Merge pull request #22 from Moballo-LLC/codex/libressl-sha1-retry
fix(setup-cert): keep SHA-1 retry compatible with LibreSSL
This commit is contained in:
@@ -216,6 +216,17 @@ def run(cmd, **kw):
|
||||
def run_allow_sha1(cmd):
|
||||
"""Run an openssl command with SHA-1 signatures force-enabled, for
|
||||
distros whose crypto policy otherwise blocks SHA-1 signing."""
|
||||
version = run(['openssl', 'version']).stdout.strip()
|
||||
if not version.startswith('OpenSSL 3.'):
|
||||
# The provider configuration below is specific to OpenSSL 3.
|
||||
# LibreSSL can exit successfully without running the requested
|
||||
# command when it is given that configuration, leaving no output
|
||||
# certificate behind. Older OpenSSL releases do not need the
|
||||
# provider override either, so retry them with a clean environment.
|
||||
env = dict(os.environ)
|
||||
env.pop('OPENSSL_CONF', None)
|
||||
return run(cmd, env=env)
|
||||
|
||||
conf = tempfile.NamedTemporaryFile(
|
||||
'w', suffix='.cnf', prefix='sha1_ok_', delete=False)
|
||||
conf.write(SHA1_OVERRIDE_CONF)
|
||||
|
||||
@@ -77,6 +77,24 @@ def test_mint_cert_retries_when_sha1_signing_blocked(tmp_path, monkeypatch):
|
||||
assert paths["leaf"].exists() # the override retry recovered
|
||||
|
||||
|
||||
def test_sha1_retry_does_not_give_openssl_3_config_to_libressl(monkeypatch):
|
||||
calls = []
|
||||
|
||||
def fake_run(cmd, **kw):
|
||||
calls.append((cmd, kw))
|
||||
if cmd == ["openssl", "version"]:
|
||||
return subprocess.CompletedProcess(cmd, 0, "LibreSSL 3.3.6\n", "")
|
||||
return subprocess.CompletedProcess(cmd, 0, "", "")
|
||||
|
||||
monkeypatch.setattr(setup_cert, "run", fake_run)
|
||||
monkeypatch.setenv("OPENSSL_CONF", "/synthetic/inherited.cnf")
|
||||
|
||||
setup_cert.run_allow_sha1(["openssl", "x509", "-req"])
|
||||
|
||||
assert calls[1][0] == ["openssl", "x509", "-req"]
|
||||
assert "OPENSSL_CONF" not in calls[1][1]["env"]
|
||||
|
||||
|
||||
def test_command_error_includes_stderr():
|
||||
with pytest.raises(setup_cert.CommandError) as exc:
|
||||
setup_cert.run(["openssl", "x509", "-in", "/no/such/file"])
|
||||
|
||||
Reference in New Issue
Block a user