Opened 4 months ago

Closed 4 months ago

#23330 closed enhancement (fixed)

Openssl-4 fixes

Reported by: pierre Owned by: blfs-book
Priority: normal Milestone: 13.1
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description (last modified by pierre)

In ​LFS ticket #5912, a list of packages affected by the move to Openssl-4 has been given. Since then, a few of those packages have been fixed, but not all. I propose to maintain this list here, striking over already treated packages:

Change History (43)

comment:1 by Xi Ruoyao, 4 months ago

Description: modified (diff)

cargo-c updated.

comment:2 by Xi Ruoyao, 4 months ago

Description: modified (diff)

comment:3 by pierre, 4 months ago

Description: modified (diff)

comment:4 by pierre, 4 months ago

Description: modified (diff)

comment:5 by pierre, 4 months ago

Description: modified (diff)

comment:6 by Douglas R. Reno, 4 months ago

Description: modified (diff)

Marked OpenSSH, lynx, libarchive, cryptsetup, neon, libnvme, pipewire, pulseaudio, libevent, and CUPS as good. I've done a pretty complete Plasma build with some additional packages over on my new workstation during the past week and can confirm these are good.

comment:7 by Douglas R. Reno, 4 months ago

I haven't had time to put these in yet with all of the security issues going on, but I do have fixes locally for:

  • krb5
  • bind/bind-utils
  • wpa_supplicant
  • OpenLDAP
  • Net-SSLeay (update to new version)
  • serf
  • Ruby

comment:8 by Douglas R. Reno, 4 months ago

Description: modified (diff)

Note that I marked the affected test as known to fail in gst-plugins-bad.

comment:9 by Douglas R. Reno, 4 months ago

Description: modified (diff)

Documented fixes required for Qt6 and commits fixed at.

comment:10 by Bruce Dubbs, 4 months ago

Description: modified (diff)

Just reorganized the description to make it easier to track progress.

in reply to:  7 comment:11 by pierre, 4 months ago

I do have a local fix for openldap too. And I've made a patch for krb5 (using information from the LFS ticket). May I commit?

comment:12 by Douglas R. Reno, 4 months ago

Yes please, go for it!

comment:13 by pierre, 4 months ago

Description: modified (diff)

comment:14 by pierre, 4 months ago

Description: modified (diff)

in reply to:  15 comment:16 by Bruce Dubbs, 4 months ago

Replying to pierre:

apache needs also ​https://github.com/apache/httpd/commit/bdea725e483c16e1a6db99d5a4207220018beb1c

We already have httpd-2.4.67-openssl4_fixes-1.patch but it hasn't made it into the book yet. I'll do it.

comment:17 by pierre, 4 months ago

Thanks for the patch. I think the patch is not enough, there are also errors in modules/md/md_ocsp.c

I've made a pull request: ​https://github.com/apache/httpd/pull/652

Last edited 4 months ago by pierre (previous) (diff)

comment:18 by Bruce Dubbs, 4 months ago

I don't see any reference to 'ocsp' in my apache build log.

in reply to:  18 comment:19 by pierre, 4 months ago

Replying to Bruce Dubbs:

I don't see any reference to 'ocsp' in my apache build log.

I got an error in the file modules/md/md_ocsp.c

in reply to:  18 comment:20 by pierre, 4 months ago

Replying to Bruce Dubbs:

I don't see any reference to 'ocsp' in my apache build log.

There is also modules/ssl/ssl_engine_ocsp.c, that we modify in the patch!

comment:21 by Bruce Dubbs, 4 months ago

Description: modified (diff)

comment:22 by pierre, 4 months ago

Description: modified (diff)

The mod_md module in apache is only built if jansson and curl are installed.

comment:23 by pierre, 4 months ago

Net::SSLeay needs ​https://github.com/radiator-software/p5-net-ssleay/pull/553 in addition to upgrading to 1.96

comment:24 by pierre, 4 months ago

Description: modified (diff)

in reply to:  23 comment:25 by Bruce Dubbs, 4 months ago

Replying to pierre:

Net::SSLeay needs ​https://github.com/radiator-software/p5-net-ssleay/pull/553 in addition to upgrading to 1.96

Interesting that the patch is not yet incorporated into cpan.

comment:26 by pierre, 4 months ago

Description: modified (diff)

IO::Socket::SSL has one test failure due to the removal of the TLSv1{,_1,_2}_method functions, that are expected to be present.

Actually Net:SSLeay patch should provide replacements, but it does not seem to work...

Last edited 4 months ago by pierre (previous) (diff)

comment:27 by Bruce Dubbs, 4 months ago

Description: modified (diff)

comment:28 by pierre, 4 months ago

Description: modified (diff)

comment:29 by pierre, 4 months ago

Subversion test "crypto" fails, due to the removal of "ENGINE_xxx" functions in OpenSSL. This is the only test failure (in addition to the already known ones), and it is not due to serf. So I think the serf patch in the SSL ticket is sufficient for serf. (I implemented it with a sed:

sed -e 's/nm->d.ia5->length/ASN1_STRING_length(nm->d.ia5)/' \
    -e 's/nm->d.ia5->data/(const char *)ASN1_STRING_get0_data(nm->d.ia5)/' \
    -i buckets/ssl_buckets.c

)

Last edited 4 months ago by pierre (previous) (diff)

comment:30 by pierre, 4 months ago

Description: modified (diff)

comment:31 by pierre, 4 months ago

Back to Net::SSLeay: one change in the patch requires a version of ExtUtils::ParseXS posterior to the one bundled with perl-5.42.2!

comment:32 by pierre, 4 months ago

For bind, 9.20.23 has the fix for OpenSSL-4. It has also a load of security fixes.

comment:33 by pierre, 4 months ago

Description: modified (diff)

Changed slightly the patch for Net::SSLeay, so that now the IO::Socket::SSL tests pass.

comment:34 by pierre, 4 months ago

Description: modified (diff)

curl tests with libssh2 and gssapi enabled worked for me. I think we can remove libssh2 from the list.

comment:35 by pierre, 4 months ago

Description: modified (diff)

ntp added to the list:

ntp_crypto.c:2035:23: error: invalid use of incomplete typedef ‘ASN1_TIME’ {aka 
‘const struct asn1_string_st’}
 2035 |         len = asn1time->length;
      |                       ^~
ntp_crypto.c:2037:43: error: invalid use of incomplete typedef ‘ASN1_TIME’ {aka 
‘const struct asn1_string_st’}
 2037 |         (void)strncpy(v, (char *)(asn1time->data), len);

etc

comment:36 by pierre, 4 months ago

ntp can be made to build with:

sed -e 's/\([[:alnum:]]*\)->length/ASN1_STRING_length(\1)/'  \
    -e 's/\([[:alnum:]]*\)->data/ASN1_STRING_get0_data(\1)/' \
    -i ntpd/ntp_crypto.c

But there is a more complicated patch upstream: ​https://bugs.ntp.org/show_bug.cgi?id=4023

Last edited 4 months ago by pierre (previous) (diff)

comment:37 by pierre, 4 months ago

Description: modified (diff)

Python-3.11 builds ok, but seamonkey fails with a missing _ssl module.

comment:38 by pierre, 4 months ago

The patch for python-3.14 does not apply cleanly...

comment:39 by pierre, 4 months ago

Description: modified (diff)

mutt also:

mutt_ssl.c: In function ‘check_host’:
mutt_ssl.c:985:33: error: invalid use of incomplete typedef ‘ASN1_IA5STRING’ {aka ‘struct asn1_string_st’}
  985 |         if (subj_alt_name->d.ia5->length >= 0 &&
      |                                 ^~
mutt_ssl.c:986:53: error: invalid use of incomplete typedef ‘ASN1_IA5STRING’ {aka ‘struct asn1_string_st’}
  986 |             mutt_strlen((char *)subj_alt_name->d.ia5->data) == (size_t)subj_alt_name->d.ia5->length &&
      |                                                     ^~
mutt_ssl.c:986:92: error: invalid use of incomplete typedef ‘ASN1_IA5STRING’ {aka ‘struct asn1_string_st’}
  986 |             mutt_strlen((char *)subj_alt_name->d.ia5->data) == (size_t)subj_alt_name->d.ia5->length &&
      |                                                                                            ^~
mutt_ssl.c:988:72: error: invalid use of incomplete typedef ‘ASN1_IA5STRING’ {aka ‘struct asn1_string_st’}
  988 |                                           (char *)(subj_alt_name->d.ia5->data))))
      |                                                                        ^~

comment:40 by pierre, 4 months ago

Description: modified (diff)

Made a patch for Python-3.11.1, that allows building the _ssl module and building seamonkey.

comment:41 by pierre, 4 months ago

Description: modified (diff)

ntp patched.

comment:42 by Joe Locash, 4 months ago

Description: modified (diff)

mutt patched.

comment:43 by pierre, 4 months ago

Description: modified (diff)
Resolution: → fixed
Status: new → closed

Looks like we are done.

Note: See TracTickets for help on using tickets.