From 6dc9dca339a9bec6106334cf822267d3a1fdd609 Mon Sep 17 00:00:00 2001 From: Jason Morcos Date: Sun, 2 Aug 2026 10:43:40 -0700 Subject: [PATCH] fix(setup-cert): keep SHA-1 retry compatible with LibreSSL --- setup_cert.py | 11 +++++++++++ tests/test_setup_cert_signing.py | 18 ++++++++++++++++++ 2 files changed, 29 insertions(+) diff --git a/setup_cert.py b/setup_cert.py index b7802ed..9c220af 100644 --- a/setup_cert.py +++ b/setup_cert.py @@ -216,6 +216,17 @@ def run(cmd, **kw): def run_allow_sha1(cmd): """Run an openssl command with SHA-1 signatures force-enabled, for distros whose crypto policy otherwise blocks SHA-1 signing.""" + version = run(['openssl', 'version']).stdout.strip() + if not version.startswith('OpenSSL 3.'): + # The provider configuration below is specific to OpenSSL 3. + # LibreSSL can exit successfully without running the requested + # command when it is given that configuration, leaving no output + # certificate behind. Older OpenSSL releases do not need the + # provider override either, so retry them with a clean environment. + env = dict(os.environ) + env.pop('OPENSSL_CONF', None) + return run(cmd, env=env) + conf = tempfile.NamedTemporaryFile( 'w', suffix='.cnf', prefix='sha1_ok_', delete=False) conf.write(SHA1_OVERRIDE_CONF) diff --git a/tests/test_setup_cert_signing.py b/tests/test_setup_cert_signing.py index 655eb20..8c30bb6 100644 --- a/tests/test_setup_cert_signing.py +++ b/tests/test_setup_cert_signing.py @@ -77,6 +77,24 @@ def test_mint_cert_retries_when_sha1_signing_blocked(tmp_path, monkeypatch): assert paths["leaf"].exists() # the override retry recovered +def test_sha1_retry_does_not_give_openssl_3_config_to_libressl(monkeypatch): + calls = [] + + def fake_run(cmd, **kw): + calls.append((cmd, kw)) + if cmd == ["openssl", "version"]: + return subprocess.CompletedProcess(cmd, 0, "LibreSSL 3.3.6\n", "") + return subprocess.CompletedProcess(cmd, 0, "", "") + + monkeypatch.setattr(setup_cert, "run", fake_run) + monkeypatch.setenv("OPENSSL_CONF", "/synthetic/inherited.cnf") + + setup_cert.run_allow_sha1(["openssl", "x509", "-req"]) + + assert calls[1][0] == ["openssl", "x509", "-req"] + assert "OPENSSL_CONF" not in calls[1][1]["env"] + + def test_command_error_includes_stderr(): with pytest.raises(setup_cert.CommandError) as exc: setup_cert.run(["openssl", "x509", "-in", "/no/such/file"])