summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorDenys Fedoryshchenko <denys.f@collabora.com>2025-11-28 08:39:54 +0200
committerGitHub <noreply@github.com>2025-11-28 08:39:54 +0200
commitac31c84a36c069c90e37ab28a9e980c0749b2b37 (patch)
tree000feeda61f4fcc3bda6cd625d94c178fbbaa2da
parent4dd5072e09df7bf487694fe6bdd16715b419c4f6 (diff)
parentf03dc39ae891d20e56d7acd764a9b5764a8a2fef (diff)
downloadaccel-ppp-ac31c84a36c069c90e37ab28a9e980c0749b2b37.tar.gz
accel-ppp-ac31c84a36c069c90e37ab28a9e980c0749b2b37.zip
Merge pull request #267 from nuclearcat/fix-ssl-warnings
Suppress OpenSSL 3.0 deprecation warnings for legacy crypto APIs
-rw-r--r--accel-pppd/ctrl/sstp/sstp.c7
-rw-r--r--accel-pppd/radius/packet.c6
-rw-r--r--crypto/crypto.h14
3 files changed, 26 insertions, 1 deletions
diff --git a/accel-pppd/ctrl/sstp/sstp.c b/accel-pppd/ctrl/sstp/sstp.c
index d63caa32..9239da30 100644
--- a/accel-pppd/ctrl/sstp/sstp.c
+++ b/accel-pppd/ctrl/sstp/sstp.c
@@ -20,8 +20,13 @@
#include "linux_ppp.h"
#ifdef CRYPTO_OPENSSL
+/*
+ * Suppress OpenSSL 3.0 deprecation warnings for DH API.
+ * See crypto.h for detailed explanation.
+ */
+#define OPENSSL_API_COMPAT 0x10100000L
#include <openssl/ssl.h>
-#include <openssl/err.h>
+#include <openssl/err.h>
#endif
#include "triton.h"
diff --git a/accel-pppd/radius/packet.c b/accel-pppd/radius/packet.c
index 87746d22..aae2c6a1 100644
--- a/accel-pppd/radius/packet.c
+++ b/accel-pppd/radius/packet.c
@@ -8,6 +8,12 @@
#include <sys/mman.h>
#include <linux/mman.h>
#include <arpa/inet.h>
+
+/*
+ * Suppress OpenSSL 3.0 deprecation warnings for HMAC API.
+ * See crypto.h for detailed explanation.
+ */
+#define OPENSSL_API_COMPAT 0x10100000L
#include <openssl/hmac.h>
#include <openssl/evp.h>
diff --git a/crypto/crypto.h b/crypto/crypto.h
index 9e2e8401..45de740e 100644
--- a/crypto/crypto.h
+++ b/crypto/crypto.h
@@ -3,6 +3,20 @@
#ifdef CRYPTO_OPENSSL
+/*
+ * Suppress OpenSSL 3.0 deprecation warnings for legacy crypto APIs.
+ * These low-level APIs (MD5, SHA1, DES, etc.) are deprecated in OpenSSL 3.0
+ * but still functional and required for protocol compatibility.
+ *
+ * This approach is consistent with other major projects:
+ * - FreeRADIUS: Uses OPENSSL_API_COMPAT for the same reason
+ * - OpenVPN: Uses OPENSSL_API_COMPAT to maintain legacy protocol support
+ *
+ * The deprecated functions will remain available in OpenSSL 3.x series.
+ * Migration to EVP API may be considered for future major versions.
+ */
+#define OPENSSL_API_COMPAT 0x10100000L
+
#include <openssl/md4.h>
#include <openssl/md5.h>
#include <openssl/sha.h>