summaryrefslogtreecommitdiff
path: root/src/lib/libssl/t1_enc.c
diff options
context:
space:
mode:
authortedu <>2014-04-15 19:42:56 +0000
committertedu <>2014-04-15 19:42:56 +0000
commitea717df2f3c9582198e1e40e6d5a566a33974039 (patch)
treec3cddef2cd4f28b6e01b7aaafadb1976f9e45d89 /src/lib/libssl/t1_enc.c
parent5fbff974ec318bfb1a7cdda2d94ac86eaca1937a (diff)
downloadopenbsd-ea717df2f3c9582198e1e40e6d5a566a33974039.tar.gz
openbsd-ea717df2f3c9582198e1e40e6d5a566a33974039.tar.bz2
openbsd-ea717df2f3c9582198e1e40e6d5a566a33974039.zip
remove FIPS mode support. people who require FIPS can buy something that
meets their needs, but dumping it in here only penalizes the rest of us. ok miod
Diffstat (limited to 'src/lib/libssl/t1_enc.c')
-rw-r--r--src/lib/libssl/t1_enc.c7
1 files changed, 0 insertions, 7 deletions
diff --git a/src/lib/libssl/t1_enc.c b/src/lib/libssl/t1_enc.c
index e59e883424..71d9f164b4 100644
--- a/src/lib/libssl/t1_enc.c
+++ b/src/lib/libssl/t1_enc.c
@@ -981,13 +981,6 @@ tls1_mac(SSL *ssl, unsigned char *md, int send)
981 EVP_DigestSignUpdate(mac_ctx, rec->input, rec->length); 981 EVP_DigestSignUpdate(mac_ctx, rec->input, rec->length);
982 t = EVP_DigestSignFinal(mac_ctx, md, &md_size); 982 t = EVP_DigestSignFinal(mac_ctx, md, &md_size);
983 OPENSSL_assert(t > 0); 983 OPENSSL_assert(t > 0);
984#ifdef OPENSSL_FIPS
985 if (!send && FIPS_mode())
986 tls_fips_digest_extra(
987 ssl->enc_read_ctx,
988 mac_ctx, rec->input,
989 rec->length, orig_len);
990#endif
991 } 984 }
992 985
993 if (!stream_mac) 986 if (!stream_mac)