Welcome! Log In Create A New Profile

Advanced

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Sergey Kandaurov
October 27, 2014 09:56AM
On Oct 24, 2014, at 3:29 PM, Piotr Sikora <piotr@cloudflare.com> wrote:
> # HG changeset patch
> # User Piotr Sikora <piotr@cloudflare.com>
> # Date 1414150080 25200
> # Fri Oct 24 04:28:00 2014 -0700
> # Node ID f71b843694fc2be7eabb9313aa82fb87e83210d6
> # Parent 973fded4f461f3a397779b3a1dc80881b1b34974
> SSL: make ssl_password_file work with recent OpenSSL releases.

I updated the patch to cover the pem file in PKCS#8 format
that is matched with PEM_STRING_PKCS8.

diff -r 973fded4f461 -r 8c59ef63e7c0 src/event/ngx_event_openssl.c
--- a/src/event/ngx_event_openssl.c Wed Oct 15 22:57:23 2014 +0400
+++ b/src/event/ngx_event_openssl.c Mon Oct 27 13:19:01 2014 +0300
@@ -410,8 +410,12 @@ ngx_ssl_certificate(ngx_conf_t *cf, ngx_
if (ERR_GET_LIB(n) == ERR_LIB_CIPHER
&& ERR_GET_REASON(n) == CIPHER_R_BAD_DECRYPT)
#else
- if (ERR_GET_LIB(n) == ERR_LIB_EVP
- && ERR_GET_REASON(n) == EVP_R_BAD_DECRYPT)
+ if ((ERR_GET_LIB(n) == ERR_LIB_PEM
+ && ERR_GET_REASON(n) == PEM_R_BAD_DECRYPT)
+ || (ERR_GET_LIB(n) == ERR_LIB_EVP
+ && ERR_GET_REASON(n) == EVP_R_BAD_DECRYPT)
+ || (ERR_GET_LIB(n) == ERR_LIB_PKCS12
+ && ERR_GET_REASON(n) == PKCS12_R_PKCS12_CIPHERFINAL_ERROR))
#endif
{
ERR_clear_error();
diff -r 973fded4f461 -r 8c59ef63e7c0 src/event/ngx_event_openssl.h
--- a/src/event/ngx_event_openssl.h Wed Oct 15 22:57:23 2014 +0400
+++ b/src/event/ngx_event_openssl.h Mon Oct 27 13:19:01 2014 +0300
@@ -22,6 +22,7 @@
#include <openssl/engine.h>
#endif
#include <openssl/evp.h>
+#include <openssl/pkcs12.h>
#ifndef OPENSSL_NO_OCSP
#include <openssl/ocsp.h>
#endif


--
Sergey Kandaurov

_______________________________________________
nginx-devel mailing list
nginx-devel@nginx.org
http://mailman.nginx.org/mailman/listinfo/nginx-devel
Subject Author Views Posted

[PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Piotr Sikora 813 October 24, 2014 07:30AM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Sergey Kandaurov 349 October 27, 2014 09:56AM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Maxim Dounin 307 October 27, 2014 12:30PM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Piotr Sikora 290 October 27, 2014 05:40PM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Sergey Kandaurov 368 October 29, 2014 02:12PM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Sergey Kandaurov 390 October 29, 2014 03:12PM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Piotr Sikora 321 October 29, 2014 03:28PM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Piotr Sikora 284 October 30, 2014 05:42AM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Sergey Kandaurov 378 October 30, 2014 10:42AM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Piotr Sikora 301 October 29, 2014 03:20PM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Piotr Sikora 325 October 30, 2014 12:16AM

Re: [PATCH] SSL: make ssl_password_file work with recent OpenSSL releases

Piotr Sikora 315 October 27, 2014 07:52PM



Sorry, you do not have permission to post/reply in this forum.

Online Users

Guests: 166
Record Number of Users: 8 on April 13, 2023
Record Number of Guests: 421 on December 02, 2018
Powered by nginx      Powered by FreeBSD      PHP Powered      Powered by MariaDB      ipv6 ready