Don't Understand Openssl_Add_All_Algorithms Method

The documentation says

OpenSSL keeps an internal table of digest algorithms and ciphers. It uses this table to lookup ciphers via functions such as EVP_get_cipher_byname().

OpenSSL_add_all_digests() adds all digest algorithms to the table.

My question is, where is this table stored? How does my code know that this method has executed?...how does it work internally, what if i want more SSL connections and one to have all digests added and one not? Does anyone know any good documentation for this?

Thank you

3 Answers

The NOTES section of the manual page pretty much sums it up:

A typical application will call OpenSSL_add_all_algorithms() initially and EVP_cleanup() before exiting.

and

The cipher and digest lookup functions are used in many parts of the library. If the table is not initialized several functions will misbehave and complain they cannot find algorithms. This includes the PEM, PKCS#12, SSL and S/MIME libraries. This is a common query in the OpenSSL mailing lists.

So assuming that you are writing a typical application, you will add this to your OpenSSL initialization code:

OpenSSL_add_all_algorithms();

and this to the OpenSSL cleanup code:

EVP_cleanup();

and you are done. You are always responsible for calling these yourself in applications which use OpenSSL. If you want to know how OpenSSL stores the table internally, use the source, Luke.

To control which ciphers are available for a specific SSL context, you would use SSL_CTX_set_cipher_list.

As for better documentation than the manual page, I can recommend "Network Security with OpenSSL" by John Viega, Matt Messier & Pravir Chandra. The book is old and does not cover newer versions of OpenSSL, but most of it is still very applicable.

1

OpenSSL_add_all_algorithms() is not needed for newer OpenSSL versions and is ignored. For backward and forward compatibility, use this:

# if OPENSSL_API_COMPAT < 0x10100000L
OpenSSL_add_all_algorithms();
# endif

And

# if OPENSSL_API_COMPAT < 0x10100000L
EVP_cleanup();
# endif

The same applies to OpenSSL_add_all_ciphers() and OpenSSL_add_all_digests().

For more details, see the man page at

1

This is an old question. The API was deprecated some years ago:

The OpenSSL_add_all_algorithms(), OpenSSL_add_all_ciphers(), OpenSSL_add_all_digests(), and EVP_cleanup(), functions were deprecated in OpenSSL 1.1.0 by OPENSSL_init_crypto().

Reference:

Your Answer

By clicking “Post Your Answer”, you agree to our terms of service and acknowledge that you have read and understand our privacy policy and code of conduct.

David Miller

David Miller

Executive Financial & Market Analyst

David Miller brings 15 years of experience in global economics, personal finance strategy, and market dynamics. He specializes in turning complex economic trends into actionable insights for everyday readers.

Share this article
Twitter Facebook Pinterest