[Touch-packages] [Bug 1994165] Re: CMS_final: do not ignore CMS_dataFinal result

2024-01-25 Thread Adrien Nader
** Tags removed: verification-needed verification-needed-jammy ** Tags added: verification-done verification-done-jammy ** Tags removed: foundations-triage-discuss -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ub

[Touch-packages] [Bug 2017924] Re: package libssl1.1 1.1.1f-1ubuntu2 failed to install/upgrade: trying to overwrite shared '/usr/share/doc/libssl1.1/changelog.Debian.gz', which is different from other

2023-04-28 Thread Adrien Nader
Hi, can you confirm that you've followed the guide at https://pimylifeup.com/ubuntu-unifi-controller/ ? -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/2017924 Title: packa

[Touch-packages] [Bug 2017924] Re: package libssl1.1 1.1.1f-1ubuntu2 failed to install/upgrade: trying to overwrite shared '/usr/share/doc/libssl1.1/changelog.Debian.gz', which is different from other

2023-04-28 Thread Adrien Nader
Unfortunately, installing older versions of packages that way is a pretty quick way to break a system. I don't think there's a bug in the openssl packages because the steps you followed are not supported. If I were you, I would try to dpkg -r the package and carefully clean up and revert the chang

[Touch-packages] [Bug 2017924] Re: package libssl1.1 1.1.1f-1ubuntu2 failed to install/upgrade: trying to overwrite shared '/usr/share/doc/libssl1.1/changelog.Debian.gz', which is different from other

2023-05-01 Thread Adrien Nader
** Changed in: openssl (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/2017924 Title: package libssl1.1 1.1.1f-1ubuntu2 failed to ins

[Touch-packages] [Bug 2008846] Re: package libssl3:amd64 3.0.2-0ubuntu1.8 failed to install/upgrade: installed libssl3:amd64 package post-installation script subprocess returned error exit status 1

2023-05-11 Thread Adrien Nader
This doesn't seem to be an issue with the openssl package itself. (oops, sent my message too quickly) In DpkgTerminalLog.gz there is this line: debconf: DbDriver "config": /var/cache/debconf/config.dat is locked by another process: Resource temporarily unavailable In general you might be ab

[Touch-packages] [Bug 1613658] Re: OPENSSL_init_library () crash in conjunction with faketime

2023-05-11 Thread Adrien Nader
AFAIU, bug is in faketime rather than in openssl. It's also an old issue fixed upstream and faketime is in universe. As a consequence, I'm closing this. ** Changed in: openssl (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch se

[Touch-packages] [Bug 357998] Re: openssh-client (amd64) can't login after upgrade to jaunty

2023-05-11 Thread Adrien Nader
** Changed in: seahorse Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/357998 Title: openssh-client (amd64) can't login after upgrade to j

[Touch-packages] [Bug 95001] Re: Please provide FIPS compliant version

2023-05-11 Thread Adrien Nader
I think this should be won't fix since there is now a FIPS version available and it's 100% sure it must not be the default version (and that it wouldn't make a lot of sense even for people who want FIPS stuff). -- You received this bug notification because you are a member of Ubuntu Touch seeded

[Touch-packages] [Bug 429907] Re: md4 should be deprecated

2023-05-11 Thread Adrien Nader
AFAIU, MD4 is officially deprecated in openssl and it should also be forbidden with openssl's seclevel. Right now I actually have troubles finding definitive answers because of how long this has probably been. ** Changed in: openssl (Ubuntu) Status: Confirmed => Fix Released -- You recei

[Touch-packages] [Bug 429907] Re: md4 should be deprecated

2023-05-11 Thread Adrien Nader
And as far as I can tell, gnutls doesn't use MD4 anymore. Marking as Fix released also for gnutls26. ** Changed in: gnutls26 (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to gn

[Touch-packages] [Bug 795355] Re: Intermittent SSL connection faults when using TLSv1

2023-05-11 Thread Adrien Nader
** Changed in: openssl (Ubuntu) Status: Confirmed => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/795355 Title: Intermittent SSL connection faults when

[Touch-packages] [Bug 592442] Re: fopen fails on some SSL urls

2023-05-11 Thread Adrien Nader
It looks like php5 was changed to accomodate whatever openssl was doing. It's difficult to tell whether something has been changed on the openssl side in the meantime but considering how long it's been, I see no reason to keep this bug open. -- You received this bug notification because you are a

[Touch-packages] [Bug 1018307] Re: SSL renegotiation fails

2023-05-11 Thread Adrien Nader
I'm going to mark this bug as Incomplete. If it is encountered again, please try to provide a reproducer: having to reproduce against a multi- tenant postgresql is a lot of work (especially when you're not familiar with pg). ** Changed in: openssl (Ubuntu) Status: Confirmed => Incomplete -

[Touch-packages] [Bug 595415] Re: Curl (openssl) fails to open some https URLs with "illegal parameter" error

2023-05-11 Thread Adrien Nader
I'm going to mark this as Fix Released due to the message above even though I wasn't able to try to reproduce today (due to so many things having changed since 2012). ** Changed in: openssl (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a

[Touch-packages] [Bug 597984] Re: Some patents have expired but still openssl package does not support them.

2023-05-11 Thread Adrien Nader
Camellia is available IIRC although it is going away. IDEA already went away in real-world scenarios (but it might be available anyway) and MDC-2 is something I hadn't heard of before now. I'm marking this as Invalid because there is no single Status meaningful here since this mentions three diffe

[Touch-packages] [Bug 396818] Re: openssl s_client behaves strangely without CAPath

2023-05-11 Thread Adrien Nader
I'm not seeing that behaviour on a 23.04 system and I expect it to be the same since 22.04 at least. As such I'm going to mark this as Fix Released. ** Changed in: openssl (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu T

[Touch-packages] [Bug 654896] Re: SCTP DTLS support

2023-05-11 Thread Adrien Nader
** Changed in: openssl (Ubuntu) Status: Confirmed => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/654896 Title: SCTP DTLS support Status in OpenSSL:

[Touch-packages] [Bug 665209] Re: Ctrl-\ after rejected key-encryption password causes hang

2023-05-11 Thread Adrien Nader
I tried this again (openssl3) and got the following: 40C75734AE7F:error:1465:UI routines:UI_set_result_ex:result too small:../crypto/ui/ui_lib.c:884:You must type in 4 to 1024 characters 40C75734AE7F:error:146B:UI routines:UI_process:processing error:../crypto/ui/ui_lib.c

[Touch-packages] [Bug 654493] Re: infinit loop with "openssl s_client -connect xmpp-gmx.gmx.net:5222 -starttls xmpp"

2023-05-11 Thread Adrien Nader
I'm going to replicate the status used by upstream (Invalid) even though rt.openssl.org has unfortunately been decomissioned. ** Changed in: openssl (Ubuntu) Status: Confirmed => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which

[Touch-packages] [Bug 654493] Re: infinit loop with "openssl s_client -connect xmpp-gmx.gmx.net:5222 -starttls xmpp"

2023-05-11 Thread Adrien Nader
Actually that's fix released instead. Maybe the "invalid" status comes from rt.openssl.org becoming unreachable. ** Bug watch added: github.com/openssl/openssl/issues #3980 https://github.com/openssl/openssl/issues/3980 -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 654493] Re: infinit loop with "openssl s_client -connect xmpp-gmx.gmx.net:5222 -starttls xmpp"

2023-05-11 Thread Adrien Nader
Btw, discussion upstream at https://github.com/openssl/openssl/issues/3980 (you can see everything has been imported in 2017). ** Changed in: openssl (Ubuntu) Status: Invalid => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, wh

[Touch-packages] [Bug 861137] Re: Openssl TLS errors while connecting to SSLv3 sites

2023-05-11 Thread Adrien Nader
This ticket will be WONTFIX because SSL3 is not supported anymore (and it's now known that supporting SSL2, SSL3 and TLS1.x at the same time with the same code was a mistake, which makes issues like this one not surprising). -- You received this bug notification because you are a member of Ubuntu

[Touch-packages] [Bug 1475228] Re: openssl/curl error: SSL23_GET_SERVER_HELLO:tlsv1 alert internal error on TLS only configured server

2023-05-11 Thread Adrien Nader
There has been no activity on this bug for 7 years. Marc stated 1.0.2 connects successfully. Moreover, the last comments were about this occuring with 1.0.1f on 14.04 (8 years old). Lastly, the corresponding code seems to be gone. I'll mark this as Fix Released. ** Changed in: openssl (Ubuntu)

[Touch-packages] [Bug 692589] Re: Bug in libssl-dev package, pem.h

2023-05-11 Thread Adrien Nader
I've tried to reproduce the issue (thanks for the reproducer!) and didn't manage to. I'm not sure the API is still there and in the same form but also, pem.h is vastly different and much much simpler. I think there's nothing to do and this bug should be WONTFIX. -- You received this bug notificat

[Touch-packages] [Bug 1046462] Re: CVE-2011-4109 erroneously listed in changelog as CVE-2011-4019

2023-05-11 Thread Adrien Nader
There is no mention of either CVE-2011-4019 or 4109 at the moment in debian/changelog. As such there is nothing to do. ** CVE added: https://cve.mitre.org/cgi-bin/cvename.cgi?name=2011-4019 -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is s

[Touch-packages] [Bug 1075916] Re: 'openssl ca' segfaults on second run

2023-05-11 Thread Adrien Nader
I've tried to reproduce the issue but to no avail. Having the exact steps coule be helpful. ** Changed in: openssl (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. h

[Touch-packages] [Bug 1144408] Re: libssl upgrade causes failure from old clients

2023-05-11 Thread Adrien Nader
As far as I can understand from the mailing-list thread, the patch unfortunately did not get merged. However, the versions against which this issue has been reported are also very old at this point and I think this means the issue will be WONTFIX. -- You received this bug notification because you

[Touch-packages] [Bug 1307190] Re: postinst script does not restart services

2023-05-11 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 This is not strictly a duplicate of https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1971650 since this one is now about switching to needrestart, but I believe it subsumes the current bug enough to ma

[Touch-packages] [Bug 1404029] Re: Segfault in openssl command line utility

2023-05-11 Thread Adrien Nader
The file private_key.pem was not provided and this makes it impossible to run the reproducer unfortunately. ** Changed in: openssl (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to open

[Touch-packages] [Bug 1075916] Re: 'openssl ca' segfaults on second run

2023-05-12 Thread Adrien Nader
Seth pointed out that there was actually a reproducer attached. I'm sorry to have missed it, especially considering how complete it is. Anyway, I tried it and it's successful at the moment so we'll close this bug. -- You received this bug notification because you are a member of Ubuntu Touch see

[Touch-packages] [Bug 1305175] Re: openssl 1.0.1f 'ssl handshake failure' connection failure

2023-05-12 Thread Adrien Nader
RC4-MD5 was already considered pretty bad when this bug was filled; now they're clearly deprecated and Ubuntu's openssl is actively pushing for higher security standards. As such I think this bug should be WONTFIX. -- You received this bug notification because you are a member of Ubuntu Touch see

[Touch-packages] [Bug 1334300] Re: after installing updates for OpenSSL there is no advice to reboot the PC

2023-05-12 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 I think this is pretty much a duplicate of 1971650 which is about migrating to needrestart from the current postinst. Like with another bug I recently marked as duplicate, I don't think it is exactly the sam

[Touch-packages] [Bug 1260230] Re: Memory leak in libcrypto.so\libssl.so

2023-05-12 Thread Adrien Nader
I wasn't able to reproduce the issue. I've tried the attached reproducer but: - I don't have a file "TrustStore.pem", - if I comment out the block of code that tries to load this file, I get "Certificate verification error: 20", - in both cases, valgrind reports no memory lost or still reachable.

[Touch-packages] [Bug 1791559] Re: Spurious reboot notifications caused by libssl upgrades.

2023-05-12 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 I'm going to mark this as duplicate of 1971650 which is about updating the logic for libssl upgrades since it will cover this issue too (and we'd like to address it in the not-so-distant future). ** This bu

[Touch-packages] [Bug 1420608] Re: s_client doesn't recognise XMPP STARTTLS messages with double quotes

2023-05-12 Thread Adrien Nader
I'm marking this bug as Fix Released for the openssl package too because we've incorporated this already and I can't reproduce the issue (I used conference.igniterealtime.org:5222 since the original testcase doesn't resolve anymore). ** Changed in: openssl (Ubuntu) Status: Confirmed => Fix

[Touch-packages] [Bug 1441461] Re: openssl verify fails with "certificate signature failure"

2023-05-12 Thread Adrien Nader
I was able to reproduce your results but there aren't that many patches being applied at the moment and that makes the failure surprising. I didn't spot anything obvious in the certificates either but overall I think this bug needs a reproducer which covers the generation of the certificates becaus

[Touch-packages] [Bug 1160435] Re: Unreadable or symlinked openssl.cnf breaks bind9

2023-05-12 Thread Adrien Nader
Marking as Fix Released since we've imported the fixed version from Debian. ** Changed in: openssl (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bug

[Touch-packages] [Bug 972783] Re: Crashes with segmentation fault operating asn1_meth_table

2023-05-12 Thread Adrien Nader
I've tried to reproduce this crash but I'm not sure how to do it. The various traces attached are informative but without a way to test and experiment, it's difficult to tell the consequences apart from their causes since there seems to be some memory corruption going on. I'm going to mark this as

[Touch-packages] [Bug 1152405] Re: The BIO_should_retry manual page misdocuments the behavior of the BIO_should_read

2023-05-12 Thread Adrien Nader
Looking at the current documentation, these functions are described the following way: BIO_should_read() is true if the cause of the condition is that the BIO has insufficient data to return. Check for readability and/or retry the last operation. BIO_should_write() is true if

[Touch-packages] [Bug 1314215] Re: openssl not use via-padlock

2023-05-12 Thread Adrien Nader
In debian/changelog for openssl, there is the following entry: openssl (1.0.1c-3) unstable; urgency=low * Disable padlock engine again, causes problems for hosts not supporting it. -- Kurt Roeckx Wed, 06 Jun 2012 18:29:37 +0200 As such, I believe this bug can be made W

[Touch-packages] [Bug 1865558] Re: gdm-session-worker segmentation fault when checking online crl from smartcard authentication

2023-05-12 Thread Adrien Nader
AFAIU this issue requires a specific hardware, possibly with specific configuration. Do you have a reproducer that others could use for this issue? ** Changed in: openssl (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seed

[Touch-packages] [Bug 1915906] Re: Ensure SRP BN_mod_exp follows the constant time path

2023-05-12 Thread Adrien Nader
Hi. Openssl is a delicate component, used by many other packages. As a consequence, it is only patched if there is a strong need. Looking at the pull request you've linked to, this falls outside of the openssl threat model since it is local only. I'm not sure Ubuntu has a stricter threat model for

[Touch-packages] [Bug 1320094] Re: segfault from aes ccm encryption after RSA key generation and EVP_PKEY_assign_RSA()

2023-05-12 Thread Adrien Nader
Thanks for the report and for the reproducer. I haven't been able to trigger a segfault despite numerous attempts. I'll therefore mark this bug as Incomplete for now. ** Changed in: openssl (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member o

[Touch-packages] [Bug 1864689] Re: openssl in 20.04 can't connect to site that was fine in 19.10 and is fine in Chrome and Firefox

2023-05-12 Thread Adrien Nader
Looking at the bug report opened upstream ( https://github.com/openssl/openssl/issues/11236 ), this is considered a bug on the server side and I'm inclined to follow openssl upstream on this. Moreover, I've tried all the tests provided in this bug and all have succeeded. I'll mark the bug as Inva

[Touch-packages] [Bug 1837526] Re: Restarting services puts puppet into restart-loop

2023-05-12 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 I'm marking this bug as a duplicate of #1971650 . The general goal is to move to needrestart rather than continue using the current postinst script. ** This bug has been marked a duplicate of bug 1971650

[Touch-packages] [Bug 1591833] Re: [Featue] Upgrade Openssl for Intel QAT (quickassist-technology)

2023-05-12 Thread Adrien Nader
1.1.0 has long been released so I'll mark the whole bug as Fix Released too. ** Changed in: openssl (Ubuntu) Status: In Progress => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https:

[Touch-packages] [Bug 1612711] Re: TLS negotiation fails

2023-05-12 Thread Adrien Nader
Going through this bug, I haven't noticed a full reproducer or even a domain that is supposed to trigger the issue. I'll mark this bug as Incomplete to reflect that. ** Changed in: openssl (Ubuntu) Status: Confirmed => Incomplete -- You received this bug notification because you are a mem

[Touch-packages] [Bug 1551274] Re: creating SRP file crashes openssl

2023-05-12 Thread Adrien Nader
I've tried to reproduce the issue but it doesn't fail for me. I"ve also looked at the code and it seems to now call OPENSSL_clear_free() which is actually CRYPTO_clear_free() and the first thing this function does is to check its first parameter is not NULL. Considering all of the above, I'm going

[Touch-packages] [Bug 1147526] Re: man page for SSL_CTX_set_info_callback gives incorrect signature

2023-05-12 Thread Adrien Nader
Copying this from 1297025 (from the same reporter): The man page for SSL_CTX_set_session_cache_mode gives its signature as: long SSL_CTX_set_session_cache_mode(SSL_CTX ctx, long mode); The correct signature is: long SSL_CTX_set_session_cache_mode(SSL_CTX *ctx, long mode); The same goe

[Touch-packages] [Bug 1145305] Re: SSL_CTX_set_session_cache_mode man page gives incorrect signature

2023-05-12 Thread Adrien Nader
*** This bug is a duplicate of bug 1147526 *** https://bugs.launchpad.net/bugs/1147526 I've copied this to #1147526 and I'm going to mark this one as duplicate of it. ** This bug has been marked a duplicate of bug 1147526 man page for SSL_CTX_set_info_callback gives incorrect signature --

[Touch-packages] [Bug 1297025] Re: Either the changelog.gz is missing or there is an erroneous link in the libssl1.0.0 package

2023-05-12 Thread Adrien Nader
I'm going to mark #1489207 as a duplicate of this bug because they're very close to each other and possibly actually completely related. I'm copying below the details from that bug: $ zcat /usr/share/doc/openssl/changelog.gz gzip: /usr/share/doc/openssl/changelog.gz: No such file or directory $ l

[Touch-packages] [Bug 1489207] Re: /usr/share/doc/openssl/changelog.gz is a broken symlink

2023-05-12 Thread Adrien Nader
*** This bug is a duplicate of bug 1297025 *** https://bugs.launchpad.net/bugs/1297025 ** This bug has been marked a duplicate of bug 1297025 Either the changelog.gz is missing or there is an erroneous link in the libssl1.0.0 package -- You received this bug notification because you are

[Touch-packages] [Bug 1457020] Re: x86_64-specific crash with one-word modulus

2023-05-13 Thread Adrien Nader
Unfortunately this bug report slipped by and it's certainly too late now. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/1457020 Title: x86_64-specific crash with one-word

[Touch-packages] [Bug 1677502] Re: openssl issue in ARM linux

2023-05-13 Thread Adrien Nader
It would be useful to know how tomcat is configured and have an easier reproducer, especially since there's at least 50% chance the issue is on its side. ** Changed in: openssl (Ubuntu) Status: New => Invalid ** Changed in: openssl (Ubuntu) Status: Invalid => Incomplete -- You rec

[Touch-packages] [Bug 1410989] Re: SSL_connect:unknown state

2023-05-13 Thread Adrien Nader
I tried to reproduce this but everything has changed: SSLv3 is completely unsupported, the websites connect successuflly and their ssllabs report is not too bad (at least for tm3.com). I think this will be a WONTFIX for this bug because there is no more appropriate status. -- You received this bu

[Touch-packages] [Bug 1767086] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.12 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-13 Thread Adrien Nader
*** This bug is a duplicate of bug 1747270 *** https://bugs.launchpad.net/bugs/1747270 ** This bug has been marked a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

[Touch-packages] [Bug 1851714] Re: package libssl1.1:i386 1.1.1-1ubuntu2.1~18.04.4 failed to install/upgrade: installed libssl1.1:i386 package post-installation script subprocess returned error exit s

2023-05-13 Thread Adrien Nader
*** This bug is a duplicate of bug 1775369 *** https://bugs.launchpad.net/bugs/1775369 ** This bug has been marked a duplicate of bug 1775369 package libssl1.0.0:i386 1.0.2g-1ubuntu4.12 failed to install/upgrade: subprocess installed post-installation script returned error exit status 128

[Touch-packages] [Bug 1728418] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.8 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-13 Thread Adrien Nader
*** This bug is a duplicate of bug 1747270 *** https://bugs.launchpad.net/bugs/1747270 ** This bug has been marked a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

[Touch-packages] [Bug 1862054] Re: package libssl1.1:arm64 1.1.1-1ubuntu2.1~18.04.5 failed to install/upgrade: installed libssl1.1:arm64 package post-installation script subprocess returned error exit

2023-05-13 Thread Adrien Nader
I'm marking this bug as Invalid due to the following line in DpkgTerminalLog.txt: Unknown terminal: nvs-term Debconf/whiptail failed and the issue seems to be in the machine configuration and/or whiptail/debconf rather than openssl. I'm not able to comment on the current status of these howev

[Touch-packages] [Bug 1800793] Re: package libssl1.0.0:i386 1.0.2g-1ubuntu4.13 failed to install/upgrade: подпроцесс установлен сценарий post-installation возвратил код ошибки 255

2023-05-13 Thread Adrien Nader
I'm marking this bug as Invalid due to the following line in DpkgTerminalLog.txt: Unknown terminal: screen.xterm-256color Debconf/whiptail failed and the issue seems to be in the machine configuration and/or whiptail/debconf rather than openssl. I'm not able to comment on the current status o

[Touch-packages] [Bug 1703866] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.8 failed to install/upgrade: subprocess installed post-installation script returned error exit status 255

2023-05-13 Thread Adrien Nader
I'm marking this bug as Invalid for openssl due to the discussion above and the following line in DpkgTerminalLog.txt: Unknown terminal: st-256color Debconf/whiptail failed and the issue seems to be in the machine configuration and/or whiptail/debconf rather than openssl. I'm not able to comm

[Touch-packages] [Bug 1637795] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.5 failed to install/upgrade: 子进程 已安装 post-installation 脚本 返回错误状态 255

2023-05-13 Thread Adrien Nader
I think the process was not run interactively or at least that whiptail/debconf believed it was but couldn't get _proper_ user input. This is rather an issue in whiptail/debconf or the surrounding script used here. As such, I'm going to mark this bug as Invalid. ** Changed in: openssl (Ubuntu)

[Touch-packages] [Bug 1806162] Re: package libssl1.1:i386 1.1.0g-2ubuntu4.1 failed to install/upgrade: installed libssl1.1:i386 package post-installation script subprocess was killed by signal (Broken

2023-05-13 Thread Adrien Nader
I'm not able to extract useful hints from the logs: too many thing could have caused this error and the logs don't help narrow things down. LP#1806162 might be the same issue but there aren't enough hints to be sure. In any case, I'm going to mark the current bug as Incomplete and work on the othe

[Touch-packages] [Bug 1391299] Re: after fresh install sudo apt-get dist-upgrade package libssl1.0.0:amd64 1.0.1f-1ubuntu2.7 failed to install/upgrade: package libssl1.0.0:amd64 is already installed a

2023-05-13 Thread Adrien Nader
The root issue seems to be with libapt instead so I'm going to mark this bug as Invalid. ** Changed in: openssl (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https:/

[Touch-packages] [Bug 1627952] Re: package libssl1.0.0:amd64 1.0.1f-1ubuntu2.21 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-13 Thread Adrien Nader
*** This bug is a duplicate of bug 1747270 *** https://bugs.launchpad.net/bugs/1747270 ** This bug has been marked a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

[Touch-packages] [Bug 1623638] Re: package libssl1.0.0:i386 1.0.2g-1ubuntu4.2 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-13 Thread Adrien Nader
*** This bug is a duplicate of bug 1747270 *** https://bugs.launchpad.net/bugs/1747270 ** This bug has been marked a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

[Touch-packages] [Bug 1743291] Re: package libssl-dev:amd64 1.0.2g-1ubuntu4.10 failed to install/upgrade: El paquete está en un estado grave de inconsistencia - debe reinstalarlo antes de intentar su

2023-05-13 Thread Adrien Nader
Following Seth's comment, I'm marking this issue as Incomplete. ** Changed in: openssl (Ubuntu) Status: New => Incomplete -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bu

[Touch-packages] [Bug 1610599] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-13 Thread Adrien Nader
*** This bug is a duplicate of bug 1747270 *** https://bugs.launchpad.net/bugs/1747270 ** This bug has been marked a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

[Touch-packages] [Bug 1632407] Re: -package libssl1.0.0:i386 1.0.2g-1ubuntu4.5 failed to install/upgrade: subprocess installed post-installation script was killed by signal (Terminated)

2023-05-13 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 It looks like something failed in the postinst about detecting what needs to be restarted after the library is upgraded. Removing that code altogether is a current topic because that code is quite old and be

[Touch-packages] [Bug 1734447] Re: BN_cmp regards negative and positive zero as different numbers

2023-05-13 Thread Adrien Nader
Thanks for the report and for the reproducer. I've tested it on 23.04 and got the following output: BN_cmp(A, B): 0 BN_cmp(A, B): 0 IIUC the issue is therefore fixed. ** Changed in: openssl (Ubuntu) Status: New => Fix Released -- You received this bug notification because you ar

[Touch-packages] [Bug 1875781] Re: Unable to verify self signed certificate

2023-05-13 Thread Adrien Nader
The corresponding patch has been merged in newer releases which have since been shipped. I'm going to mark this issue as Fix Released for openssl. ** Changed in: openssl (Ubuntu) Status: Triaged => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch

[Touch-packages] [Bug 1833305] Re: Unable to parse certificate - sometimes

2023-05-13 Thread Adrien Nader
The ticket usptream acknowledges the issue. A fix has been included in newer versions which we're now shipping. I'll therefore mark the issue as Fix Released. ** Changed in: openssl (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubun

[Touch-packages] [Bug 1936975] Re: `openssl dhparam` cannot validate named group DH parameters

2023-05-13 Thread Adrien Nader
I'm not sure what the current status is in 18.04 (partly because I'm not entirely sure how to actually reproduce the issue) but it's a release which is going end-of-life in two weeks and this issue will therefore unfortunately be WONTFIX for it anyway. -- You received this bug notification becaus

[Touch-packages] [Bug 1780323] Re: boot from usb freezes

2023-05-13 Thread Adrien Nader
This doesn't seem related to openssl so I'll mark this issue as Invalid. ** Changed in: openssl (Ubuntu) Status: New => Invalid -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.

[Touch-packages] [Bug 1832834] Re: Irregular system freezes after updating to 1.1.1b-1ubuntu2.2

2023-05-14 Thread Adrien Nader
Are some logs available for this? Such issues are especially surprising for security updates because they contain very few changes (on purpose) and this update was definitely small. ** Changed in: openssl (Ubuntu) Status: New => Incomplete -- You received this bug notification because you

[Touch-packages] [Bug 1865204] Re: Multiple packages broke with openssl 1.1.1 upgrade

2023-05-14 Thread Adrien Nader
I'm sorry this bug flew under the radar. These seem to have been bugs with the stunnel4 and pure-ftpd rather than openssl but I understand why you've filled a bug for openssl too. I can't tell if it would have made sense to initially disable TLS 1.3 by default when pushing openssl 1.1.1 but I thin

[Touch-packages] [Bug 1535141] Re: package libssl1.0.0:amd64 1.0.2d-0ubuntu1.2 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 I don't think there's enough information in the ticket at the moment to be able to pinpoint the issue. Since the issue is linked to the postinst which we've been shrinking but still need to shrink more (and

[Touch-packages] [Bug 1800219] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.13 failed to install/upgrade: subprocess installed post-installation script returned error exit status 1

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1930301 *** https://bugs.launchpad.net/bugs/1930301 This isn't a bug in openssl but rather in debconf as far as I understand. I'm going to mark this as duplicate of LP#1930301. ** This bug has been marked a duplicate of bug 1930301 package libpam0g:amd64

[Touch-packages] [Bug 1767086] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.12 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1456396 *** https://bugs.launchpad.net/bugs/1456396 ** This bug is no longer a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29 ** T

[Touch-packages] [Bug 1747270] Re: package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1456396 *** https://bugs.launchpad.net/bugs/1456396 This seems to be a duplicate of #1456396 which is itself probably a bug in debconf, or at least not in openssl. I'm going to mark this as a duplicate. ** This bug has been marked a duplicate of bug 1456396

[Touch-packages] [Bug 1627952] Re: package libssl1.0.0:amd64 1.0.1f-1ubuntu2.21 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1456396 *** https://bugs.launchpad.net/bugs/1456396 ** This bug is no longer a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29 ** T

[Touch-packages] [Bug 1728418] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.8 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1456396 *** https://bugs.launchpad.net/bugs/1456396 ** This bug is no longer a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29 ** T

[Touch-packages] [Bug 1456396] Re: Error on configuring

2023-05-14 Thread Adrien Nader
And searching for "new" on the debconf tracker returns a number of other results. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to debconf in Ubuntu. https://bugs.launchpad.net/bugs/1456396 Title: Error on configuring Statu

[Touch-packages] [Bug 1610599] Re: package libssl1.0.0:amd64 1.0.2g-1ubuntu4.1 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1456396 *** https://bugs.launchpad.net/bugs/1456396 ** This bug is no longer a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29 ** T

[Touch-packages] [Bug 1456396] Re: Error on configuring

2023-05-14 Thread Adrien Nader
I'm going to mark this bug as a Invalid on the openssl side since the issue is more likely with debconf or at least makes more sense to handle from there or the like. Btw, I've gone over many years of openssl tickets on launchpad and I've marked several tickets as duplicate of this bug, which expl

[Touch-packages] [Bug 1623638] Re: package libssl1.0.0:i386 1.0.2g-1ubuntu4.2 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1456396 *** https://bugs.launchpad.net/bugs/1456396 ** This bug is no longer a duplicate of bug 1747270 package libssl1.0.0:i386 1.0.2g-1ubuntu4.10 failed to install/upgrade: subprocess installed post-installation script returned error exit status 29 ** T

[Touch-packages] [Bug 1851714] Re: package libssl1.1:i386 1.1.1-1ubuntu2.1~18.04.4 failed to install/upgrade: installed libssl1.1:i386 package post-installation script subprocess returned error exit s

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 ** This bug is no longer a duplicate of bug 1775369 package libssl1.0.0:i386 1.0.2g-1ubuntu4.12 failed to install/upgrade: subprocess installed post-installation script returned error exit status 128 **

[Touch-packages] [Bug 1775369] Re: package libssl1.0.0:i386 1.0.2g-1ubuntu4.12 failed to install/upgrade: subprocess installed post-installation script returned error exit status 128

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 I'm tempted to say this is an issue in debconf but it seems the postinst was running and I've seen other errors with it so I'm going to mark this as a duplicate of the bug about moving away from this postins

[Touch-packages] [Bug 1644592] Re: package libssl-dev 1.0.2g-1 failed to install/upgrade: trying to overwrite shared '/usr/include/openssl/opensslv.h', which is different from other instances of packa

2023-05-14 Thread Adrien Nader
This error started a couple hours only after the user installed "oracle- java6-installer" with only an "apt -f install". I suspect the system was already broken at that point, possibly due to the java6 install or to user changes to make it work if it wasn't working immediately. I was thinking of m

[Touch-packages] [Bug 1706601] Re: Atstart up the bud appears But te program continous package libssl1.0.0:amd64 1.0.2g-1ubuntu4.6 [modified: lib/x86_64-linux-gnu/libcrypto.so.1.0.0 lib/x86_64-linux-g

2023-05-14 Thread Adrien Nader
Looking at the dpkg log, there had been errors for more than three weeks where dpkg would error out. Unfortunately there are no logs that go back enough so I'm going to mark the bug as Incomplete. ** Changed in: openssl (Ubuntu) Status: New => Incomplete -- You received this bug notificat

[Touch-packages] [Bug 1474103] Re: package libssl1.0.0:i386 1.0.1f-1ubuntu2.15 failed to install/upgrade: package is in a very bad inconsistent state; you should reinstall it before attempting config

2023-05-14 Thread Adrien Nader
I'm not able to find much in the logs. The error itself also does not necessarily originate from openssl: it could simply be the victim of something else (like a crash or power off while it was being installed I think). I'm going to mark this as Incomplete due to this. ** Changed in: openssl (Ubun

[Touch-packages] [Bug 2003333] Re: package libssl3:amd64 3.0.2-0ubuntu1.7 failed to install/upgrade: installed libssl3:amd64 package post-installation script subprocess was killed by signal (Broken pi

2023-05-14 Thread Adrien Nader
*** This bug is a duplicate of bug 1971650 *** https://bugs.launchpad.net/bugs/1971650 I'm marking all reports about errors in postinst as duplicate of #1971650 where we want to get rid of the logic to detect what needs to be restarted (and restart them). ** This bug has been marked a duplica

[Touch-packages] [Bug 1720643] Re: relocation error: /usr/lib/x86_64-linux-gnu/libssl.so: symbol EVP_rc4, version OPENSSL_1.0.0 not defined in file libcrypto.so.1.0.0 with link time reference

2023-05-15 Thread Adrien Nader
We're going to mark this as Won't Fix because while the report is about 1.0.x, at the moment it's clear there won't be any more RC4. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net

[Touch-packages] [Bug 1802125] Re: openssl 1.1.0 incorrectly verifies certificates with permitted name constraints

2023-05-15 Thread Adrien Nader
Since the versions currently in Ubuntu contain this fix, I'm going to mark this bug as Fix Released. ** Changed in: openssl (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl i

[Touch-packages] [Bug 1842383] Re: openssl 1.1.1 memory overuse/leak

2023-05-15 Thread Adrien Nader
I expect the fix for this to be shipped already and Ubuntu 18.04 is reaching end-of-life in a few days. Considering both of these elements, I'm going to mark this as Fix Released. ** Changed in: openssl (Ubuntu) Status: New => Fix Released -- You received this bug notification because you

[Touch-packages] [Bug 1820172] Re: [regression] Python async test fails with OpenSSL 1.1.1b

2023-05-15 Thread Adrien Nader
As far as I understand, this was an issue in python and it has been fixed. I'm going to mark the openssl side as Invalid. I guess the python side can be marked as Fix Released but I'll let you do it. ** Changed in: openssl (Ubuntu) Status: New => Invalid -- You received this bug notifica

[Touch-packages] [Bug 1469834] Re: openssl 1.0.1f-1ubuntu2.15 prevents connection to WPA Enterprise networks

2023-05-15 Thread Adrien Nader
Thanks for the analysis and testing. I think we can mark this issue as Won't Fix, especially after all this time. -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. https://bugs.launchpad.net/bugs/1469834 Titl

[Touch-packages] [Bug 1832822] Re: functionality stopped working (extra new_oids policy)

2023-05-15 Thread Adrien Nader
I've tried to reproduce on Lunar and got a CSR. I'm going to mark this as Fix Released. ** Changed in: openssl (Ubuntu) Status: New => Fix Released -- You received this bug notification because you are a member of Ubuntu Touch seeded packages, which is subscribed to openssl in Ubuntu. htt

[Touch-packages] [Bug 50333] Re: Default configuration file prevents the creation of a valid Certificate Authority

2023-05-15 Thread Adrien Nader
I'm leaning towards marking this bug as Won't Fix. As stated above, this is needed by a minority of users and the current configuration (which is still the same regarding this) is therefore sound for the vast majority of users. Moreover this would have consequences for this majority of users as sta

[Touch-packages] [Bug 2019970] Re: OpenSSL 3.0.2 crash in Ubuntu 22.04.2 LTS

2023-05-17 Thread Adrien Nader
Hi, Thank you for taking the time to report this issue and providing a reproducer. Unfortunately I have not succeeded in reproducing the issue. In a fresh jammy container, using "OPENSSL_BRANCH=openssl-3.0.3 scripts/fullbuild.sh", I then ran "ln -s oqsprovider.so _build/lib/oqsprovider2.so" which

<    1   2   3   >