On 8/20/26 8:10 PM, Jaipaul Cheernam via lists.openembedded.org wrote:
OpenSSL 4.0 removed the ENGINE API entirely. u-boot uses ENGINE_get_id, ENGINE_load_public_key, ENGINE_finish, ENGINE_free in lib/rsa/rsa-sign.c which causes link failures on all platforms that build u-boot (including riscv64). Backport the Provider API support patch from upstream u-boot which adds OpenSSL Provider support while maintaining backward compatibility with older OpenSSL versions that still have ENGINE. Add the patch to u-boot-common.inc so it applies to both u-boot and u-boot-tools recipes. Upstream-Status: Submitted [https://github.com/u-boot/u-boot/pull/918]
https://lore.kernel.org/u-boot/[email protected]/ is the proper link (please update the one in the patch as well).
From vague recollection, the backward-compatibility shortcomings of the patch should not impact OE-Core as we know for sure it's OpenSSL 4.0 that will be used (which we don't in U-Boot). I think it's still hit by the inablity to use pkcs11 (or other providers) due to trying to find the URI in the local filesystem first.
Fedora 45 will also ship OpenSSL 4.0 as far as I know (hence why we've got a patch from someone at Red Hat).
Feel free to comment on the thread there that this is becoming an issue for OE-Core as well, so that it adds pressure on us fixing it. I was planning on restarting efforts on OpenSSL providers (3.x+) next week though I'm unsure whether I'll manage to send something to the ML in time before I'm out of office the two weeks after.
Cheers, Quentin
-=-=-=-=-=-=-=-=-=-=-=- Links: You receive all messages sent to this group. View/Reply Online (#243921): https://lists.openembedded.org/g/openembedded-core/message/243921 Mute This Topic: https://lists.openembedded.org/mt/120850409/21656 Group Owner: [email protected] Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub [[email protected]] -=-=-=-=-=-=-=-=-=-=-=-
