<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:m="http://schemas.microsoft.com/office/2004/12/omml" xmlns="http://www.w3.org/TR/REC-html40"><head><META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii"><meta name=Generator content="Microsoft Word 15 (filtered medium)"><!--[if !mso]><style>v\:* {behavior:url(#default#VML);}
o\:* {behavior:url(#default#VML);}
w\:* {behavior:url(#default#VML);}
.shape {behavior:url(#default#VML);}
</style><![endif]--><style><!--
/* Font Definitions */
@font-face
{font-family:Helvetica;
panose-1:2 11 6 4 2 2 2 2 2 4;}
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Consolas;
panose-1:2 11 6 9 2 2 4 3 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:#0563C1;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:#954F72;
text-decoration:underline;}
pre
{mso-style-priority:99;
mso-style-link:"HTML Preformatted Char";
margin:0in;
margin-bottom:.0001pt;
font-size:10.0pt;
font-family:"Courier New";
color:black;}
p.msonormal0, li.msonormal0, div.msonormal0
{mso-style-name:msonormal;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:11.0pt;
font-family:"Calibri",sans-serif;
color:black;}
span.HTMLPreformattedChar
{mso-style-name:"HTML Preformatted Char";
mso-style-priority:99;
mso-style-link:"HTML Preformatted";
font-family:"Consolas",serif;
color:black;}
span.EmailStyle21
{mso-style-type:personal;
font-family:"Calibri",sans-serif;
color:windowtext;}
span.EmailStyle22
{mso-style-type:personal-reply;
font-family:"Calibri",sans-serif;
color:windowtext;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></head><body bgcolor=white lang=EN-US link="#0563C1" vlink="#954F72"><div class=WordSection1><p class=MsoNormal><span style='color:windowtext'>Having pulled the lates 3.0-devel version, I have the following error when trying to compile proto-tls <o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'><o:p> </o:p></span></p><p class=MsoNormal><span style='color:windowtext'>../tls_mgm/tls_conn_ops.h:118:29: error: dereferencing pointer to incomplete type ‘SSL {aka struct ssl_st}’<o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'> if ( ((SSL *)c->extra_data)->kssl_ctx ) {<o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'><o:p> </o:p></span></p><p class=MsoNormal><span style='color:windowtext'>Can you please correct ? <o:p></o:p></span></p><p class=MsoNormal><span style='color:windowtext'><o:p> </o:p></span></p><div><div style='border:none;border-top:solid #E1E1E1 1.0pt;padding:3.0pt 0in 0in 0in'><p class=MsoNormal><b><span style='color:windowtext'>From:</span></b><span style='color:windowtext'> Users <users-bounces@lists.opensips.org> <b>On Behalf Of </b>Vlad Patrascu<br><b>Sent:</b> Thursday, March 7, 2019 11:46 AM<br><b>To:</b> users@lists.opensips.org<br><b>Subject:</b> Re: [OpenSIPS-Users] opensips 2.4.4: bug in tls_mgm<o:p></o:p></span></p></div></div><p class=MsoNormal><o:p> </o:p></p><p>Hi Johan,<o:p></o:p></p><p>The issue is probably caused by the fact that OpenSIPS tries to initialize a 'default' client and server domain and the certificate file is inexistent at the default path ('/usr/local/opensips//etc/opensips/tls/cert.pem'). So even if you define your "sv_dom" custom server domain, OpenSIPS still tries to create default domains for fallback purposes. When you omit the '[sv_dom]' prefix for the domain settings in your second test, you overwrite the default ones (with a valid path for the certificate this time).<o:p></o:p></p><p>In conclusion, either specify your custom domain _and_ default domains separately (set the modparams multiple times) or make sure the certificate is found at the default path. Also, note that it's not necessary to define a custom server domain if you only intend to use a single one, as the default will match any socket.<o:p></o:p></p><p>Regards,<o:p></o:p></p><pre>Vlad Patrascu<o:p></o:p></pre><pre>OpenSIPS Developer<o:p></o:p></pre><pre><a href="http://www.opensips-solutions.com">http://www.opensips-solutions.com</a><o:p></o:p></pre><div><p class=MsoNormal>On 02/17/2019 01:35 PM, johan de clercq wrote:<o:p></o:p></p></div><blockquote style='margin-top:5.0pt;margin-bottom:5.0pt'><p class=MsoNormal>Hi, <o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>I believe that I have found a bug in tls_mgm: <o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>Using opensips default certificates:<o:p></o:p></p><p class=MsoNormal>/usr/local/opensips/etc/opensips/tls# ls -lu<o:p></o:p></p><p class=MsoNormal>total 24<o:p></o:p></p><p class=MsoNormal>-rw-r--r-- 1 root staff 2049 Feb 17 12:13 ca.conf<o:p></o:p></p><p class=MsoNormal>-rw-r--r-- 1 root staff 1048 Feb 17 12:13 README<o:p></o:p></p><p class=MsoNormal>-rw-r--r-- 1 root staff 1127 Feb 17 12:13 request.conf<o:p></o:p></p><p class=MsoNormal>drwxr-sr-x 4 root staff 4096 Feb 17 12:16 rootCA<o:p></o:p></p><p class=MsoNormal>drwxr-sr-x 2 root staff 4096 Feb 17 12:13 user<o:p></o:p></p><p class=MsoNormal>-rw-r--r-- 1 root staff 591 Feb 17 12:13 user.conf<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>/usr/local/opensips/etc/opensips/tls/rootCA# ls<o:p></o:p></p><p class=MsoNormal>cacert.pem certs index.txt private serial<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>Tls params: <o:p></o:p></p><p class=MsoNormal>loadmodule "tls_mgm.so"<o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "server_domain", "sv_dom=5.135.140.139:5061") <o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "require_cert", "[sv_dom]0")<o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "verify_cert", "[sv_dom]0")<o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "tls_method", "[sv_dom]SSLv23")<o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "certificate", "[sv_dom]/usr/local/opensips/etc/opensips/tls/rootCA/cacert.pem") <o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "private_key", "[sv_dom]/usr/local/opensips/etc/opensips/tls/rootCA/private/cakey.pem") <o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "ca_list", "[sv_dom]/usr/local/opensips/etc/opensips/tls/rootCA/cacert.pem") <o:p></o:p></p><p class=MsoNormal>#### PROTO_TLS module <o:p></o:p></p><p class=MsoNormal>loadmodule "proto_tls.so"<o:p></o:p></p><p class=MsoNormal>modparam("proto_tls", "trace_destination", "hep_dest")<o:p></o:p></p><p class=MsoNormal>modparam("proto_tls", "trace_on", 1)<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>I removed the passphrase: <o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>mv etc/tls/rootCA/private/cakey.pem etc/tls/rootCA/private/cakey.pem.protected<o:p></o:p></p><p class=MsoNormal>openssl rsa -in etc/tls/rootCA/private/cakey.pem.protected -out etc/tls/rootCA/private/cakey.pem<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>and then tried to run opensips from cmdline : ./opensips -f /usr/local/opensips/etc/opensips/opensips.cfg<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>syslog output:<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>Feb 17 12:22:01 ns3012072 ./opensips[28673]: ERROR:tls_mgm:load_certificate: unable to load certificate file '/usr/local/opensips//etc/opensips/tls/cert.pem'<o:p></o:p></p><p class=MsoNormal>Feb 17 12:22:01 ns3012072 ./opensips[28673]: ERROR:tls_mgm:init_tls_domains: Failed to init TLS domain 'default'<o:p></o:p></p><p class=MsoNormal>Feb 17 12:22:01 ns3012072 ./opensips[28673]: ERROR:core:init_mod: failed to initialize module tls_mgm<o:p></o:p></p><p class=MsoNormal>Feb 17 12:22:01 ns3012072 ./opensips[28673]: ERROR:core:main: error while initializing modules<o:p></o:p></p><p class=MsoNormal>Feb 17 12:22:01 ns3012072 ./opensips[28673]: CRITICAL:core:sig_usr: segfault in attendant (starter) process!<o:p></o:p></p><p class=MsoNormal>Feb 17 12:22:01 ns3012072 kernel: [ 4024.678398] opensips[28673]: segfault at 7fcb76dbf850 ip 00007fcb76546f69 sp 00007ffe803ac150 error 4 in libcrypto.so.1.1[7fcb763df000+265000]<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>Next I tried with: <o:p></o:p></p><p class=MsoNormal>loadmodule "tls_mgm.so"<o:p></o:p></p><p class=MsoNormal>#modparam("tls_mgm", "server_domain", "sv_dom=5.135.140.139:5061") <o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "require_cert", "0")<o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "verify_cert", "0")<o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "tls_method", "SSLv23")<o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "certificate", "/usr/local/opensips/etc/opensips/tls/rootCA/cacert.pem") <o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "private_key", "/usr/local/opensips/etc/opensips/tls/rootCA/private/cakey.pem") <o:p></o:p></p><p class=MsoNormal>modparam("tls_mgm", "ca_list", "/usr/local/opensips/etc/opensips/tls/rootCA/cacert.pem") <o:p></o:p></p><p class=MsoNormal>#### PROTO_TLS module <o:p></o:p></p><p class=MsoNormal>loadmodule "proto_tls.so"<o:p></o:p></p><p class=MsoNormal>modparam("proto_tls", "trace_destination", "hep_dest")<o:p></o:p></p><p class=MsoNormal>modparam("proto_tls", "trace_on", 1)<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>and then opensips starts… <o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal>Can you please explain what I am doing wrong ?<o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal><img border=0 width=255 height=121 style='width:2.6541in;height:1.2583in' id="_x0034_85395db-595c-48b6-9dfb-1ae976a74568" src="cid:image001.png@01D4D902.3D95DAA0" alt="cid:F3100D46-F00D-4610-87ED-3E91DA790A82"><o:p></o:p></p><p class=MsoNormal><span style='font-size:14.0pt;font-family:"Helvetica",sans-serif'>Johan De Clercq, Managing Director<br>Democon bvba - Ooigemstraat 41 - 8780 Oostrozebeke</span><o:p></o:p></p><p class=MsoNormal><span style='font-size:14.0pt;font-family:"Helvetica",sans-serif'>Tel +3256980990 – GSM +32478720104</span><o:p></o:p></p><p class=MsoNormal> <o:p></o:p></p><p class=MsoNormal><br><br><br><o:p></o:p></p><pre>_______________________________________________<o:p></o:p></pre><pre>Users mailing list<o:p></o:p></pre><pre><a href="mailto:Users@lists.opensips.org">Users@lists.opensips.org</a><o:p></o:p></pre><pre><a href="http://lists.opensips.org/cgi-bin/mailman/listinfo/users">http://lists.opensips.org/cgi-bin/mailman/listinfo/users</a><o:p></o:p></pre></blockquote><p class=MsoNormal><o:p> </o:p></p></div></body></html>