Skip site navigation (1)Skip section navigation (2)
Date:      Sat, 20 May 2017 18:34:55 +0000 (UTC)
From:      Bernard Spil <brnrd@FreeBSD.org>
To:        ports-committers@freebsd.org, svn-ports-all@freebsd.org, svn-ports-head@freebsd.org
Subject:   svn commit: r441329 - head/mail/postfix/files
Message-ID:  <201705201834.v4KIYt1Y056500@repo.freebsd.org>

next in thread | raw e-mail | index | archive | help
Author: brnrd
Date: Sat May 20 18:34:55 2017
New Revision: 441329
URL: https://svnweb.freebsd.org/changeset/ports/441329

Log:
  mail/postfix: Fix x25519 kex with LibreSSL
  
  PR:		216790
  Obtained from:	OpenBSD ports
  Approved by:	ohauer (maintainer)

Added:
  head/mail/postfix/files/patch-src_tls_tls__dh.c   (contents, props changed)
Modified:
  head/mail/postfix/files/patch-src_tls_tls.h

Modified: head/mail/postfix/files/patch-src_tls_tls.h
==============================================================================
--- head/mail/postfix/files/patch-src_tls_tls.h	Sat May 20 18:29:27 2017	(r441328)
+++ head/mail/postfix/files/patch-src_tls_tls.h	Sat May 20 18:34:55 2017	(r441329)
@@ -1,7 +1,8 @@
-# fix build against LibreSSL
-# Obtained from: http://cvsweb.openbsd.org/cgi-bin/cvsweb/ports/mail/postfix/stable/patches/
-# 
---- src/tls/tls.h.orig	2016-02-06 20:09:41 UTC
+$OpenBSD: patch-src_tls_tls_h,v 1.2 2017/03/04 22:09:43 sthen Exp $
+
+Fix building with LibreSSL
+
+--- src/tls/tls.h.orig	2017-01-01 22:22:13 UTC
 +++ src/tls/tls.h
 @@ -89,7 +89,7 @@ extern const char *str_tls_level(int);
  #endif
@@ -12,3 +13,13 @@
  #define OpenSSL_version_num SSLeay
  #define OpenSSL_version SSLeay_version
  #define OPENSSL_VERSION SSLEAY_VERSION
+@@ -104,6 +104,9 @@ extern const char *str_tls_level(int);
+ #define ASN1_STRING_get0_data ASN1_STRING_data
+ #define X509_getm_notBefore X509_get_notBefore
+ #define X509_getm_notAfter X509_get_notAfter
++#endif
++
++#if OPENSSL_VERSION_NUMBER < 0x10100000L
+ #define TLS_method SSLv23_method
+ #define TLS_client_method SSLv23_client_method
+ #define TLS_server_method SSLv23_server_method

Added: head/mail/postfix/files/patch-src_tls_tls__dh.c
==============================================================================
--- /dev/null	00:00:00 1970	(empty, because file is newly added)
+++ head/mail/postfix/files/patch-src_tls_tls__dh.c	Sat May 20 18:34:55 2017	(r441329)
@@ -0,0 +1,15 @@
+$OpenBSD: patch-src_tls_tls_dh_c,v 1.1 2017/03/04 22:09:43 sthen Exp $
+
+Fix building with LibreSSL
+
+--- src/tls/tls_dh.c.orig	2016-12-26 23:47:24 UTC
++++ src/tls/tls_dh.c
+@@ -314,7 +314,7 @@ void    tls_auto_eecdh_curves(SSL_CTX *c
+      * This is a NOP in OpenSSL 1.1.0 and later, where curves are always
+      * auto-negotiated.
+      */
+-#if OPENSSL_VERSION_NUMBER < 0x10100000UL
++#if OPENSSL_VERSION_NUMBER < 0x10100000UL || defined(LIBRESSL_VERSION_NUMBER)
+     if (SSL_CTX_set_ecdh_auto(ctx, 1) <= 0) {
+ 	msg_warn("failed to enable automatic ECDHE curve selection");
+ 	tls_print_errors();



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?201705201834.v4KIYt1Y056500>