René's URL Explorer Experiment


Title: Fallback md5 is used, when trying hard to only use OpenSSL · Issue #118224 · python/cpython · GitHub

Open Graph Title: Fallback md5 is used, when trying hard to only use OpenSSL · Issue #118224 · python/cpython

X Title: Fallback md5 is used, when trying hard to only use OpenSSL · Issue #118224 · python/cpython

Description: Bug report Bug description: When OpenSSL is configured in FIPS mode recommended config is used to only load "base + fips" providers without the default provider CPython is compiled with --with-builtin-hashlib-hashes=blake2 to exclude fal...

Open Graph Description: Bug report Bug description: When OpenSSL is configured in FIPS mode recommended config is used to only load "base + fips" providers without the default provider CPython is compiled with --with-buil...

X Description: Bug report Bug description: When OpenSSL is configured in FIPS mode recommended config is used to only load "base + fips" providers without the default provider CPython is compiled with -...

Opengraph URL: https://github.com/python/cpython/issues/118224

X: @github

direct link

Domain: github.com


Hey, it has json ld scripts:
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Fallback md5 is used, when trying hard to only use OpenSSL","articleBody":"# Bug report\r\n\r\n### Bug description:\r\n\r\nWhen\r\n* OpenSSL is configured in FIPS mode\r\n* recommended config is used to only load \"base + fips\" providers\r\n* without the default provider\r\n* CPython is compiled with `--with-builtin-hashlib-hashes=blake2` to exclude fallback implementation of MD5\r\n\r\nupon importing hashlib fails to create MD5 construct.\r\n\r\n```python\r\n# python3.10 -c 'import hashlib'\r\nERROR:root:code for hash md5 was not found.\r\nTraceback (most recent call last):\r\n  File \"/usr/lib/python3.10/hashlib.py\", line 137, in __get_openssl_constructor\r\n    f(usedforsecurity=False)\r\nValueError: [digital envelope routines] unsupported\r\n\r\nDuring handling of the above exception, another exception occurred:\r\n\r\nTraceback (most recent call last):\r\n  File \"/usr/lib/python3.10/hashlib.py\", line 261, in \u003cmodule\u003e\r\n    globals()[__func_name] = __get_hash(__func_name)\r\n  File \"/usr/lib/python3.10/hashlib.py\", line 141, in __get_openssl_constructor\r\n    return __get_builtin_constructor(name)\r\n  File \"/usr/lib/python3.10/hashlib.py\", line 123, in __get_builtin_constructor\r\n    raise ValueError('unsupported hash type ' + name)\r\nValueError: unsupported hash type md5\r\n```\r\n\r\nReference implementation is upstream openssl 3.3.0, with enable-fips, fipsinstall completed and openssl.cnf set to\r\n```\r\n# cat /etc/ssl/openssl.cnf \r\nconfig_diagnostics = 1\r\nopenssl_conf = openssl_init\r\n\r\n.include /etc/ssl/fipsmodule.cnf\r\n\r\n[openssl_init]\r\nproviders = provider_sect\r\nalg_section = algorithm_sect\r\n\r\n[provider_sect]\r\nfips = fips_sect\r\nbase = base_sect\r\n\r\n[base_sect]\r\nactivate = 1\r\n\r\n[algorithm_sect]\r\ndefault_properties = fips=yes\r\n```\r\n\r\nIn essence, things work well only when \"default + fips\" providers are loaded, as then MD5 functions in OpenSSL are detected as available and are used at runtime and correctly get blocked.\r\n\r\nWhen only \"base + fips\" providers are loaded, ValueError is raised by OpenSSL constructor, and instead fallback implementation used from _md5 module if it was compiled in.\r\n\r\nIt seems like the above configuration was not tested, however it can be made to work. CPython should try to load  the \"default\" OpenSSL provider, to guarantee access to non-fips hashes.\r\n\r\n### Security concerns\r\n\r\nThis is FedRAMP/FIPS compliance by-pass. This issue may allow using md5 without specifying \"usedforsecurity=False\" on systems otherwise configured to be in FIPS-mode only. And is the primary reason why documentation mentions that certain distributors of python remove md5 module altogether.\r\n\r\n### CPython versions tested on:\r\n\r\n3.10, 3.11, 3.12\r\n\r\n### Operating systems tested on:\r\n\r\nLinux\r\n\r\n\u003c!-- gh-linked-prs --\u003e\r\n### Linked PRs\r\n* gh-118236\r\n* gh-118238\r\n* gh-118239\r\n* gh-118240\r\n* gh-118264\r\n* gh-127300\n\u003c!-- /gh-linked-prs --\u003e\r\n","author":{"url":"https://github.com/xnox","@type":"Person","name":"xnox"},"datePublished":"2024-04-24T12:49:43.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":24},"url":"https://github.com/118224/cpython/issues/118224"}

route-pattern/_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format)
route-controllervoltron_issues_fragments
route-actionissue_layout
fetch-noncev2:167ebb2c-78b3-e3d6-5e48-f03f9b001572
current-catalog-service-hash81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114
request-idBC26:EFB79:29E914:3854D1:6969A9F4
html-safe-nonce026ad6b116e925b3aa8246a5d546a28d4345774918f44d357577c4777e71f2d7
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCQzI2OkVGQjc5OjI5RTkxNDozODU0RDE6Njk2OUE5RjQiLCJ2aXNpdG9yX2lkIjoiNzIwMTUwNzYyNDE2MTQ4NzM0OCIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9
visitor-hmac7494b7d7cab04312e12ac0df52c6d927efde4b39859a35178ccdfbfa5a441640
hovercard-subject-tagissue:2261222634
github-keyboard-shortcutsrepository,issues,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///voltron/issues_fragments/issue_layout
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/python/cpython/118224/issue_layout
twitter:imagehttps://opengraph.githubassets.com/95d92ab9310804f84085f23169ab74fec59c5f7d1695fd61f7a1eb58107a49cb/python/cpython/issues/118224
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/95d92ab9310804f84085f23169ab74fec59c5f7d1695fd61f7a1eb58107a49cb/python/cpython/issues/118224
og:image:altBug report Bug description: When OpenSSL is configured in FIPS mode recommended config is used to only load "base + fips" providers without the default provider CPython is compiled with --with-buil...
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
og:author:usernamexnox
hostnamegithub.com
expected-hostnamegithub.com
None24c4c97a2d520cb286b35e1a4c22d7a4df3c26a2fa28dd7cdf0e65db327b4de7
turbo-cache-controlno-preview
go-importgithub.com/python/cpython git https://github.com/python/cpython.git
octolytics-dimension-user_id1525981
octolytics-dimension-user_loginpython
octolytics-dimension-repository_id81598961
octolytics-dimension-repository_nwopython/cpython
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id81598961
octolytics-dimension-repository_network_root_nwopython/cpython
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release124667f43168afb6c9c03b7c02eb5b1d2e1be3d9
ui-targetfull
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/python/cpython/issues/118224#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fpython%2Fcpython%2Fissues%2F118224
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2Fpython%2Fcpython%2Fissues%2F118224
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fissues_fragments%2Fissue_layout&source=header-repo&source_repo=python%2Fcpython
Reloadhttps://github.com/python/cpython/issues/118224
Reloadhttps://github.com/python/cpython/issues/118224
Reloadhttps://github.com/python/cpython/issues/118224
python https://github.com/python
cpythonhttps://github.com/python/cpython
Please reload this pagehttps://github.com/python/cpython/issues/118224
Notifications https://github.com/login?return_to=%2Fpython%2Fcpython
Fork 33.9k https://github.com/login?return_to=%2Fpython%2Fcpython
Star 71.1k https://github.com/login?return_to=%2Fpython%2Fcpython
Code https://github.com/python/cpython
Issues 5k+ https://github.com/python/cpython/issues
Pull requests 2.1k https://github.com/python/cpython/pulls
Actions https://github.com/python/cpython/actions
Projects 31 https://github.com/python/cpython/projects
Security Uh oh! There was an error while loading. Please reload this page. https://github.com/python/cpython/security
Please reload this pagehttps://github.com/python/cpython/issues/118224
Insights https://github.com/python/cpython/pulse
Code https://github.com/python/cpython
Issues https://github.com/python/cpython/issues
Pull requests https://github.com/python/cpython/pulls
Actions https://github.com/python/cpython/actions
Projects https://github.com/python/cpython/projects
Security https://github.com/python/cpython/security
Insights https://github.com/python/cpython/pulse
New issuehttps://github.com/login?return_to=https://github.com/python/cpython/issues/118224
New issuehttps://github.com/login?return_to=https://github.com/python/cpython/issues/118224
wolfi-dev/os#17570https://github.com/wolfi-dev/os/pull/17570
Fallback md5 is used, when trying hard to only use OpenSSLhttps://github.com/python/cpython/issues/118224#top
wolfi-dev/os#17570https://github.com/wolfi-dev/os/pull/17570
type-bugAn unexpected behavior, bug, or errorhttps://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22type-bug%22
https://github.com/xnox
https://github.com/xnox
xnoxhttps://github.com/xnox
on Apr 24, 2024https://github.com/python/cpython/issues/118224#issue-2261222634
gh-118224: Load default OpenSSL provider for nonsecurity algorithms #118236https://github.com/python/cpython/pull/118236
[3.12] gh-118224: Load default OpenSSL provider for nonsecurity algorithms (GH-118236) #118238https://github.com/python/cpython/pull/118238
[3.11] gh-118224: Load default OpenSSL provider for nonsecurity algorithms (GH-118236) #118239https://github.com/python/cpython/pull/118239
[3.10] gh-118224: Load default OpenSSL provider for nonsecurity algorithms (GH-118236) #118240https://github.com/python/cpython/pull/118240
[3.9] gh-118224: Load default OpenSSL provider for nonsecurity algorithms (GH-118236) #118264https://github.com/python/cpython/pull/118264
gh-118224: When in FIPS mode ensure builtin hashes check for usedforsecurity=False #127300https://github.com/python/cpython/pull/127300
type-bugAn unexpected behavior, bug, or errorhttps://github.com/python/cpython/issues?q=state%3Aopen%20label%3A%22type-bug%22
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.