Repository navigation
Port _hashlib to OpenSSL 3.0.0 #84659
Description
Activity
OpenSSL 3.0.0-alpha1 was releases about a week ago. OpenSSL 1.1.x APIs are still functional. However some APIs have been deprecated and FIPS (usedforsecurity flag) is no longer functional.
- One shot HMAC() is deprecated and should be replaced with EVP_MAC API calls
- ERR_func_error_string() is deprecated
- OpenSSL has introduced a new concept of crypto providers (OSSL_PROVIDER), library context (OPENSSL_CTX) and additional flags. A new function EVP_MD_fetch() has been introduced.
- FIPS support has been rewritten and is now shipped with OpenSSL 3.0.0. EVP_MD_CTX_FLAG_NON_FIPS_ALLOW is no longer supported. FIPS state is no longer part of EVP_MD_CTX but of EVP_MD.
- added3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of life
on May 3, 2020 - addedtype-featureA feature request or enhancementA feature request or enhancement
on May 3, 2020 Simple benchmark with openssl-3.0.0-5.el9.x86_64
With custom EVP_MD cache:
$ ./python -m timeit -s "from hashlib import md5" "md5(b'12345678', usedforsecurity=False).digest()"500000 loops, best of 5: 520 nsec per loop
$ ./python -m timeit -s "from hashlib import sha512" "sha512(b'12345678', usedforsecurity=False).digest()"
500000 loops, best of 5: 730 nsec per loopWithout EVP_MD cache:
$ ./python -m timeit -s "from hashlib import md5" "md5(b'', usedforsecurity=False).digest()"
500000 loops, best of 5: 807 nsec per loop
$ ./python -m timeit -s "from hashlib import sha512" "sha512(b'12345678', usedforsecurity=False).digest()"
200000 loops, best of 5: 1.03 usec per loopNew changeset 59e004a by Zackery Spytz in branch 'main':
bpo-40479: Fix undefined behavior in Modules/_hashopenssl.c (GH-31153)
59e004aNew changeset 3ceff99 by Miss Islington (bot) in branch '3.10':
bpo-40479: Fix undefined behavior in Modules/_hashopenssl.c (GH-31153)
3ceff99New changeset 0892a0e by Miss Islington (bot) in branch '3.9':
bpo-40479: Fix undefined behavior in Modules/_hashopenssl.c (GH-31153)
0892a0e@tiran Can this be closed now ?
closing as the bulk of this appears done but it isn't clear what 100% is. If there are remaining deprecated APIs in use we can open individual issues for those and clean them up as needed going forwards.
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: