Skip to content

Fix TLS for OpenSSL 3.x: use TLS_client_method(), record error text - #9

Open
mikhailnov wants to merge 1 commit into
deanproxy:masterfrom
mikhailnov:fix/tls-openssl3
Open

mikhailnov wants to merge 1 commit into
deanproxy:masterfrom
mikhailnov:fix/tls-openssl3

Conversation

@mikhailnov

Copy link
Copy Markdown
Contributor

TLSv1_client_method() pins the protocol to TLS 1.0. On OpenSSL 3.x combined with system configs that enforce MinProtocol=TLSv1.2 (e.g. ROSA/other modern distros), SSL_CTX_new() fails outright; against servers that still allow TLS 1.0 the handshake pins an insecure protocol modern servers reject.

Use TLS_client_method() on OpenSSL >= 1.1.0 (SSLv23_client_method() on older releases), which negotiates the highest mutually supported version.

Also record the OpenSSL error string on every failure path inside dnetUseTls() into the socket (new errstr field, zero-initialized in dnetConnect()), and make dnetGetErr() prefer it over strerror(errno) so callers can report why the TLS setup failed instead of silently falling back to a plaintext session.

This fixes working with smtp.yandex.ru and other modern servers.

TLSv1_client_method() pins the protocol to TLS 1.0.  On OpenSSL 3.x
combined with system configs that enforce MinProtocol=TLSv1.2 (e.g.
ROSA/other modern distros), SSL_CTX_new() fails outright; against
servers that still allow TLS 1.0 the handshake pins an insecure
protocol modern servers reject.

Use TLS_client_method() on OpenSSL >= 1.1.0 (SSLv23_client_method()
on older releases), which negotiates the highest mutually supported
version.

Also record the OpenSSL error string on every failure path inside
dnetUseTls() into the socket (new errstr field, zero-initialized in
dnetConnect()), and make dnetGetErr() prefer it over strerror(errno)
so callers can report why the TLS setup failed instead of silently
falling back to a plaintext session.

Co-authored-by: Z.AI GLM <[email protected]>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant