fix(setup-cert): keep SHA-1 retry compatible with LibreSSL

This commit is contained in:
Jason Morcos
2026-08-02 10:43:40 -07:00
parent e5bd9456d4
commit 6dc9dca339
2 changed files with 29 additions and 0 deletions
+11
View File
@@ -216,6 +216,17 @@ def run(cmd, **kw):
def run_allow_sha1(cmd):
"""Run an openssl command with SHA-1 signatures force-enabled, for
distros whose crypto policy otherwise blocks SHA-1 signing."""
version = run(['openssl', 'version']).stdout.strip()
if not version.startswith('OpenSSL 3.'):
# The provider configuration below is specific to OpenSSL 3.
# LibreSSL can exit successfully without running the requested
# command when it is given that configuration, leaving no output
# certificate behind. Older OpenSSL releases do not need the
# provider override either, so retry them with a clean environment.
env = dict(os.environ)
env.pop('OPENSSL_CONF', None)
return run(cmd, env=env)
conf = tempfile.NamedTemporaryFile(
'w', suffix='.cnf', prefix='sha1_ok_', delete=False)
conf.write(SHA1_OVERRIDE_CONF)
+18
View File
@@ -77,6 +77,24 @@ def test_mint_cert_retries_when_sha1_signing_blocked(tmp_path, monkeypatch):
assert paths["leaf"].exists() # the override retry recovered
def test_sha1_retry_does_not_give_openssl_3_config_to_libressl(monkeypatch):
calls = []
def fake_run(cmd, **kw):
calls.append((cmd, kw))
if cmd == ["openssl", "version"]:
return subprocess.CompletedProcess(cmd, 0, "LibreSSL 3.3.6\n", "")
return subprocess.CompletedProcess(cmd, 0, "", "")
monkeypatch.setattr(setup_cert, "run", fake_run)
monkeypatch.setenv("OPENSSL_CONF", "/synthetic/inherited.cnf")
setup_cert.run_allow_sha1(["openssl", "x509", "-req"])
assert calls[1][0] == ["openssl", "x509", "-req"]
assert "OPENSSL_CONF" not in calls[1][1]["env"]
def test_command_error_includes_stderr():
with pytest.raises(setup_cert.CommandError) as exc:
setup_cert.run(["openssl", "x509", "-in", "/no/such/file"])