Skip to content

Commit 86ad46e

Browse files
committed
pkey/dh: deprecate OpenSSL::PKey::DH#generate_key!
OpenSSL 3.0.0 has made keys immutable, so PKey::DH#generate_key! can't work on it anymore. It's advised to use OpenSSL::PKey.generate_key instead.
1 parent 3984792 commit 86ad46e

File tree

2 files changed

+40
-19
lines changed

2 files changed

+40
-19
lines changed

lib/openssl/pkey.rb

Lines changed: 22 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -80,14 +80,32 @@ def compute_key(pub_bn)
8080
# called first in order to generate the per-session keys before performing
8181
# the actual key exchange.
8282
#
83+
# <b>Deprecated in version 3.0</b>. This method is incompatible with
84+
# OpenSSL 3.0.0 or later.
85+
#
8386
# See also OpenSSL::PKey.generate_key.
8487
#
8588
# Example:
86-
# dh = OpenSSL::PKey::DH.new(2048)
87-
# public_key = dh.public_key #contains no private/public key yet
88-
# public_key.generate_key!
89-
# puts public_key.private? # => true
89+
# # DEPRECATED USAGE: This will not work on OpenSSL 3.0 or later
90+
# dh0 = OpenSSL::PKey::DH.new(2048)
91+
# dh = dh0.public_key # #public_key only copies the DH parameters (contrary to the name)
92+
# dh.generate_key!
93+
# puts dh.private? # => true
94+
# puts dh0.pub_key == dh.pub_key #=> false
95+
#
96+
# # With OpenSSL::PKey.generate_key
97+
# dh0 = OpenSSL::PKey::DH.new(2048)
98+
# dh = OpenSSL::PKey.generate_key(dh0)
99+
# puts dh0.pub_key == dh.pub_key #=> false
90100
def generate_key!
101+
msg = "OpenSSL::PKey::DH is immutable on OpenSSL 3.0; " \
102+
"use OpenSSL::PKey.generate_key instead"
103+
if OpenSSL::OPENSSL_VERSION_NUMBER >= 0x30000000
104+
raise DHError, msg
105+
else
106+
warn "#{caller(1, 1)[0]}: warning: #{msg}"
107+
end
108+
91109
unless priv_key
92110
tmp = OpenSSL::PKey.generate_key(self)
93111
set_key(tmp.pub_key, tmp.priv_key)

test/openssl/test_pkey_dh.rb

Lines changed: 18 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -26,14 +26,19 @@ def test_new_break
2626
end
2727

2828
def test_derive_key
29-
dh1 = Fixtures.pkey("dh1024").generate_key!
30-
dh2 = Fixtures.pkey("dh1024").generate_key!
29+
params = Fixtures.pkey("dh1024")
30+
dh1 = OpenSSL::PKey.generate_key(params)
31+
dh2 = OpenSSL::PKey.generate_key(params)
3132
dh1_pub = OpenSSL::PKey.read(dh1.public_to_der)
3233
dh2_pub = OpenSSL::PKey.read(dh2.public_to_der)
34+
3335
z = dh1.g.mod_exp(dh1.priv_key, dh1.p).mod_exp(dh2.priv_key, dh1.p).to_s(2)
3436
assert_equal z, dh1.derive(dh2_pub)
3537
assert_equal z, dh2.derive(dh1_pub)
3638

39+
assert_raise(OpenSSL::PKey::PKeyError) { params.derive(dh1_pub) }
40+
assert_raise(OpenSSL::PKey::PKeyError) { dh1_pub.derive(params) }
41+
3742
assert_equal z, dh1.compute_key(dh2.pub_key)
3843
assert_equal z, dh2.compute_key(dh1.pub_key)
3944
end
@@ -74,19 +79,17 @@ def test_public_key
7479
end
7580

7681
def test_generate_key
77-
dh = Fixtures.pkey("dh1024").public_key # creates a copy
78-
assert_no_key(dh)
79-
dh.generate_key!
80-
assert_key(dh)
81-
end
82-
83-
def test_key_exchange
84-
dh = Fixtures.pkey("dh1024")
85-
dh2 = dh.public_key
86-
dh.generate_key!
87-
dh2.generate_key!
88-
assert_equal(dh.compute_key(dh2.pub_key), dh2.compute_key(dh.pub_key))
89-
end
82+
EnvUtil.suppress_warning { # Deprecated in v3.0.0; incompatible with OpenSSL 3.0
83+
dh = Fixtures.pkey("dh1024").public_key # creates a copy with params only
84+
assert_no_key(dh)
85+
dh.generate_key!
86+
assert_key(dh)
87+
88+
dh2 = dh.public_key
89+
dh2.generate_key!
90+
assert_equal(dh.compute_key(dh2.pub_key), dh2.compute_key(dh.pub_key))
91+
}
92+
end if !openssl?(3, 0, 0)
9093

9194
def test_params_ok?
9295
dh0 = Fixtures.pkey("dh1024")

0 commit comments

Comments
 (0)