Re: Configuring to fail when a provider doesn't load

Viktor Dukhovni <[email protected]>
Newsgroups gmane.comp.encryption.openssl.user
Message-ID <[email protected]>
On Thu, Mar 06, 2025 at 09:45:10PM +1100, Viktor Dukhovni wrote:

> I tested failing to load a provider with OpenSSL 3.5 and Postfix, and
> found that OPENSSL_init_ssl() does not actually return an error in that
> case.  Ordinary failure to load a provider is not considered fatal.

This will likely be fixed in a future OpenSSL version, perhaps 3.5:

    https://github.com/openssl/openssl/pull/26997

Though for an application to notice it would need to perform explicit
library initialisation with non-default "settings", as in the Postfix
example.

-- 
    Viktor.

-- 
You received this message because you are subscribed to the Google Groups "openssl-users" group.
To unsubscribe from this group and stop receiving emails from it, send an email to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-users/Z86UjRechtq6zRs7%40chardros.imrryr.org.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.