This is an automated email from the ASF dual-hosted git repository.
rmaucher pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat.git
The following commit(s) were added to refs/heads/main by this push:
new 9e8594c2b1 LibreSSL does not support PSK at all
9e8594c2b1 is described below
commit 9e8594c2b1bef6d82eb97384ab88ed3fff947a87
Author: remm <[email protected]>
AuthorDate: Fri Sep 25 13:00:23 2026 +0200
LibreSSL does not support PSK at all
And BoringSSL only supports TLS 1.2.
---
.../tomcat/util/net/openssl/panama/LocalStrings.properties | 1 +
.../apache/tomcat/util/net/openssl/panama/OpenSSLContext.java | 10 ++++++++--
2 files changed, 9 insertions(+), 2 deletions(-)
diff --git
a/java/org/apache/tomcat/util/net/openssl/panama/LocalStrings.properties
b/java/org/apache/tomcat/util/net/openssl/panama/LocalStrings.properties
index ad24091af1..31e163cb9c 100644
--- a/java/org/apache/tomcat/util/net/openssl/panama/LocalStrings.properties
+++ b/java/org/apache/tomcat/util/net/openssl/panama/LocalStrings.properties
@@ -70,6 +70,7 @@ openssl.noCACerts=No CA certificates were configured
openssl.nonJsseCertificate=The certificate [{0}] or its private key [{1}]
could not be processed using a JSSE key manager and will be given directly to
OpenSSL
openssl.nonJsseChain=The certificate chain [{0}] was not specified or was not
valid and JSSE requires a valid certificate chain so attempting to use OpenSSL
directly
openssl.passwordTooLong=The certificate password is too long
+openssl.pskTls12Unsupported=The OpenSSL implementation does not support TLS
1.2 pre-shared keys
openssl.pskTls13Unsupported=The OpenSSL implementation does not support TLS
1.3 pre-shared keys
openssl.setCustomDHParameters=Setting custom DH parameters ([{0}] bits) for
the key [{1}]
openssl.setECDHCurve=Setting ECDH curve ([{0}]) for the key [{1}]
diff --git a/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java
b/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java
index 445de98dda..97fb815128 100644
--- a/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java
+++ b/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java
@@ -662,19 +662,25 @@ public class OpenSSLContext implements
org.apache.tomcat.util.net.SSLContext {
OpenSSLPreSharedKeySelector selector = new
OpenSSLPreSharedKeySelector(psks);
for (String protocol : sslHostConfig.getEnabledProtocols()) {
if (Constants.SSL_PROTO_TLSv1_2.equals(protocol) &&
clientMode) {
+ if (openssl_h_Compatibility.LIBRESSL) {
+ throw new
SSLException(sm.getString("openssl.pskTls12Unsupported"));
+ }
SSL_CTX_set_psk_client_callback(state.sslCtx,
SSL_psk_client_cb_func.allocate(new
PskClientCallback(selector), contextArena));
} else if (Constants.SSL_PROTO_TLSv1_3.equals(protocol) &&
clientMode) {
- if (openssl_h_Compatibility.LIBRESSL) {
+ if (openssl_h_Compatibility.LIBRESSL ||
openssl_h_Compatibility.BORINGSSL) {
throw new
SSLException(sm.getString("openssl.pskTls13Unsupported"));
}
SSL_CTX_set_psk_use_session_callback(state.sslCtx,
SSL_psk_use_session_cb_func
.allocate(new PskUseSessionCallback(selector,
contextArena), contextArena));
} else if (Constants.SSL_PROTO_TLSv1_2.equals(protocol) &&
!clientMode) {
+ if (openssl_h_Compatibility.LIBRESSL) {
+ throw new
SSLException(sm.getString("openssl.pskTls12Unsupported"));
+ }
SSL_CTX_set_psk_server_callback(state.sslCtx,
SSL_psk_server_cb_func
.allocate(new PskServerCallback(selector),
contextArena));
} else if (Constants.SSL_PROTO_TLSv1_3.equals(protocol) &&
!clientMode) {
- if (openssl_h_Compatibility.LIBRESSL) {
+ if (openssl_h_Compatibility.LIBRESSL ||
openssl_h_Compatibility.BORINGSSL) {
throw new
SSLException(sm.getString("openssl.pskTls13Unsupported"));
}
SSL_CTX_set_psk_find_session_callback(state.sslCtx,
SSL_psk_find_session_cb_func
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]