Skip to content

Do not use DSA API unless USE_DSA is set - #1224

Merged
gthess merged 1 commit into
NLnetLabs:masterfrom
botovq:improve-use-dsa
Jan 21, 2025
Merged

Do not use DSA API unless USE_DSA is set#1224
gthess merged 1 commit into
NLnetLabs:masterfrom
botovq:improve-use-dsa

Conversation

@botovq

@botovq botovq commented Jan 18, 2025

Copy link
Copy Markdown
Contributor

Even if USE_DSA is unset, unbound ends up linking against OpenSSL DSA API because these guards are missing.

Even if USE_DSA is unset, unbound ends up linking against OpenSSL
DSA API because these guards are missing.
@gthess gthess self-assigned this Jan 21, 2025
@gthess

gthess commented Jan 21, 2025

Copy link
Copy Markdown
Member

This looks good to me, disabling the DSA calls when DSA support is not compiled in (default). Thanks!

@gthess
gthess merged commit a2bf32b into NLnetLabs:master Jan 21, 2025
gthess added a commit that referenced this pull request Jan 21, 2025
- Merge #1224 from Theo Buehler: Do not use DSA API unless USE_DSA is
  set.
bob-beck pushed a commit to openbsd/src that referenced this pull request Feb 7, 2025
jedisct1 added a commit to jedisct1/unbound that referenced this pull request Mar 18, 2025
* nlnet/master: (37 commits)
  - Fix for windows compile create ssl contexts.
  - Fix NLnetLabs#1251: WSAPoll first argument cannot be NULL.
  - Fix representation of types GPOS and RESINFO, add rdf type for
  - Fix 'unbound-control flush_negative' when reporting removed data;   reported by David 'eqvinox' Lamparter.
  Changelog nore for NLnetLabs#1238 and add `--help` description. - Merge NLnetLabs#1238: Prefer SOURCE_DATE_EPOCH over actual time.   Add --help output description for the SOURCE_DATE_EPOCH variable.
  Prefer SOURCE_DATE_EPOCH over actual time (NLnetLabs#1238)
  Changelog note for NLnetLabs#1243 - Merge NLnetLabs#1243: Do not shadow tm on line 236.
  Do not shadow tm on line 236. (NLnetLabs#1243)
  - Fix hash calculation for cachedb to ignore case. Previously, cached   records there were only relevant for same case queries (if not   already in Unbound's internal cache).
  Changelog entry for NLnetLabs#1241: - Merge NLnetLabs#1241: Fix infra-keep-probing for low infra-cache-max-rtt   values.
  - The maximum value of a probe rto was not aligned with the   (configurable) infra-cache-max-rtt value. That could result in   infra-keep-probing not working if an infra-cache-max-rtt value was chosen   that was below 12000 ms. This fix still uses a default value of 12000   ms for the probe but caps it to the infra-cache-max-rtt if that is   lower.
  - Fix static analysis report about unhandled EOF on error conditions   when reading anchor key files.
  - Consider reconfigurations when calculating the still_useful_timeout   for servers in the infrastructure cache.
  - Fix NLnetLabs#986: Resolving sas.com with dnssec-validation fails though   signed delegations seem to be (mostly) correct.
  - Make the default value of module-config "validator iterator"   regardless of compilation options. --enable-subnet would implicitly   change the value to enable the subnetcache module by default in the   past.
  Changelog entry for NLnetLabs#1220: - Merge NLnetLabs#1220 from Petr Menšík, Add unbound members group access to   control key.
  Changelog entry for NLnetLabs#1224: - Merge NLnetLabs#1224 from Theo Buehler: Do not use DSA API unless USE_DSA is   set.
  Changelog note for NLnetLabs#1229 - Merge NLnetLabs#1229: check before use daemon->shm_info.
  check before use daemon->shm_info (NLnetLabs#1229)
  - Do not open unencrypted channels next to encrypted ones on the same   port.
  ...
Sashan pushed a commit to Sashan/src that referenced this pull request May 4, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants