Skip to content

OpenSSL engine support in TLS module #5101

Description

@burmisov

It is possible to set a custom openssl engine via crypto.setEngine and it seems to work OK. When I plug in a GOST engine, I get the GOST ciphers in crypto.getCiphers().
But it seems to have no effect on the TLS module.
Is it somehow possible to support a pluggable openssl engine for a TLS connection?

Activity

  1. added
    questionIssues asking questions about Node.js.
    tlsIssues and PRs related to the tls subsystem.
    on Feb 5, 2016
  2. bnoordhuis commented on Feb 5, 2016

    @bnoordhuis
    Member

    Is your question whether openssl supports the GOST TLS cipher suites? I believe the answer is 'yes' but you need to configure it through the 'ciphers' option to tls.createServer(). See the man page for details.

  3. burmisov commented on Feb 5, 2016

    @burmisov
    Author

    Hey @bnoordhuis, thanks for a quick reply.
    Yes I know GOST is supported and I can successfully use openssl cli to make the connection, but it fails in node.js. GOST ciphers require a custom openssl engine though, which I can correctly use in crypto module after crypto.setEngine(), but not in tls module.
    Actually I use tls.connect() at the moment, not tls.createServer(), just to be specific.
    Whet I try to specify a correct cipher suite (namely, 'GOST2001-GOST89-GOST89'), which works fine in openssl cli, this is thrown from node:

    Error: 140026998658944:error:140830B5:SSL routines:ssl3_client_hello:no ciphers available:../deps/openssl/openssl/ssl/s3_clnt.c:832:
    

    and there are really no such cipher suite in the tls.getCiphers() response.

  4. mscdex commented on Feb 5, 2016

    @mscdex
    Contributor

    There are no ciphers listed in tls.getCiphers() at all or just not that particular one?

  5. burmisov commented on Feb 5, 2016

    @burmisov
    Author

    Just not that particular one, only the usual stuff. Note that I limit ciphers in the tls.connect() to this only one, to force this error. Otherwise the connection continues but multiple other issues arise, 'cause server supports this cipher only.

    Sorry I am not familiar that good with the node architecture, but can someone tell me if running crypto.setEngine() should have any influence on the tls module, on the cipher list particularly, by design?

  6. temaivanoff commented on Mar 16, 2016

    @temaivanoff

    The same problem and the solution I described in Pull Request, see #5739

  7. stefanmb commented on Apr 26, 2016

    @stefanmb
    Contributor

    This issue is now resolved as part of #6374.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    questionIssues asking questions about Node.js.tlsIssues and PRs related to the tls subsystem.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions