Sitelet https://github.com/nodejs/node/issues/35213
Skip to content

Node.Js does not build successfully using --shared-openssl configure flag #35213

Description

  • Version: v14.5.0, v14.10.1, git master branch
  • Platform: Linux
  • Subsystem: Build

What steps will reproduce the bug?

python2.7 ./configure.py --debug --debug-node --shared-openssl --shared
make

How often does it reproduce? Is there a required condition?

100%

What is the expected behavior?

Building with --shared-openssl should succeed, yield a node.exe or node.dll (when building with --shared, as in my case) which links against an external openssl dll.

What do you see instead?

The build fails.

Additional information

I have tried this with all of the tags mentioned above, as well as the master branch from github without success.

Activity

  1. bnoordhuis commented on Sep 16, 2020

    @bnoordhuis
    Member

    Your copy of openssl is incompatible - probably too old.

    Seeing it's missing EVP_PKEY_CTX_set_rsa_pss_keygen_md(), that probably means it's version 1.0.2 or 1.1.0 but you need 1.1.1.

    Closing, not a bug.

  2. added
    buildIssues and PRs related to Node.js builds or CI infrastructure.
    invalidIssues and PRs that are invalid.
    opensslIssues and PRs related to the OpenSSL dependency.
    on Sep 16, 2020
  3. mscdex commented on Sep 16, 2020

    @mscdex
    Contributor

    You need a newer (or more complete) version of OpenSSL 1.1.1. In general it's best to match the version of OpenSSL bundled with whichever version/branch of node you're compiling for. Node v14.x currently ships with OpenSSL 1.1.1g for example.

    A quick search reveals that a bugfix for EVP_PKEY_OP_TYPE_KEYGEN being undefined was introduced in 1.1.1a and OPENSSL_INIT_set_config_filename was introduced in 1.1.1b (check the crypto.h diff).

  4. bnoordhuis commented on Sep 20, 2020

    @bnoordhuis
    Member

    No. Building against shared libraries is effectively not a supported configuration. We allow it because it's something distro vendors want/need but with the understanding that they're on the hook when it breaks, not us.

  5. D4V3M0NK commented on Feb 17, 2021

    @D4V3M0NK

    @mscdex could I ask: how does one know what version of OpenSSL node is bundled with? I'm running into the same issue with Ubuntu 18.04 using the certified OpenSSL libraries (1.1.1) and I'm trying to build node against this library already on my system.

    $ dpkg-query --list | grep openssl
    ii  libxmlsec1-openssl:amd64               1.2.25-1build1                                  amd64        Openssl engine for the XML security library
    ii  openssl                                1.1.1-1ubuntu2.fips.2.1~18.04.7.1               amd64        Secure Sockets Layer toolkit - cryptographic utility
    ii  python3-openssl                        17.5.0-1ubuntu1                                 all          Python 3 wrapper around the OpenSSL library
    
  6. mscdex commented on Feb 18, 2021

    @mscdex
    Contributor

    @D4V3M0NK You should be able to consult https://nodejs.org/dist/index.json or https://nodejs.org/dist/index.tab to get technical information about each release, including the OpenSSL version that is ordinarily bundled with node.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    buildIssues and PRs related to Node.js builds or CI infrastructure.invalidIssues and PRs that are invalid.opensslIssues and PRs related to the OpenSSL dependency.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions