Appendix B. Configuration and Operational Reference

B.1 Full configuration file

The configuration of §13.1, with every section annotated. Paths are examples.

# openssl.cnf -- activate the tlsext provider and select its algorithms.
openssl_conf = openssl_init

[openssl_init]
providers = provider_sect
ssl_conf  = ssl_sect

# --- Provider activation (13.1) -------------------------------------
[provider_sect]
default = default_sect      # 3.7: omitting this leaves the process
tlsext  = tlsext_sect       #      without standard algorithms

[default_sect]
activate = 1

[tlsext_sect]
module   = /usr/local/lib/ossl-modules/tlsext.so
activate = 1

# --- Algorithm selection (13.2) -------------------------------------
# Activation makes algorithms AVAILABLE; these lines make them CHOSEN.
[ssl_sect]
system_default = system_default_sect

[system_default_sect]
Groups       = tlsext256:x25519:secp256r1
CipherSuites = TLS_TLSEXT_AEAD_TLSEXT_HASH256:TLS_AES_256_GCM_SHA384

B.2 Fail-closed variant

For a deployment whose requirement is mandatory rather than preferred (§6.4, §14.2). Note that rollback from this configuration requires restoring the algorithm lines, not merely deactivating the provider (§13.6).

[system_default_sect]
Groups       = tlsext256
CipherSuites = TLS_TLSEXT_AEAD_TLSEXT_HASH256

B.3 Diagnostic sequence

The order of §14.5. Each command answers one question; taking them in order is faster than reasoning backwards from a failed handshake.

# 1. Is the provider loaded?
openssl list -providers

# 2. Does it advertise the algorithm, and under what name?
openssl list -digest-algorithms  -provider tlsext
openssl list -cipher-algorithms  -provider tlsext
openssl list -key-exchange-algorithms -provider tlsext

# 3. Does the property query admit it?
openssl list -digest-algorithms -propquery 'provider=tlsext'

# 4. Which groups and suites are offered?
openssl ciphers -v -tls1_3
openssl s_client -connect host:443 -tls1_3 -groups tlsext256 </dev/null

# 5. What was actually negotiated? (14.2 -- established is not sufficient)
openssl s_client -connect host:443 -tls1_3 </dev/null \
    | grep -E 'Cipher|Server Temp Key|Negotiated'

Step 5 is the one that is usually skipped. A successful connection proves a handshake completed, not that it used the intended algorithms. Confirming the negotiated suite and group is the difference between testing the deployment and testing TLS.

B.4 Failure-to-symptom reference

SymptomLikely causeSection
Provider absent from list -providersWrong module path, or activate not set13.1
Provider listed, algorithms absentQuery function not answering that operation id7.3
Algorithms listed, never negotiatedMissing capability entry, or not named in Groups/CipherSuites10.1, 13.2
Works in the tool, not in the applicationDifferent library context13.3
Standard algorithms stop workingdefault not activated, or a broad property default3.7, 14.4
handshake_failure at ServerHelloNo shared suite or group; peer lacks the code point12.3
Failure after ServerHelloSuite selected, algorithm not fetchable12.3
Failure at FinishedTranscript divergence, duplication bug, or schedule width9.2, 15.3
Record-length errorsMissing AEAD algorithm parameters8.3
HKDF wrong from the first stepblocksize not reported9.3, 15.3
Intermittent resumption failuresSession cache not recording the hash15.5
Connection succeeds, requirement unmetProperty expressed as preferred, not required14.2

The last row has no error message, which is why it is last and why Chapter 19 makes its negative test mandatory.

B.5 Build sketch

CFLAGS  = -O2 -Wall -Wextra -fPIC $(shell pkg-config --cflags libcrypto)
LDFLAGS = -shared $(shell pkg-config --libs libcrypto)

tlsext.so: provider.o ctx.o cipher_aead.o digest.o keymgmt_ec.o \
           keyexch_ec.o signature.o capabilities.o params.o
	$(CC) $(LDFLAGS) -o $@ $^

install: tlsext.so
	install -m 0755 tlsext.so /usr/local/lib/ossl-modules/

The module links only against libcrypto (requirement N3). It does not link against libssl, and the absence is structural rather than incidental: a provider supplies algorithms to libcrypto, and the TLS library consumes them from there (Chapter 5).