<feed xmlns='http://www.w3.org/2005/Atom'>
<title>BMC/OpenBmc/bmcweb.git/include/ossl_wrappers.hpp, branch master</title>
<subtitle>A do everything Redfish, KVM, GUI, and DBus webserver for OpenBMC (mirror)</subtitle>
<id>https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master</id>
<link rel='self' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/atom?h=master'/>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/'/>
<updated>2026-07-02T18:30:22+00:00</updated>
<entry>
<title>Allow setting Mozilla modern</title>
<updated>2026-07-02T18:30:22+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-05-26T20:28:59+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=917fbad478cf5db4a79944d59a4927207adf49d1'/>
<id>urn:sha1:917fbad478cf5db4a79944d59a4927207adf49d1</id>
<content type='text'>
Mozilla publishes recommendations for TLS cipher suites to support.  For
many years bmcweb selected "intermediate" because of compatibility with
clients that didn't yet support TLS1.3.

This commit adds the ability to use the Mozilla modern recommendations,
and disable TLS1.2 support through a new meson option, tls-profile.

Tested:

Loaded on qemu, and verified with testssl.sh[1] that parameters were
applied.

[1] https://github.com/testssl/testssl.sh

Change-Id: I38e915b3943b5dbe5fb31e54eb3ebda9bbaeb811
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Generate 64 bit serial numbers</title>
<updated>2026-06-12T16:01:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>ed@tanous.net</email>
</author>
<published>2026-05-26T21:29:49+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=e5cd5009b23255637dd7f11701a65d8c8fa09b88'/>
<id>urn:sha1:e5cd5009b23255637dd7f11701a65d8c8fa09b88</id>
<content type='text'>
Even though the certificate is self signed, we should pass as many
certificate tests as possible.  testssl.sh prints
```
 Serial 4B32D4F0   NOT ok: length should be &gt;= 64 bits entropy (is: 4 bytes)
```

On our default certificate.  This is relatively easy to fix.

Change-Id: Ib1eb07b637ebf49ecf954b3d98ced9e9ef0f5a34
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>OpenSSL cleanup</title>
<updated>2026-06-12T16:01:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>etanous@nvidia.com</email>
</author>
<published>2026-04-27T21:12:01+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=048cb1125f42cf748218a3258faeb2e868d1e3cb'/>
<id>urn:sha1:048cb1125f42cf748218a3258faeb2e868d1e3cb</id>
<content type='text'>
Continue moving OpenSSL into reusable RAII classes that can be used in
unit tests and other places.  This is slightly more code, but as we're
adding unit tests, it allows reuse between unit tests rather than
writing C directly.  It also encapsulates the complexity of parsing
openssl output (usually in bytes) into standard types (string) that can
be compared/modified.

Functionally this adds two new classes to the "wrappers" functions,
OpenSSLSSLCtx and OpenSSLSSL, which each wrap SSL_CTX and SSL objects
respectively from openssl.  These are rough approximations of the boost
equivalents.

Change-Id: Id87ac4ccde88890bd70861deffdb256188ec0e39
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
<entry>
<title>Add more unit tests for UPN functionality</title>
<updated>2026-04-27T18:51:54+00:00</updated>
<author>
<name>Igor Kanyuka</name>
<email>ikanyuka@fb.com</email>
</author>
<published>2026-04-10T10:46:15+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=5d4a41fa7b46d7badbde21b9f76b4cdcff7d4c64'/>
<id>urn:sha1:5d4a41fa7b46d7badbde21b9f76b4cdcff7d4c64</id>
<content type='text'>
Current unit tests only covers happy path. Add more unit tests before
changing the code.

Tested: unit tests

Change-Id: Ibba5dbbc1457b59670d5d8f3c828fa9ca112f88c
Signed-off-by: Igor Kanyuka &lt;ifelmail@gmail.com&gt;
</content>
</entry>
<entry>
<title>RAII OpenSSL</title>
<updated>2026-04-27T18:51:54+00:00</updated>
<author>
<name>Ed Tanous</name>
<email>ed@tanous.net</email>
</author>
<published>2025-08-19T15:36:27+00:00</published>
<link rel='alternate' type='text/html' href='https://git.radix-linux.su/BMC/OpenBmc/bmcweb.git/commit/?id=cdcbf1a91011a4faf5e8271db3103325a2ba139d'/>
<id>urn:sha1:cdcbf1a91011a4faf5e8271db3103325a2ba139d</id>
<content type='text'>
bmcweb openssl usage is a mess.  Start cleaning it up.
1. Make RAII objects for any held memory.
2. Move methods from hostname monitor into the ssl namespace, so not all
   compile units need to pull in openssl headers
3. Move methods to static where functions can be encapsulated.

Because we're now testing openssl, we need to register memory init so
that the sanitizers don't cause issues when mallocing from non
bootstrapped openssl binaries.  Openssl provides a handle for this, so
use it in those unit tests.

Tested:
Unit tests pass.  bmcweb launches and can open ssl with curl as it did
previously.

Change-Id: If0340692d2c56a6c45bb8d661d654a4b58ff3d2c
Signed-off-by: Ed Tanous &lt;etanous@nvidia.com&gt;
</content>
</entry>
</feed>
