Opened 4 months ago
Closed 4 months ago
#23330 closed enhancement (fixed)
Openssl-4 fixes
| Reported by: | pierre | Owned by: | blfs-book |
|---|---|---|---|
| Priority: | normal | Milestone: | 13.1 |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description (last modified by )
In LFS ticket #5912, a list of packages affected by the move to Openssl-4 has been given. Since then, a few of those packages have been fixed, but not all. I propose to maintain this list here, striking over already treated packages:
opensshgit(new version)sudo(commit 67cf4c4e12)systemd(commit db7234d5ffcc)rustc(commit 8314b3388)cargo-c(new version)lynxlibarchivecryptsetupneonpython(commit 618a288aaa3)libnvmepipewirepulseaudiolibeventcupsgst-plugins-bad(tests marked as known to fail at 8aca372)qca(commit 073fa0ea96)urllib3(tests disabled at 60f66bb5dd241)mariadb(see #23282)nmap(see #23297)wget(commit f8042eccd5)Qt6(commit 64869dc7 and commit 6306e3fc - needed patch and removal of qtopcua submodule)openldap(commit 4e4ff408c5)krb5(commit e2aa8bdc2b5)ruby(commit b2119fac7b9)Net::SSLeay(commit 2deda56c8)apache(commit 8aec0a06ae to patches and 23383f0c67 to blfs)serf(commit 58eaa1b756)wpa_supplicant(commit fc9446d769d6)IO::Socket::SSL(commit 34eba49aab)libssh2(seems to work (PL))python-3.11(commit 0f4ffb963389c)ntp(commit 425d82c4ea)mutt(commit 6fab265f21)bind(updated at commit aba6910d61)
Change History (43)
comment:1 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:2 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:3 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:4 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:5 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:6 by , 4 months ago
| Description: | modified (diff) |
|---|
Marked OpenSSH, lynx, libarchive, cryptsetup, neon, libnvme, pipewire, pulseaudio, libevent, and CUPS as good. I've done a pretty complete Plasma build with some additional packages over on my new workstation during the past week and can confirm these are good.
follow-up: 11 comment:7 by , 4 months ago
I haven't had time to put these in yet with all of the security issues going on, but I do have fixes locally for:
- krb5
- bind/bind-utils
- wpa_supplicant
- OpenLDAP
- Net-SSLeay (update to new version)
- serf
- Ruby
comment:8 by , 4 months ago
| Description: | modified (diff) |
|---|
Note that I marked the affected test as known to fail in gst-plugins-bad.
comment:9 by , 4 months ago
| Description: | modified (diff) |
|---|
Documented fixes required for Qt6 and commits fixed at.
comment:10 by , 4 months ago
| Description: | modified (diff) |
|---|
Just reorganized the description to make it easier to track progress.
comment:11 by , 4 months ago
I do have a local fix for openldap too. And I've made a patch for krb5 (using information from the LFS ticket). May I commit?
comment:13 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:14 by , 4 months ago
| Description: | modified (diff) |
|---|
apache is affected too. Patch at https://github.com/apache/httpd/commit/e340b81301e32c9beaddf3c5da068e31a4bdb2b7
follow-up: 16 comment:15 by , 4 months ago
comment:16 by , 4 months ago
Replying to pierre:
apache needs also https://github.com/apache/httpd/commit/bdea725e483c16e1a6db99d5a4207220018beb1c
We already have httpd-2.4.67-openssl4_fixes-1.patch but it hasn't made it into the book yet. I'll do it.
comment:17 by , 4 months ago
Thanks for the patch. I think the patch is not enough, there are also errors in modules/md/md_ocsp.c
I've made a pull request: https://github.com/apache/httpd/pull/652
follow-ups: 19 20 comment:18 by , 4 months ago
I don't see any reference to 'ocsp' in my apache build log.
comment:19 by , 4 months ago
Replying to Bruce Dubbs:
I don't see any reference to 'ocsp' in my apache build log.
I got an error in the file modules/md/md_ocsp.c
comment:20 by , 4 months ago
Replying to Bruce Dubbs:
I don't see any reference to 'ocsp' in my apache build log.
There is also modules/ssl/ssl_engine_ocsp.c, that we modify in the patch!
comment:21 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:22 by , 4 months ago
| Description: | modified (diff) |
|---|
The mod_md module in apache is only built if jansson and curl are installed.
follow-up: 25 comment:23 by , 4 months ago
Net::SSLeay needs https://github.com/radiator-software/p5-net-ssleay/pull/553 in addition to upgrading to 1.96
comment:24 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:25 by , 4 months ago
Replying to pierre:
Net::SSLeay needs https://github.com/radiator-software/p5-net-ssleay/pull/553 in addition to upgrading to 1.96
Interesting that the patch is not yet incorporated into cpan.
comment:26 by , 4 months ago
| Description: | modified (diff) |
|---|
IO::Socket::SSL has one test failure due to the removal of the TLSv1{,_1,_2}_method functions, that are expected to be present.
Actually Net:SSLeay patch should provide replacements, but it does not seem to work...
comment:27 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:28 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:29 by , 4 months ago
Subversion test "crypto" fails, due to the removal of "ENGINE_xxx" functions in OpenSSL. This is the only test failure (in addition to the already known ones), and it is not due to serf. So I think the serf patch in the SSL ticket is sufficient for serf. (I implemented it with a sed:
sed -e 's/nm->d.ia5->length/ASN1_STRING_length(nm->d.ia5)/' \
-e 's/nm->d.ia5->data/(const char *)ASN1_STRING_get0_data(nm->d.ia5)/' \
-i buckets/ssl_buckets.c
)
comment:30 by , 4 months ago
| Description: | modified (diff) |
|---|
comment:31 by , 4 months ago
Back to Net::SSLeay: one change in the patch requires a version of ExtUtils::ParseXS posterior to the one bundled with perl-5.42.2!
comment:32 by , 4 months ago
For bind, 9.20.23 has the fix for OpenSSL-4. It has also a load of security fixes.
comment:33 by , 4 months ago
| Description: | modified (diff) |
|---|
Changed slightly the patch for Net::SSLeay, so that now the IO::Socket::SSL tests pass.
comment:34 by , 4 months ago
| Description: | modified (diff) |
|---|
curl tests with libssh2 and gssapi enabled worked for me. I think we can remove libssh2 from the list.
comment:35 by , 4 months ago
| Description: | modified (diff) |
|---|
ntp added to the list:
ntp_crypto.c:2035:23: error: invalid use of incomplete typedef ‘ASN1_TIME’ {aka
‘const struct asn1_string_st’}
2035 | len = asn1time->length;
| ^~
ntp_crypto.c:2037:43: error: invalid use of incomplete typedef ‘ASN1_TIME’ {aka
‘const struct asn1_string_st’}
2037 | (void)strncpy(v, (char *)(asn1time->data), len);
etc
comment:36 by , 4 months ago
ntp can be made to build with:
sed -e 's/\([[:alnum:]]*\)->length/ASN1_STRING_length(\1)/' \
-e 's/\([[:alnum:]]*\)->data/ASN1_STRING_get0_data(\1)/' \
-i ntpd/ntp_crypto.c
But there is a more complicated patch upstream: https://bugs.ntp.org/show_bug.cgi?id=4023
comment:37 by , 4 months ago
| Description: | modified (diff) |
|---|
Python-3.11 builds ok, but seamonkey fails with a missing _ssl module.
comment:39 by , 4 months ago
| Description: | modified (diff) |
|---|
mutt also:
mutt_ssl.c: In function ‘check_host’:
mutt_ssl.c:985:33: error: invalid use of incomplete typedef ‘ASN1_IA5STRING’ {aka ‘struct asn1_string_st’}
985 | if (subj_alt_name->d.ia5->length >= 0 &&
| ^~
mutt_ssl.c:986:53: error: invalid use of incomplete typedef ‘ASN1_IA5STRING’ {aka ‘struct asn1_string_st’}
986 | mutt_strlen((char *)subj_alt_name->d.ia5->data) == (size_t)subj_alt_name->d.ia5->length &&
| ^~
mutt_ssl.c:986:92: error: invalid use of incomplete typedef ‘ASN1_IA5STRING’ {aka ‘struct asn1_string_st’}
986 | mutt_strlen((char *)subj_alt_name->d.ia5->data) == (size_t)subj_alt_name->d.ia5->length &&
| ^~
mutt_ssl.c:988:72: error: invalid use of incomplete typedef ‘ASN1_IA5STRING’ {aka ‘struct asn1_string_st’}
988 | (char *)(subj_alt_name->d.ia5->data))))
| ^~
comment:40 by , 4 months ago
| Description: | modified (diff) |
|---|
Made a patch for Python-3.11.1, that allows building the _ssl module and building seamonkey.
comment:43 by , 4 months ago
| Description: | modified (diff) |
|---|---|
| Resolution: | → fixed |
| Status: | new → closed |
Looks like we are done.

cargo-c updated.