Re: Custom Build Errors
Neil Horman <[email protected]> Fri, 1 May 2026 07:56:16 -0400
| Newsgroups | gmane.comp.encryption.openssl.user |
|---|---|
| Message-ID | <CAJbOq17jGesfJ09fN+UKNcLvGEnU7rGD4P0dncvRZSUMMFx7Ag@mail.gmail.com> |
--000000000000661a5e0650c04591 Content-Type: text/plain; charset="UTF-8" Content-Transfer-Encoding: quoted-printable On Fri, May 1, 2026 at 3:55=E2=80=AFAM Jan Just Keijser <jan.just.keijser@g= mail.com> wrote: > Hi Mark, > > On 30/04/2026 18:36, Mark Sigsbee wrote: > > Here's what got me to this point: > > 1. Supporting a customer (T1) that has built a cloud solution for it's > customers (T2). Like Azure in that T2 customers don't see each other. > 2. T1 and T2 assets are required to have valid certs from a trusted CA. > 3. Trusted CA is Microsoft AD CS. > 4. AD CS is configured with NDES for remote automated certificate > issuance. > 5. T2 customers are predominantly Ubuntu, with a smattering of Rhel and > Window mixed in. > 6. Desire is to use Secure SCEP (sscep) to facilitate that. > > Issue is Ubuntu Pro (FIPS enabled) stops with a segmentation fault error > towards the end of the process. > > I was trying to find an alternative OpenSSL/FIPs provider combination tha= t > could possibly resolve the segmentation fault. > > I'm not confident that the baked in version of OpenSSL is playing nice > with certificate issuance. > > segfaults + FIPS + certificates suggests to me that the certs being issue= d > use a hashing algorithm (SHA1, MD5) that OpenSSL+FIPS does not accept. > To test this hypothesis, disable FIPS and see if it makes any difference; > if it still crashes, then at least you know it is not the FIPS enablement > > Also, what SSCEP client are you using? Have you tried > https://github.com/certnanny/sscep ? > > I sincerely doubt that replacing the OS version of the OpenSSL libs is > going to fix these issues - or it's not worth all the extra hassle you wi= ll > introduce for yourself. > > HTH, > > JJK > > I agree, you're buying a lot more problems by replacing the system versio= n of openssl. If you are having problems with the system installed version of openssl, you likely want to contact canonical for support to fix the segfault (though they may tell you that the problem is in your application, likely due to invalid error checking after the cert is rejected). If you can provide the segfault backtrace we may be able to confirm that. Alternatively, if you're insistent on using a custom openssl build, I'd suggest that you containerize the applications and install your self-built openssl version to the container. Neil --=20 You received this message because you are subscribed to the Google Groups "= openssl-users" group. To unsubscribe from this group and stop receiving emails from it, send an e= mail to openssl-users+unsubscribe-MCmKBN63+Bmbup2nOX2J7Q@public.gmane.org To view this discussion visit https://groups.google.com/a/openssl.org/d/msg= id/openssl-users/CAJbOq17jGesfJ09fN%2BUKNcLvGEnU7rGD4P0dncvRZSUMMFx7Ag%40ma= il.gmail.com. --000000000000661a5e0650c04591 Content-Type: text/html; charset="UTF-8" Content-Transfer-Encoding: quoted-printable <div dir=3D"ltr"><div dir=3D"ltr"><br></div><br><div class=3D"gmail_quote g= mail_quote_container"><div dir=3D"ltr" class=3D"gmail_attr">On Fri, May 1, = 2026 at 3:55=E2=80=AFAM Jan Just Keijser <<a href=3D"mailto:jan.just.kei= [email protected]">[email protected]</a>> wrote:<br></div><blockqu= ote class=3D"gmail_quote" style=3D"margin:0px 0px 0px 0.8ex;border-left:1px= solid rgb(204,204,204);padding-left:1ex"> =20 =20 =20 <div> <div>Hi Mark,<br> <br> On 30/04/2026 18:36, Mark Sigsbee wrote:<br> </div> <blockquote type=3D"cite"> =20 <div dir=3D"ltr">Here's what got me to this point:<br> <br> 1. Supporting a customer (T1) that has built a cloud solution for it's customers (T2). Like Azure in that T2 customers don= 9;t see each other.<br> 2. T1 and T2 assets are required to have valid certs from a trusted CA.<br> 3. Trusted CA is Microsoft AD CS.<br> 4. AD CS is configured with NDES for remote automated certificate issuance. <div>5. T2 customers are predominantly Ubuntu, with a smattering of Rhel and Window mixed in.</div> <div>6. Desire is to use Secure SCEP (sscep) to facilitate that.</d= iv> <div><br> </div> <div>Issue is Ubuntu Pro (FIPS enabled) stops with a segmentation fault error towards the end of the process.<br> <br> I was trying to find an alternative OpenSSL/FIPs provider combination that could possibly resolve the segmentation fault.<br> <br> I'm not confident that the baked in version of OpenSSL is playing nice with certificate issuance.<br> <br> </div> </div> </blockquote> segfaults + FIPS + certificates suggests to me that the certs being issued use a hashing algorithm (SHA1, MD5) that OpenSSL+FIPS does not accept.<br> To test this hypothesis, disable FIPS and see if it makes any difference; if it still crashes, then at least you know it is not the FIPS enablement<br> <br> Also, what SSCEP client are you using? Have you tried <a href=3D"https://github.com/certnanny/sscep" target=3D"_blank">https:= //github.com/certnanny/sscep</a>=C2=A0 ?<br> <br> I sincerely doubt that replacing the OS version of the OpenSSL libs is going to fix these issues - or it's not worth all the extra hassle you will introduce for yourself.<br> <br> HTH,<br> <br> JJK<br> <br></div></blockquote><div>I agree, you're buying a lot more probl= ems by replacing the system version of openssl.=C2=A0 If you are having pro= blems with the system installed version of openssl, you likely want to cont= act canonical for support to fix the segfault (though they may tell you tha= t the problem is in your application, likely due to invalid error checking = after the cert is rejected).=C2=A0 If you can provide the segfault backtrac= e we may be able to confirm that.</div><div><br></div><div>Alternatively, i= f you're insistent on using a custom openssl build, I'd suggest tha= t you containerize the applications and install your self-built openssl ver= sion to the container.</div><div><br></div><div>Neil</div><div><br></div></= div></div> <p></p> -- <br /> You received this message because you are subscribed to the Google Groups &= quot;openssl-users" group.<br /> To unsubscribe from this group and stop receiving emails from it, send an e= mail to <a href=3D"mailto:openssl-users+unsubscribe-MCmKBN63+BlAfugRpC6u6w@public.gmane.org">openssl-us= [email protected]</a>.<br /> To view this discussion visit <a href=3D"https://groups.google.com/a/openss= l.org/d/msgid/openssl-users/CAJbOq17jGesfJ09fN%2BUKNcLvGEnU7rGD4P0dncvRZSUM= MFx7Ag%40mail.gmail.com?utm_medium=3Demail&utm_source=3Dfooter">https://gro= ups.google.com/a/openssl.org/d/msgid/openssl-users/CAJbOq17jGesfJ09fN%2BUKN= cLvGEnU7rGD4P0dncvRZSUMMFx7Ag%40mail.gmail.com</a>.<br /> --000000000000661a5e0650c04591--