Our test for if the underlying TLS library supported a specific
version tested against the TLSX_Y_VERSION set of macros. These
are however always defined, regardless of if the library was
built without support for the specific protocol version. Fix
by using the feature test macros OPENSSL_NO_TLSX_Y which are
intended for this usecase.
The previous coding held no risk of protocol downgrade against
the underlying library, a library not supporting the protocol
version selected would simply error out as the feature isn't
available. This can be easily verified using a modern version
of LibreSSL, which in version 3.8 disabled TLS1 and 1.1 by
default. Once we bump our minimum supported version of LibreSSL
to 3.8+ we can add a test for this.
Author: Daniel Gustafsson <daniel@yesql.se>
Reviewed-by: Tristan Partin <tristan@partin.io>
Reviewed-by: Andreas Karlsson <andreas@proxel.se>
Reviewed-by: Yilin Zhang <jiezhilove@126.com>
Discussion: https://postgr.es/m/
68B9881D-DAA8-467D-A251-
C96E98E57BA0@yesql.se
case PG_TLS_ANY:
return 0;
case PG_TLS1_VERSION:
+#ifndef OPENSSL_NO_TLS1
return TLS1_VERSION;
+#else
+ break;
+#endif
case PG_TLS1_1_VERSION:
-#ifdef TLS1_1_VERSION
+#ifndef OPENSSL_NO_TLS1_1
return TLS1_1_VERSION;
#else
break;
#endif
case PG_TLS1_2_VERSION:
-#ifdef TLS1_2_VERSION
+#ifndef OPENSSL_NO_TLS1_2
return TLS1_2_VERSION;
#else
break;
#endif
case PG_TLS1_3_VERSION:
-#ifdef TLS1_3_VERSION
+#ifndef OPENSSL_NO_TLS1_3
return TLS1_3_VERSION;
#else
break;
static int
ssl_protocol_version_to_openssl(const char *protocol)
{
+#ifndef OPENSSL_NO_TLS1
if (pg_strcasecmp("TLSv1", protocol) == 0)
return TLS1_VERSION;
+#endif
-#ifdef TLS1_1_VERSION
+#ifndef OPENSSL_NO_TLS1_1
if (pg_strcasecmp("TLSv1.1", protocol) == 0)
return TLS1_1_VERSION;
#endif
-#ifdef TLS1_2_VERSION
+#ifndef OPENSSL_NO_TLS1_2
if (pg_strcasecmp("TLSv1.2", protocol) == 0)
return TLS1_2_VERSION;
#endif
-#ifdef TLS1_3_VERSION
+#ifndef OPENSSL_NO_TLS1_3
if (pg_strcasecmp("TLSv1.3", protocol) == 0)
return TLS1_3_VERSION;
#endif