Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-30437

Build libssh without engine support for RHEL10/Centos10

    • libssh-0.10.6-5.el10
    • 1
    • sst_security_crypto
    • ssg_security
    • 12
    • 17
    • 1
    • QE ack, Dev ack
    • False
    • Hide

      None

      Show
      None
    • Yes
    • Crypto24Q2
    • Hide

      AC1) Ensure that Build Requires in libssh spec file doesn't include openssl-pkcs11
      AC2) torture_auth_pkcs11, torture_pki_rsa_uri and torture_pki_ecdsa_uri upstream tests are passing
      AC3 Stretch goal) Make sure that https://github.com/latchset/pkcs11-provider/blob/main/tests/integration/libssh.sh test is passing

      Show
      AC1) Ensure that Build Requires in libssh spec file doesn't include openssl-pkcs11 AC2) torture_auth_pkcs11, torture_pki_rsa_uri and torture_pki_ecdsa_uri upstream tests are passing AC3 Stretch goal) Make sure that https://github.com/latchset/pkcs11-provider/blob/main/tests/integration/libssh.sh test is passing
    • Pass
    • Not Needed
    • Automated
    • Removed Functionality
    • Hide

      Description: OpenSSL Engines are deprecated and upstream will also remove it's functionality in the near future. Since the inception of providers in OpenSSL 3.0.0, the usage of engines is not recommended. Therefore openssl-pkcs11 package is dropped from Build Requires section now.
      Consequence: Instead of using engines, pkcs11-provider has be used as a replacement. This build adds support for pkcs11-provider and the tests pass with it.
      Show
      Description: OpenSSL Engines are deprecated and upstream will also remove it's functionality in the near future. Since the inception of providers in OpenSSL 3.0.0, the usage of engines is not recommended. Therefore openssl-pkcs11 package is dropped from Build Requires section now. Consequence: Instead of using engines, pkcs11-provider has be used as a replacement. This build adds support for pkcs11-provider and the tests pass with it.
    • Proposed
    • None

      To unblock openssl no-engine process, we need libssh to be built without engine support for CentOS10

            shebburn@redhat.com Sahana Prasad Hebbur Narasimha Prasad
            dbelyavs@redhat.com Dmitry Belyavskiy
            Sahana Prasad Hebbur Narasimha Prasad Sahana Prasad Hebbur Narasimha Prasad
            George Pantelakis George Pantelakis
            Votes:
            0 Vote for this issue
            Watchers:
            7 Start watching this issue

              Created:
              Updated: