#### Pre-Submission Checklist <!-- Go over all points below, and after creating the PR, tick all the checkboxes that apply --> <!-- All points should be verified, otherwise, read the CONTRIBUTING guidelines from above--> <!-- If you're unsure about any of these, don't hesitate to ask on sr-dev mailing list --> - [x] Commit message has the format required by CONTRIBUTING guide - [x] Commits are split per component (core, individual modules, libs, utils, ...) - [x] Each component has a single commit (if not, squash them into one commit) - [x] No commits to README files for modules (changes must be done to docbook files in `doc/` subfolder, the README file is autogenerated)
#### Type Of Change - [x] Small bug fix (non-breaking change which fixes an issue) - [ ] New feature (non-breaking change which adds new functionality) - [ ] Breaking change (fix or feature that would change existing functionality)
#### Checklist: <!-- Go over all points below, and after creating the PR, tick the checkboxes that apply --> - [ ] PR should be backported to stable branches - [ ] Tested changes locally - [x] Related to issues #3011 #3222 #3259
#### Description
investigate changes needed for openssl 3.0
You can view, comment on, or merge this pull request online at:
https://github.com/kamailio/kamailio/pull/3482
-- Commit Summary --
* tls: OPENSSL_fork_[prepare|parent|child] deprecated at openssl 3.0
-- File Changes --
M src/modules/tls/tls_init.c (2) M src/modules/tls/tls_mod.c (6)
-- Patch Links --
https://github.com/kamailio/kamailio/pull/3482.patch https://github.com/kamailio/kamailio/pull/3482.diff
@linuxmaniac pushed 2 commits.
a498be6438eb08956491660a644fb989c1889cc0 tls: OPENSSL_fork_[prepare|parent|child] deprecated at openssl 3.0 9e0197ca3a130a559db08fcd4b352a03c5371f04 tls: disable engine for openssl >= 3.0
@linuxmaniac pushed 1 commit.
4cbe8241f59c3238472facd85ccf7ac7fe67995d tls: disable tls_rand for openssl >= 3.0
@linuxmaniac pushed 3 commits.
ab4cd28371a47f32d65ba5fc643f8857ed8ef9aa tls: OPENSSL_fork_[prepare|parent|child] deprecated at openssl 3.0 808223dc0808d63544772d5aef7f19a24cbca215 tls: disable engine for openssl >= 3.0 cbbdbdc19611bb0b1969712726f7582b6c732149 tls: disable tls_rand for openssl >= 3.0
Probably this can be merged to master branch to facilitate easier testing.
I think next step is to investigate about enabling locking for random number generation with `EVP_RAND_enable_locking()`
- https://www.openssl.org/docs/man3.0/man3/EVP_RAND.html
Replacing the default rand engine for libssl 1.1.x had to be done to protect against some races.
@linuxmaniac pushed 2 commits.
4980e0584c08b1357e1165e9ec4f35f2476856fa tls: disable engine for openssl >= 3.0 bc6326ab747c35f689410b1f51aa956141ffe7e5 tls: disable tls_rand for openssl >= 3.0
Merged #3482 into master.