Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
35 changes: 35 additions & 0 deletions BUILDING.md
Original file line number Diff line number Diff line change
Expand Up @@ -126,6 +126,41 @@ distributed libcrypto. See [docs/SymbolVersioning.md](docs/SymbolVersioning.md)
for detailed information about symbol versioning, version evolution, and CI
integration.

### System Crypto Policies (opt-in)

On Linux distributions that ship the `crypto-policies` framework (for example
Amazon Linux 2023 and Fedora), AWS-LC can be built to seed newly created
`SSL_CTX` objects from the system-wide OpenSSL back-end policy file. This is
disabled by default; enable it with `-DENABLE_CRYPTO_POLICIES=ON`. It is aimed at
distribution packagers who want AWS-LC to honor the operator-selected system TLS
policy without per-application code changes.

When enabled, `SSL_CTX_new` reads
`/etc/crypto-policies/back-ends/opensslcnf.config` after applying AWS-LC's
built-in defaults and applies the `CipherString`, `Ciphersuites`, and
`TLS`/`DTLS` `MinProtocol`/`MaxProtocol` directives. This is best-effort: a
missing or malformed file, or a directive AWS-LC does not support, is ignored,
and consumers may still override any setting afterward. The `@SECLEVEL=N` prefix
in `CipherString` is parsed and dropped because AWS-LC does not implement
OpenSSL security levels.

A `MinProtocol` naming a version AWS-LC does not have is the exception: the floor
rises to the policy's `MaxProtocol`. Ignoring the directive would leave AWS-LC's
built-in floor of TLS 1.0, which is below any floor the policy can ask for, so
the context would offer the versions the policy forbids. A `MinProtocol` older
than TLS 1.0, such as `SSLv3`, keeps the built-in floor, which is already
stricter.

AWS-LC reads the file once per process, as OpenSSL reads `openssl.cnf`, so a
policy change takes effect only in processes started afterward. A read that fails
is retried on the next `SSL_CTX_new`, so a policy file that appears later is
picked up.

`AWSLC_CRYPTO_POLICY_FILE` names the policy file, at build time with
`-DAWSLC_CRYPTO_POLICY_FILE=/path/to/file` and at run time as an environment
variable, which wins. The environment is ignored in set-uid and set-gid
processes.

### Other Build Options

See [CMake's documentation](https://cmake.org/cmake/help/v3.4/manual/cmake-variables.7.html)
Expand Down
28 changes: 28 additions & 0 deletions docs/porting/configuration-differences.md
Original file line number Diff line number Diff line change
Expand Up @@ -34,6 +34,34 @@ The following table contains the differences in libssl configuration options AWS
* **Aside from and `SSL_MODE_AUTO_RETRY` being "ON" by default in OpenSSL, everything is "OFF" by default in OpenSSL.**
* Each “**Context Flag”** has a link that provides more details on the flag’s functionality and our decision behind it (WIP)

### System Crypto Policies Seeding (opt-in)

By default AWS-LC ignores all system configuration files. When built with
`-DENABLE_CRYPTO_POLICIES=ON` (off by default), AWS-LC seeds each newly created
`SSL_CTX` from the system-wide `crypto-policies` OpenSSL back-end file at
`/etc/crypto-policies/back-ends/opensslcnf.config`, which is shipped by Amazon
Linux 2023 and Fedora. Seeding happens inside `SSL_CTX_new`, after the built-in
defaults are applied and before the context is returned, so a consumer that
subsequently calls the relevant setters overrides the seeded values.

The directives applied are `CipherString`, `Ciphersuites`, `TLS.MinProtocol`,
`TLS.MaxProtocol`, `DTLS.MinProtocol`, and `DTLS.MaxProtocol`. Seeding is
best-effort: a missing or malformed file, or a directive AWS-LC does not support,
is ignored rather than fatal. A directive AWS-LC cannot satisfy is skipped and
the built-in default stands.

A `MinProtocol` naming a version AWS-LC does not have is the exception: the floor
rises to the policy's `MaxProtocol`. The built-in floor of TLS 1.0 sits below any
floor a policy can ask for, so skipping the directive would leave the context
offering the versions the policy forbids. A `MinProtocol` older than TLS 1.0, such
as `SSLv3`, keeps the built-in floor.

A context created from one of the legacy
version-locked methods, such as `TLSv1_2_method`, keeps its single pinned version
and takes no protocol bounds from the policy. See
[BUILDING.md](../../BUILDING.md) for the build flag and the
`AWSLC_CRYPTO_POLICY_FILE` override.


<table border=0 cellspacing=0 cellpadding=0
style='border-collapse:collapse'>
Expand Down
8 changes: 8 additions & 0 deletions docs/porting/functionality-differences.md
Original file line number Diff line number Diff line change
Expand Up @@ -15,6 +15,14 @@ libssl is the portion of OpenSSL which supports TLS. AWS-LC does not have suppor

**If you have a valid use case for any missing functionality or if anything is not clarified in our documentation, feel free to [cut an issue](https://github.com/aws/aws-lc/issues/new?assignees=&labels=&projects=&template=general-issue.md&title=) or create a PR to let us know.**

Note on the opt-in `-DENABLE_CRYPTO_POLICIES` build (off by default): when AWS-LC
seeds an `SSL_CTX` from the system `crypto-policies` OpenSSL back-end, the
`@SECLEVEL=N` prefix of the `CipherString` directive is parsed and ignored
because AWS-LC has no security levels. Only the remaining cipher list is applied,
so the key-size and hash constraints implied by a security level are not
enforced. See
[configuration-differences.md](configuration-differences.md) for details.

### libssl No-ops

<table border=0 cellspacing=0 cellpadding=0
Expand Down
Loading
Loading