#1138464 pam-pkcs11: FTBFS with openssl 4.0

Package:
pam-pkcs11
Source:
pam-pkcs11
Submitter:
Sebastian Andrzej Siewior
Date:
2026-09-09 13:07:02 UTC
Severity:
normal
Tags:
#1138464#5
Date:
2026-05-30 16:19:22 UTC
From:
To:
OpenSSL 4.0 is in experimental. This package fails to build against it:

| libtool: compile:  gcc -DHAVE_CONFIG_H -I. -I../.. -Wdate-time -D_FORTIFY_SOURCE=2 -g -O2 -Werror=implicit-function-declaration -ffile-prefix-map=/build/reproducible-path/pam-pkcs11-0.6.13=. -fstack-protector-strong -fstack-clash-protection -Wformat -Werror=format-security -fcf-protection -Wno-pointer-sign -c cert_vfy.c  -fPIC -DPIC -o .libs/libcommon_la-cert_vfy.o
| cert_vfy.c: In function 'verify_crl':
| cert_vfy.c:193:3: warning: 'X509_cmp_current_time' is deprecated: Since OpenSSL 4.0 [-Wdeprecated-declarations]
|   193 |   rv = X509_cmp_current_time(lastUpdate);
|       |   ^~
| In file included from cert_st.h:37,
|                  from cert_vfy.h:30,
|                  from cert_vfy.c:18:
| /usr/include/openssl/x509.h:694:27: note: declared here
|   694 | OSSL_DEPRECATEDIN_4_0 int X509_cmp_current_time(const ASN1_TIME *s);
|       |                           ^~~~~~~~~~~~~~~~~~~~~
| cert_vfy.c:202:3: warning: 'X509_cmp_current_time' is deprecated: Since OpenSSL 4.0 [-Wdeprecated-declarations]
|   202 |   rv = X509_cmp_current_time(nextUpdate);
|       |   ^~
| /usr/include/openssl/x509.h:694:27: note: declared here
|   694 | OSSL_DEPRECATEDIN_4_0 int X509_cmp_current_time(const ASN1_TIME *s);
|       |                           ^~~~~~~~~~~~~~~~~~~~~
| In file included from cert_vfy.c:17:
| cert_vfy.c: In function 'check_for_revocation':
| cert_vfy.c:308:56: error: invalid use of incomplete typedef 'ASN1_IA5STRING' {aka 'struct asn1_string_st'}
|   308 |             DBG1("downloading crl from %s", name->d.ia5->data);
|       |                                                        ^~
| debug.h:55:58: note: in definition of macro 'DBG1'
|    55 | #define DBG1(f,a) debug_print(1, __FILE__, __LINE__, f , a )
|       |                                                          ^
| cert_vfy.c:309:57: error: invalid use of incomplete typedef 'ASN1_IA5STRING' {aka 'struct asn1_string_st'}
|   309 |             crl = download_crl((const char *)name->d.ia5->data);
|       |                                                         ^~
| make[5]: *** [Makefile:549: libcommon_la-cert_vfy.lo] Error 1

Full buildlog
https://breakpoint.cc/openssl-rebuild/logs-4/attempted/pam-pkcs11_0.6.13-1_amd64-2026-04-19T08:44:05Z

Sebastian

#1138464#16
Date:
2026-09-09 13:05:30 UTC
From:
To:
We believe that the bug you reported is fixed in the latest version of
pam-pkcs11, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to 1138464@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
Ludovic Rousseau <rousseau@debian.org> (supplier of updated pam-pkcs11 package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Wed, 09 Sep 2026 14:57:10 +0200
Source: pam-pkcs11
Architecture: source
Version: 0.6.14-1
Distribution: unstable
Urgency: medium
Maintainer: Ludovic Rousseau <rousseau@debian.org>
Changed-By: Ludovic Rousseau <rousseau@debian.org>
Closes: 1138464
Changes:
 pam-pkcs11 (0.6.14-1) unstable; urgency=medium
 .
   * New upstream release
   * Fix "FTBFS with openssl 4.0" (Closes: #1138464)
   * d/control: reformat Build-Depends:
   * d/control: replace libpam-dev by libpam0g-dev
   * remove d/patches/0001--configure.ac now included upstream
   * d/control: upgrade Standards-Version: from 4.7.0 to 4.7.4
Checksums-Sha1:
 9c36cffaca002c11552e51b65a129741861a3aad 1989 pam-pkcs11_0.6.14-1.dsc
 40198e2cb87888e5a16ce59badfc319765fa4ba5 282568 pam-pkcs11_0.6.14.orig.tar.gz
 d6f414e1d5672df46beaba220965773ac193a94f 72360 pam-pkcs11_0.6.14-1.debian.tar.xz
 2c00ae82afc259b3116347d1bf036bde89410bf5 7920 pam-pkcs11_0.6.14-1_amd64.buildinfo
Checksums-Sha256:
 3564d9014ca7e2ce591c845ab6ea2d05a7532ea886dd05971eacce4d844921c8 1989 pam-pkcs11_0.6.14-1.dsc
 ac85021c0e883127e07ebeaf964e9b92d0d3ef2e05bc8b9cb4afea9ad1c5872e 282568 pam-pkcs11_0.6.14.orig.tar.gz
 0e29806cc012e45523570983cac018e9a8306ed5dc89ed417ff577d25766fc55 72360 pam-pkcs11_0.6.14-1.debian.tar.xz
 cc4a353da01646034b610a73d83a5a56b921894be689a4511c82626b2402e0da 7920 pam-pkcs11_0.6.14-1_amd64.buildinfo
Files:
 d95e9432b54767de7c6cd13ad414946b 1989 admin optional pam-pkcs11_0.6.14-1.dsc
 0258c4082e27880cc8289d6ee2c70fb1 282568 admin optional pam-pkcs11_0.6.14.orig.tar.gz
 5ab1913b2dfefa7f6cdd9428146449e0 72360 admin optional pam-pkcs11_0.6.14-1.debian.tar.xz
 94b38febd684e9ce792fd549626c3d5b 7920 admin optional pam-pkcs11_0.6.14-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEE9eEbn/6REUb0HZU9eKG03+j5xX4FAmqhWEUUHHJvdXNzZWF1
QGRlYmlhbi5vcmcACgkQeKG03+j5xX5Cpg/+MpDQu2bcyhs5L1EUjKOxSeQFWNA3
/UDgd5k5DCaqPDOKQuA5aqDwErNOIWSA4BW7nQz/KGKd17IBTO6XfW+p7yvinloM
B/on8XlR3H/PXIqc5w/AVBpTjqPUipE73f0eZalBKh6Pu22iQr1jL2KGfa66xM9W
9J+oV8+Y3EtHVb21N0v70Fdx8f94BbWOImVJpa5eBBwyB3ncSdz7j8NiNJElWnQg
+yrJeONd+4plMOSyqg6WiTADf0iju+zCM12WwtHSBm9FPmzmz2l1gfzIMm0pmzoJ
Smo7wllC31hEhTNBspxD5oQX6ngUHgotjOo+pMtqozX3s7aQQMzMRCg6ZLdQnW2W
yzwnP83dslNYD6oNzzrPv/yzbJXIIzaz1yFkbBSxsy7BicgbUh2VvqkgyGFm6u2D
WBz1y0lSJ5kGibQPThL4FxYt/Ew20D7Avp8lYj0pH3nrOMTJMT5iauxRXwJ9guWe
7KbSqqbCZVaziGFp3Tt95DXG0Du/9lkwtGqlAdwkABjm2FifYg4PHHotGSc0/CfM
Ck+CZ47Ex7qa9EEm86dcKWcoRNyj03jSPqeFwbeMbA5qVzC4CcmCL2VRIRJjJZ0S
90GAUJu0dutXPExOPIArEucQlqqHjY1JK7vHZXB8AebP06cblx+bpxFA94OAV/j4
E8r7MwULGMbrO+M=
=eK4T
-----END PGP SIGNATURE-----