Crypto: switched to OpenSSL EVP for hashing.#1039
Open
xeioex wants to merge 1 commit intonginx:masterfrom
Open
Crypto: switched to OpenSSL EVP for hashing.#1039xeioex wants to merge 1 commit intonginx:masterfrom
xeioex wants to merge 1 commit intonginx:masterfrom
Conversation
057de5b to
578f559
Compare
Previously, the crypto module used built-in software implementations for a limited set of hash algorithms (md5, sha1, sha256). This prevented users from using algorithms like sha384, sha512, and sha3 family, even when the underlying OpenSSL library supported them. The change replaces built-in hash implementations with OpenSSL EVP_MD_CTX for createHash() and HMAC_CTX for createHmac(), following the webcrypto module. Algorithm lookup now uses EVP_get_digestbyname(), making any digest supported by the linked OpenSSL available to JavaScript code. The module now requires OpenSSL and is conditionally compiled, same as the webcrypto module. Builds without OpenSSL (--no-openssl) will no longer have the crypto module available. Tested with OpenSSL 3.0, OpenSSL 1.1.1w, LibreSSL 3.9.2, and BoringSSL. SHA-3 tests are skipped when the SSL library does not support them (e.g. BoringSSL). This closes nginx#1037 feature request on Github.
578f559 to
d6dd62f
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Previously, the crypto module used built-in software implementations for a limited set of hash algorithms (md5, sha1, sha256). This prevented users from using algorithms like sha384, sha512, and sha3 family, even when the underlying OpenSSL library supported them.
The change replaces built-in hash implementations with OpenSSL EVP_MD_CTX for createHash() and HMAC_CTX for createHmac(), following the pattern already established by the webcrypto module. Algorithm lookup now uses EVP_get_digestbyname(), making any digest supported by the linked OpenSSL available to JavaScript code.
The module now requires OpenSSL and is conditionally compiled, same as the webcrypto module. Builds without OpenSSL (--no-openssl) will no longer have the crypto module available.
Tested with OpenSSL 3.0, OpenSSL 1.1.1w, LibreSSL 3.9.2, and BoringSSL. SHA-3 tests are skipped when the SSL library does not support them (e.g. BoringSSL).
This closes #1037 feature request on Github.