Import of pkgsrc-2015Q3
This commit is contained in:
@@ -1,6 +1,6 @@
|
||||
# $NetBSD: Makefile.version,v 1.9 2014/10/01 08:32:31 adam Exp $
|
||||
# $NetBSD: Makefile.version,v 1.11 2015/08/24 22:35:50 adam Exp $
|
||||
# used by databases/openldap/Makefile
|
||||
# used by databases/openldap/Makefile.common
|
||||
# used by databases/openldap-docs/Makefile
|
||||
|
||||
OPENLDAP_VERSION= 2.4.40
|
||||
OPENLDAP_VERSION= 2.4.42
|
||||
|
||||
@@ -1,8 +1,8 @@
|
||||
$NetBSD: distinfo,v 1.97 2014/10/01 08:32:31 adam Exp $
|
||||
$NetBSD: distinfo,v 1.102 2015/09/14 16:32:26 manu Exp $
|
||||
|
||||
SHA1 (openldap-2.4.40.tgz) = 0cfac3b024b99de2e2456cc7254481b6644e0b96
|
||||
RMD160 (openldap-2.4.40.tgz) = 38a914d785040730e9e595fe007ea4a0d0635344
|
||||
Size (openldap-2.4.40.tgz) = 5641865 bytes
|
||||
SHA1 (openldap-2.4.42.tgz) = ec03e061bfdb2e6a90827855cf77a72cb3f89cf4
|
||||
RMD160 (openldap-2.4.42.tgz) = e45f38305f9a151b194534c60899d16be02813f8
|
||||
Size (openldap-2.4.42.tgz) = 5645925 bytes
|
||||
SHA1 (patch-ac) = 2995c518278b363bf9657e181c2340d3024d5980
|
||||
SHA1 (patch-ad) = 24e7ec27d592dd76bdec1e4805801c5304951daf
|
||||
SHA1 (patch-af) = 2e00b01bd813e73bdc1fb764a02e98d7755703de
|
||||
@@ -12,10 +12,11 @@ SHA1 (patch-aj) = 857bbf14855d7d2a2911457bc6373d8beb69b751
|
||||
SHA1 (patch-am) = fb8f3e7699f8b2ef55c066cdc6216522c101c7f3
|
||||
SHA1 (patch-an) = 3e904d05a3e69930259329ca821d3bbf7dd54eb2
|
||||
SHA1 (patch-ao) = 4fcbbfd4d6be792392e3646123022aeaf25923e3
|
||||
SHA1 (patch-contrib_slapd-modules_cloak_Makefile) = 36c416f21982235270ca9f0e4b54f677c4deb1ea
|
||||
SHA1 (patch-contrib_slapd-modules_nops_Makefile) = 22a39eda3e9375e35cec4be57d92a8eafca130a5
|
||||
SHA1 (patch-contrib_slapd-modules_cloak_Makefile) = 47c81def0c013a360acb549ed69e9042f0bc1be3
|
||||
SHA1 (patch-contrib_slapd-modules_nops_Makefile) = c51bccf34c3f3112232a134038622d31b6315628
|
||||
SHA1 (patch-contrib_slapd-modules_nops_slapo-nops.5) = f32352f19361b7e9aa5b038ae8578def7c08fa47
|
||||
SHA1 (patch-da) = 880b25a9266ee057f7269c5be46ef3c3fecf16b4
|
||||
SHA1 (patch-da) = 75e26bd08c6e66b69192ebfbb36db974d391ec3e
|
||||
SHA1 (patch-dd) = 9c74118ff0b2232bda729c9917082fceef41dd16
|
||||
SHA1 (patch-de) = f371fc2bd2534832bf57c363095eecacb5cb1fe3
|
||||
SHA1 (patch-its7506) = a50f9428d6d7dd28f71d21e11ae3f8b0f1372f75
|
||||
SHA1 (patch-its7595) = 9ea396adb7f2fd572d60190534caa80a01ef79d2
|
||||
SHA1 (patch-libraries_libldap_os-local.c) = 7cd4f8638456fae12499de0d36d7802e47d3d688
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
$NetBSD: patch-contrib_slapd-modules_cloak_Makefile,v 1.1 2013/03/16 12:49:54 adam Exp $
|
||||
$NetBSD: patch-contrib_slapd-modules_cloak_Makefile,v 1.2 2015/07/17 14:49:05 adam Exp $
|
||||
|
||||
--- contrib/slapd-modules/cloak/Makefile.orig 2013-03-16 12:37:06.000000000 +0000
|
||||
--- contrib/slapd-modules/cloak/Makefile.orig 2015-06-21 00:19:58.000000000 +0000
|
||||
+++ contrib/slapd-modules/cloak/Makefile
|
||||
@@ -3,12 +3,10 @@
|
||||
LDAP_SRC = ../../..
|
||||
LDAP_BUILD = ../../..
|
||||
LDAP_BUILD = $(LDAP_SRC)
|
||||
LDAP_INC = -I$(LDAP_BUILD)/include -I$(LDAP_SRC)/include -I$(LDAP_SRC)/servers/slapd
|
||||
-LDAP_LIB = $(LDAP_BUILD)/libraries/libldap_r/libldap_r.la \
|
||||
- $(LDAP_BUILD)/libraries/liblber/liblber.la
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
$NetBSD: patch-contrib_slapd-modules_nops_Makefile,v 1.1 2013/03/16 12:49:54 adam Exp $
|
||||
$NetBSD: patch-contrib_slapd-modules_nops_Makefile,v 1.2 2015/07/17 14:49:05 adam Exp $
|
||||
|
||||
--- contrib/slapd-modules/nops/Makefile.orig 2013-03-16 12:40:41.000000000 +0000
|
||||
--- contrib/slapd-modules/nops/Makefile.orig 2015-06-21 00:19:58.000000000 +0000
|
||||
+++ contrib/slapd-modules/nops/Makefile
|
||||
@@ -3,12 +3,10 @@
|
||||
LDAP_SRC = ../../..
|
||||
LDAP_BUILD = ../../..
|
||||
LDAP_BUILD = $(LDAP_SRC)
|
||||
LDAP_INC = -I$(LDAP_BUILD)/include -I$(LDAP_SRC)/include -I$(LDAP_SRC)/servers/slapd
|
||||
-LDAP_LIB = $(LDAP_BUILD)/libraries/libldap_r/libldap_r.la \
|
||||
- $(LDAP_BUILD)/libraries/liblber/liblber.la
|
||||
|
||||
@@ -1,10 +1,10 @@
|
||||
$NetBSD: patch-da,v 1.7 2013/03/16 12:49:54 adam Exp $
|
||||
$NetBSD: patch-da,v 1.8 2015/07/17 14:49:05 adam Exp $
|
||||
|
||||
--- contrib/slapd-modules/smbk5pwd/Makefile.orig 2013-03-03 21:17:30.000000000 +0000
|
||||
--- contrib/slapd-modules/smbk5pwd/Makefile.orig 2015-06-21 00:19:58.000000000 +0000
|
||||
+++ contrib/slapd-modules/smbk5pwd/Makefile
|
||||
@@ -15,8 +15,7 @@
|
||||
LDAP_SRC = ../../..
|
||||
LDAP_BUILD = ../../..
|
||||
LDAP_BUILD = $(LDAP_SRC)
|
||||
LDAP_INC = -I$(LDAP_BUILD)/include -I$(LDAP_SRC)/include -I$(LDAP_SRC)/servers/slapd
|
||||
-LDAP_LIB = $(LDAP_BUILD)/libraries/libldap_r/libldap_r.la \
|
||||
- $(LDAP_BUILD)/libraries/liblber/liblber.la
|
||||
|
||||
@@ -1,20 +0,0 @@
|
||||
$NetBSD: patch-de,v 1.4 2014/10/01 08:32:31 adam Exp $
|
||||
|
||||
--- contrib/slapd-modules/smbk5pwd/smbk5pwd.c.orig 2014-09-19 01:48:49.000000000 +0000
|
||||
+++ contrib/slapd-modules/smbk5pwd/smbk5pwd.c
|
||||
@@ -70,8 +70,15 @@ static ObjectClass *oc_krb5KDCEntry;
|
||||
#include <nettle/md4.h>
|
||||
typedef unsigned char DES_cblock[8];
|
||||
#elif HAVE_OPENSSL
|
||||
+#ifdef __NetBSD__
|
||||
+#include <des.h>
|
||||
+#include <md4.h>
|
||||
+typedef des_key_schedule DES_key_schedule;
|
||||
+typedef des_cblock DES_cblock;
|
||||
+#else
|
||||
#include <openssl/des.h>
|
||||
#include <openssl/md4.h>
|
||||
+#endif
|
||||
#else
|
||||
#error Unsupported crypto backend.
|
||||
#endif
|
||||
222
databases/openldap/patches/patch-its7506
Normal file
222
databases/openldap/patches/patch-its7506
Normal file
@@ -0,0 +1,222 @@
|
||||
$NetBSD: patch-its7506,v 1.1 2015/07/15 16:33:57 manu Exp $
|
||||
|
||||
Upstream fix for ignored TLSDHParamFile option
|
||||
|
||||
From 6f120920d359d3b880c5c56bde4c1b91c3bedb01 Mon Sep 17 00:00:00 2001
|
||||
From: Ben Jencks <ben@bjencks.net>
|
||||
Date: Sun, 27 Jan 2013 18:27:03 -0500
|
||||
Subject: [PATCH] ITS#7506 tls_o.c: Fix Diffie-Hellman parameter usage.
|
||||
|
||||
If a DHParamFile or olcDHParamFile is specified, then it will be used,
|
||||
otherwise a hardcoded 1024 bit parameter will be used. This allows the use of
|
||||
larger parameters; previously only 512 or 1024 bit parameters would ever be
|
||||
used.
|
||||
|
||||
From cfeb28412c28ce9feeea6e6c055286f201bd0a34 Mon Sep 17 00:00:00 2001
|
||||
From: Howard Chu <hyc@openldap.org>
|
||||
Date: Sat, 7 Sep 2013 06:39:53 -0700
|
||||
Subject: [PATCH] ITS#7506 fix prev commit
|
||||
|
||||
The patch unconditionally enabled DHparams, which is a significant
|
||||
change of behavior. Reverting to previous behavior, which only enables
|
||||
DH use if a DHparam file was configured.
|
||||
|
||||
--- libraries/libldap/tls_o.c.orig 2015-07-15 18:14:17.000000000 +0200
|
||||
+++ libraries/libldap/tls_o.c 2015-07-15 18:14:41.000000000 +0200
|
||||
@@ -58,26 +58,15 @@
|
||||
static int tlso_verify_cb( int ok, X509_STORE_CTX *ctx );
|
||||
static int tlso_verify_ok( int ok, X509_STORE_CTX *ctx );
|
||||
static RSA * tlso_tmp_rsa_cb( SSL *ssl, int is_export, int key_length );
|
||||
|
||||
-static DH * tlso_tmp_dh_cb( SSL *ssl, int is_export, int key_length );
|
||||
-
|
||||
-typedef struct dhplist {
|
||||
- struct dhplist *next;
|
||||
- int keylength;
|
||||
- DH *param;
|
||||
-} dhplist;
|
||||
-
|
||||
-static dhplist *tlso_dhparams;
|
||||
-
|
||||
static int tlso_seed_PRNG( const char *randfile );
|
||||
|
||||
#ifdef LDAP_R_COMPILE
|
||||
/*
|
||||
* provide mutexes for the OpenSSL library.
|
||||
*/
|
||||
static ldap_pvt_thread_mutex_t tlso_mutexes[CRYPTO_NUM_LOCKS];
|
||||
-static ldap_pvt_thread_mutex_t tlso_dh_mutex;
|
||||
|
||||
static void tlso_locking_cb( int mode, int type, const char *file, int line )
|
||||
{
|
||||
if ( mode & CRYPTO_LOCK ) {
|
||||
@@ -106,9 +95,8 @@
|
||||
|
||||
for( i=0; i< CRYPTO_NUM_LOCKS ; i++ ) {
|
||||
ldap_pvt_thread_mutex_init( &tlso_mutexes[i] );
|
||||
}
|
||||
- ldap_pvt_thread_mutex_init( &tlso_dh_mutex );
|
||||
CRYPTO_set_locking_callback( tlso_locking_cb );
|
||||
CRYPTO_set_id_callback( tlso_thread_self );
|
||||
}
|
||||
#endif /* LDAP_R_COMPILE */
|
||||
@@ -310,27 +298,27 @@
|
||||
|
||||
if ( lo->ldo_tls_dhfile ) {
|
||||
DH *dh = NULL;
|
||||
BIO *bio;
|
||||
- dhplist *p;
|
||||
+ SSL_CTX_set_options( ctx, SSL_OP_SINGLE_DH_USE );
|
||||
|
||||
if (( bio=BIO_new_file( lt->lt_dhfile,"r" )) == NULL ) {
|
||||
Debug( LDAP_DEBUG_ANY,
|
||||
"TLS: could not use DH parameters file `%s'.\n",
|
||||
lo->ldo_tls_dhfile,0,0);
|
||||
tlso_report_error();
|
||||
return -1;
|
||||
}
|
||||
- while (( dh=PEM_read_bio_DHparams( bio, NULL, NULL, NULL ))) {
|
||||
- p = LDAP_MALLOC( sizeof(dhplist) );
|
||||
- if ( p != NULL ) {
|
||||
- p->keylength = DH_size( dh ) * 8;
|
||||
- p->param = dh;
|
||||
- p->next = tlso_dhparams;
|
||||
- tlso_dhparams = p;
|
||||
- }
|
||||
+ if (!( dh=PEM_read_bio_DHparams( bio, NULL, NULL, NULL ))) {
|
||||
+ Debug( LDAP_DEBUG_ANY,
|
||||
+ "TLS: could not read DH parameters file `%s'.\n",
|
||||
+ lo->ldo_tls_dhfile,0,0);
|
||||
+ tlso_report_error();
|
||||
+ BIO_free( bio );
|
||||
+ return -1;
|
||||
}
|
||||
BIO_free( bio );
|
||||
+ SSL_CTX_set_tmp_dh( ctx, dh );
|
||||
}
|
||||
|
||||
if ( tlso_opt_trace ) {
|
||||
SSL_CTX_set_info_callback( ctx, tlso_info_cb );
|
||||
@@ -348,11 +336,8 @@
|
||||
SSL_CTX_set_verify( ctx, i,
|
||||
lo->ldo_tls_require_cert == LDAP_OPT_X_TLS_ALLOW ?
|
||||
tlso_verify_ok : tlso_verify_cb );
|
||||
SSL_CTX_set_tmp_rsa_callback( ctx, tlso_tmp_rsa_cb );
|
||||
- if ( lo->ldo_tls_dhfile ) {
|
||||
- SSL_CTX_set_tmp_dh_callback( ctx, tlso_tmp_dh_cb );
|
||||
- }
|
||||
#ifdef HAVE_OPENSSL_CRL
|
||||
if ( lo->ldo_tls_crlcheck ) {
|
||||
X509_STORE *x509_s = SSL_CTX_get_cert_store( ctx );
|
||||
if ( lo->ldo_tls_crlcheck == LDAP_OPT_X_TLS_CRL_PEER ) {
|
||||
@@ -1159,110 +1144,8 @@
|
||||
|
||||
return 0;
|
||||
}
|
||||
|
||||
-struct dhinfo {
|
||||
- int keylength;
|
||||
- const char *pem;
|
||||
- size_t size;
|
||||
-};
|
||||
-
|
||||
-
|
||||
-/* From the OpenSSL 0.9.7 distro */
|
||||
-static const char tlso_dhpem512[] =
|
||||
-"-----BEGIN DH PARAMETERS-----\n\
|
||||
-MEYCQQDaWDwW2YUiidDkr3VvTMqS3UvlM7gE+w/tlO+cikQD7VdGUNNpmdsp13Yn\n\
|
||||
-a6LT1BLiGPTdHghM9tgAPnxHdOgzAgEC\n\
|
||||
------END DH PARAMETERS-----\n";
|
||||
-
|
||||
-static const char tlso_dhpem1024[] =
|
||||
-"-----BEGIN DH PARAMETERS-----\n\
|
||||
-MIGHAoGBAJf2QmHKtQXdKCjhPx1ottPb0PMTBH9A6FbaWMsTuKG/K3g6TG1Z1fkq\n\
|
||||
-/Gz/PWk/eLI9TzFgqVAuPvr3q14a1aZeVUMTgo2oO5/y2UHe6VaJ+trqCTat3xlx\n\
|
||||
-/mNbIK9HA2RgPC3gWfVLZQrY+gz3ASHHR5nXWHEyvpuZm7m3h+irAgEC\n\
|
||||
------END DH PARAMETERS-----\n";
|
||||
-
|
||||
-static const char tlso_dhpem2048[] =
|
||||
-"-----BEGIN DH PARAMETERS-----\n\
|
||||
-MIIBCAKCAQEA7ZKJNYJFVcs7+6J2WmkEYb8h86tT0s0h2v94GRFS8Q7B4lW9aG9o\n\
|
||||
-AFO5Imov5Jo0H2XMWTKKvbHbSe3fpxJmw/0hBHAY8H/W91hRGXKCeyKpNBgdL8sh\n\
|
||||
-z22SrkO2qCnHJ6PLAMXy5fsKpFmFor2tRfCzrfnggTXu2YOzzK7q62bmqVdmufEo\n\
|
||||
-pT8igNcLpvZxk5uBDvhakObMym9mX3rAEBoe8PwttggMYiiw7NuJKO4MqD1llGkW\n\
|
||||
-aVM8U2ATsCun1IKHrRxynkE1/MJ86VHeYYX8GZt2YA8z+GuzylIOKcMH6JAWzMwA\n\
|
||||
-Gbatw6QwizOhr9iMjZ0B26TE3X8LvW84wwIBAg==\n\
|
||||
------END DH PARAMETERS-----\n";
|
||||
-
|
||||
-static const char tlso_dhpem4096[] =
|
||||
-"-----BEGIN DH PARAMETERS-----\n\
|
||||
-MIICCAKCAgEA/urRnb6vkPYc/KEGXWnbCIOaKitq7ySIq9dTH7s+Ri59zs77zty7\n\
|
||||
-vfVlSe6VFTBWgYjD2XKUFmtqq6CqXMhVX5ElUDoYDpAyTH85xqNFLzFC7nKrff/H\n\
|
||||
-TFKNttp22cZE9V0IPpzedPfnQkE7aUdmF9JnDyv21Z/818O93u1B4r0szdnmEvEF\n\
|
||||
-bKuIxEHX+bp0ZR7RqE1AeifXGJX3d6tsd2PMAObxwwsv55RGkn50vHO4QxtTARr1\n\
|
||||
-rRUV5j3B3oPMgC7Offxx+98Xn45B1/G0Prp11anDsR1PGwtaCYipqsvMwQUSJtyE\n\
|
||||
-EOQWk+yFkeMe4vWv367eEi0Sd/wnC+TSXBE3pYvpYerJ8n1MceI5GQTdarJ77OW9\n\
|
||||
-bGTHmxRsLSCM1jpLdPja5jjb4siAa6EHc4qN9c/iFKS3PQPJEnX7pXKBRs5f7AF3\n\
|
||||
-W3RIGt+G9IVNZfXaS7Z/iCpgzgvKCs0VeqN38QsJGtC1aIkwOeyjPNy2G6jJ4yqH\n\
|
||||
-ovXYt/0mc00vCWeSNS1wren0pR2EiLxX0ypjjgsU1mk/Z3b/+zVf7fZSIB+nDLjb\n\
|
||||
-NPtUlJCVGnAeBK1J1nG3TQicqowOXoM6ISkdaXj5GPJdXHab2+S7cqhKGv5qC7rR\n\
|
||||
-jT6sx7RUr0CNTxzLI7muV2/a4tGmj0PSdXQdsZ7tw7gbXlaWT1+MM2MCAQI=\n\
|
||||
------END DH PARAMETERS-----\n";
|
||||
-
|
||||
-static const struct dhinfo tlso_dhpem[] = {
|
||||
- { 512, tlso_dhpem512, sizeof(tlso_dhpem512) },
|
||||
- { 1024, tlso_dhpem1024, sizeof(tlso_dhpem1024) },
|
||||
- { 2048, tlso_dhpem2048, sizeof(tlso_dhpem2048) },
|
||||
- { 4096, tlso_dhpem4096, sizeof(tlso_dhpem4096) },
|
||||
- { 0, NULL, 0 }
|
||||
-};
|
||||
-
|
||||
-static DH *
|
||||
-tlso_tmp_dh_cb( SSL *ssl, int is_export, int key_length )
|
||||
-{
|
||||
- struct dhplist *p = NULL;
|
||||
- BIO *b = NULL;
|
||||
- DH *dh = NULL;
|
||||
- int i;
|
||||
-
|
||||
- /* Do we have params of this length already? */
|
||||
- LDAP_MUTEX_LOCK( &tlso_dh_mutex );
|
||||
- for ( p = tlso_dhparams; p; p=p->next ) {
|
||||
- if ( p->keylength == key_length ) {
|
||||
- LDAP_MUTEX_UNLOCK( &tlso_dh_mutex );
|
||||
- return p->param;
|
||||
- }
|
||||
- }
|
||||
-
|
||||
- /* No - check for hardcoded params */
|
||||
-
|
||||
- for (i=0; tlso_dhpem[i].keylength; i++) {
|
||||
- if ( tlso_dhpem[i].keylength == key_length ) {
|
||||
- b = BIO_new_mem_buf( (char *)tlso_dhpem[i].pem, tlso_dhpem[i].size );
|
||||
- break;
|
||||
- }
|
||||
- }
|
||||
-
|
||||
- if ( b ) {
|
||||
- dh = PEM_read_bio_DHparams( b, NULL, NULL, NULL );
|
||||
- BIO_free( b );
|
||||
- }
|
||||
-
|
||||
- /* Generating on the fly is expensive/slow... */
|
||||
- if ( !dh ) {
|
||||
- dh = DH_generate_parameters( key_length, DH_GENERATOR_2, NULL, NULL );
|
||||
- }
|
||||
- if ( dh ) {
|
||||
- p = LDAP_MALLOC( sizeof(struct dhplist) );
|
||||
- if ( p != NULL ) {
|
||||
- p->keylength = key_length;
|
||||
- p->param = dh;
|
||||
- p->next = tlso_dhparams;
|
||||
- tlso_dhparams = p;
|
||||
- }
|
||||
- }
|
||||
-
|
||||
- LDAP_MUTEX_UNLOCK( &tlso_dh_mutex );
|
||||
- return dh;
|
||||
-}
|
||||
|
||||
tls_impl ldap_int_tls_impl = {
|
||||
"OpenSSL",
|
||||
|
||||
284
databases/openldap/patches/patch-its7595
Normal file
284
databases/openldap/patches/patch-its7595
Normal file
@@ -0,0 +1,284 @@
|
||||
$NetBSD: patch-its7595,v 1.1 2015/09/14 16:32:26 manu Exp $
|
||||
|
||||
ECDH support from upstream
|
||||
|
||||
From e631ce808ed56119e61321463d06db7999ba5a08 Mon Sep 17 00:00:00 2001
|
||||
From: Howard Chu <hyc@openldap.org>
|
||||
Date: Sat, 7 Sep 2013 09:47:19 -0700
|
||||
Subject: [PATCH] ITS#7595 Add Elliptic Curve support for OpenSSL
|
||||
|
||||
From 9562ad00bd7f965df721bc22ac905bc759298a27 Mon Sep 17 00:00:00 2001
|
||||
From: Howard Chu <hyc@openldap.org>
|
||||
Date: Sat, 7 Sep 2013 10:13:40 -0700
|
||||
Subject: [PATCH] ITS#7595 more doc for elliptic curve
|
||||
|
||||
From 721e46fe6695077d63a3df6ea2e397920a72308d Mon Sep 17 00:00:00 2001
|
||||
From: Howard Chu <hyc@openldap.org>
|
||||
Date: Sun, 8 Sep 2013 06:32:23 -0700
|
||||
Subject: [PATCH] ITS#7595 don't try to use EC if OpenSSL lacks it
|
||||
|
||||
--- doc/guide/admin/tls.sdf.orig
|
||||
+++ doc/guide/admin/tls.sdf
|
||||
@@ -200,8 +200,20 @@
|
||||
> openssl dhparam [-dsaparam] -out <filename> <numbits>
|
||||
|
||||
This directive is ignored with GnuTLS and Mozilla NSS.
|
||||
|
||||
+H4: TLSECName <name>
|
||||
+
|
||||
+This directive specifies the curve to use for Elliptic Curve
|
||||
+Diffie-Hellman ephemeral key exchange. This is required in order
|
||||
+to use ECDHE-based cipher suites in OpenSSL. The names of supported
|
||||
+curves may be shown using the following command
|
||||
+
|
||||
+> openssl ecparam -list_curves
|
||||
+
|
||||
+This directive is not used for GnuTLS and is ignored with Mozilla NSS.
|
||||
+For GnuTLS the curves may be specified in the ciphersuite.
|
||||
+
|
||||
H4: TLSVerifyClient { never | allow | try | demand }
|
||||
|
||||
This directive specifies what checks to perform on client certificates
|
||||
in an incoming TLS session, if any. This option is set to {{EX:never}}
|
||||
--- doc/man/man5/slapd-config.5.orig
|
||||
+++ doc/man/man5/slapd-config.5
|
||||
@@ -917,8 +917,15 @@
|
||||
from the default, otherwise no certificate exchanges or verification will
|
||||
be done. When using GnuTLS or Mozilla NSS these parameters are always generated randomly
|
||||
so this directive is ignored.
|
||||
.TP
|
||||
+.B olcTLSECName: <name>
|
||||
+Specify the name of a curve to use for Elliptic curve Diffie-Hellman
|
||||
+ephemeral key exchange. This is required to enable ECDHE algorithms in
|
||||
+OpenSSL. This option is not used with GnuTLS; the curves may be
|
||||
+chosen in the GnuTLS ciphersuite specification. This option is also
|
||||
+ignored for Mozilla NSS.
|
||||
+.TP
|
||||
.B olcTLSProtocolMin: <major>[.<minor>]
|
||||
Specifies minimum SSL/TLS protocol version that will be negotiated.
|
||||
If the server doesn't support at least that version,
|
||||
the SSL handshake will fail.
|
||||
--- doc/man/man5/slapd.conf.5.orig
|
||||
+++ doc/man/man5/slapd.conf.5
|
||||
@@ -1148,8 +1148,15 @@
|
||||
from the default, otherwise no certificate exchanges or verification will
|
||||
be done. When using GnuTLS these parameters are always generated randomly so
|
||||
this directive is ignored. This directive is ignored when using Mozilla NSS.
|
||||
.TP
|
||||
+.B TLSECName <name>
|
||||
+Specify the name of a curve to use for Elliptic curve Diffie-Hellman
|
||||
+ephemeral key exchange. This is required to enable ECDHE algorithms in
|
||||
+OpenSSL. This option is not used with GnuTLS; the curves may be
|
||||
+chosen in the GnuTLS ciphersuite specification. This option is also
|
||||
+ignored for Mozilla NSS.
|
||||
+.TP
|
||||
.B TLSProtocolMin <major>[.<minor>]
|
||||
Specifies minimum SSL/TLS protocol version that will be negotiated.
|
||||
If the server doesn't support at least that version,
|
||||
the SSL handshake will fail.
|
||||
--- include/ldap.h.orig
|
||||
+++ include/ldap.h
|
||||
@@ -157,8 +157,9 @@
|
||||
#define LDAP_OPT_X_TLS_DHFILE 0x600e
|
||||
#define LDAP_OPT_X_TLS_NEWCTX 0x600f
|
||||
#define LDAP_OPT_X_TLS_CRLFILE 0x6010 /* GNUtls only */
|
||||
#define LDAP_OPT_X_TLS_PACKAGE 0x6011
|
||||
+#define LDAP_OPT_X_TLS_ECNAME 0x6012
|
||||
|
||||
#define LDAP_OPT_X_TLS_NEVER 0
|
||||
#define LDAP_OPT_X_TLS_HARD 1
|
||||
#define LDAP_OPT_X_TLS_DEMAND 2
|
||||
--- libraries/libldap/ldap-int.h.orig
|
||||
+++ libraries/libldap/ldap-int.h
|
||||
@@ -164,8 +164,9 @@
|
||||
char *lt_cacertdir;
|
||||
char *lt_ciphersuite;
|
||||
char *lt_crlfile;
|
||||
char *lt_randfile; /* OpenSSL only */
|
||||
+ char *lt_ecname; /* OpenSSL only */
|
||||
int lt_protocol_min;
|
||||
};
|
||||
#endif
|
||||
|
||||
@@ -249,8 +250,9 @@
|
||||
struct ldaptls ldo_tls_info;
|
||||
#define ldo_tls_certfile ldo_tls_info.lt_certfile
|
||||
#define ldo_tls_keyfile ldo_tls_info.lt_keyfile
|
||||
#define ldo_tls_dhfile ldo_tls_info.lt_dhfile
|
||||
+#define ldo_tls_ecname ldo_tls_info.lt_ecname
|
||||
#define ldo_tls_cacertfile ldo_tls_info.lt_cacertfile
|
||||
#define ldo_tls_cacertdir ldo_tls_info.lt_cacertdir
|
||||
#define ldo_tls_ciphersuite ldo_tls_info.lt_ciphersuite
|
||||
#define ldo_tls_protocol_min ldo_tls_info.lt_protocol_min
|
||||
--- libraries/libldap/tls2.c.orig
|
||||
+++ libraries/libldap/tls2.c
|
||||
@@ -117,8 +117,12 @@
|
||||
if ( lo->ldo_tls_dhfile ) {
|
||||
LDAP_FREE( lo->ldo_tls_dhfile );
|
||||
lo->ldo_tls_dhfile = NULL;
|
||||
}
|
||||
+ if ( lo->ldo_tls_ecname ) {
|
||||
+ LDAP_FREE( lo->ldo_tls_ecname );
|
||||
+ lo->ldo_tls_ecname = NULL;
|
||||
+ }
|
||||
if ( lo->ldo_tls_cacertfile ) {
|
||||
LDAP_FREE( lo->ldo_tls_cacertfile );
|
||||
lo->ldo_tls_cacertfile = NULL;
|
||||
}
|
||||
@@ -231,8 +235,12 @@
|
||||
if ( lts.lt_dhfile ) {
|
||||
lts.lt_dhfile = LDAP_STRDUP( lts.lt_dhfile );
|
||||
__atoe( lts.lt_dhfile );
|
||||
}
|
||||
+ if ( lts.lt_ecname ) {
|
||||
+ lts.lt_ecname = LDAP_STRDUP( lts.lt_ecname );
|
||||
+ __atoe( lts.lt_ecname );
|
||||
+ }
|
||||
#endif
|
||||
lo->ldo_tls_ctx = ti->ti_ctx_new( lo );
|
||||
if ( lo->ldo_tls_ctx == NULL ) {
|
||||
Debug( LDAP_DEBUG_ANY,
|
||||
@@ -256,8 +264,9 @@
|
||||
LDAP_FREE( lts.lt_keyfile );
|
||||
LDAP_FREE( lts.lt_crlfile );
|
||||
LDAP_FREE( lts.lt_cacertdir );
|
||||
LDAP_FREE( lts.lt_dhfile );
|
||||
+ LDAP_FREE( lts.lt_ecname );
|
||||
#endif
|
||||
return rc;
|
||||
}
|
||||
|
||||
@@ -633,8 +642,12 @@
|
||||
case LDAP_OPT_X_TLS_DHFILE:
|
||||
*(char **)arg = lo->ldo_tls_dhfile ?
|
||||
LDAP_STRDUP( lo->ldo_tls_dhfile ) : NULL;
|
||||
break;
|
||||
+ case LDAP_OPT_X_TLS_ECNAME:
|
||||
+ *(char **)arg = lo->ldo_tls_ecname ?
|
||||
+ LDAP_STRDUP( lo->ldo_tls_ecname ) : NULL;
|
||||
+ break;
|
||||
case LDAP_OPT_X_TLS_CRLFILE: /* GnuTLS only */
|
||||
*(char **)arg = lo->ldo_tls_crlfile ?
|
||||
LDAP_STRDUP( lo->ldo_tls_crlfile ) : NULL;
|
||||
break;
|
||||
@@ -752,8 +765,12 @@
|
||||
case LDAP_OPT_X_TLS_DHFILE:
|
||||
if ( lo->ldo_tls_dhfile ) LDAP_FREE( lo->ldo_tls_dhfile );
|
||||
lo->ldo_tls_dhfile = arg ? LDAP_STRDUP( (char *) arg ) : NULL;
|
||||
return 0;
|
||||
+ case LDAP_OPT_X_TLS_ECNAME:
|
||||
+ if ( lo->ldo_tls_ecname ) LDAP_FREE( lo->ldo_tls_ecname );
|
||||
+ lo->ldo_tls_ecname = arg ? LDAP_STRDUP( (char *) arg ) : NULL;
|
||||
+ return 0;
|
||||
case LDAP_OPT_X_TLS_CRLFILE: /* GnuTLS only */
|
||||
if ( lo->ldo_tls_crlfile ) LDAP_FREE( lo->ldo_tls_crlfile );
|
||||
lo->ldo_tls_crlfile = arg ? LDAP_STRDUP( (char *) arg ) : NULL;
|
||||
return 0;
|
||||
--- libraries/libldap/tls_o.c.orig
|
||||
+++ libraries/libldap/tls_o.c
|
||||
@@ -295,12 +295,11 @@
|
||||
tlso_report_error();
|
||||
return -1;
|
||||
}
|
||||
|
||||
- if ( lo->ldo_tls_dhfile ) {
|
||||
- DH *dh = NULL;
|
||||
+ if ( is_server && lo->ldo_tls_dhfile ) {
|
||||
+ DH *dh;
|
||||
BIO *bio;
|
||||
- SSL_CTX_set_options( ctx, SSL_OP_SINGLE_DH_USE );
|
||||
|
||||
if (( bio=BIO_new_file( lt->lt_dhfile,"r" )) == NULL ) {
|
||||
Debug( LDAP_DEBUG_ANY,
|
||||
"TLS: could not use DH parameters file `%s'.\n",
|
||||
@@ -317,8 +316,40 @@
|
||||
return -1;
|
||||
}
|
||||
BIO_free( bio );
|
||||
SSL_CTX_set_tmp_dh( ctx, dh );
|
||||
+ SSL_CTX_set_options( ctx, SSL_OP_SINGLE_DH_USE );
|
||||
+ DH_free( dh );
|
||||
+ }
|
||||
+
|
||||
+ if ( is_server && lo->ldo_tls_ecname ) {
|
||||
+#ifdef OPENSSL_NO_EC
|
||||
+ Debug( LDAP_DEBUG_ANY,
|
||||
+ "TLS: Elliptic Curves not supported.\n", 0,0,0 );
|
||||
+ return -1;
|
||||
+#else
|
||||
+ EC_KEY *ecdh;
|
||||
+
|
||||
+ int nid = OBJ_sn2nid( lt->lt_ecname );
|
||||
+ if ( nid == NID_undef ) {
|
||||
+ Debug( LDAP_DEBUG_ANY,
|
||||
+ "TLS: could not use EC name `%s'.\n",
|
||||
+ lo->ldo_tls_ecname,0,0);
|
||||
+ tlso_report_error();
|
||||
+ return -1;
|
||||
+ }
|
||||
+ ecdh = EC_KEY_new_by_curve_name( nid );
|
||||
+ if ( ecdh == NULL ) {
|
||||
+ Debug( LDAP_DEBUG_ANY,
|
||||
+ "TLS: could not generate key for EC name `%s'.\n",
|
||||
+ lo->ldo_tls_ecname,0,0);
|
||||
+ tlso_report_error();
|
||||
+ return -1;
|
||||
+ }
|
||||
+ SSL_CTX_set_tmp_ecdh( ctx, ecdh );
|
||||
+ SSL_CTX_set_options( ctx, SSL_OP_SINGLE_ECDH_USE );
|
||||
+ EC_KEY_free( ecdh );
|
||||
+#endif
|
||||
}
|
||||
|
||||
if ( tlso_opt_trace ) {
|
||||
SSL_CTX_set_info_callback( ctx, tlso_info_cb );
|
||||
--- servers/slapd/bconfig.c.orig
|
||||
+++ servers/slapd/bconfig.c
|
||||
@@ -193,8 +193,9 @@
|
||||
CFG_SYNTAX,
|
||||
CFG_ACL_ADD,
|
||||
CFG_SYNC_SUBENTRY,
|
||||
CFG_LTHREADS,
|
||||
+ CFG_TLS_ECNAME,
|
||||
|
||||
CFG_LAST
|
||||
};
|
||||
|
||||
@@ -737,8 +738,16 @@
|
||||
ARG_IGNORED, NULL,
|
||||
#endif
|
||||
"( OLcfgGlAt:77 NAME 'olcTLSDHParamFile' "
|
||||
"SYNTAX OMsDirectoryString SINGLE-VALUE )", NULL, NULL },
|
||||
+ { "TLSECName", NULL, 2, 2, 0,
|
||||
+#ifdef HAVE_TLS
|
||||
+ CFG_TLS_ECNAME|ARG_STRING|ARG_MAGIC, &config_tls_option,
|
||||
+#else
|
||||
+ ARG_IGNORED, NULL,
|
||||
+#endif
|
||||
+ "( OLcfgGlAt:96 NAME 'olcTLSECName' "
|
||||
+ "SYNTAX OMsDirectoryString SINGLE-VALUE )", NULL, NULL },
|
||||
{ "TLSProtocolMin", NULL, 2, 2, 0,
|
||||
#ifdef HAVE_TLS
|
||||
CFG_TLS_PROTOCOL_MIN|ARG_STRING|ARG_MAGIC, &config_tls_config,
|
||||
#else
|
||||
@@ -818,9 +827,9 @@
|
||||
"olcTCPBuffer $ "
|
||||
"olcThreads $ olcTimeLimit $ olcTLSCACertificateFile $ "
|
||||
"olcTLSCACertificatePath $ olcTLSCertificateFile $ "
|
||||
"olcTLSCertificateKeyFile $ olcTLSCipherSuite $ olcTLSCRLCheck $ "
|
||||
- "olcTLSRandFile $ olcTLSVerifyClient $ olcTLSDHParamFile $ "
|
||||
+ "olcTLSRandFile $ olcTLSVerifyClient $ olcTLSDHParamFile $ olcTLSECName $ "
|
||||
"olcTLSCRLFile $ olcTLSProtocolMin $ olcToolThreads $ olcWriteTimeout $ "
|
||||
"olcObjectIdentifier $ olcAttributeTypes $ olcObjectClasses $ "
|
||||
"olcDitContentRules $ olcLdapSyntaxes ) )", Cft_Global },
|
||||
{ "( OLcfgGlOc:2 "
|
||||
@@ -3823,8 +3832,9 @@
|
||||
case CFG_TLS_CERT_KEY: flag = LDAP_OPT_X_TLS_KEYFILE; break;
|
||||
case CFG_TLS_CA_PATH: flag = LDAP_OPT_X_TLS_CACERTDIR; break;
|
||||
case CFG_TLS_CA_FILE: flag = LDAP_OPT_X_TLS_CACERTFILE; break;
|
||||
case CFG_TLS_DH_FILE: flag = LDAP_OPT_X_TLS_DHFILE; break;
|
||||
+ case CFG_TLS_ECNAME: flag = LDAP_OPT_X_TLS_ECNAME; break;
|
||||
#ifdef HAVE_GNUTLS
|
||||
case CFG_TLS_CRL_FILE: flag = LDAP_OPT_X_TLS_CRLFILE; break;
|
||||
#endif
|
||||
default: Debug(LDAP_DEBUG_ANY, "%s: "
|
||||
Reference in New Issue
Block a user