Re: OpenSSL version requirements
| From: | Stig Venaas | Date: | Thu, 04 Jan 2001 23:48:57 +0000 |
| Subject: | Re: OpenSSL version requirements | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-43001@lists.php.net to get a copy of this message | ||
On Thu, Jan 04, 2001 at 11:20:18AM +0000, Anil Madhavapeddy wrote:
> This one escaped my attention when I updated the OpenBSD PHP port
> to 4.0.4 - it seems that there is now a requirement for OpenSSL
> 0.9.6 with this version.
>
> Unfortunately, OpenBSD 2.8 only includes 0.9.5a, although -current
> includes 0.9.6.
>
> Is there an absolute requirement for the new features in 0.9.6
> for the OpenSSL extension, or would it be possible to get along
> with the older versions? This would affect quite a lot of operating
> systems which include OpenSSL in the base tree, as they aren't
> easy to update without updating the OS itself.
>
> If not, I guess I'll just disable OpenSSL support in our port
> until the next OpenBSD release, but that would be a waste if it
> can be worked around with the older release of OpenSSL.
It's not so hard to make the OpenSSL extension work with 0.9.5a
I think. The problem is that some functions return error codes
in 0.9.6 (which PHP uses) while in 0.9.5a they don't. By making
PHP not check for those, it should work.
I made it work with the following change:
--- /src/cvs/php4/ext/openssl/openssl.c Fri Nov 17 20:50:38 2000
+++ ext/openssl/openssl.c Fri Jan 5 00:39:13 2001
@@ -402,7 +402,7 @@
zend_hash_move_forward_ex(pubkeysht, &pos);
i++;
}
-
+#if 0
if (!EVP_EncryptInit(&ctx,EVP_rc4(),NULL,NULL)) {
for (i=0; i<nkeys; i++) {
efree(eks[i]);
@@ -412,7 +412,9 @@
efree(pkeys);
RETURN_FALSE;
}
-
+#else
+ EVP_EncryptInit(&ctx,EVP_rc4(),NULL,NULL);
+#endif
#if 0
/* Need this if allow ciphers that require initialization vector */
ivlen = EVP_CIPHER_CTX_iv_length(&ctx);
@@ -443,9 +445,7 @@
RETURN_FALSE;
}
- if (!EVP_SealInit(&ctx, EVP_rc4(), eks, eksl, NULL, pkeys, nkeys) ||
- !EVP_SealUpdate(&ctx, buf, &len1, Z_STRVAL_PP(data),
- Z_STRLEN_PP(data))) {
+ if (!EVP_SealInit(&ctx, EVP_rc4(), eks, eksl, NULL, pkeys, nkeys)) {
efree(buf);
for (i=0; i<nkeys; i++) {
efree(eks[i]);
@@ -456,6 +456,8 @@
RETURN_FALSE;
}
+ EVP_SealUpdate(&ctx, buf, &len1, Z_STRVAL_PP(data),
+ Z_STRLEN_PP(data));
EVP_SealFinal(&ctx, buf + len1, &len2);
efree(pkeys);
@@ -537,11 +539,14 @@
}
if (!EVP_OpenInit(&ctx, EVP_rc4(), Z_STRVAL_PP(ekey),
- Z_STRLEN_PP(ekey), NULL, pkey) ||
- !EVP_OpenUpdate(&ctx, buf, &len1, Z_STRVAL_PP(data),
- Z_STRLEN_PP(data)) ||
- !EVP_OpenFinal(&ctx, buf + len1, &len2) ||
- (len1 + len2 == 0)) {
+ Z_STRLEN_PP(ekey), NULL, pkey)) {
+ efree(buf);
+ RETURN_FALSE;
+ }
+ EVP_OpenUpdate(&ctx, buf, &len1, Z_STRVAL_PP(data),
+ Z_STRLEN_PP(data));
+ EVP_OpenFinal(&ctx, buf + len1, &len2);
+ if (len1 + len2 == 0) {
efree(buf);
RETURN_FALSE;
}
I didn't test that carefully, but think this should be okay. In
addition you need to change the configure check.
Stig