})
|
||||
if $RET == 0;
|
||||
$RET = run("$REQ -new -keyout ${CATOP}/private/$CAKEY"
|
||||
. " -out ${CATOP}/$CAREQ $EXTRA{req}");
|
||||
$RET = run("$CA -create_serial"
|
||||
. " -out ${CATOP}/$CACERT $CADAYS -batch"
|
||||
. " -keyfile ${CATOP}/private/$CAKEY -selfsign"
|
||||
. " $EXTENSIONS"
|
||||
. " -infiles ${CATOP}/$CAREQ $EXTRA{ca}") if $RET == 0;
|
||||
print "CA certificate is in ${CATOP}/$CACERT\n" if $RET == 0;
|
||||
}
|
||||
} elsif ($WHAT eq '-pkcs12' ) {
|
||||
my $cname = $ARGV[0];
|
||||
$cname = "My Certificate" unless defined $cname;
|
||||
$RET = run(@PKCS12, "-in", $NEWCERT, "-inkey", $NEWKEY,
|
||||
"-certfile", "${CATOP}/$CACERT", "-out", $NEWP12,
|
||||
qw(-export -name), $cname, @{$EXTRA{pkcs12}});
|
||||
print "PKCS#12 file is in $NEWP12\n" if $RET == 0;
|
||||
$RET = run("$PKCS12 -in $NEWCERT -inkey $NEWKEY"
|
||||
. " -certfile ${CATOP}/$CACERT -out $NEWP12"
|
||||
. " -export -name \"$cname\" $EXTRA{pkcs12}");
|
||||
print "PKCS #12 file is in $NEWP12\n" if $RET == 0;
|
||||
} elsif ($WHAT eq '-xsign' ) {
|
||||
$RET = run(@CA, @POLICY, "-infiles", $NEWREQ, @{$EXTRA{ca}});
|
||||
$RET = run("$CA $POLICY -infiles $NEWREQ $EXTRA{ca}");
|
||||
} elsif ($WHAT eq '-sign' ) {
|
||||
$RET = run(@CA, @POLICY, "-out", $NEWCERT,
|
||||
"-infiles", $NEWREQ, @{$EXTRA{ca}});
|
||||
$RET = run("$CA $POLICY -out $NEWCERT"
|
||||
. " -infiles $NEWREQ $EXTRA{ca}");
|
||||
print "Signed certificate is in $NEWCERT\n" if $RET == 0;
|
||||
} elsif ($WHAT eq '-signCA' ) {
|
||||
$RET = run(@CA, @POLICY, "-out", $NEWCERT, @EXTENSIONS,
|
||||
"-infiles", $NEWREQ, @{$EXTRA{ca}});
|
||||
$RET = run("$CA $POLICY -out $NEWCERT"
|
||||
. " $EXTENSIONS -infiles $NEWREQ $EXTRA{ca}");
|
||||
print "Signed CA certificate is in $NEWCERT\n" if $RET == 0;
|
||||
} elsif ($WHAT eq '-signcert' ) {
|
||||
$RET = run(@X509, qw(-x509toreq -in), $NEWREQ, "-signkey", $NEWREQ,
|
||||
qw(-out tmp.pem), @{$EXTRA{x509}});
|
||||
$RET = run(@CA, @POLICY, "-out", $NEWCERT,
|
||||
qw(-infiles tmp.pem), @{$EXTRA{ca}}) if $RET == 0;
|
||||
$RET = run("$X509 -x509toreq -in $NEWREQ -signkey $NEWREQ"
|
||||
. " -out tmp.pem $EXTRA{x509}");
|
||||
$RET = run("$CA $POLICY -out $NEWCERT"
|
||||
. "-infiles tmp.pem $EXTRA{ca}") if $RET == 0;
|
||||
print "Signed certificate is in $NEWCERT\n" if $RET == 0;
|
||||
} elsif ($WHAT eq '-verify' ) {
|
||||
my @files = @ARGV ? @ARGV : ( $NEWCERT );
|
||||
foreach my $file (@files) {
|
||||
my $status = run(@VERIFY, "-CAfile", "${CATOP}/$CACERT", $file, @{$EXTRA{verify}});
|
||||
# -CAfile quoted for VMS, since the C RTL downcases all unquoted
|
||||
# arguments to C programs
|
||||
my $status = run("$VERIFY \"-CAfile\" ${CATOP}/$CACERT $file $EXTRA{verify}");
|
||||
$RET = $status if $status != 0;
|
||||
}
|
||||
} elsif ($WHAT eq '-crl' ) {
|
||||
$RET = run(@CA, qw(-gencrl -out), "${CATOP}/crl/$CACRL", @{$EXTRA{ca}});
|
||||
$RET = run("$CA -gencrl -out ${CATOP}/crl/$CACRL $EXTRA{ca}");
|
||||
print "Generated CRL is in ${CATOP}/crl/$CACRL\n" if $RET == 0;
|
||||
} elsif ($WHAT eq '-revoke' ) {
|
||||
my $cname = $ARGV[0];
|
||||
|
|
@ -369,10 +225,10 @@ if ($WHAT eq '-newcert' ) {
|
|||
print "Certificate filename is required; reason optional.\n";
|
||||
exit 1;
|
||||
}
|
||||
my @reason;
|
||||
@reason = ("-crl_reason", $ARGV[1])
|
||||
if defined $ARGV[1] && crl_reason_ok($ARGV[1]);
|
||||
$RET = run(@CA, "-revoke", $cname, @reason, @{$EXTRA{ca}});
|
||||
my $reason = $ARGV[1];
|
||||
$reason = " -crl_reason $reason"
|
||||
if defined $reason && crl_reason_ok($reason);
|
||||
$RET = run("$CA -revoke \"$cname\"" . $reason . $EXTRA{ca});
|
||||
} else {
|
||||
print STDERR "Unknown arg \"$WHAT\"\n";
|
||||
print STDERR "Use -help for help.\n";
|
||||
|
|
|
|||
107
apps/asn1parse.c
107
apps/asn1parse.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -20,51 +20,40 @@
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_INFORM,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_INDENT,
|
||||
OPT_NOOUT,
|
||||
OPT_OID,
|
||||
OPT_OFFSET,
|
||||
OPT_LENGTH,
|
||||
OPT_DUMP,
|
||||
OPT_DLIMIT,
|
||||
OPT_STRPARSE,
|
||||
OPT_GENSTR,
|
||||
OPT_GENCONF,
|
||||
OPT_STRICTPEM,
|
||||
OPT_INFORM, OPT_IN, OPT_OUT, OPT_INDENT, OPT_NOOUT,
|
||||
OPT_OID, OPT_OFFSET, OPT_LENGTH, OPT_DUMP, OPT_DLIMIT,
|
||||
OPT_STRPARSE, OPT_GENSTR, OPT_GENCONF, OPT_STRICTPEM,
|
||||
OPT_ITEM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS asn1parse_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "oid", OPT_OID, '<', "file of extra oid definitions" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"oid", OPT_OID, '<', "file of extra oid definitions"},
|
||||
|
||||
OPT_SECTION("I/O"),
|
||||
{ "inform", OPT_INFORM, 'A', "input format - one of DER PEM B64" },
|
||||
{ "in", OPT_IN, '<', "input file" },
|
||||
{ "out", OPT_OUT, '>', "output file (output format is always DER)" },
|
||||
{ "noout", OPT_NOOUT, 0, "do not produce any output" },
|
||||
{ "offset", OPT_OFFSET, 'p', "offset into file" },
|
||||
{ "length", OPT_LENGTH, 'p', "length of section in file" },
|
||||
{ "strparse", OPT_STRPARSE, 'p',
|
||||
"offset; a series of these can be used to 'dig'" },
|
||||
{ OPT_MORE_STR, 0, 0, "into multiple ASN1 blob wrappings" },
|
||||
{ "genstr", OPT_GENSTR, 's', "string to generate ASN1 structure from" },
|
||||
{ "genconf", OPT_GENCONF, 's', "file to generate ASN1 structure from" },
|
||||
{ "strictpem", OPT_STRICTPEM, 0,
|
||||
"equivalent to '-inform pem' (obsolete)" },
|
||||
{ "item", OPT_ITEM, 's', "item to parse and print" },
|
||||
{ OPT_MORE_STR, 0, 0, "(-inform will be ignored)" },
|
||||
{"inform", OPT_INFORM, 'A', "input format - one of DER PEM B64"},
|
||||
{"in", OPT_IN, '<', "input file"},
|
||||
{"out", OPT_OUT, '>', "output file (output format is always DER)"},
|
||||
{"noout", OPT_NOOUT, 0, "do not produce any output"},
|
||||
{"offset", OPT_OFFSET, 'p', "offset into file"},
|
||||
{"length", OPT_LENGTH, 'p', "length of section in file"},
|
||||
{"strparse", OPT_STRPARSE, 'p',
|
||||
"offset; a series of these can be used to 'dig'"},
|
||||
{"genstr", OPT_GENSTR, 's', "string to generate ASN1 structure from"},
|
||||
{OPT_MORE_STR, 0, 0, "into multiple ASN1 blob wrappings"},
|
||||
{"genconf", OPT_GENCONF, 's', "file to generate ASN1 structure from"},
|
||||
{"strictpem", OPT_STRICTPEM, 0,
|
||||
"equivalent to '-inform pem' (obsolete)"},
|
||||
{"item", OPT_ITEM, 's', "item to parse and print"},
|
||||
{OPT_MORE_STR, 0, 0, "(-inform will be ignored)"},
|
||||
|
||||
OPT_SECTION("Formatting"),
|
||||
{ "i", OPT_INDENT, 0, "indents the output" },
|
||||
{ "dump", OPT_DUMP, 0, "unknown data in hex form" },
|
||||
{ "dlimit", OPT_DLIMIT, 'p',
|
||||
"dump the first arg bytes of unknown data in hex form" },
|
||||
{ NULL }
|
||||
{"i", OPT_INDENT, 0, "indents the output"},
|
||||
{"dump", OPT_DUMP, 0, "unknown data in hex form"},
|
||||
{"dlimit", OPT_DLIMIT, 'p',
|
||||
"dump the first arg bytes of unknown data in hex form"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
static int do_generate(char *genstr, const char *genconf, BUF_MEM *buf);
|
||||
|
|
@ -82,9 +71,8 @@ int asn1parse_main(int argc, char **argv)
|
|||
const unsigned char *ctmpbuf;
|
||||
int indent = 0, noout = 0, dump = 0, informat = FORMAT_PEM;
|
||||
int offset = 0, ret = 1, i, j;
|
||||
long num;
|
||||
size_t tmplen;
|
||||
const unsigned char *tmpbuf;
|
||||
long num, tmplen;
|
||||
unsigned char *tmpbuf;
|
||||
unsigned int length = 0;
|
||||
OPTION_CHOICE o;
|
||||
const ASN1_ITEM *it = NULL;
|
||||
|
|
@ -100,7 +88,7 @@ int asn1parse_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -193,7 +181,7 @@ int asn1parse_main(int argc, char **argv)
|
|||
goto end;
|
||||
if (genconf == NULL && genstr == NULL && informat == FORMAT_PEM) {
|
||||
if (PEM_read_bio(in, &name, &header, &str, &num) != 1) {
|
||||
BIO_puts(bio_err, "Error reading PEM file\n");
|
||||
BIO_printf(bio_err, "Error reading PEM file\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -201,7 +189,7 @@ int asn1parse_main(int argc, char **argv)
|
|||
buf->length = buf->max = num;
|
||||
} else {
|
||||
if (!BUF_MEM_grow(buf, BUFSIZ * 8))
|
||||
goto end; /* Pre-allocate :-) */
|
||||
goto end; /* Pre-allocate :-) */
|
||||
|
||||
if (genstr || genconf) {
|
||||
num = do_generate(genstr, genconf, buf);
|
||||
|
|
@ -236,30 +224,31 @@ int asn1parse_main(int argc, char **argv)
|
|||
}
|
||||
}
|
||||
str = (unsigned char *)buf->data;
|
||||
|
||||
}
|
||||
|
||||
/* If any structs to parse go through in sequence */
|
||||
|
||||
if (sk_OPENSSL_STRING_num(osk)) {
|
||||
tmpbuf = str;
|
||||
tmplen = (size_t)num;
|
||||
tmplen = num;
|
||||
for (i = 0; i < sk_OPENSSL_STRING_num(osk); i++) {
|
||||
ASN1_TYPE *atmp;
|
||||
int typ;
|
||||
j = strtol(sk_OPENSSL_STRING_value(osk, i), NULL, 0);
|
||||
if (j <= 0 || (size_t)j >= tmplen) {
|
||||
if (j <= 0 || j >= tmplen) {
|
||||
BIO_printf(bio_err, "'%s' is out of range\n",
|
||||
sk_OPENSSL_STRING_value(osk, i));
|
||||
sk_OPENSSL_STRING_value(osk, i));
|
||||
continue;
|
||||
}
|
||||
tmpbuf += j;
|
||||
tmplen -= j;
|
||||
atmp = at;
|
||||
ctmpbuf = tmpbuf;
|
||||
at = d2i_ASN1_TYPE(NULL, &ctmpbuf, (long)tmplen);
|
||||
at = d2i_ASN1_TYPE(NULL, &ctmpbuf, tmplen);
|
||||
ASN1_TYPE_free(atmp);
|
||||
if (!at) {
|
||||
BIO_puts(bio_err, "Error parsing structure\n");
|
||||
BIO_printf(bio_err, "Error parsing structure\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -272,21 +261,15 @@ int asn1parse_main(int argc, char **argv)
|
|||
goto end;
|
||||
}
|
||||
/* hmm... this is a little evil but it works */
|
||||
tmpbuf = ASN1_STRING_get0_data(at->value.asn1_string);
|
||||
tmplen = ASN1_STRING_length_ex(at->value.asn1_string);
|
||||
if (tmplen > INT_MAX) {
|
||||
BIO_puts(bio_err, "ASN.1 string length exceeds INT_MAX\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
tmpbuf = at->value.asn1_string->data;
|
||||
tmplen = at->value.asn1_string->length;
|
||||
}
|
||||
/* XXX casts away const */
|
||||
str = (unsigned char *)tmpbuf;
|
||||
num = (int)tmplen;
|
||||
str = tmpbuf;
|
||||
num = tmplen;
|
||||
}
|
||||
|
||||
if (offset < 0 || offset >= num) {
|
||||
BIO_puts(bio_err, "Error: offset out of range\n");
|
||||
BIO_printf(bio_err, "Error: offset out of range\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -296,7 +279,7 @@ int asn1parse_main(int argc, char **argv)
|
|||
length = (unsigned int)num;
|
||||
if (derout != NULL) {
|
||||
if (BIO_write(derout, str + offset, length) != (int)length) {
|
||||
BIO_puts(bio_err, "Error writing output\n");
|
||||
BIO_printf(bio_err, "Error writing output\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -321,7 +304,7 @@ int asn1parse_main(int argc, char **argv)
|
|||
}
|
||||
}
|
||||
ret = 0;
|
||||
end:
|
||||
end:
|
||||
BIO_free(derout);
|
||||
BIO_free(in);
|
||||
BIO_free(b64);
|
||||
|
|
@ -375,7 +358,7 @@ static int do_generate(char *genstr, const char *genconf, BUF_MEM *buf)
|
|||
ASN1_TYPE_free(atyp);
|
||||
return len;
|
||||
|
||||
err:
|
||||
err:
|
||||
NCONF_free(cnf);
|
||||
ASN1_TYPE_free(atyp);
|
||||
return -1;
|
||||
|
|
|
|||
|
|
@ -12,13 +12,12 @@ ENDIF
|
|||
# Source for the 'openssl' program
|
||||
$OPENSSLSRC=\
|
||||
openssl.c \
|
||||
asn1parse.c ca.c ciphers.c configutl.c crl.c crl2pkcs7.c dgst.c \
|
||||
asn1parse.c ca.c ciphers.c crl.c crl2pkcs7.c dgst.c \
|
||||
enc.c errstr.c \
|
||||
genpkey.c kdf.c mac.c nseq.c passwd.c pkcs7.c \
|
||||
pkcs8.c pkey.c pkeyparam.c pkeyutl.c prime.c rand.c req.c \
|
||||
s_client.c s_server.c s_time.c sess_id.c skeyutl.c smime.c speed.c \
|
||||
spkac.c verify.c version.c x509.c rehash.c storeutl.c \
|
||||
ech.c \
|
||||
list.c info.c fipsinstall.c pkcs12.c
|
||||
IF[{- !$disabled{'ec'} -}]
|
||||
$OPENSSLSRC=$OPENSSLSRC ec.c ecparam.c
|
||||
|
|
@ -38,6 +37,9 @@ ENDIF
|
|||
IF[{- !$disabled{'dsa'} -}]
|
||||
$OPENSSLSRC=$OPENSSLSRC dsa.c dsaparam.c gendsa.c
|
||||
ENDIF
|
||||
IF[{- !$disabled{'engine'} -}]
|
||||
$OPENSSLSRC=$OPENSSLSRC engine.c
|
||||
ENDIF
|
||||
IF[{- !$disabled{'rsa'} -}]
|
||||
$OPENSSLSRC=$OPENSSLSRC rsa.c genrsa.c
|
||||
ENDIF
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2022 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -20,6 +20,7 @@ typedef enum OPTION_choice {
|
|||
OPT_COMMON,
|
||||
OPT_STDNAME,
|
||||
OPT_CONVERT,
|
||||
OPT_SSL3,
|
||||
OPT_TLS1,
|
||||
OPT_TLS1_1,
|
||||
OPT_TLS1_2,
|
||||
|
|
@ -27,58 +28,58 @@ typedef enum OPTION_choice {
|
|||
OPT_PSK,
|
||||
OPT_SRP,
|
||||
OPT_CIPHERSUITES,
|
||||
OPT_V,
|
||||
OPT_UPPER_V,
|
||||
OPT_S,
|
||||
OPT_PROV_ENUM
|
||||
OPT_V, OPT_UPPER_V, OPT_S, OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS ciphers_options[] = {
|
||||
{ OPT_HELP_STR, 1, '-', "Usage: %s [options] [cipher]\n" },
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] [cipher]\n"},
|
||||
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "v", OPT_V, '-', "Verbose listing of the SSL/TLS ciphers" },
|
||||
{ "V", OPT_UPPER_V, '-', "Even more verbose" },
|
||||
{ "stdname", OPT_STDNAME, '-', "Show standard cipher names" },
|
||||
{ "convert", OPT_CONVERT, 's', "Convert standard name into OpenSSL name" },
|
||||
{"v", OPT_V, '-', "Verbose listing of the SSL/TLS ciphers"},
|
||||
{"V", OPT_UPPER_V, '-', "Even more verbose"},
|
||||
{"stdname", OPT_STDNAME, '-', "Show standard cipher names"},
|
||||
{"convert", OPT_CONVERT, 's', "Convert standard name into OpenSSL name"},
|
||||
|
||||
OPT_SECTION("Cipher specification"),
|
||||
{ "s", OPT_S, '-', "Only supported ciphers" },
|
||||
{"s", OPT_S, '-', "Only supported ciphers"},
|
||||
#ifndef OPENSSL_NO_SSL3
|
||||
{"ssl3", OPT_SSL3, '-', "Ciphers compatible with SSL3"},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1
|
||||
{ "tls1", OPT_TLS1, '-', "Ciphers compatible with TLS1" },
|
||||
{"tls1", OPT_TLS1, '-', "Ciphers compatible with TLS1"},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1_1
|
||||
{ "tls1_1", OPT_TLS1_1, '-', "Ciphers compatible with TLS1.1" },
|
||||
{"tls1_1", OPT_TLS1_1, '-', "Ciphers compatible with TLS1.1"},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1_2
|
||||
{ "tls1_2", OPT_TLS1_2, '-', "Ciphers compatible with TLS1.2" },
|
||||
{"tls1_2", OPT_TLS1_2, '-', "Ciphers compatible with TLS1.2"},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_TLS1_3
|
||||
{ "tls1_3", OPT_TLS1_3, '-', "Ciphers compatible with TLS1.3" },
|
||||
{"tls1_3", OPT_TLS1_3, '-', "Ciphers compatible with TLS1.3"},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
{ "psk", OPT_PSK, '-', "Include ciphersuites requiring PSK" },
|
||||
{"psk", OPT_PSK, '-', "Include ciphersuites requiring PSK"},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_SRP
|
||||
{ "srp", OPT_SRP, '-', "(deprecated) Include ciphersuites requiring SRP" },
|
||||
{"srp", OPT_SRP, '-', "(deprecated) Include ciphersuites requiring SRP"},
|
||||
#endif
|
||||
{ "ciphersuites", OPT_CIPHERSUITES, 's',
|
||||
"Configure the TLSv1.3 ciphersuites to use" },
|
||||
{"ciphersuites", OPT_CIPHERSUITES, 's',
|
||||
"Configure the TLSv1.3 ciphersuites to use"},
|
||||
OPT_PROV_OPTIONS,
|
||||
|
||||
OPT_PARAMETERS(),
|
||||
{ "cipher", 0, 0, "Cipher string to decode (optional)" },
|
||||
{ NULL }
|
||||
{"cipher", 0, 0, "Cipher string to decode (optional)"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
#ifndef OPENSSL_NO_PSK
|
||||
static unsigned int dummy_psk(SSL *ssl, const char *hint, char *identity,
|
||||
unsigned int max_identity_len,
|
||||
unsigned char *psk,
|
||||
unsigned int max_psk_len)
|
||||
unsigned int max_identity_len,
|
||||
unsigned char *psk,
|
||||
unsigned int max_psk_len)
|
||||
{
|
||||
return 0;
|
||||
}
|
||||
|
|
@ -109,7 +110,7 @@ int ciphers_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -131,6 +132,10 @@ int ciphers_main(int argc, char **argv)
|
|||
case OPT_CONVERT:
|
||||
convert = opt_arg();
|
||||
break;
|
||||
case OPT_SSL3:
|
||||
min_version = SSL3_VERSION;
|
||||
max_version = SSL3_VERSION;
|
||||
break;
|
||||
case OPT_TLS1:
|
||||
min_version = TLS1_VERSION;
|
||||
max_version = TLS1_VERSION;
|
||||
|
|
@ -176,7 +181,7 @@ int ciphers_main(int argc, char **argv)
|
|||
|
||||
if (convert != NULL) {
|
||||
BIO_printf(bio_out, "OpenSSL cipher name: %s\n",
|
||||
OPENSSL_cipher_name(convert));
|
||||
OPENSSL_cipher_name(convert));
|
||||
ret = 0;
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -199,13 +204,13 @@ int ciphers_main(int argc, char **argv)
|
|||
#endif
|
||||
|
||||
if (ciphersuites != NULL && !SSL_CTX_set_ciphersuites(ctx, ciphersuites)) {
|
||||
BIO_puts(bio_err, "Error setting TLSv1.3 ciphersuites\n");
|
||||
BIO_printf(bio_err, "Error setting TLSv1.3 ciphersuites\n");
|
||||
goto err;
|
||||
}
|
||||
|
||||
if (ciphers != NULL) {
|
||||
if (!SSL_CTX_set_cipher_list(ctx, ciphers)) {
|
||||
BIO_puts(bio_err, "Error in cipher list\n");
|
||||
BIO_printf(bio_err, "Error in cipher list\n");
|
||||
goto err;
|
||||
}
|
||||
}
|
||||
|
|
@ -229,10 +234,10 @@ int ciphers_main(int argc, char **argv)
|
|||
if (p == NULL)
|
||||
break;
|
||||
if (i != 0)
|
||||
BIO_puts(bio_out, ":");
|
||||
BIO_puts(bio_out, p);
|
||||
BIO_printf(bio_out, ":");
|
||||
BIO_printf(bio_out, "%s", p);
|
||||
}
|
||||
BIO_puts(bio_out, "\n");
|
||||
BIO_printf(bio_out, "\n");
|
||||
} else {
|
||||
|
||||
for (i = 0; i < sk_SSL_CIPHER_num(sk); i++) {
|
||||
|
|
@ -268,9 +273,9 @@ int ciphers_main(int argc, char **argv)
|
|||
|
||||
ret = 0;
|
||||
goto end;
|
||||
err:
|
||||
err:
|
||||
ERR_print_errors(bio_err);
|
||||
end:
|
||||
end:
|
||||
if (use_supported)
|
||||
sk_SSL_CIPHER_free(sk);
|
||||
SSL_CTX_free(ctx);
|
||||
|
|
|
|||
1834
apps/cmp.c
1834
apps/cmp.c
File diff suppressed because it is too large
Load diff
803
apps/cms.c
803
apps/cms.c
File diff suppressed because it is too large
Load diff
202
apps/configutl.c
202
apps/configutl.c
|
|
@ -1,202 +0,0 @@
|
|||
/*
|
||||
* Copyright 2025-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <openssl/conf.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/safestack.h>
|
||||
|
||||
#include "apps.h"
|
||||
#include "progs.h"
|
||||
|
||||
/**
|
||||
* Print the given value escaped for the OpenSSL configuration file format.
|
||||
*/
|
||||
static void print_escaped_value(BIO *out, const char *value)
|
||||
{
|
||||
const char *p;
|
||||
|
||||
for (p = value; *p != '\0'; p++) {
|
||||
switch (*p) {
|
||||
case '"':
|
||||
case '\'':
|
||||
case '#':
|
||||
case '\\':
|
||||
case '$':
|
||||
BIO_puts(out, "\\");
|
||||
BIO_write(out, p, 1);
|
||||
break;
|
||||
case '\n':
|
||||
BIO_puts(out, "\\n");
|
||||
break;
|
||||
case '\r':
|
||||
BIO_puts(out, "\\r");
|
||||
break;
|
||||
case '\b':
|
||||
BIO_puts(out, "\\b");
|
||||
break;
|
||||
case '\t':
|
||||
BIO_puts(out, "\\t");
|
||||
break;
|
||||
case ' ':
|
||||
if (p == value || p[1] == '\0') {
|
||||
/*
|
||||
* Quote spaces if they are the first or last char of the
|
||||
* value. We could quote the entire string (and it would
|
||||
* certainly produce nicer output), but in quoted strings
|
||||
* the escape sequences for \n, \r, \t, and \b do not work.
|
||||
* To make sure we're producing correct results we'd thus
|
||||
* have to selectively not use those in quoted strings and
|
||||
* close and re-open the quotes if they appear, which is
|
||||
* more trouble than adding the quotes just around the
|
||||
* first and last leading and trailing space.
|
||||
*/
|
||||
BIO_puts(out, "\" \"");
|
||||
break;
|
||||
}
|
||||
/* FALLTHROUGH */
|
||||
default:
|
||||
BIO_write(out, p, 1);
|
||||
break;
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
/**
|
||||
* Print all values in the configuration section identified by section_name
|
||||
*/
|
||||
static void print_section(BIO *out, const CONF *cnf, OPENSSL_CSTRING section_name)
|
||||
{
|
||||
STACK_OF(CONF_VALUE) *values = NCONF_get_section(cnf, section_name);
|
||||
int idx;
|
||||
|
||||
for (idx = 0; idx < sk_CONF_VALUE_num(values); idx++) {
|
||||
CONF_VALUE *value = sk_CONF_VALUE_value(values, idx);
|
||||
|
||||
BIO_printf(out, "%s = ", value->name);
|
||||
print_escaped_value(out, value->value);
|
||||
BIO_puts(out, "\n");
|
||||
}
|
||||
}
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_OUT,
|
||||
OPT_NOHEADER,
|
||||
OPT_CONFIG
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS configutl_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "config", OPT_CONFIG, 's', "Config file to deal with (the default one if omitted)" },
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output to filename rather than stdout" },
|
||||
{ "noheader", OPT_NOHEADER, '-', "Don't print the information about original config" },
|
||||
{ NULL }
|
||||
};
|
||||
|
||||
/**
|
||||
* Parse the passed OpenSSL configuration file (or the default one/specified in the
|
||||
* OPENSSL_CONF environment variable) and write it back in
|
||||
* a canonical format with all includes and variables expanded.
|
||||
*/
|
||||
int configutl_main(int argc, char *argv[])
|
||||
{
|
||||
int ret = 1;
|
||||
char *prog, *configfile = NULL;
|
||||
OPTION_CHOICE o;
|
||||
CONF *cnf = NULL;
|
||||
long eline = 0;
|
||||
int default_section_idx, idx;
|
||||
int no_header = 0;
|
||||
STACK_OF(OPENSSL_CSTRING) *sections = NULL;
|
||||
BIO *out = NULL;
|
||||
const char *outfile = NULL;
|
||||
|
||||
prog = opt_init(argc, argv, configutl_options);
|
||||
while ((o = opt_next()) != OPT_EOF) {
|
||||
switch (o) {
|
||||
case OPT_HELP:
|
||||
opt_help(configutl_options);
|
||||
ret = 0;
|
||||
goto end;
|
||||
break;
|
||||
case OPT_NOHEADER:
|
||||
no_header = 1;
|
||||
break;
|
||||
case OPT_CONFIG:
|
||||
/*
|
||||
* In case multiple OPT_CONFIG options are passed, we need to free
|
||||
* the previous one before assigning the new one.
|
||||
*/
|
||||
OPENSSL_free(configfile);
|
||||
configfile = OPENSSL_strdup(opt_arg());
|
||||
break;
|
||||
case OPT_OUT:
|
||||
outfile = opt_arg();
|
||||
break;
|
||||
case OPT_ERR:
|
||||
/*
|
||||
* default needed for OPT_EOF which might never happen.
|
||||
*/
|
||||
default:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
||||
out = bio_open_default(outfile, 'w', FORMAT_TEXT);
|
||||
if (out == NULL)
|
||||
goto end;
|
||||
|
||||
if (configfile == NULL)
|
||||
configfile = CONF_get1_default_config_file();
|
||||
|
||||
if (configfile == NULL)
|
||||
goto end;
|
||||
|
||||
if ((cnf = NCONF_new(NULL)) == NULL)
|
||||
goto end;
|
||||
|
||||
if (NCONF_load(cnf, configfile, &eline) == 0) {
|
||||
BIO_printf(bio_err, "Error on line %ld of configuration file\n", eline + 1);
|
||||
goto end;
|
||||
}
|
||||
|
||||
if ((sections = NCONF_get_section_names(cnf)) == NULL)
|
||||
goto end;
|
||||
|
||||
if (no_header == 0)
|
||||
BIO_printf(out, "# This configuration file was linearized and expanded from %s\n",
|
||||
configfile);
|
||||
|
||||
default_section_idx = sk_OPENSSL_CSTRING_find(sections, "default");
|
||||
if (default_section_idx != -1)
|
||||
print_section(out, cnf, "default");
|
||||
|
||||
for (idx = 0; idx < sk_OPENSSL_CSTRING_num(sections); idx++) {
|
||||
OPENSSL_CSTRING section_name = sk_OPENSSL_CSTRING_value(sections, idx);
|
||||
|
||||
if (idx == default_section_idx)
|
||||
continue;
|
||||
|
||||
BIO_printf(out, "\n[%s]\n", section_name);
|
||||
print_section(out, cnf, section_name);
|
||||
}
|
||||
|
||||
ret = 0;
|
||||
|
||||
end:
|
||||
ERR_print_errors(bio_err);
|
||||
BIO_free(out);
|
||||
OPENSSL_free(configfile);
|
||||
NCONF_free(cnf);
|
||||
sk_OPENSSL_CSTRING_free(sections);
|
||||
return ret;
|
||||
}
|
||||
168
apps/crl.c
168
apps/crl.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -20,81 +20,58 @@
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_INFORM,
|
||||
OPT_IN,
|
||||
OPT_OUTFORM,
|
||||
OPT_OUT,
|
||||
OPT_KEYFORM,
|
||||
OPT_KEY,
|
||||
OPT_ISSUER,
|
||||
OPT_LASTUPDATE,
|
||||
OPT_NEXTUPDATE,
|
||||
OPT_FINGERPRINT,
|
||||
OPT_CRLNUMBER,
|
||||
OPT_BADSIG,
|
||||
OPT_GENDELTA,
|
||||
OPT_CAPATH,
|
||||
OPT_CAFILE,
|
||||
OPT_CASTORE,
|
||||
OPT_NOCAPATH,
|
||||
OPT_NOCAFILE,
|
||||
OPT_NOCASTORE,
|
||||
OPT_VERIFY,
|
||||
OPT_DATEOPT,
|
||||
OPT_TEXT,
|
||||
OPT_HASH,
|
||||
OPT_HASH_OLD,
|
||||
OPT_NOOUT,
|
||||
OPT_NAMEOPT,
|
||||
OPT_MD,
|
||||
OPT_PROV_ENUM
|
||||
OPT_INFORM, OPT_IN, OPT_OUTFORM, OPT_OUT, OPT_KEYFORM, OPT_KEY,
|
||||
OPT_ISSUER, OPT_LASTUPDATE, OPT_NEXTUPDATE, OPT_FINGERPRINT,
|
||||
OPT_CRLNUMBER, OPT_BADSIG, OPT_GENDELTA, OPT_CAPATH, OPT_CAFILE, OPT_CASTORE,
|
||||
OPT_NOCAPATH, OPT_NOCAFILE, OPT_NOCASTORE, OPT_VERIFY, OPT_DATEOPT, OPT_TEXT, OPT_HASH,
|
||||
OPT_HASH_OLD, OPT_NOOUT, OPT_NAMEOPT, OPT_MD, OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS crl_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "verify", OPT_VERIFY, '-', "Verify CRL signature" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"verify", OPT_VERIFY, '-', "Verify CRL signature"},
|
||||
|
||||
OPT_SECTION("Input"),
|
||||
{ "in", OPT_IN, '<', "Input file - default stdin" },
|
||||
{ "inform", OPT_INFORM, 'F', "CRL input format (DER or PEM); has no effect" },
|
||||
{ "key", OPT_KEY, '<', "CRL signing Private key to use" },
|
||||
{ "keyform", OPT_KEYFORM, 'F', "Private key file format (DER/PEM/P12); has no effect" },
|
||||
{"in", OPT_IN, '<', "Input file - default stdin"},
|
||||
{"inform", OPT_INFORM, 'F', "CRL input format (DER or PEM); has no effect"},
|
||||
{"key", OPT_KEY, '<', "CRL signing Private key to use"},
|
||||
{"keyform", OPT_KEYFORM, 'F', "Private key file format (DER/PEM/P12); has no effect"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "output file - default stdout" },
|
||||
{ "outform", OPT_OUTFORM, 'F', "Output format - default PEM" },
|
||||
{ "dateopt", OPT_DATEOPT, 's', "Datetime format used for printing. (rfc_822/iso_8601). Default is rfc_822." },
|
||||
{ "text", OPT_TEXT, '-', "Print out a text format version" },
|
||||
{ "hash", OPT_HASH, '-', "Print hash value" },
|
||||
{"out", OPT_OUT, '>', "output file - default stdout"},
|
||||
{"outform", OPT_OUTFORM, 'F', "Output format - default PEM"},
|
||||
{"dateopt", OPT_DATEOPT, 's', "Datetime format used for printing. (rfc_822/iso_8601). Default is rfc_822."},
|
||||
{"text", OPT_TEXT, '-', "Print out a text format version"},
|
||||
{"hash", OPT_HASH, '-', "Print hash value"},
|
||||
#ifndef OPENSSL_NO_MD5
|
||||
{ "hash_old", OPT_HASH_OLD, '-', "Print old-style (MD5) hash value" },
|
||||
{"hash_old", OPT_HASH_OLD, '-', "Print old-style (MD5) hash value"},
|
||||
#endif
|
||||
{ "nameopt", OPT_NAMEOPT, 's', "Certificate subject/issuer name printing options" },
|
||||
{ "", OPT_MD, '-', "Any supported digest" },
|
||||
{"nameopt", OPT_NAMEOPT, 's', "Certificate subject/issuer name printing options"},
|
||||
{"", OPT_MD, '-', "Any supported digest"},
|
||||
|
||||
OPT_SECTION("CRL"),
|
||||
{ "issuer", OPT_ISSUER, '-', "Print issuer DN" },
|
||||
{ "lastupdate", OPT_LASTUPDATE, '-', "Set lastUpdate field" },
|
||||
{ "nextupdate", OPT_NEXTUPDATE, '-', "Set nextUpdate field" },
|
||||
{ "noout", OPT_NOOUT, '-', "No CRL output" },
|
||||
{ "fingerprint", OPT_FINGERPRINT, '-', "Print the crl fingerprint" },
|
||||
{ "crlnumber", OPT_CRLNUMBER, '-', "Print CRL number" },
|
||||
{ "badsig", OPT_BADSIG, '-', "Corrupt last byte of loaded CRL signature (for test)" },
|
||||
{ "gendelta", OPT_GENDELTA, '<', "Other CRL to compare/diff to the Input one" },
|
||||
{"issuer", OPT_ISSUER, '-', "Print issuer DN"},
|
||||
{"lastupdate", OPT_LASTUPDATE, '-', "Set lastUpdate field"},
|
||||
{"nextupdate", OPT_NEXTUPDATE, '-', "Set nextUpdate field"},
|
||||
{"noout", OPT_NOOUT, '-', "No CRL output"},
|
||||
{"fingerprint", OPT_FINGERPRINT, '-', "Print the crl fingerprint"},
|
||||
{"crlnumber", OPT_CRLNUMBER, '-', "Print CRL number"},
|
||||
{"badsig", OPT_BADSIG, '-', "Corrupt last byte of loaded CRL signature (for test)" },
|
||||
{"gendelta", OPT_GENDELTA, '<', "Other CRL to compare/diff to the Input one"},
|
||||
|
||||
OPT_SECTION("Certificate"),
|
||||
{ "CAfile", OPT_CAFILE, '<', "File in PEM format with trusted CA certs" },
|
||||
{ "CApath", OPT_CAPATH, '/', "Dir with trusted CA cert files in PEM format" },
|
||||
{ "CAstore", OPT_CASTORE, ':', "URI of store with trusted CA certs" },
|
||||
{ "no-CAfile", OPT_NOCAFILE, '-',
|
||||
"Do not load the default certificates file" },
|
||||
{ "no-CApath", OPT_NOCAPATH, '-',
|
||||
"Do not load certificates from the default certificates directory" },
|
||||
{ "no-CAstore", OPT_NOCASTORE, '-',
|
||||
"Do not load certificates from the default certificates store" },
|
||||
{"CApath", OPT_CAPATH, '/', "Verify CRL using certificates in dir"},
|
||||
{"CAfile", OPT_CAFILE, '<', "Verify CRL using certificates in file name"},
|
||||
{"CAstore", OPT_CASTORE, ':', "Verify CRL using certificates in store URI"},
|
||||
{"no-CAfile", OPT_NOCAFILE, '-',
|
||||
"Do not load the default certificates file"},
|
||||
{"no-CApath", OPT_NOCAPATH, '-',
|
||||
"Do not load certificates from the default certificates directory"},
|
||||
{"no-CAstore", OPT_NOCASTORE, '-',
|
||||
"Do not load certificates from the default certificates store"},
|
||||
OPT_PROV_OPTIONS,
|
||||
{ NULL }
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int crl_main(int argc, char **argv)
|
||||
|
|
@ -127,7 +104,7 @@ int crl_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -171,13 +148,13 @@ int crl_main(int argc, char **argv)
|
|||
do_ver = 1;
|
||||
break;
|
||||
case OPT_NOCAPATH:
|
||||
noCApath = 1;
|
||||
noCApath = 1;
|
||||
break;
|
||||
case OPT_NOCAFILE:
|
||||
noCAfile = 1;
|
||||
noCAfile = 1;
|
||||
break;
|
||||
case OPT_NOCASTORE:
|
||||
noCAstore = 1;
|
||||
noCAstore = 1;
|
||||
break;
|
||||
case OPT_HASH_OLD:
|
||||
#ifndef OPENSSL_NO_MD5
|
||||
|
|
@ -244,28 +221,27 @@ int crl_main(int argc, char **argv)
|
|||
|
||||
if (do_ver) {
|
||||
if ((store = setup_verify(CAfile, noCAfile, CApath, noCApath,
|
||||
CAstore, noCAstore))
|
||||
== NULL)
|
||||
CAstore, noCAstore)) == NULL)
|
||||
goto end;
|
||||
lookup = X509_STORE_add_lookup(store, X509_LOOKUP_file());
|
||||
if (lookup == NULL)
|
||||
goto end;
|
||||
ctx = X509_STORE_CTX_new();
|
||||
if (ctx == NULL || !X509_STORE_CTX_init(ctx, store, NULL, NULL)) {
|
||||
BIO_puts(bio_err, "Error initialising X509 store\n");
|
||||
BIO_printf(bio_err, "Error initialising X509 store\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
xobj = X509_STORE_CTX_get_obj_by_subject(ctx, X509_LU_X509,
|
||||
X509_CRL_get_issuer(x));
|
||||
X509_CRL_get_issuer(x));
|
||||
if (xobj == NULL) {
|
||||
BIO_puts(bio_err, "Error getting CRL issuer certificate\n");
|
||||
BIO_printf(bio_err, "Error getting CRL issuer certificate\n");
|
||||
goto end;
|
||||
}
|
||||
pkey = X509_get_pubkey(X509_OBJECT_get0_X509(xobj));
|
||||
X509_OBJECT_free(xobj);
|
||||
if (pkey == NULL) {
|
||||
BIO_puts(bio_err, "Error getting CRL issuer public key\n");
|
||||
BIO_printf(bio_err, "Error getting CRL issuer public key\n");
|
||||
goto end;
|
||||
}
|
||||
i = X509_CRL_verify(x, pkey);
|
||||
|
|
@ -273,10 +249,10 @@ int crl_main(int argc, char **argv)
|
|||
if (i < 0)
|
||||
goto end;
|
||||
if (i == 0) {
|
||||
BIO_puts(bio_err, "verify failure\n");
|
||||
goto end;
|
||||
BIO_printf(bio_err, "verify failure\n");
|
||||
goto end;
|
||||
} else
|
||||
BIO_puts(bio_err, "verify OK\n");
|
||||
BIO_printf(bio_err, "verify OK\n");
|
||||
}
|
||||
|
||||
if (crldiff != NULL) {
|
||||
|
|
@ -288,7 +264,7 @@ int crl_main(int argc, char **argv)
|
|||
newcrl = load_crl(crldiff, informat, 0, "other CRL");
|
||||
if (!newcrl)
|
||||
goto end;
|
||||
pkey = load_key(keyfile, keyformat, 0, NULL, "CRL signing key");
|
||||
pkey = load_key(keyfile, keyformat, 0, NULL, NULL, "CRL signing key");
|
||||
if (pkey == NULL) {
|
||||
X509_CRL_free(newcrl);
|
||||
goto end;
|
||||
|
|
@ -309,11 +285,7 @@ int crl_main(int argc, char **argv)
|
|||
const ASN1_BIT_STRING *sig;
|
||||
|
||||
X509_CRL_get0_signature(x, &sig, NULL);
|
||||
/* XXX Casts away const, because it mutates the value! */
|
||||
if (!corrupt_signature((ASN1_BIT_STRING *)sig)) {
|
||||
BIO_puts(bio_err, "Error corrupting signature\n");
|
||||
goto end;
|
||||
}
|
||||
corrupt_signature(sig);
|
||||
}
|
||||
|
||||
if (num) {
|
||||
|
|
@ -325,7 +297,7 @@ int crl_main(int argc, char **argv)
|
|||
ASN1_INTEGER *crlnum;
|
||||
|
||||
crlnum = X509_CRL_get_ext_d2i(x, NID_crl_number, NULL, NULL);
|
||||
BIO_puts(bio_out, "crlNumber=");
|
||||
BIO_printf(bio_out, "crlNumber=");
|
||||
if (crlnum) {
|
||||
BIO_puts(bio_out, "0x");
|
||||
i2a_ASN1_INTEGER(bio_out, crlnum);
|
||||
|
|
@ -333,15 +305,16 @@ int crl_main(int argc, char **argv)
|
|||
} else {
|
||||
BIO_puts(bio_out, "<NONE>");
|
||||
}
|
||||
BIO_puts(bio_out, "\n");
|
||||
BIO_printf(bio_out, "\n");
|
||||
}
|
||||
if (hash == i) {
|
||||
int ok;
|
||||
unsigned long hash_value = X509_NAME_hash_ex(X509_CRL_get_issuer(x), app_get0_libctx(),
|
||||
app_get0_propq(), &ok);
|
||||
unsigned long hash_value =
|
||||
X509_NAME_hash_ex(X509_CRL_get_issuer(x), app_get0_libctx(),
|
||||
app_get0_propq(), &ok);
|
||||
|
||||
if (num > 1)
|
||||
BIO_puts(bio_out, "issuer name hash=");
|
||||
BIO_printf(bio_out, "issuer name hash=");
|
||||
if (ok) {
|
||||
BIO_printf(bio_out, "%08lx\n", hash_value);
|
||||
} else {
|
||||
|
|
@ -352,23 +325,23 @@ int crl_main(int argc, char **argv)
|
|||
#ifndef OPENSSL_NO_MD5
|
||||
if (hash_old == i) {
|
||||
if (num > 1)
|
||||
BIO_puts(bio_out, "issuer name old hash=");
|
||||
BIO_printf(bio_out, "issuer name old hash=");
|
||||
BIO_printf(bio_out, "%08lx\n",
|
||||
X509_NAME_hash_old(X509_CRL_get_issuer(x)));
|
||||
X509_NAME_hash_old(X509_CRL_get_issuer(x)));
|
||||
}
|
||||
#endif
|
||||
if (lastupdate == i) {
|
||||
BIO_puts(bio_out, "lastUpdate=");
|
||||
BIO_printf(bio_out, "lastUpdate=");
|
||||
ASN1_TIME_print_ex(bio_out, X509_CRL_get0_lastUpdate(x), dateopt);
|
||||
BIO_puts(bio_out, "\n");
|
||||
BIO_printf(bio_out, "\n");
|
||||
}
|
||||
if (nextupdate == i) {
|
||||
BIO_puts(bio_out, "nextUpdate=");
|
||||
BIO_printf(bio_out, "nextUpdate=");
|
||||
if (X509_CRL_get0_nextUpdate(x))
|
||||
ASN1_TIME_print_ex(bio_out, X509_CRL_get0_nextUpdate(x), dateopt);
|
||||
else
|
||||
BIO_puts(bio_out, "NONE");
|
||||
BIO_puts(bio_out, "\n");
|
||||
BIO_printf(bio_out, "NONE");
|
||||
BIO_printf(bio_out, "\n");
|
||||
}
|
||||
if (fingerprint == i) {
|
||||
int j;
|
||||
|
|
@ -376,13 +349,14 @@ int crl_main(int argc, char **argv)
|
|||
unsigned char md[EVP_MAX_MD_SIZE];
|
||||
|
||||
if (!X509_CRL_digest(x, digest, md, &n)) {
|
||||
BIO_puts(bio_err, "out of memory\n");
|
||||
BIO_printf(bio_err, "out of memory\n");
|
||||
goto end;
|
||||
}
|
||||
BIO_printf(bio_out, "%s Fingerprint=",
|
||||
EVP_MD_get0_name(digest));
|
||||
EVP_MD_get0_name(digest));
|
||||
for (j = 0; j < (int)n; j++) {
|
||||
BIO_printf(bio_out, "%02X%c", md[j], (j + 1 == (int)n) ? '\n' : ':');
|
||||
BIO_printf(bio_out, "%02X%c", md[j], (j + 1 == (int)n)
|
||||
? '\n' : ':');
|
||||
}
|
||||
}
|
||||
}
|
||||
|
|
@ -404,12 +378,12 @@ int crl_main(int argc, char **argv)
|
|||
else
|
||||
i = PEM_write_bio_X509_CRL(out, x);
|
||||
if (!i) {
|
||||
BIO_puts(bio_err, "unable to write CRL\n");
|
||||
BIO_printf(bio_err, "unable to write CRL\n");
|
||||
goto end;
|
||||
}
|
||||
ret = 0;
|
||||
|
||||
end:
|
||||
end:
|
||||
if (ret != 0)
|
||||
ERR_print_errors(bio_err);
|
||||
BIO_free_all(out);
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -23,32 +23,27 @@ static int add_certs_from_file(STACK_OF(X509) *stack, char *certfile);
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_INFORM,
|
||||
OPT_OUTFORM,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_NOCRL,
|
||||
OPT_CERTFILE,
|
||||
OPT_INFORM, OPT_OUTFORM, OPT_IN, OPT_OUT, OPT_NOCRL, OPT_CERTFILE,
|
||||
OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS crl2pkcs7_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
|
||||
OPT_SECTION("Input"),
|
||||
{ "in", OPT_IN, '<', "Input file" },
|
||||
{ "inform", OPT_INFORM, 'F', "Input format - DER or PEM" },
|
||||
{ "nocrl", OPT_NOCRL, '-', "No crl to load, just certs from '-certfile'" },
|
||||
{ "certfile", OPT_CERTFILE, '<',
|
||||
"File of chain of certs to a trusted CA; can be repeated" },
|
||||
{"in", OPT_IN, '<', "Input file"},
|
||||
{"inform", OPT_INFORM, 'F', "Input format - DER or PEM"},
|
||||
{"nocrl", OPT_NOCRL, '-', "No crl to load, just certs from '-certfile'"},
|
||||
{"certfile", OPT_CERTFILE, '<',
|
||||
"File of chain of certs to a trusted CA; can be repeated"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output file" },
|
||||
{ "outform", OPT_OUTFORM, 'F', "Output format - DER or PEM" },
|
||||
{"out", OPT_OUT, '>', "Output file"},
|
||||
{"outform", OPT_OUTFORM, 'F', "Output format - DER or PEM"},
|
||||
|
||||
OPT_PROV_OPTIONS,
|
||||
{ NULL }
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int crl2pkcs7_main(int argc, char **argv)
|
||||
|
|
@ -61,7 +56,8 @@ int crl2pkcs7_main(int argc, char **argv)
|
|||
STACK_OF(X509_CRL) *crl_stack = NULL;
|
||||
X509_CRL *crl = NULL;
|
||||
char *infile = NULL, *outfile = NULL, *prog, *certfile;
|
||||
int i = 0, informat = FORMAT_PEM, outformat = FORMAT_PEM, ret = 1, nocrl = 0;
|
||||
int i = 0, informat = FORMAT_PEM, outformat = FORMAT_PEM, ret = 1, nocrl =
|
||||
0;
|
||||
OPTION_CHOICE o;
|
||||
|
||||
prog = opt_init(argc, argv, crl2pkcs7_options);
|
||||
|
|
@ -69,7 +65,7 @@ int crl2pkcs7_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -121,7 +117,7 @@ int crl2pkcs7_main(int argc, char **argv)
|
|||
else if (informat == FORMAT_PEM)
|
||||
crl = PEM_read_bio_X509_CRL(in, NULL, NULL, NULL);
|
||||
if (crl == NULL) {
|
||||
BIO_puts(bio_err, "unable to load CRL\n");
|
||||
BIO_printf(bio_err, "unable to load CRL\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -145,7 +141,7 @@ int crl2pkcs7_main(int argc, char **argv)
|
|||
|
||||
if (!sk_X509_CRL_push(crl_stack, crl))
|
||||
goto end;
|
||||
crl = NULL; /* now part of p7 for OPENSSL_freeing */
|
||||
crl = NULL; /* now part of p7 for OPENSSL_freeing */
|
||||
}
|
||||
|
||||
if (certflst != NULL) {
|
||||
|
|
@ -156,7 +152,7 @@ int crl2pkcs7_main(int argc, char **argv)
|
|||
for (i = 0; i < sk_OPENSSL_STRING_num(certflst); i++) {
|
||||
certfile = sk_OPENSSL_STRING_value(certflst, i);
|
||||
if (add_certs_from_file(cert_stack, certfile) < 0) {
|
||||
BIO_puts(bio_err, "error loading certificates\n");
|
||||
BIO_printf(bio_err, "error loading certificates\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -172,12 +168,12 @@ int crl2pkcs7_main(int argc, char **argv)
|
|||
else if (outformat == FORMAT_PEM)
|
||||
i = PEM_write_bio_PKCS7(out, p7);
|
||||
if (!i) {
|
||||
BIO_puts(bio_err, "unable to write pkcs7 object\n");
|
||||
BIO_printf(bio_err, "unable to write pkcs7 object\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
ret = 0;
|
||||
end:
|
||||
end:
|
||||
sk_OPENSSL_STRING_free(certflst);
|
||||
BIO_free(in);
|
||||
BIO_free_all(out);
|
||||
|
|
@ -233,7 +229,7 @@ static int add_certs_from_file(STACK_OF(X509) *stack, char *certfile)
|
|||
}
|
||||
|
||||
ret = count;
|
||||
end:
|
||||
end:
|
||||
/* never need to OPENSSL_free x */
|
||||
BIO_free(in);
|
||||
sk_X509_INFO_free(sk);
|
||||
|
|
|
|||
404
apps/dgst.c
404
apps/dgst.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -7,10 +7,10 @@
|
|||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include "apps.h"
|
||||
#include <stdio.h>
|
||||
#include <string.h>
|
||||
#include <stdlib.h>
|
||||
#include "apps.h"
|
||||
#include "progs.h"
|
||||
#include <openssl/bio.h>
|
||||
#include <openssl/err.h>
|
||||
|
|
@ -20,18 +20,17 @@
|
|||
#include <openssl/pem.h>
|
||||
#include <openssl/hmac.h>
|
||||
#include <ctype.h>
|
||||
#include <sys/stat.h>
|
||||
|
||||
#undef BUFSIZE
|
||||
#define BUFSIZE 1024 * 8
|
||||
#define BUFSIZE 1024*8
|
||||
|
||||
static int do_fp_oneshot_sign(BIO *out, EVP_MD_CTX *ctx, BIO *in, int sep, int binout,
|
||||
EVP_PKEY *key, unsigned char *sigin, int siglen,
|
||||
const char *sig_name, const char *file);
|
||||
EVP_PKEY *key, unsigned char *sigin, int siglen,
|
||||
const char *sig_name, const char *file);
|
||||
int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen,
|
||||
EVP_PKEY *key, unsigned char *sigin, int siglen,
|
||||
const char *sig_name, const char *md_name,
|
||||
const char *file);
|
||||
EVP_PKEY *key, unsigned char *sigin, int siglen,
|
||||
const char *sig_name, const char *md_name,
|
||||
const char *file);
|
||||
static void show_digests(const OBJ_NAME *name, void *bio_);
|
||||
|
||||
struct doall_dgst_digests {
|
||||
|
|
@ -42,76 +41,63 @@ struct doall_dgst_digests {
|
|||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_LIST,
|
||||
OPT_C,
|
||||
OPT_R,
|
||||
OPT_OUT,
|
||||
OPT_SIGN,
|
||||
OPT_PASSIN,
|
||||
OPT_VERIFY,
|
||||
OPT_PRVERIFY,
|
||||
OPT_SIGNATURE,
|
||||
OPT_KEYFORM,
|
||||
OPT_HEX,
|
||||
OPT_BINARY,
|
||||
OPT_DEBUG,
|
||||
OPT_FIPS_FINGERPRINT,
|
||||
OPT_HMAC,
|
||||
OPT_HMAC_ENV,
|
||||
OPT_HMAC_STDIN,
|
||||
OPT_MAC,
|
||||
OPT_SIGOPT,
|
||||
OPT_MACOPT,
|
||||
OPT_XOFLEN,
|
||||
OPT_C, OPT_R, OPT_OUT, OPT_SIGN, OPT_PASSIN, OPT_VERIFY,
|
||||
OPT_PRVERIFY, OPT_SIGNATURE, OPT_KEYFORM, OPT_ENGINE, OPT_ENGINE_IMPL,
|
||||
OPT_HEX, OPT_BINARY, OPT_DEBUG, OPT_FIPS_FINGERPRINT,
|
||||
OPT_HMAC, OPT_MAC, OPT_SIGOPT, OPT_MACOPT, OPT_XOFLEN,
|
||||
OPT_DIGEST,
|
||||
OPT_R_ENUM,
|
||||
OPT_PROV_ENUM
|
||||
OPT_R_ENUM, OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS dgst_options[] = {
|
||||
{ OPT_HELP_STR, 1, '-', "Usage: %s [options] [file...]\n" },
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] [file...]\n"},
|
||||
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "list", OPT_LIST, '-', "List digests" },
|
||||
{ "passin", OPT_PASSIN, 's', "Input file pass phrase source" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"list", OPT_LIST, '-', "List digests"},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine e, possibly a hardware device"},
|
||||
{"engine_impl", OPT_ENGINE_IMPL, '-',
|
||||
"Also use engine given by -engine for digest operations"},
|
||||
#endif
|
||||
{"passin", OPT_PASSIN, 's', "Input file pass phrase source"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "c", OPT_C, '-', "Print the digest with separating colons" },
|
||||
{ "r", OPT_R, '-', "Print the digest in coreutils format" },
|
||||
{ "out", OPT_OUT, '>', "Output to filename rather than stdout" },
|
||||
{ "keyform", OPT_KEYFORM, 'f', "Key file format (DER/PEM)" },
|
||||
{ "hex", OPT_HEX, '-', "Print as hex dump" },
|
||||
{ "binary", OPT_BINARY, '-', "Print in binary form" },
|
||||
{ "xoflen", OPT_XOFLEN, 'p', "Output length for XOF algorithms. To obtain the maximum security strength set this to 32 (or greater) for SHAKE128, and 64 (or greater) for SHAKE256" },
|
||||
{ "d", OPT_DEBUG, '-', "Print debug info" },
|
||||
{ "debug", OPT_DEBUG, '-', "Print debug info" },
|
||||
{"c", OPT_C, '-', "Print the digest with separating colons"},
|
||||
{"r", OPT_R, '-', "Print the digest in coreutils format"},
|
||||
{"out", OPT_OUT, '>', "Output to filename rather than stdout"},
|
||||
{"keyform", OPT_KEYFORM, 'f', "Key file format (ENGINE, other values ignored)"},
|
||||
{"hex", OPT_HEX, '-', "Print as hex dump"},
|
||||
{"binary", OPT_BINARY, '-', "Print in binary form"},
|
||||
{"xoflen", OPT_XOFLEN, 'p', "Output length for XOF algorithms. To obtain the maximum security strength set this to 32 (or greater) for SHAKE128, and 64 (or greater) for SHAKE256"},
|
||||
{"d", OPT_DEBUG, '-', "Print debug info"},
|
||||
{"debug", OPT_DEBUG, '-', "Print debug info"},
|
||||
|
||||
OPT_SECTION("Signing"),
|
||||
{ "sign", OPT_SIGN, 's', "Sign digest using private key" },
|
||||
{ "verify", OPT_VERIFY, 's', "Verify a signature using public key" },
|
||||
{ "prverify", OPT_PRVERIFY, 's', "Verify a signature using private key" },
|
||||
{ "sigopt", OPT_SIGOPT, 's', "Signature parameter in n:v form" },
|
||||
{ "signature", OPT_SIGNATURE, '<', "File with signature to verify" },
|
||||
{ "hmac", OPT_HMAC, 's', "Create hashed MAC with key" },
|
||||
{ "hmac-env", OPT_HMAC_ENV, 's', "Create hashed MAC with key from environment variable" },
|
||||
{ "hmac-stdin", OPT_HMAC_STDIN, '-', "Create hashed MAC with key from stdin" },
|
||||
{ "mac", OPT_MAC, 's', "Create MAC (not necessarily HMAC)" },
|
||||
{ "macopt", OPT_MACOPT, 's', "MAC algorithm parameters in n:v form or key" },
|
||||
{ "", OPT_DIGEST, '-', "Any supported digest" },
|
||||
{ "fips-fingerprint", OPT_FIPS_FINGERPRINT, '-',
|
||||
"Compute HMAC with the key used in OpenSSL-FIPS fingerprint" },
|
||||
{"sign", OPT_SIGN, 's', "Sign digest using private key"},
|
||||
{"verify", OPT_VERIFY, 's', "Verify a signature using public key"},
|
||||
{"prverify", OPT_PRVERIFY, 's', "Verify a signature using private key"},
|
||||
{"sigopt", OPT_SIGOPT, 's', "Signature parameter in n:v form"},
|
||||
{"signature", OPT_SIGNATURE, '<', "File with signature to verify"},
|
||||
{"hmac", OPT_HMAC, 's', "Create hashed MAC with key"},
|
||||
{"mac", OPT_MAC, 's', "Create MAC (not necessarily HMAC)"},
|
||||
{"macopt", OPT_MACOPT, 's', "MAC algorithm parameters in n:v form or key"},
|
||||
{"", OPT_DIGEST, '-', "Any supported digest"},
|
||||
{"fips-fingerprint", OPT_FIPS_FINGERPRINT, '-',
|
||||
"Compute HMAC with the key used in OpenSSL-FIPS fingerprint"},
|
||||
|
||||
OPT_R_OPTIONS,
|
||||
OPT_PROV_OPTIONS,
|
||||
|
||||
OPT_PARAMETERS(),
|
||||
{ "file", 0, 0, "Files to digest (optional; default is stdin)" },
|
||||
{ NULL }
|
||||
{"file", 0, 0, "Files to digest (optional; default is stdin)"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int dgst_main(int argc, char **argv)
|
||||
{
|
||||
BIO *in = NULL, *inp = NULL, *bmd = NULL, *out = NULL;
|
||||
ENGINE *e = NULL, *impl = NULL;
|
||||
EVP_PKEY *sigkey = NULL;
|
||||
STACK_OF(OPENSSL_STRING) *sigopts = NULL, *macopts = NULL;
|
||||
char *hmac_key = NULL;
|
||||
|
|
@ -121,20 +107,18 @@ int dgst_main(int argc, char **argv)
|
|||
const char *outfile = NULL, *keyfile = NULL, *prog = NULL;
|
||||
const char *sigfile = NULL;
|
||||
const char *md_name = NULL;
|
||||
char *env_var = NULL;
|
||||
char *new_opt = NULL;
|
||||
char *key_from_stdin = NULL;
|
||||
OPTION_CHOICE o;
|
||||
int separator = 0, debug = 0, keyform = FORMAT_UNDEF, siglen = 0;
|
||||
int i, ret = EXIT_FAILURE, out_bin = -1, want_pub = 0, do_verify = 0;
|
||||
int xoflen = 0;
|
||||
unsigned char *buf = NULL, *sigbuf = NULL;
|
||||
int engine_impl = 0;
|
||||
struct doall_dgst_digests dec;
|
||||
EVP_MD_CTX *signctx = NULL;
|
||||
int oneshot_sign = 0;
|
||||
|
||||
buf = app_malloc(BUFSIZE, "I/O buffer");
|
||||
md = EVP_MD_fetch(app_get0_libctx(), argv[0], app_get0_propq());
|
||||
md = (EVP_MD *)EVP_get_digestbyname(argv[0]);
|
||||
if (md != NULL)
|
||||
digestname = argv[0];
|
||||
|
||||
|
|
@ -144,7 +128,7 @@ int dgst_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -152,12 +136,12 @@ int dgst_main(int argc, char **argv)
|
|||
ret = EXIT_SUCCESS;
|
||||
goto end;
|
||||
case OPT_LIST:
|
||||
BIO_puts(bio_out, "Supported digests:\n");
|
||||
BIO_printf(bio_out, "Supported digests:\n");
|
||||
dec.bio = bio_out;
|
||||
dec.n = 0;
|
||||
OBJ_NAME_do_all_sorted(OBJ_NAME_TYPE_MD_METH,
|
||||
show_digests, &dec);
|
||||
BIO_puts(bio_out, "\n");
|
||||
show_digests, &dec);
|
||||
BIO_printf(bio_out, "\n");
|
||||
ret = EXIT_SUCCESS;
|
||||
goto end;
|
||||
case OPT_C:
|
||||
|
|
@ -194,6 +178,12 @@ int dgst_main(int argc, char **argv)
|
|||
if (!opt_format(opt_arg(), OPT_FMT_ANY, &keyform))
|
||||
goto opthelp;
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_ENGINE_IMPL:
|
||||
engine_impl = 1;
|
||||
break;
|
||||
case OPT_HEX:
|
||||
out_bin = 0;
|
||||
break;
|
||||
|
|
@ -201,7 +191,7 @@ int dgst_main(int argc, char **argv)
|
|||
out_bin = 1;
|
||||
break;
|
||||
case OPT_XOFLEN:
|
||||
xoflen = opt_int_arg();
|
||||
xoflen = atoi(opt_arg());
|
||||
break;
|
||||
case OPT_DEBUG:
|
||||
debug = 1;
|
||||
|
|
@ -212,29 +202,6 @@ int dgst_main(int argc, char **argv)
|
|||
case OPT_HMAC:
|
||||
hmac_key = opt_arg();
|
||||
break;
|
||||
case OPT_HMAC_ENV:
|
||||
env_var = opt_arg();
|
||||
hmac_key = getenv(env_var);
|
||||
if (hmac_key == NULL) {
|
||||
BIO_printf(bio_err, "No environment variable %s\n", env_var);
|
||||
ret = EXIT_FAILURE;
|
||||
goto end;
|
||||
}
|
||||
break;
|
||||
case OPT_HMAC_STDIN:
|
||||
if (key_from_stdin == NULL)
|
||||
key_from_stdin = get_str_from_file(NULL);
|
||||
if (key_from_stdin == NULL) {
|
||||
ret = EXIT_FAILURE;
|
||||
goto end;
|
||||
}
|
||||
if (strlen(key_from_stdin) == 0) {
|
||||
BIO_printf(bio_err, "Empty key\n");
|
||||
ret = EXIT_FAILURE;
|
||||
goto end;
|
||||
}
|
||||
hmac_key = key_from_stdin;
|
||||
break;
|
||||
case OPT_MAC:
|
||||
mac_name = opt_arg();
|
||||
break;
|
||||
|
|
@ -245,17 +212,10 @@ int dgst_main(int argc, char **argv)
|
|||
goto opthelp;
|
||||
break;
|
||||
case OPT_MACOPT:
|
||||
new_opt = process_additional_mac_key_arguments(opt_arg());
|
||||
if (new_opt == NULL) {
|
||||
ret = EXIT_FAILURE;
|
||||
goto end;
|
||||
}
|
||||
if (!macopts)
|
||||
macopts = sk_OPENSSL_STRING_new_null();
|
||||
if (!macopts || !sk_OPENSSL_STRING_push(macopts, new_opt)) {
|
||||
clear_free(new_opt);
|
||||
if (!macopts || !sk_OPENSSL_STRING_push(macopts, opt_arg()))
|
||||
goto opthelp;
|
||||
}
|
||||
break;
|
||||
case OPT_DIGEST:
|
||||
digestname = opt_unknown();
|
||||
|
|
@ -283,10 +243,12 @@ int dgst_main(int argc, char **argv)
|
|||
}
|
||||
|
||||
if (do_verify && sigfile == NULL) {
|
||||
BIO_puts(bio_err,
|
||||
"No signature to verify: use the -signature option\n");
|
||||
BIO_printf(bio_err,
|
||||
"No signature to verify: use the -signature option\n");
|
||||
goto end;
|
||||
}
|
||||
if (engine_impl)
|
||||
impl = e;
|
||||
|
||||
in = BIO_new(BIO_s_file());
|
||||
bmd = BIO_new(BIO_f_md());
|
||||
|
|
@ -300,7 +262,7 @@ int dgst_main(int argc, char **argv)
|
|||
}
|
||||
|
||||
if (!app_passwd(passinarg, NULL, &passin, NULL)) {
|
||||
BIO_puts(bio_err, "Error getting password\n");
|
||||
BIO_printf(bio_err, "Error getting password\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -316,15 +278,15 @@ int dgst_main(int argc, char **argv)
|
|||
goto end;
|
||||
|
||||
if ((!(mac_name == NULL) + !(keyfile == NULL) + !(hmac_key == NULL)) > 1) {
|
||||
BIO_puts(bio_err, "MAC and signing key cannot both be specified\n");
|
||||
BIO_printf(bio_err, "MAC and signing key cannot both be specified\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (keyfile != NULL) {
|
||||
if (want_pub)
|
||||
sigkey = load_pubkey(keyfile, keyform, 0, NULL, "public key");
|
||||
sigkey = load_pubkey(keyfile, keyform, 0, NULL, e, "public key");
|
||||
else
|
||||
sigkey = load_key(keyfile, keyform, 0, passin, "private key");
|
||||
sigkey = load_key(keyfile, keyform, 0, passin, e, "private key");
|
||||
if (sigkey == NULL) {
|
||||
/*
|
||||
* load_[pub]key() has already printed an appropriate message
|
||||
|
|
@ -335,9 +297,8 @@ int dgst_main(int argc, char **argv)
|
|||
char def_md[80];
|
||||
|
||||
if (EVP_PKEY_get_default_digest_name(sigkey, def_md,
|
||||
sizeof(def_md))
|
||||
== 2
|
||||
&& strcmp(def_md, "UNDEF") == 0)
|
||||
sizeof(def_md)) == 2
|
||||
&& strcmp(def_md, "UNDEF") == 0)
|
||||
oneshot_sign = 1;
|
||||
signctx = EVP_MD_CTX_new();
|
||||
if (signctx == NULL)
|
||||
|
|
@ -348,7 +309,7 @@ int dgst_main(int argc, char **argv)
|
|||
if (mac_name != NULL) {
|
||||
EVP_PKEY_CTX *mac_ctx = NULL;
|
||||
|
||||
if (!init_gen_str(&mac_ctx, mac_name, 0, NULL, NULL))
|
||||
if (!init_gen_str(&mac_ctx, mac_name, impl, 0, NULL, NULL))
|
||||
goto end;
|
||||
if (macopts != NULL) {
|
||||
for (i = 0; i < sk_OPENSSL_STRING_num(macopts); i++) {
|
||||
|
|
@ -363,6 +324,7 @@ int dgst_main(int argc, char **argv)
|
|||
}
|
||||
|
||||
sigkey = app_keygen(mac_ctx, mac_name, 0, 0 /* not verbose */);
|
||||
/* Verbose output would make external-tests gost-engine fail */
|
||||
EVP_PKEY_CTX_free(mac_ctx);
|
||||
if (sigkey == NULL)
|
||||
goto end;
|
||||
|
|
@ -373,9 +335,9 @@ int dgst_main(int argc, char **argv)
|
|||
md = (EVP_MD *)EVP_sha256();
|
||||
digestname = SN_sha256;
|
||||
}
|
||||
sigkey = EVP_PKEY_new_raw_private_key(EVP_PKEY_HMAC, NULL,
|
||||
(unsigned char *)hmac_key,
|
||||
strlen(hmac_key));
|
||||
sigkey = EVP_PKEY_new_raw_private_key(EVP_PKEY_HMAC, impl,
|
||||
(unsigned char *)hmac_key,
|
||||
strlen(hmac_key));
|
||||
if (sigkey == NULL)
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -388,19 +350,25 @@ int dgst_main(int argc, char **argv)
|
|||
if (oneshot_sign) {
|
||||
mctx = signctx;
|
||||
} else if (BIO_get_md_ctx(bmd, &mctx) <= 0) {
|
||||
BIO_puts(bio_err, "Error getting context\n");
|
||||
BIO_printf(bio_err, "Error getting context\n");
|
||||
goto end;
|
||||
}
|
||||
if (do_verify)
|
||||
res = EVP_DigestVerifyInit_ex(mctx, &pctx, digestname,
|
||||
app_get0_libctx(),
|
||||
app_get0_propq(), sigkey, NULL);
|
||||
if (impl == NULL)
|
||||
res = EVP_DigestVerifyInit_ex(mctx, &pctx, digestname,
|
||||
app_get0_libctx(),
|
||||
app_get0_propq(), sigkey, NULL);
|
||||
else
|
||||
res = EVP_DigestVerifyInit(mctx, &pctx, md, impl, sigkey);
|
||||
else
|
||||
res = EVP_DigestSignInit_ex(mctx, &pctx, digestname,
|
||||
app_get0_libctx(),
|
||||
app_get0_propq(), sigkey, NULL);
|
||||
if (impl == NULL)
|
||||
res = EVP_DigestSignInit_ex(mctx, &pctx, digestname,
|
||||
app_get0_libctx(),
|
||||
app_get0_propq(), sigkey, NULL);
|
||||
else
|
||||
res = EVP_DigestSignInit(mctx, &pctx, md, impl, sigkey);
|
||||
if (res == 0) {
|
||||
BIO_puts(bio_err, "Error setting context\n");
|
||||
BIO_printf(bio_err, "Error setting context\n");
|
||||
goto end;
|
||||
}
|
||||
if (sigopts != NULL) {
|
||||
|
|
@ -409,7 +377,7 @@ int dgst_main(int argc, char **argv)
|
|||
|
||||
if (pkey_ctrl_string(pctx, sigopt) <= 0) {
|
||||
BIO_printf(bio_err, "Signature parameter error \"%s\"\n",
|
||||
sigopt);
|
||||
sigopt);
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -420,17 +388,17 @@ int dgst_main(int argc, char **argv)
|
|||
EVP_MD_CTX *mctx = NULL;
|
||||
|
||||
if (oneshot_sign) {
|
||||
BIO_puts(bio_err, "Oneshot algorithms don't use a digest\n");
|
||||
BIO_printf(bio_err, "Oneshot algorithms don't use a digest\n");
|
||||
goto end;
|
||||
}
|
||||
if (BIO_get_md_ctx(bmd, &mctx) <= 0) {
|
||||
BIO_puts(bio_err, "Error getting context\n");
|
||||
BIO_printf(bio_err, "Error getting context\n");
|
||||
goto end;
|
||||
}
|
||||
if (md == NULL)
|
||||
md = (EVP_MD *)EVP_sha256();
|
||||
if (!EVP_DigestInit_ex(mctx, md, NULL)) {
|
||||
BIO_puts(bio_err, "Error setting digest\n");
|
||||
if (!EVP_DigestInit_ex(mctx, md, impl)) {
|
||||
BIO_printf(bio_err, "Error setting digest\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -465,7 +433,7 @@ int dgst_main(int argc, char **argv)
|
|||
}
|
||||
if (xoflen > 0) {
|
||||
if (!EVP_MD_xof(md)) {
|
||||
BIO_puts(bio_err, "Length can only be specified for XOF\n");
|
||||
BIO_printf(bio_err, "Length can only be specified for XOF\n");
|
||||
goto end;
|
||||
}
|
||||
/*
|
||||
|
|
@ -474,7 +442,7 @@ int dgst_main(int argc, char **argv)
|
|||
* and verify_final methods.
|
||||
*/
|
||||
if (sigkey != NULL) {
|
||||
BIO_puts(bio_err, "Signing key cannot be specified for XOF\n");
|
||||
BIO_printf(bio_err, "Signing key cannot be specified for XOF\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -483,14 +451,10 @@ int dgst_main(int argc, char **argv)
|
|||
BIO_set_fp(in, stdin, BIO_NOCLOSE);
|
||||
if (oneshot_sign)
|
||||
ret = do_fp_oneshot_sign(out, signctx, in, separator, out_bin,
|
||||
sigkey, sigbuf, siglen, NULL, NULL)
|
||||
? EXIT_SUCCESS
|
||||
: EXIT_FAILURE;
|
||||
sigkey, sigbuf, siglen, NULL, "stdin");
|
||||
else
|
||||
ret = do_fp(out, buf, inp, separator, out_bin, xoflen,
|
||||
sigkey, sigbuf, siglen, NULL, md_name, "stdin")
|
||||
? EXIT_SUCCESS
|
||||
: EXIT_FAILURE;
|
||||
sigkey, sigbuf, siglen, NULL, md_name, "stdin");
|
||||
} else {
|
||||
const char *sig_name = NULL;
|
||||
|
||||
|
|
@ -506,25 +470,23 @@ int dgst_main(int argc, char **argv)
|
|||
continue;
|
||||
} else {
|
||||
if (oneshot_sign) {
|
||||
if (!do_fp_oneshot_sign(out, signctx, in, separator, out_bin,
|
||||
sigkey, sigbuf, siglen, sig_name,
|
||||
argv[i]))
|
||||
if (do_fp_oneshot_sign(out, signctx, in, separator, out_bin,
|
||||
sigkey, sigbuf, siglen, sig_name,
|
||||
argv[i]))
|
||||
ret = EXIT_FAILURE;
|
||||
} else {
|
||||
if (!do_fp(out, buf, inp, separator, out_bin, xoflen,
|
||||
sigkey, sigbuf, siglen, sig_name, md_name, argv[i]))
|
||||
if (do_fp(out, buf, inp, separator, out_bin, xoflen,
|
||||
sigkey, sigbuf, siglen, sig_name, md_name, argv[i]))
|
||||
ret = EXIT_FAILURE;
|
||||
}
|
||||
}
|
||||
(void)BIO_reset(bmd);
|
||||
}
|
||||
}
|
||||
end:
|
||||
end:
|
||||
if (ret != EXIT_SUCCESS)
|
||||
ERR_print_errors(bio_err);
|
||||
OPENSSL_clear_free(buf, BUFSIZE);
|
||||
if (key_from_stdin != NULL)
|
||||
clear_free(key_from_stdin);
|
||||
BIO_free(in);
|
||||
OPENSSL_free(passin);
|
||||
BIO_free_all(out);
|
||||
|
|
@ -532,9 +494,10 @@ end:
|
|||
EVP_PKEY_free(sigkey);
|
||||
EVP_MD_CTX_free(signctx);
|
||||
sk_OPENSSL_STRING_free(sigopts);
|
||||
sk_OPENSSL_STRING_pop_free(macopts, clear_free);
|
||||
sk_OPENSSL_STRING_free(macopts);
|
||||
OPENSSL_free(sigbuf);
|
||||
BIO_free(bmd);
|
||||
release_engine(e);
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
|
@ -552,15 +515,17 @@ static void show_digests(const OBJ_NAME *name, void *arg)
|
|||
|
||||
/* Filter out message digests that we cannot use */
|
||||
md = EVP_MD_fetch(app_get0_libctx(), name->name, app_get0_propq());
|
||||
if (md == NULL)
|
||||
return;
|
||||
if (md == NULL) {
|
||||
if (EVP_get_digestbyname(name->name) == NULL)
|
||||
return;
|
||||
}
|
||||
|
||||
BIO_printf(dec->bio, "-%-25s", name->name);
|
||||
if (++dec->n == 3) {
|
||||
BIO_puts(dec->bio, "\n");
|
||||
BIO_printf(dec->bio, "\n");
|
||||
dec->n = 0;
|
||||
} else {
|
||||
BIO_puts(dec->bio, " ");
|
||||
BIO_printf(dec->bio, " ");
|
||||
}
|
||||
|
||||
EVP_MD_free(md);
|
||||
|
|
@ -601,17 +566,17 @@ static const char *newline_escape_filename(const char *file, int *backslash)
|
|||
e++;
|
||||
}
|
||||
file_cpy[i] = '\0';
|
||||
return (const char *)file_cpy;
|
||||
return (const char*)file_cpy;
|
||||
}
|
||||
|
||||
static void print_out(BIO *out, unsigned char *buf, size_t len,
|
||||
int sep, int binout,
|
||||
const char *sig_name, const char *md_name, const char *file)
|
||||
int sep, int binout,
|
||||
const char *sig_name, const char *md_name, const char *file)
|
||||
{
|
||||
int i, backslash = 0;
|
||||
|
||||
if (binout) {
|
||||
BIO_write(out, buf, (int)len);
|
||||
BIO_write(out, buf, len);
|
||||
} else if (sep == 2) {
|
||||
file = newline_escape_filename(file, &backslash);
|
||||
|
||||
|
|
@ -636,34 +601,30 @@ static void print_out(BIO *out, unsigned char *buf, size_t len,
|
|||
}
|
||||
for (i = 0; i < (int)len; i++) {
|
||||
if (sep && (i != 0))
|
||||
BIO_puts(out, ":");
|
||||
BIO_printf(out, ":");
|
||||
BIO_printf(out, "%02x", buf[i]);
|
||||
}
|
||||
BIO_puts(out, "\n");
|
||||
BIO_printf(out, "\n");
|
||||
}
|
||||
}
|
||||
|
||||
static void print_verify_result(BIO *out, int i)
|
||||
{
|
||||
if (i > 0)
|
||||
BIO_puts(out, "Verified OK\n");
|
||||
BIO_printf(out, "Verified OK\n");
|
||||
else if (i == 0)
|
||||
BIO_puts(out, "Verification failure\n");
|
||||
BIO_printf(out, "Verification failure\n");
|
||||
else
|
||||
BIO_puts(bio_err, "Error verifying data\n");
|
||||
BIO_printf(bio_err, "Error verifying data\n");
|
||||
}
|
||||
|
||||
/*
|
||||
* Returns 1 on success, 0 on failure. Do not use EXIT_SUCCESS / EXIT_FAILURE
|
||||
* here; reserve those for main() and exit(3) (issue #30562).
|
||||
*/
|
||||
int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen,
|
||||
EVP_PKEY *key, unsigned char *sigin, int siglen,
|
||||
const char *sig_name, const char *md_name,
|
||||
const char *file)
|
||||
EVP_PKEY *key, unsigned char *sigin, int siglen,
|
||||
const char *sig_name, const char *md_name,
|
||||
const char *file)
|
||||
{
|
||||
size_t len = BUFSIZE;
|
||||
int i, ret = 0;
|
||||
int i, ret = EXIT_FAILURE;
|
||||
unsigned char *allocated_buf = NULL;
|
||||
|
||||
while (BIO_pending(bp) || !BIO_eof(bp)) {
|
||||
|
|
@ -681,7 +642,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen
|
|||
i = EVP_DigestVerifyFinal(ctx, sigin, (unsigned int)siglen);
|
||||
print_verify_result(out, i);
|
||||
if (i > 0)
|
||||
ret = 1;
|
||||
ret = EXIT_SUCCESS;
|
||||
goto end;
|
||||
}
|
||||
if (key != NULL) {
|
||||
|
|
@ -690,7 +651,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen
|
|||
|
||||
BIO_get_md_ctx(bp, &ctx);
|
||||
if (!EVP_DigestSignFinal(ctx, NULL, &tmplen)) {
|
||||
BIO_puts(bio_err, "Error getting maximum length of signed data\n");
|
||||
BIO_printf(bio_err, "Error getting maximum length of signed data\n");
|
||||
goto end;
|
||||
}
|
||||
if (tmplen > BUFSIZE) {
|
||||
|
|
@ -699,7 +660,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen
|
|||
buf = allocated_buf;
|
||||
}
|
||||
if (!EVP_DigestSignFinal(ctx, buf, &len)) {
|
||||
BIO_puts(bio_err, "Error signing data\n");
|
||||
BIO_printf(bio_err, "Error signing data\n");
|
||||
goto end;
|
||||
}
|
||||
} else if (xoflen > 0) {
|
||||
|
|
@ -714,7 +675,7 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen
|
|||
BIO_get_md_ctx(bp, &ctx);
|
||||
|
||||
if (!EVP_DigestFinalXOF(ctx, buf, len)) {
|
||||
BIO_puts(bio_err, "Error Digesting Data\n");
|
||||
BIO_printf(bio_err, "Error Digesting Data\n");
|
||||
goto end;
|
||||
}
|
||||
} else {
|
||||
|
|
@ -723,95 +684,62 @@ int do_fp(BIO *out, unsigned char *buf, BIO *bp, int sep, int binout, int xoflen
|
|||
goto end;
|
||||
}
|
||||
print_out(out, buf, len, sep, binout, sig_name, md_name, file);
|
||||
ret = 1;
|
||||
end:
|
||||
ret = EXIT_SUCCESS;
|
||||
end:
|
||||
if (allocated_buf != NULL)
|
||||
OPENSSL_clear_free(allocated_buf, len);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
||||
/*
|
||||
* Perform one-shot verify or sign on a contiguous data buffer.
|
||||
* Returns 0 on failure, 1 on success.
|
||||
*/
|
||||
static int do_oneshot_verify_sign(EVP_MD_CTX *ctx, BIO *out,
|
||||
unsigned char *sigin, int siglen, EVP_PKEY *key,
|
||||
const unsigned char *data, size_t len,
|
||||
int sep, int binout, const char *sig_name, const char *file)
|
||||
{
|
||||
int res;
|
||||
size_t siglen_out = 0;
|
||||
unsigned char *sig = NULL;
|
||||
|
||||
if (sigin != NULL) {
|
||||
res = EVP_DigestVerify(ctx, sigin, siglen, data, len);
|
||||
print_verify_result(out, res);
|
||||
return res > 0;
|
||||
}
|
||||
if (key != NULL) {
|
||||
if (EVP_DigestSign(ctx, NULL, &siglen_out, data, len) != 1) {
|
||||
BIO_puts(bio_err, "Error getting maximum length of signed data\n");
|
||||
return 0;
|
||||
}
|
||||
sig = app_malloc(siglen_out, "Signature buffer");
|
||||
if (EVP_DigestSign(ctx, sig, &siglen_out, data, len) != 1) {
|
||||
BIO_puts(bio_err, "Error signing data\n");
|
||||
OPENSSL_free(sig);
|
||||
return 0;
|
||||
}
|
||||
print_out(out, sig, siglen_out, sep, binout, sig_name, NULL, file);
|
||||
OPENSSL_free(sig);
|
||||
return 1;
|
||||
}
|
||||
BIO_puts(bio_err, "key must be set for one-shot algorithms\n");
|
||||
return 0;
|
||||
}
|
||||
|
||||
/*
|
||||
* Some new algorithms only support one shot operations.
|
||||
* For these we need to buffer all input and then do the sign on the
|
||||
* total buffered input. These algorithms set a NULL digest name which is
|
||||
* then used inside EVP_DigestVerify() and EVP_DigestSign().
|
||||
* Returns 1 on success, 0 on failure. Do not use EXIT_SUCCESS / EXIT_FAILURE
|
||||
* here; reserve those for main() and exit(3) (issue #30562).
|
||||
*/
|
||||
static int do_fp_oneshot_sign(BIO *out, EVP_MD_CTX *ctx, BIO *in, int sep, int binout,
|
||||
EVP_PKEY *key, unsigned char *sigin, int siglen,
|
||||
const char *sig_name, const char *file)
|
||||
EVP_PKEY *key, unsigned char *sigin, int siglen,
|
||||
const char *sig_name, const char *file)
|
||||
{
|
||||
int ret = 0;
|
||||
size_t buflen = 0;
|
||||
size_t maxlen = 16 * 1024 * 1024;
|
||||
uint8_t *buf = NULL;
|
||||
int res, ret = EXIT_FAILURE;
|
||||
size_t len = 0;
|
||||
int buflen = 0;
|
||||
int maxlen = 16 * 1024 * 1024;
|
||||
uint8_t *buf = NULL, *sig = NULL;
|
||||
|
||||
#if defined(OPENSSL_SYS_UNIX) && defined(_POSIX_MAPPED_FILES) && _POSIX_MAPPED_FILES > 0
|
||||
if (file != NULL) {
|
||||
const unsigned char *data = NULL;
|
||||
size_t filesize = 0;
|
||||
int r = app_mmap_file(file, bio_err, (size_t)-1, &data, &filesize);
|
||||
|
||||
if (r == 1) {
|
||||
ret = do_oneshot_verify_sign(ctx, out, sigin, siglen, key, data,
|
||||
filesize, sep, binout, sig_name, file);
|
||||
munmap((void *)data, filesize);
|
||||
return ret;
|
||||
buflen = bio_to_mem(&buf, maxlen, in);
|
||||
if (buflen <= 0) {
|
||||
BIO_printf(bio_err, "Read error in %s\n", file);
|
||||
return ret;
|
||||
}
|
||||
if (sigin != NULL) {
|
||||
res = EVP_DigestVerify(ctx, sigin, siglen, buf, buflen);
|
||||
print_verify_result(out, res);
|
||||
if (res > 0)
|
||||
ret = EXIT_SUCCESS;
|
||||
goto end;
|
||||
}
|
||||
if (key != NULL) {
|
||||
if (EVP_DigestSign(ctx, NULL, &len, buf, buflen) != 1) {
|
||||
BIO_printf(bio_err, "Error getting maximum length of signed data\n");
|
||||
goto end;
|
||||
}
|
||||
if (r == -1)
|
||||
return 0; /* error already printed */
|
||||
/* r == 0: empty file, fall through to buffer path */
|
||||
sig = app_malloc(len, "Signature buffer");
|
||||
if (EVP_DigestSign(ctx, sig, &len, buf, buflen) != 1) {
|
||||
BIO_printf(bio_err, "Error signing data\n");
|
||||
goto end;
|
||||
}
|
||||
print_out(out, sig, len, sep, binout, sig_name, NULL, file);
|
||||
ret = EXIT_SUCCESS;
|
||||
} else {
|
||||
BIO_printf(bio_err, "key must be set for one-shot algorithms\n");
|
||||
goto end;
|
||||
}
|
||||
#endif
|
||||
|
||||
{
|
||||
const char *display_file = file != NULL ? file : "stdin";
|
||||
|
||||
if (!bio_to_mem(&buf, &buflen, maxlen, in))
|
||||
return 0;
|
||||
ret = do_oneshot_verify_sign(ctx, out, sigin, siglen, key, buf, buflen,
|
||||
sep, binout, sig_name, display_file);
|
||||
OPENSSL_clear_free(buf, buflen);
|
||||
}
|
||||
end:
|
||||
OPENSSL_free(sig);
|
||||
OPENSSL_clear_free(buf, buflen);
|
||||
|
||||
return ret;
|
||||
}
|
||||
|
|
|
|||
194
apps/dhparam.c
194
apps/dhparam.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -36,55 +36,47 @@ static int verbose = 1;
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_INFORM,
|
||||
OPT_OUTFORM,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_CHECK,
|
||||
OPT_TEXT,
|
||||
OPT_NOOUT,
|
||||
OPT_DSAPARAM,
|
||||
OPT_2,
|
||||
OPT_3,
|
||||
OPT_5,
|
||||
OPT_VERBOSE,
|
||||
OPT_QUIET,
|
||||
OPT_R_ENUM,
|
||||
OPT_PROV_ENUM
|
||||
OPT_INFORM, OPT_OUTFORM, OPT_IN, OPT_OUT,
|
||||
OPT_ENGINE, OPT_CHECK, OPT_TEXT, OPT_NOOUT,
|
||||
OPT_DSAPARAM, OPT_2, OPT_3, OPT_5, OPT_VERBOSE, OPT_QUIET,
|
||||
OPT_R_ENUM, OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS dhparam_options[] = {
|
||||
{ OPT_HELP_STR, 1, '-', "Usage: %s [options] [numbits]\n" },
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] [numbits]\n"},
|
||||
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "check", OPT_CHECK, '-', "Check the DH parameters" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"check", OPT_CHECK, '-', "Check the DH parameters"},
|
||||
#if !defined(OPENSSL_NO_DSA) || !defined(OPENSSL_NO_DEPRECATED_3_0)
|
||||
{ "dsaparam", OPT_DSAPARAM, '-',
|
||||
"Read or generate DSA parameters, convert to DH" },
|
||||
{"dsaparam", OPT_DSAPARAM, '-',
|
||||
"Read or generate DSA parameters, convert to DH"},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine e, possibly a hardware device"},
|
||||
#endif
|
||||
|
||||
OPT_SECTION("Input"),
|
||||
{ "in", OPT_IN, '<', "Input file" },
|
||||
{ "inform", OPT_INFORM, 'F', "Input format, DER or PEM" },
|
||||
{"in", OPT_IN, '<', "Input file"},
|
||||
{"inform", OPT_INFORM, 'F', "Input format, DER or PEM"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output file" },
|
||||
{ "outform", OPT_OUTFORM, 'F', "Output format, DER or PEM" },
|
||||
{ "text", OPT_TEXT, '-', "Print a text form of the DH parameters" },
|
||||
{ "noout", OPT_NOOUT, '-', "Don't output any DH parameters" },
|
||||
{ "2", OPT_2, '-', "Generate parameters using 2 as the generator value" },
|
||||
{ "3", OPT_3, '-', "Generate parameters using 3 as the generator value" },
|
||||
{ "5", OPT_5, '-', "Generate parameters using 5 as the generator value" },
|
||||
{ "verbose", OPT_VERBOSE, '-', "Verbose output" },
|
||||
{ "quiet", OPT_QUIET, '-', "Terse output" },
|
||||
{"out", OPT_OUT, '>', "Output file"},
|
||||
{"outform", OPT_OUTFORM, 'F', "Output format, DER or PEM"},
|
||||
{"text", OPT_TEXT, '-', "Print a text form of the DH parameters"},
|
||||
{"noout", OPT_NOOUT, '-', "Don't output any DH parameters"},
|
||||
{"2", OPT_2, '-', "Generate parameters using 2 as the generator value"},
|
||||
{"3", OPT_3, '-', "Generate parameters using 3 as the generator value"},
|
||||
{"5", OPT_5, '-', "Generate parameters using 5 as the generator value"},
|
||||
{"verbose", OPT_VERBOSE, '-', "Verbose output"},
|
||||
{"quiet", OPT_QUIET, '-', "Terse output"},
|
||||
|
||||
OPT_R_OPTIONS,
|
||||
OPT_PROV_OPTIONS,
|
||||
|
||||
OPT_PARAMETERS(),
|
||||
{ "numbits", 0, 0, "Number of bits if generating parameters (optional)" },
|
||||
{ NULL }
|
||||
{"numbits", 0, 0, "Number of bits if generating parameters (optional)"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int dhparam_main(int argc, char **argv)
|
||||
|
|
@ -93,6 +85,7 @@ int dhparam_main(int argc, char **argv)
|
|||
EVP_PKEY *pkey = NULL, *tmppkey = NULL;
|
||||
EVP_PKEY_CTX *ctx = NULL;
|
||||
char *infile = NULL, *outfile = NULL, *prog;
|
||||
ENGINE *e = NULL;
|
||||
int dsaparam = 0;
|
||||
int text = 0, ret = 1, num = 0, g = 0;
|
||||
int informat = FORMAT_PEM, outformat = FORMAT_PEM, check = 0, noout = 0;
|
||||
|
|
@ -103,7 +96,7 @@ int dhparam_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -124,6 +117,9 @@ int dhparam_main(int argc, char **argv)
|
|||
case OPT_OUT:
|
||||
outfile = opt_arg();
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_CHECK:
|
||||
check = 1;
|
||||
break;
|
||||
|
|
@ -178,8 +174,8 @@ int dhparam_main(int argc, char **argv)
|
|||
num = DEFBITS;
|
||||
|
||||
if (dsaparam && g) {
|
||||
BIO_puts(bio_err,
|
||||
"Error, generator may not be chosen for DSA parameters\n");
|
||||
BIO_printf(bio_err,
|
||||
"Error, generator may not be chosen for DSA parameters\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -197,37 +193,37 @@ int dhparam_main(int argc, char **argv)
|
|||
ctx = EVP_PKEY_CTX_new_from_name(app_get0_libctx(), alg, app_get0_propq());
|
||||
if (ctx == NULL) {
|
||||
BIO_printf(bio_err,
|
||||
"Error, %s param generation context allocation failed\n",
|
||||
alg);
|
||||
"Error, %s param generation context allocation failed\n",
|
||||
alg);
|
||||
goto end;
|
||||
}
|
||||
EVP_PKEY_CTX_set_app_data(ctx, bio_err);
|
||||
if (verbose) {
|
||||
EVP_PKEY_CTX_set_cb(ctx, progress_cb);
|
||||
BIO_printf(bio_err,
|
||||
"Generating %s parameters, %d bit long %sprime\n",
|
||||
alg, num, dsaparam ? "" : "safe ");
|
||||
"Generating %s parameters, %d bit long %sprime\n",
|
||||
alg, num, dsaparam ? "" : "safe ");
|
||||
}
|
||||
|
||||
if (EVP_PKEY_paramgen_init(ctx) <= 0) {
|
||||
BIO_printf(bio_err,
|
||||
"Error, unable to initialise %s parameters\n",
|
||||
alg);
|
||||
"Error, unable to initialise %s parameters\n",
|
||||
alg);
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (dsaparam) {
|
||||
if (EVP_PKEY_CTX_set_dsa_paramgen_bits(ctx, num) <= 0) {
|
||||
BIO_puts(bio_err, "Error, unable to set DSA prime length\n");
|
||||
BIO_printf(bio_err, "Error, unable to set DSA prime length\n");
|
||||
goto end;
|
||||
}
|
||||
} else {
|
||||
if (EVP_PKEY_CTX_set_dh_paramgen_prime_len(ctx, num) <= 0) {
|
||||
BIO_puts(bio_err, "Error, unable to set DH prime length\n");
|
||||
BIO_printf(bio_err, "Error, unable to set DH prime length\n");
|
||||
goto end;
|
||||
}
|
||||
if (EVP_PKEY_CTX_set_dh_paramgen_generator(ctx, g) <= 0) {
|
||||
BIO_puts(bio_err, "Error, unable to set generator\n");
|
||||
BIO_printf(bio_err, "Error, unable to set generator\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -262,34 +258,32 @@ int dhparam_main(int argc, char **argv)
|
|||
*/
|
||||
done = 1;
|
||||
/*
|
||||
* We set NULL for the keytype to allow any key type. We don't know
|
||||
* if we're going to get DH or DHX (or DSA in the event of dsaparam).
|
||||
* We check that we got one of those key types afterwards.
|
||||
*/
|
||||
* We set NULL for the keytype to allow any key type. We don't know
|
||||
* if we're going to get DH or DHX (or DSA in the event of dsaparam).
|
||||
* We check that we got one of those key types afterwards.
|
||||
*/
|
||||
decoderctx
|
||||
= OSSL_DECODER_CTX_new_for_pkey(&tmppkey,
|
||||
(informat == FORMAT_ASN1)
|
||||
? "DER"
|
||||
: "PEM",
|
||||
NULL,
|
||||
(informat == FORMAT_ASN1)
|
||||
? keytype
|
||||
: NULL,
|
||||
OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
|
||||
NULL, NULL);
|
||||
(informat == FORMAT_ASN1)
|
||||
? "DER" : "PEM",
|
||||
NULL,
|
||||
(informat == FORMAT_ASN1)
|
||||
? keytype : NULL,
|
||||
OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
|
||||
NULL, NULL);
|
||||
|
||||
if (decoderctx != NULL
|
||||
&& !OSSL_DECODER_from_bio(decoderctx, in)
|
||||
&& informat == FORMAT_ASN1
|
||||
&& strcmp(keytype, "DH") == 0) {
|
||||
&& !OSSL_DECODER_from_bio(decoderctx, in)
|
||||
&& informat == FORMAT_ASN1
|
||||
&& strcmp(keytype, "DH") == 0) {
|
||||
/*
|
||||
* When reading DER we explicitly state the expected keytype
|
||||
* because, unlike PEM, there is no header to declare what
|
||||
* the contents of the DER file are. The decoders just try
|
||||
* and guess. Unfortunately with DHX key types they may guess
|
||||
* wrong and think we have a DSA keytype. Therefore, we try
|
||||
* both DH and DHX sequentially.
|
||||
*/
|
||||
* When reading DER we explicitly state the expected keytype
|
||||
* because, unlike PEM, there is no header to declare what
|
||||
* the contents of the DER file are. The decoders just try
|
||||
* and guess. Unfortunately with DHX key types they may guess
|
||||
* wrong and think we have a DSA keytype. Therefore, we try
|
||||
* both DH and DHX sequentially.
|
||||
*/
|
||||
keytype = "DHX";
|
||||
/*
|
||||
* BIO_reset() returns 0 for success for file BIOs only!!!
|
||||
|
|
@ -301,13 +295,13 @@ int dhparam_main(int argc, char **argv)
|
|||
OSSL_DECODER_CTX_free(decoderctx);
|
||||
} while (!done);
|
||||
if (tmppkey == NULL) {
|
||||
BIO_puts(bio_err, "Error, unable to load parameters\n");
|
||||
BIO_printf(bio_err, "Error, unable to load parameters\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (dsaparam) {
|
||||
if (!EVP_PKEY_is_a(tmppkey, "DSA")) {
|
||||
BIO_puts(bio_err, "Error, unable to load DSA parameters\n");
|
||||
BIO_printf(bio_err, "Error, unable to load DSA parameters\n");
|
||||
goto end;
|
||||
}
|
||||
pkey = dsa_to_dh(tmppkey);
|
||||
|
|
@ -315,8 +309,8 @@ int dhparam_main(int argc, char **argv)
|
|||
goto end;
|
||||
} else {
|
||||
if (!EVP_PKEY_is_a(tmppkey, "DH")
|
||||
&& !EVP_PKEY_is_a(tmppkey, "DHX")) {
|
||||
BIO_puts(bio_err, "Error, unable to load DH parameters\n");
|
||||
&& !EVP_PKEY_is_a(tmppkey, "DHX")) {
|
||||
BIO_printf(bio_err, "Error, unable to load DH parameters\n");
|
||||
goto end;
|
||||
}
|
||||
pkey = tmppkey;
|
||||
|
|
@ -334,33 +328,33 @@ int dhparam_main(int argc, char **argv)
|
|||
if (check) {
|
||||
ctx = EVP_PKEY_CTX_new_from_pkey(app_get0_libctx(), pkey, app_get0_propq());
|
||||
if (ctx == NULL) {
|
||||
BIO_puts(bio_err, "Error, failed to check DH parameters\n");
|
||||
BIO_printf(bio_err, "Error, failed to check DH parameters\n");
|
||||
goto end;
|
||||
}
|
||||
if (EVP_PKEY_param_check(ctx) <= 0) {
|
||||
BIO_puts(bio_err, "Error, invalid parameters generated\n");
|
||||
BIO_printf(bio_err, "Error, invalid parameters generated\n");
|
||||
goto end;
|
||||
}
|
||||
BIO_puts(bio_err, "DH parameters appear to be ok.\n");
|
||||
BIO_printf(bio_err, "DH parameters appear to be ok.\n");
|
||||
}
|
||||
|
||||
if (!noout) {
|
||||
OSSL_ENCODER_CTX *ectx = OSSL_ENCODER_CTX_new_for_pkey(pkey,
|
||||
OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
|
||||
outformat == FORMAT_ASN1
|
||||
? "DER"
|
||||
: "PEM",
|
||||
NULL, NULL);
|
||||
OSSL_ENCODER_CTX *ectx =
|
||||
OSSL_ENCODER_CTX_new_for_pkey(pkey,
|
||||
OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
|
||||
outformat == FORMAT_ASN1
|
||||
? "DER" : "PEM",
|
||||
NULL, NULL);
|
||||
|
||||
if (ectx == NULL || !OSSL_ENCODER_to_bio(ectx, out)) {
|
||||
OSSL_ENCODER_CTX_free(ectx);
|
||||
BIO_puts(bio_err, "Error, unable to write DH parameters\n");
|
||||
BIO_printf(bio_err, "Error, unable to write DH parameters\n");
|
||||
goto end;
|
||||
}
|
||||
OSSL_ENCODER_CTX_free(ectx);
|
||||
}
|
||||
ret = 0;
|
||||
end:
|
||||
end:
|
||||
if (ret != 0)
|
||||
ERR_print_errors(bio_err);
|
||||
BIO_free(in);
|
||||
|
|
@ -368,6 +362,7 @@ end:
|
|||
EVP_PKEY_free(pkey);
|
||||
EVP_PKEY_free(tmppkey);
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
release_engine(e);
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
|
@ -385,33 +380,33 @@ static EVP_PKEY *dsa_to_dh(EVP_PKEY *dh)
|
|||
EVP_PKEY *pkey = NULL;
|
||||
|
||||
if (!EVP_PKEY_get_bn_param(dh, OSSL_PKEY_PARAM_FFC_P, &bn_p)
|
||||
|| !EVP_PKEY_get_bn_param(dh, OSSL_PKEY_PARAM_FFC_Q, &bn_q)
|
||||
|| !EVP_PKEY_get_bn_param(dh, OSSL_PKEY_PARAM_FFC_G, &bn_g)) {
|
||||
BIO_puts(bio_err, "Error, failed to set DH parameters\n");
|
||||
|| !EVP_PKEY_get_bn_param(dh, OSSL_PKEY_PARAM_FFC_Q, &bn_q)
|
||||
|| !EVP_PKEY_get_bn_param(dh, OSSL_PKEY_PARAM_FFC_G, &bn_g)) {
|
||||
BIO_printf(bio_err, "Error, failed to set DH parameters\n");
|
||||
goto err;
|
||||
}
|
||||
|
||||
if ((tmpl = OSSL_PARAM_BLD_new()) == NULL
|
||||
|| !OSSL_PARAM_BLD_push_BN(tmpl, OSSL_PKEY_PARAM_FFC_P,
|
||||
bn_p)
|
||||
|| !OSSL_PARAM_BLD_push_BN(tmpl, OSSL_PKEY_PARAM_FFC_Q,
|
||||
bn_q)
|
||||
|| !OSSL_PARAM_BLD_push_BN(tmpl, OSSL_PKEY_PARAM_FFC_G,
|
||||
bn_g)
|
||||
|| (params = OSSL_PARAM_BLD_to_param(tmpl)) == NULL) {
|
||||
BIO_puts(bio_err, "Error, failed to set DH parameters\n");
|
||||
|| !OSSL_PARAM_BLD_push_BN(tmpl, OSSL_PKEY_PARAM_FFC_P,
|
||||
bn_p)
|
||||
|| !OSSL_PARAM_BLD_push_BN(tmpl, OSSL_PKEY_PARAM_FFC_Q,
|
||||
bn_q)
|
||||
|| !OSSL_PARAM_BLD_push_BN(tmpl, OSSL_PKEY_PARAM_FFC_G,
|
||||
bn_g)
|
||||
|| (params = OSSL_PARAM_BLD_to_param(tmpl)) == NULL) {
|
||||
BIO_printf(bio_err, "Error, failed to set DH parameters\n");
|
||||
goto err;
|
||||
}
|
||||
|
||||
ctx = EVP_PKEY_CTX_new_from_name(app_get0_libctx(), "DHX", app_get0_propq());
|
||||
if (ctx == NULL
|
||||
|| EVP_PKEY_fromdata_init(ctx) <= 0
|
||||
|| EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_KEY_PARAMETERS, params) <= 0) {
|
||||
BIO_puts(bio_err, "Error, failed to set DH parameters\n");
|
||||
|| EVP_PKEY_fromdata_init(ctx) <= 0
|
||||
|| EVP_PKEY_fromdata(ctx, &pkey, EVP_PKEY_KEY_PARAMETERS, params) <= 0) {
|
||||
BIO_printf(bio_err, "Error, failed to set DH parameters\n");
|
||||
goto err;
|
||||
}
|
||||
|
||||
err:
|
||||
err:
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
OSSL_PARAM_free(params);
|
||||
OSSL_PARAM_BLD_free(tmpl);
|
||||
|
|
@ -420,3 +415,4 @@ err:
|
|||
BN_free(bn_g);
|
||||
return pkey;
|
||||
}
|
||||
|
||||
|
|
|
|||
111
apps/dsa.c
111
apps/dsa.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -27,64 +27,57 @@
|
|||
#include <openssl/core_dispatch.h>
|
||||
|
||||
#ifndef OPENSSL_NO_RC4
|
||||
#define DEFAULT_PVK_ENCR_STRENGTH 2
|
||||
# define DEFAULT_PVK_ENCR_STRENGTH 2
|
||||
#else
|
||||
#define DEFAULT_PVK_ENCR_STRENGTH 0
|
||||
# define DEFAULT_PVK_ENCR_STRENGTH 0
|
||||
#endif
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_INFORM,
|
||||
OPT_OUTFORM,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_INFORM, OPT_OUTFORM, OPT_IN, OPT_OUT, OPT_ENGINE,
|
||||
/* Do not change the order here; see case statements below */
|
||||
OPT_PVK_NONE,
|
||||
OPT_PVK_WEAK,
|
||||
OPT_PVK_STRONG,
|
||||
OPT_NOOUT,
|
||||
OPT_TEXT,
|
||||
OPT_MODULUS,
|
||||
OPT_PUBIN,
|
||||
OPT_PUBOUT,
|
||||
OPT_CIPHER,
|
||||
OPT_PASSIN,
|
||||
OPT_PASSOUT,
|
||||
OPT_PVK_NONE, OPT_PVK_WEAK, OPT_PVK_STRONG,
|
||||
OPT_NOOUT, OPT_TEXT, OPT_MODULUS, OPT_PUBIN,
|
||||
OPT_PUBOUT, OPT_CIPHER, OPT_PASSIN, OPT_PASSOUT,
|
||||
OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS dsa_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "", OPT_CIPHER, '-', "Any supported cipher" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"", OPT_CIPHER, '-', "Any supported cipher"},
|
||||
#ifndef OPENSSL_NO_RC4
|
||||
{ "pvk-strong", OPT_PVK_STRONG, '-', "Enable 'Strong' PVK encoding level (default)" },
|
||||
{ "pvk-weak", OPT_PVK_WEAK, '-', "Enable 'Weak' PVK encoding level" },
|
||||
{ "pvk-none", OPT_PVK_NONE, '-', "Don't enforce PVK encoding" },
|
||||
{"pvk-strong", OPT_PVK_STRONG, '-', "Enable 'Strong' PVK encoding level (default)"},
|
||||
{"pvk-weak", OPT_PVK_WEAK, '-', "Enable 'Weak' PVK encoding level"},
|
||||
{"pvk-none", OPT_PVK_NONE, '-', "Don't enforce PVK encoding"},
|
||||
#endif
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine e, possibly a hardware device"},
|
||||
#endif
|
||||
|
||||
OPT_SECTION("Input"),
|
||||
{ "in", OPT_IN, 's', "Input key" },
|
||||
{ "inform", OPT_INFORM, 'f', "Input format (DER/PEM/PVK); has no effect" },
|
||||
{ "pubin", OPT_PUBIN, '-', "Expect a public key in input file" },
|
||||
{ "passin", OPT_PASSIN, 's', "Input file pass phrase source" },
|
||||
{"in", OPT_IN, 's', "Input key"},
|
||||
{"inform", OPT_INFORM, 'f', "Input format (DER/PEM/PVK); has no effect"},
|
||||
{"pubin", OPT_PUBIN, '-', "Expect a public key in input file"},
|
||||
{"passin", OPT_PASSIN, 's', "Input file pass phrase source"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output file" },
|
||||
{ "outform", OPT_OUTFORM, 'f', "Output format, DER PEM PVK" },
|
||||
{ "noout", OPT_NOOUT, '-', "Don't print key out" },
|
||||
{ "text", OPT_TEXT, '-', "Print the key in text" },
|
||||
{ "modulus", OPT_MODULUS, '-', "Print the DSA public value" },
|
||||
{ "pubout", OPT_PUBOUT, '-', "Output public key, not private" },
|
||||
{ "passout", OPT_PASSOUT, 's', "Output file pass phrase source" },
|
||||
{"out", OPT_OUT, '>', "Output file"},
|
||||
{"outform", OPT_OUTFORM, 'f', "Output format, DER PEM PVK"},
|
||||
{"noout", OPT_NOOUT, '-', "Don't print key out"},
|
||||
{"text", OPT_TEXT, '-', "Print the key in text"},
|
||||
{"modulus", OPT_MODULUS, '-', "Print the DSA public value"},
|
||||
{"pubout", OPT_PUBOUT, '-', "Output public key, not private"},
|
||||
{"passout", OPT_PASSOUT, 's', "Output file pass phrase source"},
|
||||
|
||||
OPT_PROV_OPTIONS,
|
||||
{ NULL }
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int dsa_main(int argc, char **argv)
|
||||
{
|
||||
BIO *out = NULL;
|
||||
ENGINE *e = NULL;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
EVP_CIPHER *enc = NULL;
|
||||
char *infile = NULL, *outfile = NULL, *prog;
|
||||
|
|
@ -105,7 +98,7 @@ int dsa_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
ret = 0;
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
|
|
@ -127,15 +120,18 @@ int dsa_main(int argc, char **argv)
|
|||
case OPT_OUT:
|
||||
outfile = opt_arg();
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_PASSIN:
|
||||
passinarg = opt_arg();
|
||||
break;
|
||||
case OPT_PASSOUT:
|
||||
passoutarg = opt_arg();
|
||||
break;
|
||||
case OPT_PVK_STRONG: /* pvk_encr:= 2 */
|
||||
case OPT_PVK_WEAK: /* pvk_encr:= 1 */
|
||||
case OPT_PVK_NONE: /* pvk_encr:= 0 */
|
||||
case OPT_PVK_STRONG: /* pvk_encr:= 2 */
|
||||
case OPT_PVK_WEAK: /* pvk_encr:= 1 */
|
||||
case OPT_PVK_NONE: /* pvk_encr:= 0 */
|
||||
#ifndef OPENSSL_NO_RC4
|
||||
pvk_encr = (o - OPT_PVK_NONE);
|
||||
#endif
|
||||
|
|
@ -174,23 +170,23 @@ int dsa_main(int argc, char **argv)
|
|||
private = !pubin && (!pubout || text);
|
||||
|
||||
if (!app_passwd(passinarg, passoutarg, &passin, &passout)) {
|
||||
BIO_puts(bio_err, "Error getting passwords\n");
|
||||
BIO_printf(bio_err, "Error getting passwords\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
BIO_puts(bio_err, "read DSA key\n");
|
||||
BIO_printf(bio_err, "read DSA key\n");
|
||||
if (pubin)
|
||||
pkey = load_pubkey(infile, informat, 1, passin, "public key");
|
||||
pkey = load_pubkey(infile, informat, 1, passin, e, "public key");
|
||||
else
|
||||
pkey = load_key(infile, informat, 1, passin, "private key");
|
||||
pkey = load_key(infile, informat, 1, passin, e, "private key");
|
||||
|
||||
if (pkey == NULL) {
|
||||
BIO_puts(bio_err, "unable to load Key\n");
|
||||
BIO_printf(bio_err, "unable to load Key\n");
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
if (!EVP_PKEY_is_a(pkey, "DSA")) {
|
||||
BIO_puts(bio_err, "Not a DSA key\n");
|
||||
BIO_printf(bio_err, "Not a DSA key\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -215,9 +211,9 @@ int dsa_main(int argc, char **argv)
|
|||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
BIO_puts(out, "Public Key=");
|
||||
BIO_printf(out, "Public Key=");
|
||||
BN_print(out, pub_key);
|
||||
BIO_puts(out, "\n");
|
||||
BIO_printf(out, "\n");
|
||||
BN_free(pub_key);
|
||||
}
|
||||
|
||||
|
|
@ -225,7 +221,7 @@ int dsa_main(int argc, char **argv)
|
|||
ret = 0;
|
||||
goto end;
|
||||
}
|
||||
BIO_puts(bio_err, "writing DSA key\n");
|
||||
BIO_printf(bio_err, "writing DSA key\n");
|
||||
if (outformat == FORMAT_ASN1) {
|
||||
output_type = "DER";
|
||||
} else if (outformat == FORMAT_PEM) {
|
||||
|
|
@ -234,12 +230,12 @@ int dsa_main(int argc, char **argv)
|
|||
output_type = "MSBLOB";
|
||||
} else if (outformat == FORMAT_PVK) {
|
||||
if (pubin) {
|
||||
BIO_puts(bio_err, "PVK form impossible with public key input\n");
|
||||
BIO_printf(bio_err, "PVK form impossible with public key input\n");
|
||||
goto end;
|
||||
}
|
||||
output_type = "PVK";
|
||||
} else {
|
||||
BIO_puts(bio_err, "bad output format specified for outfile\n");
|
||||
BIO_printf(bio_err, "bad output format specified for outfile\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -256,12 +252,12 @@ int dsa_main(int argc, char **argv)
|
|||
} else {
|
||||
assert(private);
|
||||
selection = (OSSL_KEYMGMT_SELECT_KEYPAIR
|
||||
| OSSL_KEYMGMT_SELECT_ALL_PARAMETERS);
|
||||
| OSSL_KEYMGMT_SELECT_ALL_PARAMETERS);
|
||||
}
|
||||
|
||||
/* Perform the encoding */
|
||||
ectx = OSSL_ENCODER_CTX_new_for_pkey(pkey, selection, output_type,
|
||||
output_structure, NULL);
|
||||
output_structure, NULL);
|
||||
if (OSSL_ENCODER_CTX_get_num_encoders(ectx) == 0) {
|
||||
BIO_printf(bio_err, "%s format not supported\n", output_type);
|
||||
goto end;
|
||||
|
|
@ -277,8 +273,8 @@ int dsa_main(int argc, char **argv)
|
|||
if (passout != NULL)
|
||||
/* When passout given, override the passphrase prompter */
|
||||
OSSL_ENCODER_CTX_set_passphrase(ectx,
|
||||
(const unsigned char *)passout,
|
||||
strlen(passout));
|
||||
(const unsigned char *)passout,
|
||||
strlen(passout));
|
||||
}
|
||||
|
||||
/* PVK requires a bit more */
|
||||
|
|
@ -287,23 +283,24 @@ int dsa_main(int argc, char **argv)
|
|||
|
||||
params[0] = OSSL_PARAM_construct_int("encrypt-level", &pvk_encr);
|
||||
if (!OSSL_ENCODER_CTX_set_params(ectx, params)) {
|
||||
BIO_puts(bio_err, "invalid PVK encryption level\n");
|
||||
BIO_printf(bio_err, "invalid PVK encryption level\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
||||
if (!OSSL_ENCODER_to_bio(ectx, out)) {
|
||||
BIO_puts(bio_err, "unable to write key\n");
|
||||
BIO_printf(bio_err, "unable to write key\n");
|
||||
goto end;
|
||||
}
|
||||
ret = 0;
|
||||
end:
|
||||
end:
|
||||
if (ret != 0)
|
||||
ERR_print_errors(bio_err);
|
||||
OSSL_ENCODER_CTX_free(ectx);
|
||||
BIO_free_all(out);
|
||||
EVP_PKEY_free(pkey);
|
||||
EVP_CIPHER_free(enc);
|
||||
release_engine(e);
|
||||
OPENSSL_free(passin);
|
||||
OPENSSL_free(passout);
|
||||
return ret;
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -26,49 +26,45 @@ static int verbose = 0;
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_INFORM,
|
||||
OPT_OUTFORM,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_TEXT,
|
||||
OPT_NOOUT,
|
||||
OPT_GENKEY,
|
||||
OPT_VERBOSE,
|
||||
OPT_QUIET,
|
||||
OPT_R_ENUM,
|
||||
OPT_PROV_ENUM
|
||||
OPT_INFORM, OPT_OUTFORM, OPT_IN, OPT_OUT, OPT_TEXT,
|
||||
OPT_NOOUT, OPT_GENKEY, OPT_ENGINE, OPT_VERBOSE, OPT_QUIET,
|
||||
OPT_R_ENUM, OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS dsaparam_options[] = {
|
||||
{ OPT_HELP_STR, 1, '-', "Usage: %s [options] [numbits] [numqbits]\n" },
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] [numbits] [numqbits]\n"},
|
||||
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine e, possibly a hardware device"},
|
||||
#endif
|
||||
|
||||
OPT_SECTION("Input"),
|
||||
{ "in", OPT_IN, '<', "Input file" },
|
||||
{ "inform", OPT_INFORM, 'F', "Input format - DER or PEM" },
|
||||
{"in", OPT_IN, '<', "Input file"},
|
||||
{"inform", OPT_INFORM, 'F', "Input format - DER or PEM"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output file" },
|
||||
{ "outform", OPT_OUTFORM, 'F', "Output format - DER or PEM" },
|
||||
{ "text", OPT_TEXT, '-', "Print as text" },
|
||||
{ "noout", OPT_NOOUT, '-', "No output" },
|
||||
{ "verbose", OPT_VERBOSE, '-', "Verbose output" },
|
||||
{ "quiet", OPT_QUIET, '-', "Terse output" },
|
||||
{ "genkey", OPT_GENKEY, '-', "Generate a DSA key" },
|
||||
{"out", OPT_OUT, '>', "Output file"},
|
||||
{"outform", OPT_OUTFORM, 'F', "Output format - DER or PEM"},
|
||||
{"text", OPT_TEXT, '-', "Print as text"},
|
||||
{"noout", OPT_NOOUT, '-', "No output"},
|
||||
{"verbose", OPT_VERBOSE, '-', "Verbose output"},
|
||||
{"quiet", OPT_QUIET, '-', "Terse output"},
|
||||
{"genkey", OPT_GENKEY, '-', "Generate a DSA key"},
|
||||
|
||||
OPT_R_OPTIONS,
|
||||
OPT_PROV_OPTIONS,
|
||||
|
||||
OPT_PARAMETERS(),
|
||||
{ "numbits", 0, 0, "Number of bits if generating parameters or key (optional)" },
|
||||
{ "numqbits", 0, 0, "Number of bits in the subprime parameter q if generating parameters or key (optional)" },
|
||||
{ NULL }
|
||||
{"numbits", 0, 0, "Number of bits if generating parameters or key (optional)"},
|
||||
{"numqbits", 0, 0, "Number of bits in the subprime parameter q if generating parameters or key (optional)"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int dsaparam_main(int argc, char **argv)
|
||||
{
|
||||
ENGINE *e = NULL;
|
||||
BIO *out = NULL;
|
||||
EVP_PKEY *params = NULL, *pkey = NULL;
|
||||
EVP_PKEY_CTX *ctx = NULL;
|
||||
|
|
@ -83,7 +79,7 @@ int dsaparam_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -104,6 +100,9 @@ int dsaparam_main(int argc, char **argv)
|
|||
case OPT_OUT:
|
||||
outfile = opt_arg();
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_TEXT:
|
||||
text = 1;
|
||||
break;
|
||||
|
|
@ -153,38 +152,38 @@ int dsaparam_main(int argc, char **argv)
|
|||
|
||||
ctx = EVP_PKEY_CTX_new_from_name(app_get0_libctx(), "DSA", app_get0_propq());
|
||||
if (ctx == NULL) {
|
||||
BIO_puts(bio_err,
|
||||
"Error, DSA parameter generation context allocation failed\n");
|
||||
BIO_printf(bio_err,
|
||||
"Error, DSA parameter generation context allocation failed\n");
|
||||
goto end;
|
||||
}
|
||||
if (numbits > 0) {
|
||||
if (numbits > OPENSSL_DSA_MAX_MODULUS_BITS)
|
||||
BIO_printf(bio_err,
|
||||
"Warning: It is not recommended to use more than %d bit for DSA keys.\n"
|
||||
" Your key size is %d! Larger key size may behave not as expected.\n",
|
||||
OPENSSL_DSA_MAX_MODULUS_BITS, numbits);
|
||||
"Warning: It is not recommended to use more than %d bit for DSA keys.\n"
|
||||
" Your key size is %d! Larger key size may behave not as expected.\n",
|
||||
OPENSSL_DSA_MAX_MODULUS_BITS, numbits);
|
||||
|
||||
EVP_PKEY_CTX_set_app_data(ctx, bio_err);
|
||||
if (verbose) {
|
||||
EVP_PKEY_CTX_set_cb(ctx, progress_cb);
|
||||
BIO_printf(bio_err, "Generating DSA parameters, %d bit long prime\n"
|
||||
"This could take some time\n",
|
||||
num);
|
||||
BIO_printf(bio_err, "Generating DSA parameters, %d bit long prime\n",
|
||||
num);
|
||||
BIO_printf(bio_err, "This could take some time\n");
|
||||
}
|
||||
if (EVP_PKEY_paramgen_init(ctx) <= 0) {
|
||||
BIO_puts(bio_err,
|
||||
"Error, DSA key generation paramgen init failed\n");
|
||||
BIO_printf(bio_err,
|
||||
"Error, DSA key generation paramgen init failed\n");
|
||||
goto end;
|
||||
}
|
||||
if (EVP_PKEY_CTX_set_dsa_paramgen_bits(ctx, num) <= 0) {
|
||||
BIO_puts(bio_err,
|
||||
"Error, DSA key generation setting bit length failed\n");
|
||||
BIO_printf(bio_err,
|
||||
"Error, DSA key generation setting bit length failed\n");
|
||||
goto end;
|
||||
}
|
||||
if (numqbits > 0) {
|
||||
if (EVP_PKEY_CTX_set_dsa_paramgen_q_bits(ctx, numqbits) <= 0) {
|
||||
BIO_puts(bio_err,
|
||||
"Error, DSA key generation setting subprime bit length failed\n");
|
||||
BIO_printf(bio_err,
|
||||
"Error, DSA key generation setting subprime bit length failed\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -214,22 +213,22 @@ int dsaparam_main(int argc, char **argv)
|
|||
else
|
||||
i = PEM_write_bio_Parameters(out, params);
|
||||
if (!i) {
|
||||
BIO_puts(bio_err, "Error, unable to write DSA parameters\n");
|
||||
BIO_printf(bio_err, "Error, unable to write DSA parameters\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
if (genkey) {
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
ctx = EVP_PKEY_CTX_new_from_pkey(app_get0_libctx(), params,
|
||||
app_get0_propq());
|
||||
app_get0_propq());
|
||||
if (ctx == NULL) {
|
||||
BIO_printf(bio_err,
|
||||
"Error, DSA key generation context allocation failed\n");
|
||||
"Error, DSA key generation context allocation failed\n");
|
||||
goto end;
|
||||
}
|
||||
if (EVP_PKEY_keygen_init(ctx) <= 0) {
|
||||
BIO_puts(bio_err,
|
||||
"Error, unable to initialise for key generation\n");
|
||||
BIO_printf(bio_err,
|
||||
"Error, unable to initialise for key generation\n");
|
||||
goto end;
|
||||
}
|
||||
pkey = app_keygen(ctx, "DSA", numbits, verbose);
|
||||
|
|
@ -240,19 +239,15 @@ int dsaparam_main(int argc, char **argv)
|
|||
i = i2d_PrivateKey_bio(out, pkey);
|
||||
else
|
||||
i = PEM_write_bio_PrivateKey(out, pkey, NULL, NULL, 0, NULL, NULL);
|
||||
if (i <= 0) {
|
||||
BIO_printf(bio_err,
|
||||
"Error, unable to write DSA private key\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
ret = 0;
|
||||
end:
|
||||
end:
|
||||
if (ret != 0)
|
||||
ERR_print_errors(bio_err);
|
||||
BIO_free_all(out);
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
EVP_PKEY_free(pkey);
|
||||
EVP_PKEY_free(params);
|
||||
release_engine(e);
|
||||
return ret;
|
||||
}
|
||||
|
|
|
|||
114
apps/ec.c
114
apps/ec.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 2002-2023 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -23,52 +23,42 @@
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_INFORM,
|
||||
OPT_OUTFORM,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_NOOUT,
|
||||
OPT_TEXT,
|
||||
OPT_PARAM_OUT,
|
||||
OPT_PUBIN,
|
||||
OPT_PUBOUT,
|
||||
OPT_PASSIN,
|
||||
OPT_PASSOUT,
|
||||
OPT_PARAM_ENC,
|
||||
OPT_CONV_FORM,
|
||||
OPT_CIPHER,
|
||||
OPT_NO_PUBLIC,
|
||||
OPT_CHECK,
|
||||
OPT_PROV_ENUM
|
||||
OPT_INFORM, OPT_OUTFORM, OPT_ENGINE, OPT_IN, OPT_OUT,
|
||||
OPT_NOOUT, OPT_TEXT, OPT_PARAM_OUT, OPT_PUBIN, OPT_PUBOUT,
|
||||
OPT_PASSIN, OPT_PASSOUT, OPT_PARAM_ENC, OPT_CONV_FORM, OPT_CIPHER,
|
||||
OPT_NO_PUBLIC, OPT_CHECK, OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS ec_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine, possibly a hardware device"},
|
||||
#endif
|
||||
|
||||
OPT_SECTION("Input"),
|
||||
{ "in", OPT_IN, 's', "Input file" },
|
||||
{ "inform", OPT_INFORM, 'f', "Input format (DER/PEM/P12)" },
|
||||
{ "pubin", OPT_PUBIN, '-', "Expect a public key in input file" },
|
||||
{ "passin", OPT_PASSIN, 's', "Input file pass phrase source" },
|
||||
{ "check", OPT_CHECK, '-', "check key consistency" },
|
||||
{ "", OPT_CIPHER, '-', "Any supported cipher" },
|
||||
{ "param_enc", OPT_PARAM_ENC, 's',
|
||||
"Selects between named_curve and explicit EC parameter encoding" },
|
||||
{ "conv_form", OPT_CONV_FORM, 's', "Specifies the point conversion form " },
|
||||
{"in", OPT_IN, 's', "Input file"},
|
||||
{"inform", OPT_INFORM, 'f', "Input format (DER/PEM/P12/ENGINE)"},
|
||||
{"pubin", OPT_PUBIN, '-', "Expect a public key in input file"},
|
||||
{"passin", OPT_PASSIN, 's', "Input file pass phrase source"},
|
||||
{"check", OPT_CHECK, '-', "check key consistency"},
|
||||
{"", OPT_CIPHER, '-', "Any supported cipher"},
|
||||
{"param_enc", OPT_PARAM_ENC, 's',
|
||||
"Specifies the way the ec parameters are encoded"},
|
||||
{"conv_form", OPT_CONV_FORM, 's', "Specifies the point conversion form "},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output file" },
|
||||
{ "outform", OPT_OUTFORM, 'F', "Output format - DER or PEM" },
|
||||
{ "noout", OPT_NOOUT, '-', "Don't print key out" },
|
||||
{ "text", OPT_TEXT, '-', "Print the key" },
|
||||
{ "param_out", OPT_PARAM_OUT, '-', "Print the elliptic curve parameters" },
|
||||
{ "pubout", OPT_PUBOUT, '-', "Output public key, not private" },
|
||||
{ "no_public", OPT_NO_PUBLIC, '-', "exclude public key from private key" },
|
||||
{ "passout", OPT_PASSOUT, 's', "Output file pass phrase source" },
|
||||
{"out", OPT_OUT, '>', "Output file"},
|
||||
{"outform", OPT_OUTFORM, 'F', "Output format - DER or PEM"},
|
||||
{"noout", OPT_NOOUT, '-', "Don't print key out"},
|
||||
{"text", OPT_TEXT, '-', "Print the key"},
|
||||
{"param_out", OPT_PARAM_OUT, '-', "Print the elliptic curve parameters"},
|
||||
{"pubout", OPT_PUBOUT, '-', "Output public key, not private"},
|
||||
{"no_public", OPT_NO_PUBLIC, '-', "exclude public key from private key"},
|
||||
{"passout", OPT_PASSOUT, 's', "Output file pass phrase source"},
|
||||
|
||||
OPT_PROV_OPTIONS,
|
||||
{ NULL }
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int ec_main(int argc, char **argv)
|
||||
|
|
@ -78,6 +68,7 @@ int ec_main(int argc, char **argv)
|
|||
EVP_PKEY_CTX *pctx = NULL;
|
||||
EVP_PKEY *eckey = NULL;
|
||||
BIO *out = NULL;
|
||||
ENGINE *e = NULL;
|
||||
EVP_CIPHER *enc = NULL;
|
||||
char *infile = NULL, *outfile = NULL, *ciphername = NULL, *prog;
|
||||
char *passin = NULL, *passout = NULL, *passinarg = NULL, *passoutarg = NULL;
|
||||
|
|
@ -95,7 +86,7 @@ int ec_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -137,6 +128,9 @@ int ec_main(int argc, char **argv)
|
|||
case OPT_PASSOUT:
|
||||
passoutarg = opt_arg();
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_CIPHER:
|
||||
ciphername = opt_unknown();
|
||||
break;
|
||||
|
|
@ -172,17 +166,19 @@ int ec_main(int argc, char **argv)
|
|||
private = !pubin && (text || (!param_out && !pubout));
|
||||
|
||||
if (!app_passwd(passinarg, passoutarg, &passin, &passout)) {
|
||||
BIO_puts(bio_err, "Error getting passwords\n");
|
||||
BIO_printf(bio_err, "Error getting passwords\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
BIO_printf(bio_err, "read EC key\n");
|
||||
|
||||
if (pubin)
|
||||
eckey = load_pubkey(infile, informat, 1, passin, "public key");
|
||||
eckey = load_pubkey(infile, informat, 1, passin, e, "public key");
|
||||
else
|
||||
eckey = load_key(infile, informat, 1, passin, "private key");
|
||||
eckey = load_key(infile, informat, 1, passin, e, "private key");
|
||||
|
||||
if (eckey == NULL) {
|
||||
BIO_puts(bio_err, "unable to load Key\n");
|
||||
BIO_printf(bio_err, "unable to load Key\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -192,27 +188,27 @@ int ec_main(int argc, char **argv)
|
|||
|
||||
if (point_format
|
||||
&& !EVP_PKEY_set_utf8_string_param(
|
||||
eckey, OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT,
|
||||
point_format)) {
|
||||
BIO_puts(bio_err, "unable to set point conversion format\n");
|
||||
eckey, OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT,
|
||||
point_format)) {
|
||||
BIO_printf(bio_err, "unable to set point conversion format\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (asn1_encoding != NULL
|
||||
&& !EVP_PKEY_set_utf8_string_param(
|
||||
eckey, OSSL_PKEY_PARAM_EC_ENCODING, asn1_encoding)) {
|
||||
BIO_puts(bio_err, "unable to set asn1 encoding format\n");
|
||||
eckey, OSSL_PKEY_PARAM_EC_ENCODING, asn1_encoding)) {
|
||||
BIO_printf(bio_err, "unable to set asn1 encoding format\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (no_public) {
|
||||
if (!EVP_PKEY_set_int_param(eckey, OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC, 0)) {
|
||||
BIO_puts(bio_err, "unable to disable public key encoding\n");
|
||||
BIO_printf(bio_err, "unable to disable public key encoding\n");
|
||||
goto end;
|
||||
}
|
||||
} else {
|
||||
if (!EVP_PKEY_set_int_param(eckey, OSSL_PKEY_PARAM_EC_INCLUDE_PUBLIC, 1)) {
|
||||
BIO_puts(bio_err, "unable to enable public key encoding\n");
|
||||
BIO_printf(bio_err, "unable to enable public key encoding\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -221,7 +217,7 @@ int ec_main(int argc, char **argv)
|
|||
assert(pubin || private);
|
||||
if ((pubin && EVP_PKEY_print_public(out, eckey, 0, NULL) <= 0)
|
||||
|| (!pubin && EVP_PKEY_print_private(out, eckey, 0, NULL) <= 0)) {
|
||||
BIO_puts(bio_err, "unable to print EC key\n");
|
||||
BIO_printf(bio_err, "unable to print EC key\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -229,13 +225,13 @@ int ec_main(int argc, char **argv)
|
|||
if (check) {
|
||||
pctx = EVP_PKEY_CTX_new_from_pkey(NULL, eckey, NULL);
|
||||
if (pctx == NULL) {
|
||||
BIO_puts(bio_err, "unable to check EC key\n");
|
||||
BIO_printf(bio_err, "unable to check EC key\n");
|
||||
goto end;
|
||||
}
|
||||
if (EVP_PKEY_check(pctx) <= 0)
|
||||
BIO_puts(bio_err, "EC Key Invalid!\n");
|
||||
BIO_printf(bio_err, "EC Key Invalid!\n");
|
||||
else
|
||||
BIO_puts(bio_err, "EC Key valid.\n");
|
||||
BIO_printf(bio_err, "EC Key valid.\n");
|
||||
ERR_print_errors(bio_err);
|
||||
}
|
||||
|
||||
|
|
@ -244,6 +240,7 @@ int ec_main(int argc, char **argv)
|
|||
const char *output_type = outformat == FORMAT_ASN1 ? "DER" : "PEM";
|
||||
const char *output_structure = "type-specific";
|
||||
|
||||
BIO_printf(bio_err, "writing EC key\n");
|
||||
if (param_out) {
|
||||
selection = OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS;
|
||||
} else if (pubin || pubout) {
|
||||
|
|
@ -256,8 +253,8 @@ int ec_main(int argc, char **argv)
|
|||
}
|
||||
|
||||
ectx = OSSL_ENCODER_CTX_new_for_pkey(eckey, selection,
|
||||
output_type, output_structure,
|
||||
NULL);
|
||||
output_type, output_structure,
|
||||
NULL);
|
||||
if (enc != NULL) {
|
||||
OSSL_ENCODER_CTX_set_cipher(ectx, EVP_CIPHER_get0_name(enc), NULL);
|
||||
/* Default passphrase prompter */
|
||||
|
|
@ -265,11 +262,11 @@ int ec_main(int argc, char **argv)
|
|||
if (passout != NULL)
|
||||
/* When passout given, override the passphrase prompter */
|
||||
OSSL_ENCODER_CTX_set_passphrase(ectx,
|
||||
(const unsigned char *)passout,
|
||||
strlen(passout));
|
||||
(const unsigned char *)passout,
|
||||
strlen(passout));
|
||||
}
|
||||
if (!OSSL_ENCODER_to_bio(ectx, out)) {
|
||||
BIO_puts(bio_err, "unable to write EC key\n");
|
||||
BIO_printf(bio_err, "unable to write EC key\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -284,6 +281,7 @@ end:
|
|||
OSSL_ENCODER_CTX_free(ectx);
|
||||
OSSL_DECODER_CTX_free(dctx);
|
||||
EVP_PKEY_CTX_free(pctx);
|
||||
release_engine(e);
|
||||
if (passin != NULL)
|
||||
OPENSSL_clear_free(passin, strlen(passin));
|
||||
if (passout != NULL)
|
||||
|
|
|
|||
283
apps/ech.c
283
apps/ech.c
|
|
@ -1,283 +0,0 @@
|
|||
/*
|
||||
* Copyright 2024-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include "apps.h"
|
||||
#include "progs.h"
|
||||
#include <openssl/ssl.h>
|
||||
#include <openssl/bio.h>
|
||||
#include <openssl/evp.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/bn.h>
|
||||
#include <openssl/pem.h>
|
||||
#include <openssl/rand.h>
|
||||
#include <openssl/hpke.h>
|
||||
|
||||
#include <openssl/objects.h>
|
||||
#include <openssl/x509.h>
|
||||
|
||||
#ifndef OPENSSL_NO_ECH
|
||||
|
||||
#define OSSL_ECH_KEYGEN_MODE 0 /* default: generate a key pair/ECHConfig */
|
||||
#define OSSL_ECH_SELPRINT_MODE 1 /* we can print/down-select ECHConfigList */
|
||||
#define OSSL_ECH_MAXINFILES 5 /* we'll only take this many inputs */
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
/* standard openssl options */
|
||||
OPT_ERR = -1,
|
||||
OPT_EOF = 0,
|
||||
OPT_HELP,
|
||||
OPT_VERBOSE,
|
||||
OPT_TEXT,
|
||||
OPT_OUT,
|
||||
OPT_IN,
|
||||
/* ECHConfig specifics */
|
||||
OPT_PUBLICNAME,
|
||||
OPT_ECHVERSION,
|
||||
OPT_MAXNAMELENGTH,
|
||||
OPT_HPKESUITE,
|
||||
OPT_SELECT
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS ech_options[] = {
|
||||
OPT_SECTION("General options"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "verbose", OPT_VERBOSE, '-', "Provide additional output" },
|
||||
{ "text", OPT_TEXT, '-', "Provide human-readable output" },
|
||||
OPT_SECTION("Key generation"),
|
||||
{ "out", OPT_OUT, '>',
|
||||
"Private key and/or ECHConfig [default: echconfig.pem]" },
|
||||
{ "public_name", OPT_PUBLICNAME, 's', "public_name value" },
|
||||
{ "max_name_len", OPT_MAXNAMELENGTH, 'n',
|
||||
"Maximum host name length value [default: 0]" },
|
||||
{ "suite", OPT_HPKESUITE, 's', "HPKE ciphersuite: e.g. \"0x20,1,3\"" },
|
||||
{ "ech_version", OPT_ECHVERSION, 'n',
|
||||
"ECHConfig version [default: 0xff0d (13)]" },
|
||||
OPT_SECTION("ECH PEM file downselect/display"),
|
||||
{ "in", OPT_IN, '<', "An ECH PEM file" },
|
||||
{ "select", OPT_SELECT, 'n', "Downselect to the numbered ECH config" },
|
||||
{ NULL }
|
||||
};
|
||||
|
||||
/**
|
||||
* @brief map version string like 0xff01 or 65291 to uint16_t
|
||||
* @param arg is the version string, from command line
|
||||
* @return is the uint16_t value (with zero for error cases)
|
||||
*/
|
||||
static uint16_t verstr2us(char *arg)
|
||||
{
|
||||
long lv = strtol(arg, NULL, 0);
|
||||
uint16_t rv = 0;
|
||||
|
||||
if (lv < 0xffff && lv > 0)
|
||||
rv = (uint16_t)lv;
|
||||
return rv;
|
||||
}
|
||||
|
||||
int ech_main(int argc, char **argv)
|
||||
{
|
||||
char *prog = NULL;
|
||||
OPTION_CHOICE o;
|
||||
int i, rv = 1, verbose = 0, text = 0, outsupp = 0;
|
||||
int select = OSSL_ECHSTORE_ALL, numinfiles = 0;
|
||||
char *outfile = NULL, *infile = NULL;
|
||||
char *infiles[OSSL_ECH_MAXINFILES] = { NULL };
|
||||
char *public_name = NULL, *suitestr = NULL;
|
||||
uint16_t ech_version = OSSL_ECH_CURRENT_VERSION;
|
||||
uint8_t max_name_length = 0;
|
||||
OSSL_HPKE_SUITE hpke_suite = OSSL_HPKE_SUITE_DEFAULT;
|
||||
int mode = OSSL_ECH_KEYGEN_MODE; /* key generation */
|
||||
OSSL_ECHSTORE *es = NULL;
|
||||
BIO *ecf = NULL;
|
||||
|
||||
prog = opt_init(argc, argv, ech_options);
|
||||
while ((o = opt_next()) != OPT_EOF) {
|
||||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
opt_help(ech_options);
|
||||
rv = 0;
|
||||
goto end;
|
||||
case OPT_VERBOSE:
|
||||
verbose = 1;
|
||||
break;
|
||||
case OPT_TEXT:
|
||||
text = 1;
|
||||
break;
|
||||
case OPT_SELECT:
|
||||
mode = OSSL_ECH_SELPRINT_MODE;
|
||||
select = strtol(opt_arg(), NULL, 10);
|
||||
break;
|
||||
case OPT_OUT:
|
||||
outfile = opt_arg();
|
||||
outsupp = 1;
|
||||
break;
|
||||
case OPT_IN:
|
||||
mode = OSSL_ECH_SELPRINT_MODE;
|
||||
infile = opt_arg();
|
||||
if (numinfiles >= OSSL_ECH_MAXINFILES) {
|
||||
BIO_printf(bio_err, "too many input files, only %d allowed\n",
|
||||
OSSL_ECH_MAXINFILES);
|
||||
goto opthelp;
|
||||
}
|
||||
infiles[numinfiles] = infile;
|
||||
numinfiles++;
|
||||
break;
|
||||
case OPT_PUBLICNAME:
|
||||
public_name = opt_arg();
|
||||
break;
|
||||
case OPT_ECHVERSION:
|
||||
ech_version = verstr2us(opt_arg());
|
||||
break;
|
||||
case OPT_MAXNAMELENGTH: {
|
||||
long tmp = strtol(opt_arg(), NULL, 10);
|
||||
|
||||
if (tmp < 0 || tmp > OSSL_ECH_MAX_MAXNAMELEN) {
|
||||
BIO_printf(bio_err,
|
||||
"max name length out of range [0,%d] (%ld)\n",
|
||||
OSSL_ECH_MAX_MAXNAMELEN, tmp);
|
||||
goto opthelp;
|
||||
} else {
|
||||
max_name_length = (uint8_t)tmp;
|
||||
}
|
||||
} break;
|
||||
case OPT_HPKESUITE:
|
||||
suitestr = opt_arg();
|
||||
break;
|
||||
}
|
||||
}
|
||||
argc = opt_num_rest();
|
||||
argv = opt_rest();
|
||||
if (argc != 0) {
|
||||
BIO_printf(bio_err, "%s: Unknown parameter %s\n", prog, argv[0]);
|
||||
goto opthelp;
|
||||
}
|
||||
/* Check ECH-specific inputs */
|
||||
switch (ech_version) {
|
||||
case OSSL_ECH_RFC9849_VERSION: /* fall through */
|
||||
case 13:
|
||||
ech_version = OSSL_ECH_RFC9849_VERSION;
|
||||
break;
|
||||
default:
|
||||
BIO_printf(bio_err, "Un-supported version (0x%04x)\n", ech_version);
|
||||
goto end;
|
||||
}
|
||||
if (suitestr != NULL) {
|
||||
if (OSSL_HPKE_str2suite(suitestr, &hpke_suite) != 1) {
|
||||
BIO_printf(bio_err, "Bad OSSL_HPKE_SUITE (%s)\n", suitestr);
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
/* Set default if needed */
|
||||
if (outfile == NULL)
|
||||
outfile = "echconfig.pem";
|
||||
es = OSSL_ECHSTORE_new(NULL, NULL);
|
||||
if (es == NULL)
|
||||
goto end;
|
||||
if (mode == OSSL_ECH_KEYGEN_MODE) {
|
||||
if (public_name == NULL) {
|
||||
BIO_printf(bio_err, "public_name required\n");
|
||||
goto end;
|
||||
}
|
||||
if (verbose)
|
||||
BIO_printf(bio_err, "Calling OSSL_ECHSTORE_new_config\n");
|
||||
if ((ecf = bio_open_owner(outfile, FORMAT_PEM, 1)) == NULL
|
||||
|| OSSL_ECHSTORE_new_config(es, ech_version, max_name_length,
|
||||
public_name, hpke_suite)
|
||||
!= 1
|
||||
|| OSSL_ECHSTORE_write_pem(es, 0, ecf) != 1) {
|
||||
BIO_printf(bio_err, "OSSL_ECHSTORE_new_config error\n");
|
||||
goto end;
|
||||
}
|
||||
if (verbose)
|
||||
BIO_printf(bio_err, "OSSL_ECHSTORE_new_config success\n");
|
||||
rv = 0;
|
||||
}
|
||||
if (mode == OSSL_ECH_SELPRINT_MODE) {
|
||||
if (numinfiles == 0)
|
||||
goto opthelp;
|
||||
for (i = 0; i != numinfiles; i++) {
|
||||
if ((ecf = BIO_new_file(infiles[i], "r")) == NULL
|
||||
|| OSSL_ECHSTORE_read_pem(es, ecf, OSSL_ECH_FOR_RETRY) != 1) {
|
||||
BIO_printf(bio_err, "OSSL_ECHSTORE_read_pem error: %s\n",
|
||||
infiles[i]);
|
||||
goto end;
|
||||
}
|
||||
BIO_free(ecf);
|
||||
ecf = NULL;
|
||||
}
|
||||
if (verbose)
|
||||
BIO_printf(bio_err, "Success reading %d files\n", numinfiles);
|
||||
if (outsupp == 1) {
|
||||
/* write result to that, with downselection if required */
|
||||
if (verbose)
|
||||
BIO_printf(bio_err, "Will write to %s\n", outfile);
|
||||
if (verbose && select != OSSL_ECHSTORE_ALL)
|
||||
BIO_printf(bio_err, "Selected entry: %d\n", select);
|
||||
if ((ecf = BIO_new_file(outfile, "w")) == NULL
|
||||
|| OSSL_ECHSTORE_write_pem(es, select, ecf) != 1) {
|
||||
BIO_printf(bio_err, "OSSL_ECHSTORE_write_pem error: %s\n",
|
||||
outfile);
|
||||
goto end;
|
||||
}
|
||||
if (verbose)
|
||||
BIO_printf(bio_err, "Success writing to %s\n", outfile);
|
||||
}
|
||||
rv = 0;
|
||||
}
|
||||
if (text) {
|
||||
int oi_ind, oi_cnt = 0;
|
||||
|
||||
if (OSSL_ECHSTORE_num_entries(es, &oi_cnt) != 1)
|
||||
goto end;
|
||||
if (verbose)
|
||||
BIO_printf(bio_err, "Printing %d ECHConfig values\n", oi_cnt);
|
||||
for (oi_ind = 0; oi_ind != oi_cnt; oi_ind++) {
|
||||
time_t secs = 0;
|
||||
char *pn = NULL, *ec = NULL;
|
||||
int has_priv, for_retry;
|
||||
|
||||
if (OSSL_ECHSTORE_get1_info(es, oi_ind, &secs, &pn, &ec,
|
||||
&has_priv, &for_retry)
|
||||
!= 1) {
|
||||
OPENSSL_free(pn); /* just in case */
|
||||
OPENSSL_free(ec);
|
||||
goto end;
|
||||
}
|
||||
BIO_printf(bio_err, "ECH entry: %d public_name: %s age: %lld%s%s\n",
|
||||
oi_ind, pn, (long long)secs,
|
||||
has_priv ? " (has private key)" : "",
|
||||
for_retry ? " (will be sent in retry-configs)" : "");
|
||||
BIO_printf(bio_err, "\t%s\n", ec);
|
||||
OPENSSL_free(pn);
|
||||
OPENSSL_free(ec);
|
||||
}
|
||||
if (verbose)
|
||||
BIO_printf(bio_err, "Success printing %d ECHConfigList\n", oi_cnt);
|
||||
rv = 0;
|
||||
}
|
||||
end:
|
||||
OSSL_ECHSTORE_free(es);
|
||||
BIO_free_all(ecf);
|
||||
return rv;
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
BIO_printf(bio_err, "\tup to %d -in instances allowed\n", OSSL_ECH_MAXINFILES);
|
||||
OSSL_ECHSTORE_free(es);
|
||||
BIO_free_all(ecf);
|
||||
return rv;
|
||||
}
|
||||
|
||||
#endif
|
||||
155
apps/ecparam.c
155
apps/ecparam.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 2002-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 2002-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright (c) 2002, Oracle and/or its affiliates. All rights reserved
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
|
|
@ -23,55 +23,46 @@
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_INFORM,
|
||||
OPT_OUTFORM,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_TEXT,
|
||||
OPT_CHECK,
|
||||
OPT_LIST_CURVES,
|
||||
OPT_NO_SEED,
|
||||
OPT_NOOUT,
|
||||
OPT_NAME,
|
||||
OPT_CONV_FORM,
|
||||
OPT_PARAM_ENC,
|
||||
OPT_GENKEY,
|
||||
OPT_CHECK_NAMED,
|
||||
OPT_R_ENUM,
|
||||
OPT_PROV_ENUM
|
||||
OPT_INFORM, OPT_OUTFORM, OPT_IN, OPT_OUT, OPT_TEXT,
|
||||
OPT_CHECK, OPT_LIST_CURVES, OPT_NO_SEED, OPT_NOOUT, OPT_NAME,
|
||||
OPT_CONV_FORM, OPT_PARAM_ENC, OPT_GENKEY, OPT_ENGINE, OPT_CHECK_NAMED,
|
||||
OPT_R_ENUM, OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS ecparam_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "list_curves", OPT_LIST_CURVES, '-',
|
||||
"Prints a list of all curve 'short names'" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"list_curves", OPT_LIST_CURVES, '-',
|
||||
"Prints a list of all curve 'short names'"},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine, possibly a hardware device"},
|
||||
#endif
|
||||
|
||||
{ "genkey", OPT_GENKEY, '-', "Generate ec key" },
|
||||
{ "in", OPT_IN, '<', "Input file - default stdin" },
|
||||
{ "inform", OPT_INFORM, 'F', "Input format - default PEM (DER or PEM)" },
|
||||
{ "out", OPT_OUT, '>', "Output file - default stdout" },
|
||||
{ "outform", OPT_OUTFORM, 'F', "Output format - default PEM" },
|
||||
{"genkey", OPT_GENKEY, '-', "Generate ec key"},
|
||||
{"in", OPT_IN, '<', "Input file - default stdin"},
|
||||
{"inform", OPT_INFORM, 'F', "Input format - default PEM (DER or PEM)"},
|
||||
{"out", OPT_OUT, '>', "Output file - default stdout"},
|
||||
{"outform", OPT_OUTFORM, 'F', "Output format - default PEM"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "text", OPT_TEXT, '-', "Print the ec parameters in text form" },
|
||||
{ "noout", OPT_NOOUT, '-', "Do not print the ec parameter" },
|
||||
{ "param_enc", OPT_PARAM_ENC, 's',
|
||||
"Selects between named_curve and explicit EC parameter encoding" },
|
||||
{"text", OPT_TEXT, '-', "Print the ec parameters in text form"},
|
||||
{"noout", OPT_NOOUT, '-', "Do not print the ec parameter"},
|
||||
{"param_enc", OPT_PARAM_ENC, 's',
|
||||
"Specifies the way the ec parameters are encoded"},
|
||||
|
||||
OPT_SECTION("Parameter"),
|
||||
{ "check", OPT_CHECK, '-', "Validate the ec parameters" },
|
||||
{ "check_named", OPT_CHECK_NAMED, '-',
|
||||
"Check that named EC curve parameters have not been modified" },
|
||||
{ "no_seed", OPT_NO_SEED, '-',
|
||||
"If 'explicit' parameters are chosen do not use the seed" },
|
||||
{ "name", OPT_NAME, 's',
|
||||
"Use the ec parameters with specified 'short name'" },
|
||||
{ "conv_form", OPT_CONV_FORM, 's', "Specifies the point conversion form " },
|
||||
{"check", OPT_CHECK, '-', "Validate the ec parameters"},
|
||||
{"check_named", OPT_CHECK_NAMED, '-',
|
||||
"Check that named EC curve parameters have not been modified"},
|
||||
{"no_seed", OPT_NO_SEED, '-',
|
||||
"If 'explicit' parameters are chosen do not use the seed"},
|
||||
{"name", OPT_NAME, 's',
|
||||
"Use the ec parameters with specified 'short name'"},
|
||||
{"conv_form", OPT_CONV_FORM, 's', "Specifies the point conversion form "},
|
||||
|
||||
OPT_R_OPTIONS,
|
||||
OPT_PROV_OPTIONS,
|
||||
{ NULL }
|
||||
{NULL}
|
||||
};
|
||||
|
||||
static int list_builtin_curves(BIO *out)
|
||||
|
|
@ -79,7 +70,7 @@ static int list_builtin_curves(BIO *out)
|
|||
EC_builtin_curve *curves = NULL;
|
||||
size_t n, crv_len = EC_get_builtin_curves(NULL, 0);
|
||||
|
||||
curves = app_malloc_array(crv_len, sizeof(*curves), "list curves");
|
||||
curves = app_malloc((int)sizeof(*curves) * crv_len, "list curves");
|
||||
EC_get_builtin_curves(curves, crv_len);
|
||||
|
||||
for (n = 0; n < crv_len; n++) {
|
||||
|
|
@ -91,7 +82,8 @@ static int list_builtin_curves(BIO *out)
|
|||
if (sname == NULL)
|
||||
sname = "";
|
||||
|
||||
BIO_printf(out, " %-10s: %s\n", sname, comment);
|
||||
BIO_printf(out, " %-10s: ", sname);
|
||||
BIO_printf(out, "%s\n", comment);
|
||||
}
|
||||
OPENSSL_free(curves);
|
||||
return 1;
|
||||
|
|
@ -103,6 +95,7 @@ int ecparam_main(int argc, char **argv)
|
|||
EVP_PKEY *params_key = NULL, *key = NULL;
|
||||
OSSL_ENCODER_CTX *ectx_key = NULL, *ectx_params = NULL;
|
||||
OSSL_DECODER_CTX *dctx_params = NULL;
|
||||
ENGINE *e = NULL;
|
||||
BIO *out = NULL;
|
||||
char *curve_name = NULL;
|
||||
char *asn1_encoding = NULL;
|
||||
|
|
@ -119,7 +112,7 @@ int ecparam_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -182,6 +175,9 @@ int ecparam_main(int argc, char **argv)
|
|||
if (!opt_provider(o))
|
||||
goto end;
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
|
|
@ -209,44 +205,44 @@ int ecparam_main(int argc, char **argv)
|
|||
OSSL_PARAM *p = params;
|
||||
|
||||
if (strcmp(curve_name, "secp192r1") == 0) {
|
||||
BIO_puts(bio_err,
|
||||
"using curve name prime192v1 instead of secp192r1\n");
|
||||
BIO_printf(bio_err,
|
||||
"using curve name prime192v1 instead of secp192r1\n");
|
||||
curve_name = SN_X9_62_prime192v1;
|
||||
} else if (strcmp(curve_name, "secp256r1") == 0) {
|
||||
BIO_puts(bio_err,
|
||||
"using curve name prime256v1 instead of secp256r1\n");
|
||||
BIO_printf(bio_err,
|
||||
"using curve name prime256v1 instead of secp256r1\n");
|
||||
curve_name = SN_X9_62_prime256v1;
|
||||
}
|
||||
*p++ = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_GROUP_NAME,
|
||||
curve_name, 0);
|
||||
curve_name, 0);
|
||||
if (asn1_encoding != NULL)
|
||||
*p++ = OSSL_PARAM_construct_utf8_string(OSSL_PKEY_PARAM_EC_ENCODING,
|
||||
asn1_encoding, 0);
|
||||
asn1_encoding, 0);
|
||||
if (point_format != NULL)
|
||||
*p++ = OSSL_PARAM_construct_utf8_string(
|
||||
OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT,
|
||||
point_format, 0);
|
||||
OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT,
|
||||
point_format, 0);
|
||||
*p = OSSL_PARAM_construct_end();
|
||||
|
||||
if (OPENSSL_strcasecmp(curve_name, "SM2") == 0)
|
||||
gctx_params = EVP_PKEY_CTX_new_from_name(app_get0_libctx(), "sm2",
|
||||
app_get0_propq());
|
||||
app_get0_propq());
|
||||
else
|
||||
gctx_params = EVP_PKEY_CTX_new_from_name(app_get0_libctx(), "ec",
|
||||
app_get0_propq());
|
||||
app_get0_propq());
|
||||
if (gctx_params == NULL
|
||||
|| EVP_PKEY_keygen_init(gctx_params) <= 0
|
||||
|| EVP_PKEY_CTX_set_params(gctx_params, params) <= 0
|
||||
|| EVP_PKEY_keygen(gctx_params, ¶ms_key) <= 0) {
|
||||
BIO_puts(bio_err, "unable to generate key\n");
|
||||
BIO_printf(bio_err, "unable to generate key\n");
|
||||
goto end;
|
||||
}
|
||||
} else {
|
||||
params_key = load_keyparams_suppress(infile, informat, 1, "EC",
|
||||
"EC parameters", 1);
|
||||
"EC parameters", 1);
|
||||
if (params_key == NULL)
|
||||
params_key = load_keyparams_suppress(infile, informat, 1, "SM2",
|
||||
"SM2 parameters", 1);
|
||||
"SM2 parameters", 1);
|
||||
|
||||
if (params_key == NULL) {
|
||||
BIO_printf(bio_err, "Unable to load parameters from %s\n", infile);
|
||||
|
|
@ -255,24 +251,24 @@ int ecparam_main(int argc, char **argv)
|
|||
|
||||
if (point_format
|
||||
&& !EVP_PKEY_set_utf8_string_param(
|
||||
params_key, OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT,
|
||||
point_format)) {
|
||||
BIO_puts(bio_err, "unable to set point conversion format\n");
|
||||
params_key, OSSL_PKEY_PARAM_EC_POINT_CONVERSION_FORMAT,
|
||||
point_format)) {
|
||||
BIO_printf(bio_err, "unable to set point conversion format\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (asn1_encoding != NULL
|
||||
&& !EVP_PKEY_set_utf8_string_param(
|
||||
params_key, OSSL_PKEY_PARAM_EC_ENCODING, asn1_encoding)) {
|
||||
BIO_puts(bio_err, "unable to set asn1 encoding format\n");
|
||||
params_key, OSSL_PKEY_PARAM_EC_ENCODING, asn1_encoding)) {
|
||||
BIO_printf(bio_err, "unable to set asn1 encoding format\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
||||
if (no_seed
|
||||
&& !EVP_PKEY_set_octet_string_param(params_key, OSSL_PKEY_PARAM_EC_SEED,
|
||||
NULL, 0)) {
|
||||
BIO_puts(bio_err, "unable to clear seed\n");
|
||||
NULL, 0)) {
|
||||
BIO_printf(bio_err, "unable to clear seed\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -282,27 +278,27 @@ int ecparam_main(int argc, char **argv)
|
|||
|
||||
if (text
|
||||
&& EVP_PKEY_print_params(out, params_key, 0, NULL) <= 0) {
|
||||
BIO_puts(bio_err, "unable to print params\n");
|
||||
BIO_printf(bio_err, "unable to print params\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (check || check_named) {
|
||||
BIO_puts(bio_err, "checking elliptic curve parameters: ");
|
||||
BIO_printf(bio_err, "checking elliptic curve parameters: ");
|
||||
|
||||
if (check_named
|
||||
&& !EVP_PKEY_set_utf8_string_param(params_key,
|
||||
OSSL_PKEY_PARAM_EC_GROUP_CHECK_TYPE,
|
||||
OSSL_PKEY_EC_GROUP_CHECK_NAMED)) {
|
||||
BIO_puts(bio_err, "unable to set check_type\n");
|
||||
goto end;
|
||||
OSSL_PKEY_PARAM_EC_GROUP_CHECK_TYPE,
|
||||
OSSL_PKEY_EC_GROUP_CHECK_NAMED)) {
|
||||
BIO_printf(bio_err, "unable to set check_type\n");
|
||||
goto end;
|
||||
}
|
||||
pctx = EVP_PKEY_CTX_new_from_pkey(app_get0_libctx(), params_key,
|
||||
app_get0_propq());
|
||||
app_get0_propq());
|
||||
if (pctx == NULL || EVP_PKEY_param_check(pctx) <= 0) {
|
||||
BIO_puts(bio_err, "failed\n");
|
||||
BIO_printf(bio_err, "failed\n");
|
||||
goto end;
|
||||
}
|
||||
BIO_puts(bio_err, "ok\n");
|
||||
BIO_printf(bio_err, "ok\n");
|
||||
}
|
||||
|
||||
if (outformat == FORMAT_ASN1 && genkey)
|
||||
|
|
@ -310,10 +306,10 @@ int ecparam_main(int argc, char **argv)
|
|||
|
||||
if (!noout) {
|
||||
ectx_params = OSSL_ENCODER_CTX_new_for_pkey(
|
||||
params_key, OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
|
||||
outformat == FORMAT_ASN1 ? "DER" : "PEM", NULL, NULL);
|
||||
params_key, OSSL_KEYMGMT_SELECT_DOMAIN_PARAMETERS,
|
||||
outformat == FORMAT_ASN1 ? "DER" : "PEM", NULL, NULL);
|
||||
if (!OSSL_ENCODER_to_bio(ectx_params, out)) {
|
||||
BIO_puts(bio_err, "unable to write elliptic curve parameters\n");
|
||||
BIO_printf(bio_err, "unable to write elliptic curve parameters\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -328,19 +324,19 @@ int ecparam_main(int argc, char **argv)
|
|||
* EVP_PKEY_keygen(gctx, &key) <= 0)
|
||||
*/
|
||||
gctx_key = EVP_PKEY_CTX_new_from_pkey(app_get0_libctx(), params_key,
|
||||
app_get0_propq());
|
||||
app_get0_propq());
|
||||
if (EVP_PKEY_keygen_init(gctx_key) <= 0
|
||||
|| EVP_PKEY_keygen(gctx_key, &key) <= 0) {
|
||||
BIO_puts(bio_err, "unable to generate key\n");
|
||||
BIO_printf(bio_err, "unable to generate key\n");
|
||||
goto end;
|
||||
}
|
||||
assert(private);
|
||||
ectx_key = OSSL_ENCODER_CTX_new_for_pkey(
|
||||
key, OSSL_KEYMGMT_SELECT_ALL,
|
||||
outformat == FORMAT_ASN1 ? "DER" : "PEM", NULL, NULL);
|
||||
key, OSSL_KEYMGMT_SELECT_ALL,
|
||||
outformat == FORMAT_ASN1 ? "DER" : "PEM", NULL, NULL);
|
||||
if (!OSSL_ENCODER_to_bio(ectx_key, out)) {
|
||||
BIO_puts(bio_err, "unable to write elliptic "
|
||||
"curve parameters\n");
|
||||
BIO_printf(bio_err, "unable to write elliptic "
|
||||
"curve parameters\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -349,6 +345,7 @@ int ecparam_main(int argc, char **argv)
|
|||
end:
|
||||
if (ret != 0)
|
||||
ERR_print_errors(bio_err);
|
||||
release_engine(e);
|
||||
EVP_PKEY_free(params_key);
|
||||
EVP_PKEY_free(key);
|
||||
EVP_PKEY_CTX_free(pctx);
|
||||
|
|
|
|||
383
apps/enc.c
383
apps/enc.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -21,17 +21,16 @@
|
|||
#include <openssl/rand.h>
|
||||
#include <openssl/pem.h>
|
||||
#ifndef OPENSSL_NO_COMP
|
||||
#include <openssl/comp.h>
|
||||
# include <openssl/comp.h>
|
||||
#endif
|
||||
#include <ctype.h>
|
||||
#include <inttypes.h>
|
||||
|
||||
#undef SIZE
|
||||
#undef BSIZE
|
||||
#define SIZE (512)
|
||||
#define BSIZE (8 * 1024)
|
||||
#define SIZE (512)
|
||||
#define BSIZE (8*1024)
|
||||
|
||||
#define PBKDF2_ITER_DEFAULT 10000
|
||||
#define PBKDF2_ITER_DEFAULT 10000
|
||||
#define STR(a) XSTR(a)
|
||||
#define XSTR(a) #a
|
||||
|
||||
|
|
@ -46,134 +45,83 @@ struct doall_enc_ciphers {
|
|||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_LIST,
|
||||
OPT_E,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_PASS,
|
||||
OPT_D,
|
||||
OPT_P,
|
||||
OPT_V,
|
||||
OPT_NOPAD,
|
||||
OPT_SALT,
|
||||
OPT_NOSALT,
|
||||
OPT_DEBUG,
|
||||
OPT_UPPER_P,
|
||||
OPT_UPPER_A,
|
||||
OPT_A,
|
||||
OPT_Z,
|
||||
OPT_BUFSIZE,
|
||||
OPT_K,
|
||||
OPT_KFILE,
|
||||
OPT_UPPER_K,
|
||||
OPT_NONE,
|
||||
OPT_UPPER_S,
|
||||
OPT_IV,
|
||||
OPT_MD,
|
||||
OPT_ITER,
|
||||
OPT_PBKDF2,
|
||||
OPT_CIPHER,
|
||||
OPT_SALTLEN,
|
||||
OPT_R_ENUM,
|
||||
OPT_PROV_ENUM,
|
||||
OPT_SKEYOPT,
|
||||
OPT_SKEYMGMT,
|
||||
OPT_SKEYURI,
|
||||
OPT_PASSIN
|
||||
OPT_E, OPT_IN, OPT_OUT, OPT_PASS, OPT_ENGINE, OPT_D, OPT_P, OPT_V,
|
||||
OPT_NOPAD, OPT_SALT, OPT_NOSALT, OPT_DEBUG, OPT_UPPER_P, OPT_UPPER_A,
|
||||
OPT_A, OPT_Z, OPT_BUFSIZE, OPT_K, OPT_KFILE, OPT_UPPER_K, OPT_NONE,
|
||||
OPT_UPPER_S, OPT_IV, OPT_MD, OPT_ITER, OPT_PBKDF2, OPT_CIPHER,
|
||||
OPT_SALTLEN, OPT_R_ENUM, OPT_PROV_ENUM,
|
||||
OPT_SKEYOPT, OPT_SKEYMGMT
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS enc_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "list", OPT_LIST, '-', "List ciphers" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"list", OPT_LIST, '-', "List ciphers"},
|
||||
#ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
{ "ciphers", OPT_LIST, '-', "Alias for -list" },
|
||||
{"ciphers", OPT_LIST, '-', "Alias for -list"},
|
||||
#endif
|
||||
{"e", OPT_E, '-', "Encrypt"},
|
||||
{"d", OPT_D, '-', "Decrypt"},
|
||||
{"p", OPT_P, '-', "Print the iv/key"},
|
||||
{"P", OPT_UPPER_P, '-', "Print the iv/key and exit"},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine, possibly a hardware device"},
|
||||
#endif
|
||||
{ "e", OPT_E, '-', "Encrypt" },
|
||||
{ "d", OPT_D, '-', "Decrypt" },
|
||||
{ "p", OPT_P, '-', "Print the iv/key" },
|
||||
{ "P", OPT_UPPER_P, '-', "Print the iv/key and exit" },
|
||||
|
||||
OPT_SECTION("Input"),
|
||||
{ "in", OPT_IN, '<', "Input file" },
|
||||
{"in", OPT_IN, '<', "Input file"},
|
||||
{"k", OPT_K, 's', "Passphrase"},
|
||||
{"kfile", OPT_KFILE, '<', "Read passphrase from file"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output file" },
|
||||
{ "v", OPT_V, '-', "Verbose output" },
|
||||
{ "a", OPT_A, '-', "Base64 encode/decode, depending on encryption flag" },
|
||||
{ "base64", OPT_A, '-', "Same as option -a" },
|
||||
{ "A", OPT_UPPER_A, '-',
|
||||
"Used with -[base64|a] to specify base64 buffer as a single line" },
|
||||
{"out", OPT_OUT, '>', "Output file"},
|
||||
{"pass", OPT_PASS, 's', "Passphrase source"},
|
||||
{"v", OPT_V, '-', "Verbose output"},
|
||||
{"a", OPT_A, '-', "Base64 encode/decode, depending on encryption flag"},
|
||||
{"base64", OPT_A, '-', "Same as option -a"},
|
||||
{"A", OPT_UPPER_A, '-',
|
||||
"Used with -[base64|a] to specify base64 buffer as a single line"},
|
||||
|
||||
OPT_SECTION("Encryption"),
|
||||
{ "nopad", OPT_NOPAD, '-', "Disable standard block padding" },
|
||||
{ "salt", OPT_SALT, '-', "Use salt in the KDF (default)" },
|
||||
{ "nosalt", OPT_NOSALT, '-', "Do not use salt in the KDF" },
|
||||
{ "debug", OPT_DEBUG, '-', "Print debug info" },
|
||||
{"nopad", OPT_NOPAD, '-', "Disable standard block padding"},
|
||||
{"salt", OPT_SALT, '-', "Use salt in the KDF (default)"},
|
||||
{"nosalt", OPT_NOSALT, '-', "Do not use salt in the KDF"},
|
||||
{"debug", OPT_DEBUG, '-', "Print debug info"},
|
||||
|
||||
{ "bufsize", OPT_BUFSIZE, 's', "Buffer size" },
|
||||
{ "K", OPT_UPPER_K, 's', "Raw key, in hex" },
|
||||
{ "S", OPT_UPPER_S, 's', "Salt, in hex" },
|
||||
{ "iv", OPT_IV, 's', "IV in hex" },
|
||||
{ "md", OPT_MD, 's', "Use specified digest to create a key from the passphrase" },
|
||||
{ "k", OPT_K, 's', "Passphrase (Deprecated)" },
|
||||
{ "kfile", OPT_KFILE, '<', "Read passphrase from file (Deprecated)" },
|
||||
{ "pass", OPT_PASS, 's', "Passphrase source" },
|
||||
{ "iter", OPT_ITER, 'p',
|
||||
"Specify the iteration count and force the use of PBKDF2" },
|
||||
{ OPT_MORE_STR, 0, 0, "Default: " STR(PBKDF2_ITER_DEFAULT) },
|
||||
{ "pbkdf2", OPT_PBKDF2, '-',
|
||||
"Use password-based key derivation function 2 (PBKDF2)" },
|
||||
{ OPT_MORE_STR, 0, 0,
|
||||
"Use -iter to change the iteration count from " STR(PBKDF2_ITER_DEFAULT) },
|
||||
{ "none", OPT_NONE, '-', "Don't encrypt" },
|
||||
{ "saltlen", OPT_SALTLEN, 'p', "Specify the PBKDF2 salt length (in bytes)" },
|
||||
{ OPT_MORE_STR, 0, 0, "Default: 16" },
|
||||
{"bufsize", OPT_BUFSIZE, 's', "Buffer size"},
|
||||
{"K", OPT_UPPER_K, 's', "Raw key, in hex"},
|
||||
{"S", OPT_UPPER_S, 's', "Salt, in hex"},
|
||||
{"iv", OPT_IV, 's', "IV in hex"},
|
||||
{"md", OPT_MD, 's', "Use specified digest to create a key from the passphrase"},
|
||||
{"iter", OPT_ITER, 'p',
|
||||
"Specify the iteration count and force the use of PBKDF2"},
|
||||
{OPT_MORE_STR, 0, 0, "Default: " STR(PBKDF2_ITER_DEFAULT)},
|
||||
{"pbkdf2", OPT_PBKDF2, '-',
|
||||
"Use password-based key derivation function 2 (PBKDF2)"},
|
||||
{OPT_MORE_STR, 0, 0,
|
||||
"Use -iter to change the iteration count from " STR(PBKDF2_ITER_DEFAULT)},
|
||||
{"none", OPT_NONE, '-', "Don't encrypt"},
|
||||
{"saltlen", OPT_SALTLEN, 'p', "Specify the PBKDF2 salt length (in bytes)"},
|
||||
{OPT_MORE_STR, 0, 0, "Default: 16"},
|
||||
#ifndef OPENSSL_NO_ZLIB
|
||||
{ "z", OPT_Z, '-', "Compress or decompress encrypted data using zlib" },
|
||||
{"z", OPT_Z, '-', "Compress or decompress encrypted data using zlib"},
|
||||
#endif
|
||||
{ "skeyopt", OPT_SKEYOPT, 's', "Key options as opt:value for opaque symmetric key handling" },
|
||||
{ "skeymgmt", OPT_SKEYMGMT, 's', "Symmetric key management name for opaque symmetric key handling" },
|
||||
{ "skeyuri", OPT_SKEYURI, 's', "Symmetric key object URI" },
|
||||
{ "storepass", OPT_PASSIN, 's', "Store pass phrase source when skeyuri is used (optional)" },
|
||||
{ "", OPT_CIPHER, '-', "Any supported cipher" },
|
||||
{"skeyopt", OPT_SKEYOPT, 's', "Key options as opt:value for opaque symmetric key handling"},
|
||||
{"skeymgmt", OPT_SKEYMGMT, 's', "Symmetric key management name for opaque symmetric key handling"},
|
||||
{"", OPT_CIPHER, '-', "Any supported cipher"},
|
||||
|
||||
OPT_R_OPTIONS,
|
||||
OPT_PROV_OPTIONS,
|
||||
{ NULL }
|
||||
{NULL}
|
||||
};
|
||||
|
||||
static EVP_SKEY *skey_from_params(const EVP_CIPHER *cipher, const char *skeymgmt,
|
||||
STACK_OF(OPENSSL_STRING) *opts)
|
||||
{
|
||||
EVP_SKEY *skey = NULL;
|
||||
EVP_SKEYMGMT *mgmt = NULL;
|
||||
OSSL_PARAM *params = NULL;
|
||||
|
||||
mgmt = EVP_SKEYMGMT_fetch(app_get0_libctx(),
|
||||
skeymgmt != NULL ? skeymgmt : EVP_CIPHER_name(cipher),
|
||||
app_get0_propq());
|
||||
if (mgmt == NULL)
|
||||
return NULL;
|
||||
|
||||
params = app_params_new_from_opts(opts, EVP_SKEYMGMT_get0_imp_settable_params(mgmt));
|
||||
if (params == NULL) {
|
||||
EVP_SKEYMGMT_free(mgmt);
|
||||
return NULL;
|
||||
}
|
||||
|
||||
skey = EVP_SKEY_import(app_get0_libctx(), EVP_SKEYMGMT_get0_name(mgmt),
|
||||
app_get0_propq(), OSSL_SKEYMGMT_SELECT_ALL, params);
|
||||
app_params_free(params);
|
||||
EVP_SKEYMGMT_free(mgmt);
|
||||
|
||||
return skey;
|
||||
}
|
||||
|
||||
int enc_main(int argc, char **argv)
|
||||
{
|
||||
static char buf[128];
|
||||
static const char magic[] = "Salted__";
|
||||
BIO *in = NULL, *out = NULL, *b64 = NULL, *benc = NULL, *rbio = NULL, *wbio = NULL;
|
||||
ENGINE *e = NULL;
|
||||
BIO *in = NULL, *out = NULL, *b64 = NULL, *benc = NULL, *rbio =
|
||||
NULL, *wbio = NULL;
|
||||
EVP_CIPHER_CTX *ctx = NULL;
|
||||
EVP_CIPHER *cipher = NULL;
|
||||
EVP_MD *dgst = NULL;
|
||||
|
|
@ -181,7 +129,6 @@ int enc_main(int argc, char **argv)
|
|||
char *hkey = NULL, *hiv = NULL, *hsalt = NULL, *p;
|
||||
char *infile = NULL, *outfile = NULL, *prog;
|
||||
char *str = NULL, *passarg = NULL, *pass = NULL, *strbuf = NULL;
|
||||
char *storepassarg = NULL;
|
||||
const char *ciphername = NULL;
|
||||
char mbuf[sizeof(magic) - 1];
|
||||
OPTION_CHOICE o;
|
||||
|
|
@ -209,8 +156,8 @@ int enc_main(int argc, char **argv)
|
|||
BIO *bzstd = NULL;
|
||||
STACK_OF(OPENSSL_STRING) *skeyopts = NULL;
|
||||
const char *skeymgmt = NULL;
|
||||
const char *skeyuri = NULL;
|
||||
EVP_SKEY *skey = NULL;
|
||||
EVP_SKEYMGMT *mgmt = NULL;
|
||||
|
||||
/* first check the command name */
|
||||
if (strcmp(argv[0], "base64") == 0)
|
||||
|
|
@ -236,7 +183,7 @@ int enc_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -244,12 +191,12 @@ int enc_main(int argc, char **argv)
|
|||
ret = 0;
|
||||
goto end;
|
||||
case OPT_LIST:
|
||||
BIO_puts(bio_out, "Supported ciphers:\n");
|
||||
BIO_printf(bio_out, "Supported ciphers:\n");
|
||||
dec.bio = bio_out;
|
||||
dec.n = 0;
|
||||
OBJ_NAME_do_all_sorted(OBJ_NAME_TYPE_CIPHER_METH,
|
||||
show_ciphers, &dec);
|
||||
BIO_puts(bio_out, "\n");
|
||||
show_ciphers, &dec);
|
||||
BIO_printf(bio_out, "\n");
|
||||
ret = 0;
|
||||
goto end;
|
||||
case OPT_E:
|
||||
|
|
@ -264,8 +211,8 @@ int enc_main(int argc, char **argv)
|
|||
case OPT_PASS:
|
||||
passarg = opt_arg();
|
||||
break;
|
||||
case OPT_PASSIN:
|
||||
storepassarg = opt_arg();
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_D:
|
||||
enc = 0;
|
||||
|
|
@ -309,12 +256,10 @@ int enc_main(int argc, char **argv)
|
|||
if (k)
|
||||
p[i] = '\0';
|
||||
if (!opt_long(opt_arg(), &n)
|
||||
|| n < 0 || (k && n >= LONG_MAX / 1024))
|
||||
|| n < 0 || (k && n >= LONG_MAX / 1024))
|
||||
goto opthelp;
|
||||
if (k)
|
||||
n *= 1024;
|
||||
if (n > INT_MAX)
|
||||
goto opthelp;
|
||||
bsize = (int)n;
|
||||
break;
|
||||
case OPT_K:
|
||||
|
|
@ -329,7 +274,7 @@ int enc_main(int argc, char **argv)
|
|||
in = NULL;
|
||||
if (i <= 0) {
|
||||
BIO_printf(bio_err,
|
||||
"%s Can't read key from %s\n", prog, opt_arg());
|
||||
"%s Can't read key from %s\n", prog, opt_arg());
|
||||
goto opthelp;
|
||||
}
|
||||
while (--i > 0 && (buf[i] == '\r' || buf[i] == '\n'))
|
||||
|
|
@ -367,14 +312,16 @@ int enc_main(int argc, char **argv)
|
|||
break;
|
||||
case OPT_PBKDF2:
|
||||
pbkdf2 = 1;
|
||||
if (iter == 0) /* do not overwrite a chosen value */
|
||||
if (iter == 0) /* do not overwrite a chosen value */
|
||||
iter = PBKDF2_ITER_DEFAULT;
|
||||
break;
|
||||
case OPT_NONE:
|
||||
cipher = NULL;
|
||||
break;
|
||||
case OPT_SKEYOPT:
|
||||
if ((skeyopts == NULL && (skeyopts = sk_OPENSSL_STRING_new_null()) == NULL) || sk_OPENSSL_STRING_push(skeyopts, opt_arg()) == 0) {
|
||||
if ((skeyopts == NULL &&
|
||||
(skeyopts = sk_OPENSSL_STRING_new_null()) == NULL) ||
|
||||
sk_OPENSSL_STRING_push(skeyopts, opt_arg()) == 0) {
|
||||
BIO_printf(bio_err, "%s: out of memory\n", prog);
|
||||
goto end;
|
||||
}
|
||||
|
|
@ -382,9 +329,6 @@ int enc_main(int argc, char **argv)
|
|||
case OPT_SKEYMGMT:
|
||||
skeymgmt = opt_arg();
|
||||
break;
|
||||
case OPT_SKEYURI:
|
||||
skeyuri = opt_arg();
|
||||
break;
|
||||
case OPT_R_CASES:
|
||||
if (!opt_rand(o))
|
||||
goto end;
|
||||
|
|
@ -425,7 +369,7 @@ int enc_main(int argc, char **argv)
|
|||
if (base64 && bsize < 80)
|
||||
bsize = 80;
|
||||
if (verbose)
|
||||
BIO_printf(bio_out, "bufsize=%d\n", bsize);
|
||||
BIO_printf(bio_err, "bufsize=%d\n", bsize);
|
||||
|
||||
#ifndef OPENSSL_NO_ZLIB
|
||||
if (do_zlib)
|
||||
|
|
@ -447,8 +391,8 @@ int enc_main(int argc, char **argv)
|
|||
buff = app_malloc(EVP_ENCODE_LENGTH(bsize), "evp buffer");
|
||||
|
||||
if (infile == NULL) {
|
||||
if (!streamable && printkey != 2) { /* if just print key and exit, it's ok */
|
||||
BIO_puts(bio_err, "Unstreamable cipher mode\n");
|
||||
if (!streamable && printkey != 2) { /* if just print key and exit, it's ok */
|
||||
BIO_printf(bio_err, "Unstreamable cipher mode\n");
|
||||
goto end;
|
||||
}
|
||||
in = dup_bio_in(informat);
|
||||
|
|
@ -460,22 +404,21 @@ int enc_main(int argc, char **argv)
|
|||
|
||||
if (str == NULL && passarg != NULL) {
|
||||
if (!app_passwd(passarg, NULL, &pass, NULL)) {
|
||||
BIO_puts(bio_err, "Error getting password\n");
|
||||
BIO_printf(bio_err, "Error getting password\n");
|
||||
goto end;
|
||||
}
|
||||
str = pass;
|
||||
}
|
||||
|
||||
if ((str == NULL) && (cipher != NULL) && (hkey == NULL)
|
||||
&& (skeyopts == NULL) && (skeyuri == NULL)) {
|
||||
if ((str == NULL) && (cipher != NULL) && (hkey == NULL) && (skeyopts == NULL)) {
|
||||
if (1) {
|
||||
#ifndef OPENSSL_NO_UI_CONSOLE
|
||||
for (;;) {
|
||||
char prompt[200];
|
||||
|
||||
BIO_snprintf(prompt, sizeof(prompt), "enter %s %s password:",
|
||||
EVP_CIPHER_get0_name(cipher),
|
||||
(enc) ? "encryption" : "decryption");
|
||||
EVP_CIPHER_get0_name(cipher),
|
||||
(enc) ? "encryption" : "decryption");
|
||||
strbuf[0] = '\0';
|
||||
i = EVP_read_pw_string((char *)strbuf, SIZE, prompt, enc);
|
||||
if (i == 0) {
|
||||
|
|
@ -487,13 +430,13 @@ int enc_main(int argc, char **argv)
|
|||
break;
|
||||
}
|
||||
if (i < 0) {
|
||||
BIO_puts(bio_err, "bad password read\n");
|
||||
BIO_printf(bio_err, "bad password read\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
} else {
|
||||
#endif
|
||||
BIO_puts(bio_err, "password required\n");
|
||||
BIO_printf(bio_err, "password required\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -513,7 +456,7 @@ int enc_main(int argc, char **argv)
|
|||
wbio = out;
|
||||
|
||||
#ifndef OPENSSL_NO_COMP
|
||||
#ifndef OPENSSL_NO_ZLIB
|
||||
# ifndef OPENSSL_NO_ZLIB
|
||||
if (do_zlib) {
|
||||
if ((bzl = BIO_new(BIO_f_zlib())) == NULL)
|
||||
goto end;
|
||||
|
|
@ -526,7 +469,7 @@ int enc_main(int argc, char **argv)
|
|||
else
|
||||
rbio = BIO_push(bzl, rbio);
|
||||
}
|
||||
#endif
|
||||
# endif
|
||||
|
||||
if (do_brotli) {
|
||||
if ((bbrot = BIO_new(BIO_f_brotli())) == NULL)
|
||||
|
|
@ -584,13 +527,13 @@ int enc_main(int argc, char **argv)
|
|||
sptr = NULL;
|
||||
} else {
|
||||
if (hsalt != NULL && !set_hex(hsalt, salt, saltlen)) {
|
||||
BIO_puts(bio_err, "invalid hex salt value\n");
|
||||
BIO_printf(bio_err, "invalid hex salt value\n");
|
||||
goto end;
|
||||
}
|
||||
if (enc) { /* encryption */
|
||||
if (enc) { /* encryption */
|
||||
if (hsalt == NULL) {
|
||||
if (RAND_bytes(salt, saltlen) <= 0) {
|
||||
BIO_puts(bio_err, "RAND_bytes failed\n");
|
||||
BIO_printf(bio_err, "RAND_bytes failed\n");
|
||||
goto end;
|
||||
}
|
||||
/*
|
||||
|
|
@ -599,31 +542,28 @@ int enc_main(int argc, char **argv)
|
|||
*/
|
||||
if ((printkey != 2)
|
||||
&& (BIO_write(wbio, magic,
|
||||
sizeof(magic) - 1)
|
||||
!= sizeof(magic) - 1
|
||||
sizeof(magic) - 1) != sizeof(magic) - 1
|
||||
|| BIO_write(wbio,
|
||||
(char *)salt,
|
||||
saltlen)
|
||||
!= saltlen)) {
|
||||
BIO_puts(bio_err, "error writing output file\n");
|
||||
(char *)salt,
|
||||
saltlen) != saltlen)) {
|
||||
BIO_printf(bio_err, "error writing output file\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
} else { /* decryption */
|
||||
} else { /* decryption */
|
||||
if (hsalt == NULL) {
|
||||
if (BIO_read(rbio, mbuf, sizeof(mbuf)) != sizeof(mbuf)) {
|
||||
BIO_puts(bio_err, "error reading input file\n");
|
||||
BIO_printf(bio_err, "error reading input file\n");
|
||||
goto end;
|
||||
}
|
||||
if (memcmp(mbuf, magic, sizeof(mbuf)) == 0) { /* file IS salted */
|
||||
if (BIO_read(rbio, salt,
|
||||
saltlen)
|
||||
!= saltlen) {
|
||||
BIO_puts(bio_err, "error reading input file\n");
|
||||
saltlen) != saltlen) {
|
||||
BIO_printf(bio_err, "error reading input file\n");
|
||||
goto end;
|
||||
}
|
||||
} else { /* file is NOT salted, NO salt available */
|
||||
BIO_puts(bio_err, "bad magic number\n");
|
||||
BIO_printf(bio_err, "bad magic number\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -633,32 +573,32 @@ int enc_main(int argc, char **argv)
|
|||
|
||||
if (pbkdf2 == 1) {
|
||||
/*
|
||||
* derive key and default iv
|
||||
* concatenated into a temporary buffer
|
||||
*/
|
||||
* derive key and default iv
|
||||
* concatenated into a temporary buffer
|
||||
*/
|
||||
unsigned char tmpkeyiv[EVP_MAX_KEY_LENGTH + EVP_MAX_IV_LENGTH];
|
||||
int iklen = EVP_CIPHER_get_key_length(cipher);
|
||||
int ivlen = EVP_CIPHER_get_iv_length(cipher);
|
||||
/* not needed if HASH_UPDATE() is fixed : */
|
||||
int islen = (sptr != NULL ? saltlen : 0);
|
||||
|
||||
if (!PKCS5_PBKDF2_HMAC(str, (int)str_len, sptr, islen,
|
||||
iter, dgst, iklen + ivlen, tmpkeyiv)) {
|
||||
BIO_puts(bio_err, "PKCS5_PBKDF2_HMAC failed\n");
|
||||
if (!PKCS5_PBKDF2_HMAC(str, str_len, sptr, islen,
|
||||
iter, dgst, iklen+ivlen, tmpkeyiv)) {
|
||||
BIO_printf(bio_err, "PKCS5_PBKDF2_HMAC failed\n");
|
||||
goto end;
|
||||
}
|
||||
/* split and move data back to global buffer */
|
||||
memcpy(key, tmpkeyiv, iklen);
|
||||
memcpy(iv, tmpkeyiv + iklen, ivlen);
|
||||
memcpy(iv, tmpkeyiv+iklen, ivlen);
|
||||
rawkey_set = 1;
|
||||
} else {
|
||||
BIO_puts(bio_err, "*** WARNING : "
|
||||
"deprecated key derivation used.\n"
|
||||
"Using -iter or -pbkdf2 would be better.\n");
|
||||
BIO_printf(bio_err, "*** WARNING : "
|
||||
"deprecated key derivation used.\n"
|
||||
"Using -iter or -pbkdf2 would be better.\n");
|
||||
if (!EVP_BytesToKey(cipher, dgst, sptr,
|
||||
(unsigned char *)str, (int)str_len,
|
||||
1, key, iv)) {
|
||||
BIO_puts(bio_err, "EVP_BytesToKey failed\n");
|
||||
(unsigned char *)str, str_len,
|
||||
1, key, iv)) {
|
||||
BIO_printf(bio_err, "EVP_BytesToKey failed\n");
|
||||
goto end;
|
||||
}
|
||||
rawkey_set = 1;
|
||||
|
|
@ -676,9 +616,9 @@ int enc_main(int argc, char **argv)
|
|||
int siz = EVP_CIPHER_get_iv_length(cipher);
|
||||
|
||||
if (siz == 0) {
|
||||
BIO_puts(bio_err, "warning: iv not used by this cipher\n");
|
||||
BIO_printf(bio_err, "warning: iv not used by this cipher\n");
|
||||
} else if (!set_hex(hiv, iv, siz)) {
|
||||
BIO_puts(bio_err, "invalid hex iv value\n");
|
||||
BIO_printf(bio_err, "invalid hex iv value\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -689,12 +629,12 @@ int enc_main(int argc, char **argv)
|
|||
* No IV was explicitly set and no IV was generated.
|
||||
* Hence the IV is undefined, making correct decryption impossible.
|
||||
*/
|
||||
BIO_puts(bio_err, "iv undefined\n");
|
||||
BIO_printf(bio_err, "iv undefined\n");
|
||||
goto end;
|
||||
}
|
||||
if (hkey != NULL) {
|
||||
if (!set_hex(hkey, key, EVP_CIPHER_get_key_length(cipher))) {
|
||||
BIO_puts(bio_err, "invalid hex key value\n");
|
||||
BIO_printf(bio_err, "invalid hex key value\n");
|
||||
goto end;
|
||||
}
|
||||
/* wiping secret data as we no longer need it */
|
||||
|
|
@ -706,8 +646,8 @@ int enc_main(int argc, char **argv)
|
|||
* At this moment we know whether we trying to use raw bytes as the key
|
||||
* or an opaque symmetric key. We do not allow both options simultaneously.
|
||||
*/
|
||||
if (rawkey_set > 0 && (skeyopts != NULL || skeyuri != NULL)) {
|
||||
BIO_puts(bio_err, "Either a raw key or the skeyopt/skeyuri args must be used.\n");
|
||||
if (rawkey_set > 0 && skeyopts != NULL) {
|
||||
BIO_printf(bio_err, "Either a raw key or the 'skeyopt' args must be used.\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -725,41 +665,43 @@ int enc_main(int argc, char **argv)
|
|||
EVP_CIPHER_CTX_set_flags(ctx, EVP_CIPHER_CTX_FLAG_WRAP_ALLOW);
|
||||
|
||||
if (rawkey_set) {
|
||||
if (!EVP_CipherInit_ex(ctx, cipher, NULL, key,
|
||||
(hiv == NULL && wrap == 1 ? NULL : iv), enc)) {
|
||||
if (!EVP_CipherInit_ex(ctx, cipher, e, key,
|
||||
(hiv == NULL && wrap == 1 ? NULL : iv), enc)) {
|
||||
BIO_printf(bio_err, "Error setting cipher %s\n",
|
||||
EVP_CIPHER_get0_name(cipher));
|
||||
EVP_CIPHER_get0_name(cipher));
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
} else {
|
||||
if (skeyuri != NULL) {
|
||||
char *storepass = NULL;
|
||||
OSSL_PARAM *params = NULL;
|
||||
|
||||
if (!app_passwd(storepassarg, NULL, &storepass, NULL)) {
|
||||
BIO_puts(bio_err,
|
||||
"Error getting store password from 'storepass' argument\n");
|
||||
}
|
||||
mgmt = EVP_SKEYMGMT_fetch(app_get0_libctx(),
|
||||
skeymgmt != NULL ? skeymgmt : EVP_CIPHER_name(cipher),
|
||||
app_get0_propq());
|
||||
if (mgmt == NULL)
|
||||
goto end;
|
||||
|
||||
skey = load_skey(skeyuri, FORMAT_UNDEF, 0, storepass, 0);
|
||||
OPENSSL_free(storepass);
|
||||
if (skey == NULL) {
|
||||
BIO_printf(bio_err, "Error loading opaque key object from URI %s\n", skeyuri);
|
||||
goto end;
|
||||
}
|
||||
} else {
|
||||
skey = skey_from_params(cipher, skeymgmt, skeyopts);
|
||||
if (skey == NULL) {
|
||||
BIO_printf(bio_err, "Error creating opaque key object for skeymgmt %s\n",
|
||||
skeymgmt ? skeymgmt : EVP_CIPHER_name(cipher));
|
||||
goto end;
|
||||
}
|
||||
params = app_params_new_from_opts(skeyopts,
|
||||
EVP_SKEYMGMT_get0_imp_settable_params(mgmt));
|
||||
if (params == NULL)
|
||||
goto end;
|
||||
|
||||
skey = EVP_SKEY_import(app_get0_libctx(), EVP_SKEYMGMT_get0_name(mgmt),
|
||||
app_get0_propq(), OSSL_SKEYMGMT_SELECT_ALL, params);
|
||||
OSSL_PARAM_free(params);
|
||||
if (skey == NULL) {
|
||||
BIO_printf(bio_err, "Error creating opaque key object for skeymgmt %s\n",
|
||||
skeymgmt ? skeymgmt : EVP_CIPHER_name(cipher));
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (!EVP_CipherInit_SKEY(ctx, cipher, skey,
|
||||
(hiv == NULL && wrap == 1 ? NULL : iv),
|
||||
EVP_CIPHER_get_iv_length(cipher), enc, NULL)) {
|
||||
(hiv == NULL && wrap == 1 ? NULL : iv),
|
||||
EVP_CIPHER_get_iv_length(cipher), enc, NULL)) {
|
||||
BIO_printf(bio_err, "Error setting an opaque key for cipher %s\n",
|
||||
EVP_CIPHER_get0_name(cipher));
|
||||
EVP_CIPHER_get0_name(cipher));
|
||||
ERR_print_errors(bio_err);
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -806,12 +748,12 @@ int enc_main(int argc, char **argv)
|
|||
inl = BIO_read(rbio, (char *)buff, bsize);
|
||||
if (inl <= 0)
|
||||
break;
|
||||
if (!streamable && !BIO_eof(rbio)) { /* do not output data */
|
||||
BIO_puts(bio_err, "Unstreamable cipher mode\n");
|
||||
if (!streamable && !BIO_eof(rbio)) { /* do not output data */
|
||||
BIO_printf(bio_err, "Unstreamable cipher mode\n");
|
||||
goto end;
|
||||
}
|
||||
if (BIO_write(wbio, (char *)buff, inl) != inl) {
|
||||
BIO_puts(bio_err, "error writing output file\n");
|
||||
BIO_printf(bio_err, "error writing output file\n");
|
||||
goto end;
|
||||
}
|
||||
if (!streamable)
|
||||
|
|
@ -819,21 +761,21 @@ int enc_main(int argc, char **argv)
|
|||
}
|
||||
if (!BIO_flush(wbio)) {
|
||||
if (enc)
|
||||
BIO_puts(bio_err, "bad encrypt\n");
|
||||
BIO_printf(bio_err, "bad encrypt\n");
|
||||
else
|
||||
BIO_puts(bio_err, "bad decrypt\n");
|
||||
BIO_printf(bio_err, "bad decrypt\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
ret = 0;
|
||||
if (verbose) {
|
||||
BIO_printf(bio_err, "bytes read : %8" PRIu64 "\n"
|
||||
"bytes written: %8" PRIu64 "\n",
|
||||
BIO_number_read(in), BIO_number_written(out));
|
||||
BIO_printf(bio_err, "bytes read : %8ju\n", BIO_number_read(in));
|
||||
BIO_printf(bio_err, "bytes written: %8ju\n", BIO_number_written(out));
|
||||
}
|
||||
end:
|
||||
end:
|
||||
ERR_print_errors(bio_err);
|
||||
sk_OPENSSL_STRING_free(skeyopts);
|
||||
EVP_SKEYMGMT_free(mgmt);
|
||||
EVP_SKEY_free(skey);
|
||||
OPENSSL_free(strbuf);
|
||||
OPENSSL_free(buff);
|
||||
|
|
@ -848,6 +790,7 @@ end:
|
|||
#endif
|
||||
BIO_free(bbrot);
|
||||
BIO_free(bzstd);
|
||||
release_engine(e);
|
||||
OPENSSL_free(pass);
|
||||
return ret;
|
||||
}
|
||||
|
|
@ -855,29 +798,25 @@ end:
|
|||
static void show_ciphers(const OBJ_NAME *name, void *arg)
|
||||
{
|
||||
struct doall_enc_ciphers *dec = (struct doall_enc_ciphers *)arg;
|
||||
EVP_CIPHER *cipher;
|
||||
const EVP_CIPHER *cipher;
|
||||
|
||||
if (!islower((unsigned char)*name->name))
|
||||
return;
|
||||
|
||||
/* Filter out ciphers that we cannot use */
|
||||
cipher = EVP_CIPHER_fetch(app_get0_libctx(), name->name, app_get0_propq());
|
||||
cipher = EVP_get_cipherbyname(name->name);
|
||||
if (cipher == NULL
|
||||
|| (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) != 0
|
||||
|| (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_ENC_THEN_MAC) != 0
|
||||
|| EVP_CIPHER_get_mode(cipher) == EVP_CIPH_XTS_MODE) {
|
||||
EVP_CIPHER_free(cipher);
|
||||
|| (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_AEAD_CIPHER) != 0
|
||||
|| (EVP_CIPHER_get_flags(cipher) & EVP_CIPH_FLAG_ENC_THEN_MAC) != 0
|
||||
|| EVP_CIPHER_get_mode(cipher) == EVP_CIPH_XTS_MODE)
|
||||
return;
|
||||
}
|
||||
|
||||
BIO_printf(dec->bio, "-%-25s", name->name);
|
||||
if (++dec->n == 3) {
|
||||
BIO_puts(dec->bio, "\n");
|
||||
BIO_printf(dec->bio, "\n");
|
||||
dec->n = 0;
|
||||
} else
|
||||
BIO_puts(dec->bio, " ");
|
||||
|
||||
EVP_CIPHER_free(cipher);
|
||||
BIO_printf(dec->bio, " ");
|
||||
}
|
||||
|
||||
static int set_hex(const char *in, unsigned char *out, int size)
|
||||
|
|
@ -886,19 +825,19 @@ static int set_hex(const char *in, unsigned char *out, int size)
|
|||
unsigned char j;
|
||||
|
||||
i = size * 2;
|
||||
n = (int)strlen(in);
|
||||
n = strlen(in);
|
||||
if (n > i) {
|
||||
BIO_puts(bio_err, "hex string is too long, ignoring excess\n");
|
||||
BIO_printf(bio_err, "hex string is too long, ignoring excess\n");
|
||||
n = i; /* ignore exceeding part */
|
||||
} else if (n < i) {
|
||||
BIO_puts(bio_err, "hex string is too short, padding with zero bytes to length\n");
|
||||
BIO_printf(bio_err, "hex string is too short, padding with zero bytes to length\n");
|
||||
}
|
||||
|
||||
memset(out, 0, size);
|
||||
for (i = 0; i < n; i++) {
|
||||
j = (unsigned char)*in++;
|
||||
if (!isxdigit(j)) {
|
||||
BIO_puts(bio_err, "non-hex digit\n");
|
||||
BIO_printf(bio_err, "non-hex digit\n");
|
||||
return 0;
|
||||
}
|
||||
j = (unsigned char)OPENSSL_hexchar2int(j);
|
||||
|
|
|
|||
501
apps/engine.c
Normal file
501
apps/engine.c
Normal file
|
|
@ -0,0 +1,501 @@
|
|||
/*
|
||||
* Copyright 2000-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
/* We need to use some engine deprecated APIs */
|
||||
#define OPENSSL_SUPPRESS_DEPRECATED
|
||||
|
||||
#include <openssl/opensslconf.h>
|
||||
|
||||
#include "apps.h"
|
||||
#include "progs.h"
|
||||
#include <stdio.h>
|
||||
#include <stdlib.h>
|
||||
#include <string.h>
|
||||
#include <openssl/err.h>
|
||||
#include <openssl/engine.h>
|
||||
#include <openssl/ssl.h>
|
||||
#include <openssl/store.h>
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_C, OPT_T, OPT_TT, OPT_PRE, OPT_POST,
|
||||
OPT_V = 100, OPT_VV, OPT_VVV, OPT_VVVV
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS engine_options[] = {
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] engine...\n"},
|
||||
|
||||
OPT_SECTION("General"),
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"t", OPT_T, '-', "Check that specified engine is available"},
|
||||
{"pre", OPT_PRE, 's', "Run command against the ENGINE before loading it"},
|
||||
{"post", OPT_POST, 's', "Run command against the ENGINE after loading it"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{"v", OPT_V, '-', "List 'control commands' For each specified engine"},
|
||||
{"vv", OPT_VV, '-', "Also display each command's description"},
|
||||
{"vvv", OPT_VVV, '-', "Also add the input flags for each command"},
|
||||
{"vvvv", OPT_VVVV, '-', "Also show internal input flags"},
|
||||
{"c", OPT_C, '-', "List the capabilities of specified engine"},
|
||||
{"tt", OPT_TT, '-', "Display error trace for unavailable engines"},
|
||||
{OPT_MORE_STR, OPT_EOF, 1,
|
||||
"Commands are like \"SO_PATH:/lib/libdriver.so\""},
|
||||
|
||||
OPT_PARAMETERS(),
|
||||
{"engine", 0, 0, "ID of engine(s) to load"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
static int append_buf(char **buf, int *size, const char *s)
|
||||
{
|
||||
const int expand = 256;
|
||||
int len = strlen(s) + 1;
|
||||
char *p = *buf;
|
||||
|
||||
if (p == NULL) {
|
||||
*size = ((len + expand - 1) / expand) * expand;
|
||||
p = *buf = app_malloc(*size, "engine buffer");
|
||||
} else {
|
||||
const int blen = strlen(p);
|
||||
|
||||
if (blen > 0)
|
||||
len += 2 + blen;
|
||||
|
||||
if (len > *size) {
|
||||
*size = ((len + expand - 1) / expand) * expand;
|
||||
p = OPENSSL_realloc(p, *size);
|
||||
if (p == NULL) {
|
||||
OPENSSL_free(*buf);
|
||||
*buf = NULL;
|
||||
return 0;
|
||||
}
|
||||
*buf = p;
|
||||
}
|
||||
|
||||
if (blen > 0) {
|
||||
p += blen;
|
||||
*p++ = ',';
|
||||
*p++ = ' ';
|
||||
}
|
||||
}
|
||||
|
||||
strcpy(p, s);
|
||||
return 1;
|
||||
}
|
||||
|
||||
static int util_flags(BIO *out, unsigned int flags, const char *indent)
|
||||
{
|
||||
int started = 0, err = 0;
|
||||
/* Indent before displaying input flags */
|
||||
BIO_printf(out, "%s%s(input flags): ", indent, indent);
|
||||
if (flags == 0) {
|
||||
BIO_printf(out, "<no flags>\n");
|
||||
return 1;
|
||||
}
|
||||
/*
|
||||
* If the object is internal, mark it in a way that shows instead of
|
||||
* having it part of all the other flags, even if it really is.
|
||||
*/
|
||||
if (flags & ENGINE_CMD_FLAG_INTERNAL) {
|
||||
BIO_printf(out, "[Internal] ");
|
||||
}
|
||||
|
||||
if (flags & ENGINE_CMD_FLAG_NUMERIC) {
|
||||
BIO_printf(out, "NUMERIC");
|
||||
started = 1;
|
||||
}
|
||||
/*
|
||||
* Now we check that no combinations of the mutually exclusive NUMERIC,
|
||||
* STRING, and NO_INPUT flags have been used. Future flags that can be
|
||||
* OR'd together with these would need to added after these to preserve
|
||||
* the testing logic.
|
||||
*/
|
||||
if (flags & ENGINE_CMD_FLAG_STRING) {
|
||||
if (started) {
|
||||
BIO_printf(out, "|");
|
||||
err = 1;
|
||||
}
|
||||
BIO_printf(out, "STRING");
|
||||
started = 1;
|
||||
}
|
||||
if (flags & ENGINE_CMD_FLAG_NO_INPUT) {
|
||||
if (started) {
|
||||
BIO_printf(out, "|");
|
||||
err = 1;
|
||||
}
|
||||
BIO_printf(out, "NO_INPUT");
|
||||
started = 1;
|
||||
}
|
||||
/* Check for unknown flags */
|
||||
flags = flags & ~ENGINE_CMD_FLAG_NUMERIC &
|
||||
~ENGINE_CMD_FLAG_STRING &
|
||||
~ENGINE_CMD_FLAG_NO_INPUT & ~ENGINE_CMD_FLAG_INTERNAL;
|
||||
if (flags) {
|
||||
if (started)
|
||||
BIO_printf(out, "|");
|
||||
BIO_printf(out, "<0x%04X>", flags);
|
||||
}
|
||||
if (err)
|
||||
BIO_printf(out, " <illegal flags!>");
|
||||
BIO_printf(out, "\n");
|
||||
return 1;
|
||||
}
|
||||
|
||||
static int util_verbose(ENGINE *e, int verbose, BIO *out, const char *indent)
|
||||
{
|
||||
static const int line_wrap = 78;
|
||||
int num;
|
||||
int ret = 0;
|
||||
char *name = NULL;
|
||||
char *desc = NULL;
|
||||
int flags;
|
||||
int xpos = 0;
|
||||
STACK_OF(OPENSSL_STRING) *cmds = NULL;
|
||||
if (!ENGINE_ctrl(e, ENGINE_CTRL_HAS_CTRL_FUNCTION, 0, NULL, NULL) ||
|
||||
((num = ENGINE_ctrl(e, ENGINE_CTRL_GET_FIRST_CMD_TYPE,
|
||||
0, NULL, NULL)) <= 0)) {
|
||||
return 1;
|
||||
}
|
||||
|
||||
cmds = sk_OPENSSL_STRING_new_null();
|
||||
if (cmds == NULL)
|
||||
goto err;
|
||||
|
||||
do {
|
||||
int len;
|
||||
/* Get the command input flags */
|
||||
if ((flags = ENGINE_ctrl(e, ENGINE_CTRL_GET_CMD_FLAGS, num,
|
||||
NULL, NULL)) < 0)
|
||||
goto err;
|
||||
if (!(flags & ENGINE_CMD_FLAG_INTERNAL) || verbose >= 4) {
|
||||
/* Get the command name */
|
||||
if ((len = ENGINE_ctrl(e, ENGINE_CTRL_GET_NAME_LEN_FROM_CMD, num,
|
||||
NULL, NULL)) <= 0)
|
||||
goto err;
|
||||
name = app_malloc(len + 1, "name buffer");
|
||||
if (ENGINE_ctrl(e, ENGINE_CTRL_GET_NAME_FROM_CMD, num, name,
|
||||
NULL) <= 0)
|
||||
goto err;
|
||||
/* Get the command description */
|
||||
if ((len = ENGINE_ctrl(e, ENGINE_CTRL_GET_DESC_LEN_FROM_CMD, num,
|
||||
NULL, NULL)) < 0)
|
||||
goto err;
|
||||
if (len > 0) {
|
||||
desc = app_malloc(len + 1, "description buffer");
|
||||
if (ENGINE_ctrl(e, ENGINE_CTRL_GET_DESC_FROM_CMD, num, desc,
|
||||
NULL) <= 0)
|
||||
goto err;
|
||||
}
|
||||
/* Now decide on the output */
|
||||
if (xpos == 0)
|
||||
/* Do an indent */
|
||||
xpos = BIO_puts(out, indent);
|
||||
else
|
||||
/* Otherwise prepend a ", " */
|
||||
xpos += BIO_printf(out, ", ");
|
||||
if (verbose == 1) {
|
||||
/*
|
||||
* We're just listing names, comma-delimited
|
||||
*/
|
||||
if ((xpos > (int)strlen(indent)) &&
|
||||
(xpos + (int)strlen(name) > line_wrap)) {
|
||||
BIO_printf(out, "\n");
|
||||
xpos = BIO_puts(out, indent);
|
||||
}
|
||||
xpos += BIO_printf(out, "%s", name);
|
||||
} else {
|
||||
/* We're listing names plus descriptions */
|
||||
BIO_printf(out, "%s: %s\n", name,
|
||||
(desc == NULL) ? "<no description>" : desc);
|
||||
/* ... and sometimes input flags */
|
||||
if ((verbose >= 3) && !util_flags(out, flags, indent))
|
||||
goto err;
|
||||
xpos = 0;
|
||||
}
|
||||
}
|
||||
OPENSSL_free(name);
|
||||
name = NULL;
|
||||
OPENSSL_free(desc);
|
||||
desc = NULL;
|
||||
/* Move to the next command */
|
||||
num = ENGINE_ctrl(e, ENGINE_CTRL_GET_NEXT_CMD_TYPE, num, NULL, NULL);
|
||||
} while (num > 0);
|
||||
if (xpos > 0)
|
||||
BIO_printf(out, "\n");
|
||||
ret = 1;
|
||||
err:
|
||||
sk_OPENSSL_STRING_free(cmds);
|
||||
OPENSSL_free(name);
|
||||
OPENSSL_free(desc);
|
||||
return ret;
|
||||
}
|
||||
|
||||
static void util_do_cmds(ENGINE *e, STACK_OF(OPENSSL_STRING) *cmds,
|
||||
BIO *out, const char *indent)
|
||||
{
|
||||
int loop, res, num = sk_OPENSSL_STRING_num(cmds);
|
||||
|
||||
if (num < 0) {
|
||||
BIO_printf(out, "[Error]: internal stack error\n");
|
||||
return;
|
||||
}
|
||||
for (loop = 0; loop < num; loop++) {
|
||||
char buf[256];
|
||||
const char *cmd, *arg;
|
||||
cmd = sk_OPENSSL_STRING_value(cmds, loop);
|
||||
res = 1; /* assume success */
|
||||
/* Check if this command has no ":arg" */
|
||||
if ((arg = strchr(cmd, ':')) == NULL) {
|
||||
if (!ENGINE_ctrl_cmd_string(e, cmd, NULL, 0))
|
||||
res = 0;
|
||||
} else {
|
||||
if ((int)(arg - cmd) > 254) {
|
||||
BIO_printf(out, "[Error]: command name too long\n");
|
||||
return;
|
||||
}
|
||||
memcpy(buf, cmd, (int)(arg - cmd));
|
||||
buf[arg - cmd] = '\0';
|
||||
arg++; /* Move past the ":" */
|
||||
/* Call the command with the argument */
|
||||
if (!ENGINE_ctrl_cmd_string(e, buf, arg, 0))
|
||||
res = 0;
|
||||
}
|
||||
if (res) {
|
||||
BIO_printf(out, "[Success]: %s\n", cmd);
|
||||
} else {
|
||||
BIO_printf(out, "[Failure]: %s\n", cmd);
|
||||
ERR_print_errors(out);
|
||||
}
|
||||
}
|
||||
}
|
||||
|
||||
struct util_store_cap_data {
|
||||
ENGINE *engine;
|
||||
char **cap_buf;
|
||||
int *cap_size;
|
||||
int ok;
|
||||
};
|
||||
static void util_store_cap(const OSSL_STORE_LOADER *loader, void *arg)
|
||||
{
|
||||
struct util_store_cap_data *ctx = arg;
|
||||
|
||||
if (OSSL_STORE_LOADER_get0_engine(loader) == ctx->engine) {
|
||||
char buf[256];
|
||||
BIO_snprintf(buf, sizeof(buf), "STORE(%s)",
|
||||
OSSL_STORE_LOADER_get0_scheme(loader));
|
||||
if (!append_buf(ctx->cap_buf, ctx->cap_size, buf))
|
||||
ctx->ok = 0;
|
||||
}
|
||||
}
|
||||
|
||||
int engine_main(int argc, char **argv)
|
||||
{
|
||||
int ret = 1, i;
|
||||
int verbose = 0, list_cap = 0, test_avail = 0, test_avail_noise = 0;
|
||||
ENGINE *e;
|
||||
STACK_OF(OPENSSL_CSTRING) *engines = sk_OPENSSL_CSTRING_new_null();
|
||||
STACK_OF(OPENSSL_STRING) *pre_cmds = sk_OPENSSL_STRING_new_null();
|
||||
STACK_OF(OPENSSL_STRING) *post_cmds = sk_OPENSSL_STRING_new_null();
|
||||
BIO *out;
|
||||
const char *indent = " ";
|
||||
OPTION_CHOICE o;
|
||||
char *prog;
|
||||
char *argv1;
|
||||
|
||||
out = dup_bio_out(FORMAT_TEXT);
|
||||
if (engines == NULL || pre_cmds == NULL || post_cmds == NULL)
|
||||
goto end;
|
||||
|
||||
/* Remember the original command name, parse/skip any leading engine
|
||||
* names, and then setup to parse the rest of the line as flags. */
|
||||
prog = argv[0];
|
||||
while ((argv1 = argv[1]) != NULL && *argv1 != '-') {
|
||||
if (!sk_OPENSSL_CSTRING_push(engines, argv1))
|
||||
goto end;
|
||||
argc--;
|
||||
argv++;
|
||||
}
|
||||
argv[0] = prog;
|
||||
opt_init(argc, argv, engine_options);
|
||||
|
||||
while ((o = opt_next()) != OPT_EOF) {
|
||||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
opt_help(engine_options);
|
||||
ret = 0;
|
||||
goto end;
|
||||
case OPT_VVVV:
|
||||
case OPT_VVV:
|
||||
case OPT_VV:
|
||||
case OPT_V:
|
||||
/* Convert to an integer from one to four. */
|
||||
i = (int)(o - OPT_V) + 1;
|
||||
if (verbose < i)
|
||||
verbose = i;
|
||||
break;
|
||||
case OPT_C:
|
||||
list_cap = 1;
|
||||
break;
|
||||
case OPT_TT:
|
||||
test_avail_noise++;
|
||||
/* fall through */
|
||||
case OPT_T:
|
||||
test_avail++;
|
||||
break;
|
||||
case OPT_PRE:
|
||||
if (sk_OPENSSL_STRING_push(pre_cmds, opt_arg()) <= 0)
|
||||
goto end;
|
||||
break;
|
||||
case OPT_POST:
|
||||
if (sk_OPENSSL_STRING_push(post_cmds, opt_arg()) <= 0)
|
||||
goto end;
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
/* Any remaining arguments are engine names. */
|
||||
argc = opt_num_rest();
|
||||
argv = opt_rest();
|
||||
for ( ; *argv; argv++) {
|
||||
if (**argv == '-') {
|
||||
BIO_printf(bio_err, "%s: Cannot mix flags and engine names.\n",
|
||||
prog);
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
}
|
||||
if (!sk_OPENSSL_CSTRING_push(engines, *argv))
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (sk_OPENSSL_CSTRING_num(engines) == 0) {
|
||||
for (e = ENGINE_get_first(); e != NULL; e = ENGINE_get_next(e)) {
|
||||
if (!sk_OPENSSL_CSTRING_push(engines, ENGINE_get_id(e)))
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
||||
ret = 0;
|
||||
for (i = 0; i < sk_OPENSSL_CSTRING_num(engines); i++) {
|
||||
const char *id = sk_OPENSSL_CSTRING_value(engines, i);
|
||||
if ((e = ENGINE_by_id(id)) != NULL) {
|
||||
const char *name = ENGINE_get_name(e);
|
||||
/*
|
||||
* Do "id" first, then "name". Easier to auto-parse.
|
||||
*/
|
||||
BIO_printf(out, "(%s) %s\n", id, name);
|
||||
util_do_cmds(e, pre_cmds, out, indent);
|
||||
if (strcmp(ENGINE_get_id(e), id) != 0) {
|
||||
BIO_printf(out, "Loaded: (%s) %s\n",
|
||||
ENGINE_get_id(e), ENGINE_get_name(e));
|
||||
}
|
||||
if (list_cap) {
|
||||
int cap_size = 256;
|
||||
char *cap_buf = NULL;
|
||||
int k, n;
|
||||
const int *nids;
|
||||
ENGINE_CIPHERS_PTR fn_c;
|
||||
ENGINE_DIGESTS_PTR fn_d;
|
||||
ENGINE_PKEY_METHS_PTR fn_pk;
|
||||
|
||||
if (ENGINE_get_RSA(e) != NULL
|
||||
&& !append_buf(&cap_buf, &cap_size, "RSA"))
|
||||
goto end;
|
||||
if (ENGINE_get_EC(e) != NULL
|
||||
&& !append_buf(&cap_buf, &cap_size, "EC"))
|
||||
goto end;
|
||||
if (ENGINE_get_DSA(e) != NULL
|
||||
&& !append_buf(&cap_buf, &cap_size, "DSA"))
|
||||
goto end;
|
||||
if (ENGINE_get_DH(e) != NULL
|
||||
&& !append_buf(&cap_buf, &cap_size, "DH"))
|
||||
goto end;
|
||||
if (ENGINE_get_RAND(e) != NULL
|
||||
&& !append_buf(&cap_buf, &cap_size, "RAND"))
|
||||
goto end;
|
||||
|
||||
fn_c = ENGINE_get_ciphers(e);
|
||||
if (fn_c == NULL)
|
||||
goto skip_ciphers;
|
||||
n = fn_c(e, NULL, &nids, 0);
|
||||
for (k = 0; k < n; ++k)
|
||||
if (!append_buf(&cap_buf, &cap_size, OBJ_nid2sn(nids[k])))
|
||||
goto end;
|
||||
|
||||
skip_ciphers:
|
||||
fn_d = ENGINE_get_digests(e);
|
||||
if (fn_d == NULL)
|
||||
goto skip_digests;
|
||||
n = fn_d(e, NULL, &nids, 0);
|
||||
for (k = 0; k < n; ++k)
|
||||
if (!append_buf(&cap_buf, &cap_size, OBJ_nid2sn(nids[k])))
|
||||
goto end;
|
||||
|
||||
skip_digests:
|
||||
fn_pk = ENGINE_get_pkey_meths(e);
|
||||
if (fn_pk == NULL)
|
||||
goto skip_pmeths;
|
||||
n = fn_pk(e, NULL, &nids, 0);
|
||||
for (k = 0; k < n; ++k)
|
||||
if (!append_buf(&cap_buf, &cap_size, OBJ_nid2sn(nids[k])))
|
||||
goto end;
|
||||
skip_pmeths:
|
||||
{
|
||||
struct util_store_cap_data store_ctx;
|
||||
|
||||
store_ctx.engine = e;
|
||||
store_ctx.cap_buf = &cap_buf;
|
||||
store_ctx.cap_size = &cap_size;
|
||||
store_ctx.ok = 1;
|
||||
|
||||
OSSL_STORE_do_all_loaders(util_store_cap, &store_ctx);
|
||||
if (!store_ctx.ok)
|
||||
goto end;
|
||||
}
|
||||
if (cap_buf != NULL && (*cap_buf != '\0'))
|
||||
BIO_printf(out, " [%s]\n", cap_buf);
|
||||
|
||||
OPENSSL_free(cap_buf);
|
||||
}
|
||||
if (test_avail) {
|
||||
BIO_printf(out, "%s", indent);
|
||||
if (ENGINE_init(e)) {
|
||||
BIO_printf(out, "[ available ]\n");
|
||||
util_do_cmds(e, post_cmds, out, indent);
|
||||
ENGINE_finish(e);
|
||||
} else {
|
||||
BIO_printf(out, "[ unavailable ]\n");
|
||||
if (test_avail_noise)
|
||||
ERR_print_errors_fp(stdout);
|
||||
ERR_clear_error();
|
||||
}
|
||||
}
|
||||
if ((verbose > 0) && !util_verbose(e, verbose, out, indent))
|
||||
goto end;
|
||||
ENGINE_free(e);
|
||||
} else {
|
||||
ERR_print_errors(bio_err);
|
||||
/* because exit codes above 127 have special meaning on Unix */
|
||||
if (++ret > 127)
|
||||
ret = 127;
|
||||
}
|
||||
}
|
||||
|
||||
end:
|
||||
|
||||
ERR_print_errors(bio_err);
|
||||
sk_OPENSSL_CSTRING_free(engines);
|
||||
sk_OPENSSL_STRING_free(pre_cmds);
|
||||
sk_OPENSSL_STRING_free(post_cmds);
|
||||
BIO_free_all(out);
|
||||
return ret;
|
||||
}
|
||||
|
|
@ -17,20 +17,18 @@
|
|||
#include <openssl/ssl.h>
|
||||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_ERR = -1,
|
||||
OPT_EOF = 0,
|
||||
OPT_HELP
|
||||
OPT_ERR = -1, OPT_EOF = 0, OPT_HELP
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS errstr_options[] = {
|
||||
{ OPT_HELP_STR, 1, '-', "Usage: %s [options] errnum...\n" },
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] errnum...\n"},
|
||||
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
|
||||
OPT_PARAMETERS(),
|
||||
{ "errnum", 0, 0, "Error number(s) to decode" },
|
||||
{ NULL }
|
||||
{"errnum", 0, 0, "Error number(s) to decode"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int errstr_main(int argc, char **argv)
|
||||
|
|
@ -59,8 +57,7 @@ int errstr_main(int argc, char **argv)
|
|||
* we're still interested in SSL error strings
|
||||
*/
|
||||
OPENSSL_init_ssl(OPENSSL_INIT_LOAD_SSL_STRINGS
|
||||
| OPENSSL_INIT_LOAD_CRYPTO_STRINGS,
|
||||
NULL);
|
||||
| OPENSSL_INIT_LOAD_CRYPTO_STRINGS, NULL);
|
||||
|
||||
/* All remaining arg are error code. */
|
||||
ret = 0;
|
||||
|
|
@ -72,6 +69,6 @@ int errstr_main(int argc, char **argv)
|
|||
BIO_printf(bio_out, "%s\n", buf);
|
||||
}
|
||||
}
|
||||
end:
|
||||
end:
|
||||
return ret;
|
||||
}
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 2019-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 2019-2024 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -21,8 +21,8 @@
|
|||
#define BUFSIZE 4096
|
||||
|
||||
/* Configuration file values */
|
||||
#define VERSION_KEY "version"
|
||||
#define VERSION_VAL "1"
|
||||
#define VERSION_KEY "version"
|
||||
#define VERSION_VAL "1"
|
||||
#define INSTALL_STATUS_VAL "INSTALL_SELF_TEST_KATS_RUN"
|
||||
|
||||
static OSSL_CALLBACK self_test_events;
|
||||
|
|
@ -33,29 +33,15 @@ static int quiet = 0;
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_IN,
|
||||
OPT_OUT,
|
||||
OPT_MODULE,
|
||||
OPT_PEDANTIC,
|
||||
OPT_PROV_NAME,
|
||||
OPT_SECTION_NAME,
|
||||
OPT_MAC_NAME,
|
||||
OPT_MACOPT,
|
||||
OPT_VERIFY,
|
||||
OPT_NO_LOG,
|
||||
OPT_CORRUPT_DESC,
|
||||
OPT_CORRUPT_TYPE,
|
||||
OPT_QUIET,
|
||||
OPT_CONFIG,
|
||||
OPT_IN, OPT_OUT, OPT_MODULE, OPT_PEDANTIC,
|
||||
OPT_PROV_NAME, OPT_SECTION_NAME, OPT_MAC_NAME, OPT_MACOPT, OPT_VERIFY,
|
||||
OPT_NO_LOG, OPT_CORRUPT_DESC, OPT_CORRUPT_TYPE, OPT_QUIET, OPT_CONFIG,
|
||||
OPT_NO_CONDITIONAL_ERRORS,
|
||||
OPT_NO_SECURITY_CHECKS,
|
||||
OPT_TLS_PRF_EMS_CHECK,
|
||||
OPT_NO_SHORT_MAC,
|
||||
OPT_DISALLOW_PKCS15_PADDING,
|
||||
OPT_RSA_PSS_SALTLEN_CHECK,
|
||||
OPT_TLS_PRF_EMS_CHECK, OPT_NO_SHORT_MAC,
|
||||
OPT_DISALLOW_PKCS15_PADDING, OPT_RSA_PSS_SALTLEN_CHECK,
|
||||
OPT_DISALLOW_SIGNATURE_X931_PADDING,
|
||||
OPT_HMAC_KEY_CHECK,
|
||||
OPT_KMAC_KEY_CHECK,
|
||||
OPT_HMAC_KEY_CHECK, OPT_KMAC_KEY_CHECK,
|
||||
OPT_DISALLOW_DRGB_TRUNC_DIGEST,
|
||||
OPT_SIGNATURE_DIGEST_CHECK,
|
||||
OPT_HKDF_DIGEST_CHECK,
|
||||
|
|
@ -76,96 +62,93 @@ typedef enum OPTION_choice {
|
|||
OPT_X942KDF_KEY_CHECK,
|
||||
OPT_NO_PBKDF2_LOWER_BOUND_CHECK,
|
||||
OPT_ECDH_COFACTOR_CHECK,
|
||||
OPT_SELF_TEST_ONLOAD,
|
||||
OPT_SELF_TEST_ONINSTALL,
|
||||
OPT_DEFER_TESTS
|
||||
OPT_SELF_TEST_ONLOAD, OPT_SELF_TEST_ONINSTALL
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS fipsinstall_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "pedantic", OPT_PEDANTIC, '-', "Set options for strict FIPS compliance" },
|
||||
{ "verify", OPT_VERIFY, '-',
|
||||
"Verify a config file instead of generating one" },
|
||||
{ "module", OPT_MODULE, '<', "File name of the provider module" },
|
||||
{ "provider_name", OPT_PROV_NAME, 's', "FIPS provider name" },
|
||||
{ "section_name", OPT_SECTION_NAME, 's',
|
||||
"FIPS Provider config section name (optional)" },
|
||||
{ "no_conditional_errors", OPT_NO_CONDITIONAL_ERRORS, '-',
|
||||
"Disable the ability of the fips module to enter an error state if"
|
||||
" any conditional self tests fail" },
|
||||
{ "no_security_checks", OPT_NO_SECURITY_CHECKS, '-',
|
||||
"Disable the run-time FIPS security checks in the module" },
|
||||
{ "self_test_onload", OPT_SELF_TEST_ONLOAD, '-',
|
||||
"Forces self tests to always run on module load" },
|
||||
{ "self_test_oninstall", OPT_SELF_TEST_ONINSTALL, '-',
|
||||
"Forces self tests to run once on module installation" },
|
||||
{ "ems_check", OPT_TLS_PRF_EMS_CHECK, '-',
|
||||
"Enable the run-time FIPS check for EMS during TLS1_PRF" },
|
||||
{ "no_short_mac", OPT_NO_SHORT_MAC, '-', "Disallow short MAC output" },
|
||||
{ "no_drbg_truncated_digests", OPT_DISALLOW_DRGB_TRUNC_DIGEST, '-',
|
||||
"Disallow truncated digests with Hash and HMAC DRBGs" },
|
||||
{ "signature_digest_check", OPT_SIGNATURE_DIGEST_CHECK, '-',
|
||||
"Enable checking for approved digests for signatures" },
|
||||
{ "hmac_key_check", OPT_HMAC_KEY_CHECK, '-', "Enable key check for HMAC" },
|
||||
{ "kmac_key_check", OPT_KMAC_KEY_CHECK, '-', "Enable key check for KMAC" },
|
||||
{ "hkdf_digest_check", OPT_HKDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for HKDF" },
|
||||
{ "tls13_kdf_digest_check", OPT_TLS13_KDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for TLS13-KDF" },
|
||||
{ "tls1_prf_digest_check", OPT_TLS1_PRF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for TLS1-PRF" },
|
||||
{ "sshkdf_digest_check", OPT_SSHKDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for SSHKDF" },
|
||||
{ "sskdf_digest_check", OPT_SSKDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for SSKDF" },
|
||||
{ "x963kdf_digest_check", OPT_X963KDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for X963KDF" },
|
||||
{ "dsa_sign_disabled", OPT_DISALLOW_DSA_SIGN, '-',
|
||||
"Disallow DSA signing" },
|
||||
{ "tdes_encrypt_disabled", OPT_DISALLOW_TDES_ENCRYPT, '-',
|
||||
"Disallow Triple-DES encryption" },
|
||||
{ "rsa_pkcs15_padding_disabled", OPT_DISALLOW_PKCS15_PADDING, '-',
|
||||
"Disallow PKCS#1 version 1.5 padding for RSA encryption" },
|
||||
{ "rsa_pss_saltlen_check", OPT_RSA_PSS_SALTLEN_CHECK, '-',
|
||||
"Enable salt length check for RSA-PSS signature operations" },
|
||||
{ "rsa_sign_x931_disabled", OPT_DISALLOW_SIGNATURE_X931_PADDING, '-',
|
||||
"Disallow X931 Padding for RSA signing" },
|
||||
{ "hkdf_key_check", OPT_HKDF_KEY_CHECK, '-',
|
||||
"Enable key check for HKDF" },
|
||||
{ "kbkdf_key_check", OPT_KBKDF_KEY_CHECK, '-',
|
||||
"Enable key check for KBKDF" },
|
||||
{ "tls13_kdf_key_check", OPT_TLS13_KDF_KEY_CHECK, '-',
|
||||
"Enable key check for TLS13-KDF" },
|
||||
{ "tls1_prf_key_check", OPT_TLS1_PRF_KEY_CHECK, '-',
|
||||
"Enable key check for TLS1-PRF" },
|
||||
{ "sshkdf_key_check", OPT_SSHKDF_KEY_CHECK, '-',
|
||||
"Enable key check for SSHKDF" },
|
||||
{ "sskdf_key_check", OPT_SSKDF_KEY_CHECK, '-',
|
||||
"Enable key check for SSKDF" },
|
||||
{ "x963kdf_key_check", OPT_X963KDF_KEY_CHECK, '-',
|
||||
"Enable key check for X963KDF" },
|
||||
{ "x942kdf_key_check", OPT_X942KDF_KEY_CHECK, '-',
|
||||
"Enable key check for X942KDF" },
|
||||
{ "no_pbkdf2_lower_bound_check", OPT_NO_PBKDF2_LOWER_BOUND_CHECK, '-',
|
||||
"Disable lower bound check for PBKDF2" },
|
||||
{ "ecdh_cofactor_check", OPT_ECDH_COFACTOR_CHECK, '-',
|
||||
"Enable Cofactor check for ECDH" },
|
||||
{ "defer_tests", OPT_DEFER_TESTS, '-', "Enables test deferral" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
{"pedantic", OPT_PEDANTIC, '-', "Set options for strict FIPS compliance"},
|
||||
{"verify", OPT_VERIFY, '-',
|
||||
"Verify a config file instead of generating one"},
|
||||
{"module", OPT_MODULE, '<', "File name of the provider module"},
|
||||
{"provider_name", OPT_PROV_NAME, 's', "FIPS provider name"},
|
||||
{"section_name", OPT_SECTION_NAME, 's',
|
||||
"FIPS Provider config section name (optional)"},
|
||||
{"no_conditional_errors", OPT_NO_CONDITIONAL_ERRORS, '-',
|
||||
"Disable the ability of the fips module to enter an error state if"
|
||||
" any conditional self tests fail"},
|
||||
{"no_security_checks", OPT_NO_SECURITY_CHECKS, '-',
|
||||
"Disable the run-time FIPS security checks in the module"},
|
||||
{"self_test_onload", OPT_SELF_TEST_ONLOAD, '-',
|
||||
"Forces self tests to always run on module load"},
|
||||
{"self_test_oninstall", OPT_SELF_TEST_ONINSTALL, '-',
|
||||
"Forces self tests to run once on module installation"},
|
||||
{"ems_check", OPT_TLS_PRF_EMS_CHECK, '-',
|
||||
"Enable the run-time FIPS check for EMS during TLS1_PRF"},
|
||||
{"no_short_mac", OPT_NO_SHORT_MAC, '-', "Disallow short MAC output"},
|
||||
{"no_drbg_truncated_digests", OPT_DISALLOW_DRGB_TRUNC_DIGEST, '-',
|
||||
"Disallow truncated digests with Hash and HMAC DRBGs"},
|
||||
{"signature_digest_check", OPT_SIGNATURE_DIGEST_CHECK, '-',
|
||||
"Enable checking for approved digests for signatures"},
|
||||
{"hmac_key_check", OPT_HMAC_KEY_CHECK, '-', "Enable key check for HMAC"},
|
||||
{"kmac_key_check", OPT_KMAC_KEY_CHECK, '-', "Enable key check for KMAC"},
|
||||
{"hkdf_digest_check", OPT_HKDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for HKDF"},
|
||||
{"tls13_kdf_digest_check", OPT_TLS13_KDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for TLS13-KDF"},
|
||||
{"tls1_prf_digest_check", OPT_TLS1_PRF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for TLS1-PRF"},
|
||||
{"sshkdf_digest_check", OPT_SSHKDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for SSHKDF"},
|
||||
{"sskdf_digest_check", OPT_SSKDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for SSKDF"},
|
||||
{"x963kdf_digest_check", OPT_X963KDF_DIGEST_CHECK, '-',
|
||||
"Enable digest check for X963KDF"},
|
||||
{"dsa_sign_disabled", OPT_DISALLOW_DSA_SIGN, '-',
|
||||
"Disallow DSA signing"},
|
||||
{"tdes_encrypt_disabled", OPT_DISALLOW_TDES_ENCRYPT, '-',
|
||||
"Disallow Triple-DES encryption"},
|
||||
{"rsa_pkcs15_padding_disabled", OPT_DISALLOW_PKCS15_PADDING, '-',
|
||||
"Disallow PKCS#1 version 1.5 padding for RSA encryption"},
|
||||
{"rsa_pss_saltlen_check", OPT_RSA_PSS_SALTLEN_CHECK, '-',
|
||||
"Enable salt length check for RSA-PSS signature operations"},
|
||||
{"rsa_sign_x931_disabled", OPT_DISALLOW_SIGNATURE_X931_PADDING, '-',
|
||||
"Disallow X931 Padding for RSA signing"},
|
||||
{"hkdf_key_check", OPT_HKDF_KEY_CHECK, '-',
|
||||
"Enable key check for HKDF"},
|
||||
{"kbkdf_key_check", OPT_KBKDF_KEY_CHECK, '-',
|
||||
"Enable key check for KBKDF"},
|
||||
{"tls13_kdf_key_check", OPT_TLS13_KDF_KEY_CHECK, '-',
|
||||
"Enable key check for TLS13-KDF"},
|
||||
{"tls1_prf_key_check", OPT_TLS1_PRF_KEY_CHECK, '-',
|
||||
"Enable key check for TLS1-PRF"},
|
||||
{"sshkdf_key_check", OPT_SSHKDF_KEY_CHECK, '-',
|
||||
"Enable key check for SSHKDF"},
|
||||
{"sskdf_key_check", OPT_SSKDF_KEY_CHECK, '-',
|
||||
"Enable key check for SSKDF"},
|
||||
{"x963kdf_key_check", OPT_X963KDF_KEY_CHECK, '-',
|
||||
"Enable key check for X963KDF"},
|
||||
{"x942kdf_key_check", OPT_X942KDF_KEY_CHECK, '-',
|
||||
"Enable key check for X942KDF"},
|
||||
{"no_pbkdf2_lower_bound_check", OPT_NO_PBKDF2_LOWER_BOUND_CHECK, '-',
|
||||
"Disable lower bound check for PBKDF2"},
|
||||
{"ecdh_cofactor_check", OPT_ECDH_COFACTOR_CHECK, '-',
|
||||
"Enable Cofactor check for ECDH"},
|
||||
OPT_SECTION("Input"),
|
||||
{ "in", OPT_IN, '<', "Input config file, used when verifying" },
|
||||
{"in", OPT_IN, '<', "Input config file, used when verifying"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output config file, used when generating" },
|
||||
{ "mac_name", OPT_MAC_NAME, 's', "MAC name" },
|
||||
{ "macopt", OPT_MACOPT, 's', "MAC algorithm parameters in n:v form." },
|
||||
{ OPT_MORE_STR, 0, 0, "See 'PARAMETER NAMES' in the EVP_MAC_ docs" },
|
||||
{ "noout", OPT_NO_LOG, '-', "Disable logging of self test events" },
|
||||
{ "corrupt_desc", OPT_CORRUPT_DESC, 's', "Corrupt a self test by description" },
|
||||
{ "corrupt_type", OPT_CORRUPT_TYPE, 's', "Corrupt a self test by type" },
|
||||
{ "config", OPT_CONFIG, '<', "The parent config to verify" },
|
||||
{ "quiet", OPT_QUIET, '-', "No messages, just exit status" },
|
||||
{ NULL }
|
||||
{"out", OPT_OUT, '>', "Output config file, used when generating"},
|
||||
{"mac_name", OPT_MAC_NAME, 's', "MAC name"},
|
||||
{"macopt", OPT_MACOPT, 's', "MAC algorithm parameters in n:v form."},
|
||||
{OPT_MORE_STR, 0, 0, "See 'PARAMETER NAMES' in the EVP_MAC_ docs"},
|
||||
{"noout", OPT_NO_LOG, '-', "Disable logging of self test events"},
|
||||
{"corrupt_desc", OPT_CORRUPT_DESC, 's', "Corrupt a self test by description"},
|
||||
{"corrupt_type", OPT_CORRUPT_TYPE, 's', "Corrupt a self test by type"},
|
||||
{"config", OPT_CONFIG, '<', "The parent config to verify"},
|
||||
{"quiet", OPT_QUIET, '-', "No messages, just exit status"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
typedef struct {
|
||||
|
|
@ -199,77 +182,74 @@ typedef struct {
|
|||
unsigned int x942kdf_key_check : 1;
|
||||
unsigned int pbkdf2_lower_bound_check : 1;
|
||||
unsigned int ecdh_cofactor_check : 1;
|
||||
unsigned int defer_tests : 1;
|
||||
} FIPS_OPTS;
|
||||
|
||||
/* Pedantic FIPS compliance */
|
||||
static const FIPS_OPTS pedantic_opts = {
|
||||
1, /* self_test_onload */
|
||||
1, /* conditional_errors */
|
||||
1, /* security_checks */
|
||||
1, /* hmac_key_check */
|
||||
1, /* kmac_key_check */
|
||||
1, /* tls_prf_ems_check */
|
||||
1, /* no_short_mac */
|
||||
1, /* drgb_no_trunc_dgst */
|
||||
1, /* signature_digest_check */
|
||||
1, /* hkdf_digest_check */
|
||||
1, /* tls13_kdf_digest_check */
|
||||
1, /* tls1_prf_digest_check */
|
||||
1, /* sshkdf_digest_check */
|
||||
1, /* sskdf_digest_check */
|
||||
1, /* x963kdf_digest_check */
|
||||
1, /* dsa_sign_disabled */
|
||||
1, /* tdes_encrypt_disabled */
|
||||
1, /* rsa_pkcs15_padding_disabled */
|
||||
1, /* rsa_pss_saltlen_check */
|
||||
1, /* sign_x931_padding_disabled */
|
||||
1, /* hkdf_key_check */
|
||||
1, /* kbkdf_key_check */
|
||||
1, /* tls13_kdf_key_check */
|
||||
1, /* tls1_prf_key_check */
|
||||
1, /* sshkdf_key_check */
|
||||
1, /* sskdf_key_check */
|
||||
1, /* x963kdf_key_check */
|
||||
1, /* x942kdf_key_check */
|
||||
1, /* pbkdf2_lower_bound_check */
|
||||
1, /* ecdh_cofactor_check */
|
||||
0, /* defer_tests */
|
||||
1, /* self_test_onload */
|
||||
1, /* conditional_errors */
|
||||
1, /* security_checks */
|
||||
1, /* hmac_key_check */
|
||||
1, /* kmac_key_check */
|
||||
1, /* tls_prf_ems_check */
|
||||
1, /* no_short_mac */
|
||||
1, /* drgb_no_trunc_dgst */
|
||||
1, /* signature_digest_check */
|
||||
1, /* hkdf_digest_check */
|
||||
1, /* tls13_kdf_digest_check */
|
||||
1, /* tls1_prf_digest_check */
|
||||
1, /* sshkdf_digest_check */
|
||||
1, /* sskdf_digest_check */
|
||||
1, /* x963kdf_digest_check */
|
||||
1, /* dsa_sign_disabled */
|
||||
1, /* tdes_encrypt_disabled */
|
||||
1, /* rsa_pkcs15_padding_disabled */
|
||||
1, /* rsa_pss_saltlen_check */
|
||||
1, /* sign_x931_padding_disabled */
|
||||
1, /* hkdf_key_check */
|
||||
1, /* kbkdf_key_check */
|
||||
1, /* tls13_kdf_key_check */
|
||||
1, /* tls1_prf_key_check */
|
||||
1, /* sshkdf_key_check */
|
||||
1, /* sskdf_key_check */
|
||||
1, /* x963kdf_key_check */
|
||||
1, /* x942kdf_key_check */
|
||||
1, /* pbkdf2_lower_bound_check */
|
||||
1, /* ecdh_cofactor_check */
|
||||
};
|
||||
|
||||
/* Default FIPS settings for backward compatibility */
|
||||
static FIPS_OPTS fips_opts = {
|
||||
1, /* self_test_onload */
|
||||
1, /* conditional_errors */
|
||||
1, /* security_checks */
|
||||
0, /* hmac_key_check */
|
||||
0, /* kmac_key_check */
|
||||
0, /* tls_prf_ems_check */
|
||||
0, /* no_short_mac */
|
||||
0, /* drgb_no_trunc_dgst */
|
||||
0, /* signature_digest_check */
|
||||
0, /* hkdf_digest_check */
|
||||
0, /* tls13_kdf_digest_check */
|
||||
0, /* tls1_prf_digest_check */
|
||||
0, /* sshkdf_digest_check */
|
||||
0, /* sskdf_digest_check */
|
||||
0, /* x963kdf_digest_check */
|
||||
0, /* dsa_sign_disabled */
|
||||
0, /* tdes_encrypt_disabled */
|
||||
0, /* rsa_pkcs15_padding_disabled */
|
||||
0, /* rsa_pss_saltlen_check */
|
||||
0, /* sign_x931_padding_disabled */
|
||||
0, /* hkdf_key_check */
|
||||
0, /* kbkdf_key_check */
|
||||
0, /* tls13_kdf_key_check */
|
||||
0, /* tls1_prf_key_check */
|
||||
0, /* sshkdf_key_check */
|
||||
0, /* sskdf_key_check */
|
||||
0, /* x963kdf_key_check */
|
||||
0, /* x942kdf_key_check */
|
||||
1, /* pbkdf2_lower_bound_check */
|
||||
0, /* ecdh_cofactor_check */
|
||||
0, /* defer_tests */
|
||||
1, /* self_test_onload */
|
||||
1, /* conditional_errors */
|
||||
1, /* security_checks */
|
||||
0, /* hmac_key_check */
|
||||
0, /* kmac_key_check */
|
||||
0, /* tls_prf_ems_check */
|
||||
0, /* no_short_mac */
|
||||
0, /* drgb_no_trunc_dgst */
|
||||
0, /* signature_digest_check */
|
||||
0, /* hkdf_digest_check */
|
||||
0, /* tls13_kdf_digest_check */
|
||||
0, /* tls1_prf_digest_check */
|
||||
0, /* sshkdf_digest_check */
|
||||
0, /* sskdf_digest_check */
|
||||
0, /* x963kdf_digest_check */
|
||||
0, /* dsa_sign_disabled */
|
||||
0, /* tdes_encrypt_disabled */
|
||||
0, /* rsa_pkcs15_padding_disabled */
|
||||
0, /* rsa_pss_saltlen_check */
|
||||
0, /* sign_x931_padding_disabled */
|
||||
0, /* hkdf_key_check */
|
||||
0, /* kbkdf_key_check */
|
||||
0, /* tls13_kdf_key_check */
|
||||
0, /* tls1_prf_key_check */
|
||||
0, /* sshkdf_key_check */
|
||||
0, /* sskdf_key_check */
|
||||
0, /* x963kdf_key_check */
|
||||
0, /* x942kdf_key_check */
|
||||
1, /* pbkdf2_lower_bound_check */
|
||||
0, /* ecdh_cofactor_check */
|
||||
};
|
||||
|
||||
static int check_non_pedantic_fips(int pedantic, const char *name)
|
||||
|
|
@ -282,7 +262,7 @@ static int check_non_pedantic_fips(int pedantic, const char *name)
|
|||
}
|
||||
|
||||
static int do_mac(EVP_MAC_CTX *ctx, unsigned char *tmp, BIO *in,
|
||||
unsigned char *out, size_t *out_len)
|
||||
unsigned char *out, size_t *out_len)
|
||||
{
|
||||
int ret = 0;
|
||||
int i;
|
||||
|
|
@ -305,7 +285,7 @@ err:
|
|||
}
|
||||
|
||||
static int load_fips_prov_and_run_self_test(const char *prov_name,
|
||||
int *is_fips_140_2_prov)
|
||||
int *is_fips_140_2_prov)
|
||||
{
|
||||
int ret = 0;
|
||||
OSSL_PROVIDER *prov = NULL;
|
||||
|
|
@ -314,19 +294,19 @@ static int load_fips_prov_and_run_self_test(const char *prov_name,
|
|||
|
||||
prov = OSSL_PROVIDER_load(NULL, prov_name);
|
||||
if (prov == NULL) {
|
||||
BIO_puts(bio_err, "Failed to load FIPS module\n");
|
||||
BIO_printf(bio_err, "Failed to load FIPS module\n");
|
||||
goto end;
|
||||
}
|
||||
if (!quiet) {
|
||||
*p++ = OSSL_PARAM_construct_utf8_ptr(OSSL_PROV_PARAM_NAME,
|
||||
&name, sizeof(name));
|
||||
&name, sizeof(name));
|
||||
*p++ = OSSL_PARAM_construct_utf8_ptr(OSSL_PROV_PARAM_VERSION,
|
||||
&vers, sizeof(vers));
|
||||
&vers, sizeof(vers));
|
||||
*p++ = OSSL_PARAM_construct_utf8_ptr(OSSL_PROV_PARAM_BUILDINFO,
|
||||
&build, sizeof(build));
|
||||
&build, sizeof(build));
|
||||
*p = OSSL_PARAM_construct_end();
|
||||
if (!OSSL_PROVIDER_get_params(prov, params)) {
|
||||
BIO_puts(bio_err, "Failed to query FIPS module parameters\n");
|
||||
BIO_printf(bio_err, "Failed to query FIPS module parameters\n");
|
||||
goto end;
|
||||
}
|
||||
if (OSSL_PARAM_modified(params))
|
||||
|
|
@ -337,10 +317,10 @@ static int load_fips_prov_and_run_self_test(const char *prov_name,
|
|||
BIO_printf(bio_err, "\t%-10s\t%s\n", "build:", build);
|
||||
} else {
|
||||
*p++ = OSSL_PARAM_construct_utf8_ptr(OSSL_PROV_PARAM_VERSION,
|
||||
&vers, sizeof(vers));
|
||||
&vers, sizeof(vers));
|
||||
*p = OSSL_PARAM_construct_end();
|
||||
if (!OSSL_PROVIDER_get_params(prov, params)) {
|
||||
BIO_puts(bio_err, "Failed to query FIPS module parameters\n");
|
||||
BIO_printf(bio_err, "Failed to query FIPS module parameters\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -352,7 +332,7 @@ end:
|
|||
}
|
||||
|
||||
static int print_mac(BIO *bio, const char *label, const unsigned char *mac,
|
||||
size_t len)
|
||||
size_t len)
|
||||
{
|
||||
int ret;
|
||||
char *hexstr = NULL;
|
||||
|
|
@ -366,15 +346,13 @@ static int print_mac(BIO *bio, const char *label, const unsigned char *mac,
|
|||
}
|
||||
|
||||
static int write_config_header(BIO *out, const char *prov_name,
|
||||
const char *section)
|
||||
const char *section)
|
||||
{
|
||||
return (BIO_printf(out, "openssl_conf = openssl_init\n\n"
|
||||
"[openssl_init]\n"
|
||||
"providers = provider_section\n\n"
|
||||
"[provider_section]\n"
|
||||
"%s = %s\n\n",
|
||||
prov_name, section)
|
||||
> 0);
|
||||
return BIO_printf(out, "openssl_conf = openssl_init\n\n")
|
||||
&& BIO_printf(out, "[openssl_init]\n")
|
||||
&& BIO_printf(out, "providers = provider_section\n\n")
|
||||
&& BIO_printf(out, "[provider_section]\n")
|
||||
&& BIO_printf(out, "%s = %s\n\n", prov_name, section);
|
||||
}
|
||||
|
||||
/*
|
||||
|
|
@ -385,93 +363,96 @@ static int write_config_header(BIO *out, const char *prov_name,
|
|||
* Returns 1 if the config file is written otherwise it returns 0 on error.
|
||||
*/
|
||||
static int write_config_fips_section(BIO *out, const char *section,
|
||||
unsigned char *module_mac,
|
||||
size_t module_mac_len,
|
||||
const FIPS_OPTS *opts,
|
||||
unsigned char *install_mac,
|
||||
size_t install_mac_len)
|
||||
unsigned char *module_mac,
|
||||
size_t module_mac_len,
|
||||
const FIPS_OPTS *opts,
|
||||
unsigned char *install_mac,
|
||||
size_t install_mac_len)
|
||||
{
|
||||
int ret = 0;
|
||||
|
||||
if (BIO_printf(out, "[%s]\n"
|
||||
"activate = 1\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n"
|
||||
"%s = %s\n",
|
||||
section,
|
||||
OSSL_PROV_FIPS_PARAM_INSTALL_VERSION, VERSION_VAL,
|
||||
OSSL_PROV_FIPS_PARAM_CONDITIONAL_ERRORS, opts->conditional_errors ? "1" : "0",
|
||||
OSSL_PROV_PARAM_SECURITY_CHECKS, opts->security_checks ? "1" : "0",
|
||||
OSSL_PROV_PARAM_HMAC_KEY_CHECK, opts->hmac_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_KMAC_KEY_CHECK, opts->kmac_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_TLS1_PRF_EMS_CHECK, opts->tls_prf_ems_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_NO_SHORT_MAC, opts->no_short_mac ? "1" : "0",
|
||||
OSSL_PROV_PARAM_DRBG_TRUNC_DIGEST, opts->drgb_no_trunc_dgst ? "1" : "0",
|
||||
OSSL_PROV_PARAM_SIGNATURE_DIGEST_CHECK, opts->signature_digest_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_HKDF_DIGEST_CHECK, opts->hkdf_digest_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_TLS13_KDF_DIGEST_CHECK, opts->tls13_kdf_digest_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_TLS1_PRF_DIGEST_CHECK, opts->tls1_prf_digest_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_SSHKDF_DIGEST_CHECK, opts->sshkdf_digest_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_SSKDF_DIGEST_CHECK, opts->sskdf_digest_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_X963KDF_DIGEST_CHECK, opts->x963kdf_digest_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_DSA_SIGN_DISABLED, opts->dsa_sign_disabled ? "1" : "0",
|
||||
OSSL_PROV_PARAM_TDES_ENCRYPT_DISABLED, opts->tdes_encrypt_disabled ? "1" : "0",
|
||||
OSSL_PROV_PARAM_RSA_PKCS15_PAD_DISABLED, opts->rsa_pkcs15_padding_disabled ? "1" : "0",
|
||||
OSSL_PROV_PARAM_RSA_PSS_SALTLEN_CHECK, opts->rsa_pss_saltlen_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_RSA_SIGN_X931_PAD_DISABLED, opts->sign_x931_padding_disabled ? "1" : "0",
|
||||
OSSL_PROV_PARAM_HKDF_KEY_CHECK, opts->hkdf_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_KBKDF_KEY_CHECK, opts->kbkdf_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_TLS13_KDF_KEY_CHECK, opts->tls13_kdf_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_TLS1_PRF_KEY_CHECK, opts->tls1_prf_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_SSHKDF_KEY_CHECK, opts->sshkdf_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_SSKDF_KEY_CHECK, opts->sskdf_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_X963KDF_KEY_CHECK, opts->x963kdf_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_X942KDF_KEY_CHECK, opts->x942kdf_key_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_PBKDF2_LOWER_BOUND_CHECK, opts->pbkdf2_lower_bound_check ? "1" : "0",
|
||||
OSSL_PROV_PARAM_ECDH_COFACTOR_CHECK, opts->ecdh_cofactor_check ? "1" : "0")
|
||||
<= 0
|
||||
if (BIO_printf(out, "[%s]\n", section) <= 0
|
||||
|| BIO_printf(out, "activate = 1\n") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_FIPS_PARAM_INSTALL_VERSION,
|
||||
VERSION_VAL) <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_FIPS_PARAM_CONDITIONAL_ERRORS,
|
||||
opts->conditional_errors ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SECURITY_CHECKS,
|
||||
opts->security_checks ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_HMAC_KEY_CHECK,
|
||||
opts->hmac_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_KMAC_KEY_CHECK,
|
||||
opts->kmac_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_TLS1_PRF_EMS_CHECK,
|
||||
opts->tls_prf_ems_check ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_NO_SHORT_MAC,
|
||||
opts->no_short_mac ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_DRBG_TRUNC_DIGEST,
|
||||
opts->drgb_no_trunc_dgst ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SIGNATURE_DIGEST_CHECK,
|
||||
opts->signature_digest_check ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_HKDF_DIGEST_CHECK,
|
||||
opts->hkdf_digest_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_TLS13_KDF_DIGEST_CHECK,
|
||||
opts->tls13_kdf_digest_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_TLS1_PRF_DIGEST_CHECK,
|
||||
opts->tls1_prf_digest_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_SSHKDF_DIGEST_CHECK,
|
||||
opts->sshkdf_digest_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SSKDF_DIGEST_CHECK,
|
||||
opts->sskdf_digest_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_X963KDF_DIGEST_CHECK,
|
||||
opts->x963kdf_digest_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_DSA_SIGN_DISABLED,
|
||||
opts->dsa_sign_disabled ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_TDES_ENCRYPT_DISABLED,
|
||||
opts->tdes_encrypt_disabled ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_RSA_PKCS15_PAD_DISABLED,
|
||||
opts->rsa_pkcs15_padding_disabled ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_RSA_PSS_SALTLEN_CHECK,
|
||||
opts->rsa_pss_saltlen_check ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_RSA_SIGN_X931_PAD_DISABLED,
|
||||
opts->sign_x931_padding_disabled ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_HKDF_KEY_CHECK,
|
||||
opts->hkdf_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_KBKDF_KEY_CHECK,
|
||||
opts->kbkdf_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_TLS13_KDF_KEY_CHECK,
|
||||
opts->tls13_kdf_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_TLS1_PRF_KEY_CHECK,
|
||||
opts->tls1_prf_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SSHKDF_KEY_CHECK,
|
||||
opts->sshkdf_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_SSKDF_KEY_CHECK,
|
||||
opts->sskdf_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_X963KDF_KEY_CHECK,
|
||||
opts->x963kdf_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_X942KDF_KEY_CHECK,
|
||||
opts->x942kdf_key_check ? "1": "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n",
|
||||
OSSL_PROV_PARAM_PBKDF2_LOWER_BOUND_CHECK,
|
||||
opts->pbkdf2_lower_bound_check ? "1" : "0") <= 0
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_PARAM_ECDH_COFACTOR_CHECK,
|
||||
opts->ecdh_cofactor_check ? "1": "0") <= 0
|
||||
|| !print_mac(out, OSSL_PROV_FIPS_PARAM_MODULE_MAC, module_mac,
|
||||
module_mac_len)
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_FIPS_PARAM_DEFER_TESTS,
|
||||
opts->defer_tests ? "1" : "0")
|
||||
<= 0)
|
||||
module_mac_len))
|
||||
goto end;
|
||||
|
||||
if (install_mac != NULL
|
||||
&& install_mac_len > 0
|
||||
&& opts->self_test_onload == 0) {
|
||||
&& install_mac_len > 0
|
||||
&& opts->self_test_onload == 0) {
|
||||
if (!print_mac(out, OSSL_PROV_FIPS_PARAM_INSTALL_MAC, install_mac,
|
||||
install_mac_len)
|
||||
install_mac_len)
|
||||
|| BIO_printf(out, "%s = %s\n", OSSL_PROV_FIPS_PARAM_INSTALL_STATUS,
|
||||
INSTALL_STATUS_VAL)
|
||||
<= 0)
|
||||
INSTALL_STATUS_VAL) <= 0)
|
||||
goto end;
|
||||
}
|
||||
ret = 1;
|
||||
|
|
@ -480,10 +461,10 @@ end:
|
|||
}
|
||||
|
||||
static CONF *generate_config_and_load(const char *prov_name,
|
||||
const char *section,
|
||||
unsigned char *module_mac,
|
||||
size_t module_mac_len,
|
||||
const FIPS_OPTS *opts)
|
||||
const char *section,
|
||||
unsigned char *module_mac,
|
||||
size_t module_mac_len,
|
||||
const FIPS_OPTS *opts)
|
||||
{
|
||||
BIO *mem_bio = NULL;
|
||||
CONF *conf = NULL;
|
||||
|
|
@ -493,8 +474,8 @@ static CONF *generate_config_and_load(const char *prov_name,
|
|||
return 0;
|
||||
if (!write_config_header(mem_bio, prov_name, section)
|
||||
|| !write_config_fips_section(mem_bio, section,
|
||||
module_mac, module_mac_len,
|
||||
opts, NULL, 0))
|
||||
module_mac, module_mac_len,
|
||||
opts, NULL, 0))
|
||||
goto end;
|
||||
|
||||
conf = app_load_config_bio(mem_bio, NULL);
|
||||
|
|
@ -529,8 +510,8 @@ static int verify_module_load(const char *parent_config_file)
|
|||
* install_mac values, otherwise it returns 0.
|
||||
*/
|
||||
static int verify_config(const char *infile, const char *section,
|
||||
unsigned char *module_mac, size_t module_mac_len,
|
||||
unsigned char *install_mac, size_t install_mac_len)
|
||||
unsigned char *module_mac, size_t module_mac_len,
|
||||
unsigned char *install_mac, size_t install_mac_len)
|
||||
{
|
||||
int ret = 0;
|
||||
char *s = NULL;
|
||||
|
|
@ -545,37 +526,37 @@ static int verify_config(const char *infile, const char *section,
|
|||
|
||||
s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_VERSION);
|
||||
if (s == NULL || strcmp(s, VERSION_VAL) != 0) {
|
||||
BIO_puts(bio_err, "version not found\n");
|
||||
BIO_printf(bio_err, "version not found\n");
|
||||
goto end;
|
||||
}
|
||||
s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_MODULE_MAC);
|
||||
if (s == NULL) {
|
||||
BIO_puts(bio_err, "Module integrity MAC not found\n");
|
||||
BIO_printf(bio_err, "Module integrity MAC not found\n");
|
||||
goto end;
|
||||
}
|
||||
buf1 = OPENSSL_hexstr2buf(s, &len);
|
||||
if (buf1 == NULL
|
||||
|| (size_t)len != module_mac_len
|
||||
|| memcmp(module_mac, buf1, module_mac_len) != 0) {
|
||||
BIO_puts(bio_err, "Module integrity mismatch\n");
|
||||
|| (size_t)len != module_mac_len
|
||||
|| memcmp(module_mac, buf1, module_mac_len) != 0) {
|
||||
BIO_printf(bio_err, "Module integrity mismatch\n");
|
||||
goto end;
|
||||
}
|
||||
if (install_mac != NULL && install_mac_len > 0) {
|
||||
s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_STATUS);
|
||||
if (s == NULL || strcmp(s, INSTALL_STATUS_VAL) != 0) {
|
||||
BIO_puts(bio_err, "install status not found\n");
|
||||
BIO_printf(bio_err, "install status not found\n");
|
||||
goto end;
|
||||
}
|
||||
s = NCONF_get_string(conf, section, OSSL_PROV_FIPS_PARAM_INSTALL_MAC);
|
||||
if (s == NULL) {
|
||||
BIO_puts(bio_err, "Install indicator MAC not found\n");
|
||||
BIO_printf(bio_err, "Install indicator MAC not found\n");
|
||||
goto end;
|
||||
}
|
||||
buf2 = OPENSSL_hexstr2buf(s, &len);
|
||||
if (buf2 == NULL
|
||||
|| (size_t)len != install_mac_len
|
||||
|| memcmp(install_mac, buf2, install_mac_len) != 0) {
|
||||
BIO_puts(bio_err, "Install indicator status mismatch\n");
|
||||
|| (size_t)len != install_mac_len
|
||||
|| memcmp(install_mac, buf2, install_mac_len) != 0) {
|
||||
BIO_printf(bio_err, "Install indicator status mismatch\n");
|
||||
goto end;
|
||||
}
|
||||
}
|
||||
|
|
@ -617,7 +598,7 @@ int fipsinstall_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto cleanup;
|
||||
case OPT_HELP:
|
||||
|
|
@ -775,9 +756,6 @@ int fipsinstall_main(int argc, char **argv)
|
|||
set_selftest_onload_option = 1;
|
||||
fips_opts.self_test_onload = 0;
|
||||
break;
|
||||
case OPT_DEFER_TESTS:
|
||||
fips_opts.defer_tests = 1;
|
||||
break;
|
||||
}
|
||||
}
|
||||
|
||||
|
|
@ -795,7 +773,7 @@ int fipsinstall_main(int argc, char **argv)
|
|||
ret = OSSL_PROVIDER_available(NULL, prov_name) ? 0 : 1;
|
||||
if (!quiet) {
|
||||
BIO_printf(bio_err, "FIPS provider is %s\n",
|
||||
ret == 0 ? "available" : "not available");
|
||||
ret == 0 ? "available" : "not available");
|
||||
}
|
||||
}
|
||||
goto end;
|
||||
|
|
@ -814,8 +792,8 @@ int fipsinstall_main(int argc, char **argv)
|
|||
}
|
||||
|
||||
if (self_test_log
|
||||
|| self_test_corrupt_desc != NULL
|
||||
|| self_test_corrupt_type != NULL)
|
||||
|| self_test_corrupt_desc != NULL
|
||||
|| self_test_corrupt_type != NULL)
|
||||
OSSL_SELF_TEST_set_callback(NULL, self_test_events, NULL);
|
||||
|
||||
/* Use the default FIPS HMAC digest and key if not specified. */
|
||||
|
|
@ -826,7 +804,7 @@ int fipsinstall_main(int argc, char **argv)
|
|||
|
||||
module_bio = bio_open_default(module_fname, 'r', FORMAT_BINARY);
|
||||
if (module_bio == NULL) {
|
||||
BIO_puts(bio_err, "Failed to open module file\n");
|
||||
BIO_printf(bio_err, "Failed to open module file\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -842,19 +820,20 @@ int fipsinstall_main(int argc, char **argv)
|
|||
|
||||
ctx = EVP_MAC_CTX_new(mac);
|
||||
if (ctx == NULL) {
|
||||
BIO_puts(bio_err, "Unable to create MAC CTX for module check\n");
|
||||
BIO_printf(bio_err, "Unable to create MAC CTX for module check\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (opts != NULL) {
|
||||
int ok = 1;
|
||||
OSSL_PARAM *params = app_params_new_from_opts(opts, EVP_MAC_settable_ctx_params(mac));
|
||||
OSSL_PARAM *params =
|
||||
app_params_new_from_opts(opts, EVP_MAC_settable_ctx_params(mac));
|
||||
|
||||
if (params == NULL)
|
||||
goto end;
|
||||
|
||||
if (!EVP_MAC_CTX_set_params(ctx, params)) {
|
||||
BIO_puts(bio_err, "MAC parameter error\n");
|
||||
BIO_printf(bio_err, "MAC parameter error\n");
|
||||
ERR_print_errors(bio_err);
|
||||
ok = 0;
|
||||
}
|
||||
|
|
@ -865,7 +844,7 @@ int fipsinstall_main(int argc, char **argv)
|
|||
|
||||
ctx2 = EVP_MAC_CTX_dup(ctx);
|
||||
if (ctx2 == NULL) {
|
||||
BIO_puts(bio_err, "Unable to create MAC CTX for install indicator\n");
|
||||
BIO_printf(bio_err, "Unable to create MAC CTX for install indicator\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -874,9 +853,9 @@ int fipsinstall_main(int argc, char **argv)
|
|||
|
||||
/* Calculate the MAC for the indicator status - it may not be used */
|
||||
mem_bio = BIO_new_mem_buf((const void *)INSTALL_STATUS_VAL,
|
||||
(int)strlen(INSTALL_STATUS_VAL));
|
||||
strlen(INSTALL_STATUS_VAL));
|
||||
if (mem_bio == NULL) {
|
||||
BIO_puts(bio_err, "Unable to create memory BIO\n");
|
||||
BIO_printf(bio_err, "Unable to create memory BIO\n");
|
||||
goto end;
|
||||
}
|
||||
if (!do_mac(ctx2, read_buffer, mem_bio, install_mac, &install_mac_len))
|
||||
|
|
@ -886,13 +865,13 @@ int fipsinstall_main(int argc, char **argv)
|
|||
if (fips_opts.self_test_onload == 1)
|
||||
install_mac_len = 0;
|
||||
if (!verify_config(in_fname, section_name, module_mac, module_mac_len,
|
||||
install_mac, install_mac_len))
|
||||
install_mac, install_mac_len))
|
||||
goto end;
|
||||
if (!quiet)
|
||||
BIO_puts(bio_err, "VERIFY PASSED\n");
|
||||
BIO_printf(bio_err, "VERIFY PASSED\n");
|
||||
} else {
|
||||
conf = generate_config_and_load(prov_name, section_name, module_mac,
|
||||
module_mac_len, &fips_opts);
|
||||
module_mac_len, &fips_opts);
|
||||
if (conf == NULL)
|
||||
goto end;
|
||||
if (!load_fips_prov_and_run_self_test(prov_name, &is_fips_140_2_prov))
|
||||
|
|
@ -909,19 +888,20 @@ int fipsinstall_main(int argc, char **argv)
|
|||
if (set_selftest_onload_option == 0 && is_fips_140_2_prov)
|
||||
fips_opts.self_test_onload = 0;
|
||||
|
||||
fout = out_fname == NULL ? dup_bio_out(FORMAT_TEXT)
|
||||
: bio_open_default(out_fname, 'w', FORMAT_TEXT);
|
||||
fout =
|
||||
out_fname == NULL ? dup_bio_out(FORMAT_TEXT)
|
||||
: bio_open_default(out_fname, 'w', FORMAT_TEXT);
|
||||
if (fout == NULL) {
|
||||
BIO_puts(bio_err, "Failed to open file\n");
|
||||
BIO_printf(bio_err, "Failed to open file\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
if (!write_config_fips_section(fout, section_name,
|
||||
module_mac, module_mac_len, &fips_opts,
|
||||
install_mac, install_mac_len))
|
||||
module_mac, module_mac_len, &fips_opts,
|
||||
install_mac, install_mac_len))
|
||||
goto end;
|
||||
if (!quiet)
|
||||
BIO_puts(bio_err, "INSTALL PASSED\n");
|
||||
BIO_printf(bio_err, "INSTALL PASSED\n");
|
||||
}
|
||||
|
||||
ret = 0;
|
||||
|
|
@ -971,7 +951,7 @@ static int self_test_events(const OSSL_PARAM params[], void *arg)
|
|||
if (strcmp(phase, OSSL_SELF_TEST_PHASE_START) == 0)
|
||||
BIO_printf(bio_err, "%s : (%s) : ", desc, type);
|
||||
else if (strcmp(phase, OSSL_SELF_TEST_PHASE_PASS) == 0
|
||||
|| strcmp(phase, OSSL_SELF_TEST_PHASE_FAIL) == 0)
|
||||
|| strcmp(phase, OSSL_SELF_TEST_PHASE_FAIL) == 0)
|
||||
BIO_printf(bio_err, "%s\n", phase);
|
||||
}
|
||||
/*
|
||||
|
|
@ -979,13 +959,13 @@ static int self_test_events(const OSSL_PARAM params[], void *arg)
|
|||
* error is returned during the corrupt phase.
|
||||
*/
|
||||
if (strcmp(phase, OSSL_SELF_TEST_PHASE_CORRUPT) == 0
|
||||
&& (self_test_corrupt_desc != NULL
|
||||
|| self_test_corrupt_type != NULL)) {
|
||||
&& (self_test_corrupt_desc != NULL
|
||||
|| self_test_corrupt_type != NULL)) {
|
||||
if (self_test_corrupt_desc != NULL
|
||||
&& strcmp(self_test_corrupt_desc, desc) != 0)
|
||||
&& strcmp(self_test_corrupt_desc, desc) != 0)
|
||||
goto end;
|
||||
if (self_test_corrupt_type != NULL
|
||||
&& strcmp(self_test_corrupt_type, type) != 0)
|
||||
&& strcmp(self_test_corrupt_type, type) != 0)
|
||||
goto end;
|
||||
BIO_printf(bio_err, "%s ", phase);
|
||||
goto err;
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -24,37 +24,36 @@
|
|||
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_OUT,
|
||||
OPT_PASSOUT,
|
||||
OPT_CIPHER,
|
||||
OPT_VERBOSE,
|
||||
OPT_QUIET,
|
||||
OPT_R_ENUM,
|
||||
OPT_PROV_ENUM
|
||||
OPT_OUT, OPT_PASSOUT, OPT_ENGINE, OPT_CIPHER, OPT_VERBOSE, OPT_QUIET,
|
||||
OPT_R_ENUM, OPT_PROV_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS gendsa_options[] = {
|
||||
{ OPT_HELP_STR, 1, '-', "Usage: %s [options] dsaparam-file\n" },
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] dsaparam-file\n"},
|
||||
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine, possibly a hardware device"},
|
||||
#endif
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output the key to the specified file" },
|
||||
{ "passout", OPT_PASSOUT, 's', "Output file pass phrase source" },
|
||||
{"out", OPT_OUT, '>', "Output the key to the specified file"},
|
||||
{"passout", OPT_PASSOUT, 's', "Output file pass phrase source"},
|
||||
OPT_R_OPTIONS,
|
||||
OPT_PROV_OPTIONS,
|
||||
{ "", OPT_CIPHER, '-', "Encrypt the output with any supported cipher" },
|
||||
{ "verbose", OPT_VERBOSE, '-', "Verbose output" },
|
||||
{ "quiet", OPT_QUIET, '-', "Terse output" },
|
||||
{"", OPT_CIPHER, '-', "Encrypt the output with any supported cipher"},
|
||||
{"verbose", OPT_VERBOSE, '-', "Verbose output"},
|
||||
{"quiet", OPT_QUIET, '-', "Terse output"},
|
||||
|
||||
OPT_PARAMETERS(),
|
||||
{ "dsaparam-file", 0, 0, "File containing DSA parameters" },
|
||||
{ NULL }
|
||||
{"dsaparam-file", 0, 0, "File containing DSA parameters"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int gendsa_main(int argc, char **argv)
|
||||
{
|
||||
ENGINE *e = NULL;
|
||||
BIO *out = NULL, *in = NULL;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
EVP_PKEY_CTX *ctx = NULL;
|
||||
|
|
@ -70,7 +69,7 @@ int gendsa_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -83,6 +82,9 @@ int gendsa_main(int argc, char **argv)
|
|||
case OPT_PASSOUT:
|
||||
passoutarg = opt_arg();
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_R_CASES:
|
||||
if (!opt_rand(o))
|
||||
goto end;
|
||||
|
|
@ -117,7 +119,7 @@ int gendsa_main(int argc, char **argv)
|
|||
private = 1;
|
||||
|
||||
if (!app_passwd(NULL, passoutarg, NULL, &passout)) {
|
||||
BIO_puts(bio_err, "Error getting password\n");
|
||||
BIO_printf(bio_err, "Error getting password\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -130,19 +132,19 @@ int gendsa_main(int argc, char **argv)
|
|||
nbits = EVP_PKEY_get_bits(pkey);
|
||||
if (nbits > OPENSSL_DSA_MAX_MODULUS_BITS)
|
||||
BIO_printf(bio_err,
|
||||
"Warning: It is not recommended to use more than %d bit for DSA keys.\n"
|
||||
" Your key size is %d! Larger key size may behave not as expected.\n",
|
||||
OPENSSL_DSA_MAX_MODULUS_BITS, EVP_PKEY_get_bits(pkey));
|
||||
"Warning: It is not recommended to use more than %d bit for DSA keys.\n"
|
||||
" Your key size is %d! Larger key size may behave not as expected.\n",
|
||||
OPENSSL_DSA_MAX_MODULUS_BITS, EVP_PKEY_get_bits(pkey));
|
||||
|
||||
ctx = EVP_PKEY_CTX_new_from_pkey(app_get0_libctx(), pkey, app_get0_propq());
|
||||
if (ctx == NULL) {
|
||||
BIO_puts(bio_err, "unable to create PKEY context\n");
|
||||
BIO_printf(bio_err, "unable to create PKEY context\n");
|
||||
goto end;
|
||||
}
|
||||
EVP_PKEY_free(pkey);
|
||||
pkey = NULL;
|
||||
if (EVP_PKEY_keygen_init(ctx) <= 0) {
|
||||
BIO_puts(bio_err, "unable to set up for key generation\n");
|
||||
BIO_printf(bio_err, "unable to set up for key generation\n");
|
||||
goto end;
|
||||
}
|
||||
pkey = app_keygen(ctx, "DSA", nbits, verbose);
|
||||
|
|
@ -151,19 +153,20 @@ int gendsa_main(int argc, char **argv)
|
|||
|
||||
assert(private);
|
||||
if (!PEM_write_bio_PrivateKey(out, pkey, enc, NULL, 0, NULL, passout)) {
|
||||
BIO_puts(bio_err, "unable to output generated key\n");
|
||||
BIO_printf(bio_err, "unable to output generated key\n");
|
||||
goto end;
|
||||
}
|
||||
ret = 0;
|
||||
end:
|
||||
end:
|
||||
if (ret != 0)
|
||||
ERR_print_errors(bio_err);
|
||||
end2:
|
||||
end2:
|
||||
BIO_free(in);
|
||||
BIO_free_all(out);
|
||||
EVP_PKEY_free(pkey);
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
EVP_CIPHER_free(enc);
|
||||
release_engine(e);
|
||||
OPENSSL_free(passout);
|
||||
return ret;
|
||||
}
|
||||
|
|
|
|||
150
apps/genpkey.c
150
apps/genpkey.c
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 2006-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 2006-2025 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -15,58 +15,48 @@
|
|||
#include <openssl/err.h>
|
||||
#include <openssl/evp.h>
|
||||
|
||||
static int verbose = 0;
|
||||
static int verbose = 1;
|
||||
|
||||
static int init_keygen_file(EVP_PKEY_CTX **pctx, const char *file,
|
||||
OSSL_LIB_CTX *libctx, const char *propq);
|
||||
static int init_keygen_file(EVP_PKEY_CTX **pctx, const char *file, ENGINE *e,
|
||||
OSSL_LIB_CTX *libctx, const char *propq);
|
||||
typedef enum OPTION_choice {
|
||||
OPT_COMMON,
|
||||
OPT_OUTFORM,
|
||||
OPT_ENCOPT,
|
||||
OPT_OUT,
|
||||
OPT_PASS,
|
||||
OPT_PARAMFILE,
|
||||
OPT_ALGORITHM,
|
||||
OPT_PKEYOPT,
|
||||
OPT_GENPARAM,
|
||||
OPT_TEXT,
|
||||
OPT_CIPHER,
|
||||
OPT_VERBOSE,
|
||||
OPT_QUIET,
|
||||
OPT_CONFIG,
|
||||
OPT_OUTPUBKEY,
|
||||
OPT_PROV_ENUM,
|
||||
OPT_R_ENUM
|
||||
OPT_ENGINE, OPT_OUTFORM, OPT_OUT, OPT_PASS, OPT_PARAMFILE,
|
||||
OPT_ALGORITHM, OPT_PKEYOPT, OPT_GENPARAM, OPT_TEXT, OPT_CIPHER,
|
||||
OPT_VERBOSE, OPT_QUIET, OPT_CONFIG, OPT_OUTPUBKEY,
|
||||
OPT_PROV_ENUM, OPT_R_ENUM
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS genpkey_options[] = {
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{ "paramfile", OPT_PARAMFILE, '<', "Parameters file" },
|
||||
{ "algorithm", OPT_ALGORITHM, 's', "The public key algorithm" },
|
||||
{ "verbose", OPT_VERBOSE, '-', "Output status while generating keys" },
|
||||
{ "quiet", OPT_QUIET, '-', "Do not output status while generating keys" },
|
||||
{ "pkeyopt", OPT_PKEYOPT, 's',
|
||||
"Set the public key algorithm option as opt:value" },
|
||||
OPT_CONFIG_OPTION,
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine, possibly a hardware device"},
|
||||
#endif
|
||||
{"paramfile", OPT_PARAMFILE, '<', "Parameters file"},
|
||||
{"algorithm", OPT_ALGORITHM, 's', "The public key algorithm"},
|
||||
{"verbose", OPT_VERBOSE, '-', "Output status while generating keys"},
|
||||
{"quiet", OPT_QUIET, '-', "Do not output status while generating keys"},
|
||||
{"pkeyopt", OPT_PKEYOPT, 's',
|
||||
"Set the public key algorithm option as opt:value"},
|
||||
OPT_CONFIG_OPTION,
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output (private key) file" },
|
||||
{ "outpubkey", OPT_OUTPUBKEY, '>', "Output public key file" },
|
||||
{ "outform", OPT_OUTFORM, 'F', "output format (DER or PEM)" },
|
||||
{ "encopt", OPT_ENCOPT, 's', "Private key encoder parameter" },
|
||||
{ "pass", OPT_PASS, 's', "Output file pass phrase source" },
|
||||
{ "genparam", OPT_GENPARAM, '-', "Generate parameters, not key" },
|
||||
{ "text", OPT_TEXT, '-', "Print the private key in text" },
|
||||
{ "", OPT_CIPHER, '-', "Cipher to use to encrypt the key" },
|
||||
{"out", OPT_OUT, '>', "Output (private key) file"},
|
||||
{"outpubkey", OPT_OUTPUBKEY, '>', "Output public key file"},
|
||||
{"outform", OPT_OUTFORM, 'F', "output format (DER or PEM)"},
|
||||
{"pass", OPT_PASS, 's', "Output file pass phrase source"},
|
||||
{"genparam", OPT_GENPARAM, '-', "Generate parameters, not key"},
|
||||
{"text", OPT_TEXT, '-', "Print the private key in text"},
|
||||
{"", OPT_CIPHER, '-', "Cipher to use to encrypt the key"},
|
||||
|
||||
OPT_PROV_OPTIONS,
|
||||
OPT_R_OPTIONS,
|
||||
|
||||
/* This is deliberately last. */
|
||||
{ OPT_HELP_STR, 1, 1,
|
||||
"Order of options may be important! See the documentation.\n" },
|
||||
{ NULL }
|
||||
{OPT_HELP_STR, 1, 1,
|
||||
"Order of options may be important! See the documentation.\n"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
static const char *param_datatype_2name(unsigned int type, int *ishex)
|
||||
|
|
@ -74,17 +64,11 @@ static const char *param_datatype_2name(unsigned int type, int *ishex)
|
|||
*ishex = 0;
|
||||
|
||||
switch (type) {
|
||||
case OSSL_PARAM_INTEGER:
|
||||
return "int";
|
||||
case OSSL_PARAM_UNSIGNED_INTEGER:
|
||||
return "uint";
|
||||
case OSSL_PARAM_REAL:
|
||||
return "float";
|
||||
case OSSL_PARAM_OCTET_STRING:
|
||||
*ishex = 1;
|
||||
return "string";
|
||||
case OSSL_PARAM_UTF8_STRING:
|
||||
return "string";
|
||||
case OSSL_PARAM_INTEGER: return "int";
|
||||
case OSSL_PARAM_UNSIGNED_INTEGER: return "uint";
|
||||
case OSSL_PARAM_REAL: return "float";
|
||||
case OSSL_PARAM_OCTET_STRING: *ishex = 1; return "string";
|
||||
case OSSL_PARAM_UTF8_STRING: return "string";
|
||||
default:
|
||||
return NULL;
|
||||
}
|
||||
|
|
@ -108,7 +92,7 @@ static void show_gen_pkeyopt(const char *algname, OSSL_LIB_CTX *libctx, const ch
|
|||
if (params == NULL)
|
||||
goto cleanup;
|
||||
|
||||
BIO_puts(bio_err, "\nThe possible -pkeyopt arguments are:\n");
|
||||
BIO_printf(bio_err, "\nThe possible -pkeyopt arguments are:\n");
|
||||
for (i = 0; params[i].key != NULL; ++i) {
|
||||
const char *name = param_datatype_2name(params[i].data_type, &ishex);
|
||||
|
||||
|
|
@ -123,6 +107,7 @@ int genpkey_main(int argc, char **argv)
|
|||
{
|
||||
CONF *conf = NULL;
|
||||
BIO *mem_out = NULL, *mem_outpubkey = NULL;
|
||||
ENGINE *e = NULL;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
EVP_PKEY_CTX *ctx = NULL;
|
||||
char *outfile = NULL, *passarg = NULL, *pass = NULL, *prog, *p;
|
||||
|
|
@ -132,7 +117,6 @@ int genpkey_main(int argc, char **argv)
|
|||
OPTION_CHOICE o;
|
||||
int outformat = FORMAT_PEM, text = 0, ret = 1, rv, do_param = 0;
|
||||
int private = 0, i;
|
||||
STACK_OF(OPENSSL_STRING) *encopt = NULL;
|
||||
OSSL_LIB_CTX *libctx = app_get0_libctx();
|
||||
STACK_OF(OPENSSL_STRING) *keyopt = NULL;
|
||||
|
||||
|
|
@ -145,7 +129,7 @@ int genpkey_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -157,12 +141,6 @@ int genpkey_main(int argc, char **argv)
|
|||
if (!opt_format(opt_arg(), OPT_FMT_PEMDER, &outformat))
|
||||
goto opthelp;
|
||||
break;
|
||||
case OPT_ENCOPT:
|
||||
if (encopt == NULL)
|
||||
encopt = sk_OPENSSL_STRING_new_null();
|
||||
if (!sk_OPENSSL_STRING_push(encopt, opt_arg()))
|
||||
goto end;
|
||||
break;
|
||||
case OPT_OUT:
|
||||
outfile = opt_arg();
|
||||
break;
|
||||
|
|
@ -172,6 +150,9 @@ int genpkey_main(int argc, char **argv)
|
|||
case OPT_PASS:
|
||||
passarg = opt_arg();
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
e = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_PARAMFILE:
|
||||
if (do_param == 1)
|
||||
goto opthelp;
|
||||
|
|
@ -224,11 +205,11 @@ int genpkey_main(int argc, char **argv)
|
|||
|
||||
/* Fetch cipher, etc. */
|
||||
if (paramfile != NULL) {
|
||||
if (!init_keygen_file(&ctx, paramfile, libctx, app_get0_propq()))
|
||||
if (!init_keygen_file(&ctx, paramfile, e, libctx, app_get0_propq()))
|
||||
goto end;
|
||||
}
|
||||
if (algname != NULL) {
|
||||
if (!init_gen_str(&ctx, algname, do_param, libctx, app_get0_propq()))
|
||||
if (!init_gen_str(&ctx, algname, e, do_param, libctx, app_get0_propq()))
|
||||
goto end;
|
||||
}
|
||||
if (ctx == NULL)
|
||||
|
|
@ -245,7 +226,7 @@ int genpkey_main(int argc, char **argv)
|
|||
if (!opt_cipher(ciphername, &cipher))
|
||||
goto opthelp;
|
||||
if (ciphername != NULL && do_param == 1) {
|
||||
BIO_puts(bio_err, "Cannot use cipher with -genparam option\n");
|
||||
BIO_printf(bio_err, "Cannot use cipher with -genparam option\n");
|
||||
goto opthelp;
|
||||
}
|
||||
|
||||
|
|
@ -273,7 +254,7 @@ int genpkey_main(int argc, char **argv)
|
|||
EVP_PKEY_CTX_set_app_data(ctx, bio_err);
|
||||
|
||||
pkey = do_param ? app_paramgen(ctx, algname)
|
||||
: app_keygen(ctx, algname, 0, verbose);
|
||||
: app_keygen(ctx, algname, 0, 0 /* not verbose */);
|
||||
if (pkey == NULL)
|
||||
goto end;
|
||||
|
||||
|
|
@ -281,16 +262,16 @@ int genpkey_main(int argc, char **argv)
|
|||
rv = PEM_write_bio_Parameters(mem_out, pkey);
|
||||
} else if (outformat == FORMAT_PEM) {
|
||||
assert(private);
|
||||
rv = encode_private_key(mem_out, "PEM", pkey, encopt, cipher, pass);
|
||||
rv = PEM_write_bio_PrivateKey(mem_out, pkey, cipher, NULL, 0, NULL, pass);
|
||||
if (rv > 0 && mem_outpubkey != NULL)
|
||||
rv = PEM_write_bio_PUBKEY(mem_outpubkey, pkey);
|
||||
} else if (outformat == FORMAT_ASN1) {
|
||||
assert(private);
|
||||
rv = encode_private_key(mem_out, "DER", pkey, encopt, cipher, pass);
|
||||
rv = i2d_PrivateKey_bio(mem_out, pkey);
|
||||
if (rv > 0 && mem_outpubkey != NULL)
|
||||
rv = i2d_PUBKEY_bio(mem_outpubkey, pkey);
|
||||
} else {
|
||||
BIO_puts(bio_err, "Bad format specified for key\n");
|
||||
BIO_printf(bio_err, "Bad format specified for key\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -313,7 +294,7 @@ int genpkey_main(int argc, char **argv)
|
|||
}
|
||||
}
|
||||
|
||||
end:
|
||||
end:
|
||||
sk_OPENSSL_STRING_free(keyopt);
|
||||
if (ret != 0) {
|
||||
ERR_print_errors(bio_err);
|
||||
|
|
@ -321,29 +302,27 @@ end:
|
|||
if (mem_outpubkey != NULL) {
|
||||
rv = mem_bio_to_file(mem_outpubkey, outpubkeyfile, outformat, private);
|
||||
if (!rv)
|
||||
BIO_printf(bio_err, "Error writing to outpubkey: '%s'. Error: %s\n",
|
||||
outpubkeyfile, strerror(errno));
|
||||
BIO_printf(bio_err, "Error writing to outpubkey: '%s'. Error: %s\n", outpubkeyfile, strerror(errno));
|
||||
}
|
||||
if (mem_out != NULL) {
|
||||
rv = mem_bio_to_file(mem_out, outfile, outformat, private);
|
||||
if (!rv)
|
||||
BIO_printf(bio_err, "Error writing to outfile: '%s'. Error: %s\n",
|
||||
outfile, strerror(errno));
|
||||
BIO_printf(bio_err, "Error writing to outfile: '%s'. Error: %s\n", outpubkeyfile, strerror(errno));
|
||||
}
|
||||
}
|
||||
sk_OPENSSL_STRING_free(encopt);
|
||||
EVP_PKEY_free(pkey);
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
EVP_CIPHER_free(cipher);
|
||||
BIO_free_all(mem_out);
|
||||
BIO_free_all(mem_outpubkey);
|
||||
release_engine(e);
|
||||
OPENSSL_free(pass);
|
||||
NCONF_free(conf);
|
||||
return ret;
|
||||
}
|
||||
|
||||
static int init_keygen_file(EVP_PKEY_CTX **pctx, const char *file,
|
||||
OSSL_LIB_CTX *libctx, const char *propq)
|
||||
static int init_keygen_file(EVP_PKEY_CTX **pctx, const char *file, ENGINE *e,
|
||||
OSSL_LIB_CTX *libctx, const char *propq)
|
||||
{
|
||||
BIO *pbio;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
|
|
@ -367,7 +346,10 @@ static int init_keygen_file(EVP_PKEY_CTX **pctx, const char *file,
|
|||
return 0;
|
||||
}
|
||||
|
||||
ctx = EVP_PKEY_CTX_new_from_pkey(libctx, pkey, propq);
|
||||
if (e != NULL)
|
||||
ctx = EVP_PKEY_CTX_new(pkey, e);
|
||||
else
|
||||
ctx = EVP_PKEY_CTX_new_from_pkey(libctx, pkey, propq);
|
||||
if (ctx == NULL)
|
||||
goto err;
|
||||
if (EVP_PKEY_keygen_init(ctx) <= 0)
|
||||
|
|
@ -376,26 +358,32 @@ static int init_keygen_file(EVP_PKEY_CTX **pctx, const char *file,
|
|||
*pctx = ctx;
|
||||
return 1;
|
||||
|
||||
err:
|
||||
err:
|
||||
BIO_puts(bio_err, "Error initializing context\n");
|
||||
ERR_print_errors(bio_err);
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
EVP_PKEY_free(pkey);
|
||||
return 0;
|
||||
|
||||
}
|
||||
|
||||
int init_gen_str(EVP_PKEY_CTX **pctx,
|
||||
const char *algname, int do_param,
|
||||
OSSL_LIB_CTX *libctx, const char *propq)
|
||||
const char *algname, ENGINE *e, int do_param,
|
||||
OSSL_LIB_CTX *libctx, const char *propq)
|
||||
{
|
||||
EVP_PKEY_CTX *ctx = NULL;
|
||||
int pkey_id;
|
||||
|
||||
if (*pctx) {
|
||||
BIO_puts(bio_err, "Algorithm already set!\n");
|
||||
return 0;
|
||||
}
|
||||
|
||||
ctx = EVP_PKEY_CTX_new_from_name(libctx, algname, propq);
|
||||
pkey_id = get_legacy_pkey_id(libctx, algname, e);
|
||||
if (pkey_id != NID_undef)
|
||||
ctx = EVP_PKEY_CTX_new_id(pkey_id, e);
|
||||
else
|
||||
ctx = EVP_PKEY_CTX_new_from_name(libctx, algname, propq);
|
||||
|
||||
if (ctx == NULL)
|
||||
goto err;
|
||||
|
|
@ -410,9 +398,11 @@ int init_gen_str(EVP_PKEY_CTX **pctx,
|
|||
*pctx = ctx;
|
||||
return 1;
|
||||
|
||||
err:
|
||||
err:
|
||||
BIO_printf(bio_err, "Error initializing %s context\n", algname);
|
||||
ERR_print_errors(bio_err);
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
return 0;
|
||||
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -1,5 +1,5 @@
|
|||
/*
|
||||
* Copyright 1995-2026 The OpenSSL Project Authors. All Rights Reserved.
|
||||
* Copyright 1995-2023 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
|
|
@ -34,52 +34,49 @@ typedef enum OPTION_choice {
|
|||
#ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
OPT_3,
|
||||
#endif
|
||||
OPT_F4,
|
||||
OPT_OUT,
|
||||
OPT_PASSOUT,
|
||||
OPT_CIPHER,
|
||||
OPT_PRIMES,
|
||||
OPT_VERBOSE,
|
||||
OPT_QUIET,
|
||||
OPT_R_ENUM,
|
||||
OPT_PROV_ENUM,
|
||||
OPT_TRADITIONAL
|
||||
OPT_F4, OPT_ENGINE,
|
||||
OPT_OUT, OPT_PASSOUT, OPT_CIPHER, OPT_PRIMES, OPT_VERBOSE, OPT_QUIET,
|
||||
OPT_R_ENUM, OPT_PROV_ENUM, OPT_TRADITIONAL
|
||||
} OPTION_CHOICE;
|
||||
|
||||
const OPTIONS genrsa_options[] = {
|
||||
{ OPT_HELP_STR, 1, '-', "Usage: %s [options] numbits\n" },
|
||||
{OPT_HELP_STR, 1, '-', "Usage: %s [options] numbits\n"},
|
||||
|
||||
OPT_SECTION("General"),
|
||||
{ "help", OPT_HELP, '-', "Display this summary" },
|
||||
{"help", OPT_HELP, '-', "Display this summary"},
|
||||
#ifndef OPENSSL_NO_ENGINE
|
||||
{"engine", OPT_ENGINE, 's', "Use engine, possibly a hardware device"},
|
||||
#endif
|
||||
|
||||
OPT_SECTION("Input"),
|
||||
#ifndef OPENSSL_NO_DEPRECATED_3_0
|
||||
{ "3", OPT_3, '-', "(deprecated) Use 3 for the E value" },
|
||||
{"3", OPT_3, '-', "(deprecated) Use 3 for the E value"},
|
||||
#endif
|
||||
{ "F4", OPT_F4, '-', "Use the Fermat number F4 (0x10001) for the E value" },
|
||||
{ "f4", OPT_F4, '-', "Use the Fermat number F4 (0x10001) for the E value" },
|
||||
{"F4", OPT_F4, '-', "Use the Fermat number F4 (0x10001) for the E value"},
|
||||
{"f4", OPT_F4, '-', "Use the Fermat number F4 (0x10001) for the E value"},
|
||||
|
||||
OPT_SECTION("Output"),
|
||||
{ "out", OPT_OUT, '>', "Output the key to specified file" },
|
||||
{ "passout", OPT_PASSOUT, 's', "Output file pass phrase source" },
|
||||
{ "primes", OPT_PRIMES, 'p', "Specify number of primes" },
|
||||
{ "verbose", OPT_VERBOSE, '-', "Verbose output" },
|
||||
{ "quiet", OPT_QUIET, '-', "Terse output" },
|
||||
{ "traditional", OPT_TRADITIONAL, '-',
|
||||
"Use traditional format for private keys" },
|
||||
{ "", OPT_CIPHER, '-', "Encrypt the output with any supported cipher" },
|
||||
{"out", OPT_OUT, '>', "Output the key to specified file"},
|
||||
{"passout", OPT_PASSOUT, 's', "Output file pass phrase source"},
|
||||
{"primes", OPT_PRIMES, 'p', "Specify number of primes"},
|
||||
{"verbose", OPT_VERBOSE, '-', "Verbose output"},
|
||||
{"quiet", OPT_QUIET, '-', "Terse output"},
|
||||
{"traditional", OPT_TRADITIONAL, '-',
|
||||
"Use traditional format for private keys"},
|
||||
{"", OPT_CIPHER, '-', "Encrypt the output with any supported cipher"},
|
||||
|
||||
OPT_R_OPTIONS,
|
||||
OPT_PROV_OPTIONS,
|
||||
|
||||
OPT_PARAMETERS(),
|
||||
{ "numbits", 0, 0, "Size of key in bits" },
|
||||
{ NULL }
|
||||
{"numbits", 0, 0, "Size of key in bits"},
|
||||
{NULL}
|
||||
};
|
||||
|
||||
int genrsa_main(int argc, char **argv)
|
||||
{
|
||||
BN_GENCB *cb = BN_GENCB_new();
|
||||
ENGINE *eng = NULL;
|
||||
BIGNUM *bn = BN_new();
|
||||
BIO *out = NULL;
|
||||
EVP_PKEY *pkey = NULL;
|
||||
|
|
@ -101,7 +98,7 @@ int genrsa_main(int argc, char **argv)
|
|||
switch (o) {
|
||||
case OPT_EOF:
|
||||
case OPT_ERR:
|
||||
opthelp:
|
||||
opthelp:
|
||||
BIO_printf(bio_err, "%s: Use -help for summary.\n", prog);
|
||||
goto end;
|
||||
case OPT_HELP:
|
||||
|
|
@ -119,6 +116,9 @@ int genrsa_main(int argc, char **argv)
|
|||
case OPT_OUT:
|
||||
outfile = opt_arg();
|
||||
break;
|
||||
case OPT_ENGINE:
|
||||
eng = setup_engine(opt_arg(), 0);
|
||||
break;
|
||||
case OPT_R_CASES:
|
||||
if (!opt_rand(o))
|
||||
goto end;
|
||||
|
|
@ -157,9 +157,9 @@ int genrsa_main(int argc, char **argv)
|
|||
goto end;
|
||||
if (num > OPENSSL_RSA_MAX_MODULUS_BITS)
|
||||
BIO_printf(bio_err,
|
||||
"Warning: It is not recommended to use more than %d bit for RSA keys.\n"
|
||||
" Your key size is %d! Larger key size may behave not as expected.\n",
|
||||
OPENSSL_RSA_MAX_MODULUS_BITS, num);
|
||||
"Warning: It is not recommended to use more than %d bit for RSA keys.\n"
|
||||
" Your key size is %d! Larger key size may behave not as expected.\n",
|
||||
OPENSSL_RSA_MAX_MODULUS_BITS, num);
|
||||
} else if (!opt_check_rest_arg(NULL)) {
|
||||
goto opthelp;
|
||||
}
|
||||
|
|
@ -171,7 +171,7 @@ int genrsa_main(int argc, char **argv)
|
|||
if (!opt_cipher(ciphername, &enc))
|
||||
goto end;
|
||||
if (!app_passwd(NULL, passoutarg, NULL, &passout)) {
|
||||
BIO_puts(bio_err, "Error getting password\n");
|
||||
BIO_printf(bio_err, "Error getting password\n");
|
||||
goto end;
|
||||
}
|
||||
|
||||
|
|
@ -179,8 +179,8 @@ int genrsa_main(int argc, char **argv)
|
|||
if (out == NULL)
|
||||
goto end;
|
||||
|
||||
if (!init_gen_str(&ctx, "RSA", 0, app_get0_libctx(),
|
||||
app_get0_propq()))
|
||||
if (!init_gen_str(&ctx, "RSA", eng, 0, app_get0_libctx(),
|
||||
app_get0_propq()))
|
||||
goto end;
|
||||
|
||||
if (verbose)
|
||||
|
|
@ -188,19 +188,19 @@ int genrsa_main(int argc, char **argv)
|
|||
EVP_PKEY_CTX_set_app_data(ctx, bio_err);
|
||||
|
||||
if (EVP_PKEY_CTX_set_rsa_keygen_bits(ctx, num) <= 0) {
|
||||
BIO_puts(bio_err, "Error setting RSA length\n");
|
||||
BIO_printf(bio_err, "Error setting RSA length\n");
|
||||
goto end;
|
||||
}
|
||||
if (!BN_set_word(bn, f4)) {
|
||||
BIO_puts(bio_err, "Error allocating RSA public exponent\n");
|
||||
BIO_printf(bio_err, "Error allocating RSA public exponent\n");
|
||||
goto end;
|
||||
}
|
||||
if (EVP_PKEY_CTX_set1_rsa_keygen_pubexp(ctx, bn) <= 0) {
|
||||
BIO_puts(bio_err, "Error setting RSA public exponent\n");
|
||||
BIO_printf(bio_err, "Error setting RSA public exponent\n");
|
||||
goto end;
|
||||
}
|
||||
if (EVP_PKEY_CTX_set_rsa_keygen_primes(ctx, primes) <= 0) {
|
||||
BIO_puts(bio_err, "Error setting number of primes\n");
|
||||
BIO_printf(bio_err, "Error setting number of primes\n");
|
||||
goto end;
|
||||
}
|
||||
pkey = app_keygen(ctx, "RSA", num, verbose);
|
||||
|
|
@ -213,7 +213,7 @@ int genrsa_main(int argc, char **argv)
|
|||
/* Every RSA key has an 'e' */
|
||||
EVP_PKEY_get_bn_param(pkey, "e", &e);
|
||||
if (e == NULL) {
|
||||
BIO_puts(bio_err, "Error cannot access RSA e\n");
|
||||
BIO_printf(bio_err, "Error cannot access RSA e\n");
|
||||
goto end;
|
||||
}
|
||||
hexe = BN_bn2hex(e);
|
||||
|
|
@ -227,7 +227,7 @@ int genrsa_main(int argc, char **argv)
|
|||
}
|
||||
if (traditional) {
|
||||
if (!PEM_write_bio_PrivateKey_traditional(out, pkey, enc, NULL, 0,
|
||||
NULL, passout))
|
||||
NULL, passout))
|
||||
goto end;
|
||||
} else {
|
||||
if (!PEM_write_bio_PrivateKey(out, pkey, enc, NULL, 0, NULL, passout))
|
||||
|
|
@ -235,15 +235,17 @@ int genrsa_main(int argc, char **argv)
|
|||
}
|
||||
|
||||
ret = 0;
|
||||
end:
|
||||
end:
|
||||
BN_free(bn);
|
||||
BN_GENCB_free(cb);
|
||||
EVP_PKEY_CTX_free(ctx);
|
||||
EVP_PKEY_free(pkey);
|
||||
EVP_CIPHER_free(enc);
|
||||
BIO_free_all(out);
|
||||
release_engine(eng);
|
||||
OPENSSL_free(passout);
|
||||
if (ret != 0)
|
||||
ERR_print_errors(bio_err);
|
||||
return ret;
|
||||
}
|
||||
|
||||
|
|
|
|||
|
|
@ -8,9 +8,9 @@
|
|||
*/
|
||||
|
||||
#ifndef OSSL_APPS_LIBCTX_H
|
||||
#define OSSL_APPS_LIBCTX_H
|
||||
# define OSSL_APPS_LIBCTX_H
|
||||
|
||||
#include <openssl/types.h>
|
||||
# include <openssl/types.h>
|
||||
|
||||
OSSL_LIB_CTX *app_create_libctx(void);
|
||||
OSSL_LIB_CTX *app_get0_libctx(void);
|
||||
|
|
|
|||
Some files were not shown because too many files have changed in this diff Show more
Loading…
Add table
Add a link
Reference in a new issue