diff mbox

[OpenWrt-Devel,3/6] openssl: add option for NPN support

Message ID 1465468590-1961-5-git-send-email-dirk.feytons@gmail.com
State Changes Requested
Headers show

Commit Message

Dirk Feytons June 9, 2016, 10:36 a.m. UTC
NPN has been superseded by ALPN so NPN is disabled by default
The patch has been sent to OpenSSL for inclusion, see
https://github.com/openssl/openssl/pull/1100

Signed-off-by: Dirk Feytons <dirk.feytons@gmail.com>
---
 package/libs/openssl/Config.in                     |    5 +++++
 package/libs/openssl/Makefile                      |    7 ++++++-
 .../patches/301-fix_no_nextprotoneg_build.patch    |   12 ++++++++++++
 3 files changed, 23 insertions(+), 1 deletion(-)
 create mode 100644 package/libs/openssl/patches/301-fix_no_nextprotoneg_build.patch
diff mbox

Patch

diff --git a/package/libs/openssl/Config.in b/package/libs/openssl/Config.in
index 02b5da9..492b042 100644
--- a/package/libs/openssl/Config.in
+++ b/package/libs/openssl/Config.in
@@ -25,6 +25,11 @@  config OPENSSL_WITH_COMPRESSION
 	default n
 	prompt "Enable compression support"
 
+config OPENSSL_WITH_NPN
+	bool
+	default n
+	prompt "Enable NPN support"
+
 config OPENSSL_ENGINE_DIGEST
 	bool
 	depends on OPENSSL_ENGINE_CRYPTO
diff --git a/package/libs/openssl/Makefile b/package/libs/openssl/Makefile
index c6824f3..61022dc 100644
--- a/package/libs/openssl/Makefile
+++ b/package/libs/openssl/Makefile
@@ -35,7 +35,8 @@  PKG_CONFIG_DEPENDS:= \
 	CONFIG_OPENSSL_WITH_SSL3 \
 	CONFIG_OPENSSL_HARDWARE_SUPPORT \
 	CONFIG_OPENSSL_WITH_DEPRECATED \
-	CONFIG_OPENSSL_WITH_COMPRESSION
+	CONFIG_OPENSSL_WITH_COMPRESSION \
+	CONFIG_OPENSSL_WITH_NPN
 
 include $(INCLUDE_DIR)/package.mk
 
@@ -132,6 +133,10 @@  else
   OPENSSL_OPTIONS += zlib-dynamic
 endif
 
+ifndef CONFIG_OPENSSL_WITH_NPN
+  OPENSSL_OPTIONS += no-nextprotoneg
+endif
+
 ifeq ($(CONFIG_x86_64),y)
   OPENSSL_TARGET:=linux-x86_64-openwrt
   OPENSSL_MAKEFLAGS += LIBDIR=lib
diff --git a/package/libs/openssl/patches/301-fix_no_nextprotoneg_build.patch b/package/libs/openssl/patches/301-fix_no_nextprotoneg_build.patch
new file mode 100644
index 0000000..04b76c7
--- /dev/null
+++ b/package/libs/openssl/patches/301-fix_no_nextprotoneg_build.patch
@@ -0,0 +1,12 @@ 
+--- a/ssl/t1_ext.c
++++ b/ssl/t1_ext.c
+@@ -275,7 +275,9 @@ int SSL_extension_supported(unsigned int
+     case TLSEXT_TYPE_ec_point_formats:
+     case TLSEXT_TYPE_elliptic_curves:
+     case TLSEXT_TYPE_heartbeat:
++# ifndef OPENSSL_NO_NEXTPROTONEG
+     case TLSEXT_TYPE_next_proto_neg:
++# endif
+     case TLSEXT_TYPE_padding:
+     case TLSEXT_TYPE_renegotiate:
+     case TLSEXT_TYPE_server_name: