mirror of
https://github.com/ruby/ruby.git
synced 2025-09-18 01:54:00 +02:00

* ext/openssl/ossl_ssl_session.c (ossl_ssl_session_{get,set}_time{,out}): fixed a bug introduced by backporting. (see [ruby-dev:40573]) use long in according to OpenSSL API. (SSL_SESSION_{get,set}_time{,out}) * ext/openssl/ossl_x509name.c: added X509::Name#hash_old as a wrapper for X509_NAME_hash_old in OpenSSL 1.0.0. * test/openssl/test_x509name.rb (test_hash): make test pass with OpenSSL 1.0.0. * test/openssl/test_x509*: make tests pass with OpenSSL 1.0.0b5. * PKey::PKey#verify raises an exception when a given PKey does not match with signature. * PKey::DSA#sign accepts SHA1, SHA256 other than DSS1. * backport the commit from trunk: Sun Feb 28 11:49:35 2010 NARUSE, Yui <naruse@ruby-lang.org> * openssl/ossl.c (OSSL_IMPL_SK2ARY): for OpenSSL 1.0. patched by Jeroen van Meeuwen at [ruby-core:25210] fixed by Nobuyoshi Nakada [ruby-core:25238], Hongli Lai [ruby-core:27417], and Motohiro KOSAKI [ruby-core:28063] * ext/openssl/ossl_ssl.c (ossl_ssl_method_tab), (ossl_ssl_cipher_to_ary): constified. * ext/openssl/ossl_pkcs7.c (pkcs7_get_certs, pkcs7_get_crls): split pkcs7_get_certs_or_crls. * test/openssl/test_ec.rb: added test_dsa_sign_asn1_FIPS186_3. dgst is truncated with ec_key.group.order.size after openssl 0.9.8m for FIPS 186-3 compliance. WARNING: ruby-openssl aims to wrap an OpenSSL so when you're using openssl 0.9.8l or earlier version, EC.dsa_sign_asn1 raises OpenSSL::PKey::ECError as before and EC.dsa_verify_asn1 just returns false when you pass dgst longer than expected (no truncation performed). * ext/openssl/ossl_pkey_ec.c: rdoc typo fixed. * ext/openssl/ossl_config.c: defined own IMPLEMENT_LHASH_DOALL_ARG_FN_098 macro according to IMPLEMENT_LHASH_DOALL_ARG_FN in OpenSSL 0.9.8m. OpenSSL 1.0.0beta5 has a slightly different definiton so it could be a temporal workaround for 0.9.8 and 1.0.0 dual support. * ext/openssl/ossl_pkcs5.c (ossl_pkcs5_pbkdf2_hmac): follows function definition in OpenSSL 1.0.0beta5. PKCS5_PBKDF2_HMAC is from 1.0.0 (0.9.8 only has PKCS5_PBKDF2_HMAC_SHA1) * ext/openssl/ossl_ssl_session.c (ossl_ssl_session_eq): do not use SSL_SESSION_cmp and implement equality func by ousrself. See the comment. * ext/openssl/extconf.rb: check some functions added at OpenSSL 1.0.0. * ext/openssl/ossl_engine.c (ossl_engine_s_load): use engines which exists. git-svn-id: svn+ssh://ci.ruby-lang.org/ruby/branches/ruby_1_8_7@28367 b2dd03c8-39d4-4d8f-98ff-823fe69b080e
135 lines
3.8 KiB
Ruby
135 lines
3.8 KiB
Ruby
=begin
|
|
= $RCSfile$ -- Generator for Makefile
|
|
|
|
= Info
|
|
'OpenSSL for Ruby 2' project
|
|
Copyright (C) 2002 Michal Rokos <m.rokos@sh.cvut.cz>
|
|
All rights reserved.
|
|
|
|
= Licence
|
|
This program is licenced under the same licence as Ruby.
|
|
(See the file 'LICENCE'.)
|
|
|
|
= Version
|
|
$Id$
|
|
=end
|
|
|
|
require "mkmf"
|
|
|
|
dir_config("openssl")
|
|
dir_config("kerberos")
|
|
|
|
message "=== OpenSSL for Ruby configurator ===\n"
|
|
|
|
##
|
|
# Adds -Wall -DOSSL_DEBUG for compilation and some more targets when GCC is used
|
|
# To turn it on, use: --with-debug or --enable-debug
|
|
#
|
|
if with_config("debug") or enable_config("debug")
|
|
$defs.push("-DOSSL_DEBUG") unless $defs.include? "-DOSSL_DEBUG"
|
|
|
|
if /gcc/ =~ CONFIG["CC"]
|
|
$CPPFLAGS += " -Wall" unless $CPPFLAGS.split.include? "-Wall"
|
|
end
|
|
end
|
|
|
|
message "=== Checking for system dependent stuff... ===\n"
|
|
have_library("nsl", "t_open")
|
|
have_library("socket", "socket")
|
|
have_header("assert.h")
|
|
|
|
message "=== Checking for required stuff... ===\n"
|
|
if $mingw
|
|
have_library("wsock32")
|
|
have_library("gdi32")
|
|
end
|
|
result = have_header("openssl/ssl.h")
|
|
result &&= %w[crypto libeay32].any? {|lib| have_library(lib, "OpenSSL_add_all_digests")}
|
|
result &&= %w[ssl ssleay32].any? {|lib| have_library(lib, "SSL_library_init")}
|
|
if !result
|
|
unless pkg_config("openssl") and have_header("openssl/ssl.h")
|
|
message "=== Checking for required stuff failed. ===\n"
|
|
message "Makefile wasn't created. Fix the errors above.\n"
|
|
exit 1
|
|
end
|
|
end
|
|
|
|
unless have_header("openssl/conf_api.h")
|
|
message "OpenSSL 0.9.6 or later required.\n"
|
|
exit 1
|
|
end
|
|
|
|
%w"rb_str_set_len rb_block_call".each {|func| have_func(func, "ruby.h")}
|
|
|
|
message "=== Checking for OpenSSL features... ===\n"
|
|
have_func("ERR_peek_last_error")
|
|
have_func("BN_mod_add")
|
|
have_func("BN_mod_sqr")
|
|
have_func("BN_mod_sub")
|
|
have_func("BN_pseudo_rand_range")
|
|
have_func("BN_rand_range")
|
|
have_func("CONF_get1_default_config_file")
|
|
have_func("EVP_CIPHER_CTX_copy")
|
|
have_func("EVP_CIPHER_CTX_set_padding")
|
|
have_func("EVP_CipherFinal_ex")
|
|
have_func("EVP_CipherInit_ex")
|
|
have_func("EVP_DigestFinal_ex")
|
|
have_func("EVP_DigestInit_ex")
|
|
have_func("EVP_MD_CTX_cleanup")
|
|
have_func("EVP_MD_CTX_create")
|
|
have_func("EVP_MD_CTX_destroy")
|
|
have_func("EVP_MD_CTX_init")
|
|
have_func("HMAC_CTX_cleanup")
|
|
have_func("HMAC_CTX_copy")
|
|
have_func("HMAC_CTX_init")
|
|
have_func("PEM_def_callback")
|
|
have_func("PKCS5_PBKDF2_HMAC")
|
|
have_func("PKCS5_PBKDF2_HMAC_SHA1")
|
|
have_func("X509V3_set_nconf")
|
|
have_func("X509V3_EXT_nconf_nid")
|
|
have_func("X509_CRL_add0_revoked")
|
|
have_func("X509_CRL_set_issuer_name")
|
|
have_func("X509_CRL_set_version")
|
|
have_func("X509_CRL_sort")
|
|
have_func("X509_NAME_hash_old")
|
|
have_func("X509_STORE_get_ex_data")
|
|
have_func("X509_STORE_set_ex_data")
|
|
have_func("OBJ_NAME_do_all_sorted")
|
|
have_func("SSL_SESSION_get_id")
|
|
have_func("OPENSSL_cleanse")
|
|
if try_compile("#define FOO(...) foo(__VA_ARGS__)\n int x(){FOO(1);FOO(1,2);FOO(1,2,3);}\n")
|
|
$defs.push("-DHAVE_VA_ARGS_MACRO")
|
|
end
|
|
if have_header("openssl/engine.h")
|
|
have_func("ENGINE_add")
|
|
have_func("ENGINE_load_builtin_engines")
|
|
have_func("ENGINE_load_openbsd_dev_crypto")
|
|
have_func("ENGINE_get_digest")
|
|
have_func("ENGINE_get_cipher")
|
|
have_func("ENGINE_cleanup")
|
|
have_func("ENGINE_load_4758cca")
|
|
have_func("ENGINE_load_aep")
|
|
have_func("ENGINE_load_atalla")
|
|
have_func("ENGINE_load_chil")
|
|
have_func("ENGINE_load_cswift")
|
|
have_func("ENGINE_load_nuron")
|
|
have_func("ENGINE_load_sureware")
|
|
have_func("ENGINE_load_ubsec")
|
|
end
|
|
if try_compile(<<SRC)
|
|
#include <openssl/opensslv.h>
|
|
#if OPENSSL_VERSION_NUMBER < 0x00907000L
|
|
# error "OpenSSL version is less than 0.9.7."
|
|
#endif
|
|
SRC
|
|
have_header("openssl/ocsp.h")
|
|
end
|
|
have_struct_member("EVP_CIPHER_CTX", "flags", "openssl/evp.h")
|
|
have_struct_member("EVP_CIPHER_CTX", "engine", "openssl/evp.h")
|
|
have_struct_member("X509_ATTRIBUTE", "single", "openssl/x509.h")
|
|
|
|
message "=== Checking done. ===\n"
|
|
|
|
create_header
|
|
create_makefile("openssl")
|
|
message "Done.\n"
|