AI-generated analysisPublished automatically and not human-verified. Validated context appears in community notes below.
← Watch feed
Informational 19 Cryptographic libraries

net_ssl: Use EVP API to create EVP_PKEYs when available

Public commit record

What the developer wrote

Authored by jeffro256

78/100 · Adequate
net_ssl: Use EVP API to create EVP_PKEYs when available

The following functions are deprecated in OpenSSL 3.0 and used in net_ssl.cpp: `RSA_free`, `EC_KEY_free`, `RSA_new`, `RSA_generate_key_ex`, `EC_KEY_set_group`, `EC_KEY_generate_key`.

Since EVP_RSA_gen was added in OpenSSL 3.0 and since the aforementioned functions were deprecated in OpenSSL 3.0, I check if the OpenSSL version >= 3.0, and use EVP_RSA_gen instead of everything else up to assigning the private key to the certificate in `create_rsa_ssl_certificate`.

I also deleted `create_ec_ssl_certificate` since it wasn't used.
✓ Specific, descriptive subject✓ Names a concrete action or component✓ Provides detailed explanatory context✓ Names security-relevant behavior explicitly
The short version

What changed, and why it matters

This commit updates Monero's SSL certificate generation code to use newer OpenSSL 3.0 APIs instead of older, deprecated ones. It is primarily a compatibility and cleanup change: it replaces low-level RSA key creation with the modern EVP_RSA_gen function when OpenSSL 3.0+ is available, and removes an unused elliptic-curve certificate function. There is no direct security vulnerability being fixed here, but keeping up with current APIs reduces future maintenance risk and avoids deprecation warnings.

Recommended action

Treat as a routine maintenance/refactoring patch. Reviewers should verify that the EVP_RSA_gen path is exercised in OpenSSL 3.0 builds and that the legacy fallback still works on OpenSSL 1.1.x, but no urgent security response is warranted.

Security signals we found

01

Migration from deprecated OpenSSL low-level key APIs to EVP API

02

Removal of unused EC certificate generation code

03

No explicit vulnerability or bug fix described in commit message

04

No change to certificate parameters (still 4096-bit RSA, same validity period, same self-signed SHA-256)

Risk score

Why this scored 19/100

Our methodology →
Potential impact 2/30
Exploitability 1/25
Stealth signal 1/15
Affected reach 3/15
Confidence 8/10
Evidence quality 4/5
Human-validated context

Community notes

Notes can correct, qualify, or add evidence to the AI analysis. Every note shown here has been validated by a human moderator.

No validated notes yet.

The AI analysis stands alone for now. Submit a note if you can add evidence or important context.