# Ubuntu 22.04 libssl 3 migration

**URL:** <https://racket.discourse.group/t/ubuntu-22-04-libssl-3-migration/942>\
**Category:** General\
**Tags:** web\
**Created:** [April 30, 2022, 12:16am UTC](https://racket.discourse.group/t/ubuntu-22-04-libssl-3-migration/942 "2022-04-30T00:16:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![evdubs](https://avatars.discourse-cdn.com/v4/letter/e/b5ac83/32.png) [@evdubs](https://racket.discourse.group/u/evdubs)\
**Post date:** [April 30, 2022, 12:16am UTC](https://racket.discourse.group/t/ubuntu-22-04-libssl-3-migration/942/1 "2022-04-30T00:16:28Z")

</div>

I recently upgraded to Ubuntu 22.04. Apparently, with 22.04, libssl [has been moved](https://discourse.ubuntu.com/t/openssl-3-0-transition-plans/24453) to version 3.0. From that link:

> As some of you might have surmised, we’re planning to move to [OpenSSL 3.0](https://www.openssl.org/blog/blog/2021/09/07/OpenSSL3.Final/) for 22.04. This new major release brings of course some new things, but also breaks API and ABI.

I noticed this migration by doing the following in Racket:

```scheme
$ racket
> (require net/http-easy)
> (define rsp (get "https://www.google.com"))
SSL_get_peer_certificate: implementation not found [,bt for context]

```

To fix this, I pointed `libssl.so` and `libcrypto.so` (installed in `/usr/lib/x86_64-linux-gnu/`) to version 1.1.

Is there a plan to migrate the `openssl` Racket library to `libssl3`?

---

<div class="post-metadata">

**Author:** ![mflatt](https://yyz2.discourse-cdn.com/free1/user_avatar/racket.discourse.group/mflatt/32/6_2.png) [@mflatt](https://racket.discourse.group/u/mflatt)\
**Post date:** [May 4, 2022, 7:38pm UTC](https://racket.discourse.group/t/ubuntu-22-04-libssl-3-migration/942/2 "2022-05-04T19:38:18Z")

</div>

I think the answer is mostly to add "3" as a recognized version number in "libcrypto.rkt".

With that change plus a fallback for `SSL_get_peer_certificate` to use `SSL_get1_peer_certificate`, most of the tests in `tests/openssl` pass for me. The three that fail are "peer-verif2.rkt", "test-alpn.rkt", and "test-channel-binding.rkt". It's not immediately obvious whether those failures are due to OpenSSL 3 vs. 1.1 or due to trying to run tests in a Docker container.

I'll push the addition of `"3"` and the fallback to use `SSL_get1_peer_certificate`.

---

<div class="post-metadata">

**Author:** ![evdubs](https://avatars.discourse-cdn.com/v4/letter/e/b5ac83/32.png) [@evdubs](https://racket.discourse.group/u/evdubs)\
**Post date:** [May 4, 2022, 9:00pm UTC](https://racket.discourse.group/t/ubuntu-22-04-libssl-3-migration/942/3 "2022-05-04T21:00:20Z")

</div>

I applied the changes in [the commit](https://github.com/racket/racket/commit/b15f33b0bc3aca54c3fdc2bcd59f740cbb6fcb6f) to my local installation. Looks good so far. Thank you.

---

<div class="post-metadata">

**Author:** ![jacobhall](https://yyz2.discourse-cdn.com/free1/user_avatar/racket.discourse.group/jacobhall/32/624_2.png) [@jacobhall](https://racket.discourse.group/u/jacobhall)\
**Post date:** [August 10, 2022, 3:23am UTC](https://racket.discourse.group/t/ubuntu-22-04-libssl-3-migration/942/4 "2022-08-10T03:23:38Z")

</div>

I ran into an identical issue in Fedora 36 today. Thanks for the fix!
