This is an automated email from the ASF dual-hosted git repository.

rmaucher pushed a commit to branch main
in repository https://gitbox.apache.org/repos/asf/tomcat.git


The following commit(s) were added to refs/heads/main by this push:
     new 9e8594c2b1 LibreSSL does not support PSK at all
9e8594c2b1 is described below

commit 9e8594c2b1bef6d82eb97384ab88ed3fff947a87
Author: remm <[email protected]>
AuthorDate: Fri Sep 25 13:00:23 2026 +0200

    LibreSSL does not support PSK at all
    
    And BoringSSL only supports TLS 1.2.
---
 .../tomcat/util/net/openssl/panama/LocalStrings.properties     |  1 +
 .../apache/tomcat/util/net/openssl/panama/OpenSSLContext.java  | 10 ++++++++--
 2 files changed, 9 insertions(+), 2 deletions(-)

diff --git 
a/java/org/apache/tomcat/util/net/openssl/panama/LocalStrings.properties 
b/java/org/apache/tomcat/util/net/openssl/panama/LocalStrings.properties
index ad24091af1..31e163cb9c 100644
--- a/java/org/apache/tomcat/util/net/openssl/panama/LocalStrings.properties
+++ b/java/org/apache/tomcat/util/net/openssl/panama/LocalStrings.properties
@@ -70,6 +70,7 @@ openssl.noCACerts=No CA certificates were configured
 openssl.nonJsseCertificate=The certificate [{0}] or its private key [{1}] 
could not be processed using a JSSE key manager and will be given directly to 
OpenSSL
 openssl.nonJsseChain=The certificate chain [{0}] was not specified or was not 
valid and JSSE requires a valid certificate chain so attempting to use OpenSSL 
directly
 openssl.passwordTooLong=The certificate password is too long
+openssl.pskTls12Unsupported=The OpenSSL implementation does not support TLS 
1.2 pre-shared keys
 openssl.pskTls13Unsupported=The OpenSSL implementation does not support TLS 
1.3 pre-shared keys
 openssl.setCustomDHParameters=Setting custom DH parameters ([{0}] bits) for 
the key [{1}]
 openssl.setECDHCurve=Setting ECDH curve ([{0}]) for the key [{1}]
diff --git a/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java 
b/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java
index 445de98dda..97fb815128 100644
--- a/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java
+++ b/java/org/apache/tomcat/util/net/openssl/panama/OpenSSLContext.java
@@ -662,19 +662,25 @@ public class OpenSSLContext implements 
org.apache.tomcat.util.net.SSLContext {
                 OpenSSLPreSharedKeySelector selector = new 
OpenSSLPreSharedKeySelector(psks);
                 for (String protocol : sslHostConfig.getEnabledProtocols()) {
                     if (Constants.SSL_PROTO_TLSv1_2.equals(protocol) && 
clientMode) {
+                        if (openssl_h_Compatibility.LIBRESSL) {
+                            throw new 
SSLException(sm.getString("openssl.pskTls12Unsupported"));
+                        }
                         SSL_CTX_set_psk_client_callback(state.sslCtx,
                                 SSL_psk_client_cb_func.allocate(new 
PskClientCallback(selector), contextArena));
                     } else if (Constants.SSL_PROTO_TLSv1_3.equals(protocol) && 
clientMode) {
-                        if (openssl_h_Compatibility.LIBRESSL) {
+                        if (openssl_h_Compatibility.LIBRESSL || 
openssl_h_Compatibility.BORINGSSL) {
                             throw new 
SSLException(sm.getString("openssl.pskTls13Unsupported"));
                         }
                         SSL_CTX_set_psk_use_session_callback(state.sslCtx, 
SSL_psk_use_session_cb_func
                                 .allocate(new PskUseSessionCallback(selector, 
contextArena), contextArena));
                     } else if (Constants.SSL_PROTO_TLSv1_2.equals(protocol) && 
!clientMode) {
+                        if (openssl_h_Compatibility.LIBRESSL) {
+                            throw new 
SSLException(sm.getString("openssl.pskTls12Unsupported"));
+                        }
                         SSL_CTX_set_psk_server_callback(state.sslCtx, 
SSL_psk_server_cb_func
                                 .allocate(new PskServerCallback(selector), 
contextArena));
                     } else if (Constants.SSL_PROTO_TLSv1_3.equals(protocol) && 
!clientMode) {
-                        if (openssl_h_Compatibility.LIBRESSL) {
+                        if (openssl_h_Compatibility.LIBRESSL || 
openssl_h_Compatibility.BORINGSSL) {
                             throw new 
SSLException(sm.getString("openssl.pskTls13Unsupported"));
                         }
                         SSL_CTX_set_psk_find_session_callback(state.sslCtx, 
SSL_psk_find_session_cb_func


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to