source: chapter08/openssl.xml@ 10bc209

multilib
Last change on this file since 10bc209 was c931e9d, checked in by Thomas Trepl <thomas@…>, 10 months ago

Automatic merge of trunk into multilib

  • Property mode set to 100644
File size: 9.0 KB
Line 
1<?xml version="1.0" encoding="ISO-8859-1"?>
2<!DOCTYPE sect1 PUBLIC "-//OASIS//DTD DocBook XML V4.5//EN"
3 "http://www.oasis-open.org/docbook/xml/4.5/docbookx.dtd" [
4 <!ENTITY % general-entities SYSTEM "../general.ent">
5 %general-entities;
6]>
7
8<sect1 id="ch-system-openssl" role="wrap">
9 <?dbhtml filename="openssl.html"?>
10
11 <sect1info condition="script">
12 <productname>openssl</productname>
13 <productnumber>&openssl-version;</productnumber>
14 <address>&openssl-url;</address>
15 </sect1info>
16
17 <title>OpenSSL-&openssl-version;</title>
18
19 <indexterm zone="ch-system-openssl">
20 <primary sortas="a-OpenSSL">OpenSSL</primary>
21 </indexterm>
22
23 <sect2 role="package">
24 <title/>
25
26 <para>The OpenSSL package contains management tools and libraries relating
27 to cryptography. These are useful for providing cryptographic functions
28 to other packages, such as OpenSSH, email applications, and web browsers
29 (for accessing HTTPS sites). </para>
30
31 <segmentedlist>
32 <segtitle>&buildtime;</segtitle>
33 <segtitle>&diskspace;</segtitle>
34
35 <seglistitem>
36 <seg>&openssl-fin-sbu;</seg>
37 <seg>&openssl-fin-du;</seg>
38 </seglistitem>
39 </segmentedlist>
40
41 </sect2>
42
43 <sect2 role="installation">
44 <title>Installation of OpenSSL</title>
45<!--
46 <para>First fix a problem with some advanced architectures with avx512
47 capability:</para>
48
49 <screen><userinput remap="pre">sed -e '/bn_reduce.*m1/i\ factor_size /= sizeof(BN_ULONG) * 8;' \
50 -i crypto/bn/rsaz_exp_x2.c</userinput></screen>
51-->
52 <para>Prepare OpenSSL for compilation:</para>
53
54<screen><userinput remap="configure">./config --prefix=/usr \
55 --openssldir=/etc/ssl \
56 --libdir=lib \
57 shared \
58 zlib-dynamic</userinput></screen>
59
60 <para>Compile the package:</para>
61
62<screen><userinput remap="make">make</userinput></screen>
63
64 <para>To test the results, issue:</para>
65
66<screen><userinput remap="test">make test</userinput></screen>
67
68 <para>One test, 30-test_afalg.t, is known to fail if the host kernel
69 does not have <option>CONFIG_CRYPTO_USER_API_SKCIPHER</option> enabled,
70 or does not have any options providing an AES with CBC implementation
71 (for example, the combination of <option>CONFIG_CRYPTO_AES</option>
72 and <option>CONFIG_CRYPTO_CBC</option>, or
73 <option>CONFIG_CRYPTO_AES_NI_INTEL</option> if the CPU supports AES-NI)
74 enabled. If it fails, it can safely be ignored.</para>
75
76 <para>Install the package:</para>
77
78<screen><userinput remap="install">sed -i '/INSTALL_LIBS/s/libcrypto.a libssl.a//' Makefile
79make MANSUFFIX=ssl install</userinput></screen>
80
81 <para>Add the version to the documentation directory name, to be
82 consistent with other packages:</para>
83
84<screen><userinput remap="install">mv -v /usr/share/doc/openssl /usr/share/doc/openssl-&openssl-version;</userinput></screen>
85
86 <para>If desired, install some additional documentation:</para>
87
88<screen><userinput remap="install">cp -vfr doc/* /usr/share/doc/openssl-&openssl-version;</userinput></screen>
89
90 <note>
91 <para>
92 You should update OpenSSL when a new version which fixes vulnerabilities
93 is announced. Since OpenSSL 3.0.0, the OpenSSL versioning scheme
94 follows the MAJOR.MINOR.PATCH format. API/ABI compatibility
95 is guaranteed for the same MAJOR version number. Because LFS
96 installs only the shared libraries, there is no need to recompile
97 packages which link to
98 <filename class="libraryfile">libcrypto.so</filename> or
99 <filename class="libraryfile">libssl.so</filename>
100 <emphasis>when upgrading to a version with the same MAJOR version
101 number</emphasis>.
102 </para>
103
104 <para>
105 However, any running programs linked to those libraries need to be stopped
106 and restarted. Read the related entries in
107 <xref linkend='pkgmgmt-upgrade-issues'/> for details.
108 </para>
109
110 </note>
111
112 </sect2>
113
114 <!-- - - - - - - - - - -->
115 <!-- Multilib - 32bit -->
116 <!-- - - - - - - - - - -->
117
118 <sect2 arch="ml_32,ml_all" role="installation">
119 <title>Installation of OpenSSL - 32bit</title>
120
121 <para>Clean previous build:</para>
122
123<screen><userinput remap="pre">make distclean</userinput></screen>
124
125 <para>Prepare OpenSSL for compilation:</para>
126
127<screen><userinput remap="configure">./config --prefix=/usr \
128 --openssldir=/etc/ssl \
129 --libdir=lib32 \
130 shared \
131 zlib-dynamic \
132 linux-x86</userinput></screen>
133
134 <para>Compile the package:</para>
135
136<screen><userinput remap="make">make</userinput></screen>
137
138 <para>Install the package:</para>
139
140<screen><userinput remap="install">make DESTDIR=$PWD/DESTDIR install
141cp -Rv DESTDIR/usr/lib32/* /usr/lib32
142rm -rf DESTDIR</userinput></screen>
143
144 </sect2><!-- m32 -->
145
146 <!-- - - - - - - - - - -->
147 <!-- Multilib - x32bit -->
148 <!-- - - - - - - - - - -->
149
150 <sect2 arch="ml_x32,ml_all" role="installation">
151 <title>Installation of OpenSSL - x32bit</title>
152
153 <para>Clean previous build:</para>
154
155<screen><userinput remap="pre">make distclean</userinput></screen>
156
157 <para>Prepare OpenSSL for compilation:</para>
158
159<screen><userinput remap="configure">./config --prefix=/usr \
160 --openssldir=/etc/ssl \
161 --libdir=libx32 \
162 shared \
163 zlib-dynamic \
164 linux-x32</userinput></screen>
165
166 <para>Compile the package:</para>
167
168<screen><userinput remap="make">make</userinput></screen>
169
170 <para>Install the package:</para>
171
172<screen><userinput remap="install">make DESTDIR=$PWD/DESTDIR install
173cp -Rv DESTDIR/usr/libx32/* /usr/libx32
174rm -rf DESTDIR</userinput></screen>
175
176 </sect2><!-- mx32 -->
177
178 <sect2 id="contents-openssl" role="content">
179 <title>Contents of OpenSSL</title>
180
181 <segmentedlist>
182 <segtitle>Installed programs</segtitle>
183 <segtitle>Installed libraries</segtitle>
184 <segtitle>Installed directories</segtitle>
185
186 <seglistitem>
187 <seg>
188 c_rehash and openssl
189 </seg>
190 <seg>
191 libcrypto.so and libssl.so
192 </seg>
193 <seg>
194 /etc/ssl,
195 /usr/include/openssl,
196 /usr/lib/engines and
197 /usr/share/doc/openssl-&openssl-version;
198 </seg>
199 </seglistitem>
200 </segmentedlist>
201
202 <variablelist>
203 <bridgehead renderas="sect3">Short Descriptions</bridgehead>
204 <?dbfo list-presentation="list"?>
205 <?dbhtml list-presentation="table"?>
206
207 <varlistentry id="c_rehash">
208 <term><command>c_rehash</command></term>
209 <listitem>
210 <para>
211 is a <application>Perl</application> script that
212 scans all files in a directory and adds symbolic links to their
213 hash values. Use of <command>c_rehash</command> is considered
214 obsolete and should be replaced by
215 <command>openssl rehash</command> command
216 </para>
217 <indexterm zone="ch-system-openssl c_rehash">
218 <primary sortas="b-c_rehash">c_rehash</primary>
219 </indexterm>
220 </listitem>
221 </varlistentry>
222
223 <varlistentry id="openssl-prog">
224 <term><command>openssl</command></term>
225 <listitem>
226 <para>
227 is a command-line tool for using the various cryptography functions
228 of <application>OpenSSL</application>'s crypto library from the
229 shell. It can be used for various functions which are documented in
230 <command>man 1 openssl</command>
231 </para>
232 <indexterm zone="ch-system-openssl openssl-prog">
233 <primary sortas="b-openssl">openssl</primary>
234 </indexterm>
235 </listitem>
236 </varlistentry>
237
238 <varlistentry id="libcrypto">
239 <term><filename class="libraryfile">libcrypto.so</filename></term>
240 <listitem>
241 <para>
242 implements a wide range of cryptographic algorithms used in various
243 Internet standards. The services provided by this library are used
244 by the <application>OpenSSL</application> implementations of SSL,
245 TLS and S/MIME, and they have also been used to implement
246 <application>OpenSSH</application>,
247 <application>OpenPGP</application>, and other cryptographic
248 standards
249 </para>
250 <indexterm zone="ch-system-openssl libcrypto">
251 <primary sortas="c-libcrypto">libcrypto.so</primary>
252 </indexterm>
253 </listitem>
254 </varlistentry>
255
256 <varlistentry id="libssl">
257 <term><filename class="libraryfile">libssl.so</filename></term>
258 <listitem>
259 <para>
260 implements the Transport Layer Security (TLS v1) protocol.
261 It provides a rich API, documentation
262 on which can be found by running <command>man 7 ssl</command>
263 </para>
264 <indexterm zone="ch-system-openssl libssl">
265 <primary sortas="c-libssl">libssl.so</primary>
266 </indexterm>
267 </listitem>
268 </varlistentry>
269
270 </variablelist>
271
272 </sect2>
273
274</sect1>
Note: See TracBrowser for help on using the repository browser.