diff options
author | beck <> | 2021-10-23 09:13:51 +0000 |
---|---|---|
committer | beck <> | 2021-10-23 09:13:51 +0000 |
commit | 64138904c3f088bafa171c1f6375dba75080079e (patch) | |
tree | 3ffdaff75f00ed63911fb2fa9dc0ac6f6da2aec7 /src/lib | |
parent | 3781592d1cd8ce107960abb543e4eccf20288a82 (diff) | |
download | openbsd-64138904c3f088bafa171c1f6375dba75080079e.tar.gz openbsd-64138904c3f088bafa171c1f6375dba75080079e.tar.bz2 openbsd-64138904c3f088bafa171c1f6375dba75080079e.zip |
Add back the fips mode test functions, new stuff requires this.
Symbols.list changes to follow with tb's upcoming bump
ok jsing@
Diffstat (limited to 'src/lib')
-rw-r--r-- | src/lib/libcrypto/Makefile | 4 | ||||
-rw-r--r-- | src/lib/libcrypto/crypto.h | 7 | ||||
-rw-r--r-- | src/lib/libcrypto/o_fips.c | 75 |
3 files changed, 83 insertions, 3 deletions
diff --git a/src/lib/libcrypto/Makefile b/src/lib/libcrypto/Makefile index 2bc065afe2..1caac51601 100644 --- a/src/lib/libcrypto/Makefile +++ b/src/lib/libcrypto/Makefile | |||
@@ -1,4 +1,4 @@ | |||
1 | # $OpenBSD: Makefile,v 1.46 2021/09/03 23:30:42 job Exp $ | 1 | # $OpenBSD: Makefile,v 1.47 2021/10/23 09:13:51 beck Exp $ |
2 | 2 | ||
3 | LIB= crypto | 3 | LIB= crypto |
4 | LIBREBUILD=y | 4 | LIBREBUILD=y |
@@ -41,7 +41,7 @@ SYMBOL_LIST= ${.CURDIR}/Symbols.list | |||
41 | 41 | ||
42 | # crypto/ | 42 | # crypto/ |
43 | SRCS+= cryptlib.c malloc-wrapper.c mem_dbg.c cversion.c ex_data.c cpt_err.c | 43 | SRCS+= cryptlib.c malloc-wrapper.c mem_dbg.c cversion.c ex_data.c cpt_err.c |
44 | SRCS+= o_time.c o_str.c o_init.c | 44 | SRCS+= o_time.c o_str.c o_init.c o_fips.c |
45 | SRCS+= mem_clr.c crypto_init.c crypto_lock.c | 45 | SRCS+= mem_clr.c crypto_init.c crypto_lock.c |
46 | 46 | ||
47 | # aes/ | 47 | # aes/ |
diff --git a/src/lib/libcrypto/crypto.h b/src/lib/libcrypto/crypto.h index 7de8abb437..aba5556029 100644 --- a/src/lib/libcrypto/crypto.h +++ b/src/lib/libcrypto/crypto.h | |||
@@ -1,4 +1,4 @@ | |||
1 | /* $OpenBSD: crypto.h,v 1.50 2019/01/19 01:07:00 tb Exp $ */ | 1 | /* $OpenBSD: crypto.h,v 1.51 2021/10/23 09:13:51 beck Exp $ */ |
2 | /* ==================================================================== | 2 | /* ==================================================================== |
3 | * Copyright (c) 1998-2006 The OpenSSL Project. All rights reserved. | 3 | * Copyright (c) 1998-2006 The OpenSSL Project. All rights reserved. |
4 | * | 4 | * |
@@ -505,6 +505,11 @@ uint64_t OPENSSL_cpu_caps(void); | |||
505 | int OPENSSL_isservice(void); | 505 | int OPENSSL_isservice(void); |
506 | 506 | ||
507 | #ifndef LIBRESSL_INTERNAL | 507 | #ifndef LIBRESSL_INTERNAL |
508 | #if defined(LIBRESSL_NEW_API) | ||
509 | int FIPS_mode(void); | ||
510 | int FIPS_mode_set(int r); | ||
511 | #endif | ||
512 | |||
508 | void OPENSSL_init(void); | 513 | void OPENSSL_init(void); |
509 | 514 | ||
510 | /* CRYPTO_memcmp returns zero iff the |len| bytes at |a| and |b| are equal. It | 515 | /* CRYPTO_memcmp returns zero iff the |len| bytes at |a| and |b| are equal. It |
diff --git a/src/lib/libcrypto/o_fips.c b/src/lib/libcrypto/o_fips.c new file mode 100644 index 0000000000..fe3861c553 --- /dev/null +++ b/src/lib/libcrypto/o_fips.c | |||
@@ -0,0 +1,75 @@ | |||
1 | /* Written by Stephen henson (steve@@openssl.org) for the OpenSSL | ||
2 | * project 2011. | ||
3 | */ | ||
4 | /* ==================================================================== | ||
5 | * Copyright (c) 2011 The OpenSSL Project. All rights reserved. | ||
6 | * | ||
7 | * Redistribution and use in source and binary forms, with or without | ||
8 | * modification, are permitted provided that the following conditions | ||
9 | * are met: | ||
10 | * | ||
11 | * 1. Redistributions of source code must retain the above copyright | ||
12 | * notice, this list of conditions and the following disclaimer. | ||
13 | * | ||
14 | * 2. Redistributions in binary form must reproduce the above copyright | ||
15 | * notice, this list of conditions and the following disclaimer in | ||
16 | * the documentation and/or other materials provided with the | ||
17 | * distribution. | ||
18 | * | ||
19 | * 3. All advertising materials mentioning features or use of this | ||
20 | * software must display the following acknowledgment: | ||
21 | * "This product includes software developed by the OpenSSL Project | ||
22 | * for use in the OpenSSL Toolkit. (http://www.openssl.org/)" | ||
23 | * | ||
24 | * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to | ||
25 | * endorse or promote products derived from this software without | ||
26 | * prior written permission. For written permission, please contact | ||
27 | * openssl-core@@openssl.org. | ||
28 | * | ||
29 | * 5. Products derived from this software may not be called "OpenSSL" | ||
30 | * nor may "OpenSSL" appear in their names without prior written | ||
31 | * permission of the OpenSSL Project. | ||
32 | * | ||
33 | * 6. Redistributions of any form whatsoever must retain the following | ||
34 | * acknowledgment: | ||
35 | * "This product includes software developed by the OpenSSL Project | ||
36 | * for use in the OpenSSL Toolkit (http://www.openssl.org/)" | ||
37 | * | ||
38 | * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY | ||
39 | * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE | ||
40 | * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR | ||
41 | * PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL THE OpenSSL PROJECT OR | ||
42 | * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL, | ||
43 | * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT | ||
44 | * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; | ||
45 | * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) | ||
46 | * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, | ||
47 | * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) | ||
48 | * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED | ||
49 | * OF THE POSSIBILITY OF SUCH DAMAGE. | ||
50 | * ==================================================================== | ||
51 | * | ||
52 | * This product includes cryptographic software written by Eric Young | ||
53 | * (eay@@cryptsoft.com). This product includes software written by Tim | ||
54 | * Hudson (tjh@@cryptsoft.com). | ||
55 | * | ||
56 | */ | ||
57 | |||
58 | #include <openssl/err.h> | ||
59 | |||
60 | #include "cryptlib.h" | ||
61 | |||
62 | int | ||
63 | FIPS_mode(void) | ||
64 | { | ||
65 | return 0; | ||
66 | } | ||
67 | |||
68 | int | ||
69 | FIPS_mode_set(int r) | ||
70 | { | ||
71 | if (r == 0) | ||
72 | return 1; | ||
73 | CRYPTOerror(CRYPTO_R_FIPS_MODE_NOT_SUPPORTED); | ||
74 | return 0; | ||
75 | } | ||