Public bug reported:

Identified on Ubuntu 18.04

/etc/os-release:
NAME="Ubuntu"
VERSION="18.04.5 LTS (Bionic Beaver)"
ID=ubuntu
ID_LIKE=debian
PRETTY_NAME="Ubuntu 18.04.5 LTS"
VERSION_ID="18.04"
HOME_URL="https://www.ubuntu.com/";
SUPPORT_URL="https://help.ubuntu.com/";
BUG_REPORT_URL="https://bugs.launchpad.net/ubuntu/";
PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy";
VERSION_CODENAME=bionic
UBUNTU_CODENAME=bionic


Steps to reproduce:
$ openssl dhparam 


Actual Results:
```
    DH Parameters: (8192 bit)
        prime:
            00:ff:ff:ff:ff:ff:ff:ff:ff:ad:f8:54:58:a2:bb:
            4a:9a:af:dc:56:20:27:3d:3c:f1:d8:b9:c5:83:ce:
            2d:36:95:a9:e1:36:41:14:64:33:fb:cc:93:9d:ce:
            24:9b:3e:f9:7d:2f:e3:63:63:0c:75:d8:f6:81:b2:
            02:ae:c4:61:7a:d3:df:1e:d5:d5:fd:65:61:24:33:
            f5:1f:5f:06:6e:d0:85:63:65:55:3d:ed:1a:f3:b5:
            57:13:5e:7f:57:c9:35:98:4f:0c:70:e0:e6:8b:77:
            e2:a6:89:da:f3:ef:e8:72:1d:f1:58:a1:36:ad:e7:
            35:30:ac:ca:4f:48:3a:79:7a:bc:0a:b1:82:b3:24:
            fb:61:d1:08:a9:4b:b2:c8:e3:fb:b9:6a:da:b7:60:
            d7:f4:68:1d:4f:42:a3:de:39:4d:f4:ae:56:ed:e7:
            63:72:bb:19:0b:07:a7:c8:ee:0a:6d:70:9e:02:fc:
            e1:cd:f7:e2:ec:c0:34:04:cd:28:34:2f:61:91:72:
            fe:9c:e9:85:83:ff:8e:4f:12:32:ee:f2:81:83:c3:
            fe:3b:1b:4c:6f:ad:73:3b:b5:fc:bc:2e:c2:20:05:
            c5:8e:f1:83:7d:16:83:b2:c6:f3:4a:26:c1:b2:ef:
            fa:88:6b:42:38:61:1f:cf:dc:de:35:5b:3b:65:19:
            03:5b:bc:34:f4:de:f9:9c:02:38:61:b4:6f:c9:d6:
            e6:c9:07:7a:d9:1d:26:91:f7:f7:ee:59:8c:b0:fa:
            c1:86:d9:1c:ae:fe:13:09:85:13:92:70:b4:13:0c:
            93:bc:43:79:44:f4:fd:44:52:e2:d7:4d:d3:64:f2:
            e2:1e:71:f5:4b:ff:5c:ae:82:ab:9c:9d:f6:9e:e8:
            6d:2b:c5:22:36:3a:0d:ab:c5:21:97:9b:0d:ea:da:
            1d:bf:9a:42:d5:c4:48:4e:0a:bc:d0:6b:fa:53:dd:
            ef:3c:1b:20:ee:3f:d5:9d:7c:25:e4:1d:2b:66:9e:
            1e:f1:6e:6f:52:c3:16:4d:f4:fb:79:30:e9:e4:e5:
            88:57:b6:ac:7d:5f:42:d6:9f:6d:18:77:63:cf:1d:
            55:03:40:04:87:f5:5b:a5:7e:31:cc:7a:71:35:c8:
            86:ef:b4:31:8a:ed:6a:1e:01:2d:9e:68:32:a9:07:
            60:0a:91:81:30:c4:6d:c7:78:f9:71:ad:00:38:09:
            29:99:a3:33:cb:8b:7a:1a:1d:b9:3d:71:40:00:3c:
            2a:4e:ce:a9:f9:8d:0a:cc:0a:82:91:cd:ce:c9:7d:
            cf:8e:c9:b5:5a:7f:88:a4:6b:4d:b5:a8:51:f4:41:
            82:e1:c6:8a:00:7e:5e:0d:d9:02:0b:fd:64:b6:45:
            03:6c:7a:4e:67:7d:2c:38:53:2a:3a:23:ba:44:42:
            ca:f5:3e:a6:3b:b4:54:32:9b:76:24:c8:91:7b:dd:
            64:b1:c0:fd:4c:b3:8e:8c:33:4c:70:1c:3a:cd:ad:
            06:57:fc:cf:ec:71:9b:1f:5c:3e:4e:46:04:1f:38:
            81:47:fb:4c:fd:b4:77:a5:24:71:f7:a9:a9:69:10:
            b8:55:32:2e:db:63:40:d8:a0:0e:f0:92:35:05:11:
            e3:0a:be:c1:ff:f9:e3:a2:6e:7f:b2:9f:8c:18:30:
            23:c3:58:7e:38:da:00:77:d9:b4:76:3e:4e:4b:94:
            b2:bb:c1:94:c6:65:1e:77:ca:f9:92:ee:aa:c0:23:
            2a:28:1b:f6:b3:a7:39:c1:22:61:16:82:0a:e8:db:
            58:47:a6:7c:be:f9:c9:09:1b:46:2d:53:8c:d7:2b:
            03:74:6a:e7:7f:5e:62:29:2c:31:15:62:a8:46:50:
            5d:c8:2d:b8:54:33:8a:e4:9f:52:35:c9:5b:91:17:
            8c:cf:2d:d5:ca:ce:f4:03:ec:9d:18:10:c6:27:2b:
            04:5b:3b:71:f9:dc:6b:80:d6:3f:dd:4a:8e:9a:db:
            1e:69:62:a6:95:26:d4:31:61:c1:a4:1d:57:0d:79:
            38:da:d4:a4:0e:32:9c:cf:f4:6a:aa:36:ad:00:4c:
            f6:00:c8:38:1e:42:5a:31:d9:51:ae:64:fd:b2:3f:
            ce:c9:50:9d:43:68:7f:eb:69:ed:d1:cc:5e:0b:8c:
            c3:bd:f6:4b:10:ef:86:b6:31:42:a3:ab:88:29:55:
            5b:2f:74:7c:93:26:65:cb:2c:0f:1c:c0:1b:d7:02:
            29:38:88:39:d2:af:05:e4:54:50:4a:c7:8b:75:82:
            82:28:46:c0:ba:35:c3:5f:5c:59:16:0c:c0:46:fd:
            82:51:54:1f:c6:8c:9c:86:b0:22:bb:70:99:87:6a:
            46:0e:74:51:a8:a9:31:09:70:3f:ee:1c:21:7e:6c:
            38:26:e5:2c:51:aa:69:1e:0e:42:3c:fc:99:e9:e3:
            16:50:c1:21:7b:62:48:16:cd:ad:9a:95:f9:d5:b8:
            01:94:88:d9:c0:a0:a1:fe:30:75:a5:77:e2:31:83:
            f8:1d:4a:3f:2f:a4:57:1e:fc:8c:e0:ba:8a:4f:e8:
            b6:85:5d:fe:72:b0:a6:6e:de:d2:fb:ab:fb:e5:8a:
            30:fa:fa:be:1c:5d:71:a8:7e:2f:74:1e:f8:c1:fe:
            86:fe:a6:bb:fd:e5:30:67:7f:0d:97:d1:1d:49:f7:
            a8:44:3d:08:22:e5:06:a9:f4:61:4e:01:1e:2a:94:
            83:8f:f8:8c:d6:8c:8b:b7:c5:c6:42:4c:ff:ff:ff:
            ff:ff:ff:ff:ff

        generator: 2 (0x2)
        recommended-private-length: 400 bits
WARNING: the g value is not a generator
```

Expected Results:
```
    DH Parameters: (8192 bit)
        prime:
            00:ff:ff:ff:ff:ff:ff:ff:ff:ad:f8:54:58:a2:bb:
            4a:9a:af:dc:56:20:27:3d:3c:f1:d8:b9:c5:83:ce:
            2d:36:95:a9:e1:36:41:14:64:33:fb:cc:93:9d:ce:
            24:9b:3e:f9:7d:2f:e3:63:63:0c:75:d8:f6:81:b2:
            02:ae:c4:61:7a:d3:df:1e:d5:d5:fd:65:61:24:33:
            f5:1f:5f:06:6e:d0:85:63:65:55:3d:ed:1a:f3:b5:
            57:13:5e:7f:57:c9:35:98:4f:0c:70:e0:e6:8b:77:
            e2:a6:89:da:f3:ef:e8:72:1d:f1:58:a1:36:ad:e7:
            35:30:ac:ca:4f:48:3a:79:7a:bc:0a:b1:82:b3:24:
            fb:61:d1:08:a9:4b:b2:c8:e3:fb:b9:6a:da:b7:60:
            d7:f4:68:1d:4f:42:a3:de:39:4d:f4:ae:56:ed:e7:
            63:72:bb:19:0b:07:a7:c8:ee:0a:6d:70:9e:02:fc:
            e1:cd:f7:e2:ec:c0:34:04:cd:28:34:2f:61:91:72:
            fe:9c:e9:85:83:ff:8e:4f:12:32:ee:f2:81:83:c3:
            fe:3b:1b:4c:6f:ad:73:3b:b5:fc:bc:2e:c2:20:05:
            c5:8e:f1:83:7d:16:83:b2:c6:f3:4a:26:c1:b2:ef:
            fa:88:6b:42:38:61:1f:cf:dc:de:35:5b:3b:65:19:
            03:5b:bc:34:f4:de:f9:9c:02:38:61:b4:6f:c9:d6:
            e6:c9:07:7a:d9:1d:26:91:f7:f7:ee:59:8c:b0:fa:
            c1:86:d9:1c:ae:fe:13:09:85:13:92:70:b4:13:0c:
            93:bc:43:79:44:f4:fd:44:52:e2:d7:4d:d3:64:f2:
            e2:1e:71:f5:4b:ff:5c:ae:82:ab:9c:9d:f6:9e:e8:
            6d:2b:c5:22:36:3a:0d:ab:c5:21:97:9b:0d:ea:da:
            1d:bf:9a:42:d5:c4:48:4e:0a:bc:d0:6b:fa:53:dd:
            ef:3c:1b:20:ee:3f:d5:9d:7c:25:e4:1d:2b:66:9e:
            1e:f1:6e:6f:52:c3:16:4d:f4:fb:79:30:e9:e4:e5:
            88:57:b6:ac:7d:5f:42:d6:9f:6d:18:77:63:cf:1d:
            55:03:40:04:87:f5:5b:a5:7e:31:cc:7a:71:35:c8:
            86:ef:b4:31:8a:ed:6a:1e:01:2d:9e:68:32:a9:07:
            60:0a:91:81:30:c4:6d:c7:78:f9:71:ad:00:38:09:
            29:99:a3:33:cb:8b:7a:1a:1d:b9:3d:71:40:00:3c:
            2a:4e:ce:a9:f9:8d:0a:cc:0a:82:91:cd:ce:c9:7d:
            cf:8e:c9:b5:5a:7f:88:a4:6b:4d:b5:a8:51:f4:41:
            82:e1:c6:8a:00:7e:5e:0d:d9:02:0b:fd:64:b6:45:
            03:6c:7a:4e:67:7d:2c:38:53:2a:3a:23:ba:44:42:
            ca:f5:3e:a6:3b:b4:54:32:9b:76:24:c8:91:7b:dd:
            64:b1:c0:fd:4c:b3:8e:8c:33:4c:70:1c:3a:cd:ad:
            06:57:fc:cf:ec:71:9b:1f:5c:3e:4e:46:04:1f:38:
            81:47:fb:4c:fd:b4:77:a5:24:71:f7:a9:a9:69:10:
            b8:55:32:2e:db:63:40:d8:a0:0e:f0:92:35:05:11:
            e3:0a:be:c1:ff:f9:e3:a2:6e:7f:b2:9f:8c:18:30:
            23:c3:58:7e:38:da:00:77:d9:b4:76:3e:4e:4b:94:
            b2:bb:c1:94:c6:65:1e:77:ca:f9:92:ee:aa:c0:23:
            2a:28:1b:f6:b3:a7:39:c1:22:61:16:82:0a:e8:db:
            58:47:a6:7c:be:f9:c9:09:1b:46:2d:53:8c:d7:2b:
            03:74:6a:e7:7f:5e:62:29:2c:31:15:62:a8:46:50:
            5d:c8:2d:b8:54:33:8a:e4:9f:52:35:c9:5b:91:17:
            8c:cf:2d:d5:ca:ce:f4:03:ec:9d:18:10:c6:27:2b:
            04:5b:3b:71:f9:dc:6b:80:d6:3f:dd:4a:8e:9a:db:
            1e:69:62:a6:95:26:d4:31:61:c1:a4:1d:57:0d:79:
            38:da:d4:a4:0e:32:9c:cf:f4:6a:aa:36:ad:00:4c:
            f6:00:c8:38:1e:42:5a:31:d9:51:ae:64:fd:b2:3f:
            ce:c9:50:9d:43:68:7f:eb:69:ed:d1:cc:5e:0b:8c:
            c3:bd:f6:4b:10:ef:86:b6:31:42:a3:ab:88:29:55:
            5b:2f:74:7c:93:26:65:cb:2c:0f:1c:c0:1b:d7:02:
            29:38:88:39:d2:af:05:e4:54:50:4a:c7:8b:75:82:
            82:28:46:c0:ba:35:c3:5f:5c:59:16:0c:c0:46:fd:
            82:51:54:1f:c6:8c:9c:86:b0:22:bb:70:99:87:6a:
            46:0e:74:51:a8:a9:31:09:70:3f:ee:1c:21:7e:6c:
            38:26:e5:2c:51:aa:69:1e:0e:42:3c:fc:99:e9:e3:
            16:50:c1:21:7b:62:48:16:cd:ad:9a:95:f9:d5:b8:
            01:94:88:d9:c0:a0:a1:fe:30:75:a5:77:e2:31:83:
            f8:1d:4a:3f:2f:a4:57:1e:fc:8c:e0:ba:8a:4f:e8:
            b6:85:5d:fe:72:b0:a6:6e:de:d2:fb:ab:fb:e5:8a:
            30:fa:fa:be:1c:5d:71:a8:7e:2f:74:1e:f8:c1:fe:
            86:fe:a6:bb:fd:e5:30:67:7f:0d:97:d1:1d:49:f7:
            a8:44:3d:08:22:e5:06:a9:f4:61:4e:01:1e:2a:94:
            83:8f:f8:8c:d6:8c:8b:b7:c5:c6:42:4c:ff:ff:ff:
            ff:ff:ff:ff:ff
        generator: 2 (0x2)
        recommended-private-length: 400 bits
DH parameters appear to be ok.
```


Additional Information:

I've also tried with ffdhe2048 and ffdhe4096 with the same result.

The validation works properly on Ubuntu 20.04 as well as Fedora with
OpenSSL 1.1.1 and CentOS Stream 9 with OpenSSL 3.0.


Oddly, it validates properly if I generate a new set of parameters, rather than 
using the well-known ones:
```
    DH Parameters: (2048 bit)
        prime:
            00:ff:cf:17:da:c5:4c:48:75:0e:31:29:cd:42:2c:
            ac:7c:e2:ce:36:47:83:8a:26:b3:50:52:4d:45:e8:
            5a:63:10:f1:42:b5:fb:80:c9:99:14:07:8f:e3:98:
            18:23:91:87:aa:0f:93:49:0c:65:69:34:16:e1:9d:
            c3:f5:59:ef:24:38:0e:24:ca:d2:8d:0c:0d:9f:a6:
            8c:19:59:a2:18:ea:99:9c:76:a2:43:26:32:66:f4:
            70:62:a5:a7:a9:a3:bb:72:d0:63:16:a6:58:e8:e2:
            b5:7b:c6:98:bb:c9:d9:06:60:aa:0c:07:72:d9:7a:
            59:a1:3a:b1:ae:ee:21:29:77:38:c8:10:69:cb:8a:
            5f:38:bb:5b:02:9f:82:47:b4:9e:a2:0b:c5:87:f1:
            c6:68:05:81:57:53:0a:33:57:dc:2e:c6:a4:ca:b2:
            75:48:92:1f:cc:a1:5d:e3:1b:67:90:07:23:27:73:
            ce:4c:6c:27:da:80:2c:73:4b:3f:95:34:20:ac:e9:
            2a:8d:35:54:1f:7d:2d:99:fe:45:2c:6d:bf:03:52:
            74:13:3b:06:82:44:eb:13:d2:45:61:c9:03:a5:85:
            ba:a0:02:10:b4:9b:49:1f:72:09:a9:0f:fb:ac:3c:
            2f:db:4f:44:22:4c:ae:c8:c3:8e:16:f6:76:f1:ac:
            a7:4b
        generator: 2 (0x2)
DH parameters appear to be ok.
-----BEGIN DH PARAMETERS-----
MIIBCAKCAQEA/88X2sVMSHUOMSnNQiysfOLONkeDiiazUFJNRehaYxDxQrX7gMmZ
FAeP45gYI5GHqg+TSQxlaTQW4Z3D9VnvJDgOJMrSjQwNn6aMGVmiGOqZnHaiQyYy
ZvRwYqWnqaO7ctBjFqZY6OK1e8aYu8nZBmCqDAdy2XpZoTqxru4hKXc4yBBpy4pf
OLtbAp+CR7SeogvFh/HGaAWBV1MKM1fcLsakyrJ1SJIfzKFd4xtnkAcjJ3POTGwn
2oAsc0s/lTQgrOkqjTVUH30tmf5FLG2/A1J0EzsGgkTrE9JFYckDpYW6oAIQtJtJ
H3IJqQ/7rDwv209EIkyuyMOOFvZ28aynSwIBAg==
-----END DH PARAMETERS-----
```

** Affects: openssl (Ubuntu)
     Importance: Undecided
         Status: New

** Attachment added: "Valid ffdhe8192 DH parameters"
   
https://bugs.launchpad.net/bugs/1936975/+attachment/5512292/+files/dhparams.pem

-- 
You received this bug notification because you are a member of Ubuntu
Touch seeded packages, which is subscribed to openssl in Ubuntu.
https://bugs.launchpad.net/bugs/1936975

Title:
  `openssl dhparam` cannot validate named group DH parameters

Status in openssl package in Ubuntu:
  New

Bug description:
  Identified on Ubuntu 18.04

  /etc/os-release:
  NAME="Ubuntu"
  VERSION="18.04.5 LTS (Bionic Beaver)"
  ID=ubuntu
  ID_LIKE=debian
  PRETTY_NAME="Ubuntu 18.04.5 LTS"
  VERSION_ID="18.04"
  HOME_URL="https://www.ubuntu.com/";
  SUPPORT_URL="https://help.ubuntu.com/";
  BUG_REPORT_URL="https://bugs.launchpad.net/ubuntu/";
  
PRIVACY_POLICY_URL="https://www.ubuntu.com/legal/terms-and-policies/privacy-policy";
  VERSION_CODENAME=bionic
  UBUNTU_CODENAME=bionic


  Steps to reproduce:
  $ openssl dhparam 

  
  Actual Results:
  ```
      DH Parameters: (8192 bit)
          prime:
              00:ff:ff:ff:ff:ff:ff:ff:ff:ad:f8:54:58:a2:bb:
              4a:9a:af:dc:56:20:27:3d:3c:f1:d8:b9:c5:83:ce:
              2d:36:95:a9:e1:36:41:14:64:33:fb:cc:93:9d:ce:
              24:9b:3e:f9:7d:2f:e3:63:63:0c:75:d8:f6:81:b2:
              02:ae:c4:61:7a:d3:df:1e:d5:d5:fd:65:61:24:33:
              f5:1f:5f:06:6e:d0:85:63:65:55:3d:ed:1a:f3:b5:
              57:13:5e:7f:57:c9:35:98:4f:0c:70:e0:e6:8b:77:
              e2:a6:89:da:f3:ef:e8:72:1d:f1:58:a1:36:ad:e7:
              35:30:ac:ca:4f:48:3a:79:7a:bc:0a:b1:82:b3:24:
              fb:61:d1:08:a9:4b:b2:c8:e3:fb:b9:6a:da:b7:60:
              d7:f4:68:1d:4f:42:a3:de:39:4d:f4:ae:56:ed:e7:
              63:72:bb:19:0b:07:a7:c8:ee:0a:6d:70:9e:02:fc:
              e1:cd:f7:e2:ec:c0:34:04:cd:28:34:2f:61:91:72:
              fe:9c:e9:85:83:ff:8e:4f:12:32:ee:f2:81:83:c3:
              fe:3b:1b:4c:6f:ad:73:3b:b5:fc:bc:2e:c2:20:05:
              c5:8e:f1:83:7d:16:83:b2:c6:f3:4a:26:c1:b2:ef:
              fa:88:6b:42:38:61:1f:cf:dc:de:35:5b:3b:65:19:
              03:5b:bc:34:f4:de:f9:9c:02:38:61:b4:6f:c9:d6:
              e6:c9:07:7a:d9:1d:26:91:f7:f7:ee:59:8c:b0:fa:
              c1:86:d9:1c:ae:fe:13:09:85:13:92:70:b4:13:0c:
              93:bc:43:79:44:f4:fd:44:52:e2:d7:4d:d3:64:f2:
              e2:1e:71:f5:4b:ff:5c:ae:82:ab:9c:9d:f6:9e:e8:
              6d:2b:c5:22:36:3a:0d:ab:c5:21:97:9b:0d:ea:da:
              1d:bf:9a:42:d5:c4:48:4e:0a:bc:d0:6b:fa:53:dd:
              ef:3c:1b:20:ee:3f:d5:9d:7c:25:e4:1d:2b:66:9e:
              1e:f1:6e:6f:52:c3:16:4d:f4:fb:79:30:e9:e4:e5:
              88:57:b6:ac:7d:5f:42:d6:9f:6d:18:77:63:cf:1d:
              55:03:40:04:87:f5:5b:a5:7e:31:cc:7a:71:35:c8:
              86:ef:b4:31:8a:ed:6a:1e:01:2d:9e:68:32:a9:07:
              60:0a:91:81:30:c4:6d:c7:78:f9:71:ad:00:38:09:
              29:99:a3:33:cb:8b:7a:1a:1d:b9:3d:71:40:00:3c:
              2a:4e:ce:a9:f9:8d:0a:cc:0a:82:91:cd:ce:c9:7d:
              cf:8e:c9:b5:5a:7f:88:a4:6b:4d:b5:a8:51:f4:41:
              82:e1:c6:8a:00:7e:5e:0d:d9:02:0b:fd:64:b6:45:
              03:6c:7a:4e:67:7d:2c:38:53:2a:3a:23:ba:44:42:
              ca:f5:3e:a6:3b:b4:54:32:9b:76:24:c8:91:7b:dd:
              64:b1:c0:fd:4c:b3:8e:8c:33:4c:70:1c:3a:cd:ad:
              06:57:fc:cf:ec:71:9b:1f:5c:3e:4e:46:04:1f:38:
              81:47:fb:4c:fd:b4:77:a5:24:71:f7:a9:a9:69:10:
              b8:55:32:2e:db:63:40:d8:a0:0e:f0:92:35:05:11:
              e3:0a:be:c1:ff:f9:e3:a2:6e:7f:b2:9f:8c:18:30:
              23:c3:58:7e:38:da:00:77:d9:b4:76:3e:4e:4b:94:
              b2:bb:c1:94:c6:65:1e:77:ca:f9:92:ee:aa:c0:23:
              2a:28:1b:f6:b3:a7:39:c1:22:61:16:82:0a:e8:db:
              58:47:a6:7c:be:f9:c9:09:1b:46:2d:53:8c:d7:2b:
              03:74:6a:e7:7f:5e:62:29:2c:31:15:62:a8:46:50:
              5d:c8:2d:b8:54:33:8a:e4:9f:52:35:c9:5b:91:17:
              8c:cf:2d:d5:ca:ce:f4:03:ec:9d:18:10:c6:27:2b:
              04:5b:3b:71:f9:dc:6b:80:d6:3f:dd:4a:8e:9a:db:
              1e:69:62:a6:95:26:d4:31:61:c1:a4:1d:57:0d:79:
              38:da:d4:a4:0e:32:9c:cf:f4:6a:aa:36:ad:00:4c:
              f6:00:c8:38:1e:42:5a:31:d9:51:ae:64:fd:b2:3f:
              ce:c9:50:9d:43:68:7f:eb:69:ed:d1:cc:5e:0b:8c:
              c3:bd:f6:4b:10:ef:86:b6:31:42:a3:ab:88:29:55:
              5b:2f:74:7c:93:26:65:cb:2c:0f:1c:c0:1b:d7:02:
              29:38:88:39:d2:af:05:e4:54:50:4a:c7:8b:75:82:
              82:28:46:c0:ba:35:c3:5f:5c:59:16:0c:c0:46:fd:
              82:51:54:1f:c6:8c:9c:86:b0:22:bb:70:99:87:6a:
              46:0e:74:51:a8:a9:31:09:70:3f:ee:1c:21:7e:6c:
              38:26:e5:2c:51:aa:69:1e:0e:42:3c:fc:99:e9:e3:
              16:50:c1:21:7b:62:48:16:cd:ad:9a:95:f9:d5:b8:
              01:94:88:d9:c0:a0:a1:fe:30:75:a5:77:e2:31:83:
              f8:1d:4a:3f:2f:a4:57:1e:fc:8c:e0:ba:8a:4f:e8:
              b6:85:5d:fe:72:b0:a6:6e:de:d2:fb:ab:fb:e5:8a:
              30:fa:fa:be:1c:5d:71:a8:7e:2f:74:1e:f8:c1:fe:
              86:fe:a6:bb:fd:e5:30:67:7f:0d:97:d1:1d:49:f7:
              a8:44:3d:08:22:e5:06:a9:f4:61:4e:01:1e:2a:94:
              83:8f:f8:8c:d6:8c:8b:b7:c5:c6:42:4c:ff:ff:ff:
              ff:ff:ff:ff:ff

          generator: 2 (0x2)
          recommended-private-length: 400 bits
  WARNING: the g value is not a generator
  ```

  Expected Results:
  ```
      DH Parameters: (8192 bit)
          prime:
              00:ff:ff:ff:ff:ff:ff:ff:ff:ad:f8:54:58:a2:bb:
              4a:9a:af:dc:56:20:27:3d:3c:f1:d8:b9:c5:83:ce:
              2d:36:95:a9:e1:36:41:14:64:33:fb:cc:93:9d:ce:
              24:9b:3e:f9:7d:2f:e3:63:63:0c:75:d8:f6:81:b2:
              02:ae:c4:61:7a:d3:df:1e:d5:d5:fd:65:61:24:33:
              f5:1f:5f:06:6e:d0:85:63:65:55:3d:ed:1a:f3:b5:
              57:13:5e:7f:57:c9:35:98:4f:0c:70:e0:e6:8b:77:
              e2:a6:89:da:f3:ef:e8:72:1d:f1:58:a1:36:ad:e7:
              35:30:ac:ca:4f:48:3a:79:7a:bc:0a:b1:82:b3:24:
              fb:61:d1:08:a9:4b:b2:c8:e3:fb:b9:6a:da:b7:60:
              d7:f4:68:1d:4f:42:a3:de:39:4d:f4:ae:56:ed:e7:
              63:72:bb:19:0b:07:a7:c8:ee:0a:6d:70:9e:02:fc:
              e1:cd:f7:e2:ec:c0:34:04:cd:28:34:2f:61:91:72:
              fe:9c:e9:85:83:ff:8e:4f:12:32:ee:f2:81:83:c3:
              fe:3b:1b:4c:6f:ad:73:3b:b5:fc:bc:2e:c2:20:05:
              c5:8e:f1:83:7d:16:83:b2:c6:f3:4a:26:c1:b2:ef:
              fa:88:6b:42:38:61:1f:cf:dc:de:35:5b:3b:65:19:
              03:5b:bc:34:f4:de:f9:9c:02:38:61:b4:6f:c9:d6:
              e6:c9:07:7a:d9:1d:26:91:f7:f7:ee:59:8c:b0:fa:
              c1:86:d9:1c:ae:fe:13:09:85:13:92:70:b4:13:0c:
              93:bc:43:79:44:f4:fd:44:52:e2:d7:4d:d3:64:f2:
              e2:1e:71:f5:4b:ff:5c:ae:82:ab:9c:9d:f6:9e:e8:
              6d:2b:c5:22:36:3a:0d:ab:c5:21:97:9b:0d:ea:da:
              1d:bf:9a:42:d5:c4:48:4e:0a:bc:d0:6b:fa:53:dd:
              ef:3c:1b:20:ee:3f:d5:9d:7c:25:e4:1d:2b:66:9e:
              1e:f1:6e:6f:52:c3:16:4d:f4:fb:79:30:e9:e4:e5:
              88:57:b6:ac:7d:5f:42:d6:9f:6d:18:77:63:cf:1d:
              55:03:40:04:87:f5:5b:a5:7e:31:cc:7a:71:35:c8:
              86:ef:b4:31:8a:ed:6a:1e:01:2d:9e:68:32:a9:07:
              60:0a:91:81:30:c4:6d:c7:78:f9:71:ad:00:38:09:
              29:99:a3:33:cb:8b:7a:1a:1d:b9:3d:71:40:00:3c:
              2a:4e:ce:a9:f9:8d:0a:cc:0a:82:91:cd:ce:c9:7d:
              cf:8e:c9:b5:5a:7f:88:a4:6b:4d:b5:a8:51:f4:41:
              82:e1:c6:8a:00:7e:5e:0d:d9:02:0b:fd:64:b6:45:
              03:6c:7a:4e:67:7d:2c:38:53:2a:3a:23:ba:44:42:
              ca:f5:3e:a6:3b:b4:54:32:9b:76:24:c8:91:7b:dd:
              64:b1:c0:fd:4c:b3:8e:8c:33:4c:70:1c:3a:cd:ad:
              06:57:fc:cf:ec:71:9b:1f:5c:3e:4e:46:04:1f:38:
              81:47:fb:4c:fd:b4:77:a5:24:71:f7:a9:a9:69:10:
              b8:55:32:2e:db:63:40:d8:a0:0e:f0:92:35:05:11:
              e3:0a:be:c1:ff:f9:e3:a2:6e:7f:b2:9f:8c:18:30:
              23:c3:58:7e:38:da:00:77:d9:b4:76:3e:4e:4b:94:
              b2:bb:c1:94:c6:65:1e:77:ca:f9:92:ee:aa:c0:23:
              2a:28:1b:f6:b3:a7:39:c1:22:61:16:82:0a:e8:db:
              58:47:a6:7c:be:f9:c9:09:1b:46:2d:53:8c:d7:2b:
              03:74:6a:e7:7f:5e:62:29:2c:31:15:62:a8:46:50:
              5d:c8:2d:b8:54:33:8a:e4:9f:52:35:c9:5b:91:17:
              8c:cf:2d:d5:ca:ce:f4:03:ec:9d:18:10:c6:27:2b:
              04:5b:3b:71:f9:dc:6b:80:d6:3f:dd:4a:8e:9a:db:
              1e:69:62:a6:95:26:d4:31:61:c1:a4:1d:57:0d:79:
              38:da:d4:a4:0e:32:9c:cf:f4:6a:aa:36:ad:00:4c:
              f6:00:c8:38:1e:42:5a:31:d9:51:ae:64:fd:b2:3f:
              ce:c9:50:9d:43:68:7f:eb:69:ed:d1:cc:5e:0b:8c:
              c3:bd:f6:4b:10:ef:86:b6:31:42:a3:ab:88:29:55:
              5b:2f:74:7c:93:26:65:cb:2c:0f:1c:c0:1b:d7:02:
              29:38:88:39:d2:af:05:e4:54:50:4a:c7:8b:75:82:
              82:28:46:c0:ba:35:c3:5f:5c:59:16:0c:c0:46:fd:
              82:51:54:1f:c6:8c:9c:86:b0:22:bb:70:99:87:6a:
              46:0e:74:51:a8:a9:31:09:70:3f:ee:1c:21:7e:6c:
              38:26:e5:2c:51:aa:69:1e:0e:42:3c:fc:99:e9:e3:
              16:50:c1:21:7b:62:48:16:cd:ad:9a:95:f9:d5:b8:
              01:94:88:d9:c0:a0:a1:fe:30:75:a5:77:e2:31:83:
              f8:1d:4a:3f:2f:a4:57:1e:fc:8c:e0:ba:8a:4f:e8:
              b6:85:5d:fe:72:b0:a6:6e:de:d2:fb:ab:fb:e5:8a:
              30:fa:fa:be:1c:5d:71:a8:7e:2f:74:1e:f8:c1:fe:
              86:fe:a6:bb:fd:e5:30:67:7f:0d:97:d1:1d:49:f7:
              a8:44:3d:08:22:e5:06:a9:f4:61:4e:01:1e:2a:94:
              83:8f:f8:8c:d6:8c:8b:b7:c5:c6:42:4c:ff:ff:ff:
              ff:ff:ff:ff:ff
          generator: 2 (0x2)
          recommended-private-length: 400 bits
  DH parameters appear to be ok.
  ```

  
  Additional Information:

  I've also tried with ffdhe2048 and ffdhe4096 with the same result.

  The validation works properly on Ubuntu 20.04 as well as Fedora with
  OpenSSL 1.1.1 and CentOS Stream 9 with OpenSSL 3.0.

  
  Oddly, it validates properly if I generate a new set of parameters, rather 
than using the well-known ones:
  ```
      DH Parameters: (2048 bit)
          prime:
              00:ff:cf:17:da:c5:4c:48:75:0e:31:29:cd:42:2c:
              ac:7c:e2:ce:36:47:83:8a:26:b3:50:52:4d:45:e8:
              5a:63:10:f1:42:b5:fb:80:c9:99:14:07:8f:e3:98:
              18:23:91:87:aa:0f:93:49:0c:65:69:34:16:e1:9d:
              c3:f5:59:ef:24:38:0e:24:ca:d2:8d:0c:0d:9f:a6:
              8c:19:59:a2:18:ea:99:9c:76:a2:43:26:32:66:f4:
              70:62:a5:a7:a9:a3:bb:72:d0:63:16:a6:58:e8:e2:
              b5:7b:c6:98:bb:c9:d9:06:60:aa:0c:07:72:d9:7a:
              59:a1:3a:b1:ae:ee:21:29:77:38:c8:10:69:cb:8a:
              5f:38:bb:5b:02:9f:82:47:b4:9e:a2:0b:c5:87:f1:
              c6:68:05:81:57:53:0a:33:57:dc:2e:c6:a4:ca:b2:
              75:48:92:1f:cc:a1:5d:e3:1b:67:90:07:23:27:73:
              ce:4c:6c:27:da:80:2c:73:4b:3f:95:34:20:ac:e9:
              2a:8d:35:54:1f:7d:2d:99:fe:45:2c:6d:bf:03:52:
              74:13:3b:06:82:44:eb:13:d2:45:61:c9:03:a5:85:
              ba:a0:02:10:b4:9b:49:1f:72:09:a9:0f:fb:ac:3c:
              2f:db:4f:44:22:4c:ae:c8:c3:8e:16:f6:76:f1:ac:
              a7:4b
          generator: 2 (0x2)
  DH parameters appear to be ok.
  -----BEGIN DH PARAMETERS-----
  MIIBCAKCAQEA/88X2sVMSHUOMSnNQiysfOLONkeDiiazUFJNRehaYxDxQrX7gMmZ
  FAeP45gYI5GHqg+TSQxlaTQW4Z3D9VnvJDgOJMrSjQwNn6aMGVmiGOqZnHaiQyYy
  ZvRwYqWnqaO7ctBjFqZY6OK1e8aYu8nZBmCqDAdy2XpZoTqxru4hKXc4yBBpy4pf
  OLtbAp+CR7SeogvFh/HGaAWBV1MKM1fcLsakyrJ1SJIfzKFd4xtnkAcjJ3POTGwn
  2oAsc0s/lTQgrOkqjTVUH30tmf5FLG2/A1J0EzsGgkTrE9JFYckDpYW6oAIQtJtJ
  H3IJqQ/7rDwv209EIkyuyMOOFvZ28aynSwIBAg==
  -----END DH PARAMETERS-----
  ```

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/openssl/+bug/1936975/+subscriptions


-- 
Mailing list: https://launchpad.net/~touch-packages
Post to     : touch-packages@lists.launchpad.net
Unsubscribe : https://launchpad.net/~touch-packages
More help   : https://help.launchpad.net/ListHelp

Reply via email to