Re: [Buildroot] [PATCH] package/openssh: enable DES when using libopenssl
Peter Korsgaard <[email protected]> Tue, 28 Jul 2026 22:42:20 +0200
| Newsgroups | net.busybox.buildroot |
|---|---|
| Message-ID | <[email protected]> |
>>>>> "Jimmy" == Jimmy Durand Wesolowski via buildroot <[email protected]> writes: > When the OpenSSL library is selected (instead of LibreSSL), OpenSSH needs > DES to be enabled, even if all the other encryption algorithms are enabled > (except MDC2 that depends on DES). > If disabled, libopenbsd-compat "xcrypt" function will require crypt (in > place of DES_crypt), and any linking against it will fail: > .../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o > auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o > servconf.o serverloop.o auth.o auth2.o auth-options.o session.o > auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o > auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o > auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o > monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o > platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o > sandbox-null.o sandbox-rlimit.o sandbox-darwin.o > sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o > sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o > ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE > -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0 > -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack > -fstack-protector-strong -pie -lssh -lopenbsd-compat > -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib > -lssl -lcrypto -lcrypto -lz > .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../ > i686-buildroot-linux-gnu/bin/ld: > openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt': > xcrypt.c:(.text+0x51): undefined reference to `crypt' > .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../ > i686-buildroot-linux-gnu/bin/ld: > openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt': > xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error: > ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error > 1 make[2]: *** Waiting for unfinished jobs.... collect2: error: ld > returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error > 1 make[1]: *** [package/pkg-generic.mk:273: > .../build/openssh-10.4p1/.stamp_built] > Error 2 make: *** [Makefile:83: _all] Error 2 > Signed-off-by: Jimmy Durand Wesolowski <[email protected]> Hmm, with what configuration is this? Presumably not one where BR2_PACKAGE_OPENSSH_SERVER is enabled, as that pulls in libxcrypt on glibc? Given the description in the commit adding the libxcrypt select, perhaps that select should instead be moved to the the toplevel openssh symbol? commit dd244feb37fff29620a09ee96b4006cf7d558380 Author: Romain Naour <[email protected]> Date: Thu Apr 18 12:15:29 2024 +0200 package/openssh: add libxcrypt optional dependency for sshd When glibc was bumped to version 2.39 in commit b5680f53d60acf8ff6010082f873438a39bd5d97 it removed the deprecated libcrypt support. As glibc's libcrypt was providing sshd's libcrypt dependency this broke the sshd password authentification at runtime using glibc version 2.39. # sshpass -p testpwd ssh -oStrictHostKeyChecking=no localhost /bin/true Permission denied, please try again. Without libcrypt, OpenSSH >= 6.2 fall back to using openssl's DES_crypt function on platorms that don't have a native crypt() function [1]. Note that DES_crypt is deprecated since openssl 3.0 [2] [3]. "Use of the low level DES functions has been informally discouraged for a long time. We now formally deprecate them. Applications should instead use the EVP APIs, e.g. EVP_EncryptInit_ex, EVP_EncryptUpdate, EVP_EncryptFinal_ex, and the equivalently named decrypt functions." Also DES_crypt is provided by openssl only if BR2_PACKAGE_LIBOPENSSL_ENABLE_DES is enabled. Otherwise crypt() is never defined: sd-compat.a(xcrypt.o): in function `xcrypt': xcrypt.c:(.text+0x48): undefined reference to `crypt' It's not clear why the password authentification fail with openssl's DES_crypt but since it's deprecated we use libxcrypt to provide a working crypt() function for glibc based toolchains. [1] https://github.com/openssh/openssh-portable/blob/V_9_7/openbsd-compat/xcrypt.c#L57 [2] https://github.com/openssl/openssl/commit/c6fec81b88131d08c1022504ccf6effa95497afb [3] https://www.openssl.org/docs/man3.2/man3/DES_crypt.html Fixes: https://gitlab.com/buildroot.org/buildroot/-/jobs/6623402147 Signed-off-by: Romain Naour <[email protected]> -- Bye, Peter Korsgaard _______________________________________________ buildroot mailing list [email protected] https://lists.buildroot.org/mailman/listinfo/buildroot