From 50dcdc2ee050fb3f66a6fb323debdf0fbdde8faf Mon Sep 17 00:00:00 2001 From: Jun Aruga Date: Fri, 2 Oct 2026 17:48:48 +0100 Subject: [PATCH 1/2] docs: Replace deprecated SSLContext#cert=/key= with add_certificate in example The SSLContext#cert= and #key= methods are deprecated in favor of #add_certificate. Update the SSL server example in ossl.c. Assisted-by: Claude:Opus 4.6 --- ext/openssl/ossl.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) diff --git a/ext/openssl/ossl.c b/ext/openssl/ossl.c index f167ee98f..47bdad79e 100644 --- a/ext/openssl/ossl.c +++ b/ext/openssl/ossl.c @@ -941,8 +941,7 @@ ossl_crypto_fixed_length_secure_compare(VALUE dummy, VALUE str1, VALUE str2) * An \SSL server requires the certificate and private key to communicate * securely with its clients: * - * context.cert = cert - * context.key = key + * context.add_certificate(cert, key) * * After establishing a TCP connection, the socket is wrapped in an * OpenSSL::SSL::SSLSocket with the context. OpenSSL::SSL::SSLSocket#accept From ed62ad4cded40dc9ad51344eab7840c7c7430cd3 Mon Sep 17 00:00:00 2001 From: Jun Aruga Date: Fri, 2 Oct 2026 17:18:52 +0100 Subject: [PATCH 2/2] docs: Replace deprecated SSLServer references with SSLSocket The commit a77ed4b9908e179cea8f018f7e245535301746a8 deprecated SSLServer. Update code examples and the OpenSSL::SSL module description to use SSLSocket and TCPServer instead. Fix OpenSSL::DH.generate to OpenSSL::PKey::DH.generate in the tmp_dh= example. Remove P-224 from #groups= example, as I got an error with P-224 on my local OpenSSL 4.1.0-dev. test.rb ``` require 'openssl' require 'socket' tcp_svr = TCPServer.new('127.0.0.1', 10043) ctx1 = OpenSSL::SSL::SSLContext.new ctx1.groups = "X25519:P-256:P-224" Thread.new { ssl = OpenSSL::SSL::SSLSocket.new(tcp_svr.accept, ctx1) ssl.accept } ``` ``` $ ruby -I lib -r openssl -e 'puts OpenSSL::OPENSSL_VERSION' OpenSSL 4.1.0-dev $ ruby -I ./lib test.rb ... test.rb:9:in 'OpenSSL::SSL::SSLSocket#accept': SSL_accept returned=1 errno=0 peeraddr=127.0.0.1:54616 state=error: no shared cipher (OpenSSL::SSL::SSLError) OpenSSL error queue reported 1 errors: error:0A0000C1:SSL routines:tls_post_process_client_hello:no shared cipher from test.rb:9:in 'block in
' test.rb:16:in 'OpenSSL::SSL::SSLSocket#connect': SSL_connect returned=1 errno=0 peeraddr=127.0.0.1:10043 state=error: tls alert handshake failure (SSL alert number 40) (OpenSSL::SSL::SSLError) OpenSSL error queue reported 1 errors: error:0A000410:SSL routines:ssl3_read_bytes:tls alert handshake failure (SSL alert number 40) from test.rb:16:in '
' ``` Assisted-by: Claude:Opus 4.6 --- ext/openssl/ossl_ssl.c | 22 +++++++++++++--------- 1 file changed, 13 insertions(+), 9 deletions(-) diff --git a/ext/openssl/ossl_ssl.c b/ext/openssl/ossl_ssl.c index f551032b2..ee5a917c1 100644 --- a/ext/openssl/ossl_ssl.c +++ b/ext/openssl/ossl_ssl.c @@ -1178,11 +1178,13 @@ ossl_sslctx_set_client_sigalgs(VALUE self, VALUE v) * * Added in version 3.0. See also the man page SSL_CTX_set0_tmp_dh_pkey(3). * - * Example: + * === Example * ctx = OpenSSL::SSL::SSLContext.new - * ctx.tmp_dh = OpenSSL::DH.generate(2048) - * svr = OpenSSL::SSL::SSLServer.new(tcp_svr, ctx) - * Thread.new { svr.accept } + * ctx.tmp_dh = OpenSSL::PKey::DH.generate(2048) + * Thread.new { + * ssl = OpenSSL::SSL::SSLSocket.new(tcp_svr.accept, ctx) + * ssl.accept + * } */ static VALUE ossl_sslctx_set_tmp_dh(VALUE self, VALUE arg) @@ -1230,9 +1232,11 @@ ossl_sslctx_set_tmp_dh(VALUE self, VALUE arg) * * === Example * ctx1 = OpenSSL::SSL::SSLContext.new - * ctx1.groups = "X25519:P-256:P-224" - * svr = OpenSSL::SSL::SSLServer.new(tcp_svr, ctx1) - * Thread.new { svr.accept } + * ctx1.groups = "X25519:P-256" + * Thread.new { + * ssl = OpenSSL::SSL::SSLSocket.new(tcp_svr.accept, ctx1) + * ssl.accept + * } * * ctx2 = OpenSSL::SSL::SSLContext.new * ctx2.groups = "P-256" @@ -2803,8 +2807,8 @@ Init_ossl_ssl(void) /* Document-module: OpenSSL::SSL * * Use SSLContext to set up the parameters for a TLS (former SSL) - * connection. Both client and server TLS connections are supported, - * SSLSocket and SSLServer may be used in conjunction with an instance + * connection. Both client and server TLS connections are supported. + * SSLSocket may be used in conjunction with a TCPServer and an instance * of SSLContext to set up connections. */ mSSL = rb_define_module_under(mOSSL, "SSL");