source: chapter08/openssl.xml@ 289f284

xry111/loongarch xry111/loongarch-12.1
Last change on this file since 289f284 was 289f284, checked in by Xi Ruoyao <xry111@…>, 5 months ago

Merge remote-tracking branch 'origin/trunk' into xry111/loongarch

  • Property mode set to 100644
File size: 7.3 KB
Line 
1<?xml version="1.0" encoding="UTF-8"?>
2<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4 <!ENTITY % general-entities SYSTEM "../general.ent">
5 %general-entities;
6]>
7
8<sect1 id="ch-system-openssl" role="wrap">
9 <?dbhtml filename="openssl.html"?>
10
11 <sect1info condition="script">
12 <productname>openssl</productname>
13 <productnumber>&openssl-version;</productnumber>
14 <address>&openssl-url;</address>
15 </sect1info>
16
17 <title>OpenSSL-&openssl-version;</title>
18
19 <indexterm zone="ch-system-openssl">
20 <primary sortas="a-OpenSSL">OpenSSL</primary>
21 </indexterm>
22
23 <sect2 role="package">
24 <title/>
25
26 <para>The OpenSSL package contains management tools and libraries relating
27 to cryptography. These are useful for providing cryptographic functions
28 to other packages, such as OpenSSH, email applications, and web browsers
29 (for accessing HTTPS sites). </para>
30
31 <segmentedlist>
32 <segtitle>&buildtime;</segtitle>
33 <segtitle>&diskspace;</segtitle>
34
35 <seglistitem>
36 <seg>&openssl-fin-sbu;</seg>
37 <seg>&openssl-fin-du;</seg>
38 </seglistitem>
39 </segmentedlist>
40
41 </sect2>
42
43 <sect2 role="installation">
44 <title>Installation of OpenSSL</title>
45<!--
46 <para>First fix a problem with some advanced architectures with avx512
47 capability:</para>
48
49 <screen><userinput remap="pre">sed -e '/bn_reduce.*m1/i\ factor_size /= sizeof(BN_ULONG) * 8;' \
50 -i crypto/bn/rsaz_exp_x2.c</userinput></screen>
51-->
52 <para>Prepare OpenSSL for compilation:</para>
53
54<screen><userinput remap="configure">./config --prefix=/usr \
55 --openssldir=/etc/ssl \
56 --libdir=lib \
57 linux64-loongarch64 \
58 shared \
59 zlib-dynamic</userinput></screen>
60
61 <para>Compile the package:</para>
62
63<screen><userinput remap="make">make</userinput></screen>
64
65 <para>To test the results, issue:</para>
66
67<screen><userinput remap="test">HARNESS_JOBS=<replaceable>$(nproc)</replaceable> make test</userinput></screen>
68
69 <para>One test, 30-test_afalg.t, is known to fail if the host kernel
70 does not have <option>CONFIG_CRYPTO_USER_API_SKCIPHER</option> enabled,
71 or does not have any options providing an AES with CBC implementation
72 (for example, the combination of <option>CONFIG_CRYPTO_AES</option>
73 and <option>CONFIG_CRYPTO_CBC</option>, or
74 <option>CONFIG_CRYPTO_AES_NI_INTEL</option> if the CPU supports AES-NI)
75 enabled. If it fails, it can safely be ignored.</para>
76
77 <para>Install the package:</para>
78
79<screen><userinput remap="install">sed -i '/INSTALL_LIBS/s/libcrypto.a libssl.a//' Makefile
80make MANSUFFIX=ssl install</userinput></screen>
81
82 <para>Add the version to the documentation directory name, to be
83 consistent with other packages:</para>
84
85<screen><userinput remap="install">mv -v /usr/share/doc/openssl /usr/share/doc/openssl-&openssl-version;</userinput></screen>
86
87 <para>If desired, install some additional documentation:</para>
88
89<screen><userinput remap="install">cp -vfr doc/* /usr/share/doc/openssl-&openssl-version;</userinput></screen>
90
91 <note>
92 <para>
93 You should update OpenSSL when a new version which fixes vulnerabilities
94 is announced. Since OpenSSL 3.0.0, the OpenSSL versioning scheme
95 follows the MAJOR.MINOR.PATCH format. API/ABI compatibility
96 is guaranteed for the same MAJOR version number. Because LFS
97 installs only the shared libraries, there is no need to recompile
98 packages which link to
99 <filename class="libraryfile">libcrypto.so</filename> or
100 <filename class="libraryfile">libssl.so</filename>
101 <emphasis>when upgrading to a version with the same MAJOR version
102 number</emphasis>.
103 </para>
104
105 <para>
106 However, any running programs linked to those libraries need to be stopped
107 and restarted. Read the related entries in
108 <xref linkend='pkgmgmt-upgrade-issues'/> for details.
109 </para>
110
111 </note>
112
113 </sect2>
114
115 <sect2 id="contents-openssl" role="content">
116 <title>Contents of OpenSSL</title>
117
118 <segmentedlist>
119 <segtitle>Installed programs</segtitle>
120 <segtitle>Installed libraries</segtitle>
121 <segtitle>Installed directories</segtitle>
122
123 <seglistitem>
124 <seg>
125 c_rehash and openssl
126 </seg>
127 <seg>
128 libcrypto.so and libssl.so
129 </seg>
130 <seg>
131 /etc/ssl,
132 /usr/include/openssl,
133 /usr/lib/engines and
134 /usr/share/doc/openssl-&openssl-version;
135 </seg>
136 </seglistitem>
137 </segmentedlist>
138
139 <variablelist>
140 <bridgehead renderas="sect3">Short Descriptions</bridgehead>
141 <?dbfo list-presentation="list"?>
142 <?dbhtml list-presentation="table"?>
143
144 <varlistentry id="c_rehash">
145 <term><command>c_rehash</command></term>
146 <listitem>
147 <para>
148 is a <application>Perl</application> script that
149 scans all files in a directory and adds symbolic links to their
150 hash values. Use of <command>c_rehash</command> is considered
151 obsolete and should be replaced by
152 <command>openssl rehash</command> command
153 </para>
154 <indexterm zone="ch-system-openssl c_rehash">
155 <primary sortas="b-c_rehash">c_rehash</primary>
156 </indexterm>
157 </listitem>
158 </varlistentry>
159
160 <varlistentry id="openssl-prog">
161 <term><command>openssl</command></term>
162 <listitem>
163 <para>
164 is a command-line tool for using the various cryptography functions
165 of <application>OpenSSL</application>'s crypto library from the
166 shell. It can be used for various functions which are documented in
167 <filename>openssl(1)</filename>
168 </para>
169 <indexterm zone="ch-system-openssl openssl-prog">
170 <primary sortas="b-openssl">openssl</primary>
171 </indexterm>
172 </listitem>
173 </varlistentry>
174
175 <varlistentry id="libcrypto">
176 <term><filename class="libraryfile">libcrypto.so</filename></term>
177 <listitem>
178 <para>
179 implements a wide range of cryptographic algorithms used in various
180 Internet standards. The services provided by this library are used
181 by the <application>OpenSSL</application> implementations of SSL,
182 TLS and S/MIME, and they have also been used to implement
183 <application>OpenSSH</application>,
184 <application>OpenPGP</application>, and other cryptographic
185 standards
186 </para>
187 <indexterm zone="ch-system-openssl libcrypto">
188 <primary sortas="c-libcrypto">libcrypto.so</primary>
189 </indexterm>
190 </listitem>
191 </varlistentry>
192
193 <varlistentry id="libssl">
194 <term><filename class="libraryfile">libssl.so</filename></term>
195 <listitem>
196 <para>
197 implements the Transport Layer Security (TLS v1) protocol.
198 It provides a rich API, documentation
199 on which can be found in <filename>ssl(7)</filename>
200 </para>
201 <indexterm zone="ch-system-openssl libssl">
202 <primary sortas="c-libssl">libssl.so</primary>
203 </indexterm>
204 </listitem>
205 </varlistentry>
206
207 </variablelist>
208
209 </sect2>
210
211</sect1>
Note: See TracBrowser for help on using the repository browser.