Skip to content

Commit 17983de

Browse files
committed
crypto,https,tls: end OpenSSL engine support
OpenSSL removed support for engines in version 4. Remove the Node.js APIs, constants, native bindings, and implementation that depend on ENGINE. Keep recognizing the former TLS and HTTPS engine options so their use fails explicitly instead of appearing to work while being ignored. Move DEP0183 directly from Documentation-only to End-of-Life. Signed-off-by: Filip Skokan <panva.ip@gmail.com> Assisted-by: Codex
1 parent 0e9ee6e commit 17983de

40 files changed

Lines changed: 162 additions & 1279 deletions

‎deps/ncrypto/engine.cc‎

Lines changed: 0 additions & 105 deletions
This file was deleted.

‎deps/ncrypto/ncrypto.gyp‎

Lines changed: 0 additions & 35 deletions
Original file line numberDiff line numberDiff line change
@@ -5,19 +5,10 @@
55
'ncrypto.cc',
66
'ncrypto.h',
77
],
8-
'ncrypto_engine_sources': [
9-
'engine.cc',
10-
'ncrypto.h',
11-
],
128
'ncrypto_strict_defines': [
139
'OPENSSL_API_COMPAT=30000',
1410
'OPENSSL_NO_DEPRECATED',
1511
],
16-
'ncrypto_engine_defines': [
17-
'OPENSSL_API_COMPAT=30000',
18-
'OPENSSL_SUPPRESS_DEPRECATED',
19-
'NCRYPTO_ENGINE_COMPAT=1',
20-
],
2112
},
2213
'targets': [
2314
{
@@ -42,9 +33,6 @@
4233
'conditions': [
4334
['openssl_is_boringssl=="false"', {
4435
'defines': [ '<@(ncrypto_strict_defines)' ],
45-
'dependencies': [
46-
'ncrypto_engine',
47-
],
4836
}],
4937
['node_shared_openssl=="false"', {
5038
'dependencies': [
@@ -54,27 +42,4 @@
5442
]
5543
},
5644
],
57-
'conditions': [
58-
['openssl_is_boringssl=="false"', {
59-
'targets': [
60-
{
61-
'target_name': 'ncrypto_engine',
62-
'type': 'static_library',
63-
'include_dirs': ['.'],
64-
'defines': [
65-
'NCRYPTO_BSSL_LIBDECREPIT_MISSING=<(ncrypto_bssl_libdecrepit_missing)',
66-
'<@(ncrypto_engine_defines)',
67-
],
68-
'sources': [ '<@(ncrypto_engine_sources)' ],
69-
'conditions': [
70-
['node_shared_openssl=="false"', {
71-
'dependencies': [
72-
'../openssl/openssl.gyp:openssl'
73-
]
74-
}],
75-
]
76-
},
77-
],
78-
}],
79-
],
8045
}

‎deps/ncrypto/ncrypto.h‎

Lines changed: 0 additions & 43 deletions
Original file line numberDiff line numberDiff line change
@@ -22,11 +22,6 @@
2222
#include <string_view>
2323
#include <unordered_map>
2424
#include <vector>
25-
#if defined(NCRYPTO_ENGINE_COMPAT) && NCRYPTO_ENGINE_COMPAT && \
26-
!defined(OPENSSL_NO_ENGINE)
27-
#include <openssl/engine.h>
28-
#endif // NCRYPTO_ENGINE_COMPAT && !OPENSSL_NO_ENGINE
29-
3025
#ifndef OPENSSL_VERSION_PREREQ
3126
#define OPENSSL_VERSION_PREREQ(maj, min) \
3227
(OPENSSL_VERSION_NUMBER >= (((maj) << 28) | ((min) << 20)))
@@ -1922,44 +1917,6 @@ class HMACCtxPointer final {
19221917
};
19231918
#endif // OPENSSL_WITH_EVP_MAC
19241919

1925-
#ifndef OPENSSL_NO_ENGINE
1926-
class EnginePointer final {
1927-
public:
1928-
EnginePointer() = default;
1929-
1930-
explicit EnginePointer(void* engine_, bool finish_on_exit = false);
1931-
EnginePointer(EnginePointer&& other) noexcept;
1932-
EnginePointer& operator=(EnginePointer&& other) noexcept;
1933-
NCRYPTO_DISALLOW_COPY(EnginePointer)
1934-
~EnginePointer();
1935-
1936-
inline operator bool() const { return engine != nullptr; }
1937-
inline void setFinishOnExit() { finish_on_exit = true; }
1938-
1939-
void reset(void* engine_ = nullptr, bool finish_on_exit_ = false);
1940-
1941-
bool setAsDefault(uint32_t flags, CryptoErrorList* errors = nullptr);
1942-
bool init(bool finish_on_exit = false);
1943-
EVPKeyPointer loadPrivateKey(const char* key_name);
1944-
bool setClientCertEngine(SSL_CTX* ctx);
1945-
1946-
void* release();
1947-
1948-
// Retrieve an OpenSSL Engine instance by name. If the name does not
1949-
// identify a valid named engine, the returned EnginePointer will be
1950-
// empty.
1951-
static EnginePointer getEngineByName(const char* name,
1952-
CryptoErrorList* errors = nullptr);
1953-
1954-
// Call once when initializing OpenSSL at startup for the process.
1955-
static void initEnginesOnce();
1956-
1957-
private:
1958-
void* engine = nullptr;
1959-
bool finish_on_exit = false;
1960-
};
1961-
#endif // !OPENSSL_NO_ENGINE
1962-
19631920
// ============================================================================
19641921
// FIPS
19651922
bool isFipsEnabled();

‎deps/ncrypto/unofficial.gni‎

Lines changed: 1 addition & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -26,11 +26,7 @@ template("ncrypto_gn_build") {
2626
source_set(target_name) {
2727
forward_variables_from(invoker, "*")
2828
public_configs = [ ":ncrypto_config" ]
29-
defines = [
30-
"NCRYPTO_ENGINE_COMPAT=1",
31-
"OPENSSL_SUPPRESS_DEPRECATED",
32-
]
33-
sources = gypi_values.ncrypto_sources + gypi_values.ncrypto_engine_sources
29+
sources = gypi_values.ncrypto_sources
3430
deps = [ "$node_openssl_path" ]
3531
}
3632
}

‎doc/api/crypto.md‎

Lines changed: 0 additions & 89 deletions
Original file line numberDiff line numberDiff line change
@@ -6363,42 +6363,6 @@ added: v15.6.0
63636363
* `utilization` {number} The calculated ratio of `used` to `total`
63646364
allocated bytes.
63656365

6366-
### `crypto.setEngine(engine[, flags])`
6367-
6368-
<!-- YAML
6369-
added: v0.11.11
6370-
changes:
6371-
- version:
6372-
- v22.4.0
6373-
- v20.16.0
6374-
pr-url: https://github.com/nodejs/node/pull/53329
6375-
description: Custom engine support in OpenSSL 3 is deprecated.
6376-
-->
6377-
6378-
* `engine` {string}
6379-
* `flags` {crypto.constants} **Default:** `crypto.constants.ENGINE_METHOD_ALL`
6380-
6381-
Load and set the `engine` for some or all OpenSSL functions (selected by flags).
6382-
Support for custom engines in OpenSSL is deprecated from OpenSSL 3.
6383-
6384-
`engine` could be either an id or a path to the engine's shared library.
6385-
6386-
The optional `flags` argument uses `ENGINE_METHOD_ALL` by default. The `flags`
6387-
is a bit field taking one of or a mix of the following flags (defined in
6388-
`crypto.constants`):
6389-
6390-
* `crypto.constants.ENGINE_METHOD_RSA`
6391-
* `crypto.constants.ENGINE_METHOD_DSA`
6392-
* `crypto.constants.ENGINE_METHOD_DH`
6393-
* `crypto.constants.ENGINE_METHOD_RAND`
6394-
* `crypto.constants.ENGINE_METHOD_EC`
6395-
* `crypto.constants.ENGINE_METHOD_CIPHERS`
6396-
* `crypto.constants.ENGINE_METHOD_DIGESTS`
6397-
* `crypto.constants.ENGINE_METHOD_PKEY_METHS`
6398-
* `crypto.constants.ENGINE_METHOD_PKEY_ASN1_METHS`
6399-
* `crypto.constants.ENGINE_METHOD_ALL`
6400-
* `crypto.constants.ENGINE_METHOD_NONE`
6401-
64026366
### `crypto.setFips(bool)`
64036367

64046368
<!-- YAML
@@ -7219,59 +7183,6 @@ See the [list of SSL OP Flags][] for details.
72197183
</tr>
72207184
</table>
72217185

7222-
### OpenSSL engine constants
7223-
7224-
<table>
7225-
<tr>
7226-
<th>Constant</th>
7227-
<th>Description</th>
7228-
</tr>
7229-
<tr>
7230-
<td><code>ENGINE_METHOD_RSA</code></td>
7231-
<td>Limit engine usage to RSA</td>
7232-
</tr>
7233-
<tr>
7234-
<td><code>ENGINE_METHOD_DSA</code></td>
7235-
<td>Limit engine usage to DSA</td>
7236-
</tr>
7237-
<tr>
7238-
<td><code>ENGINE_METHOD_DH</code></td>
7239-
<td>Limit engine usage to DH</td>
7240-
</tr>
7241-
<tr>
7242-
<td><code>ENGINE_METHOD_RAND</code></td>
7243-
<td>Limit engine usage to RAND</td>
7244-
</tr>
7245-
<tr>
7246-
<td><code>ENGINE_METHOD_EC</code></td>
7247-
<td>Limit engine usage to EC</td>
7248-
</tr>
7249-
<tr>
7250-
<td><code>ENGINE_METHOD_CIPHERS</code></td>
7251-
<td>Limit engine usage to CIPHERS</td>
7252-
</tr>
7253-
<tr>
7254-
<td><code>ENGINE_METHOD_DIGESTS</code></td>
7255-
<td>Limit engine usage to DIGESTS</td>
7256-
</tr>
7257-
<tr>
7258-
<td><code>ENGINE_METHOD_PKEY_METHS</code></td>
7259-
<td>Limit engine usage to PKEY_METHS</td>
7260-
</tr>
7261-
<tr>
7262-
<td><code>ENGINE_METHOD_PKEY_ASN1_METHS</code></td>
7263-
<td>Limit engine usage to PKEY_ASN1_METHS</td>
7264-
</tr>
7265-
<tr>
7266-
<td><code>ENGINE_METHOD_ALL</code></td>
7267-
<td></td>
7268-
</tr>
7269-
<tr>
7270-
<td><code>ENGINE_METHOD_NONE</code></td>
7271-
<td></td>
7272-
</tr>
7273-
</table>
7274-
72757186
### Other OpenSSL constants
72767187

72777188
<table>

‎doc/api/deprecations.md‎

Lines changed: 11 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -4107,20 +4107,25 @@ that are shorter than the default authentication tag length (i.e., shorter than
41074107

41084108
<!-- YAML
41094109
changes:
4110+
- version: REPLACEME
4111+
pr-url: https://github.com/nodejs/node/pull/64777
4112+
description: End-of-Life.
41104113
- version:
41114114
- v22.4.0
41124115
- v20.16.0
41134116
pr-url: https://github.com/nodejs/node/pull/53329
41144117
description: Documentation-only deprecation.
41154118
-->
41164119

4117-
Type: Documentation-only
4120+
Type: End-of-Life
41184121

4119-
OpenSSL 3 has deprecated support for custom engines with a recommendation to
4120-
switch to its new provider model. The `clientCertEngine` option for
4121-
`https.request()`, [`tls.createSecureContext()`][], and [`tls.createServer()`][];
4122-
the `privateKeyEngine` and `privateKeyIdentifier` for [`tls.createSecureContext()`][];
4123-
and [`crypto.setEngine()`][] all depend on this functionality from OpenSSL.
4122+
The `crypto.setEngine()` API and the `crypto.constants.ENGINE_METHOD_*`
4123+
constants have been removed. The `clientCertEngine` option for
4124+
[`https.request()`][], [`tls.createSecureContext()`][], and
4125+
[`tls.createServer()`][] and the `privateKeyEngine` and `privateKeyIdentifier`
4126+
options for [`tls.createSecureContext()`][] now throw
4127+
`ERR_CRYPTO_CUSTOM_ENGINE_NOT_SUPPORTED` when used. There is no direct
4128+
replacement API in Node.js. OpenSSL's provider model replaces engines upstream.
41244129

41254130
### DEP0184: Instantiating `node:zlib` classes without `new`
41264131

@@ -4845,7 +4850,6 @@ async function example() {
48454850
[`crypto.pbkdf2()`]: crypto.md#cryptopbkdf2password-salt-iterations-keylen-digest-callback
48464851
[`crypto.randomBytes()`]: crypto.md#cryptorandombytessize-callback
48474852
[`crypto.scrypt()`]: crypto.md#cryptoscryptpassword-salt-keylen-options-callback
4848-
[`crypto.setEngine()`]: crypto.md#cryptosetengineengine-flags
48494853
[`decipher.final()`]: crypto.md#decipherfinaloutputencoding
48504854
[`decipher.setAuthTag()`]: crypto.md#deciphersetauthtagbuffer-encoding
48514855
[`dirent.parentPath`]: fs.md#direntparentpath

0 commit comments

Comments
 (0)