]> git.ipfire.org Git - thirdparty/haproxy.git/commitdiff
BUILD: ssl: introduce fine guard for OpenSSL specific SCTL functions
authorIlya Shipitsin <chipitsine@gmail.com>
Sat, 13 Feb 2021 06:45:33 +0000 (11:45 +0500)
committerWilliam Lallemand <wlallemand@haproxy.org>
Thu, 18 Feb 2021 14:55:50 +0000 (15:55 +0100)
SCTL (signed certificate timestamp list) specified in RFC6962
was implemented in c74ce24cd22e8c683ba0e5353c0762f8616e597d, let
us introduce macro HAVE_SSL_SCTL for the HAVE_SSL_SCTL sake,
which in turn is based on SN_ct_cert_scts, which comes in the same commit

include/haproxy/openssl-compat.h
src/ssl_ckch.c

index 3fe58be4058630d0280459918fe6f8f88b096bf2..b5f05d1ae42b4cc2f14dd87f8a616387a440b1b9 100644 (file)
 #define HAVE_SSL_CTX_get0_privatekey
 #endif
 
+#if (defined(SN_ct_cert_scts) && !defined(OPENSSL_NO_TLSEXT))
+#define HAVE_SSL_SCTL
+#endif
+
 #if (HA_OPENSSL_VERSION_NUMBER < 0x0090800fL)
 /* Functions present in OpenSSL 0.9.8, older not tested */
 static inline const unsigned char *SSL_SESSION_get_id(const SSL_SESSION *sess, unsigned int *sid_length)
index f654b4b52806987c731b0339912367afbafb5750..8aa29bd22e011190ece5882283b2e53b2a4f8c9f 100644 (file)
@@ -320,7 +320,7 @@ int ssl_sock_load_files_into_ckch(const char *path, struct cert_key_and_chain *c
                goto end;
        }
 
-#if (HA_OPENSSL_VERSION_NUMBER >= 0x1000200fL && !defined OPENSSL_NO_TLSEXT && !defined OPENSSL_IS_BORINGSSL)
+#ifdef HAVE_SSL_SCTL
        /* try to load the sctl file */
        if (global_ssl.extra_files & SSL_GF_SCTL) {
                struct stat st;
@@ -939,7 +939,7 @@ enum {
        CERT_TYPE_OCSP,
 #endif
        CERT_TYPE_ISSUER,
-#if (HA_OPENSSL_VERSION_NUMBER >= 0x1000200fL && !defined OPENSSL_NO_TLSEXT && !defined OPENSSL_IS_BORINGSSL)
+#ifdef HAVE_SSL_SCTL
        CERT_TYPE_SCTL,
 #endif
        CERT_TYPE_MAX,
@@ -956,7 +956,7 @@ struct {
 #if ((defined SSL_CTRL_SET_TLSEXT_STATUS_REQ_CB && !defined OPENSSL_NO_OCSP) || defined OPENSSL_IS_BORINGSSL)
        [CERT_TYPE_OCSP]   = { "ocsp",    CERT_TYPE_OCSP,     &ssl_sock_load_ocsp_response_from_file },
 #endif
-#if (HA_OPENSSL_VERSION_NUMBER >= 0x1000200fL && !defined OPENSSL_NO_TLSEXT && !defined OPENSSL_IS_BORINGSSL)
+#ifdef HAVE_SSL_SCTL
        [CERT_TYPE_SCTL]   = { "sctl",    CERT_TYPE_SCTL,     &ssl_sock_load_sctl_from_file },
 #endif
        [CERT_TYPE_ISSUER] = { "issuer",  CERT_TYPE_ISSUER,   &ssl_sock_load_issuer_file_into_ckch },