error: dereferencing pointer to incomplete type DH {aka struct dh_st}

classic Classic list List threaded Threaded
3 messages Options
Reply | Threaded
Open this post in threaded view
|

error: dereferencing pointer to incomplete type DH {aka struct dh_st}

Mark Richter
I've tried looking this up on the web, but there is no cleare guidance on how to get around this.


I'm attempting to build our RHEL 7 based product on RHEL 8 and running into a lot of changes from openssl 1.0.2k-fips (RHEL 7) to 1.1.1 FIPS (RHEL 8).  I haven't found a good guide to adapting the sources to these changes.


Where can I find one?


Thanks.

Mark Richter | Senior Staff Engineer
SolarFlare Communications, Inc. | www.Solarflare.com<http://www.solarflare.com/>
9444 Waples Street, #170, San Diego, CA  92121
Mobile: +1 949-632-8403
[Description: Description: cid:EC628FDE-ACA6-4F34-A8AE-E1F672D4E395]
The information contained in this message is confidential and is intended for the addressee(s) only. If you have received this message in error, please notify the sender immediately and delete the message. Unless you are an addressee (or authorized to receive for an addressee), you may not use, copy or disclose to anyone this message or any information contained in this message. The unauthorized use, disclosure, copying or alteration of this message is strictly prohibited.
Reply | Threaded
Open this post in threaded view
|

Re: error: dereferencing pointer to incomplete type DH {aka struct dh_st}

OpenSSL - User mailing list
>    I'm attempting to build our RHEL 7 based product on RHEL 8 and running into a lot of changes from openssl 1.0.2k-fips (RHEL 7) to 1.1.1 FIPS (RHEL 8).  I haven't found a good guide to adapting the sources to these changes.

Web search for "openssl opaque accessors" turns up many hits; these two seem useful:
 
        https://wiki.openssl.org/index.php/OpenSSL_1.1.0_Changes
        http://vega.pgw.jp/~kabe/vsd/migrate2openssl-1.1.html 
 
PS: A long confidential email disclaimer is silly, particularly when posting to a large public mailing list. :)

Reply | Threaded
Open this post in threaded view
|

Re: error: dereferencing pointer to incomplete type DH {aka struct dh_st}

Viktor Dukhovni
In reply to this post by Mark Richter
On Fri, Jun 28, 2019 at 09:22:48PM +0000, Mark Richter wrote:

> I've tried looking this up on the web, but there is no clear guidance on how to get around this.

The documentation is a good place to start.

    https://www.openssl.org/docs/man1.1.1/man3/DH_set0_pqg.html

If that's not it, look for other manpages that mention DH:

    https://www.openssl.org/docs/man1.1.1/man3/

In Postfix I have some macros that simulate 1.1.x interfaces for
OpenSSL 1.0.2:

    https://github.com/vdukhovni/postfix/blob/master/postfix/src/tls/tls.h#L87-L117

these are by no means a complete list, but my advice is to do
something similar, that is, switch to the 1.1.x APIs and define
forward-compatibility macros for 1.0.2.

--
        Viktor.