This should address the problem described in #1662.
EVP_PKEY_derive_set_peer
requires the peer's public certificate to have exactly the same DH parameters, hence we need to merge the OSSL_PARAMs
containing the public key with the DH parameters:
xrootd/src/XrdCrypto/openssl3/XrdCryptosslCipher.cc
Lines 580 to 586 in 7a4871c
EVP_PKEY_derive
requires for the keylen argument to contain the length of key buffer (if not null):
https://www.openssl.org/docs/man1.0.2/man3/EVP_PKEY_derive.html
If key is not NULL then before the call the keylen parameter should contain the length of the key buffer, if the call is successful the shared secret is written to key and the amount of data written to keylen.
https://github.com/xrootd/xrootd/pull/1665
(1 file)
—
Reply to this email directly, view it on GitHub, or unsubscribe.
You are receiving this because you are subscribed to this thread.
Use REPLY-ALL to reply to list
To unsubscribe from the XROOTD-DEV list, click the following link:
https://listserv.slac.stanford.edu/cgi-bin/wa?SUBED1=XROOTD-DEV&A=1