pgsql: Disable OpenSSL EVP digest padding in pgcrypto

From: Daniel Gustafsson <dgustafsson(at)postgresql(dot)org>
To: pgsql-committers(at)lists(dot)postgresql(dot)org
Subject: pgsql: Disable OpenSSL EVP digest padding in pgcrypto
Date: 2021-08-10 13:23:50
Message-ID: E1mDRjS-0007Ng-Cm@gemulon.postgresql.org
Views: Raw Message | Whole Thread | Download mbox | Resend email
Thread:
Lists: pgsql-committers

Disable OpenSSL EVP digest padding in pgcrypto

The PX layer in pgcrypto is handling digest padding on its own uniformly
for all backend implementations. Starting with OpenSSL 3.0.0, DecryptUpdate
doesn't flush the last block in case padding is enabled so explicitly
disable it as we don't use it.

This will be backpatched to all supported version once there is sufficient
testing in the buildfarm of OpenSSL 3.

Reviewed-by: Peter Eisentraut, Michael Paquier
Discussion: https://postgr.es/m/FEF81714-D479-4512-839B-C769D2605F8A@yesql.se

Branch
------
master

Details
-------
https://git.postgresql.org/pg/commitdiff/318df802355924015d4d8f21859bc0ef7a348970

Modified Files
--------------
contrib/pgcrypto/openssl.c | 4 ++++
1 file changed, 4 insertions(+)

Browse pgsql-committers by date

  From Date Subject
Next Message noreply 2021-08-10 21:41:31 pgsql: Tag refs/tags/REL_13_4 was created
Previous Message Masahiko Sawada 2021-08-10 11:06:45 Re: pgsql: pgstat: Bring up pgstat in BaseInit() to fix uninitialized use o