On 8/20/26 8:10 PM, Jaipaul Cheernam via lists.openembedded.org wrote:
OpenSSL 4.0 removed the ENGINE API entirely. u-boot uses
ENGINE_get_id, ENGINE_load_public_key, ENGINE_finish, ENGINE_free
in lib/rsa/rsa-sign.c which causes link failures on all platforms
that build u-boot (including riscv64).

Backport the Provider API support patch from upstream u-boot which
adds OpenSSL Provider support while maintaining backward compatibility
with older OpenSSL versions that still have ENGINE.

Add the patch to u-boot-common.inc so it applies to both u-boot
and u-boot-tools recipes.

Upstream-Status: Submitted [https://github.com/u-boot/u-boot/pull/918]

https://lore.kernel.org/u-boot/[email protected]/ is the proper link (please update the one in the patch as well).

From vague recollection, the backward-compatibility shortcomings of the patch should not impact OE-Core as we know for sure it's OpenSSL 4.0 that will be used (which we don't in U-Boot). I think it's still hit by the inablity to use pkcs11 (or other providers) due to trying to find the URI in the local filesystem first.

Fedora 45 will also ship OpenSSL 4.0 as far as I know (hence why we've got a patch from someone at Red Hat).

Feel free to comment on the thread there that this is becoming an issue for OE-Core as well, so that it adds pressure on us fixing it. I was planning on restarting efforts on OpenSSL providers (3.x+) next week though I'm unsure whether I'll manage to send something to the ML in time before I'm out of office the two weeks after.

Cheers,
Quentin
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243921): 
https://lists.openembedded.org/g/openembedded-core/message/243921
Mute This Topic: https://lists.openembedded.org/mt/120850409/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub 
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-

Reply via email to