OpenSSL 3.1.2自定义签名Provider未触发签名回调问题求助
OpenSSL 3.1.2自定义签名Provider未触发回调问题
我为OpenSSL v3.1.2编写了一个基础签名Provider,代码如下:
#include <openssl/core_dispatch.h> #include <openssl/core_names.h> #include <openssl/params.h> #include <openssl/evp.h> struct rsa_sign_ctx { EVP_PKEY *pkey; }; static void *rsa_sign_newctx(void *provctx); static void rsa_sign_freectx(void *ctx); static int rsa_sign_init(void *ctx, void *provkey); static int rsa_sign(void *ctx, unsigned char *sig, size_t *siglen, size_t sigsize, const unsigned char *tbs, size_t tbslen); // here comes basic implementation of the above callback with log printouts //////////////////// const OSSL_DISPATCH rsa_signature_functions[] = { {OSSL_FUNC_SIGNATURE_NEWCTX, (void (*)(void))rsa_sign_newctx}, {OSSL_FUNC_SIGNATURE_FREECTX, (void (*)(void))rsa_sign_freectx}, {OSSL_FUNC_SIGNATURE_SIGN_INIT, (void (*)(void))rsa_sign_init}, {OSSL_FUNC_SIGNATURE_SIGN, (void (*)(void))rsa_sign}, {0, NULL}}; const OSSL_ALGORITHM my_rsa_algorithm[] = { { "RSA", "provider=p_hsmpoc", rsa_signature_functions }, {NULL, NULL, NULL}}; const OSSL_ALGORITHM *my_provider_query(void *provctx, int operation_id, int *no_cache) { *no_cache = 0; switch (operation_id) { case OSSL_OP_SIGNATURE: return my_rsa_algorithm; } return NULL; } const OSSL_DISPATCH my_provider_functions[] = { {OSSL_FUNC_PROVIDER_QUERY_OPERATION, (void (*)(void))my_provider_query}, {0, NULL}}; int OSSL_provider_init(const OSSL_CORE_HANDLE *handle, const OSSL_DISPATCH *in, const OSSL_DISPATCH **out, void **provctx) { *provctx = NULL; *out = my_provider_functions; return 1; }
已执行的操作及现象:
- 将生成的SO文件复制到共享模块目录
/usr/local/lib64/ossl-modules - 更新
openssl.cnf后执行openssl list -provider <my-prov>无报错,可确认OSSL_provider_init函数被调用 - 启动
s_server和s_client(使用自定义SSL密钥对)时,my_provider_query查询函数按预期调用并注册了签名回调,但TLS握手过程中签名回调并未触发 - 在Nginx中加载该Provider时,出现完全相同的问题
请求指点遗漏的配置步骤。
内容的提问来源于stack exchange,提问作者eagle_bear
相关产品推荐
相关产品推荐

