Summary:ASTERISK-27865: [patch]: tcptls: Repair ./configure --with-ssl=PATH.
Reporter:Alexander Traud (traud)Labels:patch
Date Opened:2018-05-19 08:07:23Date Closed:2018-05-24 05:59:20
Versions:13.21.0 15.4.0 Frequency of
Environment:Attachments:( 0) OpenSSL_DEFINE.patch
Description:This issue was caused by Commit [3b426a8|https://github.com/asterisk/asterisk/commit/3b426a8b09c127941b29600271184583f2199a19] (no issue report), which tried to fix Commit [0de74fa|https://github.com/asterisk/asterisk/commit/0de74fad5597ba12ec68bcc935330a612ee255d6] (ASTERISK-24972). However, that change broke {{./configure --with-ssl=PATH}} because {{AST_C_DEFINE_CHECK}} does not chase the PATH. Consequently, the header {{openssl/ssl.h}} must exist in the system and that header must be from OpenSSL 1.0.1 or newer.

*Steps to Reproduce* (Ubuntu 18.04 LTS)
sudo apt install build-essential pkg-config libedit-dev libjansson-dev libsqlite3-dev uuid-dev libxslt1-dev
sudo apt remove libssl-dev
cd ~/Downloads
wget www.openssl.org/source/openssl-1.1.1-pre6.tar.gz
tar -zxf ./openssl-*.tar.gz
cd ./openssl-*
./config shared
export SSL_HOME=$PWD
cd ~/Downloads
wget downloads.asterisk.org/pub/telephony/asterisk/asterisk-13-current.tar.gz
tar -zxf ./asterisk-*.tar.gz
cd ./asterisk-*
LDFLAGS="-Wl,-rpath $SSL_HOME" ./configure --with-crypto=$SSL_HOME --with-ssl=$SSL_HOME

*Expected Result*
checking for SSL_OP_NO_TLSv1_2 in openssl/ssl.h... _yes_

*Actual Result*
checking for SSL_OP_NO_TLSv1_2 in openssl/ssl.h... _no_
The file {{config.log}} shows that the script {{./configure}} went not for the set PATH but searched the system.

Install headers of OpenSSL 1.0.1 (or newer) in the system, for example in Ubuntu via
{{sudo apt install libssl-dev}}

The attached patch was tested with OpenSSL 1.1.0h, 1.0.2o, 1.0.1u, 1.0.0s, and 0.9.8zh. When OpenSSL was {{./config shared no-deprecated}}, more is broken: {{make}} is going to error, because
* {{CRYPTO_set_id_callback}} is deprecated since OpenSSL 1.0.0 and
* {{openssl/dh.h}} and {{openssl/rsa.h}} must be included explicitly.

When it comes to Asterisk {{./configure --with-ssl=PATH}}, more is broken: {{make}} is going to error because several source-code files include an OpenSSL header (implicitly via other Asterisk headers) but look for OpenSSL just in the system path.

I fixed both issues to confirm the patch is working. However, for those two issues, I am going to create separate reports.
Change 9018 merged by Joshua Colp:

Change 9018 merged by Joshua Colp:
tcptls: Repair ./configure --with-ssl=PATH.


Change 9017 merged by Joshua Colp:

Change 9017 merged by Joshua Colp:
tcptls: Repair ./configure --with-ssl=PATH.


Change 9016 merged by Joshua Colp:

Change 9016 merged by Joshua Colp:
tcptls: Repair ./configure --with-ssl=PATH.