[opensuse-factory] factory apache2 2.2.17-5.1 no more start SSL error
After zypper up on factory I've now a none working apache2 with SSL apache2 is dated from Feb 20 rcapache2 restart httpd2-prefork: Syntax error on line 116 of /etc/apache2/httpd.conf: Syntax error on line 53 of /etc/apache2/sysconfig.d/loadmodule.conf: Cannot load /usr/lib64/apache2-prefork/mod_ssl.so into server: /usr/lib64/apache2-prefork/mod_ssl.so: undefined symbol: SSLv2_client_method ldd /usr/lib64/apache2-prefork/mod_ssl.so linux-vdso.so.1 => (0x00007ffff4583000) libssl.so.1.0.0 => /lib64/libssl.so.1.0.0 (0x00007f7694a09000) libcrypto.so.1.0.0 => /lib64/libcrypto.so.1.0.0 (0x00007f7694658000) libpthread.so.0 => /lib64/libpthread.so.0 (0x00007f769443a000) libc.so.6 => /lib64/libc.so.6 (0x00007f76940cd000) libdl.so.2 => /lib64/libdl.so.2 (0x00007f7693ec9000) libz.so.1 => /lib64/libz.so.1 (0x00007f7693cb0000) /lib64/ld-linux-x86-64.so.2 (0x00007f7694ed1000) Did someone forget to rebuild after openssl-1.0.0d-21.1.x86_64.rpm update (dated Apr 15) ? -- Bruno Friedmann Ioda-Net Sàrl www.ioda-net.ch openSUSE Member & Ambassador GPG KEY : D5C9B751C4653227 irc: tigerfoot -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
On 04/17/2011 11:03 AM, Bruno Friedmann wrote:
After zypper up on factory I've now a none working apache2 with SSL apache2 is dated from Feb 20
rcapache2 restart httpd2-prefork: Syntax error on line 116 of /etc/apache2/httpd.conf: Syntax error on line 53 of /etc/apache2/sysconfig.d/loadmodule.conf: Cannot load /usr/lib64/apache2-prefork/mod_ssl.so into server: /usr/lib64/apache2-prefork/mod_ssl.so: undefined symbol: SSLv2_client_method
ldd /usr/lib64/apache2-prefork/mod_ssl.so linux-vdso.so.1 => (0x00007ffff4583000) libssl.so.1.0.0 => /lib64/libssl.so.1.0.0 (0x00007f7694a09000) libcrypto.so.1.0.0 => /lib64/libcrypto.so.1.0.0 (0x00007f7694658000) libpthread.so.0 => /lib64/libpthread.so.0 (0x00007f769443a000) libc.so.6 => /lib64/libc.so.6 (0x00007f76940cd000) libdl.so.2 => /lib64/libdl.so.2 (0x00007f7693ec9000) libz.so.1 => /lib64/libz.so.1 (0x00007f7693cb0000) /lib64/ld-linux-x86-64.so.2 (0x00007f7694ed1000)
Did someone forget to rebuild after openssl-1.0.0d-21.1.x86_64.rpm update (dated Apr 15) ?
Found https://bugzilla.novell.com/show_bug.cgi?id=688009 -- Bruno Friedmann Ioda-Net Sàrl www.ioda-net.ch openSUSE Member & Ambassador GPG KEY : D5C9B751C4653227 irc: tigerfoot -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
On Sun, Apr 17, 2011 at 11:07:58AM +0200, Bruno Friedmann wrote:
On 04/17/2011 11:03 AM, Bruno Friedmann wrote:
After zypper up on factory I've now a none working apache2 with SSL apache2 is dated from Feb 20
rcapache2 restart httpd2-prefork: Syntax error on line 116 of /etc/apache2/httpd.conf: Syntax error on line 53 of /etc/apache2/sysconfig.d/loadmodule.conf: Cannot load /usr/lib64/apache2-prefork/mod_ssl.so into server: /usr/lib64/apache2-prefork/mod_ssl.so: undefined symbol: SSLv2_client_method
ldd /usr/lib64/apache2-prefork/mod_ssl.so linux-vdso.so.1 => (0x00007ffff4583000) libssl.so.1.0.0 => /lib64/libssl.so.1.0.0 (0x00007f7694a09000) libcrypto.so.1.0.0 => /lib64/libcrypto.so.1.0.0 (0x00007f7694658000) libpthread.so.0 => /lib64/libpthread.so.0 (0x00007f769443a000) libc.so.6 => /lib64/libc.so.6 (0x00007f76940cd000) libdl.so.2 => /lib64/libdl.so.2 (0x00007f7693ec9000) libz.so.1 => /lib64/libz.so.1 (0x00007f7693cb0000) /lib64/ld-linux-x86-64.so.2 (0x00007f7694ed1000)
Did someone forget to rebuild after openssl-1.0.0d-21.1.x86_64.rpm update (dated Apr 15) ?
This change should not have been introduced without warning. openssl should be reverted until the packages are fixed. Ciao, MArcus -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
El 17/04/11 06:50, Marcus Meissner escribió:
On Sun, Apr 17, 2011 at 11:07:58AM +0200, Bruno Friedmann wrote:
On 04/17/2011 11:03 AM, Bruno Friedmann wrote:
After zypper up on factory I've now a none working apache2 with SSL apache2 is dated from Feb 20
rcapache2 restart httpd2-prefork: Syntax error on line 116 of /etc/apache2/httpd.conf: Syntax error on line 53 of /etc/apache2/sysconfig.d/loadmodule.conf: Cannot load /usr/lib64/apache2-prefork/mod_ssl.so into server: /usr/lib64/apache2-prefork/mod_ssl.so: undefined symbol: SSLv2_client_method
ldd /usr/lib64/apache2-prefork/mod_ssl.so linux-vdso.so.1 => (0x00007ffff4583000) libssl.so.1.0.0 => /lib64/libssl.so.1.0.0 (0x00007f7694a09000) libcrypto.so.1.0.0 => /lib64/libcrypto.so.1.0.0 (0x00007f7694658000) libpthread.so.0 => /lib64/libpthread.so.0 (0x00007f769443a000) libc.so.6 => /lib64/libc.so.6 (0x00007f76940cd000) libdl.so.2 => /lib64/libdl.so.2 (0x00007f7693ec9000) libz.so.1 => /lib64/libz.so.1 (0x00007f7693cb0000) /lib64/ld-linux-x86-64.so.2 (0x00007f7694ed1000)
Did someone forget to rebuild after openssl-1.0.0d-21.1.x86_64.rpm update (dated Apr 15) ?
I fixed This particular package has been fixed around a week ago.
This change should not have been introduced without warning.
openssl should be reverted until the packages are fixed.
Sigh, I have fixed and upstreamed all changes to most important components, so it doesnt break anything major, but some has not been checked in yet either for bogus reasons or simple submit requests have been ignored. -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
On Sun, Apr 17, 2011 at 10:44:00AM -0300, Cristian Rodríguez wrote:
El 17/04/11 06:50, Marcus Meissner escribió:
On Sun, Apr 17, 2011 at 11:07:58AM +0200, Bruno Friedmann wrote:
On 04/17/2011 11:03 AM, Bruno Friedmann wrote:
After zypper up on factory I've now a none working apache2 with SSL apache2 is dated from Feb 20
rcapache2 restart httpd2-prefork: Syntax error on line 116 of /etc/apache2/httpd.conf: Syntax error on line 53 of /etc/apache2/sysconfig.d/loadmodule.conf: Cannot load /usr/lib64/apache2-prefork/mod_ssl.so into server: /usr/lib64/apache2-prefork/mod_ssl.so: undefined symbol: SSLv2_client_method
ldd /usr/lib64/apache2-prefork/mod_ssl.so linux-vdso.so.1 => (0x00007ffff4583000) libssl.so.1.0.0 => /lib64/libssl.so.1.0.0 (0x00007f7694a09000) libcrypto.so.1.0.0 => /lib64/libcrypto.so.1.0.0 (0x00007f7694658000) libpthread.so.0 => /lib64/libpthread.so.0 (0x00007f769443a000) libc.so.6 => /lib64/libc.so.6 (0x00007f76940cd000) libdl.so.2 => /lib64/libdl.so.2 (0x00007f7693ec9000) libz.so.1 => /lib64/libz.so.1 (0x00007f7693cb0000) /lib64/ld-linux-x86-64.so.2 (0x00007f7694ed1000)
Did someone forget to rebuild after openssl-1.0.0d-21.1.x86_64.rpm update (dated Apr 15) ?
I fixed This particular package has been fixed around a week ago.
This change should not have been introduced without warning.
openssl should be reverted until the packages are fixed.
Sigh, I have fixed and upstreamed all changes to most important components, so it doesnt break anything major, but some has not been checked in yet either for bogus reasons or simple submit requests have been ignored.
If all packages are in the queue... then I guess it is fine. Hmm, what if a client still needs to talk SSLv2 with very old and rusty servers? Ciao, Marcus -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
Marcus Meissner wrote:
If all packages are in the queue... then I guess it is fine.
Hmm, what if a client still needs to talk SSLv2 with very old and rusty servers?
That would be broken and after 15 years very unlikely. However, I'm not sure dropping the symbol entirely is a good idea. It's breaking the ABI after all. Adding __attribute__ ((deprecated)) for a while would be safer. cu Ludwig -- (o_ Ludwig Nussel //\ V_/_ http://www.suse.de/ SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg) -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
El 18/04/11 04:31, Ludwig Nussel escribió:
Marcus Meissner wrote:
If all packages are in the queue... then I guess it is fine.
Hmm, what if a client still needs to talk SSLv2 with very old and rusty servers?
That would be broken and after 15 years very unlikely. However, I'm not sure dropping the symbol entirely is a good idea. It's breaking the ABI after all. Adding __attribute__ ((deprecated)) for a while would be safer.
Dropping the symbol is the upstream behaviour, and what other distributions have also adopted. -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
Cristian Rodríguez wrote:
El 18/04/11 04:31, Ludwig Nussel escribió:
Marcus Meissner wrote:
If all packages are in the queue... then I guess it is fine.
Hmm, what if a client still needs to talk SSLv2 with very old and rusty servers?
That would be broken and after 15 years very unlikely. However, I'm not sure dropping the symbol entirely is a good idea. It's breaking the ABI after all. Adding __attribute__ ((deprecated)) for a while would be safer.
Dropping the symbol is the upstream behaviour, and what other distributions have also adopted.
Debian did it only very recently in their unstable release. So it's no surprise applications are not prepared for it yet. I still think removing a symbol from a library that is supposed to be stable is a bad idea. We certainly should patch out SSLv2 from applications but removing the symbol without changing soname is evil. After all glibc still has gets() ... cu Ludwig -- (o_ Ludwig Nussel //\ V_/_ http://www.suse.de/ SUSE LINUX Products GmbH, GF: Markus Rex, HRB 16746 (AG Nuernberg) -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
On Sun, 17 Apr 2011 11:03:51 +0200
Bruno Friedmann
After zypper up on factory I've now a none working apache2 with SSL apache2 is dated from Feb 20
virt-manager: seife@susi:~> virt-manager Traceback (most recent call last): File "/usr/share/virt-manager/virt-manager.py", line 26, in <module> import libvirt File "/usr/lib64/python2.7/site-packages/libvirt.py", line 30, in <module> raise lib_e ImportError: /usr/lib64/libcurl.so.4: undefined symbol: SSLv2_client_method for now it's easily fixed by downgrading to libopenssl1_0_0-1.0.0c-21.1 from factory-tested. -- Stefan Seyfried "Dispatch war rocket Ajax to bring back his body!" -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
On 04/18/2011 10:26 AM, Stefan Seyfried wrote:
On Sun, 17 Apr 2011 11:03:51 +0200 Bruno Friedmann
wrote: After zypper up on factory I've now a none working apache2 with SSL apache2 is dated from Feb 20
virt-manager:
seife@susi:~> virt-manager Traceback (most recent call last): File "/usr/share/virt-manager/virt-manager.py", line 26, in <module> import libvirt File "/usr/lib64/python2.7/site-packages/libvirt.py", line 30, in <module> raise lib_e ImportError: /usr/lib64/libcurl.so.4: undefined symbol: SSLv2_client_method
for now it's easily fixed by downgrading to libopenssl1_0_0-1.0.0c-21.1 from factory-tested.
I've updated https://bugzilla.novell.com/show_bug.cgi?id=688010 this morning there's more & more software & libs that are affected. So if we can have quickly back a working factory, thanks. -- Bruno Friedmann Ioda-Net Sàrl www.ioda-net.ch openSUSE Member & Ambassador GPG KEY : D5C9B751C4653227 irc: tigerfoot -- To unsubscribe, e-mail: opensuse-factory+unsubscribe@opensuse.org For additional commands, e-mail: opensuse-factory+help@opensuse.org
participants (5)
-
Bruno Friedmann
-
Cristian Rodríguez
-
Ludwig Nussel
-
Marcus Meissner
-
Stefan Seyfried