Buildroot Archive on lore.kernel.org
 help / color / mirror / Atom feed
* [Buildroot] [PATCH] package/openssh: enable DES when using libopenssl
@ 2026-07-27 10:07 Jimmy Durand Wesolowski via buildroot
  2026-07-28 20:42 ` Peter Korsgaard
  2026-08-31 16:09 ` [Buildroot] [PATCH] openssh: ensure libxcrypt is enabled to provide a crypt() implementation Jimmy Durand Wesolowski via buildroot
  0 siblings, 2 replies; 6+ messages in thread
From: Jimmy Durand Wesolowski via buildroot @ 2026-07-27 10:07 UTC (permalink / raw)
  To: buildroot; +Cc: guenther.harrasser, Jimmy Durand Wesolowski

When the OpenSSL library is selected (instead of LibreSSL), OpenSSH needs
DES to be enabled, even if all the other encryption algorithms are enabled
(except MDC2 that depends on DES).

If disabled, libopenbsd-compat "xcrypt" function will require crypt (in
place of DES_crypt), and any linking against it will fail:

.../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o
  auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o
  servconf.o serverloop.o auth.o auth2.o auth-options.o session.o
  auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o
  auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o
  auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o
  monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o
  platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o
  sandbox-null.o sandbox-rlimit.o sandbox-darwin.o
  sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o
  sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o
  ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE
  -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0
  -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack
  -fstack-protector-strong -pie -lssh -lopenbsd-compat
  -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib
  -lssl -lcrypto -lcrypto -lz
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
  openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt'
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error:
ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error
1 make[2]: *** Waiting for unfinished jobs....  collect2: error: ld
returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error
1 make[1]: *** [package/pkg-generic.mk:273:
.../build/openssh-10.4p1/.stamp_built]
Error 2 make: *** [Makefile:83: _all] Error 2

Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com>
---
 package/openssh/Config.in | 1 +
 1 file changed, 1 insertion(+)

diff --git a/package/openssh/Config.in b/package/openssh/Config.in
index 25843447a7..06aadbbc52 100644
--- a/package/openssh/Config.in
+++ b/package/openssh/Config.in
@@ -2,6 +2,7 @@ config BR2_PACKAGE_OPENSSH
 	bool "openssh"
 	depends on BR2_USE_MMU # fork()
 	select BR2_PACKAGE_OPENSSL
+	select BR2_PACKAGE_LIBOPENSSL_ENABLE_DES if BR2_PACKAGE_LIBOPENSSL
 	select BR2_PACKAGE_ZLIB
 	help
 	  A free version of the SSH protocol suite of network
-- 
2.55.0

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [Buildroot] [PATCH] package/openssh: enable DES when using libopenssl
  2026-07-27 10:07 [Buildroot] [PATCH] package/openssh: enable DES when using libopenssl Jimmy Durand Wesolowski via buildroot
@ 2026-07-28 20:42 ` Peter Korsgaard
  2026-08-21 12:38   ` Thomas Petazzoni via buildroot
  2026-08-31 16:09 ` [Buildroot] [PATCH] openssh: ensure libxcrypt is enabled to provide a crypt() implementation Jimmy Durand Wesolowski via buildroot
  1 sibling, 1 reply; 6+ messages in thread
From: Peter Korsgaard @ 2026-07-28 20:42 UTC (permalink / raw)
  To: Jimmy Durand Wesolowski via buildroot, romain.naour
  Cc: Jimmy Durand Wesolowski, guenther.harrasser

>>>>> "Jimmy" == Jimmy Durand Wesolowski via buildroot <buildroot@buildroot.org> writes:

 > When the OpenSSL library is selected (instead of LibreSSL), OpenSSH needs
 > DES to be enabled, even if all the other encryption algorithms are enabled
 > (except MDC2 that depends on DES).

 > If disabled, libopenbsd-compat "xcrypt" function will require crypt (in
 > place of DES_crypt), and any linking against it will fail:

 > .../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o
 >   auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o
 >   servconf.o serverloop.o auth.o auth2.o auth-options.o session.o
 >   auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o
 >   auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o
 >   auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o
 >   monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o
 >   platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o
 >   sandbox-null.o sandbox-rlimit.o sandbox-darwin.o
 >   sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o
 >   sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o
 >   ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE
 >   -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0
 >   -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack
 >   -fstack-protector-strong -pie -lssh -lopenbsd-compat
 >   -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib
 >   -lssl -lcrypto -lcrypto -lz
 > .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
 >   i686-buildroot-linux-gnu/bin/ld:
 >   openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
 > xcrypt.c:(.text+0x51): undefined reference to `crypt'
 > .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
 >   i686-buildroot-linux-gnu/bin/ld:
 > openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
 > xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error:
 > ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error
 > 1 make[2]: *** Waiting for unfinished jobs....  collect2: error: ld
 > returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error
 > 1 make[1]: *** [package/pkg-generic.mk:273:
 > .../build/openssh-10.4p1/.stamp_built]
 > Error 2 make: *** [Makefile:83: _all] Error 2

 > Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com>

Hmm, with what configuration is this? Presumably not one where
BR2_PACKAGE_OPENSSH_SERVER is enabled, as that pulls in libxcrypt on
glibc?

Given the description in the commit adding the libxcrypt select, perhaps
that select should instead be moved to the the toplevel openssh symbol?

commit dd244feb37fff29620a09ee96b4006cf7d558380
Author: Romain Naour <romain.naour@smile.fr>
Date:   Thu Apr 18 12:15:29 2024 +0200

    package/openssh: add libxcrypt optional dependency for sshd

    When glibc was bumped to version 2.39 in commit
    b5680f53d60acf8ff6010082f873438a39bd5d97 it removed the deprecated
    libcrypt support.

    As glibc's libcrypt was providing sshd's libcrypt dependency this broke
    the sshd password authentification at runtime using glibc version 2.39.

      # sshpass -p testpwd ssh -oStrictHostKeyChecking=no localhost /bin/true
      Permission denied, please try again.

    Without libcrypt, OpenSSH >= 6.2 fall back to using openssl's DES_crypt
    function on platorms that don't have a native crypt() function [1].

    Note that DES_crypt is deprecated since openssl 3.0 [2] [3].

    "Use of the low level DES functions has been informally discouraged for a
     long time. We now formally deprecate them.

     Applications should instead use the EVP APIs, e.g. EVP_EncryptInit_ex,
     EVP_EncryptUpdate, EVP_EncryptFinal_ex, and the equivalently named decrypt
     functions."

    Also DES_crypt is provided by openssl only if
    BR2_PACKAGE_LIBOPENSSL_ENABLE_DES is enabled. Otherwise crypt() is
    never defined:

      sd-compat.a(xcrypt.o): in function `xcrypt':
      xcrypt.c:(.text+0x48): undefined reference to `crypt'

    It's not clear why the password authentification fail with openssl's
    DES_crypt but since it's deprecated we use libxcrypt to provide
    a working crypt() function for glibc based toolchains.

    [1] https://github.com/openssh/openssh-portable/blob/V_9_7/openbsd-compat/xcrypt.c#L57
    [2] https://github.com/openssl/openssl/commit/c6fec81b88131d08c1022504ccf6effa95497afb
    [3] https://www.openssl.org/docs/man3.2/man3/DES_crypt.html

    Fixes:
    https://gitlab.com/buildroot.org/buildroot/-/jobs/6623402147

    Signed-off-by: Romain Naour <romain.naour@smile.fr>

-- 
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [Buildroot] [PATCH] package/openssh: enable DES when using libopenssl
  2026-07-28 20:42 ` Peter Korsgaard
@ 2026-08-21 12:38   ` Thomas Petazzoni via buildroot
  2026-08-21 14:44     ` Peter Korsgaard
  0 siblings, 1 reply; 6+ messages in thread
From: Thomas Petazzoni via buildroot @ 2026-08-21 12:38 UTC (permalink / raw)
  To: Peter Korsgaard
  Cc: Jimmy Durand Wesolowski via buildroot, romain.naour,
	Jimmy Durand Wesolowski, guenther.harrasser

Hello Jimmy, Hello Peter,

On Tue, Jul 28, 2026 at 10:42:20PM +0200, Peter Korsgaard wrote:

>  > Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com>
> 
> Hmm, with what configuration is this? Presumably not one where
> BR2_PACKAGE_OPENSSH_SERVER is enabled, as that pulls in libxcrypt on
> glibc?

Issue can be reproduced with:

  BR2_aarch64=y
  BR2_TOOLCHAIN_EXTERNAL=y
  BR2_TOOLCHAIN_EXTERNAL_BOOTLIN=y
  BR2_TOOLCHAIN_EXTERNAL_BOOTLIN_AARCH64_GLIBC_STABLE=y
  BR2_INIT_NONE=y
  BR2_SYSTEM_BIN_SH_NONE=y
  # BR2_PACKAGE_BUSYBOX is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_CHACHA is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_RC2 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_RC4 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_MD2 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_MD4 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_MDC2 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_BLAKE2 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_IDEA is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_SEED is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_DES is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_RMD160 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_WHIRLPOOL is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_BLOWFISH is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_SSL is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_SSL3 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_WEAK_SSL is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_PSK is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_CAST is not set
  # BR2_PACKAGE_LIBOPENSSL_UNSECURE is not set
  # BR2_PACKAGE_LIBOPENSSL_DYNAMIC_ENGINE is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_COMP is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_ARGON2 is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_CACHED_FETCH is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_CMP is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_THREAD_POOL is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_ECX is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_PADLOCK_ENGINE is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_MODULE is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_QUIC is not set
  # BR2_PACKAGE_LIBOPENSSL_SECURE_MEMORY is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_SIV is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_SM2_PRECOMP_TABLE is not set
  # BR2_PACKAGE_LIBOPENSSL_ENABLE_SSL_TRACE is not set
  BR2_PACKAGE_OPENSSH=y
  # BR2_PACKAGE_OPENSSH_SERVER is not set
  # BR2_PACKAGE_OPENSSH_KEY_UTILS is not set
  # BR2_PACKAGE_OPENSSH_SANDBOX is not set
  # BR2_TARGET_ROOTFS_TAR is not set

So basically, OpenSSH enabled, client only (since enabling the server
would pull in libxcrypt) and disabling all OpenSSL sub-options.

The code in OpenSSH goes like this:

# if defined(WITH_OPENSSL) && !defined(HAVE_CRYPT) && defined(HAVE_DES_CRYPT)
#  include <openssl/des.h>
#  define crypt DES_crypt
# endif

So basically, the idea is that if we have OpenSSL, we don't have
crypt(), but we have DES_crypt, then we use DES_crypt() as
crypt(). Otherwise, the crypt() call in the OpenSSH xcrypt() function
remains crypt(), and things blow up when you're building with glibc
and you don't have libxcrypt around to provide crypt().

So indeed, we have two options here:

- Always provide a crypt() implementation by making libxcrypt
  mandatory for OpenSSH as a whole, not just for the server-side

- Require OpenSSH to provide DES support, which is what Jimmy was
  proposing.

I honestly don't have a strong argument. My vague feeling is that DES
being obsolete, it feels odd to be forced to enable it. Though perhaps
libxcrypt would in fact provide exactly the same obsolete crypto
algorithm?

Peter: thoughts?

Thomas
-- 
Thomas Petazzoni, co-owner and CEO, Bootlin
Embedded Linux and Kernel engineering and training
https://bootlin.com
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 6+ messages in thread

* Re: [Buildroot] [PATCH] package/openssh: enable DES when using libopenssl
  2026-08-21 12:38   ` Thomas Petazzoni via buildroot
@ 2026-08-21 14:44     ` Peter Korsgaard
  0 siblings, 0 replies; 6+ messages in thread
From: Peter Korsgaard @ 2026-08-21 14:44 UTC (permalink / raw)
  To: Thomas Petazzoni
  Cc: Jimmy Durand Wesolowski via buildroot, romain.naour,
	Jimmy Durand Wesolowski, guenther.harrasser

>>>>> "Thomas" == Thomas Petazzoni <thomas.petazzoni@bootlin.com> writes:

Hi,

 > So basically, the idea is that if we have OpenSSL, we don't have
 > crypt(), but we have DES_crypt, then we use DES_crypt() as
 > crypt(). Otherwise, the crypt() call in the OpenSSH xcrypt() function
 > remains crypt(), and things blow up when you're building with glibc
 > and you don't have libxcrypt around to provide crypt().

 > So indeed, we have two options here:

 > - Always provide a crypt() implementation by making libxcrypt
 >   mandatory for OpenSSH as a whole, not just for the server-side

 > - Require OpenSSH to provide DES support, which is what Jimmy was
 >   proposing.

 > I honestly don't have a strong argument. My vague feeling is that DES
 > being obsolete, it feels odd to be forced to enable it. Though perhaps
 > libxcrypt would in fact provide exactly the same obsolete crypto
 > algorithm?

 > Peter: thoughts?

I am not sure what openssh uses crypt() for exactly when the server is
not built, but perhaps it just ends up building a bit too much?

Anyway, given that we already use libxcrypt for the server part and
libxcrypt supports a bunch of other algorithmns than just legacy DES, I
think it makes sense to just move the libxcrypt select to the main
option instead.

-- 
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 6+ messages in thread

* [Buildroot] [PATCH] openssh: ensure libxcrypt is enabled to provide a crypt() implementation
  2026-07-27 10:07 [Buildroot] [PATCH] package/openssh: enable DES when using libopenssl Jimmy Durand Wesolowski via buildroot
  2026-07-28 20:42 ` Peter Korsgaard
@ 2026-08-31 16:09 ` Jimmy Durand Wesolowski via buildroot
  2026-08-31 19:10   ` Peter Korsgaard
  1 sibling, 1 reply; 6+ messages in thread
From: Jimmy Durand Wesolowski via buildroot @ 2026-08-31 16:09 UTC (permalink / raw)
  To: buildroot; +Cc: guenther.harrasser, Jimmy Durand Wesolowski

When OpenSSL is enabled, if DES support is enabled, OpenSSH uses
DES_crypt. However, without OpenSSL or its DES support, there is no
available crypt() implementation for OpenSSH libopenbsd-compat xcrypt()
function, resulting in the following error:

.../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o
  auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o
  servconf.o serverloop.o auth.o auth2.o auth-options.o session.o
  auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o
  auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o
  auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o
  monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o
  platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o
  sandbox-null.o sandbox-rlimit.o sandbox-darwin.o
  sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o
  sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o
  ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE
  -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0
  -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack
  -fstack-protector-strong -pie -lssh -lopenbsd-compat
  -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib
  -lssl -lcrypto -lcrypto -lz
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
  openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt'
.../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
  i686-buildroot-linux-gnu/bin/ld:
openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error:
ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error
1 make[2]: *** Waiting for unfinished jobs....  collect2: error: ld
returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error
1 make[1]: *** [package/pkg-generic.mk:273:
.../build/openssh-10.4p1/.stamp_built]
Error 2 make: *** [Makefile:83: _all] Error 2

This commit enables BR2_PACKAGE_LIBXCRYPT with OpenSSH as long as the
glibc is used. Since "sshd-auth" is compiled regardless of
BR2_PACKAGE_OPENSSH_SERVER, we need to enable it with BR2_PACKAGE_OPENSSH.

Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com>
---
 package/openssh/Config.in  | 2 +-
 package/openssh/openssh.mk | 2 +-
 2 files changed, 2 insertions(+), 2 deletions(-)

diff --git a/package/openssh/Config.in b/package/openssh/Config.in
index 25843447a7..3b0adad63d 100644
--- a/package/openssh/Config.in
+++ b/package/openssh/Config.in
@@ -3,6 +3,7 @@ config BR2_PACKAGE_OPENSSH
 	depends on BR2_USE_MMU # fork()
 	select BR2_PACKAGE_OPENSSL
 	select BR2_PACKAGE_ZLIB
+	select BR2_PACKAGE_LIBXCRYPT if BR2_TOOLCHAIN_USES_GLIBC
 	help
 	  A free version of the SSH protocol suite of network
 	  connectivity tools. The standard 'ssh', 'sshd', 'scp', and
@@ -22,7 +23,6 @@ config BR2_PACKAGE_OPENSSH_CLIENT
 config BR2_PACKAGE_OPENSSH_SERVER
 	bool "server"
 	default y
-	select BR2_PACKAGE_LIBXCRYPT if BR2_TOOLCHAIN_USES_GLIBC
 	help
 	  Server programs: sshd, sftp-server
 
diff --git a/package/openssh/openssh.mk b/package/openssh/openssh.mk
index dd0a6e023e..f2e1f235c0 100644
--- a/package/openssh/openssh.mk
+++ b/package/openssh/openssh.mk
@@ -51,7 +51,7 @@ endif
 OPENSSH_DEPENDENCIES = host-pkgconf zlib openssl
 
 # crypt() in libcrypt only required for sshd.
-ifeq ($(BR2_PACKAGE_OPENSSH_SERVER)$(BR2_PACKAGE_LIBXCRYPT),yy)
+ifeq ($(BR2_PACKAGE_LIBXCRYPT),y)
 OPENSSH_DEPENDENCIES += libxcrypt
 endif
 
-- 
2.55.0

_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply related	[flat|nested] 6+ messages in thread

* Re: [Buildroot] [PATCH] openssh: ensure libxcrypt is enabled to provide a crypt() implementation
  2026-08-31 16:09 ` [Buildroot] [PATCH] openssh: ensure libxcrypt is enabled to provide a crypt() implementation Jimmy Durand Wesolowski via buildroot
@ 2026-08-31 19:10   ` Peter Korsgaard
  0 siblings, 0 replies; 6+ messages in thread
From: Peter Korsgaard @ 2026-08-31 19:10 UTC (permalink / raw)
  To: Jimmy Durand Wesolowski via buildroot
  Cc: Jimmy Durand Wesolowski, guenther.harrasser

>>>>> "Jimmy" == Jimmy Durand Wesolowski via buildroot <buildroot@buildroot.org> writes:

 > When OpenSSL is enabled, if DES support is enabled, OpenSSH uses
 > DES_crypt. However, without OpenSSL or its DES support, there is no
 > available crypt() implementation for OpenSSH libopenbsd-compat xcrypt()
 > function, resulting in the following error:

 > .../host/bin/i686-buildroot-linux-gnu-gcc -o sshd-auth sshd-auth.o
 >   auth2-methods.o auth-rhosts.o auth-passwd.o sshpty.o sshlogin.o
 >   servconf.o serverloop.o auth.o auth2.o auth-options.o session.o
 >   auth2-chall.o groupaccess.o auth-bsdauth.o auth2-hostbased.o
 >   auth2-kbdint.o auth2-none.o auth2-passwd.o auth2-pubkey.o
 >   auth2-pubkeyfile.o auth2-gss.o gss-serv.o gss-serv-krb5.o
 >   monitor_wrap.o auth-krb5.o audit.o audit-bsm.o audit-linux.o
 >   platform.o loginrec.o auth-pam.o auth-shadow.o auth-sia.o
 >   sandbox-null.o sandbox-rlimit.o sandbox-darwin.o
 >   sandbox-seccomp-filter.o sandbox-capsicum.o sandbox-solaris.o
 >   sftp-server.o sftp-common.o uidswap.o ssh-pkcs11-client.o
 >   ssh-sk-client.o -L. -Lopenbsd-compat/ -D_LARGEFILE_SOURCE
 >   -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -O2 -g0
 >   -D_FORTIFY_SOURCE=1 -Wl,-z,relro -Wl,-z,now -Wl,-z,noexecstack
 >   -fstack-protector-strong -pie -lssh -lopenbsd-compat
 >   -L.../host/bin/../i686-buildroot-linux-gnu/sysroot/usr/lib
 >   -lssl -lcrypto -lcrypto -lz
 > .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
 >   i686-buildroot-linux-gnu/bin/ld:
 >   openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
 > xcrypt.c:(.text+0x51): undefined reference to `crypt'
 > .../host/lib/gcc/i686-buildroot-linux-gnu/15.3.0/../../../../
 >   i686-buildroot-linux-gnu/bin/ld:
 > openbsd-compat//libopenbsd-compat.a(xcrypt.o): in function `xcrypt':
 > xcrypt.c:(.text+0x51): undefined reference to `crypt' collect2: error:
 > ld returned 1 exit status make[2]: *** [Makefile:233: sshd-auth] Error
 > 1 make[2]: *** Waiting for unfinished jobs....  collect2: error: ld
 > returned 1 exit status make[2]: *** [Makefile:230: sshd-session] Error
 > 1 make[1]: *** [package/pkg-generic.mk:273:
 > .../build/openssh-10.4p1/.stamp_built]
 > Error 2 make: *** [Makefile:83: _all] Error 2

 > This commit enables BR2_PACKAGE_LIBXCRYPT with OpenSSH as long as the
 > glibc is used. Since "sshd-auth" is compiled regardless of
 > BR2_PACKAGE_OPENSSH_SERVER, we need to enable it with BR2_PACKAGE_OPENSSH.

 > Signed-off-by: Jimmy Durand Wesolowski <jimmy.wesolowski@mobileye.com>

Committed, thanks.

-- 
Bye, Peter Korsgaard
_______________________________________________
buildroot mailing list
buildroot@buildroot.org
https://lists.buildroot.org/mailman/listinfo/buildroot

^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-08-31 19:11 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-27 10:07 [Buildroot] [PATCH] package/openssh: enable DES when using libopenssl Jimmy Durand Wesolowski via buildroot
2026-07-28 20:42 ` Peter Korsgaard
2026-08-21 12:38   ` Thomas Petazzoni via buildroot
2026-08-21 14:44     ` Peter Korsgaard
2026-08-31 16:09 ` [Buildroot] [PATCH] openssh: ensure libxcrypt is enabled to provide a crypt() implementation Jimmy Durand Wesolowski via buildroot
2026-08-31 19:10   ` Peter Korsgaard

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox