Repository navigation
Node.Js does not build successfully using --shared-openssl configure flag #35213
Description
Activity
Your copy of openssl is incompatible - probably too old.
Seeing it's missing
EVP_PKEY_CTX_set_rsa_pss_keygen_md(), that probably means it's version 1.0.2 or 1.1.0 but you need 1.1.1.Closing, not a bug.
- addedbuildIssues and PRs related to Node.js builds or CI infrastructure.Issues and PRs related to Node.js builds or CI infrastructure.invalidIssues and PRs that are invalid.Issues and PRs that are invalid.opensslIssues and PRs related to the OpenSSL dependency.Issues and PRs related to the OpenSSL dependency.
on Sep 16, 2020 You need a newer (or more complete) version of OpenSSL 1.1.1. In general it's best to match the version of OpenSSL bundled with whichever version/branch of node you're compiling for. Node v14.x currently ships with OpenSSL 1.1.1g for example.
A quick search reveals that a bugfix for
EVP_PKEY_OP_TYPE_KEYGENbeing undefined was introduced in 1.1.1a andOPENSSL_INIT_set_config_filenamewas introduced in 1.1.1b (check the crypto.h diff).No. Building against shared libraries is effectively not a supported configuration. We allow it because it's something distro vendors want/need but with the understanding that they're on the hook when it breaks, not us.
@mscdex could I ask: how does one know what version of OpenSSL node is bundled with? I'm running into the same issue with Ubuntu 18.04 using the certified OpenSSL libraries (1.1.1) and I'm trying to build node against this library already on my system.
$ dpkg-query --list | grep openssl ii libxmlsec1-openssl:amd64 1.2.25-1build1 amd64 Openssl engine for the XML security library ii openssl 1.1.1-1ubuntu2.fips.2.1~18.04.7.1 amd64 Secure Sockets Layer toolkit - cryptographic utility ii python3-openssl 17.5.0-1ubuntu1 all Python 3 wrapper around the OpenSSL library@D4V3M0NK You should be able to consult https://nodejs.org/dist/index.json or https://nodejs.org/dist/index.tab to get technical information about each release, including the OpenSSL version that is ordinarily bundled with node.
Reacted by Dave Monk
What steps will reproduce the bug?
How often does it reproduce? Is there a required condition?
100%
What is the expected behavior?
Building with --shared-openssl should succeed, yield a node.exe or node.dll (when building with --shared, as in my case) which links against an external openssl dll.
What do you see instead?
The build fails.
Additional information
I have tried this with all of the tags mentioned above, as well as the master branch from github without success.