已关闭
【26.09】stunnel服务启动失败,报错missing config data #10
ga_beng_cui创建于  8月18日关闭于  8月18日
ga_beng_cui
ga_beng_cui成员
8月18日 创建

【缺陷描述】:请补充详细的缺陷问题现象描述

stunnel服务启动失败,报错SSL_CTX_set_cipher_list: SELF_TEST_post@providers/fips/self_test.c:361: error:1C8000D5:P
rovider routines::missing config data

一、缺陷信息

stunnel-5.76-1.oe2609

【缺陷所属的os版本】

openEuler-26.09

【内核版本】

6.6.0-163.0.0.1.oe2609

【缺陷所属软件及版本号】

stunnel-5.76-1.oe2609

【环境信息】

软件信息

stunnel-5.76-1.oe2609

【问题复现步骤】

1. dnf install stunnel
2.  echo "client=yes
pid=/tmp/stunnel.pid
debug=7
foreground=no
verify=0
[squid]
accept=127.0.0.1:9999
connect=127.0.0.1:8000" >>/etc/stunnel/stunnel.conf
3. systemctl start stunnel

【实际结果】

服务启动失败,日志报错
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [!] SSL_CTX_set_cipher_list: SELF_TEST_post@providers/fips/self_test.c:361: error:1C8000D5:P
rovider routines::missing config data
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [!] Service [squid]: Failed to initialize TLS context
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [!] Configuration failed
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [ ] Deallocating temporary section defaults
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [ ] Cleaning up context [stunnel]
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [ ] Deallocating section [squid]
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [ ] Cleaning up context [squid]
8月 18 10:12:00 localhost.localdomain systemd[1]: stunnel.service: Control process exited, code=exited, status=1/FAILURE
8月 18 10:12:00 localhost.localdomain systemd[1]: stunnel.service: Failed with result 'exit-code'.
8月 18 10:12:00 localhost.localdomain systemd[1]: Failed to start TLS tunnel f

【期望结果】

服务启动成功,且日志无报错

【其他相关附件信息】

image.png
image.png

【缺陷详情及分析指导参考链接】

二、缺陷分析结构反馈
影响性分析说明:

缺陷严重等级:(Critical/High/Moderate/Low)

缺陷根因说明:

受影响版本排查(受影响/不受影响):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2

修复是否涉及abi变化(是/否):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2

likedislike
ga_beng_cuiga_beng_cui成员
8月18日 关联了里程碑:openEuler-26.09-DevStation-alpha
openeuler-ci-botopeneuler-ci-bot成员
8月18日 修改了issue 的描述
openeuler-ci-bot
openeuler-ci-bot成员
8月18日 评论:

以下的要求不是强制性的, 未按模板评论时对issue无任何影响
issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, 缺陷严重等级, 受影响版本排查(受影响/不受影响), 修复是否涉及abi变化(是/否))不能省略,省略后defect-manager将无法正常解析填写内容.
评论区可能使用到的指令说明:

指令 指令说明 使用权限
/check-issue 触发defect-manager校验 不限
/reason xxx /reason +挂起或取消条件 不限

影响性分析说明:

缺陷严重等级:(Critical/High/Moderate/Low)

缺陷根因说明:

受影响版本排查(受影响/不受影响):

  1. openEuler-20.03-LTS-SP4:
  2. openEuler-22.03-LTS-SP3:
  3. openEuler-22.03-LTS-SP4:
  4. openEuler-24.03-LTS:
  5. openEuler-24.03-LTS-SP1:
  6. openEuler-24.03-LTS-SP2:

abi变化(是/否):

  1. openEuler-20.03-LTS-SP4:
  2. openEuler-22.03-LTS-SP3:
  3. openEuler-22.03-LTS-SP4:
  4. openEuler-24.03-LTS:
  5. openEuler-24.03-LTS-SP1:
  6. openEuler-24.03-LTS-SP2:

缺陷issue处理具体操作请参考:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/defect-manager-manual.md
pr关联issue具体操作请参考:
https://docs.atomgit.com/docs/help/home/org_project/pullrequests/pr-related-issue

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月18日 添加了label:sig/Application
openeuler-ci-bot
openeuler-ci-bot成员
8月18日 评论:

Welcome To openEuler Community

Hey @ga_beng_cui , thanks for your contribution to the community.

Bot Usage Manual

I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands.

Contact Guide

If you have any questions, please contact the SIG: Application ,
and any of the maintainers: @kaitiandu, @small_leek, @zhuchunyi ,
and any of the committers: @caodongxia, @starlet-dx, @wk333 .

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月18日 添加了label:DEFECT/UNFIXED
wk333成员
8月18日 评论:

问题现象与原因分析:

  1. 补丁影响:系统打包使用的 stunnel-5.76-system-ciphers.patch 将源码中的默认加密套件修改为了 PROFILE=SYSTEM,强制应用使用系统的 crypto-policies 加密策略。
  2. FIPS 机制冲突:OpenSSL 3.x 尝试加载系统策略时触发了 FIPS 模块初始化逻辑,由于系统缺乏完整 FIPS 配置且策略组合存在冲突,导致报 missing config data / no cipher match 错误,服务初始化 TLS 上下文失败。
  3. 底层限制:该问题可通过升级 crypto-policies 软件包修复策略生成逻辑,但新版 crypto-policies 依赖 python3 >= 3.12,当前环境版本不满足,暂无法直接升级。

解决方案: 在 /etc/stunnel/stunnel.conf 的服务配置中显式添加 ciphers = DEFAULT,覆盖系统全局 PROFILE=SYSTEM 策略,直接使用 OpenSSL 原生默认加密套件,即可正常启动服务。

echo "client=yes
pid=/tmp/stunnel.pid
debug=7
foreground=no
verify=0
[squid]
accept=127.0.0.1:9999
connect=127.0.0.1:8000
ciphers = DEFAULT" >>/etc/stunnel/stunnel.conf

image.png

likedislike
wk333成员
8月18日 评论:

再讨论后先保证用例正常通过,删除补丁 stunnel-5.76-system-ciphers.patch , 后续等 crypto-policies 升级后再应用该补丁测试
https://gitcode.com/src-openeuler/stunnel/pull/21

已向 crypto-policies 提交issue: https://gitcode.com/src-openeuler/crypto-policies/issues/11

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月18日 关闭了 issue
openeuler-ci-botopeneuler-ci-bot成员
8月18日 issue状态由 待办的 改变为 已完成
openeuler-ci-botopeneuler-ci-bot成员
8月18日 删除了label:DEFECT/UNFIXED
openeuler-ci-bot
openeuler-ci-bot成员
8月18日 评论:

@lyn1001 未对受影响版本排查/abi变化进行分析

likedislike
openeuler-ci-botopeneuler-ci-bot成员
8月18日 关联了pull request:[sync] PR-21: Remove stunnel-5.76-system-ciphers.patch
yixiangzhike
8月19日 评论:

再讨论后先保证用例正常通过,删除补丁 stunnel-5.76-system-ciphers.patch , 后续等 crypto-policies 升级后再应用该补丁测试
https://gitcode.com/src-openeuler/stunnel/pull/21

已向 crypto-policies 提交issue: https://gitcode.com/src-openeuler/crypto-policies/issues/11

@wk333

openssl支持PROFILE=SYSTEM是redhat/fedora系列自己实现的功能,非上游社区功能,见fedora补丁:https://src.fedoraproject.org/rpms/openssl/blob/rawhide/f/0005-RH-Add-support-for-PROFILE-SYSTEM-system-default-cip.patch openEuler :openssl包并未引入此补丁。另外openEuler:openssl包默认并不使用crypto-policies提供的安全策略配置,此失败与crypto-policies无关。

likedislike
wk333成员
8月19日 评论:

再讨论后先保证用例正常通过,删除补丁 stunnel-5.76-system-ciphers.patch , 后续等 crypto-policies 升级后再应用该补丁测试
https://gitcode.com/src-openeuler/stunnel/pull/21

已向 crypto-policies 提交issue: https://gitcode.com/src-openeuler/crypto-policies/issues/11

openssl支持PROFILE=SYSTEM是redhat/fedora系列自己实现的功能,非上游社区功能,见fedora补丁:https://src.fedoraproject.org/rpms/openssl/blob/rawhide/f/0005-RH-Add-support-for-PROFILE-SYSTEM-system-default-cip.patch openEuler :openssl包并未引入此补丁。另外openEuler:openssl包默认并不使用crypto-policies提供的安全策略配置,此失败与crypto-policies无关。

感谢回答,看来删除这个补丁是正确的

likedislike
ga_beng_cui
ga_beng_cui成员
8月27日 评论:

使用最新版本已验证,无此问题
image.png

likedislike
ga_beng_cuiga_beng_cui成员
8月27日 issue状态由 已完成 改变为 已验收
openeuler-ci-bot
openeuler-ci-bot成员
8月27日 评论:

@lyn1001 未对受影响版本排查/abi变化进行分析

likedislike