Allow openssl version to function in the absence of a config file

the openssl application attempts to load a config file on startup
always, calling x509_get_default_cert_area() to locate the file.  On
Windows builds with -DOSSL_WINCTX set, this fails if the corresponding
registry keys are unset. allow openssl to continue to function properly
for applets that don't actually require a configuration file.

Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Matt Caswell <matt@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/24450)
This commit is contained in:
Neil Horman
2024-07-09 04:01:44 -04:00
parent aa08335852
commit 97bfbb98b0
3 changed files with 11 additions and 3 deletions
-1
View File
@@ -54,7 +54,6 @@ jobs:
- name: Gather openssl version info
working-directory: _build
run: |
$Env:OPENSSL_CONF="apps\openssl.cnf"
apps/openssl.exe version -v
apps/openssl.exe version -v | %{($_ -split '\s+')[1]}
apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+\.[0-9]+)(\..*)','$1'}
-1
View File
@@ -36,7 +36,6 @@ jobs:
- name: Gather openssl version info
working-directory: _build
run: |
$Env:OPENSSL_CONF="apps\openssl.cnf"
apps/openssl.exe version -v
apps/openssl.exe version -v | %{($_ -split '\s+')[1]}
apps/openssl.exe version -v | %{($_ -split '\s+')[1] -replace '([0-9]+\.[0-9]+)(\..*)','$1'}
+11 -1
View File
@@ -692,8 +692,18 @@ char *CONF_get1_default_config_file(void)
return OPENSSL_strdup(file);
t = X509_get_default_cert_area();
/*
* On windows systems with -DOSSL_WINCTX set, if the needed registry
* keys are not yet set, openssl applets will return, due to an inability
* to locate various directories, like the default cert area. In that
* event, clone an empty string here, so that commands like openssl version
* continue to operate properly without needing to set OPENSSL_CONF.
* Applets like cms will fail gracefully later when they try to parse an
* empty config file
*/
if (t == NULL)
return NULL;
return OPENSSL_strdup("");
#ifndef OPENSSL_SYS_VMS
sep = "/";
#endif