Re: OpenSSL version requirements

From: Date: Thu, 04 Jan 2001 23:48:57 +0000
Subject: Re: OpenSSL version requirements
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-43001@lists.php.net to get a copy of this message
On Thu, Jan 04, 2001 at 11:20:18AM +0000, Anil Madhavapeddy wrote: > This one escaped my attention when I updated the OpenBSD PHP port > to 4.0.4 - it seems that there is now a requirement for OpenSSL > 0.9.6 with this version. > > Unfortunately, OpenBSD 2.8 only includes 0.9.5a, although -current > includes 0.9.6. > > Is there an absolute requirement for the new features in 0.9.6 > for the OpenSSL extension, or would it be possible to get along > with the older versions? This would affect quite a lot of operating > systems which include OpenSSL in the base tree, as they aren't > easy to update without updating the OS itself. > > If not, I guess I'll just disable OpenSSL support in our port > until the next OpenBSD release, but that would be a waste if it > can be worked around with the older release of OpenSSL. It's not so hard to make the OpenSSL extension work with 0.9.5a I think. The problem is that some functions return error codes in 0.9.6 (which PHP uses) while in 0.9.5a they don't. By making PHP not check for those, it should work. I made it work with the following change: --- /src/cvs/php4/ext/openssl/openssl.c Fri Nov 17 20:50:38 2000 +++ ext/openssl/openssl.c Fri Jan 5 00:39:13 2001 @@ -402,7 +402,7 @@ zend_hash_move_forward_ex(pubkeysht, &pos); i++; } - +#if 0 if (!EVP_EncryptInit(&ctx,EVP_rc4(),NULL,NULL)) { for (i=0; i<nkeys; i++) { efree(eks[i]); @@ -412,7 +412,9 @@ efree(pkeys); RETURN_FALSE; } - +#else + EVP_EncryptInit(&ctx,EVP_rc4(),NULL,NULL); +#endif #if 0 /* Need this if allow ciphers that require initialization vector */ ivlen = EVP_CIPHER_CTX_iv_length(&ctx); @@ -443,9 +445,7 @@ RETURN_FALSE; } - if (!EVP_SealInit(&ctx, EVP_rc4(), eks, eksl, NULL, pkeys, nkeys) || - !EVP_SealUpdate(&ctx, buf, &len1, Z_STRVAL_PP(data), - Z_STRLEN_PP(data))) { + if (!EVP_SealInit(&ctx, EVP_rc4(), eks, eksl, NULL, pkeys, nkeys)) { efree(buf); for (i=0; i<nkeys; i++) { efree(eks[i]); @@ -456,6 +456,8 @@ RETURN_FALSE; } + EVP_SealUpdate(&ctx, buf, &len1, Z_STRVAL_PP(data), + Z_STRLEN_PP(data)); EVP_SealFinal(&ctx, buf + len1, &len2); efree(pkeys); @@ -537,11 +539,14 @@ } if (!EVP_OpenInit(&ctx, EVP_rc4(), Z_STRVAL_PP(ekey), - Z_STRLEN_PP(ekey), NULL, pkey) || - !EVP_OpenUpdate(&ctx, buf, &len1, Z_STRVAL_PP(data), - Z_STRLEN_PP(data)) || - !EVP_OpenFinal(&ctx, buf + len1, &len2) || - (len1 + len2 == 0)) { + Z_STRLEN_PP(ekey), NULL, pkey)) { + efree(buf); + RETURN_FALSE; + } + EVP_OpenUpdate(&ctx, buf, &len1, Z_STRVAL_PP(data), + Z_STRLEN_PP(data)); + EVP_OpenFinal(&ctx, buf + len1, &len2); + if (len1 + len2 == 0) { efree(buf); RETURN_FALSE; } I didn't test that carefully, but think this should be okay. In addition you need to change the configure check. Stig

« previous php.dev (#43001) next »