<feed xmlns='http://www.w3.org/2005/Atom'>
<title>openbsd/src/regress/lib/libssl/interop, branch OPENBSD_7_3</title>
<subtitle>A mirror of https://github.com/libressl/openbsd.git
</subtitle>
<id>https://git.lua4.win/openbsd/atom?h=OPENBSD_7_3</id>
<link rel='self' href='https://git.lua4.win/openbsd/atom?h=OPENBSD_7_3'/>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/'/>
<updated>2023-02-01T16:03:47+00:00</updated>
<entry>
<title>Don't run session tests with openssl 3.0 - these tests aren't TLSv1.3 ready</title>
<updated>2023-02-01T16:03:47+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-02-01T16:03:47+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=18e41f44e8da16fa34d9627787df9e72e6d1bf09'/>
<id>urn:sha1:18e41f44e8da16fa34d9627787df9e72e6d1bf09</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Hopefully the last one.</title>
<updated>2023-02-01T15:59:50+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-02-01T15:59:50+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=397f620c6d0e0e10db7eca8d1f7cdcf96e4ef3dc'/>
<id>urn:sha1:397f620c6d0e0e10db7eca8d1f7cdcf96e4ef3dc</id>
<content type='text'>
</content>
</entry>
<entry>
<title>One more openssl 1.0.2 thing missed.</title>
<updated>2023-02-01T15:58:20+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-02-01T15:58:20+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=544a66582d11ee6b8e488dc93ef69d2187f787c7'/>
<id>urn:sha1:544a66582d11ee6b8e488dc93ef69d2187f787c7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Switch from eopenssl to eopenssl30. Missed in both previous commits</title>
<updated>2023-02-01T15:38:57+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-02-01T15:38:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=09fb96cdc9f31f63544c6888bb2e8c8c30025bc5'/>
<id>urn:sha1:09fb96cdc9f31f63544c6888bb2e8c8c30025bc5</id>
<content type='text'>
for some reason.
</content>
</entry>
<entry>
<title>Retire OpenSSL 1.0.2 interop</title>
<updated>2023-02-01T14:39:09+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-02-01T14:39:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=17e85e0d750477ecd6d94c4da3d089193c536e8f'/>
<id>urn:sha1:17e85e0d750477ecd6d94c4da3d089193c536e8f</id>
<content type='text'>
Now that the OpenSSL 1.0.2 port is gone, there's no need to keep the
interop tests anymore. anton's and bluhm's regress tests will switch
to testing interoperability with OpenSSL 3.0.
</content>
</entry>
<entry>
<title>Add openssl 3.0 interop tests</title>
<updated>2023-01-27T08:28:36+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2023-01-27T08:28:36+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=971c759a469620704a18f7c93e7d71fbae75e7c2'/>
<id>urn:sha1:971c759a469620704a18f7c93e7d71fbae75e7c2</id>
<content type='text'>
The plan is to retire the 1.0.2 interop tests soon so as to be able to
drop the dead and dangerous OpenSSL 1.0.2 port.

The cert part is extremely slow on arm64: the whole interop test on an m1
is about 10x slower (~45 min!) than on a modern amd64 laptop, so people
running regress may want to wait a bit with adding OpenSSL 3 to their test
boxes until this is sorted out.
</content>
</entry>
<entry>
<title>Only run tests against ciphers supported by the method.</title>
<updated>2022-07-07T13:12:57+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-07-07T13:12:57+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=6c30e945e931211223b0bbf8f86a8754ce7d65d7'/>
<id>urn:sha1:6c30e945e931211223b0bbf8f86a8754ce7d65d7</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Add a workaround due to OpenSSL's limitation of SSL_CTX_set_cipher_list</title>
<updated>2022-02-05T18:34:06+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-02-05T18:34:06+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5ca2668e5b3228e2b85bc6198b8c7dce04c22d65'/>
<id>urn:sha1:5ca2668e5b3228e2b85bc6198b8c7dce04c22d65</id>
<content type='text'>
SSL_CTX_set_cipher_list() in OpenSSL 1.1 does not accept TLSv1.3 ciphers.
This wasn't a problem until now since the AEAD- ciphers were counted as
distinct from TLS_ ciphers by the regress test, so they were never used
in the {run,check}-cipher-${cipher}-client-${clib}-server-${slib} tests

With the renaming, the TLSv1.3 ciphers are now considered as common
ciphers, so they're tested. With openssl11 this results in

0:error:1410D0B9:SSL routines:SSL_CTX_set_cipher_list:no cipher match:ssl/ssl_lib.c:2573:

The design of these tests doesn't allow easily adding a call to
SSL_CTX_set_ciphersuites (since they also need to work with openssl 1.0.2)
so skip the TLS_* ciphers for the time being.
</content>
</entry>
<entry>
<title>Mechanically adjust from AEAD- to TLS_ to adjust to the new cipher names.</title>
<updated>2022-02-05T18:21:09+00:00</updated>
<author>
<name>tb</name>
<email></email>
</author>
<published>2022-02-05T18:21:09+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=ebd49daf0f01ffb595c4642dd2982bf31d7b9cd3'/>
<id>urn:sha1:ebd49daf0f01ffb595c4642dd2982bf31d7b9cd3</id>
<content type='text'>
</content>
</entry>
<entry>
<title>Tell testers which packages to install right away (and why)</title>
<updated>2021-12-02T17:10:53+00:00</updated>
<author>
<name>kn</name>
<email></email>
</author>
<published>2021-12-02T17:10:53+00:00</published>
<link rel='alternate' type='text/html' href='https://git.lua4.win/openbsd/commit/?id=5f76eb00e8dae262a9b0c52bae0d3b6fe1ed6ce0'/>
<id>urn:sha1:5f76eb00e8dae262a9b0c52bae0d3b6fe1ed6ce0</id>
<content type='text'>
Other regress tests do it differently;  just fix/thouch those that did not
mention any package name at all.

This helps grepping logs for SKIPPED to find instructions for the next run.
</content>
</entry>
</feed>
