Skip to content

Fix check for OpenSSL supported curves#2662

Merged
drwetter merged 1 commit intotestssl:3.2from
dcooper16:fix_ossl_supported_curve_check
Feb 20, 2025
Merged

Fix check for OpenSSL supported curves#2662
drwetter merged 1 commit intotestssl:3.2from
dcooper16:fix_ossl_supported_curve_check

Conversation

@dcooper16
Copy link
Collaborator

Describe your changes

OpenSSL 3.X outputs a different error message than previous versions when $OPENSSL s_client -curves X ... is called with an unsupported curve. This was resulting in the check within find_openssl_binary() adding every curve to $OPENSSL_SUPPORTED_CURVES, even ones that were not supported. This PR changes to check in order to detect the new error message.

I have tested the fix against multiple versions of OpenSSL/LibreSSL and verified that $OPENSSL_SUPPORTED_CURVES is being set correctly.

What is your pull request about?

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Typo fix
  • Documentation update
  • Update of other files

If it's a code change please check the boxes which are applicable

  • For the main program: My edits contain no tabs and the indentation is five spaces
  • I've read CONTRIBUTING.md and Coding_Convention.md
  • I have tested this fix against >=2 hosts and I couldn't spot a problem
  • I have tested this new feature against >=2 hosts which show this feature and >=2 host which does not (in order to avoid side effects) . I couldn't spot a problem
  • For the new feature I have made corresponding changes to the documentation and / or to help()
  • If it's a bigger change: I added myself to CREDITS.md (alphabetical order) and the change to CHANGELOG.md

OpenSSL 3.X outputs a different error message than previous versions when $OPENSSL s_client -curves X ... is called with an unsupported curve. This was resulting in the check within find_openssl_binary() adding every curve to $OPENSSL_SUPPORTED_CURVES, even ones that were not supported. This commit changes to check in order to detect the new error message.
@drwetter drwetter merged commit ffa3e19 into testssl:3.2 Feb 20, 2025
2 checks passed
@drwetter
Copy link
Collaborator

Excellent & thx!

@dcooper16 dcooper16 deleted the fix_ossl_supported_curve_check branch February 20, 2025 15:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants