Skip to content

Add possibility to load providers and use them in Poco - #4656

Open
mapogu wants to merge 4 commits into
pocoproject:mainfrom
mapogu:develop_allow_reg_openssl_provider
Open

mapogu wants to merge 4 commits into
pocoproject:mainfrom
mapogu:develop_allow_reg_openssl_provider

Conversation

@mapogu

@mapogu mapogu commented Aug 28, 2024

Copy link
Copy Markdown

We have need to externally configure and load providers to OpenSSL 3.x and I noticed that current implementation of the Poco::Net::Context does not provide a way to do this. In my understanding the library context needs to be configured for OpenSSL to search for Providers at an appropriate location. In addition to this, the actual external providers need to be loaded and kept alive until shutdown. These two steps have to happen prior to creation of the SSL Context in order to use providers.

Therefore, I've created this patch as a suggestion to add this improvement to Poco.

@mapogu

mapogu commented Aug 30, 2024

Copy link
Copy Markdown
Author

OK so two failed checks. Is it correct that CIFuzz and CodeQL build with OpenSSL version < 3.x ? In that case the correct way would be to add #if OPENSSL_VERSION_NUMBER >= 0x10100000L around changes, as the OpenSSL Provider API (replacement to Engine) is to my understanding a OpenSSL 3.x addition to OpenSSL ?

@aleks-f

aleks-f commented Sep 10, 2024

Copy link
Copy Markdown
Member

@mapogu is it possible to add a unit test here? I'm not sure what provider(s) are reasonable to expect on different platforms

@mapogu

mapogu commented Sep 23, 2024

Copy link
Copy Markdown
Author

Sorry for the late response. I can try to add unit test. To my understanding the Provider API in OpenSSL should be available on all platforms from OpenSSL 3.x. It can be used to load for instance:

  • Default Provider : standard built-in OpenSSL algorithm
  • Legacy Provider: collection of legacy algorithms (md2, md4, ... BF, DES)
  • FIPS Provider: algorithms conforming to FIPS standards
  • Base Provider: small sub-set of non-cryptographic algorithms available in the default provider.
  • Null Provider: "built-in" to libcrypto and contains no algorithm implementations. Guarantees that the default provider is not loaded.

A note in the docs seems to be that if a provider is loaded then the default provider is not automatically loaded by OpenSSL (has to be explicitly).

Hence I could try to write a test where we load for instance FIPS provider through Poco and check that the default provider is not available.

I guess this addition could be useful when you want to run the combination Poco, OpenSSL 3.x and only FIPS approved algorithms.

@mapogu

mapogu commented Sep 23, 2024

Copy link
Copy Markdown
Author

Since this is explicitly for OpenSSL 3.x is there any good compiler flag for the unit test framework so that the test case doesn't run on OpenSSL 1.x ?

@aleks-f

aleks-f commented Oct 3, 2024

Copy link
Copy Markdown
Member

Since this is explicitly for OpenSSL 3.x is there any good compiler flag for the unit test framework so that the test case doesn't run on OpenSSL 1.x ?

@mapogu see openssl3 CI jobs

@matejk

matejk commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

Status against main:

  • Crypto loads the default and legacy providers into the global library context (Crypto/src/OpenSSLInitializer.cpp). OpenSSLInitializer::enableFIPSMode() sets the fips=yes default property query when the FIPS provider is activated in the OpenSSL configuration.
  • Poco::Net::Context creates the SSL_CTX with SSL_CTX_new(). A separate OSSL_LIB_CTX with its own provider search path and property query is not available.

The feature is therefore still relevant. @mapogu, are you interested in continuing? What is needed:

  1. Rebase onto main; the branch has conflicts.
  2. A unit test in the NetSSL_OpenSSL testsuite, guarded with #if OPENSSL_VERSION_NUMBER >= 0x30000000L. Loading the default provider into a new OSSL_LIB_CTX is sufficient and works on all CI platforms.
  3. The provider argument is passed to SSL_CTX_new_ex() as the property query string. Please name it accordingly, and use the library context also when the query is empty.
  4. Document that the caller keeps ownership of the OSSL_LIB_CTX and that it must outlive the Context.
  5. One helper function for the SSL_CTX creation instead of the repeated #if block in each case of createSSLContext().

Without a response we will close the PR and keep the request as an issue.

@mapogu

mapogu commented Sep 29, 2026

Copy link
Copy Markdown
Author

Sure, I will rebase and try to produce some unit tests for this.
As background, the work-around for this limitation seems to be according to following pseudo code, i.e. setting up the openssl ctx before any Poco net ssl contex.

`
OSSL_LIB_CTX_new
OSSL_PROVIDER_set_default_search_path
OSSL_PROVIDER_load
... others
OSSL_PROVIDER_load

Poco::AutoPtrPoco::Net::Context serverCtx;

Poco::Net::Context::Params params;

params.verificationMode = Poco::Net::Context::VERIFY_STRICT;

serverCtx = new Poco::Net::Context(Poco::Net::Context::SERVER_USE, params);
serverCtx->requireMinimumProtocol(Poco::Net::Context::PROTO_TLSV1_2)

...

// Depending on type of provider additional actions might be required. For my case, a key store integration would for instance have to assure that the provider is aware of which certs are supposed to be used.

Poco::Net::SSLManager::instance().initializeServer(nullptr, nullptr, serverCtx); // ownership transferred

    Poco::Net::SecureServerSocket svs(
        bindHost.empty()
            ? Poco::Net::SocketAddress(static_cast<Poco::UInt16>(port))
            : Poco::Net::SocketAddress(bindHost, static_cast<Poco::UInt16>(port)));
    Poco::Net::TCPServer srv(new Poco::Net::TCPServerConnectionFactoryImpl<EchoConnection>(), svs);

    srv.start();

OSSL_PROVIDER_unload
OSSL_PROVIDER_unload
OSSL_LIB_CTX_free`

@mapogu
mapogu force-pushed the develop_allow_reg_openssl_provider branch from 1cb722a to 3189209 Compare September 30, 2026 04:37
@mapogu

mapogu commented Sep 30, 2026

Copy link
Copy Markdown
Author

I've rebased the patch and cleaned up the patch a bit. Also there should be some test cases now for the changes as well.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants