OpenSSL 1.1.1配置enable-deprecated及OPENSSL_USE_DEPRECATED后仍无法使用已弃用函数的问题
我现有代码是基于OpenSSL 1.0.2开发的,现在计划迁移到OpenSSL 1.1.1版本。迁移过程中我看到了OpenSSL官方指南中关于启用已弃用函数的说明:
Access to deprecated functions/macros has been removed by default. To enable access you must do two things. 1) Build OpenSSL with deprecation support (pass "enable-deprecated" as an argument to config) 2) Applications must define "OPENSSL_USE_DEPRECATED" before including OpenSSL header files
我已经按照要求编译了OpenSSL 1.1.1,编译命令如下:
./config enable-deprecated && make clean && make
同时我也在自己的C代码中,在包含OpenSSL头文件之前添加了#define OPENSSL_USE_DEPRECATED定义。
我的代码在OpenSSL 1.0.2环境下可以正常编译运行,对应的编译命令是:
gcc -std=c99 -o hmac_sha1_example hello.c -I/somepath/openssl-1.0.2k/openssl-1.0.2k/include -L/somepath/openssl-1.0.2k/ -lssl -lcrypto -ldl
但当我切换到OpenSSL 1.1.1环境编译时,即使已经在编译参数中加入了-DOPENSSL_USE_DEPRECATED,还是会出现编译错误:error: storage size of ‘ctx’ isn’t known HMAC_CTX ctx;
以下是我的示例代码(在OpenSSL 1.0.2下正常运行):
#include <stdio.h> #include <string.h> #define OPENSSL_USE_DEPRECATED #include <openssl/hmac.h> int main() { // Define the key and the message const char *key = "secret"; const char *message = "Hello World!"; // Buffer to hold the resulting HMAC unsigned char result[EVP_MAX_MD_SIZE]; unsigned int result_len; // Initialize the HMAC context HMAC_CTX ctx; HMAC_CTX_init(&ctx); // Set up the HMAC context with the key and the SHA1 algorithm HMAC_Init_ex(&ctx, key, strlen(key), EVP_sha1(), NULL); HMAC_Update(&ctx, (unsigned char*)message, strlen(message)); HMAC_Final(&ctx, result, &result_len); // Clean up the HMAC context HMAC_CTX_cleanup(&ctx); // Print the resulting HMAC printf("HMAC-SHA1: "); for (unsigned int i = 0; i < result_len; i++) { printf("%02x", result[i]); } printf("\n"); return 0; }
我本来想通过启用已弃用函数的方式快速完成迁移测试,不想立刻修改所有代码(比如改用HMAC_CTX_new这类1.1.1的新接口),但现在编译还是失败了。想请教一下,是不是我在启用已弃用支持的步骤中有哪里操作错了?
备注:内容来源于stack exchange,提问作者Srinath Ganesh

