Remove deprecated OpenSSL RSA APIs - #126034

Merged
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations
Apr 13, 2026
Merged

Remove deprecated OpenSSL RSA APIs#126034
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Remove deprecated OpenSSL RSA APIs. The RSA type and RSA_* methods have been deprecated in favor of EVP_PKEY. Most of our code already has moved, but this cleans up the function loading and updates the remaining places. The build allows deprecated APIs, but for local testing I've been using -DOPENSSL_API_COMPAT=0x30500000L -DOPENSSL_NO_DEPRECATED to error on deprecated APIs.

@PranavSenthilnathanPranavSenthilnathan added this to the 11.0.0 milestone Mar 24, 2026
CopilotAI review requested due to automatic review settings March 24, 2026 15:59
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR continues the migration away from deprecated OpenSSL RSA* APIs toward EVP-based APIs (primarily EVP_PKEY), updating certificate generation and key-validation paths, and adjusting shim/configure logic to better tolerate RSA legacy symbol availability.

Changes:

  • Update self-signed certificate generation to use/generated EVP_PKEY* directly (removing EVP_PKEY_get1_RSA / EVP_PKEY_set1_RSA usage in that flow).
  • Add an EVP-based RSA “quick check” (EVP_PKEY_get_bn_param) for OpenSSL 3+ to avoid relying on legacy RSA object access.
  • Add HAVE_OPENSSL_RSA_PRIMITIVE configure/shim support and relax several RSA-related shim bindings to “lightup” (runtime-detected) functions.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
src/native/libs/System.Security.Cryptography.Native/pal_ssl.cSwitch self-signed cert helper to return the generated EVP_PKEY* instead of extracting/setting a legacy RSA*.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.cFactor legacy private-key-availability check into a helper and gate it on EVP_PKEY_get0_RSA lightup availability.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.cIntroduce QuickRsaCheckEvp using EVP_PKEY_get_bn_param; adjust RSA validation flow to prefer EVP-param extraction.
src/native/libs/System.Security.Cryptography.Native/pal_crypto_config.h.inAdd HAVE_OPENSSL_RSA_PRIMITIVE feature define.
src/native/libs/System.Security.Cryptography.Native/osslcompat_30.hAdd RSA parameter-name constants needed for EVP param extraction on older headers.
src/native/libs/System.Security.Cryptography.Native/opensslshim.hAdd RSA primitive fallback declarations and convert multiple RSA-related bindings to lightup functions.
src/native/libs/System.Security.Cryptography.Native/configure.cmakeAdd compile probe for RSA primitive availability (RSA_new/RSA_free).

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.c Outdated
@PranavSenthilnathanPranavSenthilnathan changed the title [WIP] Remove deprecated OpenSSL RSA APIsRemove deprecated OpenSSL RSA APIsApr 2, 2026
@PranavSenthilnathan
PranavSenthilnathan marked this pull request as ready for review April 2, 2026 19:57
CopilotAI review requested due to automatic review settings April 2, 2026 19:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/opensslshim.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 20:32

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/libraries/System.Security.Cryptography/tests/RSACreateTests.cs Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 21:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • The managed to native transition for import/export are in terms of SPKI and PKCS8, so they aren't affected by the loss of RSA_get0_factors and friends.
  • I think we already don't have good tests for creating an RSAOpenSsl from an RSA*, and I'm having trouble imagining how we'd know it was "OK" to pass a synthetic pointer value in to make sure we got a sensible "uh, there's no EVP_PKEY_set1_RSA...", so it makes sense to not see test changes for that.
  • All of the new EVP_PKEY vs RSA adapter functions seem to be declared static.
  • I briefly entertained the idea of suggesting probing off of HEADER_RSA_H instead of probing for RSA_new... but, nah.

So, looks like this "I think you can #if away some more code in direct build mode" is probably the last thing from me.

CopilotAI review requested due to automatic review settings April 7, 2026 17:58

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

RSA_F_RSA_NULL_PRIVATE_DECRYPT is 0 is OpenSSL 3.0+ and 132 otherwise. It's used in ERR_put_error for the func argument which has been deprecated (and func doesn't seem very useful anyway). I can use the 132 value but I think it's fine to just remove it altogether here instead of conditionally defining the macros.

@bartonjs

bartonjs commented Apr 7, 2026

Copy link
Copy Markdown
Member

Since the code would only hit when compiled with the 3.0 headers and run on 1.1... it should be passing 132, not 0.

CopilotAI review requested due to automatic review settings April 7, 2026 22:29

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

CopilotAI review requested due to automatic review settings April 8, 2026 18:53

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

/ba-g #126675

@PranavSenthilnathan
PranavSenthilnathan merged commit 770e62e into dotnet:mainApr 13, 2026
105 of 114 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ossl-deprecations branch April 20, 2026 23:45
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@PranavSenthilnathan@bartonjs@vcsjones
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all
 blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks");
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
Skip to content

Remove deprecated OpenSSL RSA APIs - #126034

Merged
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations
Apr 13, 2026
Merged

Remove deprecated OpenSSL RSA APIs#126034
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Remove deprecated OpenSSL RSA APIs. The RSA type and RSA_* methods have been deprecated in favor of EVP_PKEY. Most of our code already has moved, but this cleans up the function loading and updates the remaining places. The build allows deprecated APIs, but for local testing I've been using -DOPENSSL_API_COMPAT=0x30500000L -DOPENSSL_NO_DEPRECATED to error on deprecated APIs.

@PranavSenthilnathanPranavSenthilnathan added this to the 11.0.0 milestone Mar 24, 2026
CopilotAI review requested due to automatic review settings March 24, 2026 15:59
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR continues the migration away from deprecated OpenSSL RSA* APIs toward EVP-based APIs (primarily EVP_PKEY), updating certificate generation and key-validation paths, and adjusting shim/configure logic to better tolerate RSA legacy symbol availability.

Changes:

  • Update self-signed certificate generation to use/generated EVP_PKEY* directly (removing EVP_PKEY_get1_RSA / EVP_PKEY_set1_RSA usage in that flow).
  • Add an EVP-based RSA “quick check” (EVP_PKEY_get_bn_param) for OpenSSL 3+ to avoid relying on legacy RSA object access.
  • Add HAVE_OPENSSL_RSA_PRIMITIVE configure/shim support and relax several RSA-related shim bindings to “lightup” (runtime-detected) functions.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
src/native/libs/System.Security.Cryptography.Native/pal_ssl.cSwitch self-signed cert helper to return the generated EVP_PKEY* instead of extracting/setting a legacy RSA*.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.cFactor legacy private-key-availability check into a helper and gate it on EVP_PKEY_get0_RSA lightup availability.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.cIntroduce QuickRsaCheckEvp using EVP_PKEY_get_bn_param; adjust RSA validation flow to prefer EVP-param extraction.
src/native/libs/System.Security.Cryptography.Native/pal_crypto_config.h.inAdd HAVE_OPENSSL_RSA_PRIMITIVE feature define.
src/native/libs/System.Security.Cryptography.Native/osslcompat_30.hAdd RSA parameter-name constants needed for EVP param extraction on older headers.
src/native/libs/System.Security.Cryptography.Native/opensslshim.hAdd RSA primitive fallback declarations and convert multiple RSA-related bindings to lightup functions.
src/native/libs/System.Security.Cryptography.Native/configure.cmakeAdd compile probe for RSA primitive availability (RSA_new/RSA_free).

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.c Outdated
@PranavSenthilnathanPranavSenthilnathan changed the title [WIP] Remove deprecated OpenSSL RSA APIsRemove deprecated OpenSSL RSA APIsApr 2, 2026
@PranavSenthilnathan
PranavSenthilnathan marked this pull request as ready for review April 2, 2026 19:57
CopilotAI review requested due to automatic review settings April 2, 2026 19:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/opensslshim.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 20:32

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/libraries/System.Security.Cryptography/tests/RSACreateTests.cs Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 21:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • The managed to native transition for import/export are in terms of SPKI and PKCS8, so they aren't affected by the loss of RSA_get0_factors and friends.
  • I think we already don't have good tests for creating an RSAOpenSsl from an RSA*, and I'm having trouble imagining how we'd know it was "OK" to pass a synthetic pointer value in to make sure we got a sensible "uh, there's no EVP_PKEY_set1_RSA...", so it makes sense to not see test changes for that.
  • All of the new EVP_PKEY vs RSA adapter functions seem to be declared static.
  • I briefly entertained the idea of suggesting probing off of HEADER_RSA_H instead of probing for RSA_new... but, nah.

So, looks like this "I think you can #if away some more code in direct build mode" is probably the last thing from me.

CopilotAI review requested due to automatic review settings April 7, 2026 17:58

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

RSA_F_RSA_NULL_PRIVATE_DECRYPT is 0 is OpenSSL 3.0+ and 132 otherwise. It's used in ERR_put_error for the func argument which has been deprecated (and func doesn't seem very useful anyway). I can use the 132 value but I think it's fine to just remove it altogether here instead of conditionally defining the macros.

@bartonjs

bartonjs commented Apr 7, 2026

Copy link
Copy Markdown
Member

Since the code would only hit when compiled with the 3.0 headers and run on 1.1... it should be passing 132, not 0.

CopilotAI review requested due to automatic review settings April 7, 2026 22:29

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

CopilotAI review requested due to automatic review settings April 8, 2026 18:53

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

/ba-g #126675

@PranavSenthilnathan
PranavSenthilnathan merged commit 770e62e into dotnet:mainApr 13, 2026
105 of 114 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ossl-deprecations branch April 20, 2026 23:45
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@PranavSenthilnathan@bartonjs@vcsjones
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Remove deprecated OpenSSL RSA APIs - #126034

Merged
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations
Apr 13, 2026
Merged

Remove deprecated OpenSSL RSA APIs#126034
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Remove deprecated OpenSSL RSA APIs. The RSA type and RSA_* methods have been deprecated in favor of EVP_PKEY. Most of our code already has moved, but this cleans up the function loading and updates the remaining places. The build allows deprecated APIs, but for local testing I've been using -DOPENSSL_API_COMPAT=0x30500000L -DOPENSSL_NO_DEPRECATED to error on deprecated APIs.

@PranavSenthilnathanPranavSenthilnathan added this to the 11.0.0 milestone Mar 24, 2026
CopilotAI review requested due to automatic review settings March 24, 2026 15:59
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR continues the migration away from deprecated OpenSSL RSA* APIs toward EVP-based APIs (primarily EVP_PKEY), updating certificate generation and key-validation paths, and adjusting shim/configure logic to better tolerate RSA legacy symbol availability.

Changes:

  • Update self-signed certificate generation to use/generated EVP_PKEY* directly (removing EVP_PKEY_get1_RSA / EVP_PKEY_set1_RSA usage in that flow).
  • Add an EVP-based RSA “quick check” (EVP_PKEY_get_bn_param) for OpenSSL 3+ to avoid relying on legacy RSA object access.
  • Add HAVE_OPENSSL_RSA_PRIMITIVE configure/shim support and relax several RSA-related shim bindings to “lightup” (runtime-detected) functions.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
src/native/libs/System.Security.Cryptography.Native/pal_ssl.cSwitch self-signed cert helper to return the generated EVP_PKEY* instead of extracting/setting a legacy RSA*.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.cFactor legacy private-key-availability check into a helper and gate it on EVP_PKEY_get0_RSA lightup availability.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.cIntroduce QuickRsaCheckEvp using EVP_PKEY_get_bn_param; adjust RSA validation flow to prefer EVP-param extraction.
src/native/libs/System.Security.Cryptography.Native/pal_crypto_config.h.inAdd HAVE_OPENSSL_RSA_PRIMITIVE feature define.
src/native/libs/System.Security.Cryptography.Native/osslcompat_30.hAdd RSA parameter-name constants needed for EVP param extraction on older headers.
src/native/libs/System.Security.Cryptography.Native/opensslshim.hAdd RSA primitive fallback declarations and convert multiple RSA-related bindings to lightup functions.
src/native/libs/System.Security.Cryptography.Native/configure.cmakeAdd compile probe for RSA primitive availability (RSA_new/RSA_free).

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.c Outdated
@PranavSenthilnathanPranavSenthilnathan changed the title [WIP] Remove deprecated OpenSSL RSA APIsRemove deprecated OpenSSL RSA APIsApr 2, 2026
@PranavSenthilnathan
PranavSenthilnathan marked this pull request as ready for review April 2, 2026 19:57
CopilotAI review requested due to automatic review settings April 2, 2026 19:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/opensslshim.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 20:32

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/libraries/System.Security.Cryptography/tests/RSACreateTests.cs Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 21:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • The managed to native transition for import/export are in terms of SPKI and PKCS8, so they aren't affected by the loss of RSA_get0_factors and friends.
  • I think we already don't have good tests for creating an RSAOpenSsl from an RSA*, and I'm having trouble imagining how we'd know it was "OK" to pass a synthetic pointer value in to make sure we got a sensible "uh, there's no EVP_PKEY_set1_RSA...", so it makes sense to not see test changes for that.
  • All of the new EVP_PKEY vs RSA adapter functions seem to be declared static.
  • I briefly entertained the idea of suggesting probing off of HEADER_RSA_H instead of probing for RSA_new... but, nah.

So, looks like this "I think you can #if away some more code in direct build mode" is probably the last thing from me.

CopilotAI review requested due to automatic review settings April 7, 2026 17:58

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

RSA_F_RSA_NULL_PRIVATE_DECRYPT is 0 is OpenSSL 3.0+ and 132 otherwise. It's used in ERR_put_error for the func argument which has been deprecated (and func doesn't seem very useful anyway). I can use the 132 value but I think it's fine to just remove it altogether here instead of conditionally defining the macros.

@bartonjs

bartonjs commented Apr 7, 2026

Copy link
Copy Markdown
Member

Since the code would only hit when compiled with the 3.0 headers and run on 1.1... it should be passing 132, not 0.

CopilotAI review requested due to automatic review settings April 7, 2026 22:29

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

CopilotAI review requested due to automatic review settings April 8, 2026 18:53

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

/ba-g #126675

@PranavSenthilnathan
PranavSenthilnathan merged commit 770e62e into dotnet:mainApr 13, 2026
105 of 114 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ossl-deprecations branch April 20, 2026 23:45
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@PranavSenthilnathan@bartonjs@vcsjones
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length > 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Remove deprecated OpenSSL RSA APIs - #126034

Merged
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations
Apr 13, 2026
Merged

Remove deprecated OpenSSL RSA APIs#126034
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Remove deprecated OpenSSL RSA APIs. The RSA type and RSA_* methods have been deprecated in favor of EVP_PKEY. Most of our code already has moved, but this cleans up the function loading and updates the remaining places. The build allows deprecated APIs, but for local testing I've been using -DOPENSSL_API_COMPAT=0x30500000L -DOPENSSL_NO_DEPRECATED to error on deprecated APIs.

@PranavSenthilnathanPranavSenthilnathan added this to the 11.0.0 milestone Mar 24, 2026
CopilotAI review requested due to automatic review settings March 24, 2026 15:59
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR continues the migration away from deprecated OpenSSL RSA* APIs toward EVP-based APIs (primarily EVP_PKEY), updating certificate generation and key-validation paths, and adjusting shim/configure logic to better tolerate RSA legacy symbol availability.

Changes:

  • Update self-signed certificate generation to use/generated EVP_PKEY* directly (removing EVP_PKEY_get1_RSA / EVP_PKEY_set1_RSA usage in that flow).
  • Add an EVP-based RSA “quick check” (EVP_PKEY_get_bn_param) for OpenSSL 3+ to avoid relying on legacy RSA object access.
  • Add HAVE_OPENSSL_RSA_PRIMITIVE configure/shim support and relax several RSA-related shim bindings to “lightup” (runtime-detected) functions.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
src/native/libs/System.Security.Cryptography.Native/pal_ssl.cSwitch self-signed cert helper to return the generated EVP_PKEY* instead of extracting/setting a legacy RSA*.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.cFactor legacy private-key-availability check into a helper and gate it on EVP_PKEY_get0_RSA lightup availability.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.cIntroduce QuickRsaCheckEvp using EVP_PKEY_get_bn_param; adjust RSA validation flow to prefer EVP-param extraction.
src/native/libs/System.Security.Cryptography.Native/pal_crypto_config.h.inAdd HAVE_OPENSSL_RSA_PRIMITIVE feature define.
src/native/libs/System.Security.Cryptography.Native/osslcompat_30.hAdd RSA parameter-name constants needed for EVP param extraction on older headers.
src/native/libs/System.Security.Cryptography.Native/opensslshim.hAdd RSA primitive fallback declarations and convert multiple RSA-related bindings to lightup functions.
src/native/libs/System.Security.Cryptography.Native/configure.cmakeAdd compile probe for RSA primitive availability (RSA_new/RSA_free).

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.c Outdated
@PranavSenthilnathanPranavSenthilnathan changed the title [WIP] Remove deprecated OpenSSL RSA APIsRemove deprecated OpenSSL RSA APIsApr 2, 2026
@PranavSenthilnathan
PranavSenthilnathan marked this pull request as ready for review April 2, 2026 19:57
CopilotAI review requested due to automatic review settings April 2, 2026 19:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/opensslshim.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 20:32

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/libraries/System.Security.Cryptography/tests/RSACreateTests.cs Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 21:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • The managed to native transition for import/export are in terms of SPKI and PKCS8, so they aren't affected by the loss of RSA_get0_factors and friends.
  • I think we already don't have good tests for creating an RSAOpenSsl from an RSA*, and I'm having trouble imagining how we'd know it was "OK" to pass a synthetic pointer value in to make sure we got a sensible "uh, there's no EVP_PKEY_set1_RSA...", so it makes sense to not see test changes for that.
  • All of the new EVP_PKEY vs RSA adapter functions seem to be declared static.
  • I briefly entertained the idea of suggesting probing off of HEADER_RSA_H instead of probing for RSA_new... but, nah.

So, looks like this "I think you can #if away some more code in direct build mode" is probably the last thing from me.

CopilotAI review requested due to automatic review settings April 7, 2026 17:58

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

RSA_F_RSA_NULL_PRIVATE_DECRYPT is 0 is OpenSSL 3.0+ and 132 otherwise. It's used in ERR_put_error for the func argument which has been deprecated (and func doesn't seem very useful anyway). I can use the 132 value but I think it's fine to just remove it altogether here instead of conditionally defining the macros.

@bartonjs

bartonjs commented Apr 7, 2026

Copy link
Copy Markdown
Member

Since the code would only hit when compiled with the 3.0 headers and run on 1.1... it should be passing 132, not 0.

CopilotAI review requested due to automatic review settings April 7, 2026 22:29

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

CopilotAI review requested due to automatic review settings April 8, 2026 18:53

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

/ba-g #126675

@PranavSenthilnathan
PranavSenthilnathan merged commit 770e62e into dotnet:mainApr 13, 2026
105 of 114 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ossl-deprecations branch April 20, 2026 23:45
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@PranavSenthilnathan@bartonjs@vcsjones
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
Skip to content

Remove deprecated OpenSSL RSA APIs - #126034

Merged
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations
Apr 13, 2026
Merged

Remove deprecated OpenSSL RSA APIs#126034
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Remove deprecated OpenSSL RSA APIs. The RSA type and RSA_* methods have been deprecated in favor of EVP_PKEY. Most of our code already has moved, but this cleans up the function loading and updates the remaining places. The build allows deprecated APIs, but for local testing I've been using -DOPENSSL_API_COMPAT=0x30500000L -DOPENSSL_NO_DEPRECATED to error on deprecated APIs.

@PranavSenthilnathanPranavSenthilnathan added this to the 11.0.0 milestone Mar 24, 2026
CopilotAI review requested due to automatic review settings March 24, 2026 15:59
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR continues the migration away from deprecated OpenSSL RSA* APIs toward EVP-based APIs (primarily EVP_PKEY), updating certificate generation and key-validation paths, and adjusting shim/configure logic to better tolerate RSA legacy symbol availability.

Changes:

  • Update self-signed certificate generation to use/generated EVP_PKEY* directly (removing EVP_PKEY_get1_RSA / EVP_PKEY_set1_RSA usage in that flow).
  • Add an EVP-based RSA “quick check” (EVP_PKEY_get_bn_param) for OpenSSL 3+ to avoid relying on legacy RSA object access.
  • Add HAVE_OPENSSL_RSA_PRIMITIVE configure/shim support and relax several RSA-related shim bindings to “lightup” (runtime-detected) functions.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
src/native/libs/System.Security.Cryptography.Native/pal_ssl.cSwitch self-signed cert helper to return the generated EVP_PKEY* instead of extracting/setting a legacy RSA*.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.cFactor legacy private-key-availability check into a helper and gate it on EVP_PKEY_get0_RSA lightup availability.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.cIntroduce QuickRsaCheckEvp using EVP_PKEY_get_bn_param; adjust RSA validation flow to prefer EVP-param extraction.
src/native/libs/System.Security.Cryptography.Native/pal_crypto_config.h.inAdd HAVE_OPENSSL_RSA_PRIMITIVE feature define.
src/native/libs/System.Security.Cryptography.Native/osslcompat_30.hAdd RSA parameter-name constants needed for EVP param extraction on older headers.
src/native/libs/System.Security.Cryptography.Native/opensslshim.hAdd RSA primitive fallback declarations and convert multiple RSA-related bindings to lightup functions.
src/native/libs/System.Security.Cryptography.Native/configure.cmakeAdd compile probe for RSA primitive availability (RSA_new/RSA_free).

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.c Outdated
@PranavSenthilnathanPranavSenthilnathan changed the title [WIP] Remove deprecated OpenSSL RSA APIsRemove deprecated OpenSSL RSA APIsApr 2, 2026
@PranavSenthilnathan
PranavSenthilnathan marked this pull request as ready for review April 2, 2026 19:57
CopilotAI review requested due to automatic review settings April 2, 2026 19:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/opensslshim.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 20:32

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/libraries/System.Security.Cryptography/tests/RSACreateTests.cs Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 21:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • The managed to native transition for import/export are in terms of SPKI and PKCS8, so they aren't affected by the loss of RSA_get0_factors and friends.
  • I think we already don't have good tests for creating an RSAOpenSsl from an RSA*, and I'm having trouble imagining how we'd know it was "OK" to pass a synthetic pointer value in to make sure we got a sensible "uh, there's no EVP_PKEY_set1_RSA...", so it makes sense to not see test changes for that.
  • All of the new EVP_PKEY vs RSA adapter functions seem to be declared static.
  • I briefly entertained the idea of suggesting probing off of HEADER_RSA_H instead of probing for RSA_new... but, nah.

So, looks like this "I think you can #if away some more code in direct build mode" is probably the last thing from me.

CopilotAI review requested due to automatic review settings April 7, 2026 17:58

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

RSA_F_RSA_NULL_PRIVATE_DECRYPT is 0 is OpenSSL 3.0+ and 132 otherwise. It's used in ERR_put_error for the func argument which has been deprecated (and func doesn't seem very useful anyway). I can use the 132 value but I think it's fine to just remove it altogether here instead of conditionally defining the macros.

@bartonjs

bartonjs commented Apr 7, 2026

Copy link
Copy Markdown
Member

Since the code would only hit when compiled with the 3.0 headers and run on 1.1... it should be passing 132, not 0.

CopilotAI review requested due to automatic review settings April 7, 2026 22:29

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

CopilotAI review requested due to automatic review settings April 8, 2026 18:53

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

/ba-g #126675

@PranavSenthilnathan
PranavSenthilnathan merged commit 770e62e into dotnet:mainApr 13, 2026
105 of 114 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ossl-deprecations branch April 20, 2026 23:45
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@PranavSenthilnathan@bartonjs@vcsjones
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Remove deprecated OpenSSL RSA APIs - #126034

Merged
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations
Apr 13, 2026
Merged

Remove deprecated OpenSSL RSA APIs#126034
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Remove deprecated OpenSSL RSA APIs. The RSA type and RSA_* methods have been deprecated in favor of EVP_PKEY. Most of our code already has moved, but this cleans up the function loading and updates the remaining places. The build allows deprecated APIs, but for local testing I've been using -DOPENSSL_API_COMPAT=0x30500000L -DOPENSSL_NO_DEPRECATED to error on deprecated APIs.

@PranavSenthilnathanPranavSenthilnathan added this to the 11.0.0 milestone Mar 24, 2026
CopilotAI review requested due to automatic review settings March 24, 2026 15:59
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR continues the migration away from deprecated OpenSSL RSA* APIs toward EVP-based APIs (primarily EVP_PKEY), updating certificate generation and key-validation paths, and adjusting shim/configure logic to better tolerate RSA legacy symbol availability.

Changes:

  • Update self-signed certificate generation to use/generated EVP_PKEY* directly (removing EVP_PKEY_get1_RSA / EVP_PKEY_set1_RSA usage in that flow).
  • Add an EVP-based RSA “quick check” (EVP_PKEY_get_bn_param) for OpenSSL 3+ to avoid relying on legacy RSA object access.
  • Add HAVE_OPENSSL_RSA_PRIMITIVE configure/shim support and relax several RSA-related shim bindings to “lightup” (runtime-detected) functions.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
src/native/libs/System.Security.Cryptography.Native/pal_ssl.cSwitch self-signed cert helper to return the generated EVP_PKEY* instead of extracting/setting a legacy RSA*.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.cFactor legacy private-key-availability check into a helper and gate it on EVP_PKEY_get0_RSA lightup availability.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.cIntroduce QuickRsaCheckEvp using EVP_PKEY_get_bn_param; adjust RSA validation flow to prefer EVP-param extraction.
src/native/libs/System.Security.Cryptography.Native/pal_crypto_config.h.inAdd HAVE_OPENSSL_RSA_PRIMITIVE feature define.
src/native/libs/System.Security.Cryptography.Native/osslcompat_30.hAdd RSA parameter-name constants needed for EVP param extraction on older headers.
src/native/libs/System.Security.Cryptography.Native/opensslshim.hAdd RSA primitive fallback declarations and convert multiple RSA-related bindings to lightup functions.
src/native/libs/System.Security.Cryptography.Native/configure.cmakeAdd compile probe for RSA primitive availability (RSA_new/RSA_free).

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.c Outdated
@PranavSenthilnathanPranavSenthilnathan changed the title [WIP] Remove deprecated OpenSSL RSA APIsRemove deprecated OpenSSL RSA APIsApr 2, 2026
@PranavSenthilnathan
PranavSenthilnathan marked this pull request as ready for review April 2, 2026 19:57
CopilotAI review requested due to automatic review settings April 2, 2026 19:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/opensslshim.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 20:32

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/libraries/System.Security.Cryptography/tests/RSACreateTests.cs Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 21:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • The managed to native transition for import/export are in terms of SPKI and PKCS8, so they aren't affected by the loss of RSA_get0_factors and friends.
  • I think we already don't have good tests for creating an RSAOpenSsl from an RSA*, and I'm having trouble imagining how we'd know it was "OK" to pass a synthetic pointer value in to make sure we got a sensible "uh, there's no EVP_PKEY_set1_RSA...", so it makes sense to not see test changes for that.
  • All of the new EVP_PKEY vs RSA adapter functions seem to be declared static.
  • I briefly entertained the idea of suggesting probing off of HEADER_RSA_H instead of probing for RSA_new... but, nah.

So, looks like this "I think you can #if away some more code in direct build mode" is probably the last thing from me.

CopilotAI review requested due to automatic review settings April 7, 2026 17:58

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

RSA_F_RSA_NULL_PRIVATE_DECRYPT is 0 is OpenSSL 3.0+ and 132 otherwise. It's used in ERR_put_error for the func argument which has been deprecated (and func doesn't seem very useful anyway). I can use the 132 value but I think it's fine to just remove it altogether here instead of conditionally defining the macros.

@bartonjs

bartonjs commented Apr 7, 2026

Copy link
Copy Markdown
Member

Since the code would only hit when compiled with the 3.0 headers and run on 1.1... it should be passing 132, not 0.

CopilotAI review requested due to automatic review settings April 7, 2026 22:29

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

CopilotAI review requested due to automatic review settings April 8, 2026 18:53

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

/ba-g #126675

@PranavSenthilnathan
PranavSenthilnathan merged commit 770e62e into dotnet:mainApr 13, 2026
105 of 114 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ossl-deprecations branch April 20, 2026 23:45
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@PranavSenthilnathan@bartonjs@vcsjones
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
Skip to content

Remove deprecated OpenSSL RSA APIs - #126034

Merged
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations
Apr 13, 2026
Merged

Remove deprecated OpenSSL RSA APIs#126034
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Remove deprecated OpenSSL RSA APIs. The RSA type and RSA_* methods have been deprecated in favor of EVP_PKEY. Most of our code already has moved, but this cleans up the function loading and updates the remaining places. The build allows deprecated APIs, but for local testing I've been using -DOPENSSL_API_COMPAT=0x30500000L -DOPENSSL_NO_DEPRECATED to error on deprecated APIs.

@PranavSenthilnathanPranavSenthilnathan added this to the 11.0.0 milestone Mar 24, 2026
CopilotAI review requested due to automatic review settings March 24, 2026 15:59
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR continues the migration away from deprecated OpenSSL RSA* APIs toward EVP-based APIs (primarily EVP_PKEY), updating certificate generation and key-validation paths, and adjusting shim/configure logic to better tolerate RSA legacy symbol availability.

Changes:

  • Update self-signed certificate generation to use/generated EVP_PKEY* directly (removing EVP_PKEY_get1_RSA / EVP_PKEY_set1_RSA usage in that flow).
  • Add an EVP-based RSA “quick check” (EVP_PKEY_get_bn_param) for OpenSSL 3+ to avoid relying on legacy RSA object access.
  • Add HAVE_OPENSSL_RSA_PRIMITIVE configure/shim support and relax several RSA-related shim bindings to “lightup” (runtime-detected) functions.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
src/native/libs/System.Security.Cryptography.Native/pal_ssl.cSwitch self-signed cert helper to return the generated EVP_PKEY* instead of extracting/setting a legacy RSA*.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.cFactor legacy private-key-availability check into a helper and gate it on EVP_PKEY_get0_RSA lightup availability.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.cIntroduce QuickRsaCheckEvp using EVP_PKEY_get_bn_param; adjust RSA validation flow to prefer EVP-param extraction.
src/native/libs/System.Security.Cryptography.Native/pal_crypto_config.h.inAdd HAVE_OPENSSL_RSA_PRIMITIVE feature define.
src/native/libs/System.Security.Cryptography.Native/osslcompat_30.hAdd RSA parameter-name constants needed for EVP param extraction on older headers.
src/native/libs/System.Security.Cryptography.Native/opensslshim.hAdd RSA primitive fallback declarations and convert multiple RSA-related bindings to lightup functions.
src/native/libs/System.Security.Cryptography.Native/configure.cmakeAdd compile probe for RSA primitive availability (RSA_new/RSA_free).

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.c Outdated
@PranavSenthilnathanPranavSenthilnathan changed the title [WIP] Remove deprecated OpenSSL RSA APIsRemove deprecated OpenSSL RSA APIsApr 2, 2026
@PranavSenthilnathan
PranavSenthilnathan marked this pull request as ready for review April 2, 2026 19:57
CopilotAI review requested due to automatic review settings April 2, 2026 19:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/opensslshim.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 20:32

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/libraries/System.Security.Cryptography/tests/RSACreateTests.cs Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 21:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • The managed to native transition for import/export are in terms of SPKI and PKCS8, so they aren't affected by the loss of RSA_get0_factors and friends.
  • I think we already don't have good tests for creating an RSAOpenSsl from an RSA*, and I'm having trouble imagining how we'd know it was "OK" to pass a synthetic pointer value in to make sure we got a sensible "uh, there's no EVP_PKEY_set1_RSA...", so it makes sense to not see test changes for that.
  • All of the new EVP_PKEY vs RSA adapter functions seem to be declared static.
  • I briefly entertained the idea of suggesting probing off of HEADER_RSA_H instead of probing for RSA_new... but, nah.

So, looks like this "I think you can #if away some more code in direct build mode" is probably the last thing from me.

CopilotAI review requested due to automatic review settings April 7, 2026 17:58

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

RSA_F_RSA_NULL_PRIVATE_DECRYPT is 0 is OpenSSL 3.0+ and 132 otherwise. It's used in ERR_put_error for the func argument which has been deprecated (and func doesn't seem very useful anyway). I can use the 132 value but I think it's fine to just remove it altogether here instead of conditionally defining the macros.

@bartonjs

bartonjs commented Apr 7, 2026

Copy link
Copy Markdown
Member

Since the code would only hit when compiled with the 3.0 headers and run on 1.1... it should be passing 132, not 0.

CopilotAI review requested due to automatic review settings April 7, 2026 22:29

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

CopilotAI review requested due to automatic review settings April 8, 2026 18:53

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

/ba-g #126675

@PranavSenthilnathan
PranavSenthilnathan merged commit 770e62e into dotnet:mainApr 13, 2026
105 of 114 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ossl-deprecations branch April 20, 2026 23:45
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@PranavSenthilnathan@bartonjs@vcsjones
, 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
Skip to content

Remove deprecated OpenSSL RSA APIs - #126034

Merged
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations
Apr 13, 2026
Merged

Remove deprecated OpenSSL RSA APIs#126034
PranavSenthilnathan merged 13 commits into
dotnet:mainfrom
PranavSenthilnathan:ossl-deprecations

Conversation

@PranavSenthilnathan

Copy link
Copy Markdown
Member

Remove deprecated OpenSSL RSA APIs. The RSA type and RSA_* methods have been deprecated in favor of EVP_PKEY. Most of our code already has moved, but this cleans up the function loading and updates the remaining places. The build allows deprecated APIs, but for local testing I've been using -DOPENSSL_API_COMPAT=0x30500000L -DOPENSSL_NO_DEPRECATED to error on deprecated APIs.

@PranavSenthilnathanPranavSenthilnathan added this to the 11.0.0 milestone Mar 24, 2026
CopilotAI review requested due to automatic review settings March 24, 2026 15:59
@dotnet-policy-service

Copy link
Copy Markdown
Contributor

Tagging subscribers to this area: @bartonjs, @vcsjones, @dotnet/area-system-security
See info in area-owners.md if you want to be subscribed.

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR continues the migration away from deprecated OpenSSL RSA* APIs toward EVP-based APIs (primarily EVP_PKEY), updating certificate generation and key-validation paths, and adjusting shim/configure logic to better tolerate RSA legacy symbol availability.

Changes:

  • Update self-signed certificate generation to use/generated EVP_PKEY* directly (removing EVP_PKEY_get1_RSA / EVP_PKEY_set1_RSA usage in that flow).
  • Add an EVP-based RSA “quick check” (EVP_PKEY_get_bn_param) for OpenSSL 3+ to avoid relying on legacy RSA object access.
  • Add HAVE_OPENSSL_RSA_PRIMITIVE configure/shim support and relax several RSA-related shim bindings to “lightup” (runtime-detected) functions.

Reviewed changes

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Show a summary per file
FileDescription
src/native/libs/System.Security.Cryptography.Native/pal_ssl.cSwitch self-signed cert helper to return the generated EVP_PKEY* instead of extracting/setting a legacy RSA*.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.cFactor legacy private-key-availability check into a helper and gate it on EVP_PKEY_get0_RSA lightup availability.
src/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.cIntroduce QuickRsaCheckEvp using EVP_PKEY_get_bn_param; adjust RSA validation flow to prefer EVP-param extraction.
src/native/libs/System.Security.Cryptography.Native/pal_crypto_config.h.inAdd HAVE_OPENSSL_RSA_PRIMITIVE feature define.
src/native/libs/System.Security.Cryptography.Native/osslcompat_30.hAdd RSA parameter-name constants needed for EVP param extraction on older headers.
src/native/libs/System.Security.Cryptography.Native/opensslshim.hAdd RSA primitive fallback declarations and convert multiple RSA-related bindings to lightup functions.
src/native/libs/System.Security.Cryptography.Native/configure.cmakeAdd compile probe for RSA primitive availability (RSA_new/RSA_free).

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey_rsa.c Outdated
@PranavSenthilnathanPranavSenthilnathan changed the title [WIP] Remove deprecated OpenSSL RSA APIsRemove deprecated OpenSSL RSA APIsApr 2, 2026
@PranavSenthilnathan
PranavSenthilnathan marked this pull request as ready for review April 2, 2026 19:57
CopilotAI review requested due to automatic review settings April 2, 2026 19:57

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 7 out of 7 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/opensslshim.h Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 20:32

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 4 comments.

Comment threadsrc/native/libs/System.Security.Cryptography.Native/pal_evp_pkey.c Outdated
Comment threadsrc/libraries/System.Security.Cryptography/tests/RSACreateTests.cs Outdated
CopilotAI review requested due to automatic review settings April 6, 2026 21:50

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@bartonjsbartonjs left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

  • The managed to native transition for import/export are in terms of SPKI and PKCS8, so they aren't affected by the loss of RSA_get0_factors and friends.
  • I think we already don't have good tests for creating an RSAOpenSsl from an RSA*, and I'm having trouble imagining how we'd know it was "OK" to pass a synthetic pointer value in to make sure we got a sensible "uh, there's no EVP_PKEY_set1_RSA...", so it makes sense to not see test changes for that.
  • All of the new EVP_PKEY vs RSA adapter functions seem to be declared static.
  • I briefly entertained the idea of suggesting probing off of HEADER_RSA_H instead of probing for RSA_new... but, nah.

So, looks like this "I think you can #if away some more code in direct build mode" is probably the last thing from me.

CopilotAI review requested due to automatic review settings April 7, 2026 17:58

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 2 comments.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

RSA_F_RSA_NULL_PRIVATE_DECRYPT is 0 is OpenSSL 3.0+ and 132 otherwise. It's used in ERR_put_error for the func argument which has been deprecated (and func doesn't seem very useful anyway). I can use the 132 value but I think it's fine to just remove it altogether here instead of conditionally defining the macros.

@bartonjs

bartonjs commented Apr 7, 2026

Copy link
Copy Markdown
Member

Since the code would only hit when compiled with the 3.0 headers and run on 1.1... it should be passing 132, not 0.

CopilotAI review requested due to automatic review settings April 7, 2026 22:29

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

CopilotAI review requested due to automatic review settings April 8, 2026 18:53

CopilotAI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Copilot reviewed 8 out of 8 changed files in this pull request and generated 1 comment.

@PranavSenthilnathan

Copy link
Copy Markdown
MemberAuthor

/ba-g #126675

@PranavSenthilnathan
PranavSenthilnathan merged commit 770e62e into dotnet:mainApr 13, 2026
105 of 114 checks passed
@PranavSenthilnathan
PranavSenthilnathan deleted the ossl-deprecations branch April 20, 2026 23:45
@github-actionsgithub-actionsBot locked and limited conversation to collaborators May 21, 2026
Sign up for freeto subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants

@PranavSenthilnathan@bartonjs@vcsjones