Hi Quentin,
Thanks for pointing out to correct patch link.
Yes — the upstream patch unconditionally loads the pkcs11 provider and atally
errors if it's not installed.
Fixed by making the load non-fatal: default provider loads first (mandatory),
pkcs11 is attempted but ERR_clear_error() on failure so file-based signing
works without it.
Sent a reply to the u-boot ML thread noting this is needed for OE-Core and
sharing our workaround, though it's currently held for moderator approval (!!).
“We're currently working on upgrading OpenEmbedded-Core (Yocto Project) to
OpenSSL 4.0.1 and hit this exact issue — mkimage fails at FIT image signing
because it unconditionally tries to load the pkcs11 provider, which isn't
available in our build environment.
For our purposes, file-based key signing with just the default provider works
fine. We're carrying this patch with a local modification that makes the pkcs11
provider load non-fatal:
if (!OSSL_PROVIDER_try_load(NULL, "default", true))
ERR(1, "OSSL_PROVIDER_try_load(default)");
/* pkcs11 provider is optional; only needed for pkcs11: URIs */
if (!OSSL_PROVIDER_try_load(NULL, "pkcs11", true))
ERR_clear_error();
This allows signing to work without pkcs11-provider installed while still
loading it when available (for pkcs11: URI keys).
Is there a v5 in the works? Happy to test if it would help move this forward.
"
Regards,
Jaipaul Cheernam
🔗 EST Website<https://www.est.tech/>
🔗 EST LinkedIn<https://www.linkedin.com/company/ericsson-software-technology/>
From: Quentin Schulz <[email protected]>
Date: Friday, 21 August 2026 at 12:52
To: Jaipaul Cheernam <[email protected]>;
[email protected]
<[email protected]>
Subject: Re: [OE-core] [RFC v2 5/6] u-boot: fix build with OpenSSL 4.0
On 8/20/26 8:10 PM, Jaipaul Cheernam via lists.openembedded.org wrote:
> OpenSSL 4.0 removed the ENGINE API entirely. u-boot uses
> ENGINE_get_id, ENGINE_load_public_key, ENGINE_finish, ENGINE_free
> in lib/rsa/rsa-sign.c which causes link failures on all platforms
> that build u-boot (including riscv64).
>
> Backport the Provider API support patch from upstream u-boot which
> adds OpenSSL Provider support while maintaining backward compatibility
> with older OpenSSL versions that still have ENGINE.
>
> Add the patch to u-boot-common.inc so it applies to both u-boot
> and u-boot-tools recipes.
>
> Upstream-Status: Submitted [https://github.com/u-boot/u-boot/pull/918]
https://lore.kernel.org/u-boot/[email protected]/
is the proper link (please update the one in the patch as well).
From vague recollection, the backward-compatibility shortcomings of the
patch should not impact OE-Core as we know for sure it's OpenSSL 4.0
that will be used (which we don't in U-Boot). I think it's still hit by
the inablity to use pkcs11 (or other providers) due to trying to find
the URI in the local filesystem first.
Fedora 45 will also ship OpenSSL 4.0 as far as I know (hence why we've
got a patch from someone at Red Hat).
Feel free to comment on the thread there that this is becoming an issue
for OE-Core as well, so that it adds pressure on us fixing it. I was
planning on restarting efforts on OpenSSL providers (3.x+) next week
though I'm unsure whether I'll manage to send something to the ML in
time before I'm out of office the two weeks after.
Cheers,
Quentin
-=-=-=-=-=-=-=-=-=-=-=-
Links: You receive all messages sent to this group.
View/Reply Online (#243974):
https://lists.openembedded.org/g/openembedded-core/message/243974
Mute This Topic: https://lists.openembedded.org/mt/120850409/21656
Group Owner: [email protected]
Unsubscribe: https://lists.openembedded.org/g/openembedded-core/unsub
[[email protected]]
-=-=-=-=-=-=-=-=-=-=-=-