LibreSSL explained
LibreSSL |
Logo Caption: | Puffy, the mascot of OpenBSD, made to resemble Che Guevara |
Author: | The OpenSSL Project |
Developer: | The OpenBSD Project |
Released: | 2.0.0 / |
Programming Language: | C, assembly, Perl |
Operating System: | OpenBSD, FreeBSD, NetBSD, Linux, HP-UX, Solaris, macOS, Windows and others[1] |
Genre: | Cryptography library |
License: | Apache-1.0, BSD-4-Clause, ISC, public domain |
LibreSSL is an open-source implementation of the Transport Layer Security (TLS) protocol. The implementation is named after Secure Sockets Layer (SSL), the deprecated predecessor of TLS, for which support was removed in release 2.3.0. The OpenBSD project forked LibreSSL from OpenSSL 1.0.1g in April 2014 as a response to the Heartbleed security vulnerability,[2] [3] [4] [5] with the goals of modernizing the codebase, improving security, and applying development best practices.[6] [7] [8]
History
After the Heartbleed security vulnerability was discovered in OpenSSL, the OpenBSD team audited the codebase and decided it was necessary to fork OpenSSL to remove dangerous code.[2] The libressl.org domain was registered on 11 April 2014; the project announced the name on 22 April 2014. In the first week of development, more than 90,000 lines of C code were removed.[9] Unused code was removed, and support for obsolete operating systems (Classic Mac OS, NetWare, OS/2, 16-bit Windows) and some older operating systems (OpenVMS) was removed.[10]
LibreSSL was initially developed as an intended replacement for OpenSSL in OpenBSD 5.6, and was ported to other platforms once a stripped-down version of the library was stable.[11], the project was seeking a "stable commitment" of external funding.[9] On 17 May 2014, Bob Beck presented "LibreSSL: The First 30 Days, and What The Future Holds" during the 2014 BSDCan conference, in which he described the progress made in the first month.[12] On 5 June 2014, several OpenSSL bugs became public. While several projects were notified in advance,[13] LibreSSL was not; Theo de Raadt accused the OpenSSL developers of intentionally withholding this information from OpenBSD and LibreSSL.[14]
On 20 June 2014, Google created another fork of OpenSSL called BoringSSL, and promised to exchange fixes with LibreSSL.[15] [16] Google has already relicensed some of its contributions under the ISC license, as it was requested by the LibreSSL developers.[15] [17] On 21 June 2014, Theo de Raadt welcomed BoringSSL and outlined the plans for LibreSSL-portable.[18] Starting on 8 July, code porting for macOS and Solaris began,[19] while the initial porting to Linux began on 20 June.[20]
As of 2021, OpenBSD uses LibreSSL as the primary SSL library. Alpine Linux supported LibreSSL as its primary TLS library for three years, until release 3.9.0 in January 2019. Gentoo supported LibreSSL until February 2021.[21] Python 3.10 dropped LibreSSL[22] after being supported since Python 3.4.3 (2015).[23]
Adoption
LibreSSL is the default provider of TLS for:
LibreSSL is the default provider of TLS for these now-discontinued systems:
LibreSSL is a selectable provider of TLS for:
Changes
Memory-related
Changes include replacement of custom memory calls to ones in a standard library (for example, [[strlcpy]]
, [[calloc]]
, [[asprintf]]
, [[reallocarray]]
, etc.).[36] [37] This process may help later on to catch buffer overflow errors with more advanced memory analysis tools or by observing program crashes (via ASLR, use of the NX bit, stack canaries, etc.).
Fixes for potential double free scenarios have also been cited in the VCS commit logs (including explicit assignments of null pointer values).[38] There have been extra sanity checks also cited in the commit logs related to ensuring length arguments, unsigned-to-signed variable assignments, pointer values, and method returns.
Proactive measures
In order to maintain good programming practice, a number of compiler options and flags designed for safety have been enabled by default to help in spotting potential issues so they can be fixed earlier (-Wall, -Werror, -Wextra, -Wuninitialized). There have also been code readability updates which help future contributors in verifying program correctness (KNF, white-space, line-wrapping, etc.). Modification or removal of unneeded method wrappers and macros also help with code readability and auditing (Error and I/O abstraction library references).
Changes were made to ensure that LibreSSL will be year 2038 compatible along with maintaining portability for other similar platforms. In addition, explicit_bzero
and bn_clear
calls were added to prevent the compiler from optimizing them out and prevent attackers from reading previously allocated memory.
Cryptographic
There were changes to help ensure proper seeding of random number generator-based methods via replacements of insecure seeding practices (taking advantage of features offered by the kernel itself natively).[39] [40] In terms of notable additions made, OpenBSD has added support for newer and more reputable algorithms (ChaCha stream cipher and Poly1305 message authentication code) along with a safer set of elliptic curves (brainpool curves from RFC 5639, up to 512 bits in strength).
Added features
The initial release of LibreSSL added a number of features: the ChaCha and Poly1305 algorithm, the Brainpool and ANSSI elliptic curves, and the AES-GCM and ChaCha20-Poly1305 AEAD modes.
Later versions added the following:
- 2.1.0: Automatic ephemeral EC keys.[41]
- 2.1.2: Built-in arc4random implementation on macOS and FreeBSD.[42]
- 2.1.2: Reworked GOST cipher suite support.
- 2.1.3: ALPN support.[43]
- 2.1.3: Support for SHA-256 and Camellia cipher suites.
- 2.1.4: TLS_FALLBACK_SCSV server-side support.[44]
- 2.1.4: certhash as a replacement of the c_rehash script.
- 2.1.4: X509_STORE_load_mem API for loading certificates from memory (enhance chroot support).
- 2.1.4: Experimental Windows binaries.
- 2.1.5: Minor update mainly for improving Windows support, first working 32- and 64-bit binaries.[45]
- 2.1.6: declared stable and enabled by default.[46]
- 2.2.0: AIX and Cygwin support.[47]
- 2.2.1: Addition of EC_curve_nid2nist and EC_curve_nist2nid[48] from OpenSSL, initial Windows XP/2003 support.
- 2.2.2: Defines LIBRESSL_VERSION_NUMBER,[49] added TLS_*methods as a replacement for the SSLv23_*method calls, cmake build support.
Old insecure features
The initial release of LibreSSL disabled a number of features by default. Some of the code for these features was later removed, including Kerberos, US-Export ciphers, TLS compression, DTLS heartbeat, SSL v2 and SSL v3.
Later versions disabled more features:
- 2.1.1: Following the discovery of the POODLE vulnerability in the legacy SSL 3.0 protocol, LibreSSL now disables the use of SSL 3.0 by default.[50]
- 2.1.3: GOST R 34.10-94 signature authentication.[51]
- 2.2.1: Removal of Dynamic Engine and MDC-2DES support
- 2.2.2: Removal of SSL 3.0 from the openssl binary, removal of Internet Explorer 6 workarounds, RSAX engine.
- 2.3.0: Complete removal of SSL 3.0, SHA-0 and DTLS1_BAD_VER.
Code removal
The initial release of LibreSSL has removed a number of features that were deemed insecure, unnecessary or deprecated as part of OpenBSD 5.6.
- In response to Heartbleed, the heartbeat functionality[52] was one of the first features to be removed.
- Support for obsolete platforms (Classic Mac OS, NetWare, OS/2, 16-bit Windows) were removed.
- Support for some older platforms (OpenVMS) was removed.
- Support for platforms that do not exist, such as big-endian i386 and amd64.[53]
- Support for old compilers.
- The IBM 4758, Broadcom ubsec, Sureware, Nuron, GOST, GMP, CSwift, CHIL, CAPI, Atalla and AEP engines were removed due to irrelevance of hardware or dependency on non-free libraries.
- The OpenSSL PRNG was removed (and replaced with ChaCha20-based implementation of arc4random).
- Preprocessor macros that have been deemed unnecessary or insecure or had already been deprecated in OpenSSL for a long time (e.g. des_old.h).
- Older unneeded files for assembly language, C, and Perl (e.g. EGD).
- MD2, SEED functionality.
- SSL 3.0, SHA-0, DTLS1_BAD_VER
The Dual EC DRBG algorithm, which is suspected of having a back door,[54] was cut along with support for the FIPS 140-2 standard that required it. Unused protocols and insecure algorithms have also been removed, including the support for FIPS 140-2,[55] MD4/MD5 J-PAKE, and SRP.[56]
Bug backlog
One of the complaints of OpenSSL was the number of open bugs reported in the bug tracker that had gone unfixed for years. Older bugs are now being fixed in LibreSSL.[57]
See also
External links
Notes and References
- Web site: LibreSSL Releases.
- Web site: Origins of libressl . Ted . Unangst . flak . 22 April 2014 . 24 April 2014.
- Web site: After Heartbleed, OpenSSL Is Forked Into LibreSSL. Sean Michael . Kerner . . 22 April 2014 . 24 April 2014.
- Web site: Not Just a Cleanup Any More: LibreSSL Project Announced. Slashdot. 24 April 2014. 22 April 2014.
- Web site: 30-Day Status Update On LibreSSL . M . Constantine . Soulskill . 17 May 2014 . .
- Web site: LibreSSL.
- Web site: OpenBSD forks, prunes, fixes OpenSSL . Larry . Seltzer . Zero Day . . 21 April 2014 . 21 April 2014.
- Web site: OpenBSD has started a massive strip-down and cleanup of OpenSSL . Peter . Hessler . . 15 April 2014 . 24 April 2014.
- Web site: OpenSSL code beyond repair, claims creator of "LibreSSL" fork . Jon . Brodkin . . 22 April 2014 . 24 April 2014.
- OpenBSD 5.6 Released . 1 November 2014 . 28 October 2015 . openbsd-announce . Jacoutot . Antoine .
- Web site: Heartbleed: LibreSSL scrubs "irresponsible" OpenSSL code . Jane . McCallion . . 22 April 2014 . 23 April 2014 . https://web.archive.org/web/20140626092314/http://www.pcpro.co.uk/news/security/388309/heartbleed-libressl-scrubs-irresponsible-openssl-code . 26 June 2014 . dead .
- Web site: Bob. Beck. LibreSSL: The first 30 days, and what the Future Holds Slides. 17 May 2014. 17 May 2014.
- Re: OpenSSL seven security fixes . 5 June 2014 . 9 June 2014 . oss-sec.
- Re: new OpenSSL flaws . 5 June 2014 . 9 June 2014 . openbsd-misc . de Raadt . Theo . Theo de Raadt .
- Web site: BoringSSL (20 Jun 2014). Langley. Adam. 20 June 2014. Imperialviolet.org. 21 June 2014.
- Web site: Google unveils independent "fork" of OpenSSL called "BoringSSL". Goodin. Dan. 20 June 2014. 21 June 2014. Ars Technica.
- Web site: OpenBSD — lib/libssl/src/crypto/evp evp_aead.c e_chacha20poly1305.c. Sing. Joel. 21 June 2014. 21 June 2014. https://archive.today/20140622060845/https://secure.freshbsd.org/commit/openbsd/ef62f9c8a51b8fb8ce21e1486986f8f3dc7f50a3. 22 June 2014. dead.
- Boringssl and such . 21 June 2014 . 28 October 2015 . openbsd-tech . de Raadt. Theo . Theo de Raadt.
- Web site: OpenBSD - lib/libcrypto/crypto getentropy_osx.c getentropy_solaris.c. 8 July 2014. Beck. Bob. 8 July 2014. https://web.archive.org/web/20140722094048/https://secure.freshbsd.org/commit/openbsd/bb95c69c5dea2b7ae53fb1036904c27c038bd2b0. 22 July 2014. dead.
- Web site: OpenBSD — lib/libcrypto/crypto getentropy_linux.c. https://archive.today/20140709185108/https://secure.freshbsd.org/commit/openbsd/1d7eab2186ba0e70b976372401977c2c784ef30a. dead. 9 July 2014. 20 June 2014. Beck. Bob.
- Web site: LibreSSL languishes on Linux [LWN.net]]. 2021-01-06. lwn.net.
- Web site: PEP 644 -- Require OpenSSL 1.1.1 or newer.
- Web site: Changelog — Python 3.4.10 documentation.
- Web site: [Beta] Switch base to use private LibreSSL libraries ]. John . Marino. 9 November 2018.
- Web site: Milky Way v0.3 release . 23 September 2019 . Hyperbola Project . 23 September 2019.
- Web site: OpenELEC Mediacenter - [Beta] OpenELEC 6.0 Beta 2 released]. Stephan. Raue. Openelec.tv. 20 August 2015. https://web.archive.org/web/20151126061521/http://openelec.tv/news/22-releases/165-beta-openelec-6-0-beta-2-released. 26 November 2015. dead.
- Web site: PC-BSD Evolves into TrueOS . 16 September 2016 . https://web.archive.org/web/20160916041238/https://www.trueos.org/2016/09/01/pc-bsd-evolves-into-trueos/ . 16 September 2016 . dead .
- Web site: PC-BSD 10.1.2: an Interview with Kris Moore . Mark . VonFange . Official PC-BSD Blog . 15 October 2015.
- Web site: Add DEFAULT_VERSIONS=ssl=XXX. Svnweb.freebsd.org.
- Web site: Project:LibreSSL - Gentoo. Wiki.gentoo.org.
- Web site: LibreSSL support discontinued. Michał. Górny. 2021-01-05. 2021-03-30. www.gentoo.org.
- Web site: Bug 762847 - dev-libs/libressl: Removal. Michał. Górny. 2020-12-31. 2021-03-30. bugs.gentoo.org.
- Web site: [gentoo-dev] [RFC] Discontinuing LibreSSL support?]. Michał. Górny. 28 Dec 2020. 2021-03-30. archives.gentoo.org.
- Web site: OPNsense version 15.7 Released . OPNsense . 15 October 2015.
- Web site: OPNsense version 22.7 Released . OPNsense . 2022-08-05.
- Web site: A quick recap over the last week. OpenSSL Valhalla Rampage. 23 April 2014. 30 April 2014. Orr. William.
- Web site: OpenBSD LibreSSL CVS Calloc Commits. Secure.freshbsd.org.
- Web site: OpenBSD LibreSSL CVS Double Free Commits. Secure.freshbsd.org.
- Web site: OpenBSD LibreSSL CVS insecure seeding. Secure.freshbsd.org.
- Web site: OpenBSD LibreSSL CVS Kernel Seeding. https://archive.today/20140916151049/https://secure.freshbsd.org/commit/openbsd/58777eed1cff7c5b34cbc026278f730176a6dbc2. dead. 2014-09-16. Secure.freshbsd.org.
- LibreSSL 2.1.0 released . 12 October 2014 . 28 October 2015 . openbsd-announce . Beck . Bob .
- LibreSSL 2.1.2 released . 9 December 2014 . 28 October 2015 . openbsd-announce . Beck . Bob .
- LibreSSL 2.1.3 released . 22 January 2015 . 28 October 2015 . openbsd-announce . Cook . Brent .
- LibreSSL 2.1.4 released . 4 March 2015 . 28 October 2015 . openbsd-announce . Cook . Brent .
- LibreSSL 2.1.5 released . 17 March 2015 . 28 October 2015 . openbsd-announce . Cook . Brent .
- LibreSSL 2.1.6 released . 19 March 2015 . 28 October 2015 . openbsd-announce . Cook . Brent .
- LibreSSL 2.1.7 and 2.2.0 released . 11 June 2015 . 28 October 2015 . openbsd-announce . Cook . Brent .
- LibreSSL 2.2.1 released . 9 July 2015 . 28 October 2015 . openbsd-announce . Cook . Brent .
- LibreSSL 2.2.2 released . 6 August 2015 . 28 October 2015 . openbsd-announce . Cook . Brent .
- Bob. Beck. LibreSSL 2.1.1 released. 16 October 2014. openbsd-tech.
- Web site: LibreSSL-portable ChangeLog . 15 October 2021 . LibreSSL.
- Web site: OpenBSD LibreSSL CVS OPENSSL_NO_HEARTBEATS.
- Remove support for big-endian i386 and amd64. Miod Vallat. openbsd-cvs.
- News: Nicole . Perlroth . Government Announces Steps to Restore Confidence on Encryption Standards. 9 May 2014. The New York Times. 10 September 2013.
- Web site: The future (or lack thereof) of LibreSSL's FIPS Object Module.
- LibreSSL 2.0.4 released . 3 August 2014 . 28 October 2015 . openbsd-announce . Beck . Bob .
- Re: CVS: cvs.openbsd.org: src . 10 November 2014 . 28 October 2015 . openbsd-cvs . Vallat . Miod .