Skip to content

Regenerate example identity.pfx without RC2 for OpenSSL 3 - #387

Open
00200200 wants to merge 1 commit into
smol-rs:masterfrom
00200200:fix-identity-pfx-openssl3
Open

00200200 wants to merge 1 commit into
smol-rs:masterfrom
00200200:fix-identity-pfx-openssl3

Conversation

@00200200

Copy link
Copy Markdown

Summary

OpenSSL 3 rejects the historical RC2-40-CBC PKCS#12 protection used by examples/identity.pfx, so TLS examples such as hyper-server failed immediately on modern Linux with:

error:0308010C:digital envelope routines:inner_evp_generic_fetch:unsupported:... Algorithm (RC2-40-CBC : 0)

Re-export the same certificate/key material with AES-256-CBC + SHA-256 and add a regression test that:

  • loads the PFX through native_tls (the path the examples use)
  • opens it with openssl pkcs12 under OpenSSL 3 without -legacy

Closes #375

Test plan

  • cargo test --test identity_pfx fails against the old RC2 PFX under OpenSSL 3
  • cargo test --test identity_pfx passes with the regenerated PFX
  • native_tls::Identity::from_pkcs12(..., "password") still succeeds
  • CI on ubuntu/macOS/windows

OpenSSL 3 rejects the historical RC2-40-CBC PKCS#12 protection by
default, so the TLS examples failed to load identity.pfx on modern
Linux. Re-export the same key material with AES-256-CBC and add a
regression test.

Closes smol-rs#375
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

async_native_tls / native_tls error when running hyper-server example

1 participant