Repository navigation
OpenSSL engine support in TLS module #5101
Description
Activity
- addedquestionIssues asking questions about Node.js.Issues asking questions about Node.js.tlsIssues and PRs related to the tls subsystem.Issues and PRs related to the tls subsystem.
on Feb 5, 2016 Is your question whether openssl supports the GOST TLS cipher suites? I believe the answer is 'yes' but you need to configure it through the 'ciphers' option to
tls.createServer(). See the man page for details.Hey @bnoordhuis, thanks for a quick reply.
Yes I know GOST is supported and I can successfully use openssl cli to make the connection, but it fails in node.js. GOST ciphers require a custom openssl engine though, which I can correctly use incryptomodule aftercrypto.setEngine(), but not intlsmodule.
Actually I usetls.connect()at the moment, nottls.createServer(), just to be specific.
Whet I try to specify a correct cipher suite (namely, 'GOST2001-GOST89-GOST89'), which works fine in openssl cli, this is thrown from node:Error: 140026998658944:error:140830B5:SSL routines:ssl3_client_hello:no ciphers available:../deps/openssl/openssl/ssl/s3_clnt.c:832:and there are really no such cipher suite in the
tls.getCiphers()response.There are no ciphers listed in
tls.getCiphers()at all or just not that particular one?Just not that particular one, only the usual stuff. Note that I limit
ciphersin thetls.connect()to this only one, to force this error. Otherwise the connection continues but multiple other issues arise, 'cause server supports this cipher only.Sorry I am not familiar that good with the node architecture, but can someone tell me if running
crypto.setEngine()should have any influence on thetlsmodule, on the cipher list particularly, by design?The same problem and the solution I described in Pull Request, see #5739
This issue is now resolved as part of #6374.
It is possible to set a custom openssl engine via
crypto.setEngineand it seems to work OK. When I plug in a GOST engine, I get the GOST ciphers incrypto.getCiphers().But it seems to have no effect on the TLS module.
Is it somehow possible to support a pluggable openssl engine for a TLS connection?