<?xml version="1.0" encoding="UTF-8" standalone="yes" ?>
<!DOCTYPE bugzilla SYSTEM "https://bugzilla.yoctoproject.org/page.cgi?id=bugzilla.dtd">

<bugzilla version="5.0.6"
          urlbase="https://bugzilla.yoctoproject.org/"
          
          maintainer="it-coreprojects-helpdesk@linuxfoundation.org"
>

    <bug>
          <bug_id>15416</bug_id>
          
          <creation_ts>2024-03-02 08:45:59 +0000</creation_ts>
          <short_desc>python3-cryptography legacy openssl broken after update to 42.0.5</short_desc>
          <delta_ts>2026-02-11 14:09:52 +0000</delta_ts>
          <reporter_accessible>1</reporter_accessible>
          <cclist_accessible>1</cclist_accessible>
          <classification_id>7</classification_id>
          <classification>Build System, Metadata &amp; Runtime</classification>
          <product>OE-Core</product>
          <component>devtools / tool chain</component>
          <version>unspecified</version>
          <rep_platform>x86</rep_platform>
          <op_sys>Multiple</op_sys>
          <bug_status>RESOLVED</bug_status>
          <resolution>FIXED</resolution>
          
          
          <bug_file_loc></bug_file_loc>
          <status_whiteboard></status_whiteboard>
          <keywords></keywords>
          <priority>Medium</priority>
          <bug_severity>major</bug_severity>
          <target_milestone>6.0</target_milestone>
          
          
          <everconfirmed>1</everconfirmed>
          <reporter>kweihmann</reporter>
          <assigned_to name="Colin McAllister">colinmca242</assigned_to>
          <cc>colinmca242</cc>
    
    <cc>meta.mr.watcher</cc>
    
    <cc>meta.watcher</cc>
    
    <cc>randy.macleod</cc>
    
    <cc>ross.burton</cc>
    
    <cc>tim.orling</cc>
          
          
          <cf_os>---</cf_os>
          <cf_regression_type>---</cf_regression_type>
          
          <cf_docchange>No (bug/feature does not impact docs)</cf_docchange>

      

      

      

          <comment_sort_order>oldest_to_newest</comment_sort_order>  
          <long_desc isprivate="0" >
    <commentid>98369</commentid>
    <comment_count>0</comment_count>
    <who name="">kweihmann</who>
    <bug_when>2024-03-02 08:45:59 +0000</bug_when>
    <thetext>Ever since https://github.com/pyca/cryptography/commit/ab83fff3c2658f093fe8e89dca83a85dd113a0b9 made it into cryptography legacy binding of openssl are required.

It seems to replace the weak/lazy binding to openssl used previously, by something that is already required at buildtime.

This lead to the effect that every consuming module trying to import ends up with

-------------

  from cryptography.hazmat.primitives.asymmetric.ec import EllipticCurve
File &quot;.../cryptography/hazmat/primitives/asymmetric/ec.py&quot;, line 11, in &lt;module&gt;
  from cryptography.hazmat._oid import ObjectIdentifier
File &quot;.../cryptography/hazmat/_oid.py&quot;, line 7, in &lt;module&gt;
  from cryptography.hazmat.bindings._rust import (
RuntimeError: OpenSSL 3.0&apos;s legacy provider failed to load. This is a fatal error by default, 
but cryptography supports running without legacy algorithms by setting the environment variable CRYPTOGRAPHY_OPENSSL_NO_LEGACY. 
If you did not expect this error, you have likely made a mistake with your OpenSSL configuration.

-------------

Setting CRYPTOGRAPHY_OPENSSL_NO_LEGACY in the calling application of course works, but is a solution that doesn&apos;t scale.

According to some message boards, a way to fix it is to enable

	echo &quot;[legacy_sect]&quot; &gt;&gt; ${D}${libdir}/ssl-3/openssl.cnf
	echo &quot;activate = 1&quot; &gt;&gt; ${D}${libdir}/ssl-3/openssl.cnf

in openssl (append to do_install), but that has a high and unwanted impact on security and is likely not the preferred option for most users.
And it also doesn&apos;t work for native recipes, as the host sided openssl might be invoked.

Not sure what to do to tackle the problem, but I think patching &quot;CRYPTOGRAPHY_OPENSSL_NO_LEGACY&quot; by default into python3-cryptography seems to be the only feasible way</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>98370</commentid>
    <comment_count>1</comment_count>
    <who name="">kweihmann</who>
    <bug_when>2024-03-02 08:56:58 +0000</bug_when>
    <thetext>I currently helped myself with a bbappend containing

do_install:append() {
    echo &quot;import os&quot; &gt;&gt; ${D}${PYTHON_SITEPACKAGES_DIR}/cryptography/hazmat/__init__.py
    echo &quot;os.environ[&apos;CRYPTOGRAPHY_OPENSSL_NO_LEGACY&apos;] = &apos;1&apos;&quot; &gt;&gt; ${D}${PYTHON_SITEPACKAGES_DIR}/cryptography/hazmat/__init__.py
}</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>98378</commentid>
    <comment_count>2</comment_count>
    <who name="Tim Orling">tim.orling</who>
    <bug_when>2024-03-05 18:30:44 +0000</bug_when>
    <thetext>All of the ptests have been passing, so saying python3-cryptography is broken is an exaggeration.

This should most likely be a PACKAGECONFIG[legacy-openssl] where by default it would be NO LEGACY. We do not want to support old algorithms unless it is for intentional reasons (such as FIPS compliance).</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>98379</commentid>
    <comment_count>3</comment_count>
    <who name="Tim Orling">tim.orling</who>
    <bug_when>2024-03-05 18:35:16 +0000</bug_when>
    <thetext>Sadly, it will also require a configuration/PACKAGECONFIG of OpenSSL in order for the &quot;legacy&quot; algorithms to work at all.

Folks that need a different configuration for OpenSSL (such as FIPS) will most likely also have a requirement to use an older (e.g. 3.0.8 for FIPS) version of OpenSSL anyway.

Please send a patch which sets a PACKAGECONFIG that enables NO LEGACY by default.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>98415</commentid>
    <comment_count>4</comment_count>
    <who name="Ross Burton">ross.burton</who>
    <bug_when>2024-03-07 15:37:25 +0000</bug_when>
    <thetext>FWIW we have some recipes that use pycryptography-native and they do this:

# python3-cryptography needs the legacy provider, so set OPENSSL_MODULES to the
# right path until this is relocated automatically.
export OPENSSL_MODULES=&quot;${STAGING_LIBDIR_NATIVE}/ossl-modules&quot;</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>100092</commentid>
    <comment_count>5</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2024-10-31 15:09:24 +0000</bug_when>
    <thetext>Bulk move of 5.1 bugs to 5.2. -- YP bug review (Randy)</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>101834</commentid>
    <comment_count>6</comment_count>
    <who name="Randy MacLeod">randy.macleod</who>
    <bug_when>2025-05-01 14:07:10 +0000</bug_when>
    <thetext>Bulk move of all unassigned 5.2 medium importance bugs to 5.3.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>103947</commentid>
    <comment_count>7</comment_count>
    <who name="Colin McAllister">colinmca242</who>
    <bug_when>2026-01-16 14:39:48 +0000</bug_when>
    <thetext>As of Python cryptography 45.0.0 it appears that there&apos;s a build-time environment variable, CRYPTOGRAPHY_BUILD_OPENSSL_NO_LEGACY, that can be used to prevent the library from ever attempting to load the legacy provider.

https://github.com/pyca/cryptography/commit/ddc364d28b480010f527c9838906992a27d4b55a

It does seem like this commit also &quot;fixes&quot; the issue somewhat where this runtime exception is now downgraded to a warning.

To Tim&apos;s point, could a PACKAGECONFIG option be added that enables legacy functionality, but otherwise sets this build time environment variable?

It&apos;s not immediately clear to me what changes are necessary on the openssl side. I do see the openssl-ossl-module-legacy package provided by openssl. I assume the PACKAGECONFIG option would need to rdepend on this? I&apos;m not quite sure what to do about what Ross mentioned where the OPENSSL_MODULES environment variable needs to be exported.

I&apos;m happy to pick up this bug and ensure that it gets closed out.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104039</commentid>
    <comment_count>8</comment_count>
    <who name="Colin McAllister">colinmca242</who>
    <bug_when>2026-01-22 16:32:56 +0000</bug_when>
    <thetext>After looking into this a bit more, I think this defect can be closed out on it&apos;s own since 45.0.0 downgraded this warning to an exception and python3-cryptography was upgraded to 45.0.7 in Whinlatter.

However, I think there&apos;s still room for improvement, so I sent in a proposal last night for a PACKAGECONFIG option to enable/disable legacy-openssl support.

https://lists.openembedded.org/g/openembedded-core/topic/patch_python3_cryptography/117394116

This option specifies a runtime dependency for the openssl-ossl-module-legacy module, which didn&apos;t exist and also uses the CRYPTOGRAPHY_BUILD_OPENSSL_NO_LEGACY build time environment variable to disable legacy support if the PACKAGECONFIG option is disabled.

To keep forwards compatibility and not introduce any breaking changes, I left this PACKAGECONFIG option enabled, but it could also be disabled by default as that is the more secure configuration. However, that could cause breaking issues for those currently using the OpenSSL legacy module.

I&apos;m not sure about a better solution for the native openssl modules path, other than what Ross is doing with exporting OPENSSL_MODULES. If anyone thinks that&apos;s worthy of a separate bug that requires a better solution, please let me know.</thetext>
  </long_desc><long_desc isprivate="0" >
    <commentid>104228</commentid>
    <comment_count>9</comment_count>
    <who name="Colin McAllister">colinmca242</who>
    <bug_when>2026-02-11 14:09:52 +0000</bug_when>
    <thetext>Fixed by:
https://git.openembedded.org/openembedded-core/commit/?id=c3c612608d816eb6b40575a86e0907701cf525dc
and
https://git.openembedded.org/openembedded-core/commit/?id=96548d97cbad4c125cdc07aa21182390513ca2c6

As noted in my previous comments, the assert was downgraded to a warning in python3-cryptography v45.0.0. However, the second change linked above sets the build-time environment variable to explicitly disable legacy support if the legacy packageconfig option is not set. This ensures the warning will not be shown if legacy support is not intended to be used and is not included.

As noted in the ML, the legacy packageconfig option is enabled by default to preserve current behavior, but will be disabled by default once OpenSSL is disables the legacy module by default.</thetext>
  </long_desc>
      
      

    </bug>

</bugzilla>