Zoltan Borok-Nagy has posted comments on this change. ( 
http://gerrit.cloudera.org:8080/24814 )

Change subject: IMPALA-15354: bump Thrift to 0.24.0 - C++ parts
......................................................................


Patch Set 6: Code-Review+1

(1 comment)

http://gerrit.cloudera.org:8080/#/c/24814/6/be/src/rpc/thrift-util.cc
File be/src/rpc/thrift-util.cc:

http://gerrit.cloudera.org:8080/#/c/24814/6/be/src/rpc/thrift-util.cc@229
PS6, Line 229: #if OPENSSL_VERSION_NUMBER < 0x10002000L
             :   // TODO: OpenSSL 1.0.1 is old. Centos 7.4 and above use 1.0.2. 
This probably can
             :   // be removed.
             :   // OpenSSL 1.0.1 and below only support setting a single ECDH 
curve at once.
             :   // We choose prime256v1 because it's the first curve listed in 
the "modern
             :   // compatibility" section of the Mozilla Server Side TLS 
recommendations,
             :   // accessed Feb. 2017.
             :   c_unique_ptr<EC_KEY> ecdh{
             :       EC_KEY_new_by_curve_name(NID_X9_62_prime256v1), 
&EC_KEY_free};
             :   if (ecdh == nullptr) {
             :     throw TSSLException(
             :         "failed to create prime256v1 curve: " + 
kudu::security::GetOpenSSLErrors());
             :   }
             :
             :   int rc = SSL_CTX_set_tmp_ecdh(ctx_->get(), ecdh.get());
             :   if (rc <= 0) {
             :     throw TSSLException(
             :         "failed to set ECDH curve: " + 
kudu::security::GetOpenSSLErrors());
             :   }
             : #elif OPENSSL_VERSION_NUMBER < 0x10100000L
             :   // OpenSSL 1.0.2 provides the set_ecdh_auto API which 
internally figures out
             :   // the best curve to use.
             :   int rc = SSL_CTX_set_ecdh_auto(ctx_->get(), 1);
             :   if (rc <= 0) {
             :     throw TSSLException(
             :         "failed to configure ECDH support: " + 
kudu::security::GetOpenSSLErrors());
             :   }
             : #endif
Dead code because of the static_asssert at L131.



--
To view, visit http://gerrit.cloudera.org:8080/24814
To unsubscribe, visit http://gerrit.cloudera.org:8080/settings

Gerrit-Project: Impala-ASF
Gerrit-Branch: master
Gerrit-MessageType: comment
Gerrit-Change-Id: Ieea10df03996fef64ea25f51c9e5e4e47c8cefa1
Gerrit-Change-Number: 24814
Gerrit-PatchSet: 6
Gerrit-Owner: Csaba Ringhofer <[email protected]>
Gerrit-Reviewer: Csaba Ringhofer <[email protected]>
Gerrit-Reviewer: Impala Public Jenkins <[email protected]>
Gerrit-Reviewer: Kurt Deschler <[email protected]>
Gerrit-Reviewer: Michael Smith <[email protected]>
Gerrit-Reviewer: Zoltan Borok-Nagy <[email protected]>
Gerrit-Comment-Date: Wed, 16 Sep 2026 11:30:53 +0000
Gerrit-HasComments: Yes

Reply via email to