[openssh-commits] [openssh] 04/04: Don't enable Brainpool on AWS-LC or BoringSSL.
git+noreply at mindrot.org
git+noreply at mindrot.org
Mon Aug 3 22:18:09 AEST 2026
This is an automated email from the git hooks/post-receive script.
dtucker pushed a commit to branch master
in repository openssh.
commit 265336a702d6a4a117889f2fe281e8f2bbb7e0ef
Author: Darren Tucker <dtucker at dtucker.net>
AuthorDate: Mon Aug 3 22:15:07 2026 +1000
Don't enable Brainpool on AWS-LC or BoringSSL.
These fail at runtime, so disable until we figure out why.
---
configure.ac | 42 ++++++++++++++++++++++++++++++++++--------
kex-names.c | 4 ++--
2 files changed, 36 insertions(+), 10 deletions(-)
diff --git a/configure.ac b/configure.ac
index d495d012c..cb1711f6b 100644
--- a/configure.ac
+++ b/configure.ac
@@ -3113,8 +3113,9 @@ if test "x$openssl" = "xyes" ; then
100*|10100*) # 1.0.x, 1.1.0x
AC_MSG_ERROR([OpenSSL >= 1.1.1 required (have "$ssl_showver")])
;;
- 101*) ;; # 1.1.x
- 200*) # LibreSSL
+ 101*) openssl_impl="openssl" # 1.1.x
+ ;;
+ 200*) openssl_impl="libressl"
lver=`echo "$sslver" | sed 's/.*libressl-//'`
case "$lver" in
2*|300*) # 2.x, 3.0.0
@@ -3123,7 +3124,7 @@ if test "x$openssl" = "xyes" ; then
*) ;; # Assume all other versions are good.
esac
;;
- 30*|40*)
+ 30*|40*) openssl_impl="openssl"
# OpenSSL 3 & 4; we use the 1.1x API
# https://openssl.org/policies/general/versioning-policy.html
CPPFLAGS="$CPPFLAGS -DOPENSSL_API_COMPAT=0x10100000L"
@@ -3211,6 +3212,18 @@ if test "x$openssl" = "xyes" ; then
]
)
+ AC_CHECK_DECL([OPENSSL_IS_AWSLC],
+ [openssl_impl="aws-lc"], [],
+ [#include <openssl/base.h>]
+ )
+ AC_CHECK_DECL([OPENSSL_IS_BORINGSSL],
+ [openssl_impl="boringssl"], [],
+ [#include <openssl/base.h>]
+ )
+
+ AC_MSG_CHECKING([OpenSSL implementation])
+ AC_MSG_RESULT([$openssl_impl])
+
AC_CHECK_FUNCS([ \
BN_is_prime_ex \
DES_crypt \
@@ -3337,17 +3350,30 @@ if test "x$openssl" = "xyes" ; then
AC_MSG_RESULT([no])
]
)
+
+ case "$openssl_impl" in
+ aws-lc|boringssl)
+ # Brainpool does not work with AWC-LS or BoringSSL.
+ unsupported_algorithms="$unsupported_algorithms mlkem768brainpoolp256r1-sha256"
+ ;;
+ *)
+ AC_CHECK_DECL([NID_brainpoolP256r1],
+ [AC_DEFINE([USE_BRAINPOOLP256R1], [1], [Enable brainpool])],
+ [],
+ [[#include <openssl/evp.h>]]
+ )
+ ;;
+ esac
+
fi
# PKCS11/U2F depend on OpenSSL and dlopen().
enable_pkcs11=yes
enable_sk=yes
-AC_CHECK_DECL([OPENSSL_IS_AWSLC],
- [enable_pkcs11="disabled; PKCS#11 not supported with AWS-LC"],
- [],
- [#include <openssl/base.h>]
-)
+if test "x$openssl_impl" = "xaws-lc"; then
+ enable_pkcs11="disabled; PKCS#11 not supported with AWS-LC"
+fi
if test "x$ac_cv_func_dlopen" != "xyes" ; then
enable_pkcs11="disabled; missing dlopen(3)"
enable_sk="disabled; missing dlopen(3)"
diff --git a/kex-names.c b/kex-names.c
index 7660c2edc..225efb0dc 100644
--- a/kex-names.c
+++ b/kex-names.c
@@ -69,10 +69,10 @@ static const struct kexalg kexalgs[] = {
SSH_DIGEST_SHA512, KEX_NOT_PQ },
{ KEX_MLKEM768NISTP256_SHA256, KEX_KEM_MLKEM768ECDH_SHA256,
NID_X9_62_prime256v1, SSH_DIGEST_SHA256, KEX_IS_PQ },
-# ifdef NID_brainpoolP256r1
+# ifdef USE_BRAINPOOLP256R1
{ KEX_MLKEM768BRAINPOOLP256R1_SHA256, KEX_KEM_MLKEM768ECDH_SHA256,
NID_brainpoolP256r1, SSH_DIGEST_SHA256, KEX_IS_PQ },
-# endif /* NID_brainpoolP256r1 */
+# endif /* USE_BRAINPOOLP256R1 */
#endif /* WITH_OPENSSL */
#if defined(HAVE_EVP_SHA256) || !defined(WITH_OPENSSL)
{ KEX_CURVE25519_SHA256, KEX_C25519_SHA256, 0, SSH_DIGEST_SHA256, KEX_NOT_PQ },
--
To stop receiving notification emails like this one, please contact
djm at mindrot.org.
More information about the openssh-commits
mailing list