2006-12-18 23:17:18 +00:00
#
2011-01-17 16:47:31 +00:00
# spec file for package openssl
2006-12-18 23:17:18 +00:00
#
2013-02-07 09:44:00 +00:00
# Copyright (c) 2013 SUSE LINUX Products GmbH, Nuernberg, Germany.
2006-12-18 23:17:18 +00:00
#
2008-10-22 16:31:03 +00:00
# All modifications and additions to the file contributed by third parties
# remain the property of their copyright owners, unless otherwise agreed
# upon. The license for this file, and modifications and additions to the
# file, is the same license as for the pristine package itself (unless the
# license for the pristine package is not an Open Source License, in which
# case the license is the MIT License). An "Open Source License" is a
# license that conforms to the Open Source Definition (Version 1.9)
# published by the Open Source Initiative.
2006-12-18 23:17:18 +00:00
# Please submit bugfixes or comments via http://bugs.opensuse.org/
#
Name : openssl
2012-05-21 08:00:42 +00:00
BuildRequires : bc
BuildRequires : ed
BuildRequires : pkg-config
BuildRequires : zlib-devel
2006-12-18 23:17:18 +00:00
%define ssletcdir %{_sysconfdir}/ssl
2012-05-21 08:00:42 +00:00
#%define num_version %(echo "%{version}" | sed -e "s+[a-zA-Z]++g; s+_.*++g")
%define num_version 1.0.0
2006-12-18 23:17:18 +00:00
Provides : ssl
2009-01-09 13:45:25 +00:00
# bug437293
%ifarch ppc64
Obsoletes : openssl-64bit
%endif
2013-02-07 09:44:00 +00:00
Version : 1.0.1d
2012-05-21 08:00:42 +00:00
Release : 0
2006-12-18 23:17:18 +00:00
Summary : Secure Sockets and Transport Layer Security
2012-05-21 08:00:42 +00:00
License : OpenSSL
Group : Productivity/Networking/Security
2007-10-13 16:03:24 +00:00
Url : http://www.openssl.org/
2012-05-21 08:00:42 +00:00
Source : http://www.%{name} .org/source/%{name} -%{version} .tar.gz
2013-02-07 09:44:00 +00:00
Source42 : http://www.%{name} .org/source/%{name} -%{version} .tar.gz.asc
2010-05-25 08:32:24 +00:00
# to get mtime of file:
Source1 : openssl.changes
2010-01-08 16:31:48 +00:00
Source2 : baselibs.conf
2006-12-18 23:17:18 +00:00
Source10 : README.SuSE
2010-04-14 13:14:18 +00:00
Patch0 : merge_from_0.9.8k.patch
2010-05-25 08:32:24 +00:00
Patch1 : openssl-1.0.0-c_rehash-compat.diff
2010-06-02 16:07:27 +00:00
Patch2 : bug610223.patch
2012-08-26 12:22:07 +00:00
Patch3 : openssl-ocloexec.patch
2012-11-22 15:51:34 +00:00
Patch4 : VIA_padlock_support_on_64systems.patch
2013-02-11 10:07:26 +00:00
# PATCH-FIX-UPSTREAM openssl-1.0.1d-s3-packet.patch Fix the calculation that checks there is enough room in a record after removing padding and optional explicit IV bnc#803004, openssl ticket#2975
Patch5 : openssl-1.0.1d-s3-packet.patch
2006-12-18 23:17:18 +00:00
BuildRoot : %{_tmppath} /%{name} -%{version} -build
%description
The OpenSSL Project is a collaborative effort to develop a robust,
commercial-grade, full-featured, and open source toolkit implementing
the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS
v1) protocols with full-strength cryptography. The project is managed
by a worldwide community of volunteers that use the Internet to
communicate, plan, and develop the OpenSSL toolkit and its related
documentation.
Derivation and License
OpenSSL is based on the excellent SSLeay library developed by Eric A.
Young and Tim J. Hudson. The OpenSSL toolkit is licensed under an
Apache-style license, which basically means that you are free to get it
and to use it for commercial and noncommercial purposes.
Authors:
--------
Mark J. Cox <mark@openssl.org>
Ralf S. Engelschall <rse@openssl.org>
Dr. Stephen Henson <steve@openssl.org>
Ben Laurie <ben@openssl.org>
Bodo Moeller <bodo@openssl.org>
Ulf Moeller <ulf@openssl.org>
Holger Reif <holger@openssl.org>
Paul C. Sutton <paul@openssl.org>
2010-04-14 13:14:18 +00:00
%package -n libopenssl1_0_0
2007-05-06 15:17:31 +00:00
Summary : Secure Sockets and Transport Layer Security
Group : Productivity/Networking/Security
2008-07-18 19:56:31 +00:00
Recommends: openssl-certs
2009-01-09 13:45:25 +00:00
# bug437293
%ifarch ppc64
Obsoletes : openssl-64bit
%endif
#
2007-05-06 15:17:31 +00:00
2010-04-14 13:14:18 +00:00
%description -n libopenssl1_0_0
2007-05-06 15:17:31 +00:00
The OpenSSL Project is a collaborative effort to develop a robust,
commercial-grade, full-featured, and open source toolkit implementing
the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS
v1) protocols with full-strength cryptography. The project is managed
by a worldwide community of volunteers that use the Internet to
communicate, plan, and develop the OpenSSL toolkit and its related
documentation.
Derivation and License
OpenSSL is based on the excellent SSLeay library developed by Eric A.
Young and Tim J. Hudson. The OpenSSL toolkit is licensed under an
Apache-style license, which basically means that you are free to get it
and to use it for commercial and noncommercial purposes.
Authors:
--------
Mark J. Cox <mark@openssl.org>
Ralf S. Engelschall <rse@openssl.org>
Dr. Stephen Henson <steve@openssl.org>
Ben Laurie <ben@openssl.org>
Bodo Moeller <bodo@openssl.org>
Ulf Moeller <ulf@openssl.org>
Holger Reif <holger@openssl.org>
Paul C. Sutton <paul@openssl.org>
%package -n libopenssl-devel
2008-07-11 18:44:41 +00:00
Summary : Include Files and Libraries mandatory for Development
2006-12-18 23:17:18 +00:00
Group : Development/Libraries/C and C++
2010-04-14 13:14:18 +00:00
Obsoletes : openssl-devel < %{version}
2011-05-30 07:05:53 +00:00
Requires : %name = %version
2012-05-21 08:00:42 +00:00
Requires : libopenssl1_0_0 = %{version}
Requires : zlib-devel
2010-04-14 13:14:18 +00:00
Provides : openssl-devel = %{version}
2009-01-09 13:45:25 +00:00
# bug437293
%ifarch ppc64
Obsoletes : openssl-devel-64bit
%endif
#
2006-12-18 23:17:18 +00:00
2007-05-06 15:17:31 +00:00
%description -n libopenssl-devel
2006-12-18 23:17:18 +00:00
This package contains all necessary include files and libraries needed
to develop applications that require these.
Authors:
--------
Mark J. Cox <mark@openssl.org>
Ralf S. Engelschall <rse@openssl.org>
Dr. Stephen <Henson steve@openssl.org>
Ben Laurie <ben@openssl.org>
Bodo Moeller <bodo@openssl.org>
Ulf Moeller <ulf@openssl.org>
Holger Reif <holger@openssl.org>
Paul C. Sutton <paul@openssl.org>
%package doc
2008-07-11 18:44:41 +00:00
Summary : Additional Package Documentation
2006-12-18 23:17:18 +00:00
Group : Productivity/Networking/Security
2010-01-08 16:31:48 +00:00
BuildArch : noarch
2006-12-18 23:17:18 +00:00
%description doc
This package contains optional documentation provided in addition to
this package's base documentation.
Authors:
--------
Mark J. Cox <mark@openssl.org>
Ralf S. Engelschall <rse@openssl.org>
Dr. Stephen <Henson steve@openssl.org>
Ben Laurie <ben@openssl.org>
Bodo Moeller <bodo@openssl.org>
Ulf Moeller <ulf@openssl.org>
Holger Reif <holger@openssl.org>
Paul C. Sutton <paul@openssl.org>
%prep
%setup -q
2010-04-14 13:14:18 +00:00
%patch0 -p1
2010-05-25 08:32:24 +00:00
%patch1 -p1
2011-04-18 08:39:50 +00:00
%patch2 -p1
2012-08-26 12:22:07 +00:00
%patch3
2012-11-22 15:51:34 +00:00
%patch4 -p1
2013-02-11 10:07:26 +00:00
%patch5 -p1
2006-12-18 23:17:18 +00:00
cp -p %{S:10} .
echo " a d d i n g / o v e r w r i t i n g s o m e e n t r i e s i n t h e ' t a b l e ' h a s h i n C o n f i g u r e "
# $dso_scheme:$shared_target:$shared_cflag:$shared_ldflag:$shared_extension:$ranlib:$arflags
2010-04-14 13:14:18 +00:00
export DSO_SCHEME='dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::'
2006-12-18 23:17:18 +00:00
cat <<EOF_ED | ed -s Configure
/^);
-
i
2010-04-14 13:14:18 +00:00
#
2006-12-18 23:17:18 +00:00
# local configuration added from specfile
2010-04-14 13:14:18 +00:00
# ... MOST of those are now correct in openssl's Configure already,
# so only add them for new ports!
#
#config-string, $cc:$cflags:$unistd:$thread_cflag:$sys_id:$lflags:$bn_ops:$cpuid_obj:$bn_obj:$des_obj:$aes_obj:$bf_obj:$md5_obj:$sha1_obj:$cast_obj:$rc4_obj:$rmd160_obj:$rc5_obj:$wp_obj:$cmll_obj:$dso_scheme:$shared_target:$shared_cflag:$shared_ldflag:$shared_extension:$ranlib:$arflags:$multilib
#"linux-elf", "gcc:-DL_ENDIAN ::-D_REENTRANT::-ldl:BN_LLONG \${x86_gcc_des} \${x86_gcc_opts}:\${x86_elf_asm}:$DSO_SCHEME:",
#"linux-ia64", "gcc:-DL_ENDIAN -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK RC4_CHAR:\${ia64_asm}: $DSO_SCHEME:",
#"linux-ppc", "gcc:-DB_ENDIAN ::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL:\${no_asm}: $DSO_SCHEME:",
#"linux-ppc64", "gcc:-DB_ENDIAN -DMD32_REG_T=int::-D_REENTRANT::-ldl:RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL SIXTY_FOUR_BIT_LONG:\${no_asm}: $DSO_SCHEME:64",
" l i n u x - e l f - a r m " ," g c c : - D L _ E N D I A N : : - D _ R E E N T R A N T : : - l d l : B N _ L L O N G : \ $ { n o _ a s m } : $ D S O _ S C H E M E : " ,
" l i n u x - m i p s " , " g c c : - D B _ E N D I A N : : - D _ R E E N T R A N T : : - l d l : B N _ L L O N G R C 4 _ C H A R R C 4 _ C H U N K D E S _ R I S C 1 D E S _ U N R O L L : \ $ { n o _ a s m } : $ D S O _ S C H E M E : " ,
" l i n u x - s p a r c v 7 " ," g c c : - D B _ E N D I A N : : - D _ R E E N T R A N T : : - l d l : B N _ L L O N G R C 4 _ C H A R R C 4 _ C H U N K D E S _ U N R O L L B F _ P T R : \ $ { n o _ a s m } : $ D S O _ S C H E M E : " ,
2012-05-21 08:00:42 +00:00
#"linux-sparcv8","gcc:-DB_ENDIAN -DBN_DIV2W -mv8 ::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::asm/sparcv8.o::::::::::::: $DSO_SCHEME:",
2010-04-14 13:14:18 +00:00
#"linux-x86_64", "gcc:-DL_ENDIAN -DNO_ASM -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG:\${no_asm}: $DSO_SCHEME:64",
#"linux-s390", "gcc:-DB_ENDIAN ::(unknown): :-ldl:BN_LLONG:\${no_asm}: $DSO_SCHEME:",
#"linux-s390x", "gcc:-DB_ENDIAN -DNO_ASM -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG:\${no_asm}: $DSO_SCHEME:64",
" l i n u x - p a r i s c " , " g c c : - D B _ E N D I A N : : - D _ R E E N T R A N T : : - l d l : B N _ L L O N G R C 4 _ C H A R D E S _ P T R D E S _ U N R O L L D E S _ R I S C 1 : \ $ { n o _ a s m } : $ D S O _ S C H E M E : " ,
2006-12-18 23:17:18 +00:00
.
wq
EOF_ED
# fix ENGINESDIR path
sed -i 's,/lib/engines,/%_lib/engines,' Configure
2010-05-25 08:32:24 +00:00
# Record mtime of changes file instead of build time
CHANGES=`stat --format=" % y " %SOURCE1`
sed -i -e " s | # d e f i n e D A T E \ ( . * \ ) . L C _ A L L . * d a t e . | # d e f i n e D A T E \1 $ C H A N G E S | " crypto/Makefile
2006-12-18 23:17:18 +00:00
%build
2012-08-08 09:18:03 +00:00
%ifarch armv5el armv5tel
export MACHINE=armv5el
%endif
2006-12-18 23:17:18 +00:00
./config --test-sanity
#
config_flags=" t h r e a d s s h a r e d n o - r c 5 n o - i d e a \
enable-camellia \
zlib \
--prefix=%{_prefix} \
2010-04-14 13:14:18 +00:00
--libdir=%{_lib} \
2006-12-18 23:17:18 +00:00
--openssldir=%{ssletcdir} \
2012-05-21 08:00:42 +00:00
$RPM_OPT_FLAGS -std=gnu99 \
2010-04-14 13:14:18 +00:00
-Wa,--noexecstack \
2006-12-18 23:17:18 +00:00
-fomit-frame-pointer \
-DTERMIO \
2011-01-10 15:41:42 +00:00
-DPURIFY \
2011-10-19 11:40:21 +00:00
-DSSL_FORBID_ENULL \
2012-05-21 08:00:42 +00:00
-D_GNU_SOURCE \
$(getconf LFS_CFLAGS) \
2010-06-18 03:17:30 +00:00
%ifnarch hppa
2006-12-18 23:17:18 +00:00
-Wall \
-fstack-protector "
2010-06-18 03:17:30 +00:00
%else
-Wall "
%endif
2006-12-18 23:17:18 +00:00
#
2009-07-09 08:42:49 +00:00
#%{!?do_profiling:%define do_profiling 0}
#%if %do_profiling
# # generate feedback
# ./config $config_flags
# make depend CC="gcc %cflags_profile_generate"
# make CC="gcc %cflags_profile_generate"
# LD_LIBRARY_PATH=`pwd` make rehash CC="gcc %cflags_profile_generate"
# LD_LIBRARY_PATH=`pwd` make test CC="gcc %cflags_profile_generate"
# LD_LIBRARY_PATH=`pwd` apps/openssl speed
# make clean
# # compile with feedback
# # but not if it makes a cipher slower:
# #find crypto/aes -name '*.da' | xargs -r rm
# ./config $config_flags %cflags_profile_feedback
# make depend
# make
# LD_LIBRARY_PATH=`pwd` make rehash
# LD_LIBRARY_PATH=`pwd` make test
#%else
2010-07-23 15:05:28 +00:00
# OpenSSL relies on uname -m (not good). Thus that little sparc line.
2010-02-18 15:49:00 +00:00
./config \
%ifarch sparc64
linux64-sparcv9 \
%endif
$config_flags
2006-12-18 23:17:18 +00:00
make depend
make
LD_LIBRARY_PATH=`pwd` make rehash
%ifnarch armv4l
LD_LIBRARY_PATH=`pwd` make test
%endif
2009-07-09 08:42:49 +00:00
#%endif
2006-12-18 23:17:18 +00:00
# show settings
make TABLE
echo $RPM_OPT_FLAGS
eval $(egrep PLATFORM='[[:alnum:]]' Makefile)
grep -B1 -A22 " ^ \ * \ * \ * $ P L A T F O R M $ " TABLE
%install
rm -rf $RPM_BUILD_ROOT
make MANDIR=%{_mandir} INSTALL_PREFIX=$RPM_BUILD_ROOT install
2012-05-08 10:28:22 +00:00
install -d -m755 $RPM_BUILD_ROOT %{ssletcdir} /certs
2006-12-18 23:17:18 +00:00
ln -sf ./%{name} $RPM_BUILD_ROOT /%{_includedir} /ssl
mkdir $RPM_BUILD_ROOT /%{_datadir} /ssl
mv $RPM_BUILD_ROOT /%{ssletcdir} /misc $RPM_BUILD_ROOT /%{_datadir} /ssl/
# ln -s %{ssletcdir}/certs $RPM_BUILD_ROOT/%{_datadir}/ssl/certs
# ln -s %{ssletcdir}/private $RPM_BUILD_ROOT/%{_datadir}/ssl/private
# ln -s %{ssletcdir}/openssl.cnf $RPM_BUILD_ROOT/%{_datadir}/ssl/openssl.cnf
#
2010-05-25 08:32:24 +00:00
2006-12-18 23:17:18 +00:00
# avoid file conflicts with man pages from other packages
#
pushd $RPM_BUILD_ROOT /%{_mandir}
# some man pages now contain spaces. This makes several scripts go havoc, among them /usr/sbin/Check.
# replace spaces by underscores
#for i in man?/*\ *; do mv -v "$i" "${i// /_}"; done
which readlink &>/dev/null || function readlink { ( set +x; target=$(file $1 2>/dev/null); target=${target//* }; test -f $target && echo $target; ) }
for i in man?/*; do
if test -L $i ; then
LDEST=`readlink $i`
rm -f $i ${i}ssl
ln -sf ${LDEST}ssl ${i}ssl
else
mv $i ${i}ssl
fi
case `basename ${i%.*}` in
asn1parse|ca|config|crl|crl2pkcs7|crypto|dgst|dhparam|dsa|dsaparam|enc|gendsa|genrsa|nseq|openssl|passwd|pkcs12|pkcs7|pkcs8|rand|req|rsa|rsautl|s_client|s_server|smime|spkac|ssl|verify|version|x509)
# these are the pages mentioned in openssl(1). They go into the main package.
echo %doc %{_mandir} /${i}ssl.gz >> $OLDPWD/filelist;;
*)
# the rest goes into the openssl-doc package.
echo %doc %{_mandir} /${i}ssl.gz >> $OLDPWD/filelist.doc;;
esac
done
popd
#
# check wether some shared library has been installed
#
2010-05-25 08:32:24 +00:00
ls -l $RPM_BUILD_ROOT %{_libdir}
2010-12-10 14:41:07 +00:00
test -f $RPM_BUILD_ROOT %{_libdir} /libssl.so.%{num_version}
test -f $RPM_BUILD_ROOT %{_libdir} /libcrypto.so.%{num_version}
2010-05-25 08:32:24 +00:00
test -L $RPM_BUILD_ROOT %{_libdir} /libssl.so
test -L $RPM_BUILD_ROOT %{_libdir} /libcrypto.so
2006-12-18 23:17:18 +00:00
#
# see what we've got
#
cat > showciphers.c <<EOF
#include <openssl/err.h>
#include <openssl/ssl.h>
2011-01-10 15:41:42 +00:00
int main(){
2006-12-18 23:17:18 +00:00
unsigned int i;
SSL_CTX *ctx;
SSL *ssl;
SSL_METHOD *meth;
2011-08-06 17:08:49 +00:00
meth = SSLv23_client_method();
2006-12-18 23:17:18 +00:00
SSLeay_add_ssl_algorithms();
ctx = SSL_CTX_new(meth);
if (ctx == NULL) return 0;
ssl = SSL_new(ctx);
if (!ssl) return 0;
for (i=0; ; i++) {
int j, k;
SSL_CIPHER *sc;
sc = (meth->get_cipher)(i);
if (!sc) break;
k = SSL_CIPHER_get_bits(sc, &j);
printf(" % s \n " , sc->name);
}
return 0;
};
EOF
gcc $RPM_OPT_FLAGS -I${RPM_BUILD_ROOT} %{_includedir} -c showciphers.c
gcc -o showciphers showciphers.o -L${RPM_BUILD_ROOT} %{_libdir} -lssl -lcrypto
LD_LIBRARY_PATH=${RPM_BUILD_ROOT} %{_libdir} ./showciphers > AVAILABLE_CIPHERS || true
cat AVAILABLE_CIPHERS
2007-06-14 22:27:50 +00:00
# Do not install demo scripts executable under /usr/share/doc
find demos -type f -perm /111 -exec chmod 644 {} \;
2006-12-18 23:17:18 +00:00
2010-05-25 08:32:24 +00:00
#process openssllib
mkdir $RPM_BUILD_ROOT /%{_lib}
2010-12-10 14:41:07 +00:00
mv $RPM_BUILD_ROOT %{_libdir} /libssl.so.%{num_version} $RPM_BUILD_ROOT /%{_lib}/
mv $RPM_BUILD_ROOT %{_libdir} /libcrypto.so.%{num_version} $RPM_BUILD_ROOT /%{_lib}/
2010-05-25 08:32:24 +00:00
mv $RPM_BUILD_ROOT %{_libdir} /engines $RPM_BUILD_ROOT /%{_lib}/
cd $RPM_BUILD_ROOT %{_libdir} /
2010-12-10 14:41:07 +00:00
ln -sf /%{_lib}/libssl.so.%{num_version} ./libssl.so
ln -sf /%{_lib}/libcrypto.so.%{num_version} ./libcrypto.so
2010-05-25 08:32:24 +00:00
2006-12-18 23:17:18 +00:00
%clean
if ! test -f /.buildenv; then rm -rf $RPM_BUILD_ROOT ; fi
2012-08-26 12:22:07 +00:00
%post -n libopenssl1_0_0 -p /sbin/ldconfig
2006-12-18 23:17:18 +00:00
2012-08-26 12:22:07 +00:00
%postun -n libopenssl1_0_0 -p /sbin/ldconfig
2006-12-18 23:17:18 +00:00
2010-04-14 13:14:18 +00:00
%files -n libopenssl1_0_0
2007-05-06 15:17:31 +00:00
%defattr (-, root, root)
2010-12-10 14:41:07 +00:00
/%{_lib}/libssl.so.%{num_version}
/%{_lib}/libcrypto.so.%{num_version}
2010-05-25 08:32:24 +00:00
/%{_lib}/engines
2007-05-06 15:17:31 +00:00
%files -n libopenssl-devel
2006-12-18 23:17:18 +00:00
%defattr (-, root, root)
%{_includedir} /%{name} /
%{_includedir} /ssl
2010-07-30 10:35:13 +00:00
%exclude %{_libdir} /libcrypto.a
%exclude %{_libdir} /libssl.a
2006-12-18 23:17:18 +00:00
%{_libdir} /libssl.so
2010-05-25 08:32:24 +00:00
%{_libdir} /libcrypto.so
2006-12-18 23:17:18 +00:00
%_libdir /pkgconfig/libcrypto.pc
%_libdir /pkgconfig/libssl.pc
%_libdir /pkgconfig/openssl.pc
%files doc -f filelist.doc
%defattr (-, root, root)
%doc doc/* demos
2007-06-14 22:27:50 +00:00
%doc showciphers.c
2006-12-18 23:17:18 +00:00
%files -f filelist
%defattr (-, root, root)
%doc CHANGE* INSTAL* AVAILABLE_CIPHERS
%doc LICENSE NEWS README README.SuSE
%dir %{ssletcdir}
2008-07-11 18:44:41 +00:00
%dir %{ssletcdir} /certs
2006-12-18 23:17:18 +00:00
%config (noreplace) %{ssletcdir} /openssl.cnf
%attr (700,root,root) %{ssletcdir} /private
%dir %{_datadir} /ssl
%{_datadir} /ssl/misc
%{_bindir} /c_rehash
%{_bindir} /%{name}
2007-05-06 15:17:31 +00:00
2007-03-06 10:18:17 +00:00
%changelog