[MDEV-18531] Use WolfSSL instead of YaSSL as "bundled" SSL Created: 2019-02-11  Updated: 2021-01-02  Resolved: 2019-05-22

Status: Closed
Project: MariaDB Server
Component/s: Compiling, SSL
Fix Version/s: 10.4.6

Type: Task Priority: Major
Reporter: Vladislav Vaintroub Assignee: Vladislav Vaintroub
Resolution: Fixed Votes: 0
Labels: None

Issue Links:
Blocks
blocks MDEV-19542 Disable SSLv3 and TLSv1.0 Closed
Problem/Incident
causes MDEV-19582 Out-of-bounds memory accesses by WolfSSL Closed
causes MDEV-19604 WolfSSL breaks binlog_encryption.binl... Closed
causes MDEV-22487 Server prints "Please supply a buffer... Closed
Relates
relates to MDEV-19578 Test whether file_key_management_encr... Closed
relates to MDEV-23663 HAVE_INTEL_RDRAND is not enabled in t... Closed
relates to MDEV-24514 WITH_MSAN is disabling WOLFSSL_AESNI ... Closed
relates to MDEV-10726 Official Windows builds do not suppor... Closed
relates to MDEV-10953 Replace yassl Closed
relates to MDEV-16475 Remove yassl Closed
relates to MDEV-21705 Source embedded WolfSSL crashes mysql... Closed
relates to MDEV-26758 Make libmariadb run under MSAN Closed

 Description   

YaSSL is out of support for several years. Newest TLS (e.g 1.2) does not work with it



 Comments   
Comment by Vladislav Vaintroub [ 2019-02-14 ]

the patches are in https://github.com/MariaDB/server/tree/bb-10.4-wlad-wolfssl

Comment by Otto Kekäläinen [ 2020-09-30 ]

In Ubuntu 20.04 we have MariaDB 10.3 and it does not have any functional TLS since Ubuntu 20.04 mandates TLSv1.2 at minimum, and the bundled YaSSL/WolfSSL only supports up to TLSv.1.1: https://bugs.launchpad.net/ubuntu/+source/mariadb-10.3/+bug/1885632

Should I backport https://github.com/mariadb/server/commit/5e4b657dd44dce601c91bc77a41f6e382bc32000 to MariaDB 10.3 in Ubuntu?

Comment by Vladislav Vaintroub [ 2020-09-30 ]

otto, This question is best asked on mailing list. As far as I understand, this would be a break of policy , no new features in old releases.

Comment by Otto Kekäläinen [ 2020-10-27 ]

I marked https://bugs.launchpad.net/ubuntu/+source/mariadb-10.3/+bug/1885632 "won't fix" now, as I don't have the bandwidth to do all the communication required to coordinate such an upload to Ubuntu stable updates.

Generated at Thu Feb 08 08:44:50 UTC 2024 using Jira 8.20.16#820016-sha1:9d11dbea5f4be3d4cc21f03a88dd11d8c8687422.