以下的要求不是强制性的, 未按模板评论时对issue无任何影响
issue处理注意事项:
1. 当前issue受影响的分支提交pr时, 须在pr描述中填写当前issue编号进行关联, 否则无法关闭当前issue;
2. 模板内容需要填写完整, 无论是受影响或者不受影响都需要填写完整内容,未引入的分支不需要填写, 否则无法关闭当前issue;
3. 以下为模板中需要填写完整的内容, 请复制到评论区回复, 注: 内容的标题名称(影响性分析说明, 缺陷严重等级, 受影响版本排查(受影响/不受影响), 修复是否涉及abi变化(是/否))不能省略,省略后defect-manager将无法正常解析填写内容.
评论区可能使用到的指令说明:
| 指令 | 指令说明 | 使用权限 |
|---|---|---|
| /check-issue | 触发defect-manager校验 | 不限 |
| /reason xxx | /reason +挂起或取消条件 | 不限 |
影响性分析说明:
缺陷严重等级:(Critical/High/Moderate/Low)
缺陷根因说明:
受影响版本排查(受影响/不受影响):
- openEuler-20.03-LTS-SP4:
- openEuler-22.03-LTS-SP3:
- openEuler-22.03-LTS-SP4:
- openEuler-24.03-LTS:
- openEuler-24.03-LTS-SP1:
- openEuler-24.03-LTS-SP2:
abi变化(是/否):
- openEuler-20.03-LTS-SP4:
- openEuler-22.03-LTS-SP3:
- openEuler-22.03-LTS-SP4:
- openEuler-24.03-LTS:
- openEuler-24.03-LTS-SP1:
- openEuler-24.03-LTS-SP2:
缺陷issue处理具体操作请参考:
https://atomgit.com/openeuler/cve-manager/blob/master/cve-vulner-manager/doc/md/defect-manager-manual.md
pr关联issue具体操作请参考:
https://docs.atomgit.com/docs/help/home/org_project/pullrequests/pr-related-issue


Welcome To openEuler Community
Hey @ga_beng_cui , thanks for your contribution to the community.
Bot Usage Manual
I'm the Bot here serving you. You can find the instructions on how to interact with me at Here . That means you can comment below every pull request or issue to trigger Bot Commands.
Contact Guide
If you have any questions, please contact the SIG: Application ,
and any of the maintainers: @kaitiandu, @small_leek, @zhuchunyi ,
and any of the committers: @caodongxia, @starlet-dx, @wk333 .


问题现象与原因分析:
- 补丁影响:系统打包使用的
stunnel-5.76-system-ciphers.patch将源码中的默认加密套件修改为了PROFILE=SYSTEM,强制应用使用系统的crypto-policies加密策略。 - FIPS 机制冲突:OpenSSL 3.x 尝试加载系统策略时触发了 FIPS 模块初始化逻辑,由于系统缺乏完整 FIPS 配置且策略组合存在冲突,导致报
missing config data/no cipher match错误,服务初始化 TLS 上下文失败。 - 底层限制:该问题可通过升级
crypto-policies软件包修复策略生成逻辑,但新版crypto-policies依赖python3 >= 3.12,当前环境版本不满足,暂无法直接升级。
解决方案: 在 /etc/stunnel/stunnel.conf 的服务配置中显式添加 ciphers = DEFAULT,覆盖系统全局 PROFILE=SYSTEM 策略,直接使用 OpenSSL 原生默认加密套件,即可正常启动服务。
echo "client=yes
pid=/tmp/stunnel.pid
debug=7
foreground=no
verify=0
[squid]
accept=127.0.0.1:9999
connect=127.0.0.1:8000
ciphers = DEFAULT" >>/etc/stunnel/stunnel.conf



再讨论后先保证用例正常通过,删除补丁 stunnel-5.76-system-ciphers.patch , 后续等 crypto-policies 升级后再应用该补丁测试
https://gitcode.com/src-openeuler/stunnel/pull/21
已向 crypto-policies 提交issue: https://gitcode.com/src-openeuler/crypto-policies/issues/11


@lyn1001 未对受影响版本排查/abi变化进行分析


再讨论后先保证用例正常通过,删除补丁 stunnel-5.76-system-ciphers.patch , 后续等 crypto-policies 升级后再应用该补丁测试
https://gitcode.com/src-openeuler/stunnel/pull/21已向 crypto-policies 提交issue: https://gitcode.com/src-openeuler/crypto-policies/issues/11
openssl支持PROFILE=SYSTEM是redhat/fedora系列自己实现的功能,非上游社区功能,见fedora补丁:https://src.fedoraproject.org/rpms/openssl/blob/rawhide/f/0005-RH-Add-support-for-PROFILE-SYSTEM-system-default-cip.patch openEuler :openssl包并未引入此补丁。另外openEuler:openssl包默认并不使用crypto-policies提供的安全策略配置,此失败与crypto-policies无关。


再讨论后先保证用例正常通过,删除补丁 stunnel-5.76-system-ciphers.patch , 后续等 crypto-policies 升级后再应用该补丁测试
https://gitcode.com/src-openeuler/stunnel/pull/21已向 crypto-policies 提交issue: https://gitcode.com/src-openeuler/crypto-policies/issues/11
openssl支持PROFILE=SYSTEM是redhat/fedora系列自己实现的功能,非上游社区功能,见fedora补丁:https://src.fedoraproject.org/rpms/openssl/blob/rawhide/f/0005-RH-Add-support-for-PROFILE-SYSTEM-system-default-cip.patch openEuler :openssl包并未引入此补丁。另外openEuler:openssl包默认并不使用crypto-policies提供的安全策略配置,此失败与crypto-policies无关。
感谢回答,看来删除这个补丁是正确的


使用最新版本已验证,无此问题



@lyn1001 未对受影响版本排查/abi变化进行分析


【缺陷描述】:请补充详细的缺陷问题现象描述
stunnel服务启动失败,报错SSL_CTX_set_cipher_list: SELF_TEST_post@providers/fips/self_test.c:361: error:1C8000D5:P
rovider routines::missing config data
一、缺陷信息
stunnel-5.76-1.oe2609
【缺陷所属的os版本】
openEuler-26.09
【内核版本】
6.6.0-163.0.0.1.oe2609
【缺陷所属软件及版本号】
stunnel-5.76-1.oe2609
【环境信息】
软件信息
stunnel-5.76-1.oe2609
【问题复现步骤】
【实际结果】
服务启动失败,日志报错
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [!] SSL_CTX_set_cipher_list: SELF_TEST_post@providers/fips/self_test.c:361: error:1C8000D5:P
rovider routines::missing config data
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [!] Service [squid]: Failed to initialize TLS context
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [!] Configuration failed
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [ ] Deallocating temporary section defaults
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [ ] Cleaning up context [stunnel]
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [ ] Deallocating section [squid]
8月 18 10:12:00 localhost.localdomain stunnel[1684]: [ ] Cleaning up context [squid]
8月 18 10:12:00 localhost.localdomain systemd[1]: stunnel.service: Control process exited, code=exited, status=1/FAILURE
8月 18 10:12:00 localhost.localdomain systemd[1]: stunnel.service: Failed with result 'exit-code'.
8月 18 10:12:00 localhost.localdomain systemd[1]: Failed to start TLS tunnel f
【期望结果】
服务启动成功,且日志无报错
【其他相关附件信息】
【缺陷详情及分析指导参考链接】
二、缺陷分析结构反馈
影响性分析说明:
缺陷严重等级:(Critical/High/Moderate/Low)
缺陷根因说明:
受影响版本排查(受影响/不受影响):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2
修复是否涉及abi变化(是/否):
openEuler-20.03-LTS-SP4
openEuler-22.03-LTS-SP3
openEuler-22.03-LTS-SP4
openEuler-24.03-LTS
openEuler-24.03-LTS-SP1
openEuler-24.03-LTS-SP2