Compare commits
379 Commits
OpenSSL_0_
...
OpenSSL-fi
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
6f93fd5685 | ||
|
|
45b364ddab | ||
|
|
8887e81bd7 | ||
|
|
9008856f7a | ||
|
|
1c4273ae0d | ||
|
|
1ba833a427 | ||
|
|
7e994953c9 | ||
|
|
f97b8f3114 | ||
|
|
c9a0ab4907 | ||
|
|
cdabf88810 | ||
|
|
e756ea4722 | ||
|
|
9fce443775 | ||
|
|
e70e417baf | ||
|
|
f64f44358d | ||
|
|
c848cd1c35 | ||
|
|
ef7c1a9490 | ||
|
|
9b4e99ebd1 | ||
|
|
351b731d00 | ||
|
|
3d3fd6beb2 | ||
|
|
7486fb6550 | ||
|
|
5786b6c92f | ||
|
|
ae2865a771 | ||
|
|
a302eb21b7 | ||
|
|
409e30479a | ||
|
|
b664536914 | ||
|
|
6fffeb46ad | ||
|
|
48331e3f64 | ||
|
|
edd529ad16 | ||
|
|
5be243dc20 | ||
|
|
e9d247d2b0 | ||
|
|
18ab306e63 | ||
|
|
03c4a3a474 | ||
|
|
e4bc9d9ef6 | ||
|
|
9620067392 | ||
|
|
814dfe70bc | ||
|
|
c79cb4a07b | ||
|
|
9ac269f78c | ||
|
|
6fa2c4cadc | ||
|
|
1980bc91fe | ||
|
|
8b7745571f | ||
|
|
0d2b761dae | ||
|
|
85a752e838 | ||
|
|
34d67fd5f6 | ||
|
|
7c01fd975c | ||
|
|
8da1de4a5a | ||
|
|
7bff8fd23d | ||
|
|
7292151850 | ||
|
|
1b4a2cf20b | ||
|
|
0c19f2c725 | ||
|
|
d48c5e8c45 | ||
|
|
f645290f31 | ||
|
|
9b95537a01 | ||
|
|
a383b2546e | ||
|
|
ff81ee92cb | ||
|
|
87863a0cd4 | ||
|
|
012d1c8dd9 | ||
|
|
86fbdae6e8 | ||
|
|
e0c5f4e438 | ||
|
|
d946944dbd | ||
|
|
ddc3e0dd03 | ||
|
|
fbe1fcccdc | ||
|
|
4578122b60 | ||
|
|
e361b2ff2e | ||
|
|
57362da5ab | ||
|
|
002104370a | ||
|
|
fda62b13d4 | ||
|
|
a7fdb764c5 | ||
|
|
3b2e785e50 | ||
|
|
280bc44730 | ||
|
|
9e1468e482 | ||
|
|
b3307eae6d | ||
|
|
19cf9463e7 | ||
|
|
2dd4c4b430 | ||
|
|
86160f3c41 | ||
|
|
0633bca11c | ||
|
|
97c9cf71aa | ||
|
|
a0dc48e7db | ||
|
|
22f6a2b271 | ||
|
|
a3a426cfb5 | ||
|
|
93d4d2b900 | ||
|
|
2f9048b8a1 | ||
|
|
d73ed541db | ||
|
|
e6e5592a50 | ||
|
|
663bbb6367 | ||
|
|
98ced05c56 | ||
|
|
5b75e1cff4 | ||
|
|
f36a8c2060 | ||
|
|
90ac9ec264 | ||
|
|
fe5c4c885b | ||
|
|
1950e8acea | ||
|
|
437bafa5cc | ||
|
|
7c78f06301 | ||
|
|
b27278d0cf | ||
|
|
24a69a8196 | ||
|
|
b3049d696b | ||
|
|
77b265f48c | ||
|
|
735b9eeed5 | ||
|
|
67c31c4b61 | ||
|
|
0406ce2646 | ||
|
|
76108ba7eb | ||
|
|
4d27e3d339 | ||
|
|
7d59e441ca | ||
|
|
3e3c47d5d5 | ||
|
|
03b7b4690c | ||
|
|
0fd9322af1 | ||
|
|
7016b1952e | ||
|
|
ff3e014820 | ||
|
|
50cd0f0eb3 | ||
|
|
32098b7565 | ||
|
|
bf4131fbf9 | ||
|
|
2ac869590f | ||
|
|
4742bc0f6f | ||
|
|
02e483d236 | ||
|
|
1a58139aaa | ||
|
|
a32f4770e9 | ||
|
|
086d475ffb | ||
|
|
7f1288da93 | ||
|
|
0a6e92a88f | ||
|
|
36eaa70621 | ||
|
|
d7dc9a7ce3 | ||
|
|
319e19db9c | ||
|
|
ef85b85b12 | ||
|
|
4d4d27a2a0 | ||
|
|
8f0d89092e | ||
|
|
c4a2cab0bb | ||
|
|
6d73d35f4f | ||
|
|
f53e66af67 | ||
|
|
5cbe626d26 | ||
|
|
fe93a60b00 | ||
|
|
5e10ca5618 | ||
|
|
4e8da09800 | ||
|
|
203ae57fe0 | ||
|
|
529c33f1e8 | ||
|
|
af18a34478 | ||
|
|
da5c0127ac | ||
|
|
ce0e12d29a | ||
|
|
87339c6290 | ||
|
|
0a22e7446b | ||
|
|
b56cb7c6ea | ||
|
|
cd5ab329f2 | ||
|
|
80106dc5fb | ||
|
|
0fa79cbe17 | ||
|
|
be22102d82 | ||
|
|
1ad95f8217 | ||
|
|
5f1211834f | ||
|
|
28feb1f8da | ||
|
|
9596d1e63b | ||
|
|
626bebeede | ||
|
|
dfe42a131f | ||
|
|
1970bc2703 | ||
|
|
08debe11f8 | ||
|
|
9c7e058216 | ||
|
|
b01e8b2063 | ||
|
|
100868d1cf | ||
|
|
0712210f03 | ||
|
|
8431a6aaf5 | ||
|
|
2b4a783f66 | ||
|
|
25df4a81cc | ||
|
|
23830280e4 | ||
|
|
bfdfc67b01 | ||
|
|
4764a0543d | ||
|
|
d92b0efbb8 | ||
|
|
b329cc2410 | ||
|
|
ed31fe68ff | ||
|
|
8fa41c6696 | ||
|
|
707a028c8b | ||
|
|
9593bc46bf | ||
|
|
5c65d38219 | ||
|
|
1b8b2d9300 | ||
|
|
4e1778b0d8 | ||
|
|
982c67fbaa | ||
|
|
2ef2463643 | ||
|
|
585eb117d4 | ||
|
|
7c27ac1030 | ||
|
|
475631c31a | ||
|
|
218ba8cb9d | ||
|
|
e881c00515 | ||
|
|
6c3fca2b10 | ||
|
|
0225c7a41e | ||
|
|
a334b0436d | ||
|
|
af13a3949d | ||
|
|
ffc35e73b4 | ||
|
|
a197212e0f | ||
|
|
8944220221 | ||
|
|
5fd76ba57a | ||
|
|
df50ec372e | ||
|
|
49fa74385d | ||
|
|
899f528c1a | ||
|
|
5faa5a9476 | ||
|
|
ddb0cb5bfd | ||
|
|
b2d65cbac7 | ||
|
|
6be8288928 | ||
|
|
9fe07b7cf0 | ||
|
|
0c86c87c60 | ||
|
|
e20d6ef3d6 | ||
|
|
27f50994ff | ||
|
|
53c381105a | ||
|
|
33d0ef8fde | ||
|
|
b2acf7a572 | ||
|
|
e8d2d9478d | ||
|
|
23b3b61921 | ||
|
|
d265676989 | ||
|
|
69fc3dff96 | ||
|
|
667731b635 | ||
|
|
a416ca47ac | ||
|
|
2714e2ac89 | ||
|
|
1139eeecbc | ||
|
|
1b936a5e37 | ||
|
|
0cca0fe0c2 | ||
|
|
56474376dc | ||
|
|
3e511f167e | ||
|
|
282af42404 | ||
|
|
a81f337331 | ||
|
|
1729dca9a8 | ||
|
|
9719193222 | ||
|
|
e6fa7c1276 | ||
|
|
cf7053430d | ||
|
|
ff03c6bc97 | ||
|
|
82c8b6b74d | ||
|
|
cb6fdc3a49 | ||
|
|
8c3b5d5f27 | ||
|
|
dc83f2e312 | ||
|
|
6693e26927 | ||
|
|
793364457b | ||
|
|
6b05350495 | ||
|
|
daec9a56a0 | ||
|
|
5c77786a55 | ||
|
|
42bc3582a9 | ||
|
|
2050f6514f | ||
|
|
5068d7dda4 | ||
|
|
55768cf773 | ||
|
|
6c69dcd9f5 | ||
|
|
ad4297dd9c | ||
|
|
aeb9ccfaad | ||
|
|
79b335a4b5 | ||
|
|
dcc309548e | ||
|
|
8eae0ff0f7 | ||
|
|
5c4a07551e | ||
|
|
b443a0ea5d | ||
|
|
1f4a5a3339 | ||
|
|
20fb51b1a7 | ||
|
|
551bfa60e0 | ||
|
|
ab50cf18db | ||
|
|
31c0a38482 | ||
|
|
91c88deafe | ||
|
|
a91cb15daa | ||
|
|
d2890f6223 | ||
|
|
1ce5bb27e4 | ||
|
|
04262cee42 | ||
|
|
a5a1e71e86 | ||
|
|
06d2a382c4 | ||
|
|
4630a51537 | ||
|
|
01f2ee2bc6 | ||
|
|
def5aefa7f | ||
|
|
5ba7d69c66 | ||
|
|
cf81dc74bd | ||
|
|
46c646225d | ||
|
|
d18c4d09d1 | ||
|
|
e5ad779b69 | ||
|
|
cb36743161 | ||
|
|
fb3eab3562 | ||
|
|
2724bcac2f | ||
|
|
3431c07a66 | ||
|
|
9abf011643 | ||
|
|
75cdb055e6 | ||
|
|
f4207058b8 | ||
|
|
900b1eb869 | ||
|
|
e3b61b1e57 | ||
|
|
750779da07 | ||
|
|
157f01a8ef | ||
|
|
491923fde1 | ||
|
|
273f5726a5 | ||
|
|
a37778046d | ||
|
|
8a087e57d2 | ||
|
|
e384fd9418 | ||
|
|
f6e32f9db4 | ||
|
|
66bb600b05 | ||
|
|
c3b2d69945 | ||
|
|
619991cc3e | ||
|
|
3c410172b7 | ||
|
|
56319ad00e | ||
|
|
f7832889d3 | ||
|
|
46fdad292a | ||
|
|
da99684a8e | ||
|
|
2130ee35d9 | ||
|
|
15f239a4a3 | ||
|
|
223ab84726 | ||
|
|
94d66c3182 | ||
|
|
a0dd62bdb7 | ||
|
|
fd6d2e0754 | ||
|
|
4a4d3c02f2 | ||
|
|
7abd533793 | ||
|
|
b1816f93e1 | ||
|
|
e1904f9eec | ||
|
|
9f3d5018c4 | ||
|
|
768729afbe | ||
|
|
0c96e35c42 | ||
|
|
72e2934909 | ||
|
|
26d96f26da | ||
|
|
5fcc83ed1e | ||
|
|
9ecb20f1de | ||
|
|
b611ff350c | ||
|
|
7f790e0575 | ||
|
|
dccf15ee25 | ||
|
|
89d8a20f22 | ||
|
|
782f8600fa | ||
|
|
f2008fe3fd | ||
|
|
70b3786ffe | ||
|
|
b48fb91edd | ||
|
|
8a19891b2a | ||
|
|
f35d0948eb | ||
|
|
d0f2c1bb81 | ||
|
|
7ba410f9a5 | ||
|
|
36c2be5645 | ||
|
|
0869cd2676 | ||
|
|
4ac5596a86 | ||
|
|
3df76b15ed | ||
|
|
9b3cce3d00 | ||
|
|
c8a2f669f3 | ||
|
|
04a2a836f7 | ||
|
|
d39e69c95a | ||
|
|
69ffdb2d46 | ||
|
|
e301a26ade | ||
|
|
2ed0cf8eef | ||
|
|
1c2cbe6fcc | ||
|
|
023616e32d | ||
|
|
b2703470e0 | ||
|
|
452cd79114 | ||
|
|
9eaca0079f | ||
|
|
bbaf3c2b40 | ||
|
|
ce147f8998 | ||
|
|
4e99f848d8 | ||
|
|
358cf2f6e8 | ||
|
|
407c2c1106 | ||
|
|
2e8aaf94c2 | ||
|
|
3108a80b09 | ||
|
|
bfa3933c8b | ||
|
|
40b4a633a1 | ||
|
|
fc784cbc5c | ||
|
|
d20b5c2043 | ||
|
|
fdf45c44be | ||
|
|
68b08c56c2 | ||
|
|
4416eec8ca | ||
|
|
709af3877d | ||
|
|
8651ba5d45 | ||
|
|
efbb2cb4e5 | ||
|
|
dec45d606f | ||
|
|
6dfd1801fe | ||
|
|
d8242c65b3 | ||
|
|
ee42430cc8 | ||
|
|
da3fe316cf | ||
|
|
c8214d6c8b | ||
|
|
063b216760 | ||
|
|
65f0a05325 | ||
|
|
952b6955c0 | ||
|
|
6f74afaa57 | ||
|
|
3edefe670a | ||
|
|
a461d307f2 | ||
|
|
89a4dad179 | ||
|
|
1ea2fda9dc | ||
|
|
f41dcf3d50 | ||
|
|
1e6031eeb7 | ||
|
|
d9e61666c9 | ||
|
|
2f07e0d591 | ||
|
|
b0a3d8dd27 | ||
|
|
a7100590fe | ||
|
|
7b1ef38609 | ||
|
|
3f5602ce04 | ||
|
|
be0dccdd9e | ||
|
|
50a4d84e79 | ||
|
|
0135aa9888 | ||
|
|
692e644df6 | ||
|
|
3b72341958 | ||
|
|
3a0278b211 | ||
|
|
304ba9fa78 | ||
|
|
4484703f5e | ||
|
|
6b7751ac2c | ||
|
|
7af4688a8f | ||
|
|
d8360c3a8a |
@@ -11,10 +11,8 @@ maketest.log
|
|||||||
cctest
|
cctest
|
||||||
cctest.c
|
cctest.c
|
||||||
cctest.a
|
cctest.a
|
||||||
|
libcrypto.so.*
|
||||||
|
libssl.so.*
|
||||||
*.flc
|
*.flc
|
||||||
semantic.cache
|
semantic.cache
|
||||||
Makefile
|
Makefile
|
||||||
*.so*
|
|
||||||
*.dll*
|
|
||||||
*.sl*
|
|
||||||
*.dylib*
|
|
||||||
|
|||||||
107
.gitignore
vendored
107
.gitignore
vendored
@@ -1,107 +0,0 @@
|
|||||||
# Object files
|
|
||||||
*.o
|
|
||||||
*.obj
|
|
||||||
|
|
||||||
# editor artefacts
|
|
||||||
*.swp
|
|
||||||
.#*
|
|
||||||
#*#
|
|
||||||
*~
|
|
||||||
|
|
||||||
# Top level excludes
|
|
||||||
/Makefile.bak
|
|
||||||
/Makefile
|
|
||||||
/*.a
|
|
||||||
/include
|
|
||||||
/*.pc
|
|
||||||
/rehash.time
|
|
||||||
|
|
||||||
# Most *.c files under test/ are symlinks
|
|
||||||
/test/*.c
|
|
||||||
# Apart from these
|
|
||||||
!/test/asn1test.c
|
|
||||||
!/test/methtest.c
|
|
||||||
!/test/dummytest.c
|
|
||||||
!/test/igetest.c
|
|
||||||
!/test/r160test.c
|
|
||||||
!/test/fips_algvs.c
|
|
||||||
|
|
||||||
/test/*.ss
|
|
||||||
/test/*.srl
|
|
||||||
/test/.rnd
|
|
||||||
/test/test*.pem
|
|
||||||
/test/newkey.pem
|
|
||||||
|
|
||||||
# Certificate symbolic links
|
|
||||||
*.0
|
|
||||||
|
|
||||||
# Links under apps
|
|
||||||
/apps/CA.pl
|
|
||||||
/apps/md4.c
|
|
||||||
|
|
||||||
|
|
||||||
# Auto generated headers
|
|
||||||
/crypto/buildinf.h
|
|
||||||
/crypto/opensslconf.h
|
|
||||||
|
|
||||||
# Auto generated assembly language source files
|
|
||||||
*.s
|
|
||||||
!/crypto/bn/asm/pa-risc2.s
|
|
||||||
!/crypto/bn/asm/pa-risc2W.s
|
|
||||||
crypto/aes/asm/a_win32.asm
|
|
||||||
crypto/bf/asm/b_win32.asm
|
|
||||||
crypto/bn/asm/bn_win32.asm
|
|
||||||
crypto/bn/asm/co_win32.asm
|
|
||||||
crypto/bn/asm/mt_win32.asm
|
|
||||||
crypto/cast/asm/c_win32.asm
|
|
||||||
crypto/cpu_win32.asm
|
|
||||||
crypto/des/asm/d_win32.asm
|
|
||||||
crypto/des/asm/y_win32.asm
|
|
||||||
crypto/md5/asm/m5_win32.asm
|
|
||||||
crypto/rc4/asm/r4_win32.asm
|
|
||||||
crypto/rc5/asm/r5_win32.asm
|
|
||||||
crypto/ripemd/asm/rm_win32.asm
|
|
||||||
crypto/sha/asm/s1_win32.asm
|
|
||||||
crypto/sha/asm/sha512-sse2.asm
|
|
||||||
|
|
||||||
# Executables
|
|
||||||
/apps/openssl
|
|
||||||
/test/sha256t
|
|
||||||
/test/sha512t
|
|
||||||
/test/*test
|
|
||||||
/test/fips_aesavs
|
|
||||||
/test/fips_desmovs
|
|
||||||
/test/fips_dhvs
|
|
||||||
/test/fips_drbgvs
|
|
||||||
/test/fips_dssvs
|
|
||||||
/test/fips_ecdhvs
|
|
||||||
/test/fips_ecdsavs
|
|
||||||
/test/fips_rngvs
|
|
||||||
/test/fips_test_suite
|
|
||||||
*.so*
|
|
||||||
*.dylib*
|
|
||||||
*.dll*
|
|
||||||
# Exceptions
|
|
||||||
!/test/bctest
|
|
||||||
!/crypto/des/times/486-50.sol
|
|
||||||
|
|
||||||
# Misc auto generated files
|
|
||||||
/tools/c_rehash
|
|
||||||
/test/evptests.txt
|
|
||||||
lib
|
|
||||||
Makefile.save
|
|
||||||
*.bak
|
|
||||||
|
|
||||||
# Windows
|
|
||||||
/tmp32dll
|
|
||||||
/tmp32dll.dbg
|
|
||||||
/out32dll
|
|
||||||
/out32dll.dbg
|
|
||||||
/inc32
|
|
||||||
/MINFO
|
|
||||||
ms/bcb.mak
|
|
||||||
ms/libeay32.def
|
|
||||||
ms/nt.mak
|
|
||||||
ms/ntdll.mak
|
|
||||||
ms/ssleay32.def
|
|
||||||
ms/version32.rc
|
|
||||||
@@ -1,30 +0,0 @@
|
|||||||
The OpenSSL project depends on volunteer efforts and financial support from
|
|
||||||
the end user community. That support comes in the form of donations and paid
|
|
||||||
sponsorships, software support contracts, paid consulting services
|
|
||||||
and commissioned software development.
|
|
||||||
|
|
||||||
Since all these activities support the continued development and improvement
|
|
||||||
of OpenSSL we consider all these clients and customers as sponsors of the
|
|
||||||
OpenSSL project.
|
|
||||||
|
|
||||||
We would like to identify and thank the following such sponsors for their past
|
|
||||||
or current significant support of the OpenSSL project:
|
|
||||||
|
|
||||||
Major support:
|
|
||||||
|
|
||||||
Qualys http://www.qualys.com/
|
|
||||||
|
|
||||||
Very significant support:
|
|
||||||
|
|
||||||
OpenGear: http://www.opengear.com/
|
|
||||||
|
|
||||||
Significant support:
|
|
||||||
|
|
||||||
PSW Group: http://www.psw.net/
|
|
||||||
Acano Ltd. http://acano.com/
|
|
||||||
|
|
||||||
Please note that we ask permission to identify sponsors and that some sponsors
|
|
||||||
we consider eligible for inclusion here have requested to remain anonymous.
|
|
||||||
|
|
||||||
Additional sponsorship or financial support is always welcome: for more
|
|
||||||
information please contact the OpenSSL Software Foundation.
|
|
||||||
880
CHANGES
880
CHANGES
@@ -2,728 +2,7 @@
|
|||||||
OpenSSL CHANGES
|
OpenSSL CHANGES
|
||||||
_______________
|
_______________
|
||||||
|
|
||||||
Changes between 0.9.8zd and 0.9.8ze [15 Jan 2015]
|
Changes between 0.9.8h and 0.9.8i [xx XXX xxxx]
|
||||||
|
|
||||||
*) Build fixes for the Windows and OpenVMS platforms
|
|
||||||
[Matt Caswell and Richard Levitte]
|
|
||||||
|
|
||||||
Changes between 0.9.8zc and 0.9.8zd [8 Jan 2015]
|
|
||||||
|
|
||||||
*) Fix DTLS segmentation fault in dtls1_get_record. A carefully crafted DTLS
|
|
||||||
message can cause a segmentation fault in OpenSSL due to a NULL pointer
|
|
||||||
dereference. This could lead to a Denial Of Service attack. Thanks to
|
|
||||||
Markus Stenberg of Cisco Systems, Inc. for reporting this issue.
|
|
||||||
(CVE-2014-3571)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Fix issue where no-ssl3 configuration sets method to NULL. When openssl is
|
|
||||||
built with the no-ssl3 option and a SSL v3 ClientHello is received the ssl
|
|
||||||
method would be set to NULL which could later result in a NULL pointer
|
|
||||||
dereference. Thanks to Frank Schmirler for reporting this issue.
|
|
||||||
(CVE-2014-3569)
|
|
||||||
[Kurt Roeckx]
|
|
||||||
|
|
||||||
*) Abort handshake if server key exchange message is omitted for ephemeral
|
|
||||||
ECDH ciphersuites.
|
|
||||||
|
|
||||||
Thanks to Karthikeyan Bhargavan of the PROSECCO team at INRIA for
|
|
||||||
reporting this issue.
|
|
||||||
(CVE-2014-3572)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Remove non-export ephemeral RSA code on client and server. This code
|
|
||||||
violated the TLS standard by allowing the use of temporary RSA keys in
|
|
||||||
non-export ciphersuites and could be used by a server to effectively
|
|
||||||
downgrade the RSA key length used to a value smaller than the server
|
|
||||||
certificate. Thanks for Karthikeyan Bhargavan of the PROSECCO team at
|
|
||||||
INRIA or reporting this issue.
|
|
||||||
(CVE-2015-0204)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Fix various certificate fingerprint issues.
|
|
||||||
|
|
||||||
By using non-DER or invalid encodings outside the signed portion of a
|
|
||||||
certificate the fingerprint can be changed without breaking the signature.
|
|
||||||
Although no details of the signed portion of the certificate can be changed
|
|
||||||
this can cause problems with some applications: e.g. those using the
|
|
||||||
certificate fingerprint for blacklists.
|
|
||||||
|
|
||||||
1. Reject signatures with non zero unused bits.
|
|
||||||
|
|
||||||
If the BIT STRING containing the signature has non zero unused bits reject
|
|
||||||
the signature. All current signature algorithms require zero unused bits.
|
|
||||||
|
|
||||||
2. Check certificate algorithm consistency.
|
|
||||||
|
|
||||||
Check the AlgorithmIdentifier inside TBS matches the one in the
|
|
||||||
certificate signature. NB: this will result in signature failure
|
|
||||||
errors for some broken certificates.
|
|
||||||
|
|
||||||
Thanks to Konrad Kraszewski from Google for reporting this issue.
|
|
||||||
|
|
||||||
3. Check DSA/ECDSA signatures use DER.
|
|
||||||
|
|
||||||
Reencode DSA/ECDSA signatures and compare with the original received
|
|
||||||
signature. Return an error if there is a mismatch.
|
|
||||||
|
|
||||||
This will reject various cases including garbage after signature
|
|
||||||
(thanks to Antti Karjalainen and Tuomo Untinen from the Codenomicon CROSS
|
|
||||||
program for discovering this case) and use of BER or invalid ASN.1 INTEGERs
|
|
||||||
(negative or with leading zeroes).
|
|
||||||
|
|
||||||
Further analysis was conducted and fixes were developed by Stephen Henson
|
|
||||||
of the OpenSSL core team.
|
|
||||||
|
|
||||||
(CVE-2014-8275)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Correct Bignum squaring. Bignum squaring (BN_sqr) may produce incorrect
|
|
||||||
results on some platforms, including x86_64. This bug occurs at random
|
|
||||||
with a very low probability, and is not known to be exploitable in any
|
|
||||||
way, though its exact impact is difficult to determine. Thanks to Pieter
|
|
||||||
Wuille (Blockstream) who reported this issue and also suggested an initial
|
|
||||||
fix. Further analysis was conducted by the OpenSSL development team and
|
|
||||||
Adam Langley of Google. The final fix was developed by Andy Polyakov of
|
|
||||||
the OpenSSL core team.
|
|
||||||
(CVE-2014-3570)
|
|
||||||
[Andy Polyakov]
|
|
||||||
|
|
||||||
Changes between 0.9.8zb and 0.9.8zc [15 Oct 2014]
|
|
||||||
|
|
||||||
*) Session Ticket Memory Leak.
|
|
||||||
|
|
||||||
When an OpenSSL SSL/TLS/DTLS server receives a session ticket the
|
|
||||||
integrity of that ticket is first verified. In the event of a session
|
|
||||||
ticket integrity check failing, OpenSSL will fail to free memory
|
|
||||||
causing a memory leak. By sending a large number of invalid session
|
|
||||||
tickets an attacker could exploit this issue in a Denial Of Service
|
|
||||||
attack.
|
|
||||||
(CVE-2014-3567)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Build option no-ssl3 is incomplete.
|
|
||||||
|
|
||||||
When OpenSSL is configured with "no-ssl3" as a build option, servers
|
|
||||||
could accept and complete a SSL 3.0 handshake, and clients could be
|
|
||||||
configured to send them.
|
|
||||||
(CVE-2014-3568)
|
|
||||||
[Akamai and the OpenSSL team]
|
|
||||||
|
|
||||||
*) Add support for TLS_FALLBACK_SCSV.
|
|
||||||
Client applications doing fallback retries should call
|
|
||||||
SSL_set_mode(s, SSL_MODE_SEND_FALLBACK_SCSV).
|
|
||||||
(CVE-2014-3566)
|
|
||||||
[Adam Langley, Bodo Moeller]
|
|
||||||
|
|
||||||
*) Add additional DigestInfo checks.
|
|
||||||
|
|
||||||
Reencode DigestInto in DER and check against the original when
|
|
||||||
verifying RSA signature: this will reject any improperly encoded
|
|
||||||
DigestInfo structures.
|
|
||||||
|
|
||||||
Note: this is a precautionary measure and no attacks are currently known.
|
|
||||||
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
Changes between 0.9.8za and 0.9.8zb [6 Aug 2014]
|
|
||||||
|
|
||||||
*) OpenSSL DTLS clients enabling anonymous (EC)DH ciphersuites are subject
|
|
||||||
to a denial of service attack. A malicious server can crash the client
|
|
||||||
with a null pointer dereference (read) by specifying an anonymous (EC)DH
|
|
||||||
ciphersuite and sending carefully crafted handshake messages.
|
|
||||||
|
|
||||||
Thanks to Felix Gr<47>bert (Google) for discovering and researching this
|
|
||||||
issue.
|
|
||||||
(CVE-2014-3510)
|
|
||||||
[Emilia K<>sper]
|
|
||||||
|
|
||||||
*) By sending carefully crafted DTLS packets an attacker could cause openssl
|
|
||||||
to leak memory. This can be exploited through a Denial of Service attack.
|
|
||||||
Thanks to Adam Langley for discovering and researching this issue.
|
|
||||||
(CVE-2014-3507)
|
|
||||||
[Adam Langley]
|
|
||||||
|
|
||||||
*) An attacker can force openssl to consume large amounts of memory whilst
|
|
||||||
processing DTLS handshake messages. This can be exploited through a
|
|
||||||
Denial of Service attack.
|
|
||||||
Thanks to Adam Langley for discovering and researching this issue.
|
|
||||||
(CVE-2014-3506)
|
|
||||||
[Adam Langley]
|
|
||||||
|
|
||||||
*) An attacker can force an error condition which causes openssl to crash
|
|
||||||
whilst processing DTLS packets due to memory being freed twice. This
|
|
||||||
can be exploited through a Denial of Service attack.
|
|
||||||
Thanks to Adam Langley and Wan-Teh Chang for discovering and researching
|
|
||||||
this issue.
|
|
||||||
(CVE-2014-3505)
|
|
||||||
[Adam Langley]
|
|
||||||
|
|
||||||
*) A flaw in OBJ_obj2txt may cause pretty printing functions such as
|
|
||||||
X509_name_oneline, X509_name_print_ex et al. to leak some information
|
|
||||||
from the stack. Applications may be affected if they echo pretty printing
|
|
||||||
output to the attacker.
|
|
||||||
|
|
||||||
Thanks to Ivan Fratric (Google) for discovering this issue.
|
|
||||||
(CVE-2014-3508)
|
|
||||||
[Emilia K<>sper, and Steve Henson]
|
|
||||||
|
|
||||||
*) Fix ec_GFp_simple_points_make_affine (thus, EC_POINTs_mul etc.)
|
|
||||||
for corner cases. (Certain input points at infinity could lead to
|
|
||||||
bogus results, with non-infinity inputs mapped to infinity too.)
|
|
||||||
[Bodo Moeller]
|
|
||||||
|
|
||||||
Changes between 0.9.8y and 0.9.8za [5 Jun 2014]
|
|
||||||
|
|
||||||
*) Fix for SSL/TLS MITM flaw. An attacker using a carefully crafted
|
|
||||||
handshake can force the use of weak keying material in OpenSSL
|
|
||||||
SSL/TLS clients and servers.
|
|
||||||
|
|
||||||
Thanks to KIKUCHI Masashi (Lepidum Co. Ltd.) for discovering and
|
|
||||||
researching this issue. (CVE-2014-0224)
|
|
||||||
[KIKUCHI Masashi, Steve Henson]
|
|
||||||
|
|
||||||
*) Fix DTLS recursion flaw. By sending an invalid DTLS handshake to an
|
|
||||||
OpenSSL DTLS client the code can be made to recurse eventually crashing
|
|
||||||
in a DoS attack.
|
|
||||||
|
|
||||||
Thanks to Imre Rad (Search-Lab Ltd.) for discovering this issue.
|
|
||||||
(CVE-2014-0221)
|
|
||||||
[Imre Rad, Steve Henson]
|
|
||||||
|
|
||||||
*) Fix DTLS invalid fragment vulnerability. A buffer overrun attack can
|
|
||||||
be triggered by sending invalid DTLS fragments to an OpenSSL DTLS
|
|
||||||
client or server. This is potentially exploitable to run arbitrary
|
|
||||||
code on a vulnerable client or server.
|
|
||||||
|
|
||||||
Thanks to J<>ri Aedla for reporting this issue. (CVE-2014-0195)
|
|
||||||
[J<>ri Aedla, Steve Henson]
|
|
||||||
|
|
||||||
*) Fix bug in TLS code where clients enable anonymous ECDH ciphersuites
|
|
||||||
are subject to a denial of service attack.
|
|
||||||
|
|
||||||
Thanks to Felix Gr<47>bert and Ivan Fratric at Google for discovering
|
|
||||||
this issue. (CVE-2014-3470)
|
|
||||||
[Felix Gr<47>bert, Ivan Fratric, Steve Henson]
|
|
||||||
|
|
||||||
*) Fix for the attack described in the paper "Recovering OpenSSL
|
|
||||||
ECDSA Nonces Using the FLUSH+RELOAD Cache Side-channel Attack"
|
|
||||||
by Yuval Yarom and Naomi Benger. Details can be obtained from:
|
|
||||||
http://eprint.iacr.org/2014/140
|
|
||||||
|
|
||||||
Thanks to Yuval Yarom and Naomi Benger for discovering this
|
|
||||||
flaw and to Yuval Yarom for supplying a fix (CVE-2014-0076)
|
|
||||||
[Yuval Yarom and Naomi Benger]
|
|
||||||
|
|
||||||
Thanks to mancha for backporting the fix to the 0.9.8 branch.
|
|
||||||
|
|
||||||
*) Fix handling of warning-level alerts in SSL23 client mode so they
|
|
||||||
don't cause client-side termination (eg. on SNI unrecognized_name
|
|
||||||
warnings). Add client and server support for six additional alerts
|
|
||||||
per RFC 6066 and RFC 4279.
|
|
||||||
[mancha]
|
|
||||||
|
|
||||||
*) Add option SSL_OP_SAFARI_ECDHE_ECDSA_BUG (part of SSL_OP_ALL) which
|
|
||||||
avoids preferring ECDHE-ECDSA ciphers when the client appears to be
|
|
||||||
Safari on OS X. Safari on OS X 10.8..10.8.3 advertises support for
|
|
||||||
several ECDHE-ECDSA ciphers, but fails to negotiate them. The bug
|
|
||||||
is fixed in OS X 10.8.4, but Apple have ruled out both hot fixing
|
|
||||||
10.8..10.8.3 and forcing users to upgrade to 10.8.4 or newer.
|
|
||||||
[Rob Stradling, Adam Langley]
|
|
||||||
|
|
||||||
Changes between 0.9.8x and 0.9.8y [5 Feb 2013]
|
|
||||||
|
|
||||||
*) Make the decoding of SSLv3, TLS and DTLS CBC records constant time.
|
|
||||||
|
|
||||||
This addresses the flaw in CBC record processing discovered by
|
|
||||||
Nadhem Alfardan and Kenny Paterson. Details of this attack can be found
|
|
||||||
at: http://www.isg.rhul.ac.uk/tls/
|
|
||||||
|
|
||||||
Thanks go to Nadhem Alfardan and Kenny Paterson of the Information
|
|
||||||
Security Group at Royal Holloway, University of London
|
|
||||||
(www.isg.rhul.ac.uk) for discovering this flaw and Adam Langley and
|
|
||||||
Emilia K<>sper for the initial patch.
|
|
||||||
(CVE-2013-0169)
|
|
||||||
[Emilia K<>sper, Adam Langley, Ben Laurie, Andy Polyakov, Steve Henson]
|
|
||||||
|
|
||||||
*) Return an error when checking OCSP signatures when key is NULL.
|
|
||||||
This fixes a DoS attack. (CVE-2013-0166)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Call OCSP Stapling callback after ciphersuite has been chosen, so
|
|
||||||
the right response is stapled. Also change SSL_get_certificate()
|
|
||||||
so it returns the certificate actually sent.
|
|
||||||
See http://rt.openssl.org/Ticket/Display.html?id=2836.
|
|
||||||
(This is a backport)
|
|
||||||
[Rob Stradling <rob.stradling@comodo.com>]
|
|
||||||
|
|
||||||
*) Fix possible deadlock when decoding public keys.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
Changes between 0.9.8w and 0.9.8x [10 May 2012]
|
|
||||||
|
|
||||||
*) Sanity check record length before skipping explicit IV in DTLS
|
|
||||||
to fix DoS attack.
|
|
||||||
|
|
||||||
Thanks to Codenomicon for discovering this issue using Fuzz-o-Matic
|
|
||||||
fuzzing as a service testing platform.
|
|
||||||
(CVE-2012-2333)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Initialise tkeylen properly when encrypting CMS messages.
|
|
||||||
Thanks to Solar Designer of Openwall for reporting this issue.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
Changes between 0.9.8v and 0.9.8w [23 Apr 2012]
|
|
||||||
|
|
||||||
*) The fix for CVE-2012-2110 did not take into account that the
|
|
||||||
'len' argument to BUF_MEM_grow and BUF_MEM_grow_clean is an
|
|
||||||
int in OpenSSL 0.9.8, making it still vulnerable. Fix by
|
|
||||||
rejecting negative len parameter. (CVE-2012-2131)
|
|
||||||
[Tomas Hoger <thoger@redhat.com>]
|
|
||||||
|
|
||||||
Changes between 0.9.8u and 0.9.8v [19 Apr 2012]
|
|
||||||
|
|
||||||
*) Check for potentially exploitable overflows in asn1_d2i_read_bio
|
|
||||||
BUF_mem_grow and BUF_mem_grow_clean. Refuse attempts to shrink buffer
|
|
||||||
in CRYPTO_realloc_clean.
|
|
||||||
|
|
||||||
Thanks to Tavis Ormandy, Google Security Team, for discovering this
|
|
||||||
issue and to Adam Langley <agl@chromium.org> for fixing it.
|
|
||||||
(CVE-2012-2110)
|
|
||||||
[Adam Langley (Google), Tavis Ormandy, Google Security Team]
|
|
||||||
|
|
||||||
Changes between 0.9.8t and 0.9.8u [12 Mar 2012]
|
|
||||||
|
|
||||||
*) Fix MMA (Bleichenbacher's attack on PKCS #1 v1.5 RSA padding) weakness
|
|
||||||
in CMS and PKCS7 code. When RSA decryption fails use a random key for
|
|
||||||
content decryption and always return the same error. Note: this attack
|
|
||||||
needs on average 2^20 messages so it only affects automated senders. The
|
|
||||||
old behaviour can be reenabled in the CMS code by setting the
|
|
||||||
CMS_DEBUG_DECRYPT flag: this is useful for debugging and testing where
|
|
||||||
an MMA defence is not necessary.
|
|
||||||
Thanks to Ivan Nestlerode <inestlerode@us.ibm.com> for discovering
|
|
||||||
this issue. (CVE-2012-0884)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Fix CVE-2011-4619: make sure we really are receiving a
|
|
||||||
client hello before rejecting multiple SGC restarts. Thanks to
|
|
||||||
Ivan Nestlerode <inestlerode@us.ibm.com> for discovering this bug.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
Changes between 0.9.8s and 0.9.8t [18 Jan 2012]
|
|
||||||
|
|
||||||
*) Fix for DTLS DoS issue introduced by fix for CVE-2011-4109.
|
|
||||||
Thanks to Antonio Martin, Enterprise Secure Access Research and
|
|
||||||
Development, Cisco Systems, Inc. for discovering this bug and
|
|
||||||
preparing a fix. (CVE-2012-0050)
|
|
||||||
[Antonio Martin]
|
|
||||||
|
|
||||||
Changes between 0.9.8r and 0.9.8s [4 Jan 2012]
|
|
||||||
|
|
||||||
*) Nadhem Alfardan and Kenny Paterson have discovered an extension
|
|
||||||
of the Vaudenay padding oracle attack on CBC mode encryption
|
|
||||||
which enables an efficient plaintext recovery attack against
|
|
||||||
the OpenSSL implementation of DTLS. Their attack exploits timing
|
|
||||||
differences arising during decryption processing. A research
|
|
||||||
paper describing this attack can be found at:
|
|
||||||
http://www.isg.rhul.ac.uk/~kp/dtls.pdf
|
|
||||||
Thanks go to Nadhem Alfardan and Kenny Paterson of the Information
|
|
||||||
Security Group at Royal Holloway, University of London
|
|
||||||
(www.isg.rhul.ac.uk) for discovering this flaw and to Robin Seggelmann
|
|
||||||
<seggelmann@fh-muenster.de> and Michael Tuexen <tuexen@fh-muenster.de>
|
|
||||||
for preparing the fix. (CVE-2011-4108)
|
|
||||||
[Robin Seggelmann, Michael Tuexen]
|
|
||||||
|
|
||||||
*) Stop policy check failure freeing same buffer twice. (CVE-2011-4109)
|
|
||||||
[Ben Laurie, Kasper <ekasper@google.com>]
|
|
||||||
|
|
||||||
*) Clear bytes used for block padding of SSL 3.0 records.
|
|
||||||
(CVE-2011-4576)
|
|
||||||
[Adam Langley (Google)]
|
|
||||||
|
|
||||||
*) Only allow one SGC handshake restart for SSL/TLS. Thanks to George
|
|
||||||
Kadianakis <desnacked@gmail.com> for discovering this issue and
|
|
||||||
Adam Langley for preparing the fix. (CVE-2011-4619)
|
|
||||||
[Adam Langley (Google)]
|
|
||||||
|
|
||||||
*) Prevent malformed RFC3779 data triggering an assertion failure.
|
|
||||||
Thanks to Andrew Chi, BBN Technologies, for discovering the flaw
|
|
||||||
and Rob Austein <sra@hactrn.net> for fixing it. (CVE-2011-4577)
|
|
||||||
[Rob Austein <sra@hactrn.net>]
|
|
||||||
|
|
||||||
*) Fix ssl_ciph.c set-up race.
|
|
||||||
[Adam Langley (Google)]
|
|
||||||
|
|
||||||
*) Fix spurious failures in ecdsatest.c.
|
|
||||||
[Emilia K<>sper (Google)]
|
|
||||||
|
|
||||||
*) Fix the BIO_f_buffer() implementation (which was mixing different
|
|
||||||
interpretations of the '..._len' fields).
|
|
||||||
[Adam Langley (Google)]
|
|
||||||
|
|
||||||
*) Fix handling of BN_BLINDING: now BN_BLINDING_invert_ex (rather than
|
|
||||||
BN_BLINDING_invert_ex) calls BN_BLINDING_update, ensuring that concurrent
|
|
||||||
threads won't reuse the same blinding coefficients.
|
|
||||||
|
|
||||||
This also avoids the need to obtain the CRYPTO_LOCK_RSA_BLINDING
|
|
||||||
lock to call BN_BLINDING_invert_ex, and avoids one use of
|
|
||||||
BN_BLINDING_update for each BN_BLINDING structure (previously,
|
|
||||||
the last update always remained unused).
|
|
||||||
[Emilia K<>sper (Google)]
|
|
||||||
|
|
||||||
*) Fix SSL memory handling for (EC)DH ciphersuites, in particular
|
|
||||||
for multi-threaded use of ECDH.
|
|
||||||
[Adam Langley (Google)]
|
|
||||||
|
|
||||||
*) Fix x509_name_ex_d2i memory leak on bad inputs.
|
|
||||||
[Bodo Moeller]
|
|
||||||
|
|
||||||
*) Add protection against ECDSA timing attacks as mentioned in the paper
|
|
||||||
by Billy Bob Brumley and Nicola Tuveri, see:
|
|
||||||
|
|
||||||
http://eprint.iacr.org/2011/232.pdf
|
|
||||||
|
|
||||||
[Billy Bob Brumley and Nicola Tuveri]
|
|
||||||
|
|
||||||
Changes between 0.9.8q and 0.9.8r [8 Feb 2011]
|
|
||||||
|
|
||||||
*) Fix parsing of OCSP stapling ClientHello extension. CVE-2011-0014
|
|
||||||
[Neel Mehta, Adam Langley, Bodo Moeller (Google)]
|
|
||||||
|
|
||||||
*) Fix bug in string printing code: if *any* escaping is enabled we must
|
|
||||||
escape the escape character (backslash) or the resulting string is
|
|
||||||
ambiguous.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
Changes between 0.9.8p and 0.9.8q [2 Dec 2010]
|
|
||||||
|
|
||||||
*) Disable code workaround for ancient and obsolete Netscape browsers
|
|
||||||
and servers: an attacker can use it in a ciphersuite downgrade attack.
|
|
||||||
Thanks to Martin Rex for discovering this bug. CVE-2010-4180
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Fixed J-PAKE implementation error, originally discovered by
|
|
||||||
Sebastien Martini, further info and confirmation from Stefan
|
|
||||||
Arentz and Feng Hao. Note that this fix is a security fix. CVE-2010-4252
|
|
||||||
[Ben Laurie]
|
|
||||||
|
|
||||||
Changes between 0.9.8o and 0.9.8p [16 Nov 2010]
|
|
||||||
|
|
||||||
*) Fix extension code to avoid race conditions which can result in a buffer
|
|
||||||
overrun vulnerability: resumed sessions must not be modified as they can
|
|
||||||
be shared by multiple threads. CVE-2010-3864
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Fix for double free bug in ssl/s3_clnt.c CVE-2010-2939
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Don't reencode certificate when calculating signature: cache and use
|
|
||||||
the original encoding instead. This makes signature verification of
|
|
||||||
some broken encodings work correctly.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) ec2_GF2m_simple_mul bugfix: compute correct result if the output EC_POINT
|
|
||||||
is also one of the inputs.
|
|
||||||
[Emilia K<>sper <emilia.kasper@esat.kuleuven.be> (Google)]
|
|
||||||
|
|
||||||
*) Don't repeatedly append PBE algorithms to table if they already exist.
|
|
||||||
Sort table on each new add. This effectively makes the table read only
|
|
||||||
after all algorithms are added and subsequent calls to PKCS12_pbe_add
|
|
||||||
etc are non-op.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
Changes between 0.9.8n and 0.9.8o [01 Jun 2010]
|
|
||||||
|
|
||||||
[NB: OpenSSL 0.9.8o and later 0.9.8 patch levels were released after
|
|
||||||
OpenSSL 1.0.0.]
|
|
||||||
|
|
||||||
*) Correct a typo in the CMS ASN1 module which can result in invalid memory
|
|
||||||
access or freeing data twice (CVE-2010-0742)
|
|
||||||
[Steve Henson, Ronald Moesbergen <intercommit@gmail.com>]
|
|
||||||
|
|
||||||
*) Add SHA2 algorithms to SSL_library_init(). SHA2 is becoming far more
|
|
||||||
common in certificates and some applications which only call
|
|
||||||
SSL_library_init and not OpenSSL_add_all_algorithms() will fail.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) VMS fixes:
|
|
||||||
Reduce copying into .apps and .test in makevms.com
|
|
||||||
Don't try to use blank CA certificate in CA.com
|
|
||||||
Allow use of C files from original directories in maketests.com
|
|
||||||
[Steven M. Schweda" <sms@antinode.info>]
|
|
||||||
|
|
||||||
Changes between 0.9.8m and 0.9.8n [24 Mar 2010]
|
|
||||||
|
|
||||||
*) When rejecting SSL/TLS records due to an incorrect version number, never
|
|
||||||
update s->server with a new major version number. As of
|
|
||||||
- OpenSSL 0.9.8m if 'short' is a 16-bit type,
|
|
||||||
- OpenSSL 0.9.8f if 'short' is longer than 16 bits,
|
|
||||||
the previous behavior could result in a read attempt at NULL when
|
|
||||||
receiving specific incorrect SSL/TLS records once record payload
|
|
||||||
protection is active. (CVE-2010-0740)
|
|
||||||
[Bodo Moeller, Adam Langley <agl@chromium.org>]
|
|
||||||
|
|
||||||
*) Fix for CVE-2010-0433 where some kerberos enabled versions of OpenSSL
|
|
||||||
could be crashed if the relevant tables were not present (e.g. chrooted).
|
|
||||||
[Tomas Hoger <thoger@redhat.com>]
|
|
||||||
|
|
||||||
Changes between 0.9.8l and 0.9.8m [25 Feb 2010]
|
|
||||||
|
|
||||||
*) Always check bn_wexpend() return values for failure. (CVE-2009-3245)
|
|
||||||
[Martin Olsson, Neel Mehta]
|
|
||||||
|
|
||||||
*) Fix X509_STORE locking: Every 'objs' access requires a lock (to
|
|
||||||
accommodate for stack sorting, always a write lock!).
|
|
||||||
[Bodo Moeller]
|
|
||||||
|
|
||||||
*) On some versions of WIN32 Heap32Next is very slow. This can cause
|
|
||||||
excessive delays in the RAND_poll(): over a minute. As a workaround
|
|
||||||
include a time check in the inner Heap32Next loop too.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) The code that handled flushing of data in SSL/TLS originally used the
|
|
||||||
BIO_CTRL_INFO ctrl to see if any data was pending first. This caused
|
|
||||||
the problem outlined in PR#1949. The fix suggested there however can
|
|
||||||
trigger problems with buggy BIO_CTRL_WPENDING (e.g. some versions
|
|
||||||
of Apache). So instead simplify the code to flush unconditionally.
|
|
||||||
This should be fine since flushing with no data to flush is a no op.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Handle TLS versions 2.0 and later properly and correctly use the
|
|
||||||
highest version of TLS/SSL supported. Although TLS >= 2.0 is some way
|
|
||||||
off ancient servers have a habit of sticking around for a while...
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Modify compression code so it frees up structures without using the
|
|
||||||
ex_data callbacks. This works around a problem where some applications
|
|
||||||
call CRYPTO_cleanup_all_ex_data() before application exit (e.g. when
|
|
||||||
restarting) then use compression (e.g. SSL with compression) later.
|
|
||||||
This results in significant per-connection memory leaks and
|
|
||||||
has caused some security issues including CVE-2008-1678 and
|
|
||||||
CVE-2009-4355.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Constify crypto/cast (i.e., <openssl/cast.h>): a CAST_KEY doesn't
|
|
||||||
change when encrypting or decrypting.
|
|
||||||
[Bodo Moeller]
|
|
||||||
|
|
||||||
*) Add option SSL_OP_LEGACY_SERVER_CONNECT which will allow clients to
|
|
||||||
connect and renegotiate with servers which do not support RI.
|
|
||||||
Until RI is more widely deployed this option is enabled by default.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Add "missing" ssl ctrls to clear options and mode.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) If client attempts to renegotiate and doesn't support RI respond with
|
|
||||||
a no_renegotiation alert as required by RFC5746. Some renegotiating
|
|
||||||
TLS clients will continue a connection gracefully when they receive
|
|
||||||
the alert. Unfortunately OpenSSL mishandled this alert and would hang
|
|
||||||
waiting for a server hello which it will never receive. Now we treat a
|
|
||||||
received no_renegotiation alert as a fatal error. This is because
|
|
||||||
applications requesting a renegotiation might well expect it to succeed
|
|
||||||
and would have no code in place to handle the server denying it so the
|
|
||||||
only safe thing to do is to terminate the connection.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Add ctrl macro SSL_get_secure_renegotiation_support() which returns 1 if
|
|
||||||
peer supports secure renegotiation and 0 otherwise. Print out peer
|
|
||||||
renegotiation support in s_client/s_server.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Replace the highly broken and deprecated SPKAC certification method with
|
|
||||||
the updated NID creation version. This should correctly handle UTF8.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Implement RFC5746. Re-enable renegotiation but require the extension
|
|
||||||
as needed. Unfortunately, SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION
|
|
||||||
turns out to be a bad idea. It has been replaced by
|
|
||||||
SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION which can be set with
|
|
||||||
SSL_CTX_set_options(). This is really not recommended unless you
|
|
||||||
know what you are doing.
|
|
||||||
[Eric Rescorla <ekr@networkresonance.com>, Ben Laurie, Steve Henson]
|
|
||||||
|
|
||||||
*) Fixes to stateless session resumption handling. Use initial_ctx when
|
|
||||||
issuing and attempting to decrypt tickets in case it has changed during
|
|
||||||
servername handling. Use a non-zero length session ID when attempting
|
|
||||||
stateless session resumption: this makes it possible to determine if
|
|
||||||
a resumption has occurred immediately after receiving server hello
|
|
||||||
(several places in OpenSSL subtly assume this) instead of later in
|
|
||||||
the handshake.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) The functions ENGINE_ctrl(), OPENSSL_isservice(),
|
|
||||||
CMS_get1_RecipientRequest() and RAND_bytes() can return <=0 on error
|
|
||||||
fixes for a few places where the return code is not checked
|
|
||||||
correctly.
|
|
||||||
[Julia Lawall <julia@diku.dk>]
|
|
||||||
|
|
||||||
*) Add --strict-warnings option to Configure script to include devteam
|
|
||||||
warnings in other configurations.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Add support for --libdir option and LIBDIR variable in makefiles. This
|
|
||||||
makes it possible to install openssl libraries in locations which
|
|
||||||
have names other than "lib", for example "/usr/lib64" which some
|
|
||||||
systems need.
|
|
||||||
[Steve Henson, based on patch from Jeremy Utley]
|
|
||||||
|
|
||||||
*) Don't allow the use of leading 0x80 in OIDs. This is a violation of
|
|
||||||
X690 8.9.12 and can produce some misleading textual output of OIDs.
|
|
||||||
[Steve Henson, reported by Dan Kaminsky]
|
|
||||||
|
|
||||||
*) Delete MD2 from algorithm tables. This follows the recommendation in
|
|
||||||
several standards that it is not used in new applications due to
|
|
||||||
several cryptographic weaknesses. For binary compatibility reasons
|
|
||||||
the MD2 API is still compiled in by default.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Add compression id to {d2i,i2d}_SSL_SESSION so it is correctly saved
|
|
||||||
and restored.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Rename uni2asc and asc2uni functions to OPENSSL_uni2asc and
|
|
||||||
OPENSSL_asc2uni conditionally on Netware platforms to avoid a name
|
|
||||||
clash.
|
|
||||||
[Guenter <lists@gknw.net>]
|
|
||||||
|
|
||||||
*) Fix the server certificate chain building code to use X509_verify_cert(),
|
|
||||||
it used to have an ad-hoc builder which was unable to cope with anything
|
|
||||||
other than a simple chain.
|
|
||||||
[David Woodhouse <dwmw2@infradead.org>, Steve Henson]
|
|
||||||
|
|
||||||
*) Don't check self signed certificate signatures in X509_verify_cert()
|
|
||||||
by default (a flag can override this): it just wastes time without
|
|
||||||
adding any security. As a useful side effect self signed root CAs
|
|
||||||
with non-FIPS digests are now usable in FIPS mode.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) In dtls1_process_out_of_seq_message() the check if the current message
|
|
||||||
is already buffered was missing. For every new message was memory
|
|
||||||
allocated, allowing an attacker to perform an denial of service attack
|
|
||||||
with sending out of seq handshake messages until there is no memory
|
|
||||||
left. Additionally every future messege was buffered, even if the
|
|
||||||
sequence number made no sense and would be part of another handshake.
|
|
||||||
So only messages with sequence numbers less than 10 in advance will be
|
|
||||||
buffered. (CVE-2009-1378)
|
|
||||||
[Robin Seggelmann, discovered by Daniel Mentz]
|
|
||||||
|
|
||||||
*) Records are buffered if they arrive with a future epoch to be
|
|
||||||
processed after finishing the corresponding handshake. There is
|
|
||||||
currently no limitation to this buffer allowing an attacker to perform
|
|
||||||
a DOS attack with sending records with future epochs until there is no
|
|
||||||
memory left. This patch adds the pqueue_size() function to detemine
|
|
||||||
the size of a buffer and limits the record buffer to 100 entries.
|
|
||||||
(CVE-2009-1377)
|
|
||||||
[Robin Seggelmann, discovered by Daniel Mentz]
|
|
||||||
|
|
||||||
*) Keep a copy of frag->msg_header.frag_len so it can be used after the
|
|
||||||
parent structure is freed. (CVE-2009-1379)
|
|
||||||
[Daniel Mentz]
|
|
||||||
|
|
||||||
*) Handle non-blocking I/O properly in SSL_shutdown() call.
|
|
||||||
[Darryl Miles <darryl-mailinglists@netbauds.net>]
|
|
||||||
|
|
||||||
*) Add 2.5.4.* OIDs
|
|
||||||
[Ilya O. <vrghost@gmail.com>]
|
|
||||||
|
|
||||||
Changes between 0.9.8k and 0.9.8l [5 Nov 2009]
|
|
||||||
|
|
||||||
*) Disable renegotiation completely - this fixes a severe security
|
|
||||||
problem (CVE-2009-3555) at the cost of breaking all
|
|
||||||
renegotiation. Renegotiation can be re-enabled by setting
|
|
||||||
SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION in s3->flags at
|
|
||||||
run-time. This is really not recommended unless you know what
|
|
||||||
you're doing.
|
|
||||||
[Ben Laurie]
|
|
||||||
|
|
||||||
Changes between 0.9.8j and 0.9.8k [25 Mar 2009]
|
|
||||||
|
|
||||||
*) Don't set val to NULL when freeing up structures, it is freed up by
|
|
||||||
underlying code. If sizeof(void *) > sizeof(long) this can result in
|
|
||||||
zeroing past the valid field. (CVE-2009-0789)
|
|
||||||
[Paolo Ganci <Paolo.Ganci@AdNovum.CH>]
|
|
||||||
|
|
||||||
*) Fix bug where return value of CMS_SignerInfo_verify_content() was not
|
|
||||||
checked correctly. This would allow some invalid signed attributes to
|
|
||||||
appear to verify correctly. (CVE-2009-0591)
|
|
||||||
[Ivan Nestlerode <inestlerode@us.ibm.com>]
|
|
||||||
|
|
||||||
*) Reject UniversalString and BMPString types with invalid lengths. This
|
|
||||||
prevents a crash in ASN1_STRING_print_ex() which assumes the strings have
|
|
||||||
a legal length. (CVE-2009-0590)
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Set S/MIME signing as the default purpose rather than setting it
|
|
||||||
unconditionally. This allows applications to override it at the store
|
|
||||||
level.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Permit restricted recursion of ASN1 strings. This is needed in practice
|
|
||||||
to handle some structures.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Improve efficiency of mem_gets: don't search whole buffer each time
|
|
||||||
for a '\n'
|
|
||||||
[Jeremy Shapiro <jnshapir@us.ibm.com>]
|
|
||||||
|
|
||||||
*) New -hex option for openssl rand.
|
|
||||||
[Matthieu Herrb]
|
|
||||||
|
|
||||||
*) Print out UTF8String and NumericString when parsing ASN1.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Support NumericString type for name components.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
*) Allow CC in the environment to override the automatically chosen
|
|
||||||
compiler. Note that nothing is done to ensure flags work with the
|
|
||||||
chosen compiler.
|
|
||||||
[Ben Laurie]
|
|
||||||
|
|
||||||
Changes between 0.9.8i and 0.9.8j [07 Jan 2009]
|
|
||||||
|
|
||||||
*) Properly check EVP_VerifyFinal() and similar return values
|
|
||||||
(CVE-2008-5077).
|
|
||||||
[Ben Laurie, Bodo Moeller, Google Security Team]
|
|
||||||
|
|
||||||
*) Enable TLS extensions by default.
|
|
||||||
[Ben Laurie]
|
|
||||||
|
|
||||||
*) Allow the CHIL engine to be loaded, whether the application is
|
|
||||||
multithreaded or not. (This does not release the developer from the
|
|
||||||
obligation to set up the dynamic locking callbacks.)
|
|
||||||
[Sander Temme <sander@temme.net>]
|
|
||||||
|
|
||||||
*) Use correct exit code if there is an error in dgst command.
|
|
||||||
[Steve Henson; problem pointed out by Roland Dirlewanger]
|
|
||||||
|
|
||||||
*) Tweak Configure so that you need to say "experimental-jpake" to enable
|
|
||||||
JPAKE, and need to use -DOPENSSL_EXPERIMENTAL_JPAKE in applications.
|
|
||||||
[Bodo Moeller]
|
|
||||||
|
|
||||||
*) Add experimental JPAKE support, including demo authentication in
|
|
||||||
s_client and s_server.
|
|
||||||
[Ben Laurie]
|
|
||||||
|
|
||||||
*) Set the comparison function in v3_addr_canonize().
|
|
||||||
[Rob Austein <sra@hactrn.net>]
|
|
||||||
|
|
||||||
*) Add support for XMPP STARTTLS in s_client.
|
|
||||||
[Philip Paeps <philip@freebsd.org>]
|
|
||||||
|
|
||||||
*) Change the server-side SSL_OP_NETSCAPE_REUSE_CIPHER_CHANGE_BUG behavior
|
|
||||||
to ensure that even with this option, only ciphersuites in the
|
|
||||||
server's preference list will be accepted. (Note that the option
|
|
||||||
applies only when resuming a session, so the earlier behavior was
|
|
||||||
just about the algorithm choice for symmetric cryptography.)
|
|
||||||
[Bodo Moeller]
|
|
||||||
|
|
||||||
Changes between 0.9.8h and 0.9.8i [15 Sep 2008]
|
|
||||||
|
|
||||||
*) Fix NULL pointer dereference if a DTLS server received
|
|
||||||
ChangeCipherSpec as first record (CVE-2009-1386).
|
|
||||||
[PR #1679]
|
|
||||||
|
|
||||||
*) Fix a state transitition in s3_srvr.c and d1_srvr.c
|
*) Fix a state transitition in s3_srvr.c and d1_srvr.c
|
||||||
(was using SSL3_ST_CW_CLNT_HELLO_B, should be ..._ST_SW_SRVR_...).
|
(was using SSL3_ST_CW_CLNT_HELLO_B, should be ..._ST_SW_SRVR_...).
|
||||||
@@ -755,10 +34,6 @@
|
|||||||
|
|
||||||
[Neel Mehta, Bodo Moeller]
|
[Neel Mehta, Bodo Moeller]
|
||||||
|
|
||||||
*) Allow engines to be "soft loaded" - i.e. optionally don't die if
|
|
||||||
the load fails. Useful for distros.
|
|
||||||
[Ben Laurie and the FreeBSD team]
|
|
||||||
|
|
||||||
*) Add support for Local Machine Keyset attribute in PKCS#12 files.
|
*) Add support for Local Machine Keyset attribute in PKCS#12 files.
|
||||||
[Steve Henson]
|
[Steve Henson]
|
||||||
|
|
||||||
@@ -777,11 +52,9 @@
|
|||||||
This work was sponsored by Logica.
|
This work was sponsored by Logica.
|
||||||
[Steve Henson]
|
[Steve Henson]
|
||||||
|
|
||||||
*) Fix bug in X509_ATTRIBUTE creation: dont set attribute using
|
*) Allow engines to be "soft loaded" - i.e. optionally don't die if
|
||||||
ASN1_TYPE_set1 if MBSTRING flag set. This bug would crash certain
|
the load fails. Useful for distros.
|
||||||
attribute creation routines such as certifcate requests and PKCS#12
|
[Ben Laurie and the FreeBSD team]
|
||||||
files.
|
|
||||||
[Steve Henson]
|
|
||||||
|
|
||||||
Changes between 0.9.8g and 0.9.8h [28 May 2008]
|
Changes between 0.9.8g and 0.9.8h [28 May 2008]
|
||||||
|
|
||||||
@@ -919,6 +192,138 @@
|
|||||||
to s_client and s_server.
|
to s_client and s_server.
|
||||||
[Steve Henson]
|
[Steve Henson]
|
||||||
|
|
||||||
|
Changes between 0.9.8g and 0.9.8h-fips [xx XXX xxxx]
|
||||||
|
|
||||||
|
*) Add flag EVP_CIPH_FLAG_LENGTH_BITS to indicate that input buffer length
|
||||||
|
is in bits not bytes. The Monte Carlo FIPS140-2 CFB1 tests require this.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Add option --with-fipslibdir to specify location of fipscanister.lib
|
||||||
|
and friends. When combined with fips build option fipscanister.lib is
|
||||||
|
not built but linked from the supplied directory. Always link fips
|
||||||
|
utilities against fiscanister.lib only except in fipsdso builds.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Add SSE2 instruction support to WIN32 build. These will be compiled
|
||||||
|
by default and used if an appopriate CPU is detected. Some older versions
|
||||||
|
of NASM or MASM which don't support SSE2 will need to be updated.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Tolerate DigestInfo structure with absent parameters in FIPS mode
|
||||||
|
(as required by several standards).
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Enhance mkfipsscr.pl to cope with different directory layouts. It now
|
||||||
|
relies on the filename and makes no assumptions about the pathname.
|
||||||
|
In the case of PSS it scans the file to determine the salt length.
|
||||||
|
Paths can be filtered. Also reports duplicate and missing files.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Updates to WIN32 build system. Make use of AES assembly language routines.
|
||||||
|
Use assembly language routines in FIPS compilation.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Use standard implementations of SHAx, DES, AES under crypto/ in FIPS
|
||||||
|
mode to avoid having to maintain two versions. This will also make use
|
||||||
|
of appropriate assembly language optimizations.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Check for selftest status in all crypto operations and exit with a
|
||||||
|
fatal error if selftest failed.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) New flag in EVP_CIPHER: EVP_CIPH_FLAG_DEFAULT_ASN1. This will
|
||||||
|
automatically use EVP_CIPHER_{get,set}_asn1_iv and avoid the
|
||||||
|
need for any ASN1 dependencies in FIPS library. Move AES and 3DES
|
||||||
|
cipher definitions to fips library and modify AES and 3DES algorithm
|
||||||
|
tests and self tests to use EVP.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Move EVP cipher code into enc_min.c to support a minimal implementation
|
||||||
|
for use by FIPS applications.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Add algorithm config module. Currently just handles setting FIPS mode.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Rewrite self tests and pairwise tests to use EVP. Add more extensive
|
||||||
|
self tests for RSA in all digests and modes.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) New flags RSA_FIPS_METHOD and DSA_FIPS_METHOD to indicate a method is
|
||||||
|
allowed in FIPS mode. Disable direct low level RSA and DSA signature
|
||||||
|
operations in FIPS mode so all operations have to be made via EVP.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) New flag EVP_MD_FLAG_SVCTX which passes EVP_MD_CTX and key to underlying
|
||||||
|
sign/verify method. This permits the method to perform finalization
|
||||||
|
and signing itself and have access to the EVP_MD_CTX structure in case
|
||||||
|
additional parameters are needed. Modify fips_{dsa,rsa}_{sign,verify}
|
||||||
|
to use EVP_MD_FLAG_SVCTX and support PSS and X9.31 RSA modes.
|
||||||
|
Modify RSA algorithm test programs to use new parameters.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Add small standalone ASN1 encoder/decoder to handle DSA signature format.
|
||||||
|
Modify test, algorithm test and selftest routines to use EVP for DSA.
|
||||||
|
Move FIPS implementation of EVP_sha*() and EVP_dss1() under fips-1.0.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Modify VC++ build system to rename .text and .rdata segments in
|
||||||
|
FIPS sources to .fipst${a,b,c}, and $fipsr${a,b,c} and place them
|
||||||
|
in a static library fipscanister.lib using a perl script. These are
|
||||||
|
then combined by the VC++ linker into a single segment in suffix
|
||||||
|
order but without the suffix (i.e. .fipstx, .fipsrd and .fipsda).
|
||||||
|
This serves the same purpose as fipscanister.o on other platforms
|
||||||
|
but has the advantage that it can be created using only standard VC++
|
||||||
|
utilities.
|
||||||
|
[Steve Henson and Andy Polyakov]
|
||||||
|
|
||||||
|
*) Modify WIN32 build system to forward references functions implemented
|
||||||
|
in FIPS DLL.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Move error library so that all lhash dependencies are in a separate
|
||||||
|
file. Include a simplified ERR_get_state() function for stand alone
|
||||||
|
FIPS applications. Include a initialization function OPENSSL_init()
|
||||||
|
to set all callbacks, automatically call OPENSSL_init() once when
|
||||||
|
a cipher or digest is added. This should mean that almost all applications
|
||||||
|
set the callbacks automatically. Exceptional cases can call OPENSSL_init()
|
||||||
|
manually like this:
|
||||||
|
|
||||||
|
#ifdef OPENSSL_HAVE_INIT
|
||||||
|
OPENSSL_init();
|
||||||
|
#endif
|
||||||
|
before starting any threads.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Collect common functions into header file "fips_utl.h".
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Only enable dynamic lock functionality in CRYPTO_lock() when it is really
|
||||||
|
needed. Move some lock functionality into new file dyn_lck.c .
|
||||||
|
This further reduces FIPS dependencies allowing the complete removal
|
||||||
|
of STACK and OBJ_bsearch().
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Reduce FIPS test program dependencies by providing stand alone
|
||||||
|
versions of some existing functions in libcrypto. Avoid use
|
||||||
|
of BIOs by converting to system stdio. Move some functions in FIPS
|
||||||
|
files: e.g. all use of BIO_printf().
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Modify build of libcrypto in FIPS mode by using a perl
|
||||||
|
script "arx.pl" which calls the archiver specifically
|
||||||
|
excluding any FIPS dependencies in libcrypto.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
*) Port OpenSSL 0.9.7 FIPS code to 0.9.8. Convert to new
|
||||||
|
Makefile form. Update Configure. Convert and update
|
||||||
|
FIPS source files. Update libcrypto, libssl and apps
|
||||||
|
with additional functionality from 0.9.7 FIPS code.
|
||||||
|
Update Windows build system.
|
||||||
|
[Steve Henson]
|
||||||
|
|
||||||
|
|
||||||
Changes between 0.9.8f and 0.9.8g [19 Oct 2007]
|
Changes between 0.9.8f and 0.9.8g [19 Oct 2007]
|
||||||
|
|
||||||
*) Fix various bugs:
|
*) Fix various bugs:
|
||||||
@@ -2128,6 +1533,19 @@
|
|||||||
differing sizes.
|
differing sizes.
|
||||||
[Richard Levitte]
|
[Richard Levitte]
|
||||||
|
|
||||||
|
Changes between 0.9.7m and 0.9.7n [xx XXX xxxx]
|
||||||
|
|
||||||
|
*) In the SSL/TLS server implementation, be strict about session ID
|
||||||
|
context matching (which matters if an application uses a single
|
||||||
|
external cache for different purposes). Previously,
|
||||||
|
out-of-context reuse was forbidden only if SSL_VERIFY_PEER was
|
||||||
|
set. This did ensure strict client verification, but meant that,
|
||||||
|
with applications using a single external cache for quite
|
||||||
|
different requirements, clients could circumvent ciphersuite
|
||||||
|
restrictions for a given session ID context by starting a session
|
||||||
|
in a different context.
|
||||||
|
[Bodo Moeller]
|
||||||
|
|
||||||
Changes between 0.9.7l and 0.9.7m [23 Feb 2007]
|
Changes between 0.9.7l and 0.9.7m [23 Feb 2007]
|
||||||
|
|
||||||
*) Cleanse PEM buffers before freeing them since they may contain
|
*) Cleanse PEM buffers before freeing them since they may contain
|
||||||
|
|||||||
163
ChangeLog.0_9_7-stable_not-in-head
Normal file
163
ChangeLog.0_9_7-stable_not-in-head
Normal file
@@ -0,0 +1,163 @@
|
|||||||
|
This file, together with ChangeLog.0_9_7-stable_not-in-head_FIPS,
|
||||||
|
provides a collection of those CVS change log entries for the
|
||||||
|
0.9.7 branch (OpenSSL_0_9_7-stable) that do not appear similarly in
|
||||||
|
0.9.8-dev (CVS head).
|
||||||
|
|
||||||
|
ChangeLog.0_9_7-stable_not-in-head_FIPS - "FIPS" related changes
|
||||||
|
ChangeLog.0_9_7-stable_not-in-head - everything else
|
||||||
|
|
||||||
|
Some obvious false positives have been eliminated: e.g., we do not
|
||||||
|
care about a simple "make update"; and we don't care about changes
|
||||||
|
identified to the 0.9.7 branch that were explicitly identified as
|
||||||
|
backports from head.
|
||||||
|
|
||||||
|
Eliminating all other entries (and finally this file and its
|
||||||
|
compantion), either as false positives or as things that should go
|
||||||
|
into 0.9.8, remains to be done. Any additional changes to 0.9.7 that
|
||||||
|
are not immediately put into 0.9.8, but belong there as well, should
|
||||||
|
be added to the end of this file.
|
||||||
|
|
||||||
|
|
||||||
|
2002-11-04 17:33 levitte
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
Configure (1.314.2.38), "Exp", lines: +4 -2
|
||||||
|
|
||||||
|
Return my normal debug targets to something not so extreme, and
|
||||||
|
make the extreme ones special (or 'extreme', if you will :-)).
|
||||||
|
|
||||||
|
2002-12-16 19:17 appro
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
crypto/bn/bn_lcl.h (1.23.2.3), "Exp", lines: +3 -0
|
||||||
|
crypto/bn/bn_mul.c (1.28.2.4), "Exp", lines: +84 -445
|
||||||
|
|
||||||
|
This is rollback to 0.9.6h bn_mul.c to address problem reported in
|
||||||
|
RT#272.
|
||||||
|
|
||||||
|
2003-07-27 15:46 ben
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
crypto/aes/aes.h (1.1.2.5), "Exp", lines: +3 -0
|
||||||
|
crypto/aes/aes_cfb.c (1.1.2.4), "Exp", lines: +57 -0
|
||||||
|
|
||||||
|
Add untested CFB-r mode. Will be tested soon.
|
||||||
|
|
||||||
|
2003-07-28 17:07 ben
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
Makefile.org (1.154.2.69), "Exp", lines: +5 -1
|
||||||
|
crypto/aes/aes.h (1.1.2.6), "Exp", lines: +3 -0
|
||||||
|
crypto/aes/aes_cfb.c (1.1.2.5), "Exp", lines: +19 -0
|
||||||
|
crypto/dsa/Makefile.ssl (1.49.2.6), "Exp", lines: +3 -2
|
||||||
|
crypto/err/Makefile.ssl (1.48.2.4), "Exp", lines: +17 -16
|
||||||
|
crypto/evp/e_aes.c (1.6.2.5), "Exp", lines: +8 -0
|
||||||
|
crypto/evp/e_des.c (1.5.2.2), "Exp", lines: +1 -1
|
||||||
|
crypto/evp/e_des3.c (1.8.2.3), "Exp", lines: +2 -2
|
||||||
|
crypto/evp/evp.h (1.86.2.11), "Exp", lines: +28 -11
|
||||||
|
crypto/evp/evp_locl.h (1.7.2.3), "Exp", lines: +2 -2
|
||||||
|
crypto/objects/obj_dat.h (1.49.2.13), "Exp", lines: +10 -5
|
||||||
|
crypto/objects/obj_mac.h (1.19.2.13), "Exp", lines: +5 -0
|
||||||
|
crypto/objects/obj_mac.num (1.15.2.9), "Exp", lines: +1 -0
|
||||||
|
crypto/objects/objects.txt (1.20.2.14), "Exp", lines: +4 -0
|
||||||
|
fips/Makefile.ssl (1.1.2.3), "Exp", lines: +7 -0
|
||||||
|
fips/aes/Makefile.ssl (1.1.2.2), "Exp", lines: +23 -1
|
||||||
|
fips/aes/fips_aesavs.c (1.1.2.3), "Exp", lines: +9 -1
|
||||||
|
test/Makefile.ssl (1.84.2.30), "Exp", lines: +101 -43
|
||||||
|
|
||||||
|
Add support for partial CFB modes, make tests work, update
|
||||||
|
dependencies.
|
||||||
|
|
||||||
|
2003-07-29 12:56 ben
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
crypto/aes/aes_cfb.c (1.1.2.6), "Exp", lines: +9 -6
|
||||||
|
crypto/evp/c_allc.c (1.8.2.3), "Exp", lines: +1 -0
|
||||||
|
crypto/evp/evp_test.c (1.14.2.11), "Exp", lines: +17 -8
|
||||||
|
crypto/evp/evptests.txt (1.9.2.2), "Exp", lines: +48 -1
|
||||||
|
|
||||||
|
Working CFB1 and test vectors.
|
||||||
|
|
||||||
|
2003-07-29 15:24 ben
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
crypto/evp/e_aes.c (1.6.2.6), "Exp", lines: +14 -0
|
||||||
|
crypto/objects/obj_dat.h (1.49.2.14), "Exp", lines: +15 -5
|
||||||
|
crypto/objects/obj_mac.h (1.19.2.14), "Exp", lines: +10 -0
|
||||||
|
crypto/objects/obj_mac.num (1.15.2.10), "Exp", lines: +2 -0
|
||||||
|
crypto/objects/objects.txt (1.20.2.15), "Exp", lines: +2 -0
|
||||||
|
fips/aes/Makefile.ssl (1.1.2.3), "Exp", lines: +1 -1
|
||||||
|
fips/aes/fips_aesavs.c (1.1.2.4), "Exp", lines: +34 -19
|
||||||
|
|
||||||
|
The rest of the keysizes for CFB1, working AES AVS test for CFB1.
|
||||||
|
|
||||||
|
2003-07-29 19:05 ben
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
crypto/aes/aes.h (1.1.2.7), "Exp", lines: +3 -0
|
||||||
|
crypto/aes/aes_cfb.c (1.1.2.7), "Exp", lines: +14 -0
|
||||||
|
crypto/evp/c_allc.c (1.8.2.4), "Exp", lines: +1 -0
|
||||||
|
crypto/evp/e_aes.c (1.6.2.7), "Exp", lines: +4 -9
|
||||||
|
crypto/evp/evptests.txt (1.9.2.3), "Exp", lines: +48 -0
|
||||||
|
crypto/objects/obj_dat.h (1.49.2.15), "Exp", lines: +20 -5
|
||||||
|
crypto/objects/obj_mac.h (1.19.2.15), "Exp", lines: +15 -0
|
||||||
|
crypto/objects/obj_mac.num (1.15.2.11), "Exp", lines: +3 -0
|
||||||
|
crypto/objects/objects.txt (1.20.2.16), "Exp", lines: +3 -0
|
||||||
|
fips/aes/fips_aesavs.c (1.1.2.7), "Exp", lines: +11 -0
|
||||||
|
|
||||||
|
AES CFB8.
|
||||||
|
|
||||||
|
2003-07-30 20:30 ben
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
Makefile.org (1.154.2.70), "Exp", lines: +16 -5
|
||||||
|
crypto/des/cfb_enc.c (1.7.2.1), "Exp", lines: +2 -1
|
||||||
|
crypto/des/des_enc.c (1.11.2.2), "Exp", lines: +4 -0
|
||||||
|
crypto/evp/e_aes.c (1.6.2.8), "Exp", lines: +7 -14
|
||||||
|
crypto/evp/e_des.c (1.5.2.3), "Exp", lines: +37 -1
|
||||||
|
crypto/evp/evp.h (1.86.2.12), "Exp", lines: +6 -0
|
||||||
|
crypto/evp/evp_locl.h (1.7.2.4), "Exp", lines: +9 -0
|
||||||
|
crypto/objects/obj_dat.h (1.49.2.16), "Exp", lines: +48 -23
|
||||||
|
crypto/objects/obj_mac.h (1.19.2.16), "Exp", lines: +31 -6
|
||||||
|
crypto/objects/obj_mac.num (1.15.2.12), "Exp", lines: +5 -0
|
||||||
|
crypto/objects/objects.txt (1.20.2.17), "Exp", lines: +12 -6
|
||||||
|
fips/Makefile.ssl (1.1.2.4), "Exp", lines: +8 -1
|
||||||
|
fips/fips_make_sha1 (1.1.2.3), "Exp", lines: +3 -0
|
||||||
|
fips/aes/Makefile.ssl (1.1.2.4), "Exp", lines: +1 -1
|
||||||
|
fips/des/.cvsignore (1.1.2.1), "Exp", lines: +3 -0
|
||||||
|
fips/des/Makefile.ssl (1.1.2.1), "Exp", lines: +96 -0
|
||||||
|
fips/des/fingerprint.sha1 (1.1.2.1), "Exp", lines: +2 -0
|
||||||
|
fips/des/fips_des_enc.c (1.1.2.1), "Exp", lines: +288 -0
|
||||||
|
fips/des/fips_des_locl.h (1.1.2.1), "Exp", lines: +428 -0
|
||||||
|
fips/des/fips_desmovs.c (1.1.2.1), "Exp", lines: +659 -0
|
||||||
|
|
||||||
|
Whoops, forgot FIPS DES, also add EVPs for DES CFB1 and 8.
|
||||||
|
|
||||||
|
2003-08-01 12:25 ben
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
crypto/des/cfb_enc.c (1.7.2.2), "Exp", lines: +45 -36
|
||||||
|
crypto/evp/c_allc.c (1.8.2.5), "Exp", lines: +2 -0
|
||||||
|
crypto/evp/e_des.c (1.5.2.4), "Exp", lines: +8 -3
|
||||||
|
crypto/evp/evptests.txt (1.9.2.4), "Exp", lines: +6 -0
|
||||||
|
|
||||||
|
Fix DES CFB-r.
|
||||||
|
|
||||||
|
2003-08-01 12:31 ben
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
crypto/evp/evptests.txt (1.9.2.5), "Exp", lines: +4 -0
|
||||||
|
|
||||||
|
DES CFB8 test.
|
||||||
|
|
||||||
|
2005-04-19 16:21 appro
|
||||||
|
|
||||||
|
Changed:
|
||||||
|
Configure (1.314.2.117), "Exp", lines: +24 -21
|
||||||
|
Makefile.org (1.154.2.100), "Exp", lines: +1 -11
|
||||||
|
TABLE (1.99.2.52), "Exp", lines: +20 -20
|
||||||
|
apps/Makefile (1.1.4.15), "Exp", lines: +1 -1
|
||||||
|
test/Makefile (1.1.4.12), "Exp", lines: +1 -1
|
||||||
|
|
||||||
|
Enable shared link on HP-UX.
|
||||||
|
|
||||||
1494
ChangeLog.0_9_7-stable_not-in-head_FIPS
Normal file
1494
ChangeLog.0_9_7-stable_not-in-head_FIPS
Normal file
File diff suppressed because it is too large
Load Diff
290
Configure
290
Configure
@@ -12,7 +12,7 @@ print STDERR "Warning: perl module strict not found.\n" if ($@);
|
|||||||
|
|
||||||
# see INSTALL for instructions.
|
# see INSTALL for instructions.
|
||||||
|
|
||||||
my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [experimental-<cipher> ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]shared] [[no-]zlib|zlib-dynamic] [enable-montasm] [no-asm] [no-dso] [no-krb5] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--test-sanity] os/compiler[:flags]\n";
|
my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [-Dxxx] [-lxxx] [-Lxxx] [-fxxx] [-Kxxx] [no-hw-xxx|no-hw] [[no-]threads] [[no-]shared] [[no-]zlib|zlib-dynamic] [no-asm] [no-dso] [no-krb5] [386] [--prefix=DIR] [--openssldir=OPENSSLDIR] [--with-xxx[=vvv]] [--test-sanity] os/compiler[:flags]\n";
|
||||||
|
|
||||||
# Options:
|
# Options:
|
||||||
#
|
#
|
||||||
@@ -56,8 +56,6 @@ my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [experimenta
|
|||||||
# [no-]zlib [don't] compile support for zlib compression.
|
# [no-]zlib [don't] compile support for zlib compression.
|
||||||
# zlib-dynamic Like "zlib", but the zlib library is expected to be a shared
|
# zlib-dynamic Like "zlib", but the zlib library is expected to be a shared
|
||||||
# library and will be loaded in run-time by the OpenSSL library.
|
# library and will be loaded in run-time by the OpenSSL library.
|
||||||
# enable-montasm 0.9.8 branch only: enable Montgomery x86 assembler backport
|
|
||||||
# from 0.9.9
|
|
||||||
# 386 generate 80386 code
|
# 386 generate 80386 code
|
||||||
# no-sse2 disables IA-32 SSE2 code, above option implies no-sse2
|
# no-sse2 disables IA-32 SSE2 code, above option implies no-sse2
|
||||||
# no-<cipher> build without specified algorithm (rsa, idea, rc5, ...)
|
# no-<cipher> build without specified algorithm (rsa, idea, rc5, ...)
|
||||||
@@ -101,13 +99,6 @@ my $usage="Usage: Configure [no-<cipher> ...] [enable-<cipher> ...] [experimenta
|
|||||||
# SHA512_ASM sha512_block is implemented in assembler
|
# SHA512_ASM sha512_block is implemented in assembler
|
||||||
# AES_ASM ASE_[en|de]crypt is implemented in assembler
|
# AES_ASM ASE_[en|de]crypt is implemented in assembler
|
||||||
|
|
||||||
# Minimum warning options... any contributions to OpenSSL should at least get
|
|
||||||
# past these.
|
|
||||||
|
|
||||||
my $gcc_devteam_warn = "-Wall -pedantic -DPEDANTIC -Wno-long-long -Wsign-compare -Wmissing-prototypes -Wshadow -Wformat -Werror -DCRYPTO_MDEBUG_ALL -DCRYPTO_MDEBUG_ABORT -DREF_CHECK -DOPENSSL_NO_DEPRECATED";
|
|
||||||
|
|
||||||
my $strict_warnings = 0;
|
|
||||||
|
|
||||||
my $x86_gcc_des="DES_PTR DES_RISC1 DES_UNROLL";
|
my $x86_gcc_des="DES_PTR DES_RISC1 DES_UNROLL";
|
||||||
|
|
||||||
# MD2_CHAR slags pentium pros
|
# MD2_CHAR slags pentium pros
|
||||||
@@ -125,15 +116,17 @@ my $tlib="-lnsl -lsocket";
|
|||||||
my $bits1="THIRTY_TWO_BIT ";
|
my $bits1="THIRTY_TWO_BIT ";
|
||||||
my $bits2="SIXTY_FOUR_BIT ";
|
my $bits2="SIXTY_FOUR_BIT ";
|
||||||
|
|
||||||
my $x86_elf_asm="x86cpuid-elf.o:bn86-elf.o co86-elf.o MAYBE-MO86-elf.o:dx86-elf.o yx86-elf.o:ax86-elf.o:bx86-elf.o:mx86-elf.o:sx86-elf.o s512sse2-elf.o:cx86-elf.o:rx86-elf.o rc4_skey.o:rm86-elf.o:r586-elf.o";
|
my $x86_elf_asm="x86cpuid-elf.o:bn86-elf.o co86-elf.o mo86-elf.o:dx86-elf.o yx86-elf.o:ax86-elf.o:bx86-elf.o:mx86-elf.o:sx86-elf.o s512sse2-elf.o:cx86-elf.o:rx86-elf.o rc4_skey.o:rm86-elf.o:r586-elf.o";
|
||||||
my $x86_coff_asm="x86cpuid-cof.o:bn86-cof.o co86-cof.o MAYBE-MO86-cof.o:dx86-cof.o yx86-cof.o:ax86-cof.o:bx86-cof.o:mx86-cof.o:sx86-cof.o s512sse2-cof.o:cx86-cof.o:rx86-cof.o rc4_skey.o:rm86-cof.o:r586-cof.o";
|
my $x86_coff_asm="x86cpuid-cof.o:bn86-cof.o co86-cof.o mo86-cof.o:dx86-cof.o yx86-cof.o:ax86-cof.o:bx86-cof.o:mx86-cof.o:sx86-cof.o s512sse2-cof.o:cx86-cof.o:rx86-cof.o rc4_skey.o:rm86-cof.o:r586-cof.o";
|
||||||
my $x86_out_asm="x86cpuid-out.o:bn86-out.o co86-out.o MAYBE-MO86-out.o:dx86-out.o yx86-out.o:ax86-out.o:bx86-out.o:mx86-out.o:sx86-out.o s512sse2-out.o:cx86-out.o:rx86-out.o rc4_skey.o:rm86-out.o:r586-out.o";
|
my $x86_out_asm="x86cpuid-out.o:bn86-out.o co86-out.o mo86-out.o:dx86-out.o yx86-out.o:ax86-out.o:bx86-out.o:mx86-out.o:sx86-out.o s512sse2-out.o:cx86-out.o:rx86-out.o rc4_skey.o:rm86-out.o:r586-out.o";
|
||||||
|
|
||||||
my $x86_64_asm="x86_64cpuid.o:x86_64-gcc.o x86_64-mont.o::aes-x86_64.o::md5-x86_64.o:sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o::rc4-x86_64.o::";
|
my $x86_64_asm="x86_64cpuid.o:x86_64-gcc.o x86_64-mont.o::aes-x86_64.o::md5-x86_64.o:sha1-x86_64.o sha256-x86_64.o sha512-x86_64.o::rc4-x86_64.o::";
|
||||||
my $ia64_asm=":bn-ia64.o::aes_core.o aes_cbc.o aes-ia64.o:::sha1-ia64.o sha256-ia64.o sha512-ia64.o::rc4-ia64.o rc4_skey.o::";
|
|
||||||
|
|
||||||
my $no_asm="::::::::::";
|
my $no_asm="::::::::::";
|
||||||
|
|
||||||
|
my $ia64_asm=":bn-ia64.o::aes_core.o aes_cbc.o aes-ia64.o:::sha1-ia64.o sha256-ia64.o sha512-ia64.o::rc4-ia64.o rc4_skey.o::";
|
||||||
|
my $s390x_asm=$no_asm;
|
||||||
|
|
||||||
# As for $BSDthreads. Idea is to maintain "collective" set of flags,
|
# As for $BSDthreads. Idea is to maintain "collective" set of flags,
|
||||||
# which would cover all BSD flavors. -pthread applies to them all,
|
# which would cover all BSD flavors. -pthread applies to them all,
|
||||||
# but is treated differently. OpenBSD expands is as -D_POSIX_THREAD
|
# but is treated differently. OpenBSD expands is as -D_POSIX_THREAD
|
||||||
@@ -161,30 +154,24 @@ my %table=(
|
|||||||
"debug-ben", "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown):::::bn86-elf.o co86-elf.o",
|
"debug-ben", "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown):::::bn86-elf.o co86-elf.o",
|
||||||
"debug-ben-openbsd","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -DOPENSSL_OPENBSD_DEV_CRYPTO -DOPENSSL_NO_ASM -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown)::::",
|
"debug-ben-openbsd","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -DOPENSSL_OPENBSD_DEV_CRYPTO -DOPENSSL_NO_ASM -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown)::::",
|
||||||
"debug-ben-openbsd-debug","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -DOPENSSL_OPENBSD_DEV_CRYPTO -DOPENSSL_NO_ASM -g3 -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown)::::",
|
"debug-ben-openbsd-debug","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -DOPENSSL_OPENBSD_DEV_CRYPTO -DOPENSSL_NO_ASM -g3 -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown)::::",
|
||||||
"debug-ben-debug", "gcc:$gcc_devteam_warn -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DDEBUG_SAFESTACK -ggdb3 -O2 -pipe::(unknown)::::::",
|
"debug-ben-debug", "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DPEDANTIC -DDEBUG_SAFESTACK -g3 -O2 -pedantic -Wall -Wshadow -Werror -pipe::(unknown)::::::",
|
||||||
"debug-ben-debug-64", "gcc:$gcc_devteam_warn -DBN_DEBUG -DCONF_DEBUG -DDEBUG_SAFESTACK -DDEBUG_UNUSED -g3 -O3 -pipe::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:elf:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
|
||||||
"debug-ben-debug-noopt", "gcc:$gcc_devteam_warn -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DDEBUG_SAFESTACK -ggdb3 -pipe::(unknown)::::::",
|
|
||||||
"debug-ben-strict", "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DCONST_STRICT -O2 -Wall -Wshadow -Werror -Wpointer-arith -Wcast-qual -Wwrite-strings -pipe::(unknown)::::::",
|
"debug-ben-strict", "gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DCONST_STRICT -O2 -Wall -Wshadow -Werror -Wpointer-arith -Wcast-qual -Wwrite-strings -pipe::(unknown)::::::",
|
||||||
"debug-rse","cc:-DTERMIOS -DL_ENDIAN -pipe -O -g -ggdb3 -Wall::(unknown):::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}",
|
"debug-rse","cc:-DTERMIOS -DL_ENDIAN -pipe -O -g -ggdb3 -Wall::(unknown):::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}",
|
||||||
"debug-bodo", "gcc:$gcc_devteam_warn -Wno-error=overlength-strings -DBN_DEBUG -DBN_DEBUG_RAND -DCONF_DEBUG -DBIO_PAIR_DEBUG -m64 -DL_ENDIAN -DTERMIO -g -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:elf:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR):::64",
|
"debug-bodo", "gcc:-DL_ENDIAN -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DBIO_PAIR_DEBUG -DPEDANTIC -g -march=i486 -pedantic -Wshadow -Wall::-D_REENTRANT:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}",
|
||||||
"debug-ulf", "gcc:-DTERMIOS -DL_ENDIAN -march=i486 -Wall -DBN_DEBUG -DBN_DEBUG_RAND -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DOPENSSL_NO_ASM -g -Wformat -Wshadow -Wmissing-prototypes -Wmissing-declarations:::CYGWIN32:::${no_asm}:win32:cygwin-shared:::.dll",
|
"debug-ulf", "gcc:-DTERMIOS -DL_ENDIAN -march=i486 -Wall -DBN_DEBUG -DBN_DEBUG_RAND -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DCRYPTO_MDEBUG -DOPENSSL_NO_ASM -g -Wformat -Wshadow -Wmissing-prototypes -Wmissing-declarations:::CYGWIN32:::${no_asm}:win32:cygwin-shared:::.dll",
|
||||||
"debug-steve64", "gcc:$gcc_devteam_warn -m64 -DL_ENDIAN -DTERMIO -DCONF_DEBUG -DDEBUG_SAFESTACK -g -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-steve64", "gcc:-m64 -DL_ENDIAN -DTERMIO -DREF_CHECK -DCONF_DEBUG -DDEBUG_SAFESTACK -DCRYPTO_MDEBUG_ALL -DPEDANTIC -DOPENSSL_NO_DEPRECATED -g -pedantic -Wall -Werror -Wno-long-long -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK BF_PTR2 DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-steve32", "gcc:$gcc_devteam_warn -m32 -DL_ENDIAN -DCONF_DEBUG -DDEBUG_SAFESTACK -g -pipe::-D_REENTRANT::-rdynamic -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC:-m32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-steve32", "gcc:-m32 -DL_ENDIAN -DREF_CHECK -DCONF_DEBUG -DDEBUG_SAFESTACK -DCRYPTO_MDEBUG_ALL -DPEDANTIC -DOPENSSL_NO_DEPRECATED -g -pedantic -Wno-long-long -Wall -Werror -Wshadow -pipe::-D_REENTRANT::-rdynamic -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC:-m32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-steve-opt", "gcc:$gcc_devteam_warn -m64 -O3 -DL_ENDIAN -DTERMIO -DCONF_DEBUG -DDEBUG_SAFESTACK -g -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-steve", "gcc:-DL_ENDIAN -DREF_CHECK -DCONF_DEBUG -DDEBUG_SAFESTACK -DCRYPTO_MDEBUG_ALL -DPEDANTIC -g -m32 -pedantic -Wno-long-long -Wall -Werror -Wshadow -pipe::-D_REENTRANT::-rdynamic -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared",
|
||||||
"debug-steve", "gcc:-DL_ENDIAN -DREF_CHECK -DCONF_DEBUG -DDEBUG_SAFESTACK -DCRYPTO_MDEBUG_ALL -DPEDANTIC -m32 -g -pedantic -Wno-long-long -Wall -Werror -Wshadow -pipe::-D_REENTRANT::-rdynamic -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared",
|
"debug-steve-opt", "gcc:-DL_ENDIAN -DREF_CHECK -DCONF_DEBUG -DDEBUG_SAFESTACK -DCRYPTO_MDEBUG_ALL -DPEDANTIC -g -O3 -m32 -pedantic -Wno-long-long -Wall -Werror -Wshadow -pipe::-D_REENTRANT::-rdynamic -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared",
|
||||||
"debug-steve-linux-pseudo64", "gcc:-DL_ENDIAN -DREF_CHECK -DCONF_DEBUG -DBN_CTX_DEBUG -DDEBUG_SAFESTACK -DCRYPTO_MDEBUG_ALL -DOPENSSL_NO_ASM -g -mcpu=i486 -Wall -Werror -Wshadow -pipe::-D_REENTRANT::-rdynamic -ldl:SIXTY_FOUR_BIT:${no_asm}:dlfcn:linux-shared",
|
"debug-levitte-linux-elf","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DL_ENDIAN -DTERMIO -D_POSIX_SOURCE -DPEDANTIC -ggdb -g3 -mcpu=i486 -pedantic -ansi -Wall -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-levitte-linux-elf","gcc:-DLEVITTE_DEBUG -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -ggdb -g3 -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-levitte-linux-noasm","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DOPENSSL_NO_ASM -DL_ENDIAN -DTERMIO -D_POSIX_SOURCE -DPEDANTIC -ggdb -g3 -mcpu=i486 -pedantic -ansi -Wall -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-levitte-linux-noasm","gcc:-DLEVITTE_DEBUG -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DOPENSSL_NO_ASM -DL_ENDIAN -ggdb -g3 -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-levitte-linux-elf-extreme","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DL_ENDIAN -DTERMIO -D_POSIX_SOURCE -DPEDANTIC -ggdb -g3 -mcpu=i486 -pedantic -ansi -Wall -W -Wundef -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-levitte-linux-elf-extreme","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DL_ENDIAN -DTERMIO -DPEDANTIC -ggdb -g3 -pedantic -ansi -Wall -W -Wundef -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-levitte-linux-noasm-extreme","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DOPENSSL_NO_ASM -DL_ENDIAN -DTERMIO -D_POSIX_SOURCE -DPEDANTIC -ggdb -g3 -mcpu=i486 -pedantic -ansi -Wall -W -Wundef -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-levitte-linux-noasm-extreme","gcc:-DLEVITTE_DEBUG -DREF_CHECK -DCONF_DEBUG -DBN_DEBUG -DBN_DEBUG_RAND -DCRYPTO_MDEBUG -DENGINE_CONF_DEBUG -DOPENSSL_NO_ASM -DL_ENDIAN -DTERMIO -DPEDANTIC -ggdb -g3 -pedantic -ansi -Wall -W -Wundef -Wshadow -Wcast-align -Wstrict-prototypes -Wmissing-prototypes -Wno-long-long -Wundef -Wconversion -pipe::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
|
||||||
"debug-geoff","gcc:-DBN_DEBUG -DBN_DEBUG_RAND -DBN_STRICT -DPURIFY -DOPENSSL_NO_DEPRECATED -DOPENSSL_NO_ASM -DOPENSSL_NO_INLINE_ASM -DL_ENDIAN -DTERMIO -DPEDANTIC -O1 -ggdb2 -Wall -Werror -Wundef -pedantic -Wshadow -Wpointer-arith -Wbad-function-cast -Wcast-align -Wsign-compare -Wmissing-prototypes -Wmissing-declarations -Wno-long-long::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-geoff","gcc:-DBN_DEBUG -DBN_DEBUG_RAND -DBN_STRICT -DPURIFY -DOPENSSL_NO_DEPRECATED -DOPENSSL_NO_ASM -DOPENSSL_NO_INLINE_ASM -DL_ENDIAN -DTERMIO -DPEDANTIC -O1 -ggdb2 -Wall -Werror -Wundef -pedantic -Wshadow -Wpointer-arith -Wbad-function-cast -Wcast-align -Wsign-compare -Wmissing-prototypes -Wmissing-declarations -Wno-long-long::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-linux-pentium","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -mcpu=pentium -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn",
|
"debug-linux-pentium","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -mcpu=pentium -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn",
|
||||||
"debug-linux-ppro","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -mcpu=pentiumpro -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn",
|
"debug-linux-ppro","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -mcpu=pentiumpro -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn",
|
||||||
"debug-linux-elf","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -march=i486 -Wall::-D_REENTRANT::-lefence -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-linux-elf","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -march=i486 -Wall::-D_REENTRANT::-lefence -ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-linux-elf-noefence","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -march=i486 -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-linux-elf-noefence","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DL_ENDIAN -DTERMIO -g -march=i486 -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-linux-generic32","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DTERMIO -g -Wall::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
|
||||||
"debug-linux-generic64","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DTERMIO -g -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
|
||||||
"debug-linux-x86_64","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -m64 -DL_ENDIAN -DTERMIO -g -Wall -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
|
||||||
"dist", "cc:-O::(unknown)::::::",
|
"dist", "cc:-O::(unknown)::::::",
|
||||||
|
|
||||||
# Basic configs that should work on any (32 and less bit) box
|
# Basic configs that should work on any (32 and less bit) box
|
||||||
@@ -210,33 +197,33 @@ my %table=(
|
|||||||
# actually recommend to consider using gcc shared build even with vendor
|
# actually recommend to consider using gcc shared build even with vendor
|
||||||
# compiler:-)
|
# compiler:-)
|
||||||
# <appro@fy.chalmers.se>
|
# <appro@fy.chalmers.se>
|
||||||
"solaris64-x86_64-gcc","gcc:-m64 -O3 -Wall -DL_ENDIAN -DMD32_REG_T=int::-D_REENTRANT::-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:solaris-shared:-fPIC:-m64 -shared -static-libgcc:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris64-x86_64-gcc","gcc:-m64 -O3 -Wall -DL_ENDIAN -DMD32_REG_T=int::-D_REENTRANT::-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK BF_PTR2 DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:solaris-shared:-fPIC:-m64 -shared -static-libgcc:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
#### Solaris x86 with Sun C setups
|
#### Solaris x86 with Sun C setups
|
||||||
"solaris-x86-cc","cc:-fast -O -Xa::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris-x86-cc","cc:-fast -O -Xa::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"solaris64-x86_64-cc","cc:-fast -xarch=amd64 -xstrconst -Xa -DL_ENDIAN::-D_REENTRANT::-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:solaris-shared:-KPIC:-xarch=amd64 -G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris64-x86_64-cc","cc:-fast -xarch=amd64 -xstrconst -Xa -DL_ENDIAN::-D_REENTRANT::-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK BF_PTR2 DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:solaris-shared:-KPIC:-xarch=amd64 -G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
#### SPARC Solaris with GNU C setups
|
#### SPARC Solaris with GNU C setups
|
||||||
"solaris-sparcv7-gcc","gcc:-O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris-sparcv7-gcc","gcc:-O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"solaris-sparcv8-gcc","gcc:-mv8 -O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::sparcv8.o:des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris-sparcv8-gcc","gcc:-mv8 -O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
# -m32 should be safe to add as long as driver recognizes -mcpu=ultrasparc
|
# -m32 should be safe to add as long as driver recognizes -mcpu=ultrasparc
|
||||||
"solaris-sparcv9-gcc","gcc:-m32 -mcpu=ultrasparc -O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::sparcv8plus.o:des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris-sparcv9-gcc","gcc:-m32 -mcpu=ultrasparc -O3 -fomit-frame-pointer -Wall -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"solaris64-sparcv9-gcc","gcc:-m64 -mcpu=ultrasparc -O3 -Wall -DB_ENDIAN::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL BF_PTR:::des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:solaris-shared:-fPIC:-m64 -shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris64-sparcv9-gcc","gcc:-m64 -mcpu=ultrasparc -O3 -Wall -DB_ENDIAN::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-m64 -shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
####
|
####
|
||||||
"debug-solaris-sparcv8-gcc","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -O -g -mv8 -Wall -DB_ENDIAN::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::sparcv8.o::::::::::dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-solaris-sparcv8-gcc","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -O -g -mv8 -Wall -DB_ENDIAN::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-solaris-sparcv9-gcc","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -DPEDANTIC -O -g -mcpu=ultrasparc -pedantic -ansi -Wall -Wshadow -Wno-long-long -D__EXTENSIONS__ -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::sparcv8plus.o:des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-solaris-sparcv9-gcc","gcc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -DPEDANTIC -O -g -mcpu=ultrasparc -pedantic -ansi -Wall -Wshadow -Wno-long-long -D__EXTENSIONS__ -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-fPIC:-shared:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
#### SPARC Solaris with Sun C setups
|
#### SPARC Solaris with Sun C setups
|
||||||
# SC4.0 doesn't pass 'make test', upgrade to SC5.0 or SC4.2.
|
# SC4.0 doesn't pass 'make test', upgrade to SC5.0 or SC4.2.
|
||||||
# SC4.2 is ok, better than gcc even on bn as long as you tell it -xarch=v8
|
# SC4.2 is ok, better than gcc even on bn as long as you tell it -xarch=v8
|
||||||
# SC5.0 note: Compiler common patch 107357-01 or later is required!
|
# SC5.0 note: Compiler common patch 107357-01 or later is required!
|
||||||
"solaris-sparcv7-cc","cc:-xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris-sparcv7-cc","cc:-xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"solaris-sparcv8-cc","cc:-xarch=v8 -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR::sparcv8.o:des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris-sparcv8-cc","cc:-xarch=v8 -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"solaris-sparcv9-cc","cc:-xtarget=ultra -xarch=v8plus -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK_LL DES_PTR DES_RISC1 DES_UNROLL BF_PTR::sparcv8plus.o:des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"solaris-sparcv9-cc","cc:-xtarget=ultra -xarch=v8plus -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK_LL DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"solaris64-sparcv9-cc","cc:-xtarget=ultra -xarch=v9 -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL BF_PTR:::des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:solaris-shared:-KPIC:-xarch=v9 -G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR):/usr/ccs/bin/ar rs",
|
"solaris64-sparcv9-cc","cc:-xtarget=ultra -xarch=v9 -xO5 -xstrconst -xdepend -Xa -DB_ENDIAN::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-xarch=v9 -G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR):/usr/ccs/bin/ar rs",
|
||||||
####
|
####
|
||||||
"debug-solaris-sparcv8-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -xarch=v8 -g -O -xstrconst -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR::sparcv8.o::::::::::dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-solaris-sparcv8-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -xarch=v8 -g -O -xstrconst -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-solaris-sparcv9-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -xtarget=ultra -xarch=v8plus -g -O -xstrconst -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK_LL DES_PTR DES_RISC1 DES_UNROLL BF_PTR::sparcv8plus.o::::::::::dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-solaris-sparcv9-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG_ALL -xtarget=ultra -xarch=v8plus -g -O -xstrconst -Xa -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-lsocket -lnsl -ldl:BN_LLONG RC4_CHAR RC4_CHUNK_LL DES_PTR DES_RISC1 DES_UNROLL BF_PTR:${no_asm}:dlfcn:solaris-shared:-KPIC:-G -dy -z text:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
#### SunOS configs, assuming sparc for the gcc one.
|
#### SunOS configs, assuming sparc for the gcc one.
|
||||||
#"sunos-cc", "cc:-O4 -DNOPROTO -DNOCONST::(unknown):SUNOS::DES_UNROLL:${no_asm}::",
|
#"sunos-cc", "cc:-O4 -DNOPROTO -DNOCONST::(unknown):SUNOS::DES_UNROLL:${no_asm}::",
|
||||||
@@ -249,11 +236,11 @@ my %table=(
|
|||||||
#### IRIX 6.x configs
|
#### IRIX 6.x configs
|
||||||
# Only N32 and N64 ABIs are supported. If you need O32 ABI build, invoke
|
# Only N32 and N64 ABIs are supported. If you need O32 ABI build, invoke
|
||||||
# './Configure irix-cc -o32' manually.
|
# './Configure irix-cc -o32' manually.
|
||||||
"irix-mips3-gcc","gcc:-mabi=n32 -O3 -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::MD2_CHAR RC4_INDEX RC4_CHAR RC4_CHUNK_LL DES_UNROLL DES_RISC2 DES_PTR BF_PTR SIXTY_FOUR_BIT::bn-mips3.o::::::::::dlfcn:irix-shared::-mabi=n32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"irix-mips3-gcc","gcc:-mabi=n32 -O3 -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::MD2_CHAR RC4_INDEX RC4_CHAR RC4_CHUNK_LL DES_UNROLL DES_RISC2 DES_PTR BF_PTR SIXTY_FOUR_BIT:${no_asm}:dlfcn:irix-shared::-mabi=n32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"irix-mips3-cc", "cc:-n32 -mips3 -O2 -use_readonly_const -G0 -rdata_shared -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::DES_PTR RC4_CHAR RC4_CHUNK_LL DES_RISC2 DES_UNROLL BF_PTR SIXTY_FOUR_BIT::bn-mips3.o::::::::::dlfcn:irix-shared::-n32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"irix-mips3-cc", "cc:-n32 -mips3 -O2 -use_readonly_const -G0 -rdata_shared -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::DES_PTR RC4_CHAR RC4_CHUNK_LL DES_RISC2 DES_UNROLL BF_PTR SIXTY_FOUR_BIT:${no_asm}:dlfcn:irix-shared::-n32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
# N64 ABI builds.
|
# N64 ABI builds.
|
||||||
"irix64-mips4-gcc","gcc:-mabi=64 -mips4 -O3 -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::RC4_CHAR RC4_CHUNK DES_RISC2 DES_UNROLL SIXTY_FOUR_BIT_LONG::bn-mips3.o::::::::::dlfcn:irix-shared::-mabi=64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"irix64-mips4-gcc","gcc:-mabi=64 -mips4 -O3 -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::RC4_CHAR RC4_CHUNK DES_RISC2 DES_UNROLL SIXTY_FOUR_BIT_LONG:${no_asm}:dlfcn:irix-shared::-mabi=64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"irix64-mips4-cc", "cc:-64 -mips4 -O2 -use_readonly_const -G0 -rdata_shared -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::RC4_CHAR RC4_CHUNK DES_RISC2 DES_UNROLL SIXTY_FOUR_BIT_LONG::bn-mips3.o::::::::::dlfcn:irix-shared::-64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"irix64-mips4-cc", "cc:-64 -mips4 -O2 -use_readonly_const -G0 -rdata_shared -DTERMIOS -DB_ENDIAN -DBN_DIV3W::-D_SGI_MP_SOURCE:::RC4_CHAR RC4_CHUNK DES_RISC2 DES_UNROLL SIXTY_FOUR_BIT_LONG:${no_asm}:dlfcn:irix-shared::-64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
#### Unified HP-UX ANSI C configs.
|
#### Unified HP-UX ANSI C configs.
|
||||||
# Special notes:
|
# Special notes:
|
||||||
@@ -286,8 +273,8 @@ my %table=(
|
|||||||
# Since there is mention of this in shlib/hpux10-cc.sh
|
# Since there is mention of this in shlib/hpux10-cc.sh
|
||||||
"hpux-parisc-cc-o4","cc:-Ae +O4 +ESlit -z -DB_ENDIAN -DBN_DIV2W -DMD32_XARRAY::-D_REENTRANT::-ldld:BN_LLONG DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux-parisc-cc-o4","cc:-Ae +O4 +ESlit -z -DB_ENDIAN -DBN_DIV2W -DMD32_XARRAY::-D_REENTRANT::-ldld:BN_LLONG DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"hpux-parisc-gcc","gcc:-O3 -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-Wl,+s -ldld:BN_LLONG DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:-fPIC:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux-parisc-gcc","gcc:-O3 -DB_ENDIAN -DBN_DIV2W::-D_REENTRANT::-Wl,+s -ldld:BN_LLONG DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:-fPIC:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"hpux-parisc2-gcc","gcc:-march=2.0 -O3 -DB_ENDIAN -D_REENTRANT::::-Wl,+s -ldld:SIXTY_FOUR_BIT RC4_CHAR RC4_CHUNK DES_PTR DES_UNROLL DES_RISC1::pa-risc2.o::::::::::dl:hpux-shared:-fPIC:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux-parisc2-gcc","gcc:-march=2.0 -O3 -DB_ENDIAN -D_REENTRANT::::-Wl,+s -ldld:SIXTY_FOUR_BIT RC4_CHAR RC4_CHUNK DES_PTR DES_UNROLL DES_RISC1:${no_asm}:dl:hpux-shared:-fPIC:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"hpux64-parisc2-gcc","gcc:-O3 -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT_LONG MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT::pa-risc2W.o::::::::::dlfcn:hpux-shared:-fpic:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux64-parisc2-gcc","gcc:-O3 -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT_LONG MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dlfcn:hpux-shared:-fpic:-shared:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
# More attempts at unified 10.X and 11.X targets for HP C compiler.
|
# More attempts at unified 10.X and 11.X targets for HP C compiler.
|
||||||
#
|
#
|
||||||
@@ -295,8 +282,8 @@ my %table=(
|
|||||||
# Kevin Steves <ks@hp.se>
|
# Kevin Steves <ks@hp.se>
|
||||||
"hpux-parisc-cc","cc:+O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DBN_DIV2W -DMD32_XARRAY::-D_REENTRANT::-Wl,+s -ldld:MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux-parisc-cc","cc:+O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DBN_DIV2W -DMD32_XARRAY::-D_REENTRANT::-Wl,+s -ldld:MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"hpux-parisc1_0-cc","cc:+DAportable +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY::-D_REENTRANT::-Wl,+s -ldld:MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux-parisc1_0-cc","cc:+DAportable +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY::-D_REENTRANT::-Wl,+s -ldld:MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"hpux-parisc2-cc","cc:+DA2.0 +DS2.0 +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY -D_REENTRANT::::-Wl,+s -ldld:SIXTY_FOUR_BIT MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT::pa-risc2.o::::::::::dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux-parisc2-cc","cc:+DA2.0 +DS2.0 +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY -D_REENTRANT::::-Wl,+s -ldld:SIXTY_FOUR_BIT MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dl:hpux-shared:+Z:-b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"hpux64-parisc2-cc","cc:+DD64 +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT_LONG MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT::pa-risc2W.o::::::::::dlfcn:hpux-shared:+Z:+DD64 -b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux64-parisc2-cc","cc:+DD64 +O3 +Optrs_strongly_typed -Ae +ESlit -DB_ENDIAN -DMD32_XARRAY -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT_LONG MD2_CHAR RC4_INDEX RC4_CHAR DES_UNROLL DES_RISC1 DES_INT:${no_asm}:dlfcn:hpux-shared:+Z:+DD64 -b:.sl.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
# HP/UX IA-64 targets
|
# HP/UX IA-64 targets
|
||||||
"hpux-ia64-cc","cc:-Ae +DD32 +O2 +Olit=all -z -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT MD2_CHAR RC4_INDEX DES_UNROLL DES_RISC1 DES_INT:${ia64_asm}:dlfcn:hpux-shared:+Z:+DD32 -b:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"hpux-ia64-cc","cc:-Ae +DD32 +O2 +Olit=all -z -DB_ENDIAN -D_REENTRANT::::-ldl:SIXTY_FOUR_BIT MD2_CHAR RC4_INDEX DES_UNROLL DES_RISC1 DES_INT:${ia64_asm}:dlfcn:hpux-shared:+Z:+DD32 -b:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
@@ -333,27 +320,28 @@ my %table=(
|
|||||||
# *-generic* is endian-neutral target, but ./config is free to
|
# *-generic* is endian-neutral target, but ./config is free to
|
||||||
# throw in -D[BL]_ENDIAN, whichever appropriate...
|
# throw in -D[BL]_ENDIAN, whichever appropriate...
|
||||||
"linux-generic32","gcc:-DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-generic32","gcc:-DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"linux-ppc", "gcc:-DB_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL::linux_ppc32.o::::::::::dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-ppc", "gcc:-DB_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
#### IA-32 targets...
|
#### IA-32 targets...
|
||||||
"linux-ia32-icc", "icc:-DL_ENDIAN -DTERMIO -O2 -no_cpprt::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-KPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-ia32-icc", "icc:-DL_ENDIAN -DTERMIO -O2 -no_cpprt::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-KPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"linux-elf", "gcc:-DL_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-elf", "gcc:-DL_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT::-ldl:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"linux-aout", "gcc:-DL_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -march=i486 -Wall::(unknown):::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}",
|
"linux-aout", "gcc:-DL_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -march=i486 -Wall::(unknown):::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}",
|
||||||
####
|
####
|
||||||
"linux-generic64","gcc:-DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-generic64","gcc:-DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"linux-ppc64", "gcc:-m64 -DB_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL::linux_ppc64.o::::::::::dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-ppc64", "gcc:-m64 -DB_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_RISC1 DES_UNROLL:${no_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"linux-ia64", "gcc:-DL_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-ia64", "gcc:-DL_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"linux-ia64-ecc","ecc:-DL_ENDIAN -DTERMIO -O2 -Wall -no_cpprt::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-ia64-ecc","ecc:-DL_ENDIAN -DTERMIO -O2 -Wall -no_cpprt::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"linux-ia64-icc","icc:-DL_ENDIAN -DTERMIO -O2 -Wall -no_cpprt::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-ia64-icc","icc:-DL_ENDIAN -DTERMIO -O2 -Wall -no_cpprt::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"linux-x86_64", "gcc:-m64 -DL_ENDIAN -DTERMIO -O3 -Wall -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-x86_64", "gcc:-m64 -DL_ENDIAN -DTERMIO -O3 -Wall -DMD32_REG_T=int::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHUNK BF_PTR2 DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
"linux-s390x", "gcc:-m64 -DB_ENDIAN -DTERMIO -O3 -Wall::-D_REENTRANT::-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL:${s390x_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
#### SPARC Linux setups
|
#### SPARC Linux setups
|
||||||
# Ray Miller <ray.miller@computing-services.oxford.ac.uk> has patiently
|
# Ray Miller <ray.miller@computing-services.oxford.ac.uk> has patiently
|
||||||
# assisted with debugging of following two configs.
|
# assisted with debugging of following two configs.
|
||||||
"linux-sparcv8","gcc:-mv8 -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall -DBN_DIV2W::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::sparcv8.o:des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-sparcv8","gcc:-mv8 -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall -DBN_DIV2W::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
# it's a real mess with -mcpu=ultrasparc option under Linux, but
|
# it's a real mess with -mcpu=ultrasparc option under Linux, but
|
||||||
# -Wa,-Av8plus should do the trick no matter what.
|
# -Wa,-Av8plus should do the trick no matter what.
|
||||||
"linux-sparcv9","gcc:-m32 -mcpu=ultrasparc -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall -Wa,-Av8plus -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::sparcv8plus.o:des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:linux-shared:-fPIC:-m32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux-sparcv9","gcc:-m32 -mcpu=ultrasparc -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall -Wa,-Av8plus -DBN_DIV2W::-D_REENTRANT:ULTRASPARC:-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC:-m32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
# GCC 3.1 is a requirement
|
# GCC 3.1 is a requirement
|
||||||
"linux64-sparcv9","gcc:-m64 -mcpu=ultrasparc -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT:ULTRASPARC:-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::::::::::::dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"linux64-sparcv9","gcc:-m64 -mcpu=ultrasparc -DB_ENDIAN -DTERMIO -O3 -fomit-frame-pointer -Wall::-D_REENTRANT:ULTRASPARC:-ldl:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC:-m64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
#### Alpha Linux with GNU C and Compaq C setups
|
#### Alpha Linux with GNU C and Compaq C setups
|
||||||
# Special notes:
|
# Special notes:
|
||||||
# - linux-alpha+bwx-gcc is ment to be used from ./config only. If you
|
# - linux-alpha+bwx-gcc is ment to be used from ./config only. If you
|
||||||
@@ -372,21 +360,18 @@ my %table=(
|
|||||||
"linux-alpha-ccc","ccc:-fast -readonly_strings -DL_ENDIAN -DTERMIO::-D_REENTRANT:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL:${no_asm}",
|
"linux-alpha-ccc","ccc:-fast -readonly_strings -DL_ENDIAN -DTERMIO::-D_REENTRANT:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL:${no_asm}",
|
||||||
"linux-alpha+bwx-ccc","ccc:-fast -readonly_strings -DL_ENDIAN -DTERMIO::-D_REENTRANT:::SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL:${no_asm}",
|
"linux-alpha+bwx-ccc","ccc:-fast -readonly_strings -DL_ENDIAN -DTERMIO::-D_REENTRANT:::SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC1 DES_UNROLL:${no_asm}",
|
||||||
|
|
||||||
# Android: Linux but without -DTERMIO and pointers to headers and libs.
|
|
||||||
"android","gcc:-mandroid -I\$(ANDROID_DEV)/include -B\$(ANDROID_DEV)/lib -O3 -fomit-frame-pointer -Wall::-D_REENTRANT::-ldl:BN_LLONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL BF_PTR:${no_asm}:dlfcn:linux-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
|
||||||
|
|
||||||
#### *BSD [do see comment about ${BSDthreads} above!]
|
#### *BSD [do see comment about ${BSDthreads} above!]
|
||||||
"BSD-generic32","gcc:-DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG RC2_CHAR RC4_INDEX DES_INT DES_UNROLL:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"BSD-generic32","gcc:-DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG RC2_CHAR RC4_INDEX DES_INT DES_UNROLL:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"BSD-x86", "gcc:-DL_ENDIAN -DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"BSD-x86", "gcc:-DL_ENDIAN -DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"BSD-x86-elf", "gcc:-DL_ENDIAN -DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"BSD-x86-elf", "gcc:-DL_ENDIAN -DTERMIOS -O3 -fomit-frame-pointer -Wall::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"debug-BSD-x86-elf", "gcc:-DL_ENDIAN -DTERMIOS -O3 -Wall -g::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"debug-BSD-x86-elf", "gcc:-DL_ENDIAN -DTERMIOS -O3 -Wall -g::${BSDthreads}:::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:bsd-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"BSD-sparcv8", "gcc:-DB_ENDIAN -DTERMIOS -O3 -mv8 -Wall::${BSDthreads}:::BN_LLONG RC2_CHAR RC4_INDEX DES_INT DES_UNROLL::sparcv8.o:des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"BSD-sparcv8", "gcc:-DB_ENDIAN -DTERMIOS -O3 -mv8 -Wall::${BSDthreads}:::BN_LLONG RC2_CHAR RC4_INDEX DES_INT DES_UNROLL:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
"BSD-generic64","gcc:-DTERMIOS -O3 -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"BSD-generic64","gcc:-DTERMIOS -O3 -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
# -DMD32_REG_T=int doesn't actually belong in sparc64 target, it
|
# -DMD32_REG_T=int doesn't actually belong in sparc64 target, it
|
||||||
# simply *happens* to work around a compiler bug in gcc 3.3.3,
|
# simply *happens* to work around a compiler bug in gcc 3.3.3,
|
||||||
# triggered by RIPEMD160 code.
|
# triggered by RIPEMD160 code.
|
||||||
"BSD-sparc64", "gcc:-DB_ENDIAN -DTERMIOS -O3 -DMD32_REG_T=int -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC2_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC2 BF_PTR:::des_enc-sparc.o fcrypt_b.o:::::::::dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"BSD-sparc64", "gcc:-DB_ENDIAN -DTERMIOS -O3 -DMD32_REG_T=int -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC2_CHAR RC4_CHUNK DES_INT DES_PTR DES_RISC2 BF_PTR:${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"BSD-ia64", "gcc:-DL_ENDIAN -DTERMIOS -O3 -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"BSD-ia64", "gcc:-DL_ENDIAN -DTERMIOS -O3 -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK:${ia64_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
"BSD-x86_64", "gcc:-DL_ENDIAN -DTERMIOS -O3 -DMD32_REG_T=int -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"BSD-x86_64", "gcc:-DL_ENDIAN -DTERMIOS -O3 -DMD32_REG_T=int -Wall::${BSDthreads}:::SIXTY_FOUR_BIT_LONG RC4_CHUNK DES_INT DES_UNROLL:${x86_64_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
||||||
|
|
||||||
@@ -400,8 +385,7 @@ my %table=(
|
|||||||
|
|
||||||
# QNX
|
# QNX
|
||||||
"qnx4", "cc:-DL_ENDIAN -DTERMIO::(unknown):::${x86_gcc_des} ${x86_gcc_opts}:",
|
"qnx4", "cc:-DL_ENDIAN -DTERMIO::(unknown):::${x86_gcc_des} ${x86_gcc_opts}:",
|
||||||
"QNX6", "gcc:-DTERMIOS::::-lsocket::${no_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
"qnx6", "cc:-DL_ENDIAN -DTERMIOS::(unknown)::-lsocket:${x86_gcc_des} ${x86_gcc_opts}:",
|
||||||
"QNX6-i386", "gcc:-DL_ENDIAN -DTERMIOS -O2 -Wall::::-lsocket:${x86_gcc_des} ${x86_gcc_opts}:${x86_elf_asm}:dlfcn:bsd-gcc-shared:-fPIC::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)",
|
|
||||||
|
|
||||||
#### SCO/Caldera targets.
|
#### SCO/Caldera targets.
|
||||||
#
|
#
|
||||||
@@ -425,12 +409,12 @@ my %table=(
|
|||||||
|
|
||||||
#### IBM's AIX.
|
#### IBM's AIX.
|
||||||
"aix3-cc", "cc:-O -DB_ENDIAN -qmaxmem=16384::(unknown):AIX::BN_LLONG RC4_CHAR:::",
|
"aix3-cc", "cc:-O -DB_ENDIAN -qmaxmem=16384::(unknown):AIX::BN_LLONG RC4_CHAR:::",
|
||||||
"aix-gcc", "gcc:-O -DB_ENDIAN::-pthread:AIX::BN_LLONG RC4_CHAR::aix_ppc32.o::::::::::dlfcn:aix-shared::-shared -Wl,-G:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 32",
|
"aix-gcc", "gcc:-O -DB_ENDIAN::-D_THREAD_SAFE:AIX::BN_LLONG RC4_CHAR:${no_asm}:dlfcn:aix-shared:::.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 32",
|
||||||
"aix64-gcc","gcc:-maix64 -O -DB_ENDIAN::-pthread:AIX::SIXTY_FOUR_BIT_LONG RC4_CHAR::aix_ppc64.o::::::::::dlfcn:aix-shared::-maix64 -shared -Wl,-G:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X64",
|
"aix64-gcc","gcc:-maix64 -O -DB_ENDIAN::-D_THREAD_SAFE:AIX::SIXTY_FOUR_BIT_LONG RC4_CHAR:${no_asm}:dlfcn:aix-shared::-maix64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X64",
|
||||||
# Below targets assume AIX 5. Idea is to effectively disregard $OBJECT_MODE
|
# Below targets assume AIX 5. Idea is to effectively disregard $OBJECT_MODE
|
||||||
# at build time. $OBJECT_MODE is respected at ./config stage!
|
# at build time. $OBJECT_MODE is respected at ./config stage!
|
||||||
"aix-cc", "cc:-q32 -O -DB_ENDIAN -qmaxmem=16384 -qro -qroconst::-qthreaded -D_THREAD_SAFE:AIX::BN_LLONG RC4_CHAR::aix_ppc32.o::::::::::dlfcn:aix-shared::-q32 -G:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 32",
|
"aix-cc", "cc:-q32 -O -DB_ENDIAN -qmaxmem=16384 -qro -qroconst::-qthreaded:AIX::BN_LLONG RC4_CHAR:${no_asm}:dlfcn:aix-shared::-q32:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 32",
|
||||||
"aix64-cc", "cc:-q64 -O -DB_ENDIAN -qmaxmem=16384 -qro -qroconst::-qthreaded -D_THREAD_SAFE:AIX::SIXTY_FOUR_BIT_LONG RC4_CHAR::aix_ppc64.o::::::::::dlfcn:aix-shared::-q64 -G:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 64",
|
"aix64-cc", "cc:-q64 -O -DB_ENDIAN -qmaxmem=16384 -qro -qroconst::-qthreaded:AIX::SIXTY_FOUR_BIT_LONG RC4_CHAR:${no_asm}:dlfcn:aix-shared::-q64:.so.\$(SHLIB_MAJOR).\$(SHLIB_MINOR)::-X 64",
|
||||||
|
|
||||||
#
|
#
|
||||||
# Cray T90 and similar (SDSC)
|
# Cray T90 and similar (SDSC)
|
||||||
@@ -501,20 +485,15 @@ my %table=(
|
|||||||
"Cygwin", "gcc:-DTERMIOS -DL_ENDIAN -fomit-frame-pointer -O3 -march=i486 -Wall:::CYGWIN32::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_coff_asm}:dlfcn:cygwin-shared:-D_WINDLL:-shared:.dll.a",
|
"Cygwin", "gcc:-DTERMIOS -DL_ENDIAN -fomit-frame-pointer -O3 -march=i486 -Wall:::CYGWIN32::BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_coff_asm}:dlfcn:cygwin-shared:-D_WINDLL:-shared:.dll.a",
|
||||||
"debug-Cygwin", "gcc:-DTERMIOS -DL_ENDIAN -march=i486 -Wall -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DOPENSSL_NO_ASM -g -Wformat -Wshadow -Wmissing-prototypes -Wmissing-declarations -Werror:::CYGWIN32:::${no_asm}:dlfcn:cygwin-shared:-D_WINDLL:-shared:.dll.a",
|
"debug-Cygwin", "gcc:-DTERMIOS -DL_ENDIAN -march=i486 -Wall -DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DOPENSSL_NO_ASM -g -Wformat -Wshadow -Wmissing-prototypes -Wmissing-declarations -Werror:::CYGWIN32:::${no_asm}:dlfcn:cygwin-shared:-D_WINDLL:-shared:.dll.a",
|
||||||
|
|
||||||
# NetWare from David Ward (dsward@novell.com)
|
# NetWare from David Ward (dsward@novell.com) - requires MetroWerks NLM development tools
|
||||||
# requires either MetroWerks NLM development tools, or gcc / nlmconv
|
|
||||||
# NetWare defaults socket bio to WinSock sockets. However,
|
|
||||||
# the builds can be configured to use BSD sockets instead.
|
|
||||||
# netware-clib => legacy CLib c-runtime support
|
# netware-clib => legacy CLib c-runtime support
|
||||||
"netware-clib", "mwccnlm::::::${x86_gcc_opts}::",
|
"netware-clib", "mwccnlm::::::BN_LLONG ${x86_gcc_opts}::",
|
||||||
"netware-clib-bsdsock", "mwccnlm::::::${x86_gcc_opts}::",
|
|
||||||
"netware-clib-gcc", "i586-netware-gcc:-nostdinc -I/ndk/nwsdk/include/nlm -I/ndk/ws295sdk/include -DL_ENDIAN -DNETWARE_CLIB -DOPENSSL_SYSNAME_NETWARE -O2 -Wall:::::${x86_gcc_opts}::",
|
|
||||||
"netware-clib-bsdsock-gcc", "i586-netware-gcc:-nostdinc -I/ndk/nwsdk/include/nlm -DNETWARE_BSDSOCK -DNETDB_USE_INTERNET -DL_ENDIAN -DNETWARE_CLIB -DOPENSSL_SYSNAME_NETWARE -O2 -Wall:::::${x86_gcc_opts}::",
|
|
||||||
# netware-libc => LibC/NKS support
|
# netware-libc => LibC/NKS support
|
||||||
|
# NetWare defaults socket bio to WinSock sockets. However, the LibC build can be
|
||||||
|
# configured to use BSD sockets instead.
|
||||||
"netware-libc", "mwccnlm::::::BN_LLONG ${x86_gcc_opts}::",
|
"netware-libc", "mwccnlm::::::BN_LLONG ${x86_gcc_opts}::",
|
||||||
"netware-libc-bsdsock", "mwccnlm::::::BN_LLONG ${x86_gcc_opts}::",
|
"netware-libc-bsdsock", "mwccnlm::::::BN_LLONG ${x86_gcc_opts}::",
|
||||||
"netware-libc-gcc", "i586-netware-gcc:-nostdinc -I/ndk/libc/include -I/ndk/libc/include/winsock -DL_ENDIAN -DNETWARE_LIBC -DOPENSSL_SYSNAME_NETWARE -DTERMIO -O2 -Wall:::::BN_LLONG ${x86_gcc_opts}::",
|
"netware-libc-gcc", "i586-netware-gcc:-nostdinc -I/ndk/libc/include -I/ndk/libc/include/winsock -DL_ENDIAN -DNETWARE_LIBC -DOPENSSL_SYSNAME_NETWARE -DTERMIO -O2 -Wall:::::BN_LLONG ${x86_gcc_opts}::",
|
||||||
"netware-libc-bsdsock-gcc", "i586-netware-gcc:-nostdinc -I/ndk/libc/include -DNETWARE_BSDSOCK -DL_ENDIAN -DNETWARE_LIBC -DOPENSSL_SYSNAME_NETWARE -DTERMIO -O2 -Wall:::::BN_LLONG ${x86_gcc_opts}::",
|
|
||||||
|
|
||||||
# DJGPP
|
# DJGPP
|
||||||
"DJGPP", "gcc:-I/dev/env/WATT_ROOT/inc -DTERMIOS -DL_ENDIAN -fomit-frame-pointer -O2 -Wall:::MSDOS:-L/dev/env/WATT_ROOT/lib -lwatt:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}:",
|
"DJGPP", "gcc:-I/dev/env/WATT_ROOT/inc -DTERMIOS -DL_ENDIAN -fomit-frame-pointer -O2 -Wall:::MSDOS:-L/dev/env/WATT_ROOT/lib -lwatt:BN_LLONG ${x86_gcc_des} ${x86_gcc_opts}:${x86_out_asm}:",
|
||||||
@@ -527,12 +506,9 @@ my %table=(
|
|||||||
|
|
||||||
##### MacOS X (a.k.a. Rhapsody or Darwin) setup
|
##### MacOS X (a.k.a. Rhapsody or Darwin) setup
|
||||||
"rhapsody-ppc-cc","cc:-O3 -DB_ENDIAN::(unknown):MACOSX_RHAPSODY::BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}::",
|
"rhapsody-ppc-cc","cc:-O3 -DB_ENDIAN::(unknown):MACOSX_RHAPSODY::BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}::",
|
||||||
"darwin-ppc-cc","cc:-arch ppc -O3 -DB_ENDIAN::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::osx_ppc32.o::::::::::dlfcn:darwin-shared:-fPIC -fno-common:-arch ppc -dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
"darwin-ppc-cc","cc:-O3 -DB_ENDIAN::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
||||||
"darwin64-ppc-cc","cc:-arch ppc64 -O3 -DB_ENDIAN::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::osx_ppc64.o::::::::::dlfcn:darwin-shared:-fPIC -fno-common:-arch ppc64 -dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
"darwin-i386-cc","cc:-O3 -fomit-frame-pointer -fno-common::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
||||||
"darwin-i386-cc","cc:-arch i386 -O3 -fomit-frame-pointer -DL_ENDIAN::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-arch i386 -dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
"debug-darwin-ppc-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DB_ENDIAN -g -Wall -O::-D_REENTRANT:MACOSX::BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
||||||
"debug-darwin-i386-cc","cc:-arch i386 -g3 -DL_ENDIAN::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-arch i386 -dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
|
||||||
"darwin64-x86_64-cc","cc:-arch x86_64 -O3 -fomit-frame-pointer -DL_ENDIAN -DMD32_REG_T=int -Wall::-D_REENTRANT:MACOSX:-Wl,-search_paths_first%:SIXTY_FOUR_BIT_LONG RC4_CHAR RC4_CHUNK DES_INT DES_UNROLL:${no_asm}:dlfcn:darwin-shared:-fPIC -fno-common:-arch x86_64 -dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
|
||||||
"debug-darwin-ppc-cc","cc:-DBN_DEBUG -DREF_CHECK -DCONF_DEBUG -DCRYPTO_MDEBUG -DB_ENDIAN -g -Wall -O::-D_REENTRANT:MACOSX::BN_LLONG RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR::osx_ppc32.o::::::::::dlfcn:darwin-shared:-fPIC -fno-common:-dynamiclib:.\$(SHLIB_MAJOR).\$(SHLIB_MINOR).dylib",
|
|
||||||
|
|
||||||
##### A/UX
|
##### A/UX
|
||||||
"aux3-gcc","gcc:-O2 -DTERMIO::(unknown):AUX:-lbsd:RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:::",
|
"aux3-gcc","gcc:-O2 -DTERMIO::(unknown):AUX:-lbsd:RC4_CHAR RC4_CHUNK DES_UNROLL BF_PTR:::",
|
||||||
@@ -560,9 +536,7 @@ my %table=(
|
|||||||
|
|
||||||
my @MK1MF_Builds=qw(VC-WIN64I VC-WIN64A
|
my @MK1MF_Builds=qw(VC-WIN64I VC-WIN64A
|
||||||
VC-NT VC-CE VC-WIN32
|
VC-NT VC-CE VC-WIN32
|
||||||
BC-32 OS2-EMX
|
BC-32 OS2-EMX netware-clib netware-libc netware-libc-bsdsock);
|
||||||
netware-clib netware-clib-bsdsock
|
|
||||||
netware-libc netware-libc-bsdsock);
|
|
||||||
|
|
||||||
my $idx = 0;
|
my $idx = 0;
|
||||||
my $idx_cc = $idx++;
|
my $idx_cc = $idx++;
|
||||||
@@ -592,11 +566,9 @@ my $idx_ranlib = $idx++;
|
|||||||
my $idx_arflags = $idx++;
|
my $idx_arflags = $idx++;
|
||||||
|
|
||||||
my $prefix="";
|
my $prefix="";
|
||||||
my $libdir="";
|
|
||||||
my $openssldir="";
|
my $openssldir="";
|
||||||
my $exe_ext="";
|
my $exe_ext="";
|
||||||
my $install_prefix= "$ENV{'INSTALL_PREFIX'}";
|
my $install_prefix="";
|
||||||
my $cross_compile_prefix="";
|
|
||||||
my $fipslibdir="/usr/local/ssl/fips-1.0/lib/";
|
my $fipslibdir="/usr/local/ssl/fips-1.0/lib/";
|
||||||
my $nofipscanistercheck=0;
|
my $nofipscanistercheck=0;
|
||||||
my $fipsdso=0;
|
my $fipsdso=0;
|
||||||
@@ -608,7 +580,6 @@ my $no_shared=0; # but "no-shared" is default
|
|||||||
my $zlib=1; # but "no-zlib" is default
|
my $zlib=1; # but "no-zlib" is default
|
||||||
my $no_krb5=0; # but "no-krb5" is implied unless "--with-krb5-..." is used
|
my $no_krb5=0; # but "no-krb5" is implied unless "--with-krb5-..." is used
|
||||||
my $no_rfc3779=1; # but "no-rfc3779" is default
|
my $no_rfc3779=1; # but "no-rfc3779" is default
|
||||||
my $montasm=1; # but "no-montasm" is default
|
|
||||||
my $no_asm=0;
|
my $no_asm=0;
|
||||||
my $no_dso=0;
|
my $no_dso=0;
|
||||||
my $no_gmp=0;
|
my $no_gmp=0;
|
||||||
@@ -642,35 +613,27 @@ my $fips=0;
|
|||||||
|
|
||||||
# All of the following is disabled by default (RC5 was enabled before 0.9.8):
|
# All of the following is disabled by default (RC5 was enabled before 0.9.8):
|
||||||
|
|
||||||
my %disabled = ( # "what" => "comment" [or special keyword "experimental"]
|
my %disabled = ( # "what" => "comment"
|
||||||
"camellia" => "default",
|
"camellia" => "default",
|
||||||
"capieng" => "default",
|
"capieng" => "default",
|
||||||
"cms" => "default",
|
"cms" => "default",
|
||||||
"gmp" => "default",
|
"gmp" => "default",
|
||||||
"jpake" => "experimental",
|
|
||||||
"mdc2" => "default",
|
"mdc2" => "default",
|
||||||
"montasm" => "default", # explicit option in 0.9.8 only (implicitly enabled in 0.9.9)
|
|
||||||
"rc5" => "default",
|
"rc5" => "default",
|
||||||
"rfc3779" => "default",
|
"rfc3779" => "default",
|
||||||
"seed" => "default",
|
"seed" => "default",
|
||||||
"shared" => "default",
|
"shared" => "default",
|
||||||
|
"tlsext" => "default",
|
||||||
"zlib" => "default",
|
"zlib" => "default",
|
||||||
"zlib-dynamic" => "default"
|
"zlib-dynamic" => "default"
|
||||||
);
|
);
|
||||||
my @experimental = ();
|
|
||||||
|
|
||||||
# This is what $depflags will look like with the above defaults
|
# Additional "no-..." options will be collected in %disabled.
|
||||||
# (we need this to see if we should advise the user to run "make depend"):
|
# To remove something from %disabled, use e.g. "enable-rc5".
|
||||||
my $default_depflags = " -DOPENSSL_NO_CAMELLIA -DOPENSSL_NO_CAPIENG -DOPENSSL_NO_CMS -DOPENSSL_NO_GMP -DOPENSSL_NO_JPAKE -DOPENSSL_NO_MDC2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779 -DOPENSSL_NO_SEED";
|
# For symmetry, "disable-..." is a synonym for "no-...".
|
||||||
|
|
||||||
|
# This is what $depflags will look like with the above default:
|
||||||
# Explicit "no-..." options will be collected in %disabled along with the defaults.
|
my $default_depflags = "-DOPENSSL_NO_CAMELLIA -DOPENSSL_NO_GMP -DOPENSSL_NO_MDC2 -DOPENSSL_NO_RC5 -DOPENSSL_NO_RFC3779 -DOPENSSL_NO_SEED -DOPENSSL_NO_TLSEXT ";
|
||||||
# To remove something from %disabled, use "enable-foo" (unless it's experimental).
|
|
||||||
# For symmetry, "disable-foo" is a synonym for "no-foo".
|
|
||||||
|
|
||||||
# For features called "experimental" here, a more explicit "experimental-foo" is needed to enable.
|
|
||||||
# We will collect such requests in @experimental.
|
|
||||||
# To avoid accidental use of experimental features, applications will have to use -DOPENSSL_EXPERIMENTAL_FOO.
|
|
||||||
|
|
||||||
|
|
||||||
my $no_sse2=0;
|
my $no_sse2=0;
|
||||||
@@ -679,7 +642,6 @@ my $no_sse2=0;
|
|||||||
|
|
||||||
my $flags;
|
my $flags;
|
||||||
my $depflags;
|
my $depflags;
|
||||||
my $openssl_experimental_defines;
|
|
||||||
my $openssl_algorithm_defines;
|
my $openssl_algorithm_defines;
|
||||||
my $openssl_thread_defines;
|
my $openssl_thread_defines;
|
||||||
my $openssl_sys_defines="";
|
my $openssl_sys_defines="";
|
||||||
@@ -700,7 +662,6 @@ while($argv_unprocessed)
|
|||||||
{
|
{
|
||||||
$flags="";
|
$flags="";
|
||||||
$depflags="";
|
$depflags="";
|
||||||
$openssl_experimental_defines="";
|
|
||||||
$openssl_algorithm_defines="";
|
$openssl_algorithm_defines="";
|
||||||
$openssl_thread_defines="";
|
$openssl_thread_defines="";
|
||||||
$openssl_sys_defines="";
|
$openssl_sys_defines="";
|
||||||
@@ -725,8 +686,6 @@ PROCESS_ARGS:
|
|||||||
s /^zlib-dynamic$/enable-zlib-dynamic/;
|
s /^zlib-dynamic$/enable-zlib-dynamic/;
|
||||||
|
|
||||||
if (/^no-(.+)$/ || /^disable-(.+)$/)
|
if (/^no-(.+)$/ || /^disable-(.+)$/)
|
||||||
{
|
|
||||||
if (!($disabled{$1} eq "experimental"))
|
|
||||||
{
|
{
|
||||||
if ($1 eq "ssl")
|
if ($1 eq "ssl")
|
||||||
{
|
{
|
||||||
@@ -742,28 +701,16 @@ PROCESS_ARGS:
|
|||||||
$disabled{$1} = "option";
|
$disabled{$1} = "option";
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
elsif (/^enable-(.+)$/)
|
||||||
elsif (/^enable-(.+)$/ || /^experimental-(.+)$/)
|
|
||||||
{
|
{
|
||||||
my $algo = $1;
|
delete $disabled{$1};
|
||||||
if ($disabled{$algo} eq "experimental")
|
|
||||||
{
|
|
||||||
die "You are requesting an experimental feature; please say 'experimental-$algo' if you are sure\n"
|
|
||||||
unless (/^experimental-/);
|
|
||||||
push @experimental, $algo;
|
|
||||||
}
|
|
||||||
delete $disabled{$algo};
|
|
||||||
|
|
||||||
$threads = 1 if ($algo eq "threads");
|
$threads = 1 if ($1 eq "threads");
|
||||||
}
|
}
|
||||||
elsif (/^--test-sanity$/)
|
elsif (/^--test-sanity$/)
|
||||||
{
|
{
|
||||||
exit(&test_sanity());
|
exit(&test_sanity());
|
||||||
}
|
}
|
||||||
elsif (/^--strict-warnings/)
|
|
||||||
{
|
|
||||||
$strict_warnings = 1;
|
|
||||||
}
|
|
||||||
elsif (/^reconfigure/ || /^reconf/)
|
elsif (/^reconfigure/ || /^reconf/)
|
||||||
{
|
{
|
||||||
if (open(IN,"<$Makefile"))
|
if (open(IN,"<$Makefile"))
|
||||||
@@ -833,10 +780,6 @@ PROCESS_ARGS:
|
|||||||
{
|
{
|
||||||
$prefix=$1;
|
$prefix=$1;
|
||||||
}
|
}
|
||||||
elsif (/^--libdir=(.*)$/)
|
|
||||||
{
|
|
||||||
$libdir=$1;
|
|
||||||
}
|
|
||||||
elsif (/^--openssldir=(.*)$/)
|
elsif (/^--openssldir=(.*)$/)
|
||||||
{
|
{
|
||||||
$openssldir=$1;
|
$openssldir=$1;
|
||||||
@@ -974,10 +917,6 @@ print "Configuring for $target\n";
|
|||||||
|
|
||||||
my @fields = split(/\s*:\s*/,$table{$target} . ":" x 30 , -1);
|
my @fields = split(/\s*:\s*/,$table{$target} . ":" x 30 , -1);
|
||||||
my $cc = $fields[$idx_cc];
|
my $cc = $fields[$idx_cc];
|
||||||
# Allow environment CC to override compiler...
|
|
||||||
if($ENV{CC}) {
|
|
||||||
$cc = $ENV{CC};
|
|
||||||
}
|
|
||||||
my $cflags = $fields[$idx_cflags];
|
my $cflags = $fields[$idx_cflags];
|
||||||
my $unistd = $fields[$idx_unistd];
|
my $unistd = $fields[$idx_unistd];
|
||||||
my $thread_cflag = $fields[$idx_thread_cflag];
|
my $thread_cflag = $fields[$idx_thread_cflag];
|
||||||
@@ -1000,8 +939,7 @@ my $shared_target = $fields[$idx_shared_target];
|
|||||||
my $shared_cflag = $fields[$idx_shared_cflag];
|
my $shared_cflag = $fields[$idx_shared_cflag];
|
||||||
my $shared_ldflag = $fields[$idx_shared_ldflag];
|
my $shared_ldflag = $fields[$idx_shared_ldflag];
|
||||||
my $shared_extension = $fields[$idx_shared_extension];
|
my $shared_extension = $fields[$idx_shared_extension];
|
||||||
my $ranlib = $ENV{'RANLIB'} || $fields[$idx_ranlib];
|
my $ranlib = $fields[$idx_ranlib];
|
||||||
my $ar = $ENV{'AR'} || "ar";
|
|
||||||
my $arflags = $fields[$idx_arflags];
|
my $arflags = $fields[$idx_arflags];
|
||||||
|
|
||||||
if ($fips)
|
if ($fips)
|
||||||
@@ -1012,15 +950,6 @@ if ($fips)
|
|||||||
"$cpuid_obj:$bn_obj:$aes_obj:$des_obj:$sha1_obj" eq "::::");
|
"$cpuid_obj:$bn_obj:$aes_obj:$des_obj:$sha1_obj" eq "::::");
|
||||||
}
|
}
|
||||||
|
|
||||||
foreach (sort @experimental)
|
|
||||||
{
|
|
||||||
my $ALGO;
|
|
||||||
($ALGO = $_) =~ tr/[a-z]/[A-Z]/;
|
|
||||||
|
|
||||||
# opensslconf.h will set OPENSSL_NO_... unless OPENSSL_EXPERIMENTAL_... is defined
|
|
||||||
$openssl_experimental_defines .= "#define OPENSSL_NO_$ALGO\n";
|
|
||||||
$cflags .= " -DOPENSSL_EXPERIMENTAL_$ALGO";
|
|
||||||
}
|
|
||||||
|
|
||||||
foreach (sort (keys %disabled))
|
foreach (sort (keys %disabled))
|
||||||
{
|
{
|
||||||
@@ -1036,8 +965,6 @@ foreach (sort (keys %disabled))
|
|||||||
{ $no_shared = 1; }
|
{ $no_shared = 1; }
|
||||||
elsif (/^zlib$/)
|
elsif (/^zlib$/)
|
||||||
{ $zlib = 0; }
|
{ $zlib = 0; }
|
||||||
elsif (/^montasm$/)
|
|
||||||
{ $montasm = 0; }
|
|
||||||
elsif (/^static-engine$/)
|
elsif (/^static-engine$/)
|
||||||
{ }
|
{ }
|
||||||
elsif (/^zlib-dynamic$/)
|
elsif (/^zlib-dynamic$/)
|
||||||
@@ -1079,6 +1006,7 @@ foreach (sort (keys %disabled))
|
|||||||
print "\n";
|
print "\n";
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
my $IsMK1MF=scalar grep /^$target$/,@MK1MF_Builds;
|
my $IsMK1MF=scalar grep /^$target$/,@MK1MF_Builds;
|
||||||
|
|
||||||
$IsMK1MF=1 if ($target eq "mingw" && $^O ne "cygwin" && !is_msys());
|
$IsMK1MF=1 if ($target eq "mingw" && $^O ne "cygwin" && !is_msys());
|
||||||
@@ -1086,7 +1014,6 @@ $IsMK1MF=1 if ($target eq "mingw" && $^O ne "cygwin" && !is_msys());
|
|||||||
$no_shared = 0 if ($fipsdso && !$IsMK1MF);
|
$no_shared = 0 if ($fipsdso && !$IsMK1MF);
|
||||||
|
|
||||||
$exe_ext=".exe" if ($target eq "Cygwin" || $target eq "DJGPP" || $target eq "mingw");
|
$exe_ext=".exe" if ($target eq "Cygwin" || $target eq "DJGPP" || $target eq "mingw");
|
||||||
$exe_ext=".nlm" if ($target =~ /netware/);
|
|
||||||
$exe_ext=".pm" if ($target =~ /vos/);
|
$exe_ext=".pm" if ($target =~ /vos/);
|
||||||
if ($openssldir eq "" and $prefix eq "")
|
if ($openssldir eq "" and $prefix eq "")
|
||||||
{
|
{
|
||||||
@@ -1101,17 +1028,12 @@ if ($openssldir eq "" and $prefix eq "")
|
|||||||
}
|
}
|
||||||
$prefix=$openssldir if $prefix eq "";
|
$prefix=$openssldir if $prefix eq "";
|
||||||
|
|
||||||
$libdir="lib" if $libdir eq "";
|
|
||||||
|
|
||||||
$default_ranlib= &which("ranlib") or $default_ranlib="true";
|
$default_ranlib= &which("ranlib") or $default_ranlib="true";
|
||||||
$perl=$ENV{'PERL'} or $perl=&which("perl5") or $perl=&which("perl")
|
$perl=$ENV{'PERL'} or $perl=&which("perl5") or $perl=&which("perl")
|
||||||
or $perl="perl";
|
or $perl="perl";
|
||||||
my $make = $ENV{'MAKE'} || "make";
|
|
||||||
|
|
||||||
$cross_compile_prefix=$ENV{'CROSS_COMPILE'} if $cross_compile_prefix eq "";
|
|
||||||
|
|
||||||
chop $openssldir if $openssldir =~ /\/$/;
|
chop $openssldir if $openssldir =~ /\/$/;
|
||||||
chop $prefix if $prefix =~ /.\/$/;
|
chop $prefix if $prefix =~ /\/$/;
|
||||||
|
|
||||||
$openssldir=$prefix . "/ssl" if $openssldir eq "";
|
$openssldir=$prefix . "/ssl" if $openssldir eq "";
|
||||||
$openssldir=$prefix . "/" . $openssldir if $openssldir !~ /(^\/|^[a-zA-Z]:[\\\/])/;
|
$openssldir=$prefix . "/" . $openssldir if $openssldir !~ /(^\/|^[a-zA-Z]:[\\\/])/;
|
||||||
@@ -1255,14 +1177,6 @@ if ($no_asm)
|
|||||||
$cflags=~s/\-D[BL]_ENDIAN// if ($fips);
|
$cflags=~s/\-D[BL]_ENDIAN// if ($fips);
|
||||||
$thread_cflags=~s/\-D[BL]_ENDIAN// if ($fips);
|
$thread_cflags=~s/\-D[BL]_ENDIAN// if ($fips);
|
||||||
}
|
}
|
||||||
if ($montasm)
|
|
||||||
{
|
|
||||||
$bn_obj =~ s/MAYBE-MO86-/mo86-/;
|
|
||||||
}
|
|
||||||
else
|
|
||||||
{
|
|
||||||
$bn_obj =~ s/MAYBE-MO86-[a-z.]*//;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!$no_shared)
|
if (!$no_shared)
|
||||||
{
|
{
|
||||||
@@ -1328,6 +1242,7 @@ if ($target =~ /\-icc$/) # Intel C compiler
|
|||||||
while(<FD>) { $iccver=$1 if (/Version ([0-9]+)\./); }
|
while(<FD>) { $iccver=$1 if (/Version ([0-9]+)\./); }
|
||||||
close(FD);
|
close(FD);
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($iccver>=8)
|
if ($iccver>=8)
|
||||||
{
|
{
|
||||||
# Eliminate unnecessary dependency from libirc.a. This is
|
# Eliminate unnecessary dependency from libirc.a. This is
|
||||||
@@ -1461,16 +1376,6 @@ if ($shlib_version_number =~ /(^[0-9]*)\.([0-9\.]*)/)
|
|||||||
$shlib_minor=$2;
|
$shlib_minor=$2;
|
||||||
}
|
}
|
||||||
|
|
||||||
if ($strict_warnings)
|
|
||||||
{
|
|
||||||
my $wopt;
|
|
||||||
die "ERROR --strict-warnings requires gcc" unless ($cc =~ /gcc$/);
|
|
||||||
foreach $wopt (split /\s+/, $gcc_devteam_warn)
|
|
||||||
{
|
|
||||||
$cflags .= " $wopt" unless ($cflags =~ /$wopt/)
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
open(IN,'<Makefile.org') || die "unable to read Makefile.org:$!\n";
|
open(IN,'<Makefile.org') || die "unable to read Makefile.org:$!\n";
|
||||||
unlink("$Makefile.new") || die "unable to remove old $Makefile.new:$!\n" if -e "$Makefile.new";
|
unlink("$Makefile.new") || die "unable to remove old $Makefile.new:$!\n" if -e "$Makefile.new";
|
||||||
open(OUT,">$Makefile.new") || die "unable to create $Makefile.new:$!\n";
|
open(OUT,">$Makefile.new") || die "unable to create $Makefile.new:$!\n";
|
||||||
@@ -1483,13 +1388,10 @@ while (<IN>)
|
|||||||
if ($sdirs) {
|
if ($sdirs) {
|
||||||
my $dir;
|
my $dir;
|
||||||
foreach $dir (@skip) {
|
foreach $dir (@skip) {
|
||||||
s/(\s)$dir\s/$1/;
|
s/([ ])$dir /\1/;
|
||||||
s/\s$dir$//;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
$sdirs = 0 unless /\\$/;
|
$sdirs = 0 unless /\\$/;
|
||||||
s/fips // if (/^DIRS=/ && !$fips);
|
|
||||||
s/engines // if (/^DIRS=/ && $disabled{"engine"});
|
|
||||||
s/^VERSION=.*/VERSION=$version/;
|
s/^VERSION=.*/VERSION=$version/;
|
||||||
s/^MAJOR=.*/MAJOR=$major/;
|
s/^MAJOR=.*/MAJOR=$major/;
|
||||||
s/^MINOR=.*/MINOR=$minor/;
|
s/^MINOR=.*/MINOR=$minor/;
|
||||||
@@ -1500,22 +1402,11 @@ while (<IN>)
|
|||||||
s/^SHLIB_EXT=.*/SHLIB_EXT=$shared_extension/;
|
s/^SHLIB_EXT=.*/SHLIB_EXT=$shared_extension/;
|
||||||
s/^INSTALLTOP=.*$/INSTALLTOP=$prefix/;
|
s/^INSTALLTOP=.*$/INSTALLTOP=$prefix/;
|
||||||
s/^OPENSSLDIR=.*$/OPENSSLDIR=$openssldir/;
|
s/^OPENSSLDIR=.*$/OPENSSLDIR=$openssldir/;
|
||||||
s/^LIBDIR=.*$/LIBDIR=$libdir/;
|
|
||||||
s/^INSTALL_PREFIX=.*$/INSTALL_PREFIX=$install_prefix/;
|
s/^INSTALL_PREFIX=.*$/INSTALL_PREFIX=$install_prefix/;
|
||||||
s/^PLATFORM=.*$/PLATFORM=$target/;
|
s/^PLATFORM=.*$/PLATFORM=$target/;
|
||||||
s/^OPTIONS=.*$/OPTIONS=$options/;
|
s/^OPTIONS=.*$/OPTIONS=$options/;
|
||||||
s/^CONFIGURE_ARGS=.*$/CONFIGURE_ARGS=$argvstring/;
|
s/^CONFIGURE_ARGS=.*$/CONFIGURE_ARGS=$argvstring/;
|
||||||
if ($cross_compile_prefix)
|
|
||||||
{
|
|
||||||
s/^CC=.*$/CROSS_COMPILE= $cross_compile_prefix\nCC= \$\(CROSS_COMPILE\)$cc/;
|
|
||||||
s/^AR=\s*/AR= \$\(CROSS_COMPILE\)/;
|
|
||||||
s/^RANLIB=\s*/RANLIB= \$\(CROSS_COMPILE\)/;
|
|
||||||
}
|
|
||||||
else {
|
|
||||||
s/^CC=.*$/CC= $cc/;
|
s/^CC=.*$/CC= $cc/;
|
||||||
s/^AR=\s*ar/AR= $ar/;
|
|
||||||
s/^RANLIB=.*/RANLIB= $ranlib/;
|
|
||||||
}
|
|
||||||
s/^MAKEDEPPROG=.*$/MAKEDEPPROG= $cc/ if $cc eq "gcc";
|
s/^MAKEDEPPROG=.*$/MAKEDEPPROG= $cc/ if $cc eq "gcc";
|
||||||
s/^CFLAG=.*$/CFLAG= $cflags/;
|
s/^CFLAG=.*$/CFLAG= $cflags/;
|
||||||
s/^DEPFLAG=.*$/DEPFLAG= $depflags/;
|
s/^DEPFLAG=.*$/DEPFLAG= $depflags/;
|
||||||
@@ -1534,6 +1425,7 @@ while (<IN>)
|
|||||||
s/^SHA1_ASM_OBJ=.*$/SHA1_ASM_OBJ= $sha1_obj/;
|
s/^SHA1_ASM_OBJ=.*$/SHA1_ASM_OBJ= $sha1_obj/;
|
||||||
s/^RMD160_ASM_OBJ=.*$/RMD160_ASM_OBJ= $rmd160_obj/;
|
s/^RMD160_ASM_OBJ=.*$/RMD160_ASM_OBJ= $rmd160_obj/;
|
||||||
s/^PROCESSOR=.*/PROCESSOR= $processor/;
|
s/^PROCESSOR=.*/PROCESSOR= $processor/;
|
||||||
|
s/^RANLIB=.*/RANLIB= $ranlib/;
|
||||||
s/^ARFLAGS=.*/ARFLAGS= $arflags/;
|
s/^ARFLAGS=.*/ARFLAGS= $arflags/;
|
||||||
s/^PERL=.*/PERL= $perl/;
|
s/^PERL=.*/PERL= $perl/;
|
||||||
s/^KRB5_INCLUDES=.*/KRB5_INCLUDES=$withargs{"krb5-include"}/;
|
s/^KRB5_INCLUDES=.*/KRB5_INCLUDES=$withargs{"krb5-include"}/;
|
||||||
@@ -1661,7 +1553,6 @@ print OUT "/* WARNING: Generated automatically from opensslconf.h.in by Configur
|
|||||||
|
|
||||||
print OUT "/* OpenSSL was configured with the following options: */\n";
|
print OUT "/* OpenSSL was configured with the following options: */\n";
|
||||||
my $openssl_algorithm_defines_trans = $openssl_algorithm_defines;
|
my $openssl_algorithm_defines_trans = $openssl_algorithm_defines;
|
||||||
$openssl_experimental_defines =~ s/^\s*#\s*define\s+OPENSSL_NO_(.*)/#ifndef OPENSSL_EXPERIMENTAL_$1\n# ifndef OPENSSL_NO_$1\n# define OPENSSL_NO_$1\n# endif\n#endif/mg;
|
|
||||||
$openssl_algorithm_defines_trans =~ s/^\s*#\s*define\s+OPENSSL_(.*)/# if defined(OPENSSL_$1) \&\& !defined($1)\n# define $1\n# endif/mg;
|
$openssl_algorithm_defines_trans =~ s/^\s*#\s*define\s+OPENSSL_(.*)/# if defined(OPENSSL_$1) \&\& !defined($1)\n# define $1\n# endif/mg;
|
||||||
$openssl_algorithm_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
|
$openssl_algorithm_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
|
||||||
$openssl_algorithm_defines = " /* no ciphers excluded */\n" if $openssl_algorithm_defines eq "";
|
$openssl_algorithm_defines = " /* no ciphers excluded */\n" if $openssl_algorithm_defines eq "";
|
||||||
@@ -1670,10 +1561,8 @@ $openssl_sys_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/
|
|||||||
$openssl_other_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
|
$openssl_other_defines =~ s/^\s*#\s*define\s+(.*)/#ifndef $1\n# define $1\n#endif/mg;
|
||||||
print OUT $openssl_sys_defines;
|
print OUT $openssl_sys_defines;
|
||||||
print OUT "#ifndef OPENSSL_DOING_MAKEDEPEND\n\n";
|
print OUT "#ifndef OPENSSL_DOING_MAKEDEPEND\n\n";
|
||||||
print OUT $openssl_experimental_defines;
|
|
||||||
print OUT "\n";
|
|
||||||
print OUT $openssl_algorithm_defines;
|
print OUT $openssl_algorithm_defines;
|
||||||
print OUT "\n#endif /* OPENSSL_DOING_MAKEDEPEND */\n\n";
|
print OUT "\n#endif /* OPENSSL_DOING_MAKEDEPEND */\n";
|
||||||
print OUT $openssl_thread_defines;
|
print OUT $openssl_thread_defines;
|
||||||
print OUT $openssl_other_defines,"\n";
|
print OUT $openssl_other_defines,"\n";
|
||||||
|
|
||||||
@@ -1690,20 +1579,9 @@ print OUT "#define OPENSSL_CPUID_OBJ\n\n" if ($cpuid_obj);
|
|||||||
while (<IN>)
|
while (<IN>)
|
||||||
{
|
{
|
||||||
if (/^#define\s+OPENSSLDIR/)
|
if (/^#define\s+OPENSSLDIR/)
|
||||||
{
|
{ print OUT "#define OPENSSLDIR \"$openssldir\"\n"; }
|
||||||
my $foo = $openssldir;
|
|
||||||
$foo =~ s/\\/\\\\/g;
|
|
||||||
print OUT "#define OPENSSLDIR \"$foo\"\n";
|
|
||||||
}
|
|
||||||
elsif (/^#define\s+ENGINESDIR/)
|
elsif (/^#define\s+ENGINESDIR/)
|
||||||
{
|
{ print OUT "#define ENGINESDIR \"$prefix/lib/engines\"\n"; }
|
||||||
# $foo is to become "$prefix/lib$multilib/engines";
|
|
||||||
# as Makefile.org and engines/Makefile are adapted for
|
|
||||||
# $multilib suffix.
|
|
||||||
my $foo = "$prefix/lib/engines";
|
|
||||||
$foo =~ s/\\/\\\\/g;
|
|
||||||
print OUT "#define ENGINESDIR \"$foo\"\n";
|
|
||||||
}
|
|
||||||
elsif (/^#((define)|(undef))\s+OPENSSL_EXPORT_VAR_AS_FUNCTION/)
|
elsif (/^#((define)|(undef))\s+OPENSSL_EXPORT_VAR_AS_FUNCTION/)
|
||||||
{ printf OUT "#undef OPENSSL_EXPORT_VAR_AS_FUNCTION\n"
|
{ printf OUT "#undef OPENSSL_EXPORT_VAR_AS_FUNCTION\n"
|
||||||
if $export_var_as_fn;
|
if $export_var_as_fn;
|
||||||
@@ -1808,7 +1686,7 @@ if($IsMK1MF) {
|
|||||||
EOF
|
EOF
|
||||||
close(OUT);
|
close(OUT);
|
||||||
} else {
|
} else {
|
||||||
my $make_command = "$make PERL=\'$perl\'";
|
my $make_command = "make PERL=\'$perl\'";
|
||||||
my $make_targets = "";
|
my $make_targets = "";
|
||||||
$make_targets .= " links" if $symlink;
|
$make_targets .= " links" if $symlink;
|
||||||
$make_targets .= " depend" if $depflags ne $default_depflags && $make_depend;
|
$make_targets .= " depend" if $depflags ne $default_depflags && $make_depend;
|
||||||
@@ -1816,11 +1694,11 @@ EOF
|
|||||||
(system $make_command.$make_targets) == 0 or exit $?
|
(system $make_command.$make_targets) == 0 or exit $?
|
||||||
if $make_targets ne "";
|
if $make_targets ne "";
|
||||||
if ( $perl =~ m@^/@) {
|
if ( $perl =~ m@^/@) {
|
||||||
&dofile("tools/c_rehash",$perl,'^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";', '^my \$prefix;$', 'my $prefix = "' . $prefix . '";');
|
&dofile("tools/c_rehash",$perl,'^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";');
|
||||||
&dofile("apps/CA.pl",$perl,'^#!/', '#!%s');
|
&dofile("apps/CA.pl",$perl,'^#!/', '#!%s');
|
||||||
} else {
|
} else {
|
||||||
# No path for Perl known ...
|
# No path for Perl known ...
|
||||||
&dofile("tools/c_rehash",'/usr/local/bin/perl','^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";', '^my \$prefix;$', 'my $prefix = "' . $prefix . '";');
|
&dofile("tools/c_rehash",'/usr/local/bin/perl','^#!/', '#!%s','^my \$dir;$', 'my $dir = "' . $openssldir . '";');
|
||||||
&dofile("apps/CA.pl",'/usr/local/bin/perl','^#!/', '#!%s');
|
&dofile("apps/CA.pl",'/usr/local/bin/perl','^#!/', '#!%s');
|
||||||
}
|
}
|
||||||
if ($depflags ne $default_depflags && !$make_depend) {
|
if ($depflags ne $default_depflags && !$make_depend) {
|
||||||
@@ -1835,7 +1713,7 @@ EOF
|
|||||||
}
|
}
|
||||||
|
|
||||||
# create the ms/version32.rc file if needed
|
# create the ms/version32.rc file if needed
|
||||||
if ($IsMK1MF && ($target !~ /^netware/)) {
|
if ($IsMK1MF) {
|
||||||
my ($v1, $v2, $v3, $v4);
|
my ($v1, $v2, $v3, $v4);
|
||||||
if ($version_num =~ /(^[0-9a-f]{1})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{2})/i) {
|
if ($version_num =~ /(^[0-9a-f]{1})([0-9a-f]{2})([0-9a-f]{2})([0-9a-f]{2})/i) {
|
||||||
$v1=hex $1;
|
$v1=hex $1;
|
||||||
@@ -1937,7 +1815,7 @@ OpenSSL FIPS Object Module as identified by the CMVP
|
|||||||
(http://csrc.nist.gov/cryptval/) in any application requiring the use of FIPS
|
(http://csrc.nist.gov/cryptval/) in any application requiring the use of FIPS
|
||||||
140-2 validated software.
|
140-2 validated software.
|
||||||
|
|
||||||
This is an OpenSSL 0.9.8 test version.
|
This is an OpenSSL 0.9.8-fips test version.
|
||||||
|
|
||||||
See the file README.FIPS for details of how to build a test library.
|
See the file README.FIPS for details of how to build a test library.
|
||||||
|
|
||||||
|
|||||||
189
FAQ
189
FAQ
@@ -10,7 +10,6 @@ OpenSSL - Frequently Asked Questions
|
|||||||
* Why aren't tools like 'autoconf' and 'libtool' used?
|
* Why aren't tools like 'autoconf' and 'libtool' used?
|
||||||
* What is an 'engine' version?
|
* What is an 'engine' version?
|
||||||
* How do I check the authenticity of the OpenSSL distribution?
|
* How do I check the authenticity of the OpenSSL distribution?
|
||||||
* How does the versioning scheme work?
|
|
||||||
|
|
||||||
[LEGAL] Legal questions
|
[LEGAL] Legal questions
|
||||||
|
|
||||||
@@ -33,8 +32,6 @@ OpenSSL - Frequently Asked Questions
|
|||||||
* How do I install a CA certificate into a browser?
|
* How do I install a CA certificate into a browser?
|
||||||
* Why is OpenSSL x509 DN output not conformant to RFC2253?
|
* Why is OpenSSL x509 DN output not conformant to RFC2253?
|
||||||
* What is a "128 bit certificate"? Can I create one with OpenSSL?
|
* What is a "128 bit certificate"? Can I create one with OpenSSL?
|
||||||
* Why does OpenSSL set the authority key identifier extension incorrectly?
|
|
||||||
* How can I set up a bundle of commercial root CA certificates?
|
|
||||||
|
|
||||||
[BUILD] Questions about building and testing OpenSSL
|
[BUILD] Questions about building and testing OpenSSL
|
||||||
|
|
||||||
@@ -53,9 +50,6 @@ OpenSSL - Frequently Asked Questions
|
|||||||
* Why does the OpenSSL test suite fail in sha512t on x86 CPU?
|
* Why does the OpenSSL test suite fail in sha512t on x86 CPU?
|
||||||
* Why does compiler fail to compile sha512.c?
|
* Why does compiler fail to compile sha512.c?
|
||||||
* Test suite still fails, what to do?
|
* Test suite still fails, what to do?
|
||||||
* I think I've found a bug, what should I do?
|
|
||||||
* I'm SURE I've found a bug, how do I report it?
|
|
||||||
* I've found a security issue, how do I report it?
|
|
||||||
|
|
||||||
[PROG] Questions about programming with OpenSSL
|
[PROG] Questions about programming with OpenSSL
|
||||||
|
|
||||||
@@ -72,9 +66,6 @@ OpenSSL - Frequently Asked Questions
|
|||||||
* Why doesn't my server application receive a client certificate?
|
* Why doesn't my server application receive a client certificate?
|
||||||
* Why does compilation fail due to an undefined symbol NID_uniqueIdentifier?
|
* Why does compilation fail due to an undefined symbol NID_uniqueIdentifier?
|
||||||
* I think I've detected a memory leak, is this a bug?
|
* I think I've detected a memory leak, is this a bug?
|
||||||
* Why does Valgrind complain about the use of uninitialized data?
|
|
||||||
* Why doesn't a memory BIO work when a file does?
|
|
||||||
* Where are the declarations and implementations of d2i_X509() etc?
|
|
||||||
|
|
||||||
===============================================================================
|
===============================================================================
|
||||||
|
|
||||||
@@ -83,11 +74,11 @@ OpenSSL - Frequently Asked Questions
|
|||||||
* Which is the current version of OpenSSL?
|
* Which is the current version of OpenSSL?
|
||||||
|
|
||||||
The current version is available from <URL: http://www.openssl.org>.
|
The current version is available from <URL: http://www.openssl.org>.
|
||||||
OpenSSL 1.0.1d was released on Feb 5th, 2013.
|
OpenSSL 0.9.8e was released on February 23rd, 2007.
|
||||||
|
|
||||||
In addition to the current stable release, you can also access daily
|
In addition to the current stable release, you can also access daily
|
||||||
snapshots of the OpenSSL development version at <URL:
|
snapshots of the OpenSSL development version at <URL:
|
||||||
ftp://ftp.openssl.org/snapshot/>, or get it by anonymous Git access.
|
ftp://ftp.openssl.org/snapshot/>, or get it by anonymous CVS access.
|
||||||
|
|
||||||
|
|
||||||
* Where is the documentation?
|
* Where is the documentation?
|
||||||
@@ -99,19 +90,19 @@ explains how to install this library.
|
|||||||
|
|
||||||
OpenSSL includes a command line utility that can be used to perform a
|
OpenSSL includes a command line utility that can be used to perform a
|
||||||
variety of cryptographic functions. It is described in the openssl(1)
|
variety of cryptographic functions. It is described in the openssl(1)
|
||||||
manpage. Documentation for developers is currently being written. Many
|
manpage. Documentation for developers is currently being written. A
|
||||||
manual pages are available; overviews over libcrypto and
|
few manual pages already are available; overviews over libcrypto and
|
||||||
libssl are given in the crypto(3) and ssl(3) manpages.
|
libssl are given in the crypto(3) and ssl(3) manpages.
|
||||||
|
|
||||||
The OpenSSL manpages are installed in /usr/local/ssl/man/ (or a
|
The OpenSSL manpages are installed in /usr/local/ssl/man/ (or a
|
||||||
different directory if you specified one as described in INSTALL).
|
different directory if you specified one as described in INSTALL).
|
||||||
In addition, you can read the most current versions at
|
In addition, you can read the most current versions at
|
||||||
<URL: http://www.openssl.org/docs/>. Note that the online documents refer
|
<URL: http://www.openssl.org/docs/>.
|
||||||
to the very latest development versions of OpenSSL and may include features
|
|
||||||
not present in released versions. If in doubt refer to the documentation
|
For information on parts of libcrypto that are not yet documented, you
|
||||||
that came with the version of OpenSSL you are using. The pod format
|
might want to read Ariel Glenn's documentation on SSLeay 0.9, OpenSSL's
|
||||||
documentation is included in each OpenSSL distribution under the docs
|
predecessor, at <URL: http://www.columbia.edu/~ariel/ssleay/>. Much
|
||||||
directory.
|
of this still applies to OpenSSL.
|
||||||
|
|
||||||
There is some documentation about certificate extensions and PKCS#12
|
There is some documentation about certificate extensions and PKCS#12
|
||||||
in doc/openssl.txt
|
in doc/openssl.txt
|
||||||
@@ -132,7 +123,7 @@ OpenSSL. Information on the OpenSSL mailing lists is available from
|
|||||||
* Where can I get a compiled version of OpenSSL?
|
* Where can I get a compiled version of OpenSSL?
|
||||||
|
|
||||||
You can finder pointers to binary distributions in
|
You can finder pointers to binary distributions in
|
||||||
<URL: http://www.openssl.org/related/binaries.html> .
|
http://www.openssl.org/related/binaries.html .
|
||||||
|
|
||||||
Some applications that use OpenSSL are distributed in binary form.
|
Some applications that use OpenSSL are distributed in binary form.
|
||||||
When using such an application, you don't need to install OpenSSL
|
When using such an application, you don't need to install OpenSSL
|
||||||
@@ -171,19 +162,6 @@ just do:
|
|||||||
|
|
||||||
pgp TARBALL.asc
|
pgp TARBALL.asc
|
||||||
|
|
||||||
* How does the versioning scheme work?
|
|
||||||
|
|
||||||
After the release of OpenSSL 1.0.0 the versioning scheme changed. Letter
|
|
||||||
releases (e.g. 1.0.1a) can only contain bug and security fixes and no
|
|
||||||
new features. Minor releases change the last number (e.g. 1.0.2) and
|
|
||||||
can contain new features that retain binary compatibility. Changes to
|
|
||||||
the middle number are considered major releases and neither source nor
|
|
||||||
binary compatibility is guaranteed.
|
|
||||||
|
|
||||||
Therefore the answer to the common question "when will feature X be
|
|
||||||
backported to OpenSSL 1.0.0/0.9.8?" is "never" but it could appear
|
|
||||||
in the next minor release.
|
|
||||||
|
|
||||||
[LEGAL] =======================================================================
|
[LEGAL] =======================================================================
|
||||||
|
|
||||||
* Do I need patent licenses to use OpenSSL?
|
* Do I need patent licenses to use OpenSSL?
|
||||||
@@ -295,7 +273,7 @@ current directory in this case, but this has changed with 0.9.6a.)
|
|||||||
Check out the CA.pl(1) manual page. This provides a simple wrapper round
|
Check out the CA.pl(1) manual page. This provides a simple wrapper round
|
||||||
the 'req', 'verify', 'ca' and 'pkcs12' utilities. For finer control check
|
the 'req', 'verify', 'ca' and 'pkcs12' utilities. For finer control check
|
||||||
out the manual pages for the individual utilities and the certificate
|
out the manual pages for the individual utilities and the certificate
|
||||||
extensions documentation (in ca(1), req(1), x509v3_config(5) )
|
extensions documentation (currently in doc/openssl.txt).
|
||||||
|
|
||||||
|
|
||||||
* Why can't I create certificate requests?
|
* Why can't I create certificate requests?
|
||||||
@@ -423,10 +401,10 @@ You can't generally create such a certificate using OpenSSL but there is no
|
|||||||
need to any more. Nowadays web browsers using unrestricted strong encryption
|
need to any more. Nowadays web browsers using unrestricted strong encryption
|
||||||
are generally available.
|
are generally available.
|
||||||
|
|
||||||
When there were tight restrictions on the export of strong encryption
|
When there were tight export restrictions on the export of strong encryption
|
||||||
software from the US only weak encryption algorithms could be freely exported
|
software from the US only weak encryption algorithms could be freely exported
|
||||||
(initially 40 bit and then 56 bit). It was widely recognised that this was
|
(initially 40 bit and then 56 bit). It was widely recognised that this was
|
||||||
inadequate. A relaxation of the rules allowed the use of strong encryption but
|
inadequate. A relaxation the rules allowed the use of strong encryption but
|
||||||
only to an authorised server.
|
only to an authorised server.
|
||||||
|
|
||||||
Two slighly different techniques were developed to support this, one used by
|
Two slighly different techniques were developed to support this, one used by
|
||||||
@@ -447,39 +425,6 @@ The export laws were later changed to allow almost unrestricted use of strong
|
|||||||
encryption so these certificates are now obsolete.
|
encryption so these certificates are now obsolete.
|
||||||
|
|
||||||
|
|
||||||
* Why does OpenSSL set the authority key identifier (AKID) extension incorrectly?
|
|
||||||
|
|
||||||
It doesn't: this extension is often the cause of confusion.
|
|
||||||
|
|
||||||
Consider a certificate chain A->B->C so that A signs B and B signs C. Suppose
|
|
||||||
certificate C contains AKID.
|
|
||||||
|
|
||||||
The purpose of this extension is to identify the authority certificate B. This
|
|
||||||
can be done either by including the subject key identifier of B or its issuer
|
|
||||||
name and serial number.
|
|
||||||
|
|
||||||
In this latter case because it is identifying certifcate B it must contain the
|
|
||||||
issuer name and serial number of B.
|
|
||||||
|
|
||||||
It is often wrongly assumed that it should contain the subject name of B. If it
|
|
||||||
did this would be redundant information because it would duplicate the issuer
|
|
||||||
name of C.
|
|
||||||
|
|
||||||
|
|
||||||
* How can I set up a bundle of commercial root CA certificates?
|
|
||||||
|
|
||||||
The OpenSSL software is shipped without any root CA certificate as the
|
|
||||||
OpenSSL project does not have any policy on including or excluding
|
|
||||||
any specific CA and does not intend to set up such a policy. Deciding
|
|
||||||
about which CAs to support is up to application developers or
|
|
||||||
administrators.
|
|
||||||
|
|
||||||
Other projects do have other policies so you can for example extract the CA
|
|
||||||
bundle used by Mozilla and/or modssl as described in this article:
|
|
||||||
|
|
||||||
<URL: http://www.mail-archive.com/modssl-users@modssl.org/msg16980.html>
|
|
||||||
|
|
||||||
|
|
||||||
[BUILD] =======================================================================
|
[BUILD] =======================================================================
|
||||||
|
|
||||||
* Why does the linker complain about undefined symbols?
|
* Why does the linker complain about undefined symbols?
|
||||||
@@ -519,7 +464,7 @@ when you run the test suite (using "make test"). The message returned is
|
|||||||
"bc: 1 not implemented".
|
"bc: 1 not implemented".
|
||||||
|
|
||||||
The best way to deal with this is to find another implementation of bc
|
The best way to deal with this is to find another implementation of bc
|
||||||
and compile/install it. GNU bc (see <URL: http://www.gnu.org/software/software.html>
|
and compile/install it. GNU bc (see http://www.gnu.org/software/software.html
|
||||||
for download instructions) can be safely used, for example.
|
for download instructions) can be safely used, for example.
|
||||||
|
|
||||||
|
|
||||||
@@ -530,7 +475,7 @@ that the OpenSSL bntest throws at it. This gets triggered when you run the
|
|||||||
test suite (using "make test"). The message returned is "bc: stack empty".
|
test suite (using "make test"). The message returned is "bc: stack empty".
|
||||||
|
|
||||||
The best way to deal with this is to find another implementation of bc
|
The best way to deal with this is to find another implementation of bc
|
||||||
and compile/install it. GNU bc (see <URL: http://www.gnu.org/software/software.html>
|
and compile/install it. GNU bc (see http://www.gnu.org/software/software.html
|
||||||
for download instructions) can be safely used, for example.
|
for download instructions) can be safely used, for example.
|
||||||
|
|
||||||
|
|
||||||
@@ -723,49 +668,6 @@ never make sense, and tend to emerge when you least expect them. In order
|
|||||||
to identify one, drop optimization level, e.g. by editing CFLAG line in
|
to identify one, drop optimization level, e.g. by editing CFLAG line in
|
||||||
top-level Makefile, recompile and re-run the test.
|
top-level Makefile, recompile and re-run the test.
|
||||||
|
|
||||||
* I think I've found a bug, what should I do?
|
|
||||||
|
|
||||||
If you are a new user then it is quite likely you haven't found a bug and
|
|
||||||
something is happening you aren't familiar with. Check this FAQ, the associated
|
|
||||||
documentation and the mailing lists for similar queries. If you are still
|
|
||||||
unsure whether it is a bug or not submit a query to the openssl-users mailing
|
|
||||||
list.
|
|
||||||
|
|
||||||
|
|
||||||
* I'm SURE I've found a bug, how do I report it?
|
|
||||||
|
|
||||||
Bug reports with no security implications should be sent to the request
|
|
||||||
tracker. This can be done by mailing the report to <rt@openssl.org> (or its
|
|
||||||
alias <openssl-bugs@openssl.org>), please note that messages sent to the
|
|
||||||
request tracker also appear in the public openssl-dev mailing list.
|
|
||||||
|
|
||||||
The report should be in plain text. Any patches should be sent as
|
|
||||||
plain text attachments because some mailers corrupt patches sent inline.
|
|
||||||
If your issue affects multiple versions of OpenSSL check any patches apply
|
|
||||||
cleanly and, if possible include patches to each affected version.
|
|
||||||
|
|
||||||
The report should be given a meaningful subject line briefly summarising the
|
|
||||||
issue. Just "bug in OpenSSL" or "bug in OpenSSL 0.9.8n" is not very helpful.
|
|
||||||
|
|
||||||
By sending reports to the request tracker the bug can then be given a priority
|
|
||||||
and assigned to the appropriate maintainer. The history of discussions can be
|
|
||||||
accessed and if the issue has been addressed or a reason why not. If patches
|
|
||||||
are only sent to openssl-dev they can be mislaid if a team member has to
|
|
||||||
wade through months of old messages to review the discussion.
|
|
||||||
|
|
||||||
See also <URL: http://www.openssl.org/support/rt.html>
|
|
||||||
|
|
||||||
|
|
||||||
* I've found a security issue, how do I report it?
|
|
||||||
|
|
||||||
If you think your bug has security implications then please send it to
|
|
||||||
openssl-security@openssl.org if you don't get a prompt reply at least
|
|
||||||
acknowledging receipt then resend or mail it directly to one of the
|
|
||||||
more active team members (e.g. Steve).
|
|
||||||
|
|
||||||
Note that bugs only present in the openssl utility are not in general
|
|
||||||
considered to be security issues.
|
|
||||||
|
|
||||||
[PROG] ========================================================================
|
[PROG] ========================================================================
|
||||||
|
|
||||||
* Is OpenSSL thread-safe?
|
* Is OpenSSL thread-safe?
|
||||||
@@ -778,10 +680,8 @@ file.
|
|||||||
|
|
||||||
Multi-threaded applications must provide two callback functions to
|
Multi-threaded applications must provide two callback functions to
|
||||||
OpenSSL by calling CRYPTO_set_locking_callback() and
|
OpenSSL by calling CRYPTO_set_locking_callback() and
|
||||||
CRYPTO_set_id_callback(), for all versions of OpenSSL up to and
|
CRYPTO_set_id_callback(). This is described in the threads(3)
|
||||||
including 0.9.8[abc...]. As of version 1.0.0, CRYPTO_set_id_callback()
|
manpage.
|
||||||
and associated APIs are deprecated by CRYPTO_THREADID_set_callback()
|
|
||||||
and friends. This is described in the threads(3) manpage.
|
|
||||||
|
|
||||||
* I've compiled a program under Windows and it crashes: why?
|
* I've compiled a program under Windows and it crashes: why?
|
||||||
|
|
||||||
@@ -922,11 +822,11 @@ code itself (the hex digits after the second colon).
|
|||||||
|
|
||||||
* Why do I get errors about unknown algorithms?
|
* Why do I get errors about unknown algorithms?
|
||||||
|
|
||||||
The cause is forgetting to load OpenSSL's table of algorithms with
|
This can happen under several circumstances such as reading in an
|
||||||
OpenSSL_add_all_algorithms(). See the manual page for more information. This
|
encrypted private key or attempting to decrypt a PKCS#12 file. The cause
|
||||||
can cause several problems such as being unable to read in an encrypted
|
is forgetting to load OpenSSL's table of algorithms with
|
||||||
PEM file, unable to decrypt a PKCS#12 file or signature failure when
|
OpenSSL_add_all_algorithms(). See the manual page for more information.
|
||||||
verifying certificates.
|
|
||||||
|
|
||||||
* Why can't the OpenSSH configure script detect OpenSSL?
|
* Why can't the OpenSSH configure script detect OpenSSL?
|
||||||
|
|
||||||
@@ -994,46 +894,5 @@ thread-safe):
|
|||||||
ERR_free_strings(), EVP_cleanup() and CRYPTO_cleanup_all_ex_data().
|
ERR_free_strings(), EVP_cleanup() and CRYPTO_cleanup_all_ex_data().
|
||||||
|
|
||||||
|
|
||||||
* Why does Valgrind complain about the use of uninitialized data?
|
|
||||||
|
|
||||||
When OpenSSL's PRNG routines are called to generate random numbers the supplied
|
|
||||||
buffer contents are mixed into the entropy pool: so it technically does not
|
|
||||||
matter whether the buffer is initialized at this point or not. Valgrind (and
|
|
||||||
other test tools) will complain about this. When using Valgrind, make sure the
|
|
||||||
OpenSSL library has been compiled with the PURIFY macro defined (-DPURIFY)
|
|
||||||
to get rid of these warnings.
|
|
||||||
|
|
||||||
|
|
||||||
* Why doesn't a memory BIO work when a file does?
|
|
||||||
|
|
||||||
This can occur in several cases for example reading an S/MIME email message.
|
|
||||||
The reason is that a memory BIO can do one of two things when all the data
|
|
||||||
has been read from it.
|
|
||||||
|
|
||||||
The default behaviour is to indicate that no more data is available and that
|
|
||||||
the call should be retried, this is to allow the application to fill up the BIO
|
|
||||||
again if necessary.
|
|
||||||
|
|
||||||
Alternatively it can indicate that no more data is available and that EOF has
|
|
||||||
been reached.
|
|
||||||
|
|
||||||
If a memory BIO is to behave in the same way as a file this second behaviour
|
|
||||||
is needed. This must be done by calling:
|
|
||||||
|
|
||||||
BIO_set_mem_eof_return(bio, 0);
|
|
||||||
|
|
||||||
See the manual pages for more details.
|
|
||||||
|
|
||||||
|
|
||||||
* Where are the declarations and implementations of d2i_X509() etc?
|
|
||||||
|
|
||||||
These are defined and implemented by macros of the form:
|
|
||||||
|
|
||||||
|
|
||||||
DECLARE_ASN1_FUNCTIONS(X509) and IMPLEMENT_ASN1_FUNCTIONS(X509)
|
|
||||||
|
|
||||||
The implementation passes an ASN1 "template" defining the structure into an
|
|
||||||
ASN1 interpreter using generalised functions such as ASN1_item_d2i().
|
|
||||||
|
|
||||||
|
|
||||||
===============================================================================
|
===============================================================================
|
||||||
|
|
||||||
|
|||||||
4
INSTALL
4
INSTALL
@@ -158,7 +158,7 @@
|
|||||||
standard headers). If it is a problem with OpenSSL itself, please
|
standard headers). If it is a problem with OpenSSL itself, please
|
||||||
report the problem to <openssl-bugs@openssl.org> (note that your
|
report the problem to <openssl-bugs@openssl.org> (note that your
|
||||||
message will be recorded in the request tracker publicly readable
|
message will be recorded in the request tracker publicly readable
|
||||||
via http://www.openssl.org/support/rt.html and will be forwarded to a
|
via http://www.openssl.org/support/rt2.html and will be forwarded to a
|
||||||
public mailing list). Include the output of "make report" in your message.
|
public mailing list). Include the output of "make report" in your message.
|
||||||
Please check out the request tracker. Maybe the bug was already
|
Please check out the request tracker. Maybe the bug was already
|
||||||
reported or has already been fixed.
|
reported or has already been fixed.
|
||||||
@@ -180,7 +180,7 @@
|
|||||||
in Makefile.ssl and run "make clean; make". Please send a bug
|
in Makefile.ssl and run "make clean; make". Please send a bug
|
||||||
report to <openssl-bugs@openssl.org>, including the output of
|
report to <openssl-bugs@openssl.org>, including the output of
|
||||||
"make report" in order to be added to the request tracker at
|
"make report" in order to be added to the request tracker at
|
||||||
http://www.openssl.org/support/rt.html.
|
http://www.openssl.org/support/rt2.html.
|
||||||
|
|
||||||
4. If everything tests ok, install OpenSSL with
|
4. If everything tests ok, install OpenSSL with
|
||||||
|
|
||||||
|
|||||||
120
INSTALL.NW
120
INSTALL.NW
@@ -8,62 +8,58 @@ Notes about building OpenSSL for NetWare.
|
|||||||
BUILD PLATFORM:
|
BUILD PLATFORM:
|
||||||
---------------
|
---------------
|
||||||
The build scripts (batch files, perl scripts, etc) have been developed and
|
The build scripts (batch files, perl scripts, etc) have been developed and
|
||||||
tested on W2K. The scripts should run fine on other Windows platforms
|
tested on W2K. The scripts should run fine on other Windows
|
||||||
(NT, Win9x, WinXP) but they have not been tested. They may require some
|
platforms (NT, Win9x, WinXP) but they haven't been tested. They may require
|
||||||
modifications.
|
some modifications.
|
||||||
|
|
||||||
|
|
||||||
Supported NetWare Platforms - NetWare 5.x, NetWare 6.x:
|
Supported NetWare Platforms - NetWare 5.x, NetWare 6.x:
|
||||||
-------------------------------------------------------
|
------------------------------------------
|
||||||
OpenSSL can either use the WinSock interfaces introduced in NetWare 5,
|
OpenSSL uses the WinSock interfaces introduced in NetWare 5. Therefore,
|
||||||
or the BSD socket interface. Previous versions of NetWare, 4.x and 3.x,
|
previous versions of NetWare, 4.x and 3.x, are not supported.
|
||||||
are only supported if OpenSSL is build for CLIB and BSD sockets;
|
|
||||||
WinSock builds only support NetWare 5 and up.
|
|
||||||
|
|
||||||
On NetWare there are two c-runtime libraries. There is the legacy CLIB
|
On NetWare there are two c-runtime libraries. There is the legacy CLIB
|
||||||
interfaces and the newer LIBC interfaces. Being ANSI-C libraries, the
|
interfaces and the newer LibC interfaces. Being ANSI-C libraries, the
|
||||||
functionality in CLIB and LIBC is similar but the LIBC interfaces are built
|
functionality in CLIB and LibC is similar but the LibC interfaces are built
|
||||||
using Novell Kernal Services (NKS) which is designed to leverage
|
using Novell Kernal Services (NKS) which is designed to leverage
|
||||||
multi-processor environments.
|
multi-processor environments.
|
||||||
|
|
||||||
The NetWare port of OpenSSL can be configured to build using CLIB or LIBC.
|
The NetWare port of OpenSSL can configured to build using CLIB or LibC. The
|
||||||
The CLIB build was developed and tested using NetWare 5.0 sp6.0a. The LIBC
|
CLIB build was developed and tested using NetWare 5.0 sp6.0a. The LibC
|
||||||
build was developed and tested using the NetWare 6.0 FCS.
|
build was developed and tested using the NetWare 6.0 FCS.
|
||||||
|
|
||||||
The necessary LIBC functionality ships with NetWare 6. However, earlier
|
The necessary LibC functionality ships with NetWare 6. However, earlier
|
||||||
NetWare 5.x versions will require updates in order to run the OpenSSL LIBC
|
NetWare 5.x versions will require updates in order to run the OpenSSL LibC
|
||||||
build (NetWare 5.1 SP8 is known to work).
|
build.
|
||||||
|
|
||||||
As of June 2005, the LIBC build can be configured to use BSD sockets instead
|
As of June 2005, the LibC build can be configured to use BSD sockets instead
|
||||||
of WinSock sockets. Call Configure (usually through netware\build.bat) using
|
of WinSock sockets. Call Configure (usually through netware\build.bat) using
|
||||||
a target of "netware-libc-bsdsock" instead of "netware-libc".
|
a target of "netware-libc-bsdsock" instead of "netware-libc".
|
||||||
|
|
||||||
As of June 2007, support for CLIB and BSD sockets is also now available
|
|
||||||
using a target of "netware-clib-bsdsock" instead of "netware-clib";
|
|
||||||
also gcc builds are now supported on both Linux and Win32 (post 0.9.8e).
|
|
||||||
|
|
||||||
REQUIRED TOOLS:
|
REQUIRED TOOLS:
|
||||||
---------------
|
---------------
|
||||||
Based upon the configuration and build options used, some or all of the
|
Based upon the configuration and build options used, some or all of the
|
||||||
following tools may be required:
|
following tools may be required:
|
||||||
|
|
||||||
|
|
||||||
* Perl for Win32 - required (http://www.activestate.com/ActivePerl)
|
* Perl for Win32 - required (http://www.activestate.com/ActivePerl)
|
||||||
Used to run the various perl scripts on the build platform.
|
Used to run the various perl scripts on the build platform.
|
||||||
|
|
||||||
|
|
||||||
* Perl 5.8.0 for NetWare v3.20 (or later) - required
|
* Perl 5.8.0 for NetWare v3.20 (or later) - required
|
||||||
(http://developer.novell.com) Used to run the test script on NetWare
|
(http://developer.novell.com) Used to run the test script on NetWare
|
||||||
after building.
|
after building.
|
||||||
|
|
||||||
* Compiler / Linker - required:
|
|
||||||
Metrowerks CodeWarrior PDK 2.1 (or later) for NetWare (commercial):
|
* Metrowerks CodeWarrior PDK 2.1 (or later) for NetWare - required:
|
||||||
Provides command line tools used for building.
|
Provides command line tools used for building.
|
||||||
|
|
||||||
Tools:
|
Tools:
|
||||||
mwccnlm.exe - C/C++ Compiler for NetWare
|
mwccnlm.exe - C/C++ Compiler for NetWare
|
||||||
mwldnlm.exe - Linker for NetWare
|
mwldnlm.exe - Linker for NetWare
|
||||||
mwasmnlm.exe - x86 assembler for NetWare (if using assembly option)
|
mwasmnlm.exe - x86 assembler for NetWare (if using assembly option)
|
||||||
|
|
||||||
gcc / nlmconv Cross-Compiler, available from Novell Forge (free):
|
|
||||||
http://forge.novell.com/modules/xfmod/project/?aunixnw
|
|
||||||
|
|
||||||
* Assemblers - optional:
|
* Assemblers - optional:
|
||||||
If you intend to build using the assembly options you will need an
|
If you intend to build using the assembly options you will need an
|
||||||
@@ -83,11 +79,11 @@ following tools may be required:
|
|||||||
In order to build you will need a make tool. Two make tools are
|
In order to build you will need a make tool. Two make tools are
|
||||||
supported, GNU make (gmake.exe) or Microsoft nmake.exe.
|
supported, GNU make (gmake.exe) or Microsoft nmake.exe.
|
||||||
|
|
||||||
make.exe - GNU make for Windows (version 3.75 used for development)
|
gmake.exe - GNU make for Windows (version 3.75 used for development)
|
||||||
http://gnuwin32.sourceforge.net/packages/make.htm
|
http://www.gnu.org/software/make/make.html
|
||||||
|
|
||||||
nmake.exe - Microsoft make (Version 6.00.8168.0 used for development)
|
nmake.exe - Microsoft make (Version 6.00.8168.0 used for development)
|
||||||
http://support.microsoft.com/kb/132084/EN-US/
|
|
||||||
|
|
||||||
* Novell Developer Kit (NDK) - required: (http://developer.novell.com)
|
* Novell Developer Kit (NDK) - required: (http://developer.novell.com)
|
||||||
|
|
||||||
@@ -127,14 +123,14 @@ following tools may be required:
|
|||||||
|
|
||||||
LIBC - BUILDS:
|
LIBC - BUILDS:
|
||||||
|
|
||||||
Libraries for C (LIBC) - LIBC headers and import files
|
Libraries for C (LibC) - LibC headers and import files
|
||||||
If you are going to build a LIBC version of OpenSSL, you will
|
If you are going to build a LibC version of OpenSSL, you will
|
||||||
need the LIBC headers and imports. The March 14, 2002 NDK release or
|
need the LibC headers and imports. The March 14, 2002 NDK release or
|
||||||
later is required.
|
later is required.
|
||||||
|
|
||||||
NOTE: The LIBC SDK includes the necessary WinSock2 support.
|
NOTE: The LibC SDK includes the necessary WinSock2 support. It
|
||||||
It is not necessary to download the WinSock2 NDK when building for
|
It is not necessary to download the WinSock2 Developer when building
|
||||||
LIBC. The LIBC SDK also includes the appropriate BSD socket support
|
for LibC. The LibC SDK also includes the appropriate BSD socket support
|
||||||
if configuring to use BSD sockets.
|
if configuring to use BSD sockets.
|
||||||
|
|
||||||
|
|
||||||
@@ -147,36 +143,33 @@ The set_env.bat file is a template you can use to set up the path
|
|||||||
and environment variables you will need to build. Modify the
|
and environment variables you will need to build. Modify the
|
||||||
various lines to point to YOUR tools and run set_env.bat.
|
various lines to point to YOUR tools and run set_env.bat.
|
||||||
|
|
||||||
netware\set_env.bat <target> [compiler]
|
netware\set_env.bat [target]
|
||||||
|
|
||||||
target - "netware-clib" - CLIB NetWare build
|
target - "netware-clib" - CLib NetWare build
|
||||||
- "netware-libc" - LIBC NetWare build
|
- "netware-libc" - LibC NetWare build
|
||||||
|
|
||||||
compiler - "gnuc" - GNU GCC Compiler
|
|
||||||
- "codewarrior" - MetroWerks CodeWarrior (default)
|
|
||||||
|
|
||||||
If you don't use set_env.bat, you will need to set up the following
|
If you don't use set_env.bat, you will need to set up the following
|
||||||
environment variables:
|
environment variables:
|
||||||
|
|
||||||
PATH - Set PATH to point to the tools you will use.
|
path - Set path to point to the tools you will use.
|
||||||
|
|
||||||
INCLUDE - The location of the NDK include files.
|
MWCIncludes - The location of the NDK include files.
|
||||||
|
|
||||||
CLIB ex: set INCLUDE=c:\ndk\nwsdk\include\nlm
|
CLIB ex: set MWCIncludes=c:\ndk\nwsdk\include\nlm
|
||||||
LIBC ex: set INCLUDE=c:\ndk\libc\include
|
LibC ex: set MWCIncludes=c:\ndk\libc\include
|
||||||
|
|
||||||
PRELUDE - The absolute path of the prelude object to link with. For
|
PRELUDE - The absolute path of the prelude object to link with. For
|
||||||
a CLIB build it is recommended you use the "clibpre.o" files shipped
|
a CLIB build it is recommended you use the "clibpre.o" files shipped
|
||||||
with the Metrowerks PDK for NetWare. For a LIBC build you should
|
with the Metrowerks PDK for NetWare. For a LibC build you should
|
||||||
use the "libcpre.o" file delivered with the LIBC NDK components.
|
use the "libcpre.o" file delivered with the LibC NDK components.
|
||||||
|
|
||||||
CLIB ex: set PRELUDE=c:\ndk\nwsdk\imports\clibpre.o
|
CLIB ex: set PRELUDE=c:\ndk\nwsdk\imports\clibpre.o
|
||||||
LIBC ex: set PRELUDE=c:\ndk\libc\imports\libcpre.o
|
LibC ex: set PRELUDE=c:\ndk\libc\imports\libcpre.o
|
||||||
|
|
||||||
IMPORTS - The locaton of the NDK import files.
|
IMPORTS - The locaton of the NDK import files.
|
||||||
|
|
||||||
CLIB ex: set IMPORTS=c:\ndk\nwsdk\imports
|
CLIB ex: set IMPORTS=c:\ndk\nwsdk\imports
|
||||||
LIBC ex: set IMPORTS=c:\ndk\libc\imports
|
LibC ex: set IMPORTS=c:\ndk\libc\imports
|
||||||
|
|
||||||
|
|
||||||
In order to build, you need to run the Perl scripts to configure the build
|
In order to build, you need to run the Perl scripts to configure the build
|
||||||
@@ -189,10 +182,9 @@ the assembly code. Always run build.bat from the "openssl" directory.
|
|||||||
|
|
||||||
netware\build [target] [debug opts] [assembly opts] [configure opts]
|
netware\build [target] [debug opts] [assembly opts] [configure opts]
|
||||||
|
|
||||||
target - "netware-clib" - CLIB NetWare build (WinSock Sockets)
|
target - "netware-clib" - CLib NetWare build (WinSock Sockets)
|
||||||
- "netware-clib-bsdsock" - CLIB NetWare build (BSD Sockets)
|
- "netware-libc" - LibC NetWare build (WinSock Sockets)
|
||||||
- "netware-libc" - LIBC NetWare build (WinSock Sockets)
|
- "netware-libc-bsdsock" - LibC NetWare build (BSD Sockets)
|
||||||
- "netware-libc-bsdsock" - LIBC NetWare build (BSD Sockets)
|
|
||||||
|
|
||||||
debug opts - "debug" - build debug
|
debug opts - "debug" - build debug
|
||||||
|
|
||||||
@@ -201,27 +193,25 @@ the assembly code. Always run build.bat from the "openssl" directory.
|
|||||||
"no-asm" - don't use assembly
|
"no-asm" - don't use assembly
|
||||||
|
|
||||||
configure opts- all unrecognized arguments are passed to the
|
configure opts- all unrecognized arguments are passed to the
|
||||||
perl 'configure' script. See that script for
|
perl configure script
|
||||||
internal documentation regarding options that
|
|
||||||
are available.
|
|
||||||
|
|
||||||
examples:
|
examples:
|
||||||
|
|
||||||
CLIB build, debug, without assembly:
|
CLIB build, debug, without assembly:
|
||||||
netware\build.bat netware-clib debug no-asm
|
netware\build.bat netware-clib debug no-asm
|
||||||
|
|
||||||
LIBC build, non-debug, using NASM assembly, add mdc2 support:
|
LibC build, non-debug, using NASM assembly:
|
||||||
netware\build.bat netware-libc nw-nasm enable-mdc2
|
netware\build.bat netware-libc nw-nasm
|
||||||
|
|
||||||
LIBC build, BSD sockets, non-debug, without assembly:
|
LibC build, BSD sockets, non-debug, without assembly:
|
||||||
netware\build.bat netware-libc-bsdsock no-asm
|
netware\build.bat netware-libc-bsdsock no-asm
|
||||||
|
|
||||||
Running build.bat generates a make file to be processed by your make
|
Running build.bat generates a make file to be processed by your make
|
||||||
tool (gmake or nmake):
|
tool (gmake or nmake):
|
||||||
|
|
||||||
CLIB ex: gmake -f netware\nlm_clib_dbg.mak
|
CLIB ex: gmake -f netware\nlm_clib_dbg.mak
|
||||||
LIBC ex: gmake -f netware\nlm_libc.mak
|
LibC ex: gmake -f netware\nlm_libc.mak
|
||||||
LIBC ex: gmake -f netware\nlm_libc_bsdsock.mak
|
LibC ex: gmake -f netware\nlm_libc_bsdsock.mak
|
||||||
|
|
||||||
|
|
||||||
You can also run the build scripts manually if you do not want to use the
|
You can also run the build scripts manually if you do not want to use the
|
||||||
@@ -230,7 +220,7 @@ subdirectory (in the order listed below):
|
|||||||
|
|
||||||
perl configure no-asm [other config opts] [netware-clib|netware-libc|netware-libc-bsdsock]
|
perl configure no-asm [other config opts] [netware-clib|netware-libc|netware-libc-bsdsock]
|
||||||
configures no assembly build for specified netware environment
|
configures no assembly build for specified netware environment
|
||||||
(CLIB or LIBC).
|
(CLIB or LibC).
|
||||||
|
|
||||||
perl util\mkfiles.pl >MINFO
|
perl util\mkfiles.pl >MINFO
|
||||||
generates a listing of source files (used by mk1mf)
|
generates a listing of source files (used by mk1mf)
|
||||||
@@ -260,12 +250,12 @@ The output from the build is placed in the following directories:
|
|||||||
tmp_nw_clib - temporary build files
|
tmp_nw_clib - temporary build files
|
||||||
outinc_nw_clib - necesary include files
|
outinc_nw_clib - necesary include files
|
||||||
|
|
||||||
LIBC Debug build:
|
LibC Debug build:
|
||||||
out_nw_libc.dbg - static libs & test nlm(s)
|
out_nw_libc.dbg - static libs & test nlm(s)
|
||||||
tmp_nw_libc.dbg - temporary build files
|
tmp_nw_libc.dbg - temporary build files
|
||||||
outinc_nw_libc - necessary include files
|
outinc_nw_libc - necessary include files
|
||||||
|
|
||||||
LIBC Non-debug build:
|
LibC Non-debug build:
|
||||||
out_nw_libc - static libs & test nlm(s)
|
out_nw_libc - static libs & test nlm(s)
|
||||||
tmp_nw_libc - temporary build files
|
tmp_nw_libc - temporary build files
|
||||||
outinc_nw_libc - necesary include files
|
outinc_nw_libc - necesary include files
|
||||||
@@ -291,7 +281,7 @@ To run cpy_tests.bat:
|
|||||||
NetWare drive - drive letter of mapped drive
|
NetWare drive - drive letter of mapped drive
|
||||||
|
|
||||||
CLIB ex: netware\cpy_tests out_nw_clib m:
|
CLIB ex: netware\cpy_tests out_nw_clib m:
|
||||||
LIBC ex: netware\cpy_tests out_nw_libc m:
|
LibC ex: netware\cpy_tests out_nw_libc m:
|
||||||
|
|
||||||
|
|
||||||
The Perl script, "do_tests.pl", in the "OpenSSL" directory on the server
|
The Perl script, "do_tests.pl", in the "OpenSSL" directory on the server
|
||||||
@@ -366,9 +356,9 @@ clean up the resources!
|
|||||||
|
|
||||||
Multi-threaded Development
|
Multi-threaded Development
|
||||||
---------------------------
|
---------------------------
|
||||||
The NetWare version of OpenSSL is thread-safe, however multi-threaded
|
The NetWare version of OpenSSL is thread-safe however, multi-threaded
|
||||||
applications must provide the necessary locking function callbacks. This
|
applications must provide the necessary locking function callbacks. This
|
||||||
is described in doc\threads.doc. The file "openssl-x.x.x\crypto\threads\mttest.c"
|
is described in doc\threads.doc. The file "openssl\crypto\threads\mttest.c"
|
||||||
is a multi-threaded test program and demonstrates the locking functions.
|
is a multi-threaded test program and demonstrates the locking functions.
|
||||||
|
|
||||||
|
|
||||||
@@ -438,7 +428,7 @@ Makefile "vclean"
|
|||||||
------------------
|
------------------
|
||||||
The generated makefile has a "vclean" target which cleans up the build
|
The generated makefile has a "vclean" target which cleans up the build
|
||||||
directories. If you have been building successfully and suddenly
|
directories. If you have been building successfully and suddenly
|
||||||
experience problems, use "vclean" (gmake -f netware\nlm_xxxx.mak vclean) and retry.
|
experience problems, use "vclean" (gmake -f netware\nlm.mak vclean) and retry.
|
||||||
|
|
||||||
|
|
||||||
"Undefined Symbol" Linker errors
|
"Undefined Symbol" Linker errors
|
||||||
|
|||||||
@@ -18,7 +18,7 @@
|
|||||||
* Borland C
|
* Borland C
|
||||||
* GNU C (Cygwin or MinGW)
|
* GNU C (Cygwin or MinGW)
|
||||||
|
|
||||||
If you are compiling from a tarball or a Git snapshot then the Win32 files
|
If you are compiling from a tarball or a CVS snapshot then the Win32 files
|
||||||
may well be not up to date. This may mean that some "tweaking" is required to
|
may well be not up to date. This may mean that some "tweaking" is required to
|
||||||
get it all to work. See the trouble shooting section later on for if (when?)
|
get it all to work. See the trouble shooting section later on for if (when?)
|
||||||
it goes wrong.
|
it goes wrong.
|
||||||
@@ -264,7 +264,7 @@ To install OpenSSL to the specified location do:
|
|||||||
|
|
||||||
then ms\do_XXX should not give a warning any more. However the numbers that
|
then ms\do_XXX should not give a warning any more. However the numbers that
|
||||||
get assigned by this technique may not match those that eventually get
|
get assigned by this technique may not match those that eventually get
|
||||||
assigned in the Git tree: so anything linked against this version of the
|
assigned in the CVS tree: so anything linked against this version of the
|
||||||
library may need to be recompiled.
|
library may need to be recompiled.
|
||||||
|
|
||||||
If you get errors about unresolved symbols there are several possible
|
If you get errors about unresolved symbols there are several possible
|
||||||
|
|||||||
2
LICENSE
2
LICENSE
@@ -12,7 +12,7 @@
|
|||||||
---------------
|
---------------
|
||||||
|
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
* Copyright (c) 1998-2011 The OpenSSL Project. All rights reserved.
|
* Copyright (c) 1998-2007 The OpenSSL Project. All rights reserved.
|
||||||
*
|
*
|
||||||
* Redistribution and use in source and binary forms, with or without
|
* Redistribution and use in source and binary forms, with or without
|
||||||
* modification, are permitted provided that the following conditions
|
* modification, are permitted provided that the following conditions
|
||||||
|
|||||||
@@ -29,7 +29,7 @@ OSErr AppendErrorMessageToHandle(Handle inoutHandle);
|
|||||||
|
|
||||||
|
|
||||||
|
|
||||||
// A bunch of evil macros that would be unnecessary if I were always using C++ !
|
// A bunch of evil macros that would be uneccessary if I were always using C++ !
|
||||||
|
|
||||||
#define SetErrorMessageAndBailIfNil(theArg,theMessage) \
|
#define SetErrorMessageAndBailIfNil(theArg,theMessage) \
|
||||||
{ \
|
{ \
|
||||||
|
|||||||
97
Makefile.org
97
Makefile.org
@@ -69,9 +69,8 @@ ARD=ar $(ARFLAGS) d
|
|||||||
RANLIB= ranlib
|
RANLIB= ranlib
|
||||||
PERL= perl
|
PERL= perl
|
||||||
TAR= tar
|
TAR= tar
|
||||||
TARFLAGS= --no-recursion --record-size=10240
|
TARFLAGS= --no-recursion
|
||||||
MAKEDEPPROG=makedepend
|
MAKEDEPPROG=makedepend
|
||||||
LIBDIR=lib
|
|
||||||
|
|
||||||
# We let the C compiler driver to take care of .s files. This is done in
|
# We let the C compiler driver to take care of .s files. This is done in
|
||||||
# order to be excused from maintaining a separate set of architecture
|
# order to be excused from maintaining a separate set of architecture
|
||||||
@@ -113,7 +112,7 @@ LIBZLIB=
|
|||||||
# $(INSTALLTOP) for this build make be different so hard
|
# $(INSTALLTOP) for this build make be different so hard
|
||||||
# code the path.
|
# code the path.
|
||||||
|
|
||||||
FIPSLIBDIR=/usr/local/ssl/$(LIBDIR)/
|
FIPSLIBDIR=/usr/local/ssl/lib/
|
||||||
|
|
||||||
# This is set to "y" if fipscanister.o is compiled internally as
|
# This is set to "y" if fipscanister.o is compiled internally as
|
||||||
# opposed to coming from an external validated location.
|
# opposed to coming from an external validated location.
|
||||||
@@ -143,7 +142,7 @@ SDIRS= \
|
|||||||
bn ec rsa dsa ecdsa dh ecdh dso engine \
|
bn ec rsa dsa ecdsa dh ecdh dso engine \
|
||||||
buffer bio stack lhash rand err \
|
buffer bio stack lhash rand err \
|
||||||
evp asn1 pem x509 x509v3 conf txt_db pkcs7 pkcs12 comp ocsp ui krb5 \
|
evp asn1 pem x509 x509v3 conf txt_db pkcs7 pkcs12 comp ocsp ui krb5 \
|
||||||
store cms pqueue jpake
|
store cms pqueue
|
||||||
# keep in mind that the above list is adjusted by ./Configure
|
# keep in mind that the above list is adjusted by ./Configure
|
||||||
# according to no-xxx arguments...
|
# according to no-xxx arguments...
|
||||||
|
|
||||||
@@ -173,7 +172,7 @@ SHARED_LDFLAGS=
|
|||||||
|
|
||||||
GENERAL= Makefile
|
GENERAL= Makefile
|
||||||
BASENAME= openssl
|
BASENAME= openssl
|
||||||
NAME= $(BASENAME)-$(VERSION)
|
NAME= $(BASENAME)-fips-$(VERSION)
|
||||||
TARFILE= $(NAME).tar
|
TARFILE= $(NAME).tar
|
||||||
WTARFILE= $(NAME)-win.tar
|
WTARFILE= $(NAME)-win.tar
|
||||||
EXHEADER= e_os2.h
|
EXHEADER= e_os2.h
|
||||||
@@ -201,10 +200,9 @@ BUILDENV= PLATFORM='${PLATFORM}' PROCESSOR='${PROCESSOR}' \
|
|||||||
CC='${CC}' CFLAG='${CFLAG}' \
|
CC='${CC}' CFLAG='${CFLAG}' \
|
||||||
AS='${CC}' ASFLAG='${CFLAG} -c' \
|
AS='${CC}' ASFLAG='${CFLAG} -c' \
|
||||||
AR='${AR}' PERL='${PERL}' RANLIB='${RANLIB}' \
|
AR='${AR}' PERL='${PERL}' RANLIB='${RANLIB}' \
|
||||||
SDIRS='${SDIRS}' LIBRPATH='${INSTALLTOP}/$(LIBDIR)' \
|
SDIRS='${SDIRS}' LIBRPATH='${INSTALLTOP}/lib' \
|
||||||
INSTALL_PREFIX='${INSTALL_PREFIX}' \
|
INSTALL_PREFIX='${INSTALL_PREFIX}' \
|
||||||
INSTALLTOP='${INSTALLTOP}' OPENSSLDIR='${OPENSSLDIR}' \
|
INSTALLTOP='${INSTALLTOP}' OPENSSLDIR='${OPENSSLDIR}' \
|
||||||
LIBDIR='${LIBDIR}' \
|
|
||||||
MAKEDEPEND='$$$${TOP}/util/domd $$$${TOP} -MD ${MAKEDEPPROG}' \
|
MAKEDEPEND='$$$${TOP}/util/domd $$$${TOP} -MD ${MAKEDEPPROG}' \
|
||||||
DEPFLAG='-DOPENSSL_NO_DEPRECATED ${DEPFLAG}' \
|
DEPFLAG='-DOPENSSL_NO_DEPRECATED ${DEPFLAG}' \
|
||||||
MAKEDEPPROG='${MAKEDEPPROG}' \
|
MAKEDEPPROG='${MAKEDEPPROG}' \
|
||||||
@@ -221,8 +219,7 @@ BUILDENV= PLATFORM='${PLATFORM}' PROCESSOR='${PROCESSOR}' \
|
|||||||
SHA1_ASM_OBJ='${SHA1_ASM_OBJ}' \
|
SHA1_ASM_OBJ='${SHA1_ASM_OBJ}' \
|
||||||
MD5_ASM_OBJ='${MD5_ASM_OBJ}' \
|
MD5_ASM_OBJ='${MD5_ASM_OBJ}' \
|
||||||
RMD160_ASM_OBJ='${RMD160_ASM_OBJ}' \
|
RMD160_ASM_OBJ='${RMD160_ASM_OBJ}' \
|
||||||
FIPSLIBDIR='${FIPSLIBDIR}' \
|
FIPSLIBDIR='${FIPSLIBDIR}' FIPSCANLIB='${FIPSCANLIB}' \
|
||||||
FIPSCANLIB="$${FIPSCANLIB:-$(FIPSCANLIB)}" \
|
|
||||||
FIPSCANISTERINTERNAL='${FIPSCANISTERINTERNAL}' \
|
FIPSCANISTERINTERNAL='${FIPSCANISTERINTERNAL}' \
|
||||||
FIPS_EX_OBJ='${FIPS_EX_OBJ}' \
|
FIPS_EX_OBJ='${FIPS_EX_OBJ}' \
|
||||||
THIS=$${THIS:-$@} MAKEFILE=Makefile MAKEOVERRIDES=
|
THIS=$${THIS:-$@} MAKEFILE=Makefile MAKEOVERRIDES=
|
||||||
@@ -243,8 +240,7 @@ BUILDENV= PLATFORM='${PLATFORM}' PROCESSOR='${PROCESSOR}' \
|
|||||||
# subdirectories defined in $(DIRS). It requires that the target
|
# subdirectories defined in $(DIRS). It requires that the target
|
||||||
# is given through the shell variable `target'.
|
# is given through the shell variable `target'.
|
||||||
BUILD_CMD= if [ -d "$$dir" ]; then \
|
BUILD_CMD= if [ -d "$$dir" ]; then \
|
||||||
( [ $$target != all -a -z "$(FIPSCANLIB)" ] && FIPSCANLIB=/dev/null; \
|
( cd $$dir && echo "making $$target in $$dir..." && \
|
||||||
cd $$dir && echo "making $$target in $$dir..." && \
|
|
||||||
$(CLEARENV) && $(MAKE) -e $(BUILDENV) TOP=.. DIR=$$dir $$target \
|
$(CLEARENV) && $(MAKE) -e $(BUILDENV) TOP=.. DIR=$$dir $$target \
|
||||||
) || exit 1; \
|
) || exit 1; \
|
||||||
fi
|
fi
|
||||||
@@ -335,15 +331,15 @@ build_crypto:
|
|||||||
dir=crypto; target=all; $(BUILD_ONE_CMD)
|
dir=crypto; target=all; $(BUILD_ONE_CMD)
|
||||||
build_fips:
|
build_fips:
|
||||||
@dir=fips; target=all; [ -z "$(FIPSCANLIB)" ] || $(BUILD_ONE_CMD)
|
@dir=fips; target=all; [ -z "$(FIPSCANLIB)" ] || $(BUILD_ONE_CMD)
|
||||||
build_ssl: build_crypto
|
build_ssl:
|
||||||
@dir=ssl; target=all; $(BUILD_ONE_CMD)
|
@dir=ssl; target=all; $(BUILD_ONE_CMD)
|
||||||
build_engines: build_crypto
|
build_engines:
|
||||||
@dir=engines; target=all; $(BUILD_ONE_CMD)
|
@dir=engines; target=all; $(BUILD_ONE_CMD)
|
||||||
build_apps: build_libs
|
build_apps:
|
||||||
@dir=apps; target=all; $(BUILD_ONE_CMD)
|
@dir=apps; target=all; $(BUILD_ONE_CMD)
|
||||||
build_tests: build_libs
|
build_tests:
|
||||||
@dir=test; target=all; $(BUILD_ONE_CMD)
|
@dir=test; target=all; $(BUILD_ONE_CMD)
|
||||||
build_tools: build_libs
|
build_tools:
|
||||||
@dir=tools; target=all; $(BUILD_ONE_CMD)
|
@dir=tools; target=all; $(BUILD_ONE_CMD)
|
||||||
|
|
||||||
all_testapps: build_libs build_testapps
|
all_testapps: build_libs build_testapps
|
||||||
@@ -359,7 +355,7 @@ libcrypto$(SHLIB_EXT): libcrypto.a $(SHARED_FIPS)
|
|||||||
$(AR) libcrypto.a fips/fipscanister.o ; \
|
$(AR) libcrypto.a fips/fipscanister.o ; \
|
||||||
else \
|
else \
|
||||||
if [ "$(FIPSCANLIB)" = "libcrypto" ]; then \
|
if [ "$(FIPSCANLIB)" = "libcrypto" ]; then \
|
||||||
FIPSLD_CC="$(CC)"; CC=fips/fipsld; \
|
FIPSLD_CC=$(CC); CC=fips/fipsld; \
|
||||||
export CC FIPSLD_CC; \
|
export CC FIPSLD_CC; \
|
||||||
fi; \
|
fi; \
|
||||||
$(MAKE) -e SHLIBDIRS='crypto' build-shared; \
|
$(MAKE) -e SHLIBDIRS='crypto' build-shared; \
|
||||||
@@ -382,7 +378,7 @@ libssl$(SHLIB_EXT): libcrypto$(SHLIB_EXT) libssl.a
|
|||||||
fips/fipscanister.o: build_fips
|
fips/fipscanister.o: build_fips
|
||||||
libfips$(SHLIB_EXT): fips/fipscanister.o
|
libfips$(SHLIB_EXT): fips/fipscanister.o
|
||||||
@if [ "$(SHLIB_TARGET)" != "" ]; then \
|
@if [ "$(SHLIB_TARGET)" != "" ]; then \
|
||||||
FIPSLD_CC="$(CC)"; CC=fips/fipsld; export CC FIPSLD_CC; \
|
FIPSLD_CC=$(CC); CC=fips/fipsld; export CC FIPSLD_CC; \
|
||||||
$(MAKE) -f Makefile.shared -e $(BUILDENV) \
|
$(MAKE) -f Makefile.shared -e $(BUILDENV) \
|
||||||
CC=$${CC} LIBNAME=fips THIS=$@ \
|
CC=$${CC} LIBNAME=fips THIS=$@ \
|
||||||
LIBEXTRAS=fips/fipscanister.o \
|
LIBEXTRAS=fips/fipscanister.o \
|
||||||
@@ -438,7 +434,7 @@ do_$(SHLIB_TARGET):
|
|||||||
libcrypto.pc: Makefile
|
libcrypto.pc: Makefile
|
||||||
@ ( echo 'prefix=$(INSTALLTOP)'; \
|
@ ( echo 'prefix=$(INSTALLTOP)'; \
|
||||||
echo 'exec_prefix=$${prefix}'; \
|
echo 'exec_prefix=$${prefix}'; \
|
||||||
echo 'libdir=$${exec_prefix}/$(LIBDIR)'; \
|
echo 'libdir=$${exec_prefix}/lib'; \
|
||||||
echo 'includedir=$${prefix}/include'; \
|
echo 'includedir=$${prefix}/include'; \
|
||||||
echo ''; \
|
echo ''; \
|
||||||
echo 'Name: OpenSSL-libcrypto'; \
|
echo 'Name: OpenSSL-libcrypto'; \
|
||||||
@@ -451,7 +447,7 @@ libcrypto.pc: Makefile
|
|||||||
libssl.pc: Makefile
|
libssl.pc: Makefile
|
||||||
@ ( echo 'prefix=$(INSTALLTOP)'; \
|
@ ( echo 'prefix=$(INSTALLTOP)'; \
|
||||||
echo 'exec_prefix=$${prefix}'; \
|
echo 'exec_prefix=$${prefix}'; \
|
||||||
echo 'libdir=$${exec_prefix}/$(LIBDIR)'; \
|
echo 'libdir=$${exec_prefix}/lib'; \
|
||||||
echo 'includedir=$${prefix}/include'; \
|
echo 'includedir=$${prefix}/include'; \
|
||||||
echo ''; \
|
echo ''; \
|
||||||
echo 'Name: OpenSSL'; \
|
echo 'Name: OpenSSL'; \
|
||||||
@@ -464,7 +460,7 @@ libssl.pc: Makefile
|
|||||||
openssl.pc: Makefile
|
openssl.pc: Makefile
|
||||||
@ ( echo 'prefix=$(INSTALLTOP)'; \
|
@ ( echo 'prefix=$(INSTALLTOP)'; \
|
||||||
echo 'exec_prefix=$${prefix}'; \
|
echo 'exec_prefix=$${prefix}'; \
|
||||||
echo 'libdir=$${exec_prefix}/$(LIBDIR)'; \
|
echo 'libdir=$${exec_prefix}/lib'; \
|
||||||
echo 'includedir=$${prefix}/include'; \
|
echo 'includedir=$${prefix}/include'; \
|
||||||
echo ''; \
|
echo ''; \
|
||||||
echo 'Name: OpenSSL'; \
|
echo 'Name: OpenSSL'; \
|
||||||
@@ -506,9 +502,6 @@ links:
|
|||||||
@$(PERL) $(TOP)/util/mkdir-p.pl include/openssl
|
@$(PERL) $(TOP)/util/mkdir-p.pl include/openssl
|
||||||
@$(PERL) $(TOP)/util/mklink.pl include/openssl $(EXHEADER)
|
@$(PERL) $(TOP)/util/mklink.pl include/openssl $(EXHEADER)
|
||||||
@set -e; target=links; $(RECURSIVE_BUILD_CMD)
|
@set -e; target=links; $(RECURSIVE_BUILD_CMD)
|
||||||
@if [ -z "$(FIPSCANLIB)" ]; then \
|
|
||||||
set -e; target=links; dir=fips ; $(BUILD_CMD) ; \
|
|
||||||
fi
|
|
||||||
|
|
||||||
gentests:
|
gentests:
|
||||||
@(cd test && echo "generating dummy tests (if needed)..." && \
|
@(cd test && echo "generating dummy tests (if needed)..." && \
|
||||||
@@ -519,14 +512,12 @@ dclean:
|
|||||||
@set -e; target=dclean; $(RECURSIVE_BUILD_CMD)
|
@set -e; target=dclean; $(RECURSIVE_BUILD_CMD)
|
||||||
|
|
||||||
rehash: rehash.time
|
rehash: rehash.time
|
||||||
rehash.time: certs apps
|
rehash.time: certs
|
||||||
@if [ -z "$(CROSS_COMPILE)" ]; then \
|
@(OPENSSL="`pwd`/util/opensslwrap.sh"; \
|
||||||
(OPENSSL="`pwd`/util/opensslwrap.sh"; \
|
|
||||||
OPENSSL_DEBUG_MEMORY=on; \
|
OPENSSL_DEBUG_MEMORY=on; \
|
||||||
export OPENSSL OPENSSL_DEBUG_MEMORY; \
|
export OPENSSL OPENSSL_DEBUG_MEMORY; \
|
||||||
$(PERL) tools/c_rehash certs) && \
|
$(PERL) tools/c_rehash certs)
|
||||||
touch rehash.time; \
|
touch rehash.time
|
||||||
fi
|
|
||||||
|
|
||||||
test: tests
|
test: tests
|
||||||
|
|
||||||
@@ -593,7 +584,7 @@ tar:
|
|||||||
$(TAR) $(TARFLAGS) --files-from ../$(TARFILE).list -cvf - | \
|
$(TAR) $(TARFLAGS) --files-from ../$(TARFILE).list -cvf - | \
|
||||||
tardy --user_number=0 --user_name=openssl \
|
tardy --user_number=0 --user_name=openssl \
|
||||||
--group_number=0 --group_name=openssl \
|
--group_number=0 --group_name=openssl \
|
||||||
--prefix=openssl-$(VERSION) - |\
|
--prefix=openssl-fips-$(VERSION) - |\
|
||||||
gzip --best >../$(TARFILE).gz; \
|
gzip --best >../$(TARFILE).gz; \
|
||||||
rm -f ../$(TARFILE).list; \
|
rm -f ../$(TARFILE).list; \
|
||||||
ls -l ../$(TARFILE).gz
|
ls -l ../$(TARFILE).gz
|
||||||
@@ -615,13 +606,13 @@ dist:
|
|||||||
dist_pem_h:
|
dist_pem_h:
|
||||||
(cd crypto/pem; $(MAKE) -e $(BUILDENV) pem.h; $(MAKE) clean)
|
(cd crypto/pem; $(MAKE) -e $(BUILDENV) pem.h; $(MAKE) clean)
|
||||||
|
|
||||||
install: all install_docs install_sw
|
install: all install_sw
|
||||||
|
|
||||||
install_sw:
|
install_sw:
|
||||||
@$(PERL) $(TOP)/util/mkdir-p.pl $(INSTALL_PREFIX)$(INSTALLTOP)/bin \
|
@$(PERL) $(TOP)/util/mkdir-p.pl $(INSTALL_PREFIX)$(INSTALLTOP)/bin \
|
||||||
$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR) \
|
$(INSTALL_PREFIX)$(INSTALLTOP)/lib \
|
||||||
$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/engines \
|
$(INSTALL_PREFIX)$(INSTALLTOP)/lib/engines \
|
||||||
$(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig \
|
$(INSTALL_PREFIX)$(INSTALLTOP)/lib/pkgconfig \
|
||||||
$(INSTALL_PREFIX)$(INSTALLTOP)/include/openssl \
|
$(INSTALL_PREFIX)$(INSTALLTOP)/include/openssl \
|
||||||
$(INSTALL_PREFIX)$(OPENSSLDIR)/misc \
|
$(INSTALL_PREFIX)$(OPENSSLDIR)/misc \
|
||||||
$(INSTALL_PREFIX)$(OPENSSLDIR)/certs \
|
$(INSTALL_PREFIX)$(OPENSSLDIR)/certs \
|
||||||
@@ -636,10 +627,10 @@ install_sw:
|
|||||||
do \
|
do \
|
||||||
if [ -f "$$i" ]; then \
|
if [ -f "$$i" ]; then \
|
||||||
( echo installing $$i; \
|
( echo installing $$i; \
|
||||||
cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
|
cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new; \
|
||||||
$(RANLIB) $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
|
$(RANLIB) $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new; \
|
||||||
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
|
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new; \
|
||||||
mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i ); \
|
mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i ); \
|
||||||
fi; \
|
fi; \
|
||||||
done;
|
done;
|
||||||
@set -e; if [ -n "$(SHARED_LIBS)" ]; then \
|
@set -e; if [ -n "$(SHARED_LIBS)" ]; then \
|
||||||
@@ -649,22 +640,22 @@ install_sw:
|
|||||||
if [ -f "$$i" -o -f "$$i.a" ]; then \
|
if [ -f "$$i" -o -f "$$i.a" ]; then \
|
||||||
( echo installing $$i; \
|
( echo installing $$i; \
|
||||||
if [ "$(PLATFORM)" != "Cygwin" ]; then \
|
if [ "$(PLATFORM)" != "Cygwin" ]; then \
|
||||||
cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
|
cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new; \
|
||||||
chmod 555 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
|
chmod 555 $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new; \
|
||||||
mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
|
mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i; \
|
||||||
else \
|
else \
|
||||||
c=`echo $$i | sed 's/^lib\(.*\)\.dll\.a/cyg\1-$(SHLIB_VERSION_NUMBER).dll/'`; \
|
c=`echo $$i | sed 's/^lib\(.*\)\.dll\.a/cyg\1-$(SHLIB_VERSION_NUMBER).dll/'`; \
|
||||||
cp $$c $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c.new; \
|
cp $$c $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c.new; \
|
||||||
chmod 755 $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c.new; \
|
chmod 755 $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c.new; \
|
||||||
mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c.new $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c; \
|
mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c.new $(INSTALL_PREFIX)$(INSTALLTOP)/bin/$$c; \
|
||||||
cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
|
cp $$i $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new; \
|
||||||
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new; \
|
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new; \
|
||||||
mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/$$i; \
|
mv -f $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i.new $(INSTALL_PREFIX)$(INSTALLTOP)/lib/$$i; \
|
||||||
fi ); \
|
fi ); \
|
||||||
fi; \
|
fi; \
|
||||||
done; \
|
done; \
|
||||||
( here="`pwd`"; \
|
( here="`pwd`"; \
|
||||||
cd $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR); \
|
cd $(INSTALL_PREFIX)$(INSTALLTOP)/lib; \
|
||||||
$(MAKE) -f $$here/Makefile HERE="$$here" link-shared ); \
|
$(MAKE) -f $$here/Makefile HERE="$$here" link-shared ); \
|
||||||
if [ "$(INSTALLTOP)" != "/usr" ]; then \
|
if [ "$(INSTALLTOP)" != "/usr" ]; then \
|
||||||
echo 'OpenSSL shared libraries have been installed in:'; \
|
echo 'OpenSSL shared libraries have been installed in:'; \
|
||||||
@@ -673,12 +664,12 @@ install_sw:
|
|||||||
sed -e '1,/^$$/d' doc/openssl-shared.txt; \
|
sed -e '1,/^$$/d' doc/openssl-shared.txt; \
|
||||||
fi; \
|
fi; \
|
||||||
fi
|
fi
|
||||||
cp libcrypto.pc $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig
|
cp libcrypto.pc $(INSTALL_PREFIX)$(INSTALLTOP)/lib/pkgconfig
|
||||||
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig/libcrypto.pc
|
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/lib/pkgconfig/libcrypto.pc
|
||||||
cp libssl.pc $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig
|
cp libssl.pc $(INSTALL_PREFIX)$(INSTALLTOP)/lib/pkgconfig
|
||||||
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig/libssl.pc
|
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/lib/pkgconfig/libssl.pc
|
||||||
cp openssl.pc $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig
|
cp openssl.pc $(INSTALL_PREFIX)$(INSTALLTOP)/lib/pkgconfig
|
||||||
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/$(LIBDIR)/pkgconfig/openssl.pc
|
chmod 644 $(INSTALL_PREFIX)$(INSTALLTOP)/lib/pkgconfig/openssl.pc
|
||||||
|
|
||||||
install_docs:
|
install_docs:
|
||||||
@$(PERL) $(TOP)/util/mkdir-p.pl \
|
@$(PERL) $(TOP)/util/mkdir-p.pl \
|
||||||
@@ -686,7 +677,7 @@ install_docs:
|
|||||||
$(INSTALL_PREFIX)$(MANDIR)/man3 \
|
$(INSTALL_PREFIX)$(MANDIR)/man3 \
|
||||||
$(INSTALL_PREFIX)$(MANDIR)/man5 \
|
$(INSTALL_PREFIX)$(MANDIR)/man5 \
|
||||||
$(INSTALL_PREFIX)$(MANDIR)/man7
|
$(INSTALL_PREFIX)$(MANDIR)/man7
|
||||||
@pod2man="`cd ./util; ./pod2mantest $(PERL)`"; \
|
@pod2man="`cd util; ./pod2mantest $(PERL)`"; \
|
||||||
here="`pwd`"; \
|
here="`pwd`"; \
|
||||||
filecase=; \
|
filecase=; \
|
||||||
if [ "$(PLATFORM)" = "DJGPP" -o "$(PLATFORM)" = "Cygwin" -o "$(PLATFORM)" = "mingw" ]; then \
|
if [ "$(PLATFORM)" = "DJGPP" -o "$(PLATFORM)" = "Cygwin" -o "$(PLATFORM)" = "mingw" ]; then \
|
||||||
|
|||||||
@@ -491,23 +491,23 @@ link_app.hpux:
|
|||||||
|
|
||||||
link_o.aix:
|
link_o.aix:
|
||||||
@ $(CALC_VERSIONS); \
|
@ $(CALC_VERSIONS); \
|
||||||
OBJECT_MODE=`expr "x$(SHARED_LDFLAGS)" : 'x\-[a-z]*\(64\)'` || :; \
|
OBJECT_MODE=`expr x$(SHARED_LDFLAGS) : 'x\-[a-z]*\(64\)'` || :; \
|
||||||
OBJECT_MODE=$${OBJECT_MODE:-32}; export OBJECT_MODE; \
|
OBJECT_MODE=$${OBJECT_MODE:-32}; export OBJECT_MODE; \
|
||||||
SHLIB=lib$(LIBNAME).so; \
|
SHLIB=lib$(LIBNAME).so; \
|
||||||
SHLIB_SUFFIX=; \
|
SHLIB_SUFFIX=; \
|
||||||
ALLSYMSFLAGS=''; \
|
ALLSYMSFLAGS=''; \
|
||||||
NOALLSYMSFLAGS=''; \
|
NOALLSYMSFLAGS=''; \
|
||||||
SHAREDFLAGS='$(CFLAGS) $(SHARED_LDFLAGS) -Wl,-bexpall,-bnolibpath,-bM:SRE'; \
|
SHAREDFLAGS='$(CFLAGS) $(SHARED_LDFLAGS) -Wl,-G,-bexpall,-bnolibpath,-bM:SRE'; \
|
||||||
$(LINK_SO_O);
|
$(LINK_SO_O);
|
||||||
link_a.aix:
|
link_a.aix:
|
||||||
@ $(CALC_VERSIONS); \
|
@ $(CALC_VERSIONS); \
|
||||||
OBJECT_MODE=`expr "x$(SHARED_LDFLAGS)" : 'x\-[a-z]*\(64\)'` || : ; \
|
OBJECT_MODE=`expr x$(SHARED_LDFLAGS) : 'x\-[a-z]*\(64\)'` || : ; \
|
||||||
OBJECT_MODE=$${OBJECT_MODE:-32}; export OBJECT_MODE; \
|
OBJECT_MODE=$${OBJECT_MODE:-32}; export OBJECT_MODE; \
|
||||||
SHLIB=lib$(LIBNAME).so; \
|
SHLIB=lib$(LIBNAME).so; \
|
||||||
SHLIB_SUFFIX=; \
|
SHLIB_SUFFIX=; \
|
||||||
ALLSYMSFLAGS='-bnogc'; \
|
ALLSYMSFLAGS='-bnogc'; \
|
||||||
NOALLSYMSFLAGS=''; \
|
NOALLSYMSFLAGS=''; \
|
||||||
SHAREDFLAGS='$(CFLAGS) $(SHARED_LDFLAGS) -Wl,-bexpall,-bnolibpath,-bM:SRE'; \
|
SHAREDFLAGS='$(CFLAGS) $(SHARED_LDFLAGS) -Wl,-G,-bexpall,-bnolibpath,-bM:SRE'; \
|
||||||
$(LINK_SO_A_VIA_O)
|
$(LINK_SO_A_VIA_O)
|
||||||
link_app.aix:
|
link_app.aix:
|
||||||
LDFLAGS="$(CFLAGS) -Wl,-brtl,-blibpath:$(LIBRPATH):$${LIBPATH:-/usr/lib:/lib}"; \
|
LDFLAGS="$(CFLAGS) -Wl,-brtl,-blibpath:$(LIBRPATH):$${LIBPATH:-/usr/lib:/lib}"; \
|
||||||
|
|||||||
235
NEWS
235
NEWS
@@ -5,179 +5,23 @@
|
|||||||
This file gives a brief overview of the major changes between each OpenSSL
|
This file gives a brief overview of the major changes between each OpenSSL
|
||||||
release. For more details please read the CHANGES file.
|
release. For more details please read the CHANGES file.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8zd and OpenSSL 0.9.8ze [15 Jan 2015]
|
Major changes between OpenSSL 0.9.8d and OpenSSL 0.9.8e:
|
||||||
|
|
||||||
o Build fixes for the Windows and OpenVMS platforms
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8zc and OpenSSL 0.9.8zd [8 Jan 2015]
|
|
||||||
|
|
||||||
o Fix for CVE-2014-3571
|
|
||||||
o Fix for CVE-2014-3569
|
|
||||||
o Fix for CVE-2014-3572
|
|
||||||
o Fix for CVE-2015-0204
|
|
||||||
o Fix for CVE-2014-8275
|
|
||||||
o Fix for CVE-2014-3570
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8zb and OpenSSL 0.9.8zc [15 Oct 2014]:
|
|
||||||
|
|
||||||
o Fix for CVE-2014-3513
|
|
||||||
o Fix for CVE-2014-3567
|
|
||||||
o Mitigation for CVE-2014-3566 (SSL protocol vulnerability)
|
|
||||||
o Fix for CVE-2014-3568
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8za and OpenSSL 0.9.8zb [6 Aug 2014]:
|
|
||||||
|
|
||||||
o Fix for CVE-2014-3510
|
|
||||||
o Fix for CVE-2014-3507
|
|
||||||
o Fix for CVE-2014-3506
|
|
||||||
o Fix for CVE-2014-3505
|
|
||||||
o Fix for CVE-2014-3508
|
|
||||||
|
|
||||||
Known issues in OpenSSL 0.9.8za:
|
|
||||||
|
|
||||||
o Compilation failure of s3_pkt.c on some platforms due to missing
|
|
||||||
<limits.h> include. Fixed in 0.9.8zb-dev.
|
|
||||||
o FIPS capable link failure with missing symbol BN_consttime_swap.
|
|
||||||
Fixed in 0.9.8zb-dev. Workaround is to compile with no-ec: the EC
|
|
||||||
algorithms are not FIPS approved in OpenSSL 0.9.8 anyway.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8y and OpenSSL 0.9.8za [5 Jun 2014]:
|
|
||||||
|
|
||||||
o Fix for CVE-2014-0224
|
|
||||||
o Fix for CVE-2014-0221
|
|
||||||
o Fix for CVE-2014-0195
|
|
||||||
o Fix for CVE-2014-3470
|
|
||||||
o Fix for CVE-2014-0076
|
|
||||||
o Fix for CVE-2010-5298
|
|
||||||
o Fix to TLS alert handling.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8x and OpenSSL 0.9.8y [5 Feb 2013]:
|
|
||||||
|
|
||||||
o Fix for SSL/TLS/DTLS CBC plaintext recovery attack CVE-2013-0169
|
|
||||||
o Fix OCSP bad key DoS attack CVE-2013-0166
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8w and OpenSSL 0.9.8x [10 May 2012]:
|
|
||||||
|
|
||||||
o Fix DTLS record length checking bug CVE-2012-2333
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8v and OpenSSL 0.9.8w [23 Apr 2012]:
|
|
||||||
|
|
||||||
o Fix for CVE-2012-2131 (corrected fix for 0.9.8 and CVE-2012-2110)
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8u and OpenSSL 0.9.8v [19 Apr 2012]:
|
|
||||||
|
|
||||||
o Fix for ASN1 overflow bug CVE-2012-2110
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8t and OpenSSL 0.9.8u [12 Mar 2012]:
|
|
||||||
|
|
||||||
o Fix for CMS/PKCS#7 MMA CVE-2012-0884
|
|
||||||
o Corrected fix for CVE-2011-4619
|
|
||||||
o Various DTLS fixes.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8s and OpenSSL 0.9.8t [18 Jan 2012]:
|
|
||||||
|
|
||||||
o Fix for DTLS DoS issue CVE-2012-0050
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8r and OpenSSL 0.9.8s [4 Jan 2012]:
|
|
||||||
|
|
||||||
o Fix for DTLS plaintext recovery attack CVE-2011-4108
|
|
||||||
o Fix policy check double free error CVE-2011-4109
|
|
||||||
o Clear block padding bytes of SSL 3.0 records CVE-2011-4576
|
|
||||||
o Only allow one SGC handshake restart for SSL/TLS CVE-2011-4619
|
|
||||||
o Check for malformed RFC3779 data CVE-2011-4577
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8q and OpenSSL 0.9.8r [8 Feb 2011]:
|
|
||||||
|
|
||||||
o Fix for security issue CVE-2011-0014
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8p and OpenSSL 0.9.8q [2 Dec 2010]:
|
|
||||||
|
|
||||||
o Fix for security issue CVE-2010-4180
|
|
||||||
o Fix for CVE-2010-4252
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8o and OpenSSL 0.9.8p [16 Nov 2010]:
|
|
||||||
|
|
||||||
o Fix for security issue CVE-2010-3864.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8n and OpenSSL 0.9.8o [1 Jun 2010]:
|
|
||||||
|
|
||||||
o Fix for security issue CVE-2010-0742.
|
|
||||||
o Various DTLS fixes.
|
|
||||||
o Recognise SHA2 certificates if only SSL algorithms added.
|
|
||||||
o Fix for no-rc4 compilation.
|
|
||||||
o Chil ENGINE unload workaround.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8m and OpenSSL 0.9.8n [24 Mar 2010]:
|
|
||||||
|
|
||||||
o CFB cipher definition fixes.
|
|
||||||
o Fix security issues CVE-2010-0740 and CVE-2010-0433.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8l and OpenSSL 0.9.8m [25 Feb 2010]:
|
|
||||||
|
|
||||||
o Cipher definition fixes.
|
|
||||||
o Workaround for slow RAND_poll() on some WIN32 versions.
|
|
||||||
o Remove MD2 from algorithm tables.
|
|
||||||
o SPKAC handling fixes.
|
|
||||||
o Support for RFC5746 TLS renegotiation extension.
|
|
||||||
o Compression memory leak fixed.
|
|
||||||
o Compression session resumption fixed.
|
|
||||||
o Ticket and SNI coexistence fixes.
|
|
||||||
o Many fixes to DTLS handling.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8k and OpenSSL 0.9.8l [5 Nov 2009]:
|
|
||||||
|
|
||||||
o Temporary work around for CVE-2009-3555: disable renegotiation.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8j and OpenSSL 0.9.8k [25 Mar 2009]:
|
|
||||||
|
|
||||||
o Fix various build issues.
|
|
||||||
o Fix security issues (CVE-2009-0590, CVE-2009-0591, CVE-2009-0789)
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8i and OpenSSL 0.9.8j [7 Jan 2009]:
|
|
||||||
|
|
||||||
o Fix security issue (CVE-2008-5077)
|
|
||||||
o Merge FIPS 140-2 branch code.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8g and OpenSSL 0.9.8h [28 May 2008]:
|
|
||||||
|
|
||||||
o CryptoAPI ENGINE support.
|
|
||||||
o Various precautionary measures.
|
|
||||||
o Fix for bugs affecting certificate request creation.
|
|
||||||
o Support for local machine keyset attribute in PKCS#12 files.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8f and OpenSSL 0.9.8g [19 Oct 2007]:
|
|
||||||
|
|
||||||
o Backport of CMS functionality to 0.9.8.
|
|
||||||
o Fixes for bugs introduced with 0.9.8f.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8e and OpenSSL 0.9.8f [11 Oct 2007]:
|
|
||||||
|
|
||||||
o Add gcc 4.2 support.
|
|
||||||
o Add support for AES and SSE2 assembly lanugauge optimization
|
|
||||||
for VC++ build.
|
|
||||||
o Support for RFC4507bis and server name extensions if explicitly
|
|
||||||
selected at compile time.
|
|
||||||
o DTLS improvements.
|
|
||||||
o RFC4507bis support.
|
|
||||||
o TLS Extensions support.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8d and OpenSSL 0.9.8e [23 Feb 2007]:
|
|
||||||
|
|
||||||
o Various ciphersuite selection fixes.
|
o Various ciphersuite selection fixes.
|
||||||
o RFC3779 support.
|
o RFC3779 support.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8c and OpenSSL 0.9.8d [28 Sep 2006]:
|
Major changes between OpenSSL 0.9.8c and OpenSSL 0.9.8d:
|
||||||
|
|
||||||
o Introduce limits to prevent malicious key DoS (CVE-2006-2940)
|
o Introduce limits to prevent malicious key DoS (CVE-2006-2940)
|
||||||
o Fix security issues (CVE-2006-2937, CVE-2006-3737, CVE-2006-4343)
|
o Fix security issues (CVE-2006-2937, CVE-2006-3737, CVE-2006-4343)
|
||||||
o Changes to ciphersuite selection algorithm
|
o Changes to ciphersuite selection algorithm
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8b and OpenSSL 0.9.8c [5 Sep 2006]:
|
Major changes between OpenSSL 0.9.8b and OpenSSL 0.9.8c:
|
||||||
|
|
||||||
o Fix Daniel Bleichenbacher forged signature attack, CVE-2006-4339
|
o Fix Daniel Bleichenbacher forged signature attack, CVE-2006-4339
|
||||||
o New cipher Camellia
|
o New cipher Camellia
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8a and OpenSSL 0.9.8b [4 May 2006]:
|
Major changes between OpenSSL 0.9.8a and OpenSSL 0.9.8b:
|
||||||
|
|
||||||
o Cipher string fixes.
|
o Cipher string fixes.
|
||||||
o Fixes for VC++ 2005.
|
o Fixes for VC++ 2005.
|
||||||
@@ -187,12 +31,12 @@
|
|||||||
o Built in dynamic engine compilation support on Win32.
|
o Built in dynamic engine compilation support on Win32.
|
||||||
o Fixes auto dynamic engine loading in Win32.
|
o Fixes auto dynamic engine loading in Win32.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.8 and OpenSSL 0.9.8a [11 Oct 2005]:
|
Major changes between OpenSSL 0.9.8 and OpenSSL 0.9.8a:
|
||||||
|
|
||||||
o Fix potential SSL 2.0 rollback, CVE-2005-2969
|
o Fix potential SSL 2.0 rollback, CVE-2005-2969
|
||||||
o Extended Windows CE support
|
o Extended Windows CE support
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7g and OpenSSL 0.9.8 [5 Jul 2005]:
|
Major changes between OpenSSL 0.9.7g and OpenSSL 0.9.8:
|
||||||
|
|
||||||
o Major work on the BIGNUM library for higher efficiency and to
|
o Major work on the BIGNUM library for higher efficiency and to
|
||||||
make operations more streamlined and less contradictory. This
|
make operations more streamlined and less contradictory. This
|
||||||
@@ -266,36 +110,31 @@
|
|||||||
o Added initial support for Win64.
|
o Added initial support for Win64.
|
||||||
o Added alternate pkg-config files.
|
o Added alternate pkg-config files.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7l and OpenSSL 0.9.7m [23 Feb 2007]:
|
Major changes between OpenSSL 0.9.7k and OpenSSL 0.9.7l:
|
||||||
|
|
||||||
o FIPS 1.1.1 module linking.
|
|
||||||
o Various ciphersuite selection fixes.
|
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7k and OpenSSL 0.9.7l [28 Sep 2006]:
|
|
||||||
|
|
||||||
o Introduce limits to prevent malicious key DoS (CVE-2006-2940)
|
o Introduce limits to prevent malicious key DoS (CVE-2006-2940)
|
||||||
o Fix security issues (CVE-2006-2937, CVE-2006-3737, CVE-2006-4343)
|
o Fix security issues (CVE-2006-2937, CVE-2006-3737, CVE-2006-4343)
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7j and OpenSSL 0.9.7k [5 Sep 2006]:
|
Major changes between OpenSSL 0.9.7j and OpenSSL 0.9.7k:
|
||||||
|
|
||||||
o Fix Daniel Bleichenbacher forged signature attack, CVE-2006-4339
|
o Fix Daniel Bleichenbacher forged signature attack, CVE-2006-4339
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7i and OpenSSL 0.9.7j [4 May 2006]:
|
Major changes between OpenSSL 0.9.7i and OpenSSL 0.9.7j:
|
||||||
|
|
||||||
o Visual C++ 2005 fixes.
|
o Visual C++ 2005 fixes.
|
||||||
o Update Windows build system for FIPS.
|
o Update Windows build system for FIPS.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7h and OpenSSL 0.9.7i [14 Oct 2005]:
|
Major changes between OpenSSL 0.9.7h and OpenSSL 0.9.7i:
|
||||||
|
|
||||||
o Give EVP_MAX_MD_SIZE it's old value, except for a FIPS build.
|
o Give EVP_MAX_MD_SIZE it's old value, except for a FIPS build.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7g and OpenSSL 0.9.7h [11 Oct 2005]:
|
Major changes between OpenSSL 0.9.7g and OpenSSL 0.9.7h:
|
||||||
|
|
||||||
o Fix SSL 2.0 Rollback, CVE-2005-2969
|
o Fix SSL 2.0 Rollback, CVE-2005-2969
|
||||||
o Allow use of fixed-length exponent on DSA signing
|
o Allow use of fixed-length exponent on DSA signing
|
||||||
o Default fixed-window RSA, DSA, DH private-key operations
|
o Default fixed-window RSA, DSA, DH private-key operations
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7f and OpenSSL 0.9.7g [11 Apr 2005]:
|
Major changes between OpenSSL 0.9.7f and OpenSSL 0.9.7g:
|
||||||
|
|
||||||
o More compilation issues fixed.
|
o More compilation issues fixed.
|
||||||
o Adaptation to more modern Kerberos API.
|
o Adaptation to more modern Kerberos API.
|
||||||
@@ -304,7 +143,7 @@
|
|||||||
o More constification.
|
o More constification.
|
||||||
o Added processing of proxy certificates (RFC 3820).
|
o Added processing of proxy certificates (RFC 3820).
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7e and OpenSSL 0.9.7f [22 Mar 2005]:
|
Major changes between OpenSSL 0.9.7e and OpenSSL 0.9.7f:
|
||||||
|
|
||||||
o Several compilation issues fixed.
|
o Several compilation issues fixed.
|
||||||
o Many memory allocation failure checks added.
|
o Many memory allocation failure checks added.
|
||||||
@@ -312,12 +151,12 @@
|
|||||||
o Mandatory basic checks on certificates.
|
o Mandatory basic checks on certificates.
|
||||||
o Performance improvements.
|
o Performance improvements.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7d and OpenSSL 0.9.7e [25 Oct 2004]:
|
Major changes between OpenSSL 0.9.7d and OpenSSL 0.9.7e:
|
||||||
|
|
||||||
o Fix race condition in CRL checking code.
|
o Fix race condition in CRL checking code.
|
||||||
o Fixes to PKCS#7 (S/MIME) code.
|
o Fixes to PKCS#7 (S/MIME) code.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7c and OpenSSL 0.9.7d [17 Mar 2004]:
|
Major changes between OpenSSL 0.9.7c and OpenSSL 0.9.7d:
|
||||||
|
|
||||||
o Security: Fix Kerberos ciphersuite SSL/TLS handshaking bug
|
o Security: Fix Kerberos ciphersuite SSL/TLS handshaking bug
|
||||||
o Security: Fix null-pointer assignment in do_change_cipher_spec()
|
o Security: Fix null-pointer assignment in do_change_cipher_spec()
|
||||||
@@ -325,14 +164,14 @@
|
|||||||
o Multiple X509 verification fixes
|
o Multiple X509 verification fixes
|
||||||
o Speed up HMAC and other operations
|
o Speed up HMAC and other operations
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7b and OpenSSL 0.9.7c [30 Sep 2003]:
|
Major changes between OpenSSL 0.9.7b and OpenSSL 0.9.7c:
|
||||||
|
|
||||||
o Security: fix various ASN1 parsing bugs.
|
o Security: fix various ASN1 parsing bugs.
|
||||||
o New -ignore_err option to OCSP utility.
|
o New -ignore_err option to OCSP utility.
|
||||||
o Various interop and bug fixes in S/MIME code.
|
o Various interop and bug fixes in S/MIME code.
|
||||||
o SSL/TLS protocol fix for unrequested client certificates.
|
o SSL/TLS protocol fix for unrequested client certificates.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7a and OpenSSL 0.9.7b [10 Apr 2003]:
|
Major changes between OpenSSL 0.9.7a and OpenSSL 0.9.7b:
|
||||||
|
|
||||||
o Security: counter the Klima-Pokorny-Rosa extension of
|
o Security: counter the Klima-Pokorny-Rosa extension of
|
||||||
Bleichbacher's attack
|
Bleichbacher's attack
|
||||||
@@ -343,7 +182,7 @@
|
|||||||
o ASN.1: treat domainComponent correctly.
|
o ASN.1: treat domainComponent correctly.
|
||||||
o Documentation: fixes and additions.
|
o Documentation: fixes and additions.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.7 and OpenSSL 0.9.7a [19 Feb 2003]:
|
Major changes between OpenSSL 0.9.7 and OpenSSL 0.9.7a:
|
||||||
|
|
||||||
o Security: Important security related bugfixes.
|
o Security: Important security related bugfixes.
|
||||||
o Enhanced compatibility with MIT Kerberos.
|
o Enhanced compatibility with MIT Kerberos.
|
||||||
@@ -354,7 +193,7 @@
|
|||||||
o SSL/TLS: now handles manual certificate chain building.
|
o SSL/TLS: now handles manual certificate chain building.
|
||||||
o SSL/TLS: certain session ID malfunctions corrected.
|
o SSL/TLS: certain session ID malfunctions corrected.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6 and OpenSSL 0.9.7 [30 Dec 2002]:
|
Major changes between OpenSSL 0.9.6 and OpenSSL 0.9.7:
|
||||||
|
|
||||||
o New library section OCSP.
|
o New library section OCSP.
|
||||||
o Complete rewrite of ASN1 code.
|
o Complete rewrite of ASN1 code.
|
||||||
@@ -400,23 +239,23 @@
|
|||||||
o SSL/TLS: add callback to retrieve SSL/TLS messages.
|
o SSL/TLS: add callback to retrieve SSL/TLS messages.
|
||||||
o SSL/TLS: support AES cipher suites (RFC3268).
|
o SSL/TLS: support AES cipher suites (RFC3268).
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6j and OpenSSL 0.9.6k [30 Sep 2003]:
|
Major changes between OpenSSL 0.9.6j and OpenSSL 0.9.6k:
|
||||||
|
|
||||||
o Security: fix various ASN1 parsing bugs.
|
o Security: fix various ASN1 parsing bugs.
|
||||||
o SSL/TLS protocol fix for unrequested client certificates.
|
o SSL/TLS protocol fix for unrequested client certificates.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6i and OpenSSL 0.9.6j [10 Apr 2003]:
|
Major changes between OpenSSL 0.9.6i and OpenSSL 0.9.6j:
|
||||||
|
|
||||||
o Security: counter the Klima-Pokorny-Rosa extension of
|
o Security: counter the Klima-Pokorny-Rosa extension of
|
||||||
Bleichbacher's attack
|
Bleichbacher's attack
|
||||||
o Security: make RSA blinding default.
|
o Security: make RSA blinding default.
|
||||||
o Build: shared library support fixes.
|
o Build: shared library support fixes.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6h and OpenSSL 0.9.6i [19 Feb 2003]:
|
Major changes between OpenSSL 0.9.6h and OpenSSL 0.9.6i:
|
||||||
|
|
||||||
o Important security related bugfixes.
|
o Important security related bugfixes.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6g and OpenSSL 0.9.6h [5 Dec 2002]:
|
Major changes between OpenSSL 0.9.6g and OpenSSL 0.9.6h:
|
||||||
|
|
||||||
o New configuration targets for Tandem OSS and A/UX.
|
o New configuration targets for Tandem OSS and A/UX.
|
||||||
o New OIDs for Microsoft attributes.
|
o New OIDs for Microsoft attributes.
|
||||||
@@ -430,25 +269,25 @@
|
|||||||
o Fixes for smaller building problems.
|
o Fixes for smaller building problems.
|
||||||
o Updates of manuals, FAQ and other instructive documents.
|
o Updates of manuals, FAQ and other instructive documents.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6f and OpenSSL 0.9.6g [9 Aug 2002]:
|
Major changes between OpenSSL 0.9.6f and OpenSSL 0.9.6g:
|
||||||
|
|
||||||
o Important building fixes on Unix.
|
o Important building fixes on Unix.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6e and OpenSSL 0.9.6f [8 Aug 2002]:
|
Major changes between OpenSSL 0.9.6e and OpenSSL 0.9.6f:
|
||||||
|
|
||||||
o Various important bugfixes.
|
o Various important bugfixes.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6d and OpenSSL 0.9.6e [30 Jul 2002]:
|
Major changes between OpenSSL 0.9.6d and OpenSSL 0.9.6e:
|
||||||
|
|
||||||
o Important security related bugfixes.
|
o Important security related bugfixes.
|
||||||
o Various SSL/TLS library bugfixes.
|
o Various SSL/TLS library bugfixes.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6c and OpenSSL 0.9.6d [9 May 2002]:
|
Major changes between OpenSSL 0.9.6c and OpenSSL 0.9.6d:
|
||||||
|
|
||||||
o Various SSL/TLS library bugfixes.
|
o Various SSL/TLS library bugfixes.
|
||||||
o Fix DH parameter generation for 'non-standard' generators.
|
o Fix DH parameter generation for 'non-standard' generators.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6b and OpenSSL 0.9.6c [21 Dec 2001]:
|
Major changes between OpenSSL 0.9.6b and OpenSSL 0.9.6c:
|
||||||
|
|
||||||
o Various SSL/TLS library bugfixes.
|
o Various SSL/TLS library bugfixes.
|
||||||
o BIGNUM library fixes.
|
o BIGNUM library fixes.
|
||||||
@@ -461,7 +300,7 @@
|
|||||||
Broadcom and Cryptographic Appliance's keyserver
|
Broadcom and Cryptographic Appliance's keyserver
|
||||||
[in 0.9.6c-engine release].
|
[in 0.9.6c-engine release].
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6a and OpenSSL 0.9.6b [9 Jul 2001]:
|
Major changes between OpenSSL 0.9.6a and OpenSSL 0.9.6b:
|
||||||
|
|
||||||
o Security fix: PRNG improvements.
|
o Security fix: PRNG improvements.
|
||||||
o Security fix: RSA OAEP check.
|
o Security fix: RSA OAEP check.
|
||||||
@@ -478,7 +317,7 @@
|
|||||||
o Increase default size for BIO buffering filter.
|
o Increase default size for BIO buffering filter.
|
||||||
o Compatibility fixes in some scripts.
|
o Compatibility fixes in some scripts.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.6 and OpenSSL 0.9.6a [5 Apr 2001]:
|
Major changes between OpenSSL 0.9.6 and OpenSSL 0.9.6a:
|
||||||
|
|
||||||
o Security fix: change behavior of OpenSSL to avoid using
|
o Security fix: change behavior of OpenSSL to avoid using
|
||||||
environment variables when running as root.
|
environment variables when running as root.
|
||||||
@@ -503,7 +342,7 @@
|
|||||||
o New function BN_rand_range().
|
o New function BN_rand_range().
|
||||||
o Add "-rand" option to openssl s_client and s_server.
|
o Add "-rand" option to openssl s_client and s_server.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.5a and OpenSSL 0.9.6 [10 Oct 2000]:
|
Major changes between OpenSSL 0.9.5a and OpenSSL 0.9.6:
|
||||||
|
|
||||||
o Some documentation for BIO and SSL libraries.
|
o Some documentation for BIO and SSL libraries.
|
||||||
o Enhanced chain verification using key identifiers.
|
o Enhanced chain verification using key identifiers.
|
||||||
@@ -518,7 +357,7 @@
|
|||||||
[1] The support for external crypto devices is currently a separate
|
[1] The support for external crypto devices is currently a separate
|
||||||
distribution. See the file README.ENGINE.
|
distribution. See the file README.ENGINE.
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.5 and OpenSSL 0.9.5a [1 Apr 2000]:
|
Major changes between OpenSSL 0.9.5 and OpenSSL 0.9.5a:
|
||||||
|
|
||||||
o Bug fixes for Win32, SuSE Linux, NeXTSTEP and FreeBSD 2.2.8
|
o Bug fixes for Win32, SuSE Linux, NeXTSTEP and FreeBSD 2.2.8
|
||||||
o Shared library support for HPUX and Solaris-gcc
|
o Shared library support for HPUX and Solaris-gcc
|
||||||
@@ -527,7 +366,7 @@
|
|||||||
o New 'rand' application
|
o New 'rand' application
|
||||||
o New way to check for existence of algorithms from scripts
|
o New way to check for existence of algorithms from scripts
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.4 and OpenSSL 0.9.5 [25 May 2000]:
|
Major changes between OpenSSL 0.9.4 and OpenSSL 0.9.5:
|
||||||
|
|
||||||
o S/MIME support in new 'smime' command
|
o S/MIME support in new 'smime' command
|
||||||
o Documentation for the OpenSSL command line application
|
o Documentation for the OpenSSL command line application
|
||||||
@@ -563,7 +402,7 @@
|
|||||||
o Enhanced support for Alpha Linux
|
o Enhanced support for Alpha Linux
|
||||||
o Experimental MacOS support
|
o Experimental MacOS support
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.3 and OpenSSL 0.9.4 [9 Aug 1999]:
|
Major changes between OpenSSL 0.9.3 and OpenSSL 0.9.4:
|
||||||
|
|
||||||
o Transparent support for PKCS#8 format private keys: these are used
|
o Transparent support for PKCS#8 format private keys: these are used
|
||||||
by several software packages and are more secure than the standard
|
by several software packages and are more secure than the standard
|
||||||
@@ -574,7 +413,7 @@
|
|||||||
o New pipe-like BIO that allows using the SSL library when actual I/O
|
o New pipe-like BIO that allows using the SSL library when actual I/O
|
||||||
must be handled by the application (BIO pair)
|
must be handled by the application (BIO pair)
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.2b and OpenSSL 0.9.3 [24 May 1999]:
|
Major changes between OpenSSL 0.9.2b and OpenSSL 0.9.3:
|
||||||
o Lots of enhancements and cleanups to the Configuration mechanism
|
o Lots of enhancements and cleanups to the Configuration mechanism
|
||||||
o RSA OEAP related fixes
|
o RSA OEAP related fixes
|
||||||
o Added `openssl ca -revoke' option for revoking a certificate
|
o Added `openssl ca -revoke' option for revoking a certificate
|
||||||
@@ -588,7 +427,7 @@
|
|||||||
o Sparc assembler bignum implementation, optimized hash functions
|
o Sparc assembler bignum implementation, optimized hash functions
|
||||||
o Option to disable selected ciphers
|
o Option to disable selected ciphers
|
||||||
|
|
||||||
Major changes between OpenSSL 0.9.1c and OpenSSL 0.9.2b [22 Mar 1999]:
|
Major changes between OpenSSL 0.9.1c and OpenSSL 0.9.2b:
|
||||||
o Fixed a security hole related to session resumption
|
o Fixed a security hole related to session resumption
|
||||||
o Fixed RSA encryption routines for the p < q case
|
o Fixed RSA encryption routines for the p < q case
|
||||||
o "ALL" in cipher lists now means "everything except NULL ciphers"
|
o "ALL" in cipher lists now means "everything except NULL ciphers"
|
||||||
@@ -610,7 +449,7 @@
|
|||||||
o Lots of memory leak fixes.
|
o Lots of memory leak fixes.
|
||||||
o Lots of bug fixes.
|
o Lots of bug fixes.
|
||||||
|
|
||||||
Major changes between SSLeay 0.9.0b and OpenSSL 0.9.1c [23 Dec 1998]:
|
Major changes between SSLeay 0.9.0b and OpenSSL 0.9.1c:
|
||||||
o Integration of the popular NO_RSA/NO_DSA patches
|
o Integration of the popular NO_RSA/NO_DSA patches
|
||||||
o Initial support for compression inside the SSL record layer
|
o Initial support for compression inside the SSL record layer
|
||||||
o Added BIO proxy and filtering functionality
|
o Added BIO proxy and filtering functionality
|
||||||
|
|||||||
4
PROBLEMS
4
PROBLEMS
@@ -36,9 +36,7 @@ may differ on your machine.
|
|||||||
|
|
||||||
|
|
||||||
As long as Apple doesn't fix the problem with ld, this problem building
|
As long as Apple doesn't fix the problem with ld, this problem building
|
||||||
OpenSSL will remain as is. Well, the problem was addressed in 0.9.8f by
|
OpenSSL will remain as is.
|
||||||
passing -Wl,-search_paths_first, but it's unknown if the flag was
|
|
||||||
supported from the initial MacOS X release.
|
|
||||||
|
|
||||||
|
|
||||||
* Parallell make leads to errors
|
* Parallell make leads to errors
|
||||||
|
|||||||
35
README
35
README
@@ -1,10 +1,16 @@
|
|||||||
|
|
||||||
OpenSSL 0.9.8ze 15 Jan 2015
|
OpenSSL 0.9.8h-fips-dev test version
|
||||||
|
|
||||||
Copyright (c) 1998-2011 The OpenSSL Project
|
Copyright (c) 1998-2007 The OpenSSL Project
|
||||||
Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson
|
Copyright (c) 1995-1998 Eric A. Young, Tim J. Hudson
|
||||||
All rights reserved.
|
All rights reserved.
|
||||||
|
|
||||||
|
WARNING
|
||||||
|
-------
|
||||||
|
|
||||||
|
This version of OpenSSL is a port of the FIPS 140-2 code to OpenSSL
|
||||||
|
0.9.8. See the file README.FIPS for brief usage details.
|
||||||
|
|
||||||
DESCRIPTION
|
DESCRIPTION
|
||||||
-----------
|
-----------
|
||||||
|
|
||||||
@@ -112,6 +118,8 @@
|
|||||||
should be contacted if that algorithm is to be used; their web page is
|
should be contacted if that algorithm is to be used; their web page is
|
||||||
http://www.ascom.ch/.
|
http://www.ascom.ch/.
|
||||||
|
|
||||||
|
The MDC2 algorithm is patented by IBM.
|
||||||
|
|
||||||
NTT and Mitsubishi have patents and pending patents on the Camellia
|
NTT and Mitsubishi have patents and pending patents on the Camellia
|
||||||
algorithm, but allow use at no charge without requiring an explicit
|
algorithm, but allow use at no charge without requiring an explicit
|
||||||
licensing agreement: http://info.isl.ntt.co.jp/crypt/eng/info/chiteki.html
|
licensing agreement: http://info.isl.ntt.co.jp/crypt/eng/info/chiteki.html
|
||||||
@@ -137,9 +145,6 @@
|
|||||||
SUPPORT
|
SUPPORT
|
||||||
-------
|
-------
|
||||||
|
|
||||||
See the OpenSSL website www.openssl.org for details of how to obtain
|
|
||||||
commercial technical support.
|
|
||||||
|
|
||||||
If you have any problems with OpenSSL then please take the following steps
|
If you have any problems with OpenSSL then please take the following steps
|
||||||
first:
|
first:
|
||||||
|
|
||||||
@@ -162,14 +167,10 @@
|
|||||||
- Stack Traceback (if the application dumps core)
|
- Stack Traceback (if the application dumps core)
|
||||||
|
|
||||||
Report the bug to the OpenSSL project via the Request Tracker
|
Report the bug to the OpenSSL project via the Request Tracker
|
||||||
(http://www.openssl.org/support/rt.html) by mail to:
|
(http://www.openssl.org/support/rt2.html) by mail to:
|
||||||
|
|
||||||
openssl-bugs@openssl.org
|
openssl-bugs@openssl.org
|
||||||
|
|
||||||
Note that the request tracker should NOT be used for general assistance
|
|
||||||
or support queries. Just because something doesn't work the way you expect
|
|
||||||
does not mean it is necessarily a bug in OpenSSL.
|
|
||||||
|
|
||||||
Note that mail to openssl-bugs@openssl.org is recorded in the publicly
|
Note that mail to openssl-bugs@openssl.org is recorded in the publicly
|
||||||
readable request tracker database and is forwarded to a public
|
readable request tracker database and is forwarded to a public
|
||||||
mailing list. Confidential mail may be sent to openssl-security@openssl.org
|
mailing list. Confidential mail may be sent to openssl-security@openssl.org
|
||||||
@@ -180,22 +181,10 @@
|
|||||||
|
|
||||||
Development is coordinated on the openssl-dev mailing list (see
|
Development is coordinated on the openssl-dev mailing list (see
|
||||||
http://www.openssl.org for information on subscribing). If you
|
http://www.openssl.org for information on subscribing). If you
|
||||||
would like to submit a patch, send it to openssl-bugs@openssl.org with
|
would like to submit a patch, send it to openssl-dev@openssl.org with
|
||||||
the string "[PATCH]" in the subject. Please be sure to include a
|
the string "[PATCH]" in the subject. Please be sure to include a
|
||||||
textual explanation of what your patch does.
|
textual explanation of what your patch does.
|
||||||
|
|
||||||
If you are unsure as to whether a feature will be useful for the general
|
|
||||||
OpenSSL community please discuss it on the openssl-dev mailing list first.
|
|
||||||
Someone may be already working on the same thing or there may be a good
|
|
||||||
reason as to why that feature isn't implemented.
|
|
||||||
|
|
||||||
Patches should be as up to date as possible, preferably relative to the
|
|
||||||
current Git or the last snapshot. They should follow the coding style of
|
|
||||||
OpenSSL and compile without warnings. Some of the core team developer targets
|
|
||||||
can be used for testing purposes, (debug-steve64, debug-geoff etc). OpenSSL
|
|
||||||
compiles on many varied platforms: try to ensure you only use portable
|
|
||||||
features.
|
|
||||||
|
|
||||||
Note: For legal reasons, contributions from the US can be accepted only
|
Note: For legal reasons, contributions from the US can be accepted only
|
||||||
if a TSU notification and a copy of the patch are sent to crypt@bis.doc.gov
|
if a TSU notification and a copy of the patch are sent to crypt@bis.doc.gov
|
||||||
(formerly BXA) with a copy to the ENC Encryption Request Coordinator;
|
(formerly BXA) with a copy to the ENC Encryption Request Coordinator;
|
||||||
|
|||||||
84
README.FIPS
Normal file
84
README.FIPS
Normal file
@@ -0,0 +1,84 @@
|
|||||||
|
Brief instructions on using OpenSSL 0.9.8 FIPS 140-2 test branch.
|
||||||
|
|
||||||
|
NOTE: this distribution is NOT FIPS140-2 validated. These instructions are
|
||||||
|
intended for people who wish to test the OpenSSL FIPS 140-2 1.2 module. More
|
||||||
|
complete instructions will be made available after validation.
|
||||||
|
|
||||||
|
1. Build from test tarball.
|
||||||
|
|
||||||
|
Download the OpenSSL test 1.2 source tree. The current version has the CVS tag
|
||||||
|
FIPS_098_TEST_8 or can be downloaded from:
|
||||||
|
|
||||||
|
ftp://ftp.openssl.org/snapshot/openssl-fips-test-1.2.0.tar.gz
|
||||||
|
|
||||||
|
Ignore any instructions in that tree: they are likely to be out of date.
|
||||||
|
|
||||||
|
If you are using a Unix like environment run the following commands. You may
|
||||||
|
NOT specify ANY other options at this stage.
|
||||||
|
|
||||||
|
./config fipscanisterbuild
|
||||||
|
make
|
||||||
|
make install
|
||||||
|
|
||||||
|
This will build and install the test 1.2 module and binaries under
|
||||||
|
/usr/local/fips-1.0
|
||||||
|
|
||||||
|
For Windows you need VC++, perl and NASM installed. This is now a pure VC++
|
||||||
|
build: no alternative compilers or tools are required. From a VC++ environment
|
||||||
|
do:
|
||||||
|
|
||||||
|
ms\do_fips
|
||||||
|
|
||||||
|
It should report that the compile was successful.
|
||||||
|
|
||||||
|
This will compile binaries into the out32dll directory. They can be copied to
|
||||||
|
a more convenient location.
|
||||||
|
|
||||||
|
2. Link test module to a more recent version of OpenSSL.
|
||||||
|
|
||||||
|
Once the test module has been installed it can be linked against a more recent
|
||||||
|
version of OpenSSL. Currently only versions from the 0.9.8-fips stable branch
|
||||||
|
can be used. It has the CVS tag OpenSSL-fips-0_9_8-stable daily snaphots can
|
||||||
|
also be downloaded as:
|
||||||
|
|
||||||
|
ftp://ftp.openssl.org/snapshot/openssl-0.9.8-fips-test-SNAP-YYMMDD.tar.gz
|
||||||
|
|
||||||
|
For a Unix build the standrd build procedure is followed and the option "fips"
|
||||||
|
is passed to either the config or Configure scripts. The fipscanisterbuild
|
||||||
|
option MUST NOT be used. Any other options may be included. Static libraries
|
||||||
|
can be built using the no-shared option.
|
||||||
|
|
||||||
|
For example:
|
||||||
|
|
||||||
|
./config fips
|
||||||
|
|
||||||
|
./config fips no-shared
|
||||||
|
|
||||||
|
For Windows builds the options "fips" and --with-fipslibdir=<path> are passed
|
||||||
|
to the Configure script where <path> is wherever the module was installed
|
||||||
|
For example:
|
||||||
|
|
||||||
|
perl Configure fips --with-fipslibdir=C:\some\path\fips
|
||||||
|
|
||||||
|
Then the build process continues in the normal way for example:
|
||||||
|
|
||||||
|
ms\do_nasm
|
||||||
|
nmake -f ms\ntdll.mak
|
||||||
|
|
||||||
|
for DLLs or
|
||||||
|
|
||||||
|
ms\do_nasm
|
||||||
|
nmake -f ms\nt.mak
|
||||||
|
|
||||||
|
for static builds.
|
||||||
|
|
||||||
|
3. Test new version of OpenSSL.
|
||||||
|
|
||||||
|
The new test FIPS enabled OpenSSL can now be tested in the usual way.
|
||||||
|
|
||||||
|
Additionally binary compatibility tests against OpenSSL 0.9.8x would be
|
||||||
|
MOST welcomed. This will help avoid any major issues when the 0.9.8-fips
|
||||||
|
branch is merged into 0.9.8 branch.
|
||||||
|
|
||||||
|
Any problems should be reported to the openssl-dev mailing list.
|
||||||
|
|
||||||
129
STATUS
Normal file
129
STATUS
Normal file
@@ -0,0 +1,129 @@
|
|||||||
|
|
||||||
|
OpenSSL STATUS Last modified at
|
||||||
|
______________ $Date: 2007/02/23 12:12:27 $
|
||||||
|
|
||||||
|
DEVELOPMENT STATE
|
||||||
|
|
||||||
|
o OpenSSL 0.9.9: Under development...
|
||||||
|
o OpenSSL 0.9.8e: Released on February 23rd, 2007
|
||||||
|
o OpenSSL 0.9.8d: Released on September 28th, 2006
|
||||||
|
o OpenSSL 0.9.8c: Released on September 5th, 2006
|
||||||
|
o OpenSSL 0.9.8b: Released on May 4th, 2006
|
||||||
|
o OpenSSL 0.9.8a: Released on October 11th, 2005
|
||||||
|
o OpenSSL 0.9.8: Released on July 5th, 2005
|
||||||
|
o OpenSSL 0.9.7m: Released on February 23rd, 2007
|
||||||
|
o OpenSSL 0.9.7l: Released on September 28th, 2006
|
||||||
|
o OpenSSL 0.9.7k: Released on September 5th, 2006
|
||||||
|
o OpenSSL 0.9.7j: Released on May 4th, 2006
|
||||||
|
o OpenSSL 0.9.7i: Released on October 14th, 2005
|
||||||
|
o OpenSSL 0.9.7h: Released on October 11th, 2005
|
||||||
|
o OpenSSL 0.9.7g: Released on April 11th, 2005
|
||||||
|
o OpenSSL 0.9.7f: Released on March 22nd, 2005
|
||||||
|
o OpenSSL 0.9.7e: Released on October 25th, 2004
|
||||||
|
o OpenSSL 0.9.7d: Released on March 17th, 2004
|
||||||
|
o OpenSSL 0.9.7c: Released on September 30th, 2003
|
||||||
|
o OpenSSL 0.9.7b: Released on April 10th, 2003
|
||||||
|
o OpenSSL 0.9.7a: Released on February 19th, 2003
|
||||||
|
o OpenSSL 0.9.7: Released on December 31st, 2002
|
||||||
|
o OpenSSL 0.9.6m: Released on March 17th, 2004
|
||||||
|
o OpenSSL 0.9.6l: Released on November 4th, 2003
|
||||||
|
o OpenSSL 0.9.6k: Released on September 30th, 2003
|
||||||
|
o OpenSSL 0.9.6j: Released on April 10th, 2003
|
||||||
|
o OpenSSL 0.9.6i: Released on February 19th, 2003
|
||||||
|
o OpenSSL 0.9.6h: Released on December 5th, 2002
|
||||||
|
o OpenSSL 0.9.6g: Released on August 9th, 2002
|
||||||
|
o OpenSSL 0.9.6f: Released on August 8th, 2002
|
||||||
|
o OpenSSL 0.9.6e: Released on July 30th, 2002
|
||||||
|
o OpenSSL 0.9.6d: Released on May 9th, 2002
|
||||||
|
o OpenSSL 0.9.6c: Released on December 21st, 2001
|
||||||
|
o OpenSSL 0.9.6b: Released on July 9th, 2001
|
||||||
|
o OpenSSL 0.9.6a: Released on April 5th, 2001
|
||||||
|
o OpenSSL 0.9.6: Released on September 24th, 2000
|
||||||
|
o OpenSSL 0.9.5a: Released on April 1st, 2000
|
||||||
|
o OpenSSL 0.9.5: Released on February 28th, 2000
|
||||||
|
o OpenSSL 0.9.4: Released on August 09th, 1999
|
||||||
|
o OpenSSL 0.9.3a: Released on May 29th, 1999
|
||||||
|
o OpenSSL 0.9.3: Released on May 25th, 1999
|
||||||
|
o OpenSSL 0.9.2b: Released on March 22th, 1999
|
||||||
|
o OpenSSL 0.9.1c: Released on December 23th, 1998
|
||||||
|
|
||||||
|
[See also http://www.openssl.org/support/rt2.html]
|
||||||
|
|
||||||
|
RELEASE SHOWSTOPPERS
|
||||||
|
|
||||||
|
o The Makefiles fail with some SysV makes.
|
||||||
|
o
|
||||||
|
|
||||||
|
AVAILABLE PATCHES
|
||||||
|
|
||||||
|
o
|
||||||
|
|
||||||
|
IN PROGRESS
|
||||||
|
|
||||||
|
o Steve is currently working on (in no particular order):
|
||||||
|
ASN1 code redesign, butchery, replacement.
|
||||||
|
OCSP
|
||||||
|
EVP cipher enhancement.
|
||||||
|
Enhanced certificate chain verification.
|
||||||
|
Private key, certificate and CRL API and implementation.
|
||||||
|
Developing and bugfixing PKCS#7 (S/MIME code).
|
||||||
|
Various X509 issues: character sets, certificate request extensions.
|
||||||
|
o Richard is currently working on:
|
||||||
|
Constification
|
||||||
|
Attribute Certificate support
|
||||||
|
Certificate Pair support
|
||||||
|
Storage Engines (primarly an LDAP storage engine)
|
||||||
|
Certificate chain validation with full RFC 3280 compatibility
|
||||||
|
|
||||||
|
NEEDS PATCH
|
||||||
|
|
||||||
|
o 0.9.8-dev: COMPLEMENTOFALL and COMPLEMENTOFDEFAULT do not
|
||||||
|
handle ECCdraft cipher suites correctly.
|
||||||
|
|
||||||
|
o apps/ca.c: "Sign the certificate?" - "n" creates empty certificate file
|
||||||
|
|
||||||
|
o "OpenSSL STATUS" is never up-to-date.
|
||||||
|
|
||||||
|
OPEN ISSUES
|
||||||
|
|
||||||
|
o The Makefile hierarchy and build mechanism is still not a round thing:
|
||||||
|
|
||||||
|
1. The config vs. Configure scripts
|
||||||
|
It's the same nasty situation as for Apache with APACI vs.
|
||||||
|
src/Configure. It confuses.
|
||||||
|
Suggestion: Merge Configure and config into a single configure
|
||||||
|
script with a Autoconf style interface ;-) and remove
|
||||||
|
Configure and config. Or even let us use GNU Autoconf
|
||||||
|
itself. Then we can avoid a lot of those platform checks
|
||||||
|
which are currently in Configure.
|
||||||
|
|
||||||
|
o Support for Shared Libraries has to be added at least
|
||||||
|
for the major Unix platforms. The details we can rip from the stuff
|
||||||
|
Ralf has done for the Apache src/Configure script. Ben wants the
|
||||||
|
solution to be really simple.
|
||||||
|
|
||||||
|
Status: Ralf will look how we can easily incorporate the
|
||||||
|
compiler PIC and linker DSO flags from Apache
|
||||||
|
into the OpenSSL Configure script.
|
||||||
|
|
||||||
|
Ulf: +1 for using GNU autoconf and libtool (but not automake,
|
||||||
|
which apparently is not flexible enough to generate
|
||||||
|
libcrypto)
|
||||||
|
|
||||||
|
WISHES
|
||||||
|
|
||||||
|
o Add variants of DH_generate_parameters() and BN_generate_prime() [etc?]
|
||||||
|
where the callback function can request that the function be aborted.
|
||||||
|
[Gregory Stark <ghstark@pobox.com>, <rayyang2000@yahoo.com>]
|
||||||
|
|
||||||
|
o SRP in TLS.
|
||||||
|
[wished by:
|
||||||
|
Dj <derek@yo.net>, Tom Wu <tom@arcot.com>,
|
||||||
|
Tom Holroyd <tomh@po.crl.go.jp>]
|
||||||
|
|
||||||
|
See http://search.ietf.org/internet-drafts/draft-ietf-tls-srp-00.txt
|
||||||
|
as well as http://www-cs-students.stanford.edu/~tjw/srp/.
|
||||||
|
|
||||||
|
Tom Holroyd tells us there is a SRP patch for OpenSSH at
|
||||||
|
http://members.tripod.com/professor_tom/archives/, that could
|
||||||
|
be useful.
|
||||||
@@ -12,14 +12,6 @@ $ WRITE SYS$OUTPUT "Should be the directory where you want things installed.
|
|||||||
$ EXIT
|
$ EXIT
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$
|
$
|
||||||
$ IF (F$GETSYI("CPU").LT.128)
|
|
||||||
$ THEN
|
|
||||||
$ ARCH := VAX
|
|
||||||
$ ELSE
|
|
||||||
$ ARCH = F$EDIT( F$GETSYI( "ARCH_NAME"), "UPCASE")
|
|
||||||
$ IF (ARCH .EQS. "") THEN ARCH = "UNK"
|
|
||||||
$ ENDIF
|
|
||||||
$
|
|
||||||
$ ROOT = F$PARSE(P1,"[]A.;0",,,"SYNTAX_ONLY,NO_CONCEAL") - "A.;0"
|
$ ROOT = F$PARSE(P1,"[]A.;0",,,"SYNTAX_ONLY,NO_CONCEAL") - "A.;0"
|
||||||
$ ROOT_DEV = F$PARSE(ROOT,,,"DEVICE","SYNTAX_ONLY")
|
$ ROOT_DEV = F$PARSE(ROOT,,,"DEVICE","SYNTAX_ONLY")
|
||||||
$ ROOT_DIR = F$PARSE(ROOT,,,"DIRECTORY","SYNTAX_ONLY") -
|
$ ROOT_DIR = F$PARSE(ROOT,,,"DIRECTORY","SYNTAX_ONLY") -
|
||||||
@@ -27,7 +19,13 @@ $ ROOT_DIR = F$PARSE(ROOT,,,"DIRECTORY","SYNTAX_ONLY") -
|
|||||||
$ ROOT = ROOT_DEV + "[" + ROOT_DIR
|
$ ROOT = ROOT_DEV + "[" + ROOT_DIR
|
||||||
$
|
$
|
||||||
$ DEFINE/NOLOG WRK_SSLROOT 'ROOT'.] /TRANS=CONC
|
$ DEFINE/NOLOG WRK_SSLROOT 'ROOT'.] /TRANS=CONC
|
||||||
|
$ DEFINE/NOLOG WRK_SSLVLIB WRK_SSLROOT:[VAX_LIB]
|
||||||
|
$ DEFINE/NOLOG WRK_SSLALIB WRK_SSLROOT:[ALPHA_LIB]
|
||||||
$ DEFINE/NOLOG WRK_SSLINCLUDE WRK_SSLROOT:[INCLUDE]
|
$ DEFINE/NOLOG WRK_SSLINCLUDE WRK_SSLROOT:[INCLUDE]
|
||||||
|
$ DEFINE/NOLOG WRK_SSLVEXE WRK_SSLROOT:[VAX_EXE]
|
||||||
|
$ DEFINE/NOLOG WRK_SSLAEXE WRK_SSLROOT:[ALPHA_EXE]
|
||||||
|
$ DEFINE/NOLOG WRK_SSLCERTS WRK_SSLROOT:[CERTS]
|
||||||
|
$ DEFINE/NOLOG WRK_SSLPRIVATE WRK_SSLROOT:[PRIVATE]
|
||||||
$
|
$
|
||||||
$ IF F$PARSE("WRK_SSLROOT:[000000]") .EQS. "" THEN -
|
$ IF F$PARSE("WRK_SSLROOT:[000000]") .EQS. "" THEN -
|
||||||
CREATE/DIR/LOG WRK_SSLROOT:[000000]
|
CREATE/DIR/LOG WRK_SSLROOT:[000000]
|
||||||
@@ -41,7 +39,7 @@ $ IF F$SEARCH("WRK_SSLINCLUDE:vms_idhacks.h") .NES. "" THEN -
|
|||||||
$
|
$
|
||||||
$ OPEN/WRITE SF WRK_SSLROOT:[VMS]OPENSSL_STARTUP.COM
|
$ OPEN/WRITE SF WRK_SSLROOT:[VMS]OPENSSL_STARTUP.COM
|
||||||
$ WRITE SYS$OUTPUT "%OPEN-I-CREATED, ",F$SEARCH("WRK_SSLROOT:[VMS]OPENSSL_STARTUP.COM")," created."
|
$ WRITE SYS$OUTPUT "%OPEN-I-CREATED, ",F$SEARCH("WRK_SSLROOT:[VMS]OPENSSL_STARTUP.COM")," created."
|
||||||
$ WRITE SF "$! Startup file for Openssl"
|
$ WRITE SF "$! Startup file for Openssl 0.9.2-RL 15-Mar-1999"
|
||||||
$ WRITE SF "$!"
|
$ WRITE SF "$!"
|
||||||
$ WRITE SF "$! Do not edit this file, as it will be regenerated during next installation."
|
$ WRITE SF "$! Do not edit this file, as it will be regenerated during next installation."
|
||||||
$ WRITE SF "$! Instead, add or change SSLROOT:[VMS]OPENSSL_SYSTARTUP.COM"
|
$ WRITE SF "$! Instead, add or change SSLROOT:[VMS]OPENSSL_SYSTARTUP.COM"
|
||||||
@@ -49,13 +47,8 @@ $ WRITE SF "$!"
|
|||||||
$ WRITE SF "$! P1 a qualifier to DEFINE. For example ""/SYSTEM"" to get the logical names"
|
$ WRITE SF "$! P1 a qualifier to DEFINE. For example ""/SYSTEM"" to get the logical names"
|
||||||
$ WRITE SF "$! defined in the system logical name table."
|
$ WRITE SF "$! defined in the system logical name table."
|
||||||
$ WRITE SF "$!"
|
$ WRITE SF "$!"
|
||||||
$ WRITE SF "$ IF (F$GETSYI(""CPU"").LT.128)"
|
$ WRITE SF "$ ARCH = ""VAX"""
|
||||||
$ WRITE SF "$ THEN"
|
$ WRITE SF "$ IF F$GETSYI(""CPU"") .GE. 128 THEN ARCH = ""ALPHA"""
|
||||||
$ WRITE SF "$ ARCH := VAX"
|
|
||||||
$ WRITE SF "$ ELSE"
|
|
||||||
$ WRITE SF "$ ARCH = F$EDIT( F$GETSYI( ""ARCH_NAME""), ""UPCASE"")"
|
|
||||||
$ WRITE SF "$ IF (ARCH .EQS. """") THEN ARCH = ""UNK"""
|
|
||||||
$ WRITE SF "$ ENDIF"
|
|
||||||
$ WRITE SF "$ DEFINE/NOLOG'P1 SSLROOT ",ROOT,".] /TRANS=CONC"
|
$ WRITE SF "$ DEFINE/NOLOG'P1 SSLROOT ",ROOT,".] /TRANS=CONC"
|
||||||
$ WRITE SF "$ DEFINE/NOLOG'P1 SSLLIB SSLROOT:['ARCH'_LIB]"
|
$ WRITE SF "$ DEFINE/NOLOG'P1 SSLLIB SSLROOT:['ARCH'_LIB]"
|
||||||
$ WRITE SF "$ DEFINE/NOLOG'P1 SSLINCLUDE SSLROOT:[INCLUDE]"
|
$ WRITE SF "$ DEFINE/NOLOG'P1 SSLINCLUDE SSLROOT:[INCLUDE]"
|
||||||
|
|||||||
@@ -3,10 +3,10 @@ $!
|
|||||||
$! No command line parameters. This should be run at the start of the source
|
$! No command line parameters. This should be run at the start of the source
|
||||||
$! tree (the same directory where one finds INSTALL.VMS).
|
$! tree (the same directory where one finds INSTALL.VMS).
|
||||||
$!
|
$!
|
||||||
$! Input: [.UTIL]LIBEAY.NUM,[.xxx.EXE.CRYPTO]LIBCRYPTO.OLB
|
$! Input: [.UTIL]LIBEAY.NUM,[.AXP.EXE.CRYPTO]LIBCRYPTO.OLB
|
||||||
$! [.UTIL]SSLEAY.NUM,[.xxx.EXE.SSL]LIBSSL.OLB
|
$! [.UTIL]SSLEAY.NUM,[.AXP.EXE.SSL]LIBSSL.OLB
|
||||||
$! Output: [.xxx.EXE.CRYPTO]LIBCRYPTO.OPT,.MAP,.EXE
|
$! Output: [.AXP.EXE.CRYPTO]LIBCRYPTO.OPT,.MAP,.EXE
|
||||||
$! [.xxx.EXE.SSL]LIBSSL.OPT,.MAP,.EXE
|
$! [.AXP.EXE.SSL]LIBSSL.OPT,.MAP,.EXE
|
||||||
$!
|
$!
|
||||||
$! So far, tests have only been made on VMS for Alpha. VAX will come in time.
|
$! So far, tests have only been made on VMS for Alpha. VAX will come in time.
|
||||||
$! ===========================================================================
|
$! ===========================================================================
|
||||||
@@ -19,41 +19,31 @@ $ write sys$error "ERROR: Couldn't find any library version info..."
|
|||||||
$ exit
|
$ exit
|
||||||
$ endif
|
$ endif
|
||||||
$
|
$
|
||||||
$ if (f$getsyi("cpu").lt.128)
|
$ if f$getsyi("CPU") .ge. 128
|
||||||
$ then
|
$ then
|
||||||
$ arch := VAX
|
|
||||||
$ else
|
|
||||||
$ arch = f$edit( f$getsyi( "ARCH_NAME"), "UPCASE")
|
|
||||||
$ if (arch .eqs. "") then arch = "UNK"
|
|
||||||
$ endif
|
|
||||||
$
|
|
||||||
$ if arch .nes. "VAX"
|
|
||||||
$ then
|
|
||||||
$ arch_vax = 0
|
|
||||||
$ libid = "Crypto"
|
$ libid = "Crypto"
|
||||||
$ libnum = "[.UTIL]LIBEAY.NUM"
|
$ libnum = "[.UTIL]LIBEAY.NUM"
|
||||||
$ libdir = "[.''ARCH'.EXE.CRYPTO]"
|
$ libdir = "[.AXP.EXE.CRYPTO]"
|
||||||
$ libolb = "''libdir'LIBCRYPTO.OLB"
|
$ libolb = "''libdir'LIBCRYPTO.OLB"
|
||||||
$ libopt = "''libdir'LIBCRYPTO.OPT"
|
$ libopt = "''libdir'LIBCRYPTO.OPT"
|
||||||
$ libmap = "''libdir'LIBCRYPTO.MAP"
|
$ libmap = "''libdir'LIBCRYPTO.MAP"
|
||||||
$ libgoal= "''libdir'LIBCRYPTO.EXE"
|
$ libgoal= "''libdir'LIBCRYPTO.EXE"
|
||||||
$ libref = ""
|
$ libref = ""
|
||||||
$ gosub create_nonvax_shr
|
$ gosub create_axp_shr
|
||||||
$ libid = "SSL"
|
$ libid = "SSL"
|
||||||
$ libnum = "[.UTIL]SSLEAY.NUM"
|
$ libnum = "[.UTIL]SSLEAY.NUM"
|
||||||
$ libdir = "[.''ARCH'.EXE.SSL]"
|
$ libdir = "[.AXP.EXE.SSL]"
|
||||||
$ libolb = "''libdir'LIBSSL.OLB"
|
$ libolb = "''libdir'LIBSSL.OLB"
|
||||||
$ libopt = "''libdir'LIBSSL.OPT"
|
$ libopt = "''libdir'LIBSSL.OPT"
|
||||||
$ libmap = "''libdir'LIBSSL.MAP"
|
$ libmap = "''libdir'LIBSSL.MAP"
|
||||||
$ libgoal= "''libdir'LIBSSL.EXE"
|
$ libgoal= "''libdir'LIBSSL.EXE"
|
||||||
$ libref = "[.''ARCH'.EXE.CRYPTO]LIBCRYPTO.EXE"
|
$ libref = "[.AXP.EXE.CRYPTO]LIBCRYPTO.EXE"
|
||||||
$ gosub create_nonvax_shr
|
$ gosub create_axp_shr
|
||||||
$ else
|
$ else
|
||||||
$ arch_vax = 1
|
|
||||||
$ libtit = "CRYPTO_TRANSFER_VECTOR"
|
$ libtit = "CRYPTO_TRANSFER_VECTOR"
|
||||||
$ libid = "Crypto"
|
$ libid = "Crypto"
|
||||||
$ libnum = "[.UTIL]LIBEAY.NUM"
|
$ libnum = "[.UTIL]LIBEAY.NUM"
|
||||||
$ libdir = "[.''ARCH'.EXE.CRYPTO]"
|
$ libdir = "[.VAX.EXE.CRYPTO]"
|
||||||
$ libmar = "''libdir'LIBCRYPTO.MAR"
|
$ libmar = "''libdir'LIBCRYPTO.MAR"
|
||||||
$ libolb = "''libdir'LIBCRYPTO.OLB"
|
$ libolb = "''libdir'LIBCRYPTO.OLB"
|
||||||
$ libopt = "''libdir'LIBCRYPTO.OPT"
|
$ libopt = "''libdir'LIBCRYPTO.OPT"
|
||||||
@@ -66,22 +56,22 @@ $ gosub create_vax_shr
|
|||||||
$ libtit = "SSL_TRANSFER_VECTOR"
|
$ libtit = "SSL_TRANSFER_VECTOR"
|
||||||
$ libid = "SSL"
|
$ libid = "SSL"
|
||||||
$ libnum = "[.UTIL]SSLEAY.NUM"
|
$ libnum = "[.UTIL]SSLEAY.NUM"
|
||||||
$ libdir = "[.''ARCH'.EXE.SSL]"
|
$ libdir = "[.VAX.EXE.SSL]"
|
||||||
$ libmar = "''libdir'LIBSSL.MAR"
|
$ libmar = "''libdir'LIBSSL.MAR"
|
||||||
$ libolb = "''libdir'LIBSSL.OLB"
|
$ libolb = "''libdir'LIBSSL.OLB"
|
||||||
$ libopt = "''libdir'LIBSSL.OPT"
|
$ libopt = "''libdir'LIBSSL.OPT"
|
||||||
$ libobj = "''libdir'LIBSSL.OBJ"
|
$ libobj = "''libdir'LIBSSL.OBJ"
|
||||||
$ libmap = "''libdir'LIBSSL.MAP"
|
$ libmap = "''libdir'LIBSSL.MAP"
|
||||||
$ libgoal= "''libdir'LIBSSL.EXE"
|
$ libgoal= "''libdir'LIBSSL.EXE"
|
||||||
$ libref = "[.''ARCH'.EXE.CRYPTO]LIBCRYPTO.EXE"
|
$ libref = "[.VAX.EXE.CRYPTO]LIBCRYPTO.EXE"
|
||||||
$ libvec = "LIBSSL"
|
$ libvec = "LIBSSL"
|
||||||
$ gosub create_vax_shr
|
$ gosub create_vax_shr
|
||||||
$ endif
|
$ endif
|
||||||
$ exit
|
$ exit
|
||||||
$
|
$
|
||||||
$! ----- Soubroutines to build the shareable libraries
|
$! ----- Soubroutines to actually build the shareable libraries
|
||||||
$! For each supported architecture, there's a main shareable library
|
$! The way things work, there's a main shareable library creator for each
|
||||||
$! creator, which is called from the main code above.
|
$! supported architecture, which is called from the main code above.
|
||||||
$! The creator will define a number of variables to tell the next levels of
|
$! The creator will define a number of variables to tell the next levels of
|
||||||
$! subroutines what routines to use to write to the option files, call the
|
$! subroutines what routines to use to write to the option files, call the
|
||||||
$! main processor, read_func_num, and when that is done, it will write version
|
$! main processor, read_func_num, and when that is done, it will write version
|
||||||
@@ -107,10 +97,10 @@ $! read_func_num depends on the following variables from the creator:
|
|||||||
$! libwriter The name of the writer routine to call for each .num file line
|
$! libwriter The name of the writer routine to call for each .num file line
|
||||||
$! -----
|
$! -----
|
||||||
$
|
$
|
||||||
$! ----- Subroutines for non-VAX
|
$! ----- Subroutines for AXP
|
||||||
$! -----
|
$! -----
|
||||||
$! The creator routine
|
$! The creator routine
|
||||||
$ create_nonvax_shr:
|
$ create_axp_shr:
|
||||||
$ open/write opt 'libopt'
|
$ open/write opt 'libopt'
|
||||||
$ write opt "identification=""",libid," ",libverstr,""""
|
$ write opt "identification=""",libid," ",libverstr,""""
|
||||||
$ write opt libolb,"/lib"
|
$ write opt libolb,"/lib"
|
||||||
@@ -118,7 +108,7 @@ $ if libref .nes. "" then write opt libref,"/SHARE"
|
|||||||
$ write opt "SYMBOL_VECTOR=(-"
|
$ write opt "SYMBOL_VECTOR=(-"
|
||||||
$ libfirstentry := true
|
$ libfirstentry := true
|
||||||
$ libwrch := opt
|
$ libwrch := opt
|
||||||
$ libwriter := write_nonvax_transfer_entry
|
$ libwriter := write_axp_transfer_entry
|
||||||
$ textcount = 0
|
$ textcount = 0
|
||||||
$ gosub read_func_num
|
$ gosub read_func_num
|
||||||
$ write opt ")"
|
$ write opt ")"
|
||||||
@@ -128,7 +118,7 @@ $ link/map='libmap'/full/share='libgoal' 'libopt'/option
|
|||||||
$ return
|
$ return
|
||||||
$
|
$
|
||||||
$! The record writer routine
|
$! The record writer routine
|
||||||
$ write_nonvax_transfer_entry:
|
$ write_axp_transfer_entry:
|
||||||
$ if libentry .eqs. ".dummy" then return
|
$ if libentry .eqs. ".dummy" then return
|
||||||
$ if info_kind .eqs. "VARIABLE"
|
$ if info_kind .eqs. "VARIABLE"
|
||||||
$ then
|
$ then
|
||||||
@@ -154,7 +144,7 @@ $ libfirstentry := false
|
|||||||
$ textcount = textcount + textcount_this
|
$ textcount = textcount + textcount_this
|
||||||
$ return
|
$ return
|
||||||
$
|
$
|
||||||
$! ----- Subroutines for VAX
|
$! ----- Subroutines for AXP
|
||||||
$! -----
|
$! -----
|
||||||
$! The creator routine
|
$! The creator routine
|
||||||
$ create_vax_shr:
|
$ create_vax_shr:
|
||||||
@@ -274,15 +264,8 @@ $ truesum = truesum + 1
|
|||||||
$ if plat_entry .eqs. "!EXPORT_VAR_AS_FUNCTION" then -
|
$ if plat_entry .eqs. "!EXPORT_VAR_AS_FUNCTION" then -
|
||||||
$ falsesum = falsesum + 1
|
$ falsesum = falsesum + 1
|
||||||
$ endif
|
$ endif
|
||||||
$!
|
$ if plat_entry .eqs. "VMS" then truesum = truesum + 1
|
||||||
$ if ((plat_entry .eqs. "VMS") .or. -
|
$ if plat_entry .eqs. "!VMS" then falsesum = falsesum + 1
|
||||||
(arch_vax .and. (plat_entry .eqs. "VMSVAX"))) then -
|
|
||||||
truesum = truesum + 1
|
|
||||||
$!
|
|
||||||
$ if ((plat_entry .eqs. "!VMS") .or. -
|
|
||||||
(arch_vax .and. (plat_entry .eqs. "!VMSVAX"))) then -
|
|
||||||
falsesum = falsesum + 1
|
|
||||||
$!
|
|
||||||
$ goto loop1
|
$ goto loop1
|
||||||
$ endif
|
$ endif
|
||||||
$ endloop1:
|
$ endloop1:
|
||||||
|
|||||||
@@ -8,17 +8,10 @@ $!
|
|||||||
$!
|
$!
|
||||||
$! Slightly modified by Richard Levitte <richard@levitte.org>
|
$! Slightly modified by Richard Levitte <richard@levitte.org>
|
||||||
$!
|
$!
|
||||||
$!
|
|
||||||
$! Always define OPENSSL. Others are optional (non-null P1).
|
|
||||||
$!
|
|
||||||
$ OPENSSL :== $SSLEXE:OPENSSL
|
$ OPENSSL :== $SSLEXE:OPENSSL
|
||||||
$
|
|
||||||
$ IF (P1 .NES. "")
|
|
||||||
$ THEN
|
|
||||||
$ VERIFY :== $SSLEXE:OPENSSL VERIFY
|
$ VERIFY :== $SSLEXE:OPENSSL VERIFY
|
||||||
$ ASN1PARSE:== $SSLEXE:OPENSSL ASN1PARS
|
$ ASN1PARSE:== $SSLEXE:OPENSSL ASN1PARS
|
||||||
$! REQ could conflict with REQUEST.
|
$ REQ :== $SSLEXE:OPENSSL REQ
|
||||||
$ OREQ :== $SSLEXE:OPENSSL REQ
|
|
||||||
$ DGST :== $SSLEXE:OPENSSL DGST
|
$ DGST :== $SSLEXE:OPENSSL DGST
|
||||||
$ DH :== $SSLEXE:OPENSSL DH
|
$ DH :== $SSLEXE:OPENSSL DH
|
||||||
$ ENC :== $SSLEXE:OPENSSL ENC
|
$ ENC :== $SSLEXE:OPENSSL ENC
|
||||||
@@ -43,4 +36,3 @@ $ SESS_ID :== $SSLEXE:OPENSSL SESS_ID
|
|||||||
$ CIPHERS :== $SSLEXE:OPENSSL CIPHERS
|
$ CIPHERS :== $SSLEXE:OPENSSL CIPHERS
|
||||||
$ NSEQ :== $SSLEXE:OPENSSL NSEQ
|
$ NSEQ :== $SSLEXE:OPENSSL NSEQ
|
||||||
$ PKCS12 :== $SSLEXE:OPENSSL PKCS12
|
$ PKCS12 :== $SSLEXE:OPENSSL PKCS12
|
||||||
$ ENDIF
|
|
||||||
|
|||||||
@@ -114,8 +114,8 @@ $!
|
|||||||
$ IF F$SEARCH(CATOP+".private"+CAKEY) .EQS. ""
|
$ IF F$SEARCH(CATOP+".private"+CAKEY) .EQS. ""
|
||||||
$ THEN
|
$ THEN
|
||||||
$ READ '__INPUT' FILE -
|
$ READ '__INPUT' FILE -
|
||||||
/PROMPT="CA certificate filename (or enter to create): "
|
/PROMT="CA certificate filename (or enter to create)"
|
||||||
$ IF (FILE .NES. "") .AND. (F$SEARCH(FILE) .NES. "")
|
$ IF F$SEARCH(FILE) .NES. ""
|
||||||
$ THEN
|
$ THEN
|
||||||
$ COPY 'FILE' 'CATOP'.private'CAKEY'
|
$ COPY 'FILE' 'CATOP'.private'CAKEY'
|
||||||
$ RET=$STATUS
|
$ RET=$STATUS
|
||||||
|
|||||||
93
apps/CA.sh
93
apps/CA.sh
@@ -29,56 +29,26 @@
|
|||||||
|
|
||||||
# default openssl.cnf file has setup as per the following
|
# default openssl.cnf file has setup as per the following
|
||||||
# demoCA ... where everything is stored
|
# demoCA ... where everything is stored
|
||||||
cp_pem() {
|
|
||||||
infile=$1
|
|
||||||
outfile=$2
|
|
||||||
bound=$3
|
|
||||||
flag=0
|
|
||||||
exec <$infile;
|
|
||||||
while read line; do
|
|
||||||
if [ $flag -eq 1 ]; then
|
|
||||||
echo $line|grep "^-----END.*$bound" 2>/dev/null 1>/dev/null
|
|
||||||
if [ $? -eq 0 ] ; then
|
|
||||||
echo $line >>$outfile
|
|
||||||
break
|
|
||||||
else
|
|
||||||
echo $line >>$outfile
|
|
||||||
fi
|
|
||||||
fi
|
|
||||||
|
|
||||||
echo $line|grep "^-----BEGIN.*$bound" 2>/dev/null 1>/dev/null
|
|
||||||
if [ $? -eq 0 ]; then
|
|
||||||
echo $line >$outfile
|
|
||||||
flag=1
|
|
||||||
fi
|
|
||||||
done
|
|
||||||
}
|
|
||||||
|
|
||||||
usage() {
|
|
||||||
echo "usage: $0 -newcert|-newreq|-newreq-nodes|-newca|-sign|-verify" >&2
|
|
||||||
}
|
|
||||||
|
|
||||||
if [ -z "$OPENSSL" ]; then OPENSSL=openssl; fi
|
if [ -z "$OPENSSL" ]; then OPENSSL=openssl; fi
|
||||||
|
|
||||||
if [ -z "$DAYS" ] ; then DAYS="-days 365" ; fi # 1 year
|
DAYS="-days 365" # 1 year
|
||||||
CADAYS="-days 1095" # 3 years
|
CADAYS="-days 1095" # 3 years
|
||||||
REQ="$OPENSSL req $SSLEAY_CONFIG"
|
REQ="$OPENSSL req $SSLEAY_CONFIG"
|
||||||
CA="$OPENSSL ca $SSLEAY_CONFIG"
|
CA="$OPENSSL ca $SSLEAY_CONFIG"
|
||||||
VERIFY="$OPENSSL verify"
|
VERIFY="$OPENSSL verify"
|
||||||
X509="$OPENSSL x509"
|
X509="$OPENSSL x509"
|
||||||
PKCS12="openssl pkcs12"
|
|
||||||
|
|
||||||
if [ -z "$CATOP" ] ; then CATOP=./demoCA ; fi
|
CATOP=./demoCA
|
||||||
CAKEY=./cakey.pem
|
CAKEY=./cakey.pem
|
||||||
CAREQ=./careq.pem
|
CAREQ=./careq.pem
|
||||||
CACERT=./cacert.pem
|
CACERT=./cacert.pem
|
||||||
|
|
||||||
RET=0
|
for i
|
||||||
|
do
|
||||||
while [ "$1" != "" ] ; do
|
case $i in
|
||||||
case $1 in
|
|
||||||
-\?|-h|-help)
|
-\?|-h|-help)
|
||||||
usage
|
echo "usage: CA -newcert|-newreq|-newca|-sign|-verify" >&2
|
||||||
exit 0
|
exit 0
|
||||||
;;
|
;;
|
||||||
-newcert)
|
-newcert)
|
||||||
@@ -93,23 +63,18 @@ case $1 in
|
|||||||
RET=$?
|
RET=$?
|
||||||
echo "Request is in newreq.pem, private key is in newkey.pem"
|
echo "Request is in newreq.pem, private key is in newkey.pem"
|
||||||
;;
|
;;
|
||||||
-newreq-nodes)
|
|
||||||
# create a certificate request
|
|
||||||
$REQ -new -nodes -keyout newreq.pem -out newreq.pem $DAYS
|
|
||||||
RET=$?
|
|
||||||
echo "Request (and private key) is in newreq.pem"
|
|
||||||
;;
|
|
||||||
-newca)
|
-newca)
|
||||||
# if explicitly asked for or it doesn't exist then setup the directory
|
# if explicitly asked for or it doesn't exist then setup the directory
|
||||||
# structure that Eric likes to manage things
|
# structure that Eric likes to manage things
|
||||||
NEW="1"
|
NEW="1"
|
||||||
if [ "$NEW" -o ! -f ${CATOP}/serial ]; then
|
if [ "$NEW" -o ! -f ${CATOP}/serial ]; then
|
||||||
# create the directory hierarchy
|
# create the directory hierarchy
|
||||||
mkdir -p ${CATOP}
|
mkdir ${CATOP}
|
||||||
mkdir -p ${CATOP}/certs
|
mkdir ${CATOP}/certs
|
||||||
mkdir -p ${CATOP}/crl
|
mkdir ${CATOP}/crl
|
||||||
mkdir -p ${CATOP}/newcerts
|
mkdir ${CATOP}/newcerts
|
||||||
mkdir -p ${CATOP}/private
|
mkdir ${CATOP}/private
|
||||||
|
echo "00" > ${CATOP}/serial
|
||||||
touch ${CATOP}/index.txt
|
touch ${CATOP}/index.txt
|
||||||
fi
|
fi
|
||||||
if [ ! -f ${CATOP}/private/$CAKEY ]; then
|
if [ ! -f ${CATOP}/private/$CAKEY ]; then
|
||||||
@@ -118,20 +83,14 @@ case $1 in
|
|||||||
|
|
||||||
# ask user for existing CA certificate
|
# ask user for existing CA certificate
|
||||||
if [ "$FILE" ]; then
|
if [ "$FILE" ]; then
|
||||||
cp_pem $FILE ${CATOP}/private/$CAKEY PRIVATE
|
cp $FILE ${CATOP}/private/$CAKEY
|
||||||
cp_pem $FILE ${CATOP}/$CACERT CERTIFICATE
|
|
||||||
RET=$?
|
RET=$?
|
||||||
if [ ! -f "${CATOP}/serial" ]; then
|
|
||||||
$X509 -in ${CATOP}/$CACERT -noout -next_serial \
|
|
||||||
-out ${CATOP}/serial
|
|
||||||
fi
|
|
||||||
else
|
else
|
||||||
echo "Making CA certificate ..."
|
echo "Making CA certificate ..."
|
||||||
$REQ -new -keyout ${CATOP}/private/$CAKEY \
|
$REQ -new -keyout ${CATOP}/private/$CAKEY \
|
||||||
-out ${CATOP}/$CAREQ
|
-out ${CATOP}/$CAREQ
|
||||||
$CA -create_serial -out ${CATOP}/$CACERT $CADAYS -batch \
|
$CA -out ${CATOP}/$CACERT $CADAYS -batch \
|
||||||
-keyfile ${CATOP}/private/$CAKEY -selfsign \
|
-keyfile ${CATOP}/private/$CAKEY -selfsign \
|
||||||
-extensions v3_ca \
|
|
||||||
-infiles ${CATOP}/$CAREQ
|
-infiles ${CATOP}/$CAREQ
|
||||||
RET=$?
|
RET=$?
|
||||||
fi
|
fi
|
||||||
@@ -141,33 +100,16 @@ case $1 in
|
|||||||
$CA -policy policy_anything -infiles newreq.pem
|
$CA -policy policy_anything -infiles newreq.pem
|
||||||
RET=$?
|
RET=$?
|
||||||
;;
|
;;
|
||||||
-pkcs12)
|
|
||||||
if [ -z "$2" ] ; then
|
|
||||||
CNAME="My Certificate"
|
|
||||||
else
|
|
||||||
CNAME="$2"
|
|
||||||
fi
|
|
||||||
$PKCS12 -in newcert.pem -inkey newreq.pem -certfile ${CATOP}/$CACERT \
|
|
||||||
-out newcert.p12 -export -name "$CNAME"
|
|
||||||
RET=$?
|
|
||||||
exit $RET
|
|
||||||
;;
|
|
||||||
-sign|-signreq)
|
-sign|-signreq)
|
||||||
$CA -policy policy_anything -out newcert.pem -infiles newreq.pem
|
$CA -policy policy_anything -out newcert.pem -infiles newreq.pem
|
||||||
RET=$?
|
RET=$?
|
||||||
cat newcert.pem
|
cat newcert.pem
|
||||||
echo "Signed certificate is in newcert.pem"
|
echo "Signed certificate is in newcert.pem"
|
||||||
;;
|
;;
|
||||||
-signCA)
|
|
||||||
$CA -policy policy_anything -out newcert.pem -extensions v3_ca -infiles newreq.pem
|
|
||||||
RET=$?
|
|
||||||
echo "Signed CA certificate is in newcert.pem"
|
|
||||||
;;
|
|
||||||
-signcert)
|
-signcert)
|
||||||
echo "Cert passphrase will be requested twice - bug?"
|
echo "Cert passphrase will be requested twice - bug?"
|
||||||
$X509 -x509toreq -in newreq.pem -signkey newreq.pem -out tmp.pem
|
$X509 -x509toreq -in newreq.pem -signkey newreq.pem -out tmp.pem
|
||||||
$CA -policy policy_anything -out newcert.pem -infiles tmp.pem
|
$CA -policy policy_anything -out newcert.pem -infiles tmp.pem
|
||||||
RET=$?
|
|
||||||
cat newcert.pem
|
cat newcert.pem
|
||||||
echo "Signed certificate is in newcert.pem"
|
echo "Signed certificate is in newcert.pem"
|
||||||
;;
|
;;
|
||||||
@@ -185,14 +127,13 @@ case $1 in
|
|||||||
fi
|
fi
|
||||||
done
|
done
|
||||||
fi
|
fi
|
||||||
exit $RET
|
exit 0
|
||||||
;;
|
;;
|
||||||
*)
|
*)
|
||||||
echo "Unknown arg $i" >&2
|
echo "Unknown arg $i";
|
||||||
usage
|
|
||||||
exit 1
|
exit 1
|
||||||
;;
|
;;
|
||||||
esac
|
esac
|
||||||
shift
|
|
||||||
done
|
done
|
||||||
exit $RET
|
exit $RET
|
||||||
|
|
||||||
|
|||||||
681
apps/Makefile
681
apps/Makefile
@@ -153,19 +153,17 @@ $(EXE): progs.h $(E_OBJ) $(PROGRAM).o $(DLIBCRYPTO) $(DLIBSSL)
|
|||||||
shlib_target=; if [ -n "$(SHARED_LIBS)" ]; then \
|
shlib_target=; if [ -n "$(SHARED_LIBS)" ]; then \
|
||||||
shlib_target="$(SHLIB_TARGET)"; \
|
shlib_target="$(SHLIB_TARGET)"; \
|
||||||
elif [ -n "$(FIPSCANLIB)" ]; then \
|
elif [ -n "$(FIPSCANLIB)" ]; then \
|
||||||
FIPSLD_CC="$(CC)"; CC=$(TOP)/fips/fipsld; export CC FIPSLD_CC; \
|
FIPSLD_CC=$(CC); CC=$(TOP)/fips/fipsld; export CC FIPSLD_CC; \
|
||||||
fi; \
|
fi; \
|
||||||
LIBRARIES="$(LIBSSL) $(LIBKRB5) $(LIBCRYPTO)" ; \
|
LIBRARIES="$(LIBSSL) $(LIBKRB5) $(LIBCRYPTO)" ; \
|
||||||
[ "x$(FIPSCANLIB)" = "xlibfips" ] && LIBRARIES="$$LIBRARIES -lfips"; \
|
[ "x$(FIPSCANLIB)" = "xlibfips" ] && LIBRARIES="$$LIBRARIES -lfips"; \
|
||||||
$(MAKE) -f $(TOP)/Makefile.shared -e \
|
$(MAKE) -f $(TOP)/Makefile.shared -e \
|
||||||
CC="$${CC}" APPNAME=$(EXE) OBJECTS="$(PROGRAM).o $(E_OBJ)" \
|
CC=$${CC} APPNAME=$(EXE) OBJECTS="$(PROGRAM).o $(E_OBJ)" \
|
||||||
LIBDEPS="$(PEX_LIBS) $$LIBRARIES $(EX_LIBS)" \
|
LIBDEPS="$(PEX_LIBS) $$LIBRARIES $(EX_LIBS)" \
|
||||||
link_app.$${shlib_target}
|
link_app.$${shlib_target}
|
||||||
@if [ -z "$(CROSS_COMPILE)" ]; then \
|
-(cd ..; \
|
||||||
(cd ..; \
|
|
||||||
OPENSSL="`pwd`/util/opensslwrap.sh"; export OPENSSL; \
|
OPENSSL="`pwd`/util/opensslwrap.sh"; export OPENSSL; \
|
||||||
$(PERL) tools/c_rehash certs) \
|
$(PERL) tools/c_rehash certs)
|
||||||
fi
|
|
||||||
|
|
||||||
progs.h: progs.pl
|
progs.h: progs.pl
|
||||||
$(PERL) progs.pl $(E_EXE) >progs.h
|
$(PERL) progs.pl $(E_EXE) >progs.h
|
||||||
@@ -180,14 +178,13 @@ app_rand.o: ../include/openssl/ec.h ../include/openssl/ecdh.h
|
|||||||
app_rand.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
app_rand.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
||||||
app_rand.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
app_rand.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
app_rand.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
app_rand.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
app_rand.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
app_rand.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
app_rand.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
app_rand.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
app_rand.o: ../include/openssl/ossl_typ.h ../include/openssl/pkcs7.h
|
app_rand.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
||||||
app_rand.o: ../include/openssl/rand.h ../include/openssl/safestack.h
|
app_rand.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
app_rand.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
app_rand.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
app_rand.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
app_rand.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
app_rand.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
app_rand.o: ../include/openssl/x509_vfy.h app_rand.c apps.h
|
||||||
app_rand.o: ../include/openssl/x509v3.h app_rand.c apps.h
|
|
||||||
apps.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
apps.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
apps.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
apps.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
apps.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
apps.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -196,16 +193,15 @@ apps.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
|||||||
apps.o: ../include/openssl/engine.h ../include/openssl/err.h
|
apps.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
apps.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
apps.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
apps.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
apps.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
apps.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
apps.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
apps.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
apps.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
apps.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
apps.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
apps.o: ../include/openssl/pem2.h ../include/openssl/pkcs12.h
|
apps.o: ../include/openssl/pkcs12.h ../include/openssl/pkcs7.h
|
||||||
apps.o: ../include/openssl/pkcs7.h ../include/openssl/rsa.h
|
apps.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
||||||
apps.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
apps.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
apps.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
apps.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
apps.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
apps.o: ../include/openssl/ui.h ../include/openssl/x509.h
|
||||||
apps.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
apps.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.c apps.h
|
||||||
apps.o: ../include/openssl/x509v3.h apps.c apps.h
|
|
||||||
asn1pars.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
asn1pars.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
asn1pars.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
asn1pars.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
asn1pars.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
asn1pars.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -214,14 +210,13 @@ asn1pars.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
asn1pars.o: ../include/openssl/err.h ../include/openssl/evp.h
|
asn1pars.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
asn1pars.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
asn1pars.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
asn1pars.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
asn1pars.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
asn1pars.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
asn1pars.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
asn1pars.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
asn1pars.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
asn1pars.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
asn1pars.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
asn1pars.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
asn1pars.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
asn1pars.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
asn1pars.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
asn1pars.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
asn1pars.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
asn1pars.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
asn1pars.o: ../include/openssl/x509_vfy.h apps.h asn1pars.c
|
||||||
asn1pars.o: ../include/openssl/x509v3.h apps.h asn1pars.c
|
|
||||||
ca.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
ca.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
ca.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
ca.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
ca.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
ca.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -246,9 +241,8 @@ ciphers.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
ciphers.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
ciphers.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
ciphers.o: ../include/openssl/engine.h ../include/openssl/err.h
|
ciphers.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
ciphers.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
ciphers.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
ciphers.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
ciphers.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
ciphers.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
ciphers.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
ciphers.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
ciphers.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
ciphers.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
ciphers.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
ciphers.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
ciphers.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
ciphers.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
@@ -258,22 +252,8 @@ ciphers.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
|||||||
ciphers.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
ciphers.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
||||||
ciphers.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
ciphers.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
ciphers.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
ciphers.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
||||||
ciphers.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
ciphers.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
ciphers.o: ../include/openssl/x509v3.h apps.h ciphers.c
|
ciphers.o: ciphers.c
|
||||||
cms.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
|
||||||
cms.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
|
||||||
cms.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
|
||||||
cms.o: ../include/openssl/ec.h ../include/openssl/ecdh.h
|
|
||||||
cms.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|
||||||
cms.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
|
||||||
cms.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
|
||||||
cms.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
cms.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
|
||||||
cms.o: ../include/openssl/ossl_typ.h ../include/openssl/pkcs7.h
|
|
||||||
cms.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
|
||||||
cms.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
|
||||||
cms.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
|
||||||
cms.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h cms.c
|
|
||||||
crl.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
crl.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
crl.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
crl.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
crl.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
crl.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -282,14 +262,13 @@ crl.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
crl.o: ../include/openssl/err.h ../include/openssl/evp.h
|
crl.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
crl.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
crl.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
crl.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
crl.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
crl.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
crl.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
crl.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
crl.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
crl.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
crl.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
crl.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
crl.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
crl.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
crl.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
crl.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
crl.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
crl.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
crl.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h crl.c
|
||||||
crl.o: ../include/openssl/x509v3.h apps.h crl.c
|
|
||||||
crl2p7.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
crl2p7.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
crl2p7.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
crl2p7.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
crl2p7.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
crl2p7.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -298,14 +277,13 @@ crl2p7.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
crl2p7.o: ../include/openssl/err.h ../include/openssl/evp.h
|
crl2p7.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
crl2p7.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
crl2p7.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
crl2p7.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
crl2p7.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
crl2p7.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
crl2p7.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
crl2p7.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
crl2p7.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
crl2p7.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
crl2p7.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
crl2p7.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
crl2p7.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
crl2p7.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
crl2p7.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
crl2p7.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
crl2p7.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
crl2p7.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
crl2p7.o: ../include/openssl/x509_vfy.h apps.h crl2p7.c
|
||||||
crl2p7.o: ../include/openssl/x509v3.h apps.h crl2p7.c
|
|
||||||
dgst.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
dgst.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
dgst.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
dgst.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
dgst.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
dgst.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -314,14 +292,13 @@ dgst.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
dgst.o: ../include/openssl/err.h ../include/openssl/evp.h
|
dgst.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
dgst.o: ../include/openssl/fips.h ../include/openssl/hmac.h
|
dgst.o: ../include/openssl/fips.h ../include/openssl/hmac.h
|
||||||
dgst.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
dgst.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
dgst.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
dgst.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
dgst.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
dgst.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
dgst.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
dgst.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
dgst.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
dgst.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
||||||
dgst.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
dgst.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
dgst.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
dgst.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
dgst.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
dgst.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h dgst.c
|
||||||
dgst.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h dgst.c
|
|
||||||
dh.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
dh.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
dh.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
dh.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
dh.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
dh.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -331,14 +308,13 @@ dh.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
dh.o: ../include/openssl/err.h ../include/openssl/evp.h
|
dh.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
dh.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
dh.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
dh.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
dh.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
dh.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
dh.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
dh.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
dh.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
dh.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
dh.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
dh.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
dh.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
dh.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
dh.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
dh.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
dh.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
dh.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
dh.o: ../include/openssl/x509_vfy.h apps.h dh.c
|
||||||
dh.o: ../include/openssl/x509v3.h apps.h dh.c
|
|
||||||
dsa.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
dsa.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
dsa.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
dsa.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
dsa.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
dsa.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -348,14 +324,13 @@ dsa.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
dsa.o: ../include/openssl/err.h ../include/openssl/evp.h
|
dsa.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
dsa.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
dsa.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
dsa.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
dsa.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
dsa.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
dsa.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
dsa.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
dsa.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
dsa.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
dsa.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
dsa.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
dsa.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
dsa.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
dsa.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
dsa.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
dsa.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
dsa.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
dsa.o: ../include/openssl/x509_vfy.h apps.h dsa.c
|
||||||
dsa.o: ../include/openssl/x509v3.h apps.h dsa.c
|
|
||||||
dsaparam.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
dsaparam.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
dsaparam.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
dsaparam.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
dsaparam.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
dsaparam.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -365,16 +340,15 @@ dsaparam.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
|||||||
dsaparam.o: ../include/openssl/engine.h ../include/openssl/err.h
|
dsaparam.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
dsaparam.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
dsaparam.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
dsaparam.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
dsaparam.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
dsaparam.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
dsaparam.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
dsaparam.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
dsaparam.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
dsaparam.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
dsaparam.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
dsaparam.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
dsaparam.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
||||||
dsaparam.o: ../include/openssl/rand.h ../include/openssl/rsa.h
|
dsaparam.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
||||||
dsaparam.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
dsaparam.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
dsaparam.o: ../include/openssl/stack.h ../include/openssl/store.h
|
dsaparam.o: ../include/openssl/store.h ../include/openssl/symhacks.h
|
||||||
dsaparam.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
dsaparam.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
||||||
dsaparam.o: ../include/openssl/ui.h ../include/openssl/x509.h
|
dsaparam.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
dsaparam.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
|
||||||
dsaparam.o: dsaparam.c
|
dsaparam.o: dsaparam.c
|
||||||
ec.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
ec.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
ec.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
ec.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
@@ -384,14 +358,13 @@ ec.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
ec.o: ../include/openssl/err.h ../include/openssl/evp.h
|
ec.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
ec.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
ec.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
ec.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
ec.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
ec.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
ec.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
ec.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
ec.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
ec.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
ec.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
ec.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
ec.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
ec.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
ec.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
ec.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
ec.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
ec.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
ec.o: ../include/openssl/x509_vfy.h apps.h ec.c
|
||||||
ec.o: ../include/openssl/x509v3.h apps.h ec.c
|
|
||||||
ecparam.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
ecparam.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
ecparam.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
ecparam.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
ecparam.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
ecparam.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -400,14 +373,13 @@ ecparam.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
|||||||
ecparam.o: ../include/openssl/engine.h ../include/openssl/err.h
|
ecparam.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
ecparam.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
ecparam.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
ecparam.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
ecparam.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
ecparam.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
ecparam.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
ecparam.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
ecparam.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
ecparam.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
ecparam.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
ecparam.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
ecparam.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
||||||
ecparam.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
ecparam.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
ecparam.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
ecparam.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
ecparam.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
ecparam.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
ecparam.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
|
||||||
ecparam.o: ecparam.c
|
ecparam.o: ecparam.c
|
||||||
enc.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
enc.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
enc.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
enc.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
@@ -417,14 +389,13 @@ enc.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
enc.o: ../include/openssl/err.h ../include/openssl/evp.h
|
enc.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
enc.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
enc.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
enc.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
enc.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
enc.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
enc.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
enc.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
enc.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
enc.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
enc.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
enc.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
enc.o: ../include/openssl/rand.h ../include/openssl/safestack.h
|
||||||
enc.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
enc.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
enc.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
enc.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
enc.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
enc.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h enc.c
|
||||||
enc.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h enc.c
|
|
||||||
engine.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
engine.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
engine.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
engine.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
engine.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
engine.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
@@ -433,9 +404,8 @@ engine.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
engine.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
engine.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
engine.o: ../include/openssl/engine.h ../include/openssl/err.h
|
engine.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
engine.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
engine.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
engine.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
engine.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
engine.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
engine.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
engine.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
engine.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
engine.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
engine.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
engine.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
engine.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
engine.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
@@ -445,8 +415,8 @@ engine.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
|||||||
engine.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
engine.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
||||||
engine.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
engine.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
engine.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
engine.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
||||||
engine.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
engine.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
engine.o: ../include/openssl/x509v3.h apps.h engine.c
|
engine.o: engine.c
|
||||||
errstr.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
errstr.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
errstr.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
errstr.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
errstr.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
errstr.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
@@ -455,9 +425,8 @@ errstr.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
errstr.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
errstr.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
errstr.o: ../include/openssl/engine.h ../include/openssl/err.h
|
errstr.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
errstr.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
errstr.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
errstr.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
errstr.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
errstr.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
errstr.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
errstr.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
errstr.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
errstr.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
errstr.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
errstr.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
errstr.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
errstr.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
@@ -467,8 +436,8 @@ errstr.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
|||||||
errstr.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
errstr.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
||||||
errstr.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
errstr.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
errstr.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
errstr.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
||||||
errstr.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
errstr.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
errstr.o: ../include/openssl/x509v3.h apps.h errstr.c
|
errstr.o: errstr.c
|
||||||
gendh.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
gendh.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
gendh.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
gendh.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
gendh.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
gendh.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -478,17 +447,15 @@ gendh.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
|||||||
gendh.o: ../include/openssl/engine.h ../include/openssl/err.h
|
gendh.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
gendh.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
gendh.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
gendh.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
gendh.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
gendh.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
gendh.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
gendh.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
gendh.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
gendh.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
gendh.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
gendh.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
gendh.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
||||||
gendh.o: ../include/openssl/rand.h ../include/openssl/rsa.h
|
gendh.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
||||||
gendh.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
gendh.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
gendh.o: ../include/openssl/stack.h ../include/openssl/store.h
|
gendh.o: ../include/openssl/store.h ../include/openssl/symhacks.h
|
||||||
gendh.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
gendh.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
||||||
gendh.o: ../include/openssl/ui.h ../include/openssl/x509.h
|
gendh.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h gendh.c
|
||||||
gendh.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
|
||||||
gendh.o: gendh.c
|
|
||||||
gendsa.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
gendsa.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
gendsa.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
gendsa.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
gendsa.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
gendsa.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -498,14 +465,13 @@ gendsa.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
gendsa.o: ../include/openssl/err.h ../include/openssl/evp.h
|
gendsa.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
gendsa.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
gendsa.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
gendsa.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
gendsa.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
gendsa.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
gendsa.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
gendsa.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
gendsa.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
gendsa.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
gendsa.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
gendsa.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
gendsa.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
gendsa.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
gendsa.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
gendsa.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
gendsa.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
gendsa.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
gendsa.o: ../include/openssl/x509_vfy.h apps.h gendsa.c
|
||||||
gendsa.o: ../include/openssl/x509v3.h apps.h gendsa.c
|
|
||||||
genrsa.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
genrsa.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
genrsa.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
genrsa.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
genrsa.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
genrsa.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -515,16 +481,15 @@ genrsa.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
|||||||
genrsa.o: ../include/openssl/engine.h ../include/openssl/err.h
|
genrsa.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
genrsa.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
genrsa.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
genrsa.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
genrsa.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
genrsa.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
genrsa.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
genrsa.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
genrsa.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
genrsa.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
genrsa.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
genrsa.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
genrsa.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
||||||
genrsa.o: ../include/openssl/rand.h ../include/openssl/rsa.h
|
genrsa.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
||||||
genrsa.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
genrsa.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
genrsa.o: ../include/openssl/stack.h ../include/openssl/store.h
|
genrsa.o: ../include/openssl/store.h ../include/openssl/symhacks.h
|
||||||
genrsa.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
genrsa.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
||||||
genrsa.o: ../include/openssl/ui.h ../include/openssl/x509.h
|
genrsa.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
genrsa.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
|
||||||
genrsa.o: genrsa.c
|
genrsa.o: genrsa.c
|
||||||
nseq.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
nseq.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
nseq.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
nseq.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
@@ -534,14 +499,13 @@ nseq.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
nseq.o: ../include/openssl/err.h ../include/openssl/evp.h
|
nseq.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
nseq.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
nseq.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
nseq.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
nseq.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
nseq.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
nseq.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
nseq.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
nseq.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
nseq.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
nseq.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
nseq.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
nseq.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
nseq.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
nseq.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
nseq.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
nseq.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
nseq.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
nseq.o: ../include/openssl/x509_vfy.h apps.h nseq.c
|
||||||
nseq.o: ../include/openssl/x509v3.h apps.h nseq.c
|
|
||||||
ocsp.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
ocsp.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
ocsp.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
ocsp.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
ocsp.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
ocsp.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
@@ -550,20 +514,19 @@ ocsp.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
ocsp.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
ocsp.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
ocsp.o: ../include/openssl/engine.h ../include/openssl/err.h
|
ocsp.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
ocsp.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
ocsp.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
ocsp.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
ocsp.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
ocsp.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
ocsp.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
ocsp.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
ocsp.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
||||||
ocsp.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
ocsp.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
ocsp.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
ocsp.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
ocsp.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
ocsp.o: ../include/openssl/pkcs7.h ../include/openssl/pq_compat.h
|
||||||
ocsp.o: ../include/openssl/pq_compat.h ../include/openssl/pqueue.h
|
ocsp.o: ../include/openssl/pqueue.h ../include/openssl/safestack.h
|
||||||
ocsp.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
ocsp.o: ../include/openssl/sha.h ../include/openssl/ssl.h
|
||||||
ocsp.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
ocsp.o: ../include/openssl/ssl2.h ../include/openssl/ssl23.h
|
||||||
ocsp.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
ocsp.o: ../include/openssl/ssl3.h ../include/openssl/stack.h
|
||||||
ocsp.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
ocsp.o: ../include/openssl/symhacks.h ../include/openssl/tls1.h
|
||||||
ocsp.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
ocsp.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
ocsp.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
ocsp.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h ocsp.c
|
||||||
ocsp.o: ../include/openssl/x509v3.h apps.h ocsp.c
|
|
||||||
openssl.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
openssl.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
openssl.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
openssl.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
openssl.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
openssl.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
@@ -572,9 +535,8 @@ openssl.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
openssl.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
openssl.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
openssl.o: ../include/openssl/engine.h ../include/openssl/err.h
|
openssl.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
openssl.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
openssl.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
openssl.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
openssl.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
openssl.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
openssl.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
openssl.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
openssl.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
openssl.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
openssl.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
openssl.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
openssl.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
openssl.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
@@ -584,8 +546,8 @@ openssl.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
|||||||
openssl.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
openssl.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
||||||
openssl.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
openssl.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
openssl.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
openssl.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
||||||
openssl.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
openssl.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
openssl.o: ../include/openssl/x509v3.h apps.h openssl.c progs.h s_apps.h
|
openssl.o: openssl.c progs.h s_apps.h
|
||||||
passwd.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
passwd.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
passwd.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
passwd.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
passwd.o: ../include/openssl/crypto.h ../include/openssl/des.h
|
passwd.o: ../include/openssl/crypto.h ../include/openssl/des.h
|
||||||
@@ -595,15 +557,14 @@ passwd.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
passwd.o: ../include/openssl/err.h ../include/openssl/evp.h
|
passwd.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
passwd.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
passwd.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
passwd.o: ../include/openssl/md5.h ../include/openssl/obj_mac.h
|
passwd.o: ../include/openssl/md5.h ../include/openssl/obj_mac.h
|
||||||
passwd.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
passwd.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
passwd.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
passwd.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
passwd.o: ../include/openssl/ossl_typ.h ../include/openssl/pkcs7.h
|
passwd.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
||||||
passwd.o: ../include/openssl/rand.h ../include/openssl/safestack.h
|
passwd.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
passwd.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
passwd.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
passwd.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
passwd.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
||||||
passwd.o: ../include/openssl/ui.h ../include/openssl/ui_compat.h
|
passwd.o: ../include/openssl/ui_compat.h ../include/openssl/x509.h
|
||||||
passwd.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
passwd.o: ../include/openssl/x509_vfy.h apps.h passwd.c
|
||||||
passwd.o: ../include/openssl/x509v3.h apps.h passwd.c
|
|
||||||
pkcs12.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
pkcs12.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
pkcs12.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
pkcs12.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
pkcs12.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
pkcs12.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -612,14 +573,13 @@ pkcs12.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
pkcs12.o: ../include/openssl/err.h ../include/openssl/evp.h
|
pkcs12.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
pkcs12.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
pkcs12.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
pkcs12.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
pkcs12.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
pkcs12.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
pkcs12.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
pkcs12.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
pkcs12.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
pkcs12.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
pkcs12.o: ../include/openssl/pem2.h ../include/openssl/pkcs12.h
|
||||||
pkcs12.o: ../include/openssl/pkcs12.h ../include/openssl/pkcs7.h
|
pkcs12.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
||||||
pkcs12.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
pkcs12.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
pkcs12.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
pkcs12.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
pkcs12.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
pkcs12.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
pkcs12.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
|
||||||
pkcs12.o: pkcs12.c
|
pkcs12.o: pkcs12.c
|
||||||
pkcs7.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
pkcs7.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
pkcs7.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
pkcs7.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
@@ -629,14 +589,13 @@ pkcs7.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
pkcs7.o: ../include/openssl/err.h ../include/openssl/evp.h
|
pkcs7.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
pkcs7.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
pkcs7.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
pkcs7.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
pkcs7.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
pkcs7.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
pkcs7.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
pkcs7.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
pkcs7.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
pkcs7.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
pkcs7.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
pkcs7.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
pkcs7.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
pkcs7.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
pkcs7.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
pkcs7.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
pkcs7.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
pkcs7.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
pkcs7.o: ../include/openssl/x509_vfy.h apps.h pkcs7.c
|
||||||
pkcs7.o: ../include/openssl/x509v3.h apps.h pkcs7.c
|
|
||||||
pkcs8.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
pkcs8.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
pkcs8.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
pkcs8.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
pkcs8.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
pkcs8.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -645,15 +604,13 @@ pkcs8.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
pkcs8.o: ../include/openssl/err.h ../include/openssl/evp.h
|
pkcs8.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
pkcs8.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
pkcs8.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
pkcs8.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
pkcs8.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
pkcs8.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
pkcs8.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
pkcs8.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
pkcs8.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
pkcs8.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
pkcs8.o: ../include/openssl/pem2.h ../include/openssl/pkcs12.h
|
||||||
pkcs8.o: ../include/openssl/pkcs12.h ../include/openssl/pkcs7.h
|
pkcs8.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
||||||
pkcs8.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
pkcs8.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
pkcs8.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
pkcs8.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
pkcs8.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
pkcs8.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h pkcs8.c
|
||||||
pkcs8.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
|
||||||
pkcs8.o: pkcs8.c
|
|
||||||
prime.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
prime.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
prime.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
prime.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
prime.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
prime.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -662,13 +619,12 @@ prime.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
|||||||
prime.o: ../include/openssl/engine.h ../include/openssl/evp.h
|
prime.o: ../include/openssl/engine.h ../include/openssl/evp.h
|
||||||
prime.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
prime.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
prime.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
prime.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
prime.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
prime.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
prime.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
prime.o: ../include/openssl/ossl_typ.h ../include/openssl/pkcs7.h
|
||||||
prime.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
prime.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
prime.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
prime.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
prime.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
prime.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
prime.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
prime.o: ../include/openssl/x509_vfy.h apps.h prime.c
|
||||||
prime.o: ../include/openssl/x509v3.h apps.h prime.c
|
|
||||||
rand.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
rand.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
rand.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
rand.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
rand.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
rand.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -677,13 +633,12 @@ rand.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
rand.o: ../include/openssl/err.h ../include/openssl/evp.h
|
rand.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
rand.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
rand.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
rand.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
rand.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
rand.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
rand.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
rand.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
rand.o: ../include/openssl/ossl_typ.h ../include/openssl/pkcs7.h
|
||||||
rand.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
rand.o: ../include/openssl/rand.h ../include/openssl/safestack.h
|
||||||
rand.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
rand.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
rand.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
rand.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
rand.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
rand.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h rand.c
|
||||||
rand.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h rand.c
|
|
||||||
req.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
req.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
req.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
req.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
req.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
req.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -693,16 +648,16 @@ req.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
|||||||
req.o: ../include/openssl/engine.h ../include/openssl/err.h
|
req.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
req.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
req.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
req.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
req.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
req.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
req.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
req.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
req.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
req.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
req.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
req.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
req.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
||||||
req.o: ../include/openssl/rand.h ../include/openssl/rsa.h
|
req.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
||||||
req.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
req.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
req.o: ../include/openssl/stack.h ../include/openssl/store.h
|
req.o: ../include/openssl/store.h ../include/openssl/symhacks.h
|
||||||
req.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
req.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
||||||
req.o: ../include/openssl/ui.h ../include/openssl/x509.h
|
req.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
||||||
req.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h req.c
|
req.o: ../include/openssl/x509v3.h apps.h req.c
|
||||||
rsa.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
rsa.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
rsa.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
rsa.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
rsa.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
rsa.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -711,15 +666,14 @@ rsa.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
|||||||
rsa.o: ../include/openssl/engine.h ../include/openssl/err.h
|
rsa.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
rsa.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
rsa.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
rsa.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
rsa.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
rsa.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
rsa.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
rsa.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
rsa.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
rsa.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
rsa.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
rsa.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
rsa.o: ../include/openssl/pkcs7.h ../include/openssl/rsa.h
|
||||||
rsa.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
rsa.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
rsa.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
rsa.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
rsa.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
rsa.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
rsa.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
rsa.o: ../include/openssl/x509_vfy.h apps.h rsa.c
|
||||||
rsa.o: ../include/openssl/x509v3.h apps.h rsa.c
|
|
||||||
rsautl.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
rsautl.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
rsautl.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
rsautl.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
rsautl.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
rsautl.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -728,14 +682,13 @@ rsautl.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
rsautl.o: ../include/openssl/err.h ../include/openssl/evp.h
|
rsautl.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
rsautl.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
rsautl.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
rsautl.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
rsautl.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
rsautl.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
rsautl.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
rsautl.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
rsautl.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
rsautl.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
rsautl.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
rsautl.o: ../include/openssl/pkcs7.h ../include/openssl/rsa.h
|
rsautl.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
||||||
rsautl.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
rsautl.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
rsautl.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
rsautl.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
rsautl.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
rsautl.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
rsautl.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
|
||||||
rsautl.o: rsautl.c
|
rsautl.o: rsautl.c
|
||||||
s_cb.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
s_cb.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
s_cb.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
s_cb.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
@@ -745,21 +698,19 @@ s_cb.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
s_cb.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
s_cb.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
s_cb.o: ../include/openssl/engine.h ../include/openssl/err.h
|
s_cb.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
s_cb.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
s_cb.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
s_cb.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
s_cb.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
s_cb.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
s_cb.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
s_cb.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
s_cb.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
s_cb.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
s_cb.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
s_cb.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
s_cb.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
s_cb.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
s_cb.o: ../include/openssl/pq_compat.h ../include/openssl/pqueue.h
|
s_cb.o: ../include/openssl/pq_compat.h ../include/openssl/pqueue.h
|
||||||
s_cb.o: ../include/openssl/rand.h ../include/openssl/safestack.h
|
s_cb.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
s_cb.o: ../include/openssl/sha.h ../include/openssl/ssl.h
|
s_cb.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
||||||
s_cb.o: ../include/openssl/ssl2.h ../include/openssl/ssl23.h
|
s_cb.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
||||||
s_cb.o: ../include/openssl/ssl3.h ../include/openssl/stack.h
|
s_cb.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
s_cb.o: ../include/openssl/symhacks.h ../include/openssl/tls1.h
|
s_cb.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
||||||
s_cb.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
s_cb.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h s_apps.h
|
||||||
s_cb.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
s_cb.o: s_cb.c
|
||||||
s_cb.o: s_apps.h s_cb.c
|
|
||||||
s_client.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
s_client.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
s_client.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
s_client.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
s_client.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
s_client.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
@@ -768,9 +719,8 @@ s_client.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
s_client.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
s_client.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
s_client.o: ../include/openssl/engine.h ../include/openssl/err.h
|
s_client.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
s_client.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
s_client.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
s_client.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
s_client.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
s_client.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
s_client.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
s_client.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
s_client.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
s_client.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
s_client.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
s_client.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
s_client.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
s_client.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
@@ -781,8 +731,7 @@ s_client.o: ../include/openssl/ssl2.h ../include/openssl/ssl23.h
|
|||||||
s_client.o: ../include/openssl/ssl3.h ../include/openssl/stack.h
|
s_client.o: ../include/openssl/ssl3.h ../include/openssl/stack.h
|
||||||
s_client.o: ../include/openssl/symhacks.h ../include/openssl/tls1.h
|
s_client.o: ../include/openssl/symhacks.h ../include/openssl/tls1.h
|
||||||
s_client.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
s_client.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
s_client.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
s_client.o: ../include/openssl/x509_vfy.h apps.h s_apps.h s_client.c timeouts.h
|
||||||
s_client.o: s_apps.h s_client.c timeouts.h
|
|
||||||
s_server.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
s_server.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
s_server.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
s_server.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
s_server.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
s_server.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
@@ -792,9 +741,8 @@ s_server.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
s_server.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
s_server.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
s_server.o: ../include/openssl/engine.h ../include/openssl/err.h
|
s_server.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
s_server.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
s_server.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
s_server.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
s_server.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
s_server.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
s_server.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
s_server.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
s_server.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
s_server.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
s_server.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
s_server.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
s_server.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
s_server.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
@@ -806,30 +754,28 @@ s_server.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
|||||||
s_server.o: ../include/openssl/stack.h ../include/openssl/store.h
|
s_server.o: ../include/openssl/stack.h ../include/openssl/store.h
|
||||||
s_server.o: ../include/openssl/symhacks.h ../include/openssl/tls1.h
|
s_server.o: ../include/openssl/symhacks.h ../include/openssl/tls1.h
|
||||||
s_server.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
s_server.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
||||||
s_server.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
s_server.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
s_server.o: ../include/openssl/x509v3.h apps.h s_apps.h s_server.c timeouts.h
|
s_server.o: s_apps.h s_server.c timeouts.h
|
||||||
s_socket.o: ../e_os.h ../e_os2.h ../include/openssl/asn1.h
|
s_socket.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
s_socket.o: ../include/openssl/bio.h ../include/openssl/bn.h
|
s_socket.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
s_socket.o: ../include/openssl/buffer.h ../include/openssl/comp.h
|
s_socket.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
s_socket.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
s_socket.o: ../include/openssl/crypto.h ../include/openssl/dtls1.h
|
||||||
s_socket.o: ../include/openssl/dtls1.h ../include/openssl/e_os2.h
|
s_socket.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
||||||
s_socket.o: ../include/openssl/ec.h ../include/openssl/ecdh.h
|
s_socket.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
s_socket.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
s_socket.o: ../include/openssl/engine.h ../include/openssl/evp.h
|
||||||
s_socket.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
s_socket.o: ../include/openssl/fips.h ../include/openssl/kssl.h
|
||||||
s_socket.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
|
||||||
s_socket.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
s_socket.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
||||||
s_socket.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
s_socket.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
s_socket.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
s_socket.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
s_socket.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
s_socket.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
||||||
s_socket.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
s_socket.o: ../include/openssl/pkcs7.h ../include/openssl/pq_compat.h
|
||||||
s_socket.o: ../include/openssl/pq_compat.h ../include/openssl/pqueue.h
|
s_socket.o: ../include/openssl/pqueue.h ../include/openssl/safestack.h
|
||||||
s_socket.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
s_socket.o: ../include/openssl/sha.h ../include/openssl/ssl.h
|
||||||
s_socket.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
s_socket.o: ../include/openssl/ssl2.h ../include/openssl/ssl23.h
|
||||||
s_socket.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
s_socket.o: ../include/openssl/ssl3.h ../include/openssl/stack.h
|
||||||
s_socket.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
s_socket.o: ../include/openssl/symhacks.h ../include/openssl/tls1.h
|
||||||
s_socket.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
s_socket.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
s_socket.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
s_socket.o: ../include/openssl/x509_vfy.h apps.h s_apps.h s_socket.c
|
||||||
s_socket.o: ../include/openssl/x509v3.h apps.h s_apps.h s_socket.c
|
|
||||||
s_time.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
s_time.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
s_time.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
s_time.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
s_time.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
s_time.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
@@ -838,9 +784,8 @@ s_time.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
s_time.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
s_time.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
s_time.o: ../include/openssl/engine.h ../include/openssl/err.h
|
s_time.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
s_time.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
s_time.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
s_time.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
s_time.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
s_time.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
s_time.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
s_time.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
s_time.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
s_time.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
s_time.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
s_time.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
s_time.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
s_time.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
@@ -850,8 +795,8 @@ s_time.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
|||||||
s_time.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
s_time.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
||||||
s_time.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
s_time.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
s_time.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
s_time.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
||||||
s_time.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
s_time.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
s_time.o: ../include/openssl/x509v3.h apps.h s_apps.h s_time.c
|
s_time.o: s_apps.h s_time.c
|
||||||
sess_id.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
sess_id.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
sess_id.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
sess_id.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
sess_id.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
sess_id.o: ../include/openssl/comp.h ../include/openssl/conf.h
|
||||||
@@ -860,9 +805,8 @@ sess_id.o: ../include/openssl/e_os2.h ../include/openssl/ec.h
|
|||||||
sess_id.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
sess_id.o: ../include/openssl/ecdh.h ../include/openssl/ecdsa.h
|
||||||
sess_id.o: ../include/openssl/engine.h ../include/openssl/err.h
|
sess_id.o: ../include/openssl/engine.h ../include/openssl/err.h
|
||||||
sess_id.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
sess_id.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
sess_id.o: ../include/openssl/hmac.h ../include/openssl/kssl.h
|
sess_id.o: ../include/openssl/kssl.h ../include/openssl/lhash.h
|
||||||
sess_id.o: ../include/openssl/lhash.h ../include/openssl/obj_mac.h
|
sess_id.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
sess_id.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
|
||||||
sess_id.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
sess_id.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
sess_id.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
sess_id.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
sess_id.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
sess_id.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
@@ -872,8 +816,8 @@ sess_id.o: ../include/openssl/ssl.h ../include/openssl/ssl2.h
|
|||||||
sess_id.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
sess_id.o: ../include/openssl/ssl23.h ../include/openssl/ssl3.h
|
||||||
sess_id.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
sess_id.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
sess_id.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
sess_id.o: ../include/openssl/tls1.h ../include/openssl/txt_db.h
|
||||||
sess_id.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
sess_id.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h
|
||||||
sess_id.o: ../include/openssl/x509v3.h apps.h sess_id.c
|
sess_id.o: sess_id.c
|
||||||
smime.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
smime.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
smime.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
smime.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
smime.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
smime.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -882,14 +826,14 @@ smime.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
smime.o: ../include/openssl/err.h ../include/openssl/evp.h
|
smime.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
smime.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
smime.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
smime.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
smime.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
smime.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
smime.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
smime.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
smime.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
smime.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
smime.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
smime.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
smime.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
smime.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
smime.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
smime.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
smime.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
smime.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
smime.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
||||||
smime.o: ../include/openssl/x509v3.h apps.h smime.c
|
smime.o: smime.c
|
||||||
speed.o: ../e_os.h ../include/openssl/aes.h ../include/openssl/asn1.h
|
speed.o: ../e_os.h ../include/openssl/aes.h ../include/openssl/asn1.h
|
||||||
speed.o: ../include/openssl/bio.h ../include/openssl/blowfish.h
|
speed.o: ../include/openssl/bio.h ../include/openssl/blowfish.h
|
||||||
speed.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
speed.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
@@ -904,17 +848,16 @@ speed.o: ../include/openssl/hmac.h ../include/openssl/idea.h
|
|||||||
speed.o: ../include/openssl/lhash.h ../include/openssl/md2.h
|
speed.o: ../include/openssl/lhash.h ../include/openssl/md2.h
|
||||||
speed.o: ../include/openssl/md4.h ../include/openssl/md5.h
|
speed.o: ../include/openssl/md4.h ../include/openssl/md5.h
|
||||||
speed.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
speed.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
speed.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
speed.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
speed.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
speed.o: ../include/openssl/ossl_typ.h ../include/openssl/pkcs7.h
|
||||||
speed.o: ../include/openssl/pkcs7.h ../include/openssl/rand.h
|
speed.o: ../include/openssl/rand.h ../include/openssl/rc2.h
|
||||||
speed.o: ../include/openssl/rc2.h ../include/openssl/rc4.h
|
speed.o: ../include/openssl/rc4.h ../include/openssl/ripemd.h
|
||||||
speed.o: ../include/openssl/ripemd.h ../include/openssl/rsa.h
|
speed.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
||||||
speed.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
speed.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
speed.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
speed.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
speed.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
speed.o: ../include/openssl/ui.h ../include/openssl/ui_compat.h
|
||||||
speed.o: ../include/openssl/ui_compat.h ../include/openssl/x509.h
|
speed.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h apps.h speed.c
|
||||||
speed.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
speed.o: testdsa.h testrsa.h
|
||||||
speed.o: speed.c testdsa.h testrsa.h
|
|
||||||
spkac.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
spkac.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
spkac.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
spkac.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
spkac.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
spkac.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -923,14 +866,13 @@ spkac.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
spkac.o: ../include/openssl/err.h ../include/openssl/evp.h
|
spkac.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
spkac.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
spkac.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
spkac.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
spkac.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
spkac.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
spkac.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
spkac.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
spkac.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
spkac.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
spkac.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
spkac.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
spkac.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
spkac.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
spkac.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
spkac.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
spkac.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
spkac.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
spkac.o: ../include/openssl/x509_vfy.h apps.h spkac.c
|
||||||
spkac.o: ../include/openssl/x509v3.h apps.h spkac.c
|
|
||||||
verify.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
verify.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
verify.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
verify.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
verify.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
verify.o: ../include/openssl/crypto.h ../include/openssl/e_os2.h
|
||||||
@@ -939,14 +881,14 @@ verify.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
verify.o: ../include/openssl/err.h ../include/openssl/evp.h
|
verify.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
verify.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
verify.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
verify.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
verify.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
verify.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
verify.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
verify.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
verify.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
verify.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
verify.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
verify.o: ../include/openssl/pkcs7.h ../include/openssl/safestack.h
|
verify.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
verify.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
verify.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
verify.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
verify.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
||||||
verify.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
verify.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h
|
||||||
verify.o: ../include/openssl/x509v3.h apps.h verify.c
|
verify.o: verify.c
|
||||||
version.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
version.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
version.o: ../include/openssl/blowfish.h ../include/openssl/bn.h
|
version.o: ../include/openssl/blowfish.h ../include/openssl/bn.h
|
||||||
version.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
version.o: ../include/openssl/buffer.h ../include/openssl/conf.h
|
||||||
@@ -957,15 +899,14 @@ version.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
version.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
version.o: ../include/openssl/evp.h ../include/openssl/fips.h
|
||||||
version.o: ../include/openssl/idea.h ../include/openssl/lhash.h
|
version.o: ../include/openssl/idea.h ../include/openssl/lhash.h
|
||||||
version.o: ../include/openssl/md2.h ../include/openssl/obj_mac.h
|
version.o: ../include/openssl/md2.h ../include/openssl/obj_mac.h
|
||||||
version.o: ../include/openssl/objects.h ../include/openssl/ocsp.h
|
version.o: ../include/openssl/objects.h ../include/openssl/opensslconf.h
|
||||||
version.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
version.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
||||||
version.o: ../include/openssl/ossl_typ.h ../include/openssl/pkcs7.h
|
version.o: ../include/openssl/pkcs7.h ../include/openssl/rc4.h
|
||||||
version.o: ../include/openssl/rc4.h ../include/openssl/safestack.h
|
version.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
||||||
version.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
version.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
||||||
version.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
version.o: ../include/openssl/txt_db.h ../include/openssl/ui.h
|
||||||
version.o: ../include/openssl/ui.h ../include/openssl/ui_compat.h
|
version.o: ../include/openssl/ui_compat.h ../include/openssl/x509.h
|
||||||
version.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
version.o: ../include/openssl/x509_vfy.h apps.h version.c
|
||||||
version.o: ../include/openssl/x509v3.h apps.h version.c
|
|
||||||
x509.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
x509.o: ../e_os.h ../include/openssl/asn1.h ../include/openssl/bio.h
|
||||||
x509.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
x509.o: ../include/openssl/bn.h ../include/openssl/buffer.h
|
||||||
x509.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
x509.o: ../include/openssl/conf.h ../include/openssl/crypto.h
|
||||||
@@ -975,11 +916,11 @@ x509.o: ../include/openssl/ecdsa.h ../include/openssl/engine.h
|
|||||||
x509.o: ../include/openssl/err.h ../include/openssl/evp.h
|
x509.o: ../include/openssl/err.h ../include/openssl/evp.h
|
||||||
x509.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
x509.o: ../include/openssl/fips.h ../include/openssl/lhash.h
|
||||||
x509.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
x509.o: ../include/openssl/obj_mac.h ../include/openssl/objects.h
|
||||||
x509.o: ../include/openssl/ocsp.h ../include/openssl/opensslconf.h
|
x509.o: ../include/openssl/opensslconf.h ../include/openssl/opensslv.h
|
||||||
x509.o: ../include/openssl/opensslv.h ../include/openssl/ossl_typ.h
|
x509.o: ../include/openssl/ossl_typ.h ../include/openssl/pem.h
|
||||||
x509.o: ../include/openssl/pem.h ../include/openssl/pem2.h
|
x509.o: ../include/openssl/pem2.h ../include/openssl/pkcs7.h
|
||||||
x509.o: ../include/openssl/pkcs7.h ../include/openssl/rsa.h
|
x509.o: ../include/openssl/rsa.h ../include/openssl/safestack.h
|
||||||
x509.o: ../include/openssl/safestack.h ../include/openssl/sha.h
|
x509.o: ../include/openssl/sha.h ../include/openssl/stack.h
|
||||||
x509.o: ../include/openssl/stack.h ../include/openssl/symhacks.h
|
x509.o: ../include/openssl/symhacks.h ../include/openssl/txt_db.h
|
||||||
x509.o: ../include/openssl/txt_db.h ../include/openssl/x509.h
|
x509.o: ../include/openssl/x509.h ../include/openssl/x509_vfy.h
|
||||||
x509.o: ../include/openssl/x509_vfy.h ../include/openssl/x509v3.h apps.h x509.c
|
x509.o: ../include/openssl/x509v3.h apps.h x509.c
|
||||||
|
|||||||
264
apps/apps.c
264
apps/apps.c
@@ -115,7 +115,6 @@
|
|||||||
#include <sys/types.h>
|
#include <sys/types.h>
|
||||||
#include <sys/stat.h>
|
#include <sys/stat.h>
|
||||||
#include <ctype.h>
|
#include <ctype.h>
|
||||||
#include <assert.h>
|
|
||||||
#include <openssl/err.h>
|
#include <openssl/err.h>
|
||||||
#include <openssl/x509.h>
|
#include <openssl/x509.h>
|
||||||
#include <openssl/x509v3.h>
|
#include <openssl/x509v3.h>
|
||||||
@@ -130,9 +129,6 @@
|
|||||||
#include <openssl/rsa.h>
|
#include <openssl/rsa.h>
|
||||||
#endif
|
#endif
|
||||||
#include <openssl/bn.h>
|
#include <openssl/bn.h>
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
#include <openssl/jpake.h>
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#define NON_MAIN
|
#define NON_MAIN
|
||||||
#include "apps.h"
|
#include "apps.h"
|
||||||
@@ -351,19 +347,18 @@ void program_name(char *in, char *out, int size)
|
|||||||
|
|
||||||
int chopup_args(ARGS *arg, char *buf, int *argc, char **argv[])
|
int chopup_args(ARGS *arg, char *buf, int *argc, char **argv[])
|
||||||
{
|
{
|
||||||
int num,i;
|
int num,len,i;
|
||||||
char *p;
|
char *p;
|
||||||
|
|
||||||
*argc=0;
|
*argc=0;
|
||||||
*argv=NULL;
|
*argv=NULL;
|
||||||
|
|
||||||
|
len=strlen(buf);
|
||||||
i=0;
|
i=0;
|
||||||
if (arg->count == 0)
|
if (arg->count == 0)
|
||||||
{
|
{
|
||||||
arg->count=20;
|
arg->count=20;
|
||||||
arg->data=(char **)OPENSSL_malloc(sizeof(char *)*arg->count);
|
arg->data=(char **)OPENSSL_malloc(sizeof(char *)*arg->count);
|
||||||
if (arg->data == NULL)
|
|
||||||
return 0;
|
|
||||||
}
|
}
|
||||||
for (i=0; i<arg->count; i++)
|
for (i=0; i<arg->count; i++)
|
||||||
arg->data[i]=NULL;
|
arg->data[i]=NULL;
|
||||||
@@ -560,12 +555,12 @@ int password_callback(char *buf, int bufsiz, int verify,
|
|||||||
|
|
||||||
if (ok >= 0)
|
if (ok >= 0)
|
||||||
ok = UI_add_input_string(ui,prompt,ui_flags,buf,
|
ok = UI_add_input_string(ui,prompt,ui_flags,buf,
|
||||||
PW_MIN_LENGTH,bufsiz-1);
|
PW_MIN_LENGTH,BUFSIZ-1);
|
||||||
if (ok >= 0 && verify)
|
if (ok >= 0 && verify)
|
||||||
{
|
{
|
||||||
buff = (char *)OPENSSL_malloc(bufsiz);
|
buff = (char *)OPENSSL_malloc(bufsiz);
|
||||||
ok = UI_add_verify_string(ui,prompt,ui_flags,buff,
|
ok = UI_add_verify_string(ui,prompt,ui_flags,buff,
|
||||||
PW_MIN_LENGTH,bufsiz-1, buf);
|
PW_MIN_LENGTH,BUFSIZ-1, buf);
|
||||||
}
|
}
|
||||||
if (ok >= 0)
|
if (ok >= 0)
|
||||||
do
|
do
|
||||||
@@ -867,17 +862,10 @@ EVP_PKEY *load_key(BIO *err, const char *file, int format, int maybe_stdin,
|
|||||||
if (format == FORMAT_ENGINE)
|
if (format == FORMAT_ENGINE)
|
||||||
{
|
{
|
||||||
if (!e)
|
if (!e)
|
||||||
BIO_printf(err,"no engine specified\n");
|
BIO_printf(bio_err,"no engine specified\n");
|
||||||
else
|
else
|
||||||
{
|
|
||||||
pkey = ENGINE_load_private_key(e, file,
|
pkey = ENGINE_load_private_key(e, file,
|
||||||
ui_method, &cb_data);
|
ui_method, &cb_data);
|
||||||
if (!pkey)
|
|
||||||
{
|
|
||||||
BIO_printf(err,"cannot load %s from engine\n",key_descrip);
|
|
||||||
ERR_print_errors(err);
|
|
||||||
}
|
|
||||||
}
|
|
||||||
goto end;
|
goto end;
|
||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
@@ -928,10 +916,7 @@ EVP_PKEY *load_key(BIO *err, const char *file, int format, int maybe_stdin,
|
|||||||
end:
|
end:
|
||||||
if (key != NULL) BIO_free(key);
|
if (key != NULL) BIO_free(key);
|
||||||
if (pkey == NULL)
|
if (pkey == NULL)
|
||||||
{
|
|
||||||
BIO_printf(err,"unable to load %s\n", key_descrip);
|
BIO_printf(err,"unable to load %s\n", key_descrip);
|
||||||
ERR_print_errors(err);
|
|
||||||
}
|
|
||||||
return(pkey);
|
return(pkey);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -1431,8 +1416,6 @@ char *make_config_name()
|
|||||||
|
|
||||||
len=strlen(t)+strlen(OPENSSL_CONF)+2;
|
len=strlen(t)+strlen(OPENSSL_CONF)+2;
|
||||||
p=OPENSSL_malloc(len);
|
p=OPENSSL_malloc(len);
|
||||||
if (p == NULL)
|
|
||||||
return NULL;
|
|
||||||
BUF_strlcpy(p,t,len);
|
BUF_strlcpy(p,t,len);
|
||||||
#ifndef OPENSSL_SYS_VMS
|
#ifndef OPENSSL_SYS_VMS
|
||||||
BUF_strlcat(p,"/",len);
|
BUF_strlcat(p,"/",len);
|
||||||
@@ -2056,7 +2039,7 @@ X509_NAME *parse_name(char *subject, long chtype, int multirdn)
|
|||||||
X509_NAME *n = NULL;
|
X509_NAME *n = NULL;
|
||||||
int nid;
|
int nid;
|
||||||
|
|
||||||
if (!buf || !ne_types || !ne_values || !mval)
|
if (!buf || !ne_types || !ne_values)
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err, "malloc error\n");
|
BIO_printf(bio_err, "malloc error\n");
|
||||||
goto error;
|
goto error;
|
||||||
@@ -2160,7 +2143,6 @@ X509_NAME *parse_name(char *subject, long chtype, int multirdn)
|
|||||||
OPENSSL_free(ne_values);
|
OPENSSL_free(ne_values);
|
||||||
OPENSSL_free(ne_types);
|
OPENSSL_free(ne_types);
|
||||||
OPENSSL_free(buf);
|
OPENSSL_free(buf);
|
||||||
OPENSSL_free(mval);
|
|
||||||
return n;
|
return n;
|
||||||
|
|
||||||
error:
|
error:
|
||||||
@@ -2169,8 +2151,6 @@ error:
|
|||||||
OPENSSL_free(ne_values);
|
OPENSSL_free(ne_values);
|
||||||
if (ne_types)
|
if (ne_types)
|
||||||
OPENSSL_free(ne_types);
|
OPENSSL_free(ne_types);
|
||||||
if (mval)
|
|
||||||
OPENSSL_free(mval);
|
|
||||||
if (buf)
|
if (buf)
|
||||||
OPENSSL_free(buf);
|
OPENSSL_free(buf);
|
||||||
return NULL;
|
return NULL;
|
||||||
@@ -2277,8 +2257,6 @@ int args_verify(char ***pargs, int *pargc,
|
|||||||
flags |= X509_V_FLAG_X509_STRICT;
|
flags |= X509_V_FLAG_X509_STRICT;
|
||||||
else if (!strcmp(arg, "-policy_print"))
|
else if (!strcmp(arg, "-policy_print"))
|
||||||
flags |= X509_V_FLAG_NOTIFY_POLICY;
|
flags |= X509_V_FLAG_NOTIFY_POLICY;
|
||||||
else if (!strcmp(arg, "-check_ss_sig"))
|
|
||||||
flags |= X509_V_FLAG_CHECK_SS_SIGNATURE;
|
|
||||||
else
|
else
|
||||||
return 0;
|
return 0;
|
||||||
|
|
||||||
@@ -2355,233 +2333,3 @@ void policies_print(BIO *out, X509_STORE_CTX *ctx)
|
|||||||
if (free_out)
|
if (free_out)
|
||||||
BIO_free(out);
|
BIO_free(out);
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
|
|
||||||
static JPAKE_CTX *jpake_init(const char *us, const char *them,
|
|
||||||
const char *secret)
|
|
||||||
{
|
|
||||||
BIGNUM *p = NULL;
|
|
||||||
BIGNUM *g = NULL;
|
|
||||||
BIGNUM *q = NULL;
|
|
||||||
BIGNUM *bnsecret = BN_new();
|
|
||||||
JPAKE_CTX *ctx;
|
|
||||||
|
|
||||||
/* Use a safe prime for p (that we found earlier) */
|
|
||||||
BN_hex2bn(&p, "F9E5B365665EA7A05A9C534502780FEE6F1AB5BD4F49947FD036DBD7E905269AF46EF28B0FC07487EE4F5D20FB3C0AF8E700F3A2FA3414970CBED44FEDFF80CE78D800F184BB82435D137AADA2C6C16523247930A63B85661D1FC817A51ACD96168E95898A1F83A79FFB529368AA7833ABD1B0C3AEDDB14D2E1A2F71D99F763F");
|
|
||||||
g = BN_new();
|
|
||||||
BN_set_word(g, 2);
|
|
||||||
q = BN_new();
|
|
||||||
BN_rshift1(q, p);
|
|
||||||
|
|
||||||
BN_bin2bn((const unsigned char *)secret, strlen(secret), bnsecret);
|
|
||||||
|
|
||||||
ctx = JPAKE_CTX_new(us, them, p, g, q, bnsecret);
|
|
||||||
BN_free(bnsecret);
|
|
||||||
BN_free(q);
|
|
||||||
BN_free(g);
|
|
||||||
BN_free(p);
|
|
||||||
|
|
||||||
return ctx;
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_send_part(BIO *conn, const JPAKE_STEP_PART *p)
|
|
||||||
{
|
|
||||||
BN_print(conn, p->gx);
|
|
||||||
BIO_puts(conn, "\n");
|
|
||||||
BN_print(conn, p->zkpx.gr);
|
|
||||||
BIO_puts(conn, "\n");
|
|
||||||
BN_print(conn, p->zkpx.b);
|
|
||||||
BIO_puts(conn, "\n");
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_send_step1(BIO *bconn, JPAKE_CTX *ctx)
|
|
||||||
{
|
|
||||||
JPAKE_STEP1 s1;
|
|
||||||
|
|
||||||
JPAKE_STEP1_init(&s1);
|
|
||||||
JPAKE_STEP1_generate(&s1, ctx);
|
|
||||||
jpake_send_part(bconn, &s1.p1);
|
|
||||||
jpake_send_part(bconn, &s1.p2);
|
|
||||||
(void)BIO_flush(bconn);
|
|
||||||
JPAKE_STEP1_release(&s1);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_send_step2(BIO *bconn, JPAKE_CTX *ctx)
|
|
||||||
{
|
|
||||||
JPAKE_STEP2 s2;
|
|
||||||
|
|
||||||
JPAKE_STEP2_init(&s2);
|
|
||||||
JPAKE_STEP2_generate(&s2, ctx);
|
|
||||||
jpake_send_part(bconn, &s2);
|
|
||||||
(void)BIO_flush(bconn);
|
|
||||||
JPAKE_STEP2_release(&s2);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_send_step3a(BIO *bconn, JPAKE_CTX *ctx)
|
|
||||||
{
|
|
||||||
JPAKE_STEP3A s3a;
|
|
||||||
|
|
||||||
JPAKE_STEP3A_init(&s3a);
|
|
||||||
JPAKE_STEP3A_generate(&s3a, ctx);
|
|
||||||
BIO_write(bconn, s3a.hhk, sizeof s3a.hhk);
|
|
||||||
(void)BIO_flush(bconn);
|
|
||||||
JPAKE_STEP3A_release(&s3a);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_send_step3b(BIO *bconn, JPAKE_CTX *ctx)
|
|
||||||
{
|
|
||||||
JPAKE_STEP3B s3b;
|
|
||||||
|
|
||||||
JPAKE_STEP3B_init(&s3b);
|
|
||||||
JPAKE_STEP3B_generate(&s3b, ctx);
|
|
||||||
BIO_write(bconn, s3b.hk, sizeof s3b.hk);
|
|
||||||
(void)BIO_flush(bconn);
|
|
||||||
JPAKE_STEP3B_release(&s3b);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void readbn(BIGNUM **bn, BIO *bconn)
|
|
||||||
{
|
|
||||||
char buf[10240];
|
|
||||||
int l;
|
|
||||||
|
|
||||||
l = BIO_gets(bconn, buf, sizeof buf);
|
|
||||||
assert(l > 0);
|
|
||||||
assert(buf[l-1] == '\n');
|
|
||||||
buf[l-1] = '\0';
|
|
||||||
BN_hex2bn(bn, buf);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_receive_part(JPAKE_STEP_PART *p, BIO *bconn)
|
|
||||||
{
|
|
||||||
readbn(&p->gx, bconn);
|
|
||||||
readbn(&p->zkpx.gr, bconn);
|
|
||||||
readbn(&p->zkpx.b, bconn);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_receive_step1(JPAKE_CTX *ctx, BIO *bconn)
|
|
||||||
{
|
|
||||||
JPAKE_STEP1 s1;
|
|
||||||
|
|
||||||
JPAKE_STEP1_init(&s1);
|
|
||||||
jpake_receive_part(&s1.p1, bconn);
|
|
||||||
jpake_receive_part(&s1.p2, bconn);
|
|
||||||
if(!JPAKE_STEP1_process(ctx, &s1))
|
|
||||||
{
|
|
||||||
ERR_print_errors(bio_err);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
JPAKE_STEP1_release(&s1);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_receive_step2(JPAKE_CTX *ctx, BIO *bconn)
|
|
||||||
{
|
|
||||||
JPAKE_STEP2 s2;
|
|
||||||
|
|
||||||
JPAKE_STEP2_init(&s2);
|
|
||||||
jpake_receive_part(&s2, bconn);
|
|
||||||
if(!JPAKE_STEP2_process(ctx, &s2))
|
|
||||||
{
|
|
||||||
ERR_print_errors(bio_err);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
JPAKE_STEP2_release(&s2);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_receive_step3a(JPAKE_CTX *ctx, BIO *bconn)
|
|
||||||
{
|
|
||||||
JPAKE_STEP3A s3a;
|
|
||||||
int l;
|
|
||||||
|
|
||||||
JPAKE_STEP3A_init(&s3a);
|
|
||||||
l = BIO_read(bconn, s3a.hhk, sizeof s3a.hhk);
|
|
||||||
assert(l == sizeof s3a.hhk);
|
|
||||||
if(!JPAKE_STEP3A_process(ctx, &s3a))
|
|
||||||
{
|
|
||||||
ERR_print_errors(bio_err);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
JPAKE_STEP3A_release(&s3a);
|
|
||||||
}
|
|
||||||
|
|
||||||
static void jpake_receive_step3b(JPAKE_CTX *ctx, BIO *bconn)
|
|
||||||
{
|
|
||||||
JPAKE_STEP3B s3b;
|
|
||||||
int l;
|
|
||||||
|
|
||||||
JPAKE_STEP3B_init(&s3b);
|
|
||||||
l = BIO_read(bconn, s3b.hk, sizeof s3b.hk);
|
|
||||||
assert(l == sizeof s3b.hk);
|
|
||||||
if(!JPAKE_STEP3B_process(ctx, &s3b))
|
|
||||||
{
|
|
||||||
ERR_print_errors(bio_err);
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
JPAKE_STEP3B_release(&s3b);
|
|
||||||
}
|
|
||||||
|
|
||||||
void jpake_client_auth(BIO *out, BIO *conn, const char *secret)
|
|
||||||
{
|
|
||||||
JPAKE_CTX *ctx;
|
|
||||||
BIO *bconn;
|
|
||||||
|
|
||||||
BIO_puts(out, "Authenticating with JPAKE\n");
|
|
||||||
|
|
||||||
ctx = jpake_init("client", "server", secret);
|
|
||||||
|
|
||||||
bconn = BIO_new(BIO_f_buffer());
|
|
||||||
BIO_push(bconn, conn);
|
|
||||||
|
|
||||||
jpake_send_step1(bconn, ctx);
|
|
||||||
jpake_receive_step1(ctx, bconn);
|
|
||||||
jpake_send_step2(bconn, ctx);
|
|
||||||
jpake_receive_step2(ctx, bconn);
|
|
||||||
jpake_send_step3a(bconn, ctx);
|
|
||||||
jpake_receive_step3b(ctx, bconn);
|
|
||||||
|
|
||||||
/*
|
|
||||||
* The problem is that you must use the derived key in the
|
|
||||||
* session key or you are subject to man-in-the-middle
|
|
||||||
* attacks.
|
|
||||||
*/
|
|
||||||
BIO_puts(out, "JPAKE authentication succeeded (N.B. This version can"
|
|
||||||
" be MitMed. See the version in HEAD for how to do it"
|
|
||||||
" properly)\n");
|
|
||||||
|
|
||||||
BIO_pop(bconn);
|
|
||||||
BIO_free(bconn);
|
|
||||||
}
|
|
||||||
|
|
||||||
void jpake_server_auth(BIO *out, BIO *conn, const char *secret)
|
|
||||||
{
|
|
||||||
JPAKE_CTX *ctx;
|
|
||||||
BIO *bconn;
|
|
||||||
|
|
||||||
BIO_puts(out, "Authenticating with JPAKE\n");
|
|
||||||
|
|
||||||
ctx = jpake_init("server", "client", secret);
|
|
||||||
|
|
||||||
bconn = BIO_new(BIO_f_buffer());
|
|
||||||
BIO_push(bconn, conn);
|
|
||||||
|
|
||||||
jpake_receive_step1(ctx, bconn);
|
|
||||||
jpake_send_step1(bconn, ctx);
|
|
||||||
jpake_receive_step2(ctx, bconn);
|
|
||||||
jpake_send_step2(bconn, ctx);
|
|
||||||
jpake_receive_step3a(ctx, bconn);
|
|
||||||
jpake_send_step3b(bconn, ctx);
|
|
||||||
|
|
||||||
/*
|
|
||||||
* The problem is that you must use the derived key in the
|
|
||||||
* session key or you are subject to man-in-the-middle
|
|
||||||
* attacks.
|
|
||||||
*/
|
|
||||||
BIO_puts(out, "JPAKE authentication succeeded (N.B. This version can"
|
|
||||||
" be MitMed. See the version in HEAD for how to do it"
|
|
||||||
" properly)\n");
|
|
||||||
|
|
||||||
BIO_pop(bconn);
|
|
||||||
BIO_free(bconn);
|
|
||||||
}
|
|
||||||
|
|
||||||
#endif
|
|
||||||
|
|||||||
@@ -338,10 +338,6 @@ X509_NAME *parse_name(char *str, long chtype, int multirdn);
|
|||||||
int args_verify(char ***pargs, int *pargc,
|
int args_verify(char ***pargs, int *pargc,
|
||||||
int *badarg, BIO *err, X509_VERIFY_PARAM **pm);
|
int *badarg, BIO *err, X509_VERIFY_PARAM **pm);
|
||||||
void policies_print(BIO *out, X509_STORE_CTX *ctx);
|
void policies_print(BIO *out, X509_STORE_CTX *ctx);
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
void jpake_client_auth(BIO *out, BIO *conn, const char *secret);
|
|
||||||
void jpake_server_auth(BIO *out, BIO *conn, const char *secret);
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#define FORMAT_UNDEF 0
|
#define FORMAT_UNDEF 0
|
||||||
#define FORMAT_ASN1 1
|
#define FORMAT_ASN1 1
|
||||||
|
|||||||
@@ -56,7 +56,7 @@
|
|||||||
* [including the GNU Public Licence.]
|
* [including the GNU Public Licence.]
|
||||||
*/
|
*/
|
||||||
|
|
||||||
/* A nice addition from Dr Stephen Henson <steve@openssl.org> to
|
/* A nice addition from Dr Stephen Henson <shenson@bigfoot.com> to
|
||||||
* add the -strparse option which parses nested binary structures
|
* add the -strparse option which parses nested binary structures
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@@ -408,7 +408,6 @@ static int do_generate(BIO *bio, char *genstr, char *genconf, BUF_MEM *buf)
|
|||||||
|
|
||||||
atyp = ASN1_generate_nconf(genstr, cnf);
|
atyp = ASN1_generate_nconf(genstr, cnf);
|
||||||
NCONF_free(cnf);
|
NCONF_free(cnf);
|
||||||
cnf = NULL;
|
|
||||||
|
|
||||||
if (!atyp)
|
if (!atyp)
|
||||||
return -1;
|
return -1;
|
||||||
|
|||||||
76
apps/ca.c
76
apps/ca.c
@@ -83,7 +83,7 @@
|
|||||||
# else
|
# else
|
||||||
# include <unixlib.h>
|
# include <unixlib.h>
|
||||||
# endif
|
# endif
|
||||||
# elif !defined(OPENSSL_SYS_VXWORKS) && !defined(OPENSSL_SYS_WINDOWS) && !defined(OPENSSL_SYS_NETWARE) && !defined(__TANDEM)
|
# elif !defined(OPENSSL_SYS_VXWORKS) && !defined(OPENSSL_SYS_WINDOWS) && !defined(OPENSSL_SYS_NETWARE)
|
||||||
# include <sys/file.h>
|
# include <sys/file.h>
|
||||||
# endif
|
# endif
|
||||||
#endif
|
#endif
|
||||||
@@ -216,6 +216,7 @@ static int certify_spkac(X509 **xret, char *infile,EVP_PKEY *pkey,X509 *x509,
|
|||||||
char *startdate, char *enddate, long days, char *ext_sect,
|
char *startdate, char *enddate, long days, char *ext_sect,
|
||||||
CONF *conf, int verbose, unsigned long certopt,
|
CONF *conf, int verbose, unsigned long certopt,
|
||||||
unsigned long nameopt, int default_op, int ext_copy);
|
unsigned long nameopt, int default_op, int ext_copy);
|
||||||
|
static int fix_data(int nid, int *type);
|
||||||
static void write_new_certificate(BIO *bp, X509 *x, int output_der, int notext);
|
static void write_new_certificate(BIO *bp, X509 *x, int output_der, int notext);
|
||||||
static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, const EVP_MD *dgst,
|
static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, const EVP_MD *dgst,
|
||||||
STACK_OF(CONF_VALUE) *policy, CA_DB *db, BIGNUM *serial,char *subj,unsigned long chtype, int multirdn,
|
STACK_OF(CONF_VALUE) *policy, CA_DB *db, BIGNUM *serial,char *subj,unsigned long chtype, int multirdn,
|
||||||
@@ -226,7 +227,7 @@ static int do_body(X509 **xret, EVP_PKEY *pkey, X509 *x509, const EVP_MD *dgst,
|
|||||||
static int do_revoke(X509 *x509, CA_DB *db, int ext, char *extval);
|
static int do_revoke(X509 *x509, CA_DB *db, int ext, char *extval);
|
||||||
static int get_certificate_status(const char *ser_status, CA_DB *db);
|
static int get_certificate_status(const char *ser_status, CA_DB *db);
|
||||||
static int do_updatedb(CA_DB *db);
|
static int do_updatedb(CA_DB *db);
|
||||||
static int check_time_format(const char *str);
|
static int check_time_format(char *str);
|
||||||
char *make_revocation_str(int rev_type, char *rev_arg);
|
char *make_revocation_str(int rev_type, char *rev_arg);
|
||||||
int make_revoked(X509_REVOKED *rev, const char *str);
|
int make_revoked(X509_REVOKED *rev, const char *str);
|
||||||
int old_entry_print(BIO *bp, ASN1_OBJECT *obj, ASN1_STRING *str);
|
int old_entry_print(BIO *bp, ASN1_OBJECT *obj, ASN1_STRING *str);
|
||||||
@@ -857,8 +858,8 @@ bad:
|
|||||||
perror(outdir);
|
perror(outdir);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
#ifdef S_ISDIR
|
#ifdef S_IFDIR
|
||||||
if (!S_ISDIR(sb.st_mode))
|
if (!(sb.st_mode & S_IFDIR))
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,"%s need to be a directory\n",outdir);
|
BIO_printf(bio_err,"%s need to be a directory\n",outdir);
|
||||||
perror(outdir);
|
perror(outdir);
|
||||||
@@ -894,7 +895,7 @@ bad:
|
|||||||
BIO_printf(bio_err," in entry %d\n", i+1);
|
BIO_printf(bio_err," in entry %d\n", i+1);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
if (!check_time_format(pp[DB_exp_date]))
|
if (!check_time_format((char *)pp[DB_exp_date]))
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,"entry %d: invalid expiry date\n",i+1);
|
BIO_printf(bio_err,"entry %d: invalid expiry date\n",i+1);
|
||||||
goto err;
|
goto err;
|
||||||
@@ -1248,12 +1249,7 @@ bad:
|
|||||||
BIO_printf(bio_err,"\n%d out of %d certificate requests certified, commit? [y/n]",total_done,total);
|
BIO_printf(bio_err,"\n%d out of %d certificate requests certified, commit? [y/n]",total_done,total);
|
||||||
(void)BIO_flush(bio_err);
|
(void)BIO_flush(bio_err);
|
||||||
buf[0][0]='\0';
|
buf[0][0]='\0';
|
||||||
if (!fgets(buf[0],10,stdin))
|
fgets(buf[0],10,stdin);
|
||||||
{
|
|
||||||
BIO_printf(bio_err,"CERTIFICATION CANCELED: I/O error\n");
|
|
||||||
ret=0;
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
if ((buf[0][0] != 'y') && (buf[0][0] != 'Y'))
|
if ((buf[0][0] != 'y') && (buf[0][0] != 'Y'))
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,"CERTIFICATION CANCELED\n");
|
BIO_printf(bio_err,"CERTIFICATION CANCELED\n");
|
||||||
@@ -1582,14 +1578,12 @@ static int certify(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
|
|||||||
{
|
{
|
||||||
ok=0;
|
ok=0;
|
||||||
BIO_printf(bio_err,"Signature verification problems....\n");
|
BIO_printf(bio_err,"Signature verification problems....\n");
|
||||||
ERR_print_errors(bio_err);
|
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
if (i == 0)
|
if (i == 0)
|
||||||
{
|
{
|
||||||
ok=0;
|
ok=0;
|
||||||
BIO_printf(bio_err,"Signature did not match the certificate request\n");
|
BIO_printf(bio_err,"Signature did not match the certificate request\n");
|
||||||
ERR_print_errors(bio_err);
|
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
@@ -2097,7 +2091,7 @@ again2:
|
|||||||
}
|
}
|
||||||
|
|
||||||
BIO_printf(bio_err,"Certificate is to be certified until ");
|
BIO_printf(bio_err,"Certificate is to be certified until ");
|
||||||
ASN1_TIME_print(bio_err,X509_get_notAfter(ret));
|
ASN1_UTCTIME_print(bio_err,X509_get_notAfter(ret));
|
||||||
if (days) BIO_printf(bio_err," (%ld days)",days);
|
if (days) BIO_printf(bio_err," (%ld days)",days);
|
||||||
BIO_printf(bio_err, "\n");
|
BIO_printf(bio_err, "\n");
|
||||||
|
|
||||||
@@ -2107,12 +2101,7 @@ again2:
|
|||||||
BIO_printf(bio_err,"Sign the certificate? [y/n]:");
|
BIO_printf(bio_err,"Sign the certificate? [y/n]:");
|
||||||
(void)BIO_flush(bio_err);
|
(void)BIO_flush(bio_err);
|
||||||
buf[0]='\0';
|
buf[0]='\0';
|
||||||
if (!fgets(buf,sizeof(buf)-1,stdin))
|
fgets(buf,sizeof(buf)-1,stdin);
|
||||||
{
|
|
||||||
BIO_printf(bio_err,"CERTIFICATE WILL NOT BE CERTIFIED: I/O error\n");
|
|
||||||
ok=0;
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
if (!((buf[0] == 'y') || (buf[0] == 'Y')))
|
if (!((buf[0] == 'y') || (buf[0] == 'Y')))
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,"CERTIFICATE WILL NOT BE CERTIFIED\n");
|
BIO_printf(bio_err,"CERTIFICATE WILL NOT BE CERTIFIED\n");
|
||||||
@@ -2328,10 +2317,26 @@ static int certify_spkac(X509 **xret, char *infile, EVP_PKEY *pkey, X509 *x509,
|
|||||||
continue;
|
continue;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!X509_NAME_add_entry_by_NID(n, nid, chtype,
|
/*
|
||||||
(unsigned char *)buf, -1, -1, 0))
|
if ((nid == NID_pkcs9_emailAddress) && (email_dn == 0))
|
||||||
|
continue;
|
||||||
|
*/
|
||||||
|
|
||||||
|
j=ASN1_PRINTABLE_type((unsigned char *)buf,-1);
|
||||||
|
if (fix_data(nid, &j) == 0)
|
||||||
|
{
|
||||||
|
BIO_printf(bio_err,
|
||||||
|
"invalid characters in string %s\n",buf);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
if ((ne=X509_NAME_ENTRY_create_by_NID(&ne,nid,j,
|
||||||
|
(unsigned char *)buf,
|
||||||
|
strlen(buf))) == NULL)
|
||||||
|
goto err;
|
||||||
|
|
||||||
|
if (!X509_NAME_add_entry(n,ne,-1, 0)) goto err;
|
||||||
|
}
|
||||||
if (spki == NULL)
|
if (spki == NULL)
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,"Netscape SPKAC structure not found in %s\n",
|
BIO_printf(bio_err,"Netscape SPKAC structure not found in %s\n",
|
||||||
@@ -2373,17 +2378,29 @@ err:
|
|||||||
return(ok);
|
return(ok);
|
||||||
}
|
}
|
||||||
|
|
||||||
static int check_time_format(const char *str)
|
static int fix_data(int nid, int *type)
|
||||||
{
|
{
|
||||||
ASN1_TIME tm;
|
if (nid == NID_pkcs9_emailAddress)
|
||||||
|
*type=V_ASN1_IA5STRING;
|
||||||
|
if ((nid == NID_commonName) && (*type == V_ASN1_IA5STRING))
|
||||||
|
*type=V_ASN1_T61STRING;
|
||||||
|
if ((nid == NID_pkcs9_challengePassword) && (*type == V_ASN1_IA5STRING))
|
||||||
|
*type=V_ASN1_T61STRING;
|
||||||
|
if ((nid == NID_pkcs9_unstructuredName) && (*type == V_ASN1_T61STRING))
|
||||||
|
return(0);
|
||||||
|
if (nid == NID_pkcs9_unstructuredName)
|
||||||
|
*type=V_ASN1_IA5STRING;
|
||||||
|
return(1);
|
||||||
|
}
|
||||||
|
|
||||||
|
static int check_time_format(char *str)
|
||||||
|
{
|
||||||
|
ASN1_UTCTIME tm;
|
||||||
|
|
||||||
tm.data=(unsigned char *)str;
|
tm.data=(unsigned char *)str;
|
||||||
tm.length=strlen(str);
|
tm.length=strlen(str);
|
||||||
tm.type=V_ASN1_UTCTIME;
|
tm.type=V_ASN1_UTCTIME;
|
||||||
if (ASN1_TIME_check(&tm))
|
return(ASN1_UTCTIME_check(&tm));
|
||||||
return 1;
|
|
||||||
tm.type=V_ASN1_GENERALIZEDTIME;
|
|
||||||
return ASN1_TIME_check(&tm);
|
|
||||||
}
|
}
|
||||||
|
|
||||||
static int do_revoke(X509 *x509, CA_DB *db, int type, char *value)
|
static int do_revoke(X509 *x509, CA_DB *db, int type, char *value)
|
||||||
@@ -2753,9 +2770,6 @@ char *make_revocation_str(int rev_type, char *rev_arg)
|
|||||||
|
|
||||||
revtm = X509_gmtime_adj(NULL, 0);
|
revtm = X509_gmtime_adj(NULL, 0);
|
||||||
|
|
||||||
if (!revtm)
|
|
||||||
return NULL;
|
|
||||||
|
|
||||||
i = revtm->length + 1;
|
i = revtm->length + 1;
|
||||||
|
|
||||||
if (reason) i += strlen(reason) + 1;
|
if (reason) i += strlen(reason) + 1;
|
||||||
|
|||||||
@@ -226,8 +226,6 @@ int MAIN(int argc, char **argv)
|
|||||||
else if (!strcmp(*args,"-camellia256"))
|
else if (!strcmp(*args,"-camellia256"))
|
||||||
cipher = EVP_camellia_256_cbc();
|
cipher = EVP_camellia_256_cbc();
|
||||||
#endif
|
#endif
|
||||||
else if (!strcmp (*args, "-debug_decrypt"))
|
|
||||||
flags |= CMS_DEBUG_DECRYPT;
|
|
||||||
else if (!strcmp (*args, "-text"))
|
else if (!strcmp (*args, "-text"))
|
||||||
flags |= CMS_TEXT;
|
flags |= CMS_TEXT;
|
||||||
else if (!strcmp (*args, "-nointern"))
|
else if (!strcmp (*args, "-nointern"))
|
||||||
@@ -613,7 +611,7 @@ int MAIN(int argc, char **argv)
|
|||||||
BIO_printf (bio_err, "-certsout file certificate output file\n");
|
BIO_printf (bio_err, "-certsout file certificate output file\n");
|
||||||
BIO_printf (bio_err, "-signer file signer certificate file\n");
|
BIO_printf (bio_err, "-signer file signer certificate file\n");
|
||||||
BIO_printf (bio_err, "-recip file recipient certificate file for decryption\n");
|
BIO_printf (bio_err, "-recip file recipient certificate file for decryption\n");
|
||||||
BIO_printf (bio_err, "-keyid use subject key identifier\n");
|
BIO_printf (bio_err, "-skeyid use subject key identifier\n");
|
||||||
BIO_printf (bio_err, "-in file input file\n");
|
BIO_printf (bio_err, "-in file input file\n");
|
||||||
BIO_printf (bio_err, "-inform arg input format SMIME (default), PEM or DER\n");
|
BIO_printf (bio_err, "-inform arg input format SMIME (default), PEM or DER\n");
|
||||||
BIO_printf (bio_err, "-inkey file input private key (if not signer or recipient)\n");
|
BIO_printf (bio_err, "-inkey file input private key (if not signer or recipient)\n");
|
||||||
@@ -1015,8 +1013,6 @@ int MAIN(int argc, char **argv)
|
|||||||
ret = 4;
|
ret = 4;
|
||||||
if (operation == SMIME_DECRYPT)
|
if (operation == SMIME_DECRYPT)
|
||||||
{
|
{
|
||||||
if (flags & CMS_DEBUG_DECRYPT)
|
|
||||||
CMS_decrypt(cms, NULL, NULL, NULL, NULL, flags);
|
|
||||||
|
|
||||||
if (secret_key)
|
if (secret_key)
|
||||||
{
|
{
|
||||||
|
|||||||
21
apps/crl.c
21
apps/crl.c
@@ -85,7 +85,6 @@ static const char *crl_usage[]={
|
|||||||
" -issuer - print issuer DN\n",
|
" -issuer - print issuer DN\n",
|
||||||
" -lastupdate - lastUpdate field\n",
|
" -lastupdate - lastUpdate field\n",
|
||||||
" -nextupdate - nextUpdate field\n",
|
" -nextupdate - nextUpdate field\n",
|
||||||
" -crlnumber - print CRL number\n",
|
|
||||||
" -noout - no CRL output\n",
|
" -noout - no CRL output\n",
|
||||||
" -CAfile name - verify CRL using certificates in file \"name\"\n",
|
" -CAfile name - verify CRL using certificates in file \"name\"\n",
|
||||||
" -CApath dir - verify CRL using certificates in \"dir\"\n",
|
" -CApath dir - verify CRL using certificates in \"dir\"\n",
|
||||||
@@ -108,7 +107,7 @@ int MAIN(int argc, char **argv)
|
|||||||
int informat,outformat;
|
int informat,outformat;
|
||||||
char *infile=NULL,*outfile=NULL;
|
char *infile=NULL,*outfile=NULL;
|
||||||
int hash=0,issuer=0,lastupdate=0,nextupdate=0,noout=0,text=0;
|
int hash=0,issuer=0,lastupdate=0,nextupdate=0,noout=0,text=0;
|
||||||
int fingerprint = 0, crlnumber = 0;
|
int fingerprint = 0;
|
||||||
const char **pp;
|
const char **pp;
|
||||||
X509_STORE *store = NULL;
|
X509_STORE *store = NULL;
|
||||||
X509_STORE_CTX ctx;
|
X509_STORE_CTX ctx;
|
||||||
@@ -207,8 +206,6 @@ int MAIN(int argc, char **argv)
|
|||||||
noout= ++num;
|
noout= ++num;
|
||||||
else if (strcmp(*argv,"-fingerprint") == 0)
|
else if (strcmp(*argv,"-fingerprint") == 0)
|
||||||
fingerprint= ++num;
|
fingerprint= ++num;
|
||||||
else if (strcmp(*argv,"-crlnumber") == 0)
|
|
||||||
crlnumber= ++num;
|
|
||||||
else if ((md_alg=EVP_get_digestbyname(*argv + 1)))
|
else if ((md_alg=EVP_get_digestbyname(*argv + 1)))
|
||||||
{
|
{
|
||||||
/* ok */
|
/* ok */
|
||||||
@@ -284,21 +281,7 @@ bad:
|
|||||||
{
|
{
|
||||||
print_name(bio_out, "issuer=", X509_CRL_get_issuer(x), nmflag);
|
print_name(bio_out, "issuer=", X509_CRL_get_issuer(x), nmflag);
|
||||||
}
|
}
|
||||||
if (crlnumber == i)
|
|
||||||
{
|
|
||||||
ASN1_INTEGER *crlnum;
|
|
||||||
crlnum = X509_CRL_get_ext_d2i(x, NID_crl_number,
|
|
||||||
NULL, NULL);
|
|
||||||
BIO_printf(bio_out,"crlNumber=");
|
|
||||||
if (crlnum)
|
|
||||||
{
|
|
||||||
i2a_ASN1_INTEGER(bio_out, crlnum);
|
|
||||||
ASN1_INTEGER_free(crlnum);
|
|
||||||
}
|
|
||||||
else
|
|
||||||
BIO_puts(bio_out, "<NONE>");
|
|
||||||
BIO_printf(bio_out,"\n");
|
|
||||||
}
|
|
||||||
if (hash == i)
|
if (hash == i)
|
||||||
{
|
{
|
||||||
BIO_printf(bio_out,"%08lx\n",
|
BIO_printf(bio_out,"%08lx\n",
|
||||||
|
|||||||
@@ -142,13 +142,7 @@ int MAIN(int argc, char **argv)
|
|||||||
{
|
{
|
||||||
if (--argc < 1) goto bad;
|
if (--argc < 1) goto bad;
|
||||||
if(!certflst) certflst = sk_new_null();
|
if(!certflst) certflst = sk_new_null();
|
||||||
if (!certflst)
|
sk_push(certflst,*(++argv));
|
||||||
goto end;
|
|
||||||
if (!sk_push(certflst,*(++argv)))
|
|
||||||
{
|
|
||||||
sk_free(certflst);
|
|
||||||
goto end;
|
|
||||||
}
|
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -84,7 +84,7 @@ int MAIN(int argc, char **argv)
|
|||||||
{
|
{
|
||||||
ENGINE *e = NULL;
|
ENGINE *e = NULL;
|
||||||
unsigned char *buf=NULL;
|
unsigned char *buf=NULL;
|
||||||
int i,err=1;
|
int i,err=0;
|
||||||
const EVP_MD *md=NULL,*m;
|
const EVP_MD *md=NULL,*m;
|
||||||
BIO *in=NULL,*inp;
|
BIO *in=NULL,*inp;
|
||||||
BIO *bmd=NULL;
|
BIO *bmd=NULL;
|
||||||
@@ -415,7 +415,6 @@ ERR_load_crypto_strings();
|
|||||||
else
|
else
|
||||||
{
|
{
|
||||||
name=OBJ_nid2sn(md->type);
|
name=OBJ_nid2sn(md->type);
|
||||||
err = 0;
|
|
||||||
for (i=0; i<argc; i++)
|
for (i=0; i<argc; i++)
|
||||||
{
|
{
|
||||||
char *tmp,*tofree=NULL;
|
char *tmp,*tofree=NULL;
|
||||||
|
|||||||
@@ -88,6 +88,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
DH *dh=NULL;
|
DH *dh=NULL;
|
||||||
int i,badops=0,text=0;
|
int i,badops=0,text=0;
|
||||||
BIO *in=NULL,*out=NULL;
|
BIO *in=NULL,*out=NULL;
|
||||||
@@ -186,7 +189,7 @@ bad:
|
|||||||
ERR_load_crypto_strings();
|
ERR_load_crypto_strings();
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
in=BIO_new(BIO_s_file());
|
in=BIO_new(BIO_s_file());
|
||||||
|
|||||||
@@ -149,6 +149,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
DH *dh=NULL;
|
DH *dh=NULL;
|
||||||
int i,badops=0,text=0;
|
int i,badops=0,text=0;
|
||||||
#ifndef OPENSSL_NO_DSA
|
#ifndef OPENSSL_NO_DSA
|
||||||
@@ -267,7 +270,7 @@ bad:
|
|||||||
ERR_load_crypto_strings();
|
ERR_load_crypto_strings();
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if (g && !num)
|
if (g && !num)
|
||||||
@@ -332,6 +335,7 @@ bad:
|
|||||||
BIO_printf(bio_err,"This is going to take a long time\n");
|
BIO_printf(bio_err,"This is going to take a long time\n");
|
||||||
if(!dh || !DH_generate_parameters_ex(dh, num, g, &cb))
|
if(!dh || !DH_generate_parameters_ex(dh, num, g, &cb))
|
||||||
{
|
{
|
||||||
|
if(dh) DH_free(dh);
|
||||||
ERR_print_errors(bio_err);
|
ERR_print_errors(bio_err);
|
||||||
goto end;
|
goto end;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -65,11 +65,11 @@
|
|||||||
#include "apps.h"
|
#include "apps.h"
|
||||||
#include <openssl/bio.h>
|
#include <openssl/bio.h>
|
||||||
#include <openssl/err.h>
|
#include <openssl/err.h>
|
||||||
|
#include <openssl/dsa.h>
|
||||||
#include <openssl/evp.h>
|
#include <openssl/evp.h>
|
||||||
#include <openssl/x509.h>
|
#include <openssl/x509.h>
|
||||||
#include <openssl/pem.h>
|
#include <openssl/pem.h>
|
||||||
#include <openssl/bn.h>
|
#include <openssl/bn.h>
|
||||||
#include <openssl/dsa.h>
|
|
||||||
|
|
||||||
#undef PROG
|
#undef PROG
|
||||||
#define PROG dsa_main
|
#define PROG dsa_main
|
||||||
@@ -96,7 +96,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
ENGINE *e = NULL;
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
int ret=1;
|
int ret=1;
|
||||||
DSA *dsa=NULL;
|
DSA *dsa=NULL;
|
||||||
int i,badops=0;
|
int i,badops=0;
|
||||||
|
|||||||
@@ -111,6 +111,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
DSA *dsa=NULL;
|
DSA *dsa=NULL;
|
||||||
int i,badops=0,text=0;
|
int i,badops=0,text=0;
|
||||||
BIO *in=NULL,*out=NULL;
|
BIO *in=NULL,*out=NULL;
|
||||||
@@ -275,7 +278,7 @@ bad:
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if (need_rand)
|
if (need_rand)
|
||||||
@@ -354,10 +357,12 @@ bad:
|
|||||||
if (C)
|
if (C)
|
||||||
{
|
{
|
||||||
unsigned char *data;
|
unsigned char *data;
|
||||||
int l,len,bits_p;
|
int l,len,bits_p,bits_q,bits_g;
|
||||||
|
|
||||||
len=BN_num_bytes(dsa->p);
|
len=BN_num_bytes(dsa->p);
|
||||||
bits_p=BN_num_bits(dsa->p);
|
bits_p=BN_num_bits(dsa->p);
|
||||||
|
bits_q=BN_num_bits(dsa->q);
|
||||||
|
bits_g=BN_num_bits(dsa->g);
|
||||||
data=(unsigned char *)OPENSSL_malloc(len+20);
|
data=(unsigned char *)OPENSSL_malloc(len+20);
|
||||||
if (data == NULL)
|
if (data == NULL)
|
||||||
{
|
{
|
||||||
@@ -470,10 +475,4 @@ static int MS_CALLBACK dsa_cb(int p, int n, BN_GENCB *cb)
|
|||||||
#endif
|
#endif
|
||||||
return 1;
|
return 1;
|
||||||
}
|
}
|
||||||
#else /* !OPENSSL_NO_DSA */
|
|
||||||
|
|
||||||
# if PEDANTIC
|
|
||||||
static void *dummy=&dummy;
|
|
||||||
# endif
|
|
||||||
|
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
@@ -85,6 +85,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
int ret = 1;
|
int ret = 1;
|
||||||
EC_KEY *eckey = NULL;
|
EC_KEY *eckey = NULL;
|
||||||
const EC_GROUP *group;
|
const EC_GROUP *group;
|
||||||
@@ -251,7 +254,7 @@ bad:
|
|||||||
ERR_load_crypto_strings();
|
ERR_load_crypto_strings();
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if(!app_passwd(bio_err, passargin, passargout, &passin, &passout))
|
if(!app_passwd(bio_err, passargin, passargout, &passin, &passout))
|
||||||
|
|||||||
@@ -129,6 +129,9 @@ int MAIN(int argc, char **argv)
|
|||||||
char *infile = NULL, *outfile = NULL, *prog;
|
char *infile = NULL, *outfile = NULL, *prog;
|
||||||
BIO *in = NULL, *out = NULL;
|
BIO *in = NULL, *out = NULL;
|
||||||
int informat, outformat, noout = 0, C = 0, ret = 1;
|
int informat, outformat, noout = 0, C = 0, ret = 1;
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
char *engine = NULL;
|
char *engine = NULL;
|
||||||
|
|
||||||
BIGNUM *ec_p = NULL, *ec_a = NULL, *ec_b = NULL,
|
BIGNUM *ec_p = NULL, *ec_a = NULL, *ec_b = NULL,
|
||||||
@@ -337,7 +340,7 @@ bad:
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if (list_curves)
|
if (list_curves)
|
||||||
|
|||||||
15
apps/enc.c
15
apps/enc.c
@@ -100,6 +100,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
static const char magic[]="Salted__";
|
static const char magic[]="Salted__";
|
||||||
char mbuf[sizeof magic-1];
|
char mbuf[sizeof magic-1];
|
||||||
char *strbuf=NULL;
|
char *strbuf=NULL;
|
||||||
@@ -223,12 +226,7 @@ int MAIN(int argc, char **argv)
|
|||||||
goto bad;
|
goto bad;
|
||||||
}
|
}
|
||||||
buf[0]='\0';
|
buf[0]='\0';
|
||||||
if (!fgets(buf,sizeof buf,infile))
|
fgets(buf,sizeof buf,infile);
|
||||||
{
|
|
||||||
BIO_printf(bio_err,"unable to read key from '%s'\n",
|
|
||||||
file);
|
|
||||||
goto bad;
|
|
||||||
}
|
|
||||||
fclose(infile);
|
fclose(infile);
|
||||||
i=strlen(buf);
|
i=strlen(buf);
|
||||||
if ((i > 0) &&
|
if ((i > 0) &&
|
||||||
@@ -308,7 +306,7 @@ bad:
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if (md && (dgst=EVP_get_digestbyname(md)) == NULL)
|
if (md && (dgst=EVP_get_digestbyname(md)) == NULL)
|
||||||
@@ -535,8 +533,7 @@ bad:
|
|||||||
BIO_printf(bio_err,"invalid hex iv value\n");
|
BIO_printf(bio_err,"invalid hex iv value\n");
|
||||||
goto end;
|
goto end;
|
||||||
}
|
}
|
||||||
if ((hiv == NULL) && (str == NULL)
|
if ((hiv == NULL) && (str == NULL))
|
||||||
&& EVP_CIPHER_iv_length(cipher) != 0)
|
|
||||||
{
|
{
|
||||||
/* No IV was explicitly set and no IV was generated
|
/* No IV was explicitly set and no IV was generated
|
||||||
* during EVP_BytesToKey. Hence the IV is undefined,
|
* during EVP_BytesToKey. Hence the IV is undefined,
|
||||||
|
|||||||
@@ -56,6 +56,7 @@
|
|||||||
*
|
*
|
||||||
*/
|
*/
|
||||||
|
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <stdlib.h>
|
#include <stdlib.h>
|
||||||
@@ -65,7 +66,6 @@
|
|||||||
#endif
|
#endif
|
||||||
#include "apps.h"
|
#include "apps.h"
|
||||||
#include <openssl/err.h>
|
#include <openssl/err.h>
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
|
||||||
#include <openssl/engine.h>
|
#include <openssl/engine.h>
|
||||||
#include <openssl/ssl.h>
|
#include <openssl/ssl.h>
|
||||||
|
|
||||||
@@ -252,7 +252,7 @@ static int util_verbose(ENGINE *e, int verbose, BIO *bio_out, const char *indent
|
|||||||
/* Now decide on the output */
|
/* Now decide on the output */
|
||||||
if(xpos == 0)
|
if(xpos == 0)
|
||||||
/* Do an indent */
|
/* Do an indent */
|
||||||
xpos = BIO_puts(bio_out, indent);
|
xpos = BIO_printf(bio_out, indent);
|
||||||
else
|
else
|
||||||
/* Otherwise prepend a ", " */
|
/* Otherwise prepend a ", " */
|
||||||
xpos += BIO_printf(bio_out, ", ");
|
xpos += BIO_printf(bio_out, ", ");
|
||||||
@@ -263,7 +263,7 @@ static int util_verbose(ENGINE *e, int verbose, BIO *bio_out, const char *indent
|
|||||||
(xpos + (int)strlen(name) > line_wrap))
|
(xpos + (int)strlen(name) > line_wrap))
|
||||||
{
|
{
|
||||||
BIO_printf(bio_out, "\n");
|
BIO_printf(bio_out, "\n");
|
||||||
xpos = BIO_puts(bio_out, indent);
|
xpos = BIO_printf(bio_out, indent);
|
||||||
}
|
}
|
||||||
xpos += BIO_printf(bio_out, "%s", name);
|
xpos += BIO_printf(bio_out, "%s", name);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -89,6 +89,9 @@ int MAIN(int, char **);
|
|||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
BN_GENCB cb;
|
BN_GENCB cb;
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
DH *dh=NULL;
|
DH *dh=NULL;
|
||||||
int ret=1,num=DEFBITS;
|
int ret=1,num=DEFBITS;
|
||||||
int g=2;
|
int g=2;
|
||||||
@@ -160,7 +163,7 @@ bad:
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
out=BIO_new(BIO_s_file());
|
out=BIO_new(BIO_s_file());
|
||||||
|
|||||||
@@ -78,6 +78,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
DSA *dsa=NULL;
|
DSA *dsa=NULL;
|
||||||
int ret=1;
|
int ret=1;
|
||||||
char *outfile=NULL;
|
char *outfile=NULL;
|
||||||
@@ -203,7 +206,7 @@ bad:
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if(!app_passwd(bio_err, NULL, passargout, NULL, &passout)) {
|
if(!app_passwd(bio_err, NULL, passargout, NULL, &passout)) {
|
||||||
@@ -276,10 +279,4 @@ end:
|
|||||||
apps_shutdown();
|
apps_shutdown();
|
||||||
OPENSSL_EXIT(ret);
|
OPENSSL_EXIT(ret);
|
||||||
}
|
}
|
||||||
#else /* !OPENSSL_NO_DSA */
|
|
||||||
|
|
||||||
# if PEDANTIC
|
|
||||||
static void *dummy=&dummy;
|
|
||||||
# endif
|
|
||||||
|
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
@@ -89,6 +89,9 @@ int MAIN(int, char **);
|
|||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
BN_GENCB cb;
|
BN_GENCB cb;
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
int ret=1;
|
int ret=1;
|
||||||
int i,num=DEFBITS;
|
int i,num=DEFBITS;
|
||||||
long l;
|
long l;
|
||||||
@@ -103,9 +106,9 @@ int MAIN(int argc, char **argv)
|
|||||||
char *inrand=NULL;
|
char *inrand=NULL;
|
||||||
BIO *out=NULL;
|
BIO *out=NULL;
|
||||||
BIGNUM *bn = BN_new();
|
BIGNUM *bn = BN_new();
|
||||||
RSA *rsa = NULL;
|
RSA *rsa = RSA_new();
|
||||||
|
|
||||||
if(!bn) goto err;
|
if(!bn || !rsa) goto err;
|
||||||
|
|
||||||
apps_startup();
|
apps_startup();
|
||||||
BN_GENCB_set(&cb, genrsa_cb, bio_err);
|
BN_GENCB_set(&cb, genrsa_cb, bio_err);
|
||||||
@@ -232,7 +235,7 @@ bad:
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if (outfile == NULL)
|
if (outfile == NULL)
|
||||||
@@ -266,10 +269,6 @@ bad:
|
|||||||
BIO_printf(bio_err,"Generating RSA private key, %d bit long modulus\n",
|
BIO_printf(bio_err,"Generating RSA private key, %d bit long modulus\n",
|
||||||
num);
|
num);
|
||||||
|
|
||||||
rsa = RSA_new();
|
|
||||||
if (!rsa)
|
|
||||||
goto err;
|
|
||||||
|
|
||||||
if (use_x931)
|
if (use_x931)
|
||||||
{
|
{
|
||||||
BIGNUM *pubexp;
|
BIGNUM *pubexp;
|
||||||
|
|||||||
@@ -5,23 +5,13 @@ $! Time of creation: 22-MAY-1998 10:13
|
|||||||
$!
|
$!
|
||||||
$! P1 root of the directory tree
|
$! P1 root of the directory tree
|
||||||
$!
|
$!
|
||||||
$
|
|
||||||
$ IF P1 .EQS. ""
|
$ IF P1 .EQS. ""
|
||||||
$ THEN
|
$ THEN
|
||||||
$ WRITE SYS$OUTPUT "First argument missing."
|
$ WRITE SYS$OUTPUT "First argument missing."
|
||||||
$ WRITE SYS$OUTPUT -
|
$ WRITE SYS$OUTPUT "Should be the directory where you want things installed."
|
||||||
"Should be the directory where you want things installed."
|
|
||||||
$ EXIT
|
$ EXIT
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$
|
$
|
||||||
$ IF (F$GETSYI("CPU").LT.128)
|
|
||||||
$ THEN
|
|
||||||
$ ARCH := VAX
|
|
||||||
$ ELSE
|
|
||||||
$ ARCH = F$EDIT( F$GETSYI( "ARCH_NAME"), "UPCASE")
|
|
||||||
$ IF (ARCH .EQS. "") THEN ARCH = "UNK"
|
|
||||||
$ ENDIF
|
|
||||||
$
|
|
||||||
$ ROOT = F$PARSE(P1,"[]A.;0",,,"SYNTAX_ONLY,NO_CONCEAL") - "A.;0"
|
$ ROOT = F$PARSE(P1,"[]A.;0",,,"SYNTAX_ONLY,NO_CONCEAL") - "A.;0"
|
||||||
$ ROOT_DEV = F$PARSE(ROOT,,,"DEVICE","SYNTAX_ONLY")
|
$ ROOT_DEV = F$PARSE(ROOT,,,"DEVICE","SYNTAX_ONLY")
|
||||||
$ ROOT_DIR = F$PARSE(ROOT,,,"DIRECTORY","SYNTAX_ONLY") -
|
$ ROOT_DIR = F$PARSE(ROOT,,,"DIRECTORY","SYNTAX_ONLY") -
|
||||||
@@ -29,16 +19,23 @@ $ ROOT_DIR = F$PARSE(ROOT,,,"DIRECTORY","SYNTAX_ONLY") -
|
|||||||
$ ROOT = ROOT_DEV + "[" + ROOT_DIR
|
$ ROOT = ROOT_DEV + "[" + ROOT_DIR
|
||||||
$
|
$
|
||||||
$ DEFINE/NOLOG WRK_SSLROOT 'ROOT'.] /TRANS=CONC
|
$ DEFINE/NOLOG WRK_SSLROOT 'ROOT'.] /TRANS=CONC
|
||||||
$ DEFINE/NOLOG WRK_SSLEXE WRK_SSLROOT:['ARCH'_EXE]
|
$ DEFINE/NOLOG WRK_SSLVEXE WRK_SSLROOT:[VAX_EXE]
|
||||||
|
$ DEFINE/NOLOG WRK_SSLAEXE WRK_SSLROOT:[ALPHA_EXE]
|
||||||
|
$ DEFINE/NOLOG WRK_SSLLIB WRK_SSLROOT:[LIB]
|
||||||
$
|
$
|
||||||
$ IF F$PARSE("WRK_SSLROOT:[000000]") .EQS. "" THEN -
|
$ IF F$PARSE("WRK_SSLROOT:[000000]") .EQS. "" THEN -
|
||||||
CREATE/DIR/LOG WRK_SSLROOT:[000000]
|
CREATE/DIR/LOG WRK_SSLROOT:[000000]
|
||||||
$ IF F$PARSE("WRK_SSLEXE:") .EQS. "" THEN -
|
$ IF F$PARSE("WRK_SSLVEXE:") .EQS. "" THEN -
|
||||||
CREATE/DIR/LOG WRK_SSLEXE:
|
CREATE/DIR/LOG WRK_SSLVEXE:
|
||||||
|
$ IF F$PARSE("WRK_SSLAEXE:") .EQS. "" THEN -
|
||||||
|
CREATE/DIR/LOG WRK_SSLAEXE:
|
||||||
|
$ IF F$PARSE("WRK_SSLLIB:") .EQS. "" THEN -
|
||||||
|
CREATE/DIR/LOG WRK_SSLLIB:
|
||||||
$
|
$
|
||||||
$ EXE := openssl
|
$ EXE := openssl
|
||||||
$
|
$
|
||||||
$ EXE_DIR := [-.'ARCH'.EXE.APPS]
|
$ VEXE_DIR := [-.VAX.EXE.APPS]
|
||||||
|
$ AEXE_DIR := [-.AXP.EXE.APPS]
|
||||||
$
|
$
|
||||||
$ I = 0
|
$ I = 0
|
||||||
$ LOOP_EXE:
|
$ LOOP_EXE:
|
||||||
@@ -46,18 +43,25 @@ $ E = F$EDIT(F$ELEMENT(I, ",", EXE),"TRIM")
|
|||||||
$ I = I + 1
|
$ I = I + 1
|
||||||
$ IF E .EQS. "," THEN GOTO LOOP_EXE_END
|
$ IF E .EQS. "," THEN GOTO LOOP_EXE_END
|
||||||
$ SET NOON
|
$ SET NOON
|
||||||
$ IF F$SEARCH(EXE_DIR+E+".EXE") .NES. ""
|
$ IF F$SEARCH(VEXE_DIR+E+".EXE") .NES. ""
|
||||||
$ THEN
|
$ THEN
|
||||||
$ COPY 'EXE_DIR''E'.EXE WRK_SSLEXE:'E'.EXE/log
|
$ COPY 'VEXE_DIR''E'.EXE WRK_SSLVEXE:'E'.EXE/log
|
||||||
$ SET FILE/PROT=W:RE WRK_SSLEXE:'E'.EXE
|
$ SET FILE/PROT=W:RE WRK_SSLVEXE:'E'.EXE
|
||||||
|
$ ENDIF
|
||||||
|
$ IF F$SEARCH(AEXE_DIR+E+".EXE") .NES. ""
|
||||||
|
$ THEN
|
||||||
|
$ COPY 'AEXE_DIR''E'.EXE WRK_SSLAEXE:'E'.EXE/log
|
||||||
|
$ SET FILE/PROT=W:RE WRK_SSLAEXE:'E'.EXE
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$ SET ON
|
$ SET ON
|
||||||
$ GOTO LOOP_EXE
|
$ GOTO LOOP_EXE
|
||||||
$ LOOP_EXE_END:
|
$ LOOP_EXE_END:
|
||||||
$
|
$
|
||||||
$ SET NOON
|
$ SET NOON
|
||||||
$ COPY CA.COM WRK_SSLEXE:CA.COM/LOG
|
$ COPY CA.COM WRK_SSLAEXE:CA.COM/LOG
|
||||||
$ SET FILE/PROT=W:RE WRK_SSLEXE:CA.COM
|
$ SET FILE/PROT=W:RE WRK_SSLAEXE:CA.COM
|
||||||
|
$ COPY CA.COM WRK_SSLVEXE:CA.COM/LOG
|
||||||
|
$ SET FILE/PROT=W:RE WRK_SSLVEXE:CA.COM
|
||||||
$ COPY OPENSSL-VMS.CNF WRK_SSLROOT:[000000]OPENSSL.CNF/LOG
|
$ COPY OPENSSL-VMS.CNF WRK_SSLROOT:[000000]OPENSSL.CNF/LOG
|
||||||
$ SET FILE/PROT=W:R WRK_SSLROOT:[000000]OPENSSL.CNF
|
$ SET FILE/PROT=W:R WRK_SSLROOT:[000000]OPENSSL.CNF
|
||||||
$ SET ON
|
$ SET ON
|
||||||
|
|||||||
@@ -6,12 +6,11 @@ $! A-Com Computing, Inc.
|
|||||||
$! byer@mail.all-net.net
|
$! byer@mail.all-net.net
|
||||||
$!
|
$!
|
||||||
$! Changes by Richard Levitte <richard@levitte.org>
|
$! Changes by Richard Levitte <richard@levitte.org>
|
||||||
$! Zoltan Arpadffy <zoli@polarhome.com>
|
|
||||||
$!
|
$!
|
||||||
$! This command files compiles and creates all the various different
|
$! This command files compiles and creates all the various different
|
||||||
$! "application" programs for the different types of encryption for OpenSSL.
|
$! "application" programs for the different types of encryption for OpenSSL.
|
||||||
$! The EXE's are placed in the directory [.xxx.EXE.APPS] where "xxx" denotes
|
$! The EXE's are placed in the directory [.xxx.EXE.APPS] where "xxx" denotes
|
||||||
$! ALPHA, IA64 or VAX, depending on your machine architecture.
|
$! either AXP or VAX depending on your machine architecture.
|
||||||
$!
|
$!
|
||||||
$! It was written so it would try to determine what "C" compiler to
|
$! It was written so it would try to determine what "C" compiler to
|
||||||
$! use or you can specify which "C" compiler to use.
|
$! use or you can specify which "C" compiler to use.
|
||||||
@@ -47,21 +46,20 @@ $ TCPIP_LIB = ""
|
|||||||
$!
|
$!
|
||||||
$! Check What Architecture We Are Using.
|
$! Check What Architecture We Are Using.
|
||||||
$!
|
$!
|
||||||
$ IF (F$GETSYI("CPU").LT.128)
|
$ IF (F$GETSYI("CPU").GE.128)
|
||||||
$ THEN
|
$ THEN
|
||||||
$!
|
$!
|
||||||
$! The Architecture Is VAX.
|
$! The Architecture Is AXP.
|
||||||
$!
|
$!
|
||||||
$ ARCH := VAX
|
$ ARCH := AXP
|
||||||
$!
|
$!
|
||||||
$! Else...
|
$! Else...
|
||||||
$!
|
$!
|
||||||
$ ELSE
|
$ ELSE
|
||||||
$!
|
$!
|
||||||
$! The Architecture Is Alpha, IA64 or whatever comes in the future.
|
$! The Architecture Is VAX.
|
||||||
$!
|
$!
|
||||||
$ ARCH = F$EDIT( F$GETSYI( "ARCH_NAME"), "UPCASE")
|
$ ARCH := VAX
|
||||||
$ IF (ARCH .EQS. "") THEN ARCH = "UNK"
|
|
||||||
$!
|
$!
|
||||||
$! End The Architecture Check.
|
$! End The Architecture Check.
|
||||||
$!
|
$!
|
||||||
@@ -70,22 +68,10 @@ $!
|
|||||||
$! Define what programs should be compiled
|
$! Define what programs should be compiled
|
||||||
$!
|
$!
|
||||||
$ PROGRAMS := OPENSSL
|
$ PROGRAMS := OPENSSL
|
||||||
$!
|
$!$ PROGRAMS := VERIFY,ASN1PARS,REQ,DGST,DH,ENC,PASSWD,GENDH,ERRSTR,CA,CRL,-
|
||||||
$! Define The CRYPTO Library.
|
$! RSA,DSA,DSAPARAM,-
|
||||||
$!
|
$! X509,GENRSA,GENDSA,S_SERVER,S_CLIENT,SPEED,-
|
||||||
$ CRYPTO_LIB := SYS$DISK:[-.'ARCH'.EXE.CRYPTO]LIBCRYPTO.OLB
|
$! S_TIME,VERSION,PKCS7,CRL2P7,SESS_ID,CIPHERS,NSEQ,
|
||||||
$!
|
|
||||||
$! Define The SSL Library.
|
|
||||||
$!
|
|
||||||
$ SSL_LIB := SYS$DISK:[-.'ARCH'.EXE.SSL]LIBSSL.OLB
|
|
||||||
$!
|
|
||||||
$! Define The OBJ Directory.
|
|
||||||
$!
|
|
||||||
$ OBJ_DIR := SYS$DISK:[-.'ARCH'.OBJ.APPS]
|
|
||||||
$!
|
|
||||||
$! Define The EXE Directory.
|
|
||||||
$!
|
|
||||||
$ EXE_DIR := SYS$DISK:[-.'ARCH'.EXE.APPS]
|
|
||||||
$!
|
$!
|
||||||
$! Check To Make Sure We Have Valid Command Line Parameters.
|
$! Check To Make Sure We Have Valid Command Line Parameters.
|
||||||
$!
|
$!
|
||||||
@@ -99,6 +85,18 @@ $! Tell The User What Kind of Machine We Run On.
|
|||||||
$!
|
$!
|
||||||
$ WRITE SYS$OUTPUT "Compiling On A ",ARCH," Machine."
|
$ WRITE SYS$OUTPUT "Compiling On A ",ARCH," Machine."
|
||||||
$!
|
$!
|
||||||
|
$! Define The CRYPTO Library.
|
||||||
|
$!
|
||||||
|
$ CRYPTO_LIB := SYS$DISK:[-.'ARCH'.EXE.CRYPTO]LIBCRYPTO.OLB
|
||||||
|
$!
|
||||||
|
$! Define The SSL Library.
|
||||||
|
$!
|
||||||
|
$ SSL_LIB := SYS$DISK:[-.'ARCH'.EXE.SSL]LIBSSL.OLB
|
||||||
|
$!
|
||||||
|
$! Define The OBJ Directory.
|
||||||
|
$!
|
||||||
|
$ OBJ_DIR := SYS$DISK:[-.'ARCH'.OBJ.APPS]
|
||||||
|
$!
|
||||||
$! Check To See If The OBJ Directory Exists.
|
$! Check To See If The OBJ Directory Exists.
|
||||||
$!
|
$!
|
||||||
$ IF (F$PARSE(OBJ_DIR).EQS."")
|
$ IF (F$PARSE(OBJ_DIR).EQS."")
|
||||||
@@ -112,6 +110,10 @@ $! End The OBJ Directory Check.
|
|||||||
$!
|
$!
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$!
|
$!
|
||||||
|
$! Define The EXE Directory.
|
||||||
|
$!
|
||||||
|
$ EXE_DIR := SYS$DISK:[-.'ARCH'.EXE.APPS]
|
||||||
|
$!
|
||||||
$! Check To See If The EXE Directory Exists.
|
$! Check To See If The EXE Directory Exists.
|
||||||
$!
|
$!
|
||||||
$ IF (F$PARSE(EXE_DIR).EQS."")
|
$ IF (F$PARSE(EXE_DIR).EQS."")
|
||||||
@@ -134,101 +136,64 @@ $!
|
|||||||
$ GOSUB CHECK_OPT_FILE
|
$ GOSUB CHECK_OPT_FILE
|
||||||
$!
|
$!
|
||||||
$! Define The Application Files.
|
$! Define The Application Files.
|
||||||
$! NOTE: Some might think this list ugly. However, it's made this way to
|
|
||||||
$! reflect the E_OBJ variable in Makefile as closely as possible, thereby
|
|
||||||
$! making it fairly easy to verify that the lists are the same.
|
|
||||||
$!
|
$!
|
||||||
$ LIB_OPENSSL = "VERIFY,ASN1PARS,REQ,DGST,DH,DHPARAM,ENC,PASSWD,GENDH,ERRSTR,"+-
|
$ LIB_FILES = "VERIFY;ASN1PARS;REQ;DGST;DH;DHPARAM;ENC;PASSWD;GENDH;ERRSTR;"+-
|
||||||
"CA,PKCS7,CRL2P7,CRL,"+-
|
"CA;PKCS7;CRL2P7;CRL;"+-
|
||||||
"RSA,RSAUTL,DSA,DSAPARAM,EC,ECPARAM,"+-
|
"RSA;RSAUTL;DSA;DSAPARAM;EC;ECPARAM;"+-
|
||||||
"X509,GENRSA,GENDSA,S_SERVER,S_CLIENT,SPEED,"+-
|
"X509;GENRSA;GENDSA;S_SERVER;S_CLIENT;SPEED;"+-
|
||||||
"S_TIME,APPS,S_CB,S_SOCKET,APP_RAND,VERSION,SESS_ID,"+-
|
"S_TIME;APPS;S_CB;S_SOCKET;APP_RAND;VERSION;SESS_ID;"+-
|
||||||
"CIPHERS,NSEQ,PKCS12,PKCS8,SPKAC,SMIME,RAND,ENGINE,"+-
|
"CIPHERS;NSEQ;PKCS12;PKCS8;SPKAC;SMIME;RAND;ENGINE;OCSP;PRIME"
|
||||||
"OCSP,PRIME,CMS"
|
|
||||||
$ TCPIP_PROGRAMS = ",,"
|
$ TCPIP_PROGRAMS = ",,"
|
||||||
$ IF COMPILER .EQS. "VAXC" THEN -
|
$ IF COMPILER .EQS. "VAXC" THEN -
|
||||||
TCPIP_PROGRAMS = ",OPENSSL,"
|
TCPIP_PROGRAMS = ",OPENSSL,"
|
||||||
$!
|
$!
|
||||||
$! Setup exceptional compilations
|
$! Setup exceptional compilations
|
||||||
$!
|
$!
|
||||||
$ COMPILEWITH_CC2 = ",S_SOCKET,S_SERVER,S_CLIENT,"
|
$ COMPILEWITH_CC2 = ",S_SERVER,S_CLIENT,"
|
||||||
$!
|
$!
|
||||||
$ PHASE := LIB
|
$ PHASE := LIB
|
||||||
$!
|
$!
|
||||||
$ RESTART:
|
$ RESTART:
|
||||||
$!
|
$!
|
||||||
$! Define An App Counter And Set It To "0".
|
$! Define A File Counter And Set It To "0".
|
||||||
$!
|
$!
|
||||||
$ APP_COUNTER = 0
|
$ FILE_COUNTER = 0
|
||||||
$!
|
$!
|
||||||
$! Top Of The App Loop.
|
$! Top Of The File Loop.
|
||||||
$!
|
$!
|
||||||
$ NEXT_APP:
|
$ NEXT_FILE:
|
||||||
$!
|
$!
|
||||||
$! Make The Application File Name
|
$! O.K, Extract The File Name From The File List.
|
||||||
$!
|
$!
|
||||||
$ CURRENT_APP = F$EDIT(F$ELEMENT(APP_COUNTER,",",PROGRAMS),"TRIM")
|
$ FILE_NAME0 = F$EDIT(F$ELEMENT(FILE_COUNTER,";",'PHASE'_FILES),"TRIM")
|
||||||
$!
|
$ FILE_NAME = F$EDIT(F$ELEMENT(0,",",FILE_NAME0),"TRIM")
|
||||||
$! Create The Executable File Name.
|
$ EXTRA_OBJ = FILE_NAME0 - FILE_NAME
|
||||||
$!
|
|
||||||
$ EXE_FILE = EXE_DIR + CURRENT_APP + ".EXE"
|
|
||||||
$!
|
$!
|
||||||
$! Check To See If We Are At The End Of The File List.
|
$! Check To See If We Are At The End Of The File List.
|
||||||
$!
|
$!
|
||||||
$ IF (CURRENT_APP.EQS.",")
|
$ IF (FILE_NAME0.EQS.";")
|
||||||
$ THEN
|
$ THEN
|
||||||
$ IF (PHASE.EQS."LIB")
|
$ IF (PHASE.EQS."LIB")
|
||||||
$ THEN
|
$ THEN
|
||||||
$ PHASE := APP
|
$ PHASE := APP
|
||||||
$ GOTO RESTART
|
$ GOTO RESTART
|
||||||
$ ELSE
|
$ ELSE
|
||||||
$ GOTO APP_DONE
|
$ GOTO FILE_DONE
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$!
|
$!
|
||||||
$! Increment The Counter.
|
$! Increment The Counter.
|
||||||
$!
|
$!
|
||||||
$ APP_COUNTER = APP_COUNTER + 1
|
$ FILE_COUNTER = FILE_COUNTER + 1
|
||||||
$!
|
$!
|
||||||
$! Decide if we're building the object files or not.
|
$! Check to see if this program should actually be compiled
|
||||||
$!
|
$!
|
||||||
$ IF (PHASE.EQS."LIB")
|
$ IF PHASE .EQS. "APP" .AND. -
|
||||||
|
","+PROGRAMS+"," - (","+F$EDIT(FILE_NAME,"UPCASE")+",") .EQS. ","+PROGRAMS+","
|
||||||
$ THEN
|
$ THEN
|
||||||
$!
|
$ GOTO NEXT_FILE
|
||||||
$! Define A Library File Counter And Set It To "-1".
|
|
||||||
$! -1 Means The Application File Name Is To Be Used.
|
|
||||||
$!
|
|
||||||
$ LIB_COUNTER = -1
|
|
||||||
$!
|
|
||||||
$! Create a .OPT file for the object files
|
|
||||||
$!
|
|
||||||
$ OPEN/WRITE OBJECTS 'EXE_DIR''CURRENT_APP'.OPT
|
|
||||||
$!
|
|
||||||
$! Top Of The File Loop.
|
|
||||||
$!
|
|
||||||
$ NEXT_LIB:
|
|
||||||
$!
|
|
||||||
$! O.K, Extract The File Name From The File List.
|
|
||||||
$!
|
|
||||||
$ IF LIB_COUNTER .GE. 0
|
|
||||||
$ THEN
|
|
||||||
$ FILE_NAME = F$EDIT(F$ELEMENT(LIB_COUNTER,",",LIB_'CURRENT_APP'),"TRIM")
|
|
||||||
$ ELSE
|
|
||||||
$ FILE_NAME = CURRENT_APP
|
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$!
|
$!
|
||||||
$! Check To See If We Are At The End Of The File List.
|
|
||||||
$!
|
|
||||||
$ IF (FILE_NAME.EQS.",")
|
|
||||||
$ THEN
|
|
||||||
$ CLOSE OBJECTS
|
|
||||||
$ GOTO NEXT_APP
|
|
||||||
$ ENDIF
|
|
||||||
$!
|
|
||||||
$! Increment The Counter.
|
|
||||||
$!
|
|
||||||
$ LIB_COUNTER = LIB_COUNTER + 1
|
|
||||||
$!
|
|
||||||
$! Create The Source File Name.
|
$! Create The Source File Name.
|
||||||
$!
|
$!
|
||||||
$ SOURCE_FILE = "SYS$DISK:[]" + FILE_NAME + ".C"
|
$ SOURCE_FILE = "SYS$DISK:[]" + FILE_NAME + ".C"
|
||||||
@@ -236,7 +201,11 @@ $!
|
|||||||
$! Create The Object File Name.
|
$! Create The Object File Name.
|
||||||
$!
|
$!
|
||||||
$ OBJECT_FILE = OBJ_DIR + FILE_NAME + ".OBJ"
|
$ OBJECT_FILE = OBJ_DIR + FILE_NAME + ".OBJ"
|
||||||
$ ON WARNING THEN GOTO NEXT_LIB
|
$!
|
||||||
|
$! Create The Executable File Name.
|
||||||
|
$!
|
||||||
|
$ EXE_FILE = EXE_DIR + FILE_NAME + ".EXE"
|
||||||
|
$ ON WARNING THEN GOTO NEXT_FILE
|
||||||
$!
|
$!
|
||||||
$! Check To See If The File We Want To Compile Actually Exists.
|
$! Check To See If The File We Want To Compile Actually Exists.
|
||||||
$!
|
$!
|
||||||
@@ -268,38 +237,39 @@ $ ENDIF
|
|||||||
$!
|
$!
|
||||||
$! Compile The File.
|
$! Compile The File.
|
||||||
$!
|
$!
|
||||||
$ ON ERROR THEN GOTO NEXT_LIB
|
$ ON ERROR THEN GOTO NEXT_FILE
|
||||||
$ IF COMPILEWITH_CC2 - FILE_NAME .NES. COMPILEWITH_CC2
|
$ IF COMPILEWITH_CC2 - FILE_NAME .NES. COMPILEWITH_CC2
|
||||||
$ THEN
|
$ THEN
|
||||||
$ CC2/OBJECT='OBJECT_FILE' 'SOURCE_FILE'
|
$ CC2/OBJECT='OBJECT_FILE' 'SOURCE_FILE'
|
||||||
$ ELSE
|
$ ELSE
|
||||||
$ CC/OBJECT='OBJECT_FILE' 'SOURCE_FILE'
|
$ CC/OBJECT='OBJECT_FILE' 'SOURCE_FILE'
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$ WRITE OBJECTS OBJECT_FILE
|
|
||||||
$!
|
$!
|
||||||
$ GOTO NEXT_LIB
|
$ ON WARNING THEN GOTO NEXT_FILE
|
||||||
|
$!
|
||||||
|
$ IF (PHASE.EQS."LIB")
|
||||||
|
$ THEN
|
||||||
|
$ GOTO NEXT_FILE
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$!
|
$!
|
||||||
$! Check if this program works well without a TCPIP library
|
$! Check if this program works well without a TCPIP library
|
||||||
$!
|
$!
|
||||||
$ IF TCPIP_LIB .EQS. "" .AND. TCPIP_PROGRAMS - CURRENT_APP .NES. TCPIP_PROGRAMS
|
$ IF TCPIP_LIB .EQS. "" .AND. TCPIP_PROGRAMS - FILE_NAME .NES. TCPIP_PROGRAMS
|
||||||
$ THEN
|
$ THEN
|
||||||
$ WRITE SYS$OUTPUT CURRENT_APP," needs a TCP/IP library. Can't link. Skipping..."
|
$ WRITE SYS$OUTPUT FILE_NAME," needs a TCP/IP library. Can't link. Skipping..."
|
||||||
$ GOTO NEXT_APP
|
$ GOTO NEXT_FILE
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$!
|
$!
|
||||||
$! Link The Program.
|
$! Link The Program.
|
||||||
$! Check To See If We Are To Link With A Specific TCP/IP Library.
|
$! Check To See If We Are To Link With A Specific TCP/IP Library.
|
||||||
$!
|
$!
|
||||||
$ ON WARNING THEN GOTO NEXT_APP
|
|
||||||
$!
|
|
||||||
$ IF (TCPIP_LIB.NES."")
|
$ IF (TCPIP_LIB.NES."")
|
||||||
$ THEN
|
$ THEN
|
||||||
$!
|
$!
|
||||||
$! Don't Link With The RSAREF Routines And TCP/IP Library.
|
$! Don't Link With The RSAREF Routines And TCP/IP Library.
|
||||||
$!
|
$!
|
||||||
$ LINK/'DEBUGGER'/'TRACEBACK' /EXE='EXE_FILE' -
|
$ LINK/'DEBUGGER'/'TRACEBACK' /EXE='EXE_FILE' -
|
||||||
'EXE_DIR''CURRENT_APP'.OPT/OPTION, -
|
'OBJECT_FILE''EXTRA_OBJ', -
|
||||||
'SSL_LIB'/LIBRARY,'CRYPTO_LIB'/LIBRARY, -
|
'SSL_LIB'/LIBRARY,'CRYPTO_LIB'/LIBRARY, -
|
||||||
'TCPIP_LIB','OPT_FILE'/OPTION
|
'TCPIP_LIB','OPT_FILE'/OPTION
|
||||||
$!
|
$!
|
||||||
@@ -310,7 +280,7 @@ $!
|
|||||||
$! Don't Link With The RSAREF Routines And Link With A TCP/IP Library.
|
$! Don't Link With The RSAREF Routines And Link With A TCP/IP Library.
|
||||||
$!
|
$!
|
||||||
$ LINK/'DEBUGGER'/'TRACEBACK' /EXE='EXE_FILE' -
|
$ LINK/'DEBUGGER'/'TRACEBACK' /EXE='EXE_FILE' -
|
||||||
'EXE_DIR''CURRENT_APP'.OPT/OPTION, -
|
'OBJECT_FILE''EXTRA_OBJ', -
|
||||||
'SSL_LIB'/LIBRARY,'CRYPTO_LIB'/LIBRARY, -
|
'SSL_LIB'/LIBRARY,'CRYPTO_LIB'/LIBRARY, -
|
||||||
'OPT_FILE'/OPTION
|
'OPT_FILE'/OPTION
|
||||||
$!
|
$!
|
||||||
@@ -320,11 +290,11 @@ $ ENDIF
|
|||||||
$!
|
$!
|
||||||
$! Go Back And Do It Again.
|
$! Go Back And Do It Again.
|
||||||
$!
|
$!
|
||||||
$ GOTO NEXT_APP
|
$ GOTO NEXT_FILE
|
||||||
$!
|
$!
|
||||||
$! All Done With This File.
|
$! All Done With This File.
|
||||||
$!
|
$!
|
||||||
$ APP_DONE:
|
$ FILE_DONE:
|
||||||
$ EXIT:
|
$ EXIT:
|
||||||
$!
|
$!
|
||||||
$! All Done, Time To Clean Up And Exit.
|
$! All Done, Time To Clean Up And Exit.
|
||||||
@@ -425,19 +395,19 @@ $! Else...
|
|||||||
$!
|
$!
|
||||||
$ ELSE
|
$ ELSE
|
||||||
$!
|
$!
|
||||||
$! Create The non-VAX Linker Option File.
|
$! Create The AXP Linker Option File.
|
||||||
$!
|
$!
|
||||||
$ CREATE 'OPT_FILE'
|
$ CREATE 'OPT_FILE'
|
||||||
$DECK
|
$DECK
|
||||||
!
|
!
|
||||||
! Default System Options File For non-VAX To Link Agianst
|
! Default System Options File For AXP To Link Agianst
|
||||||
! The Sharable C Runtime Library.
|
! The Sharable C Runtime Library.
|
||||||
!
|
!
|
||||||
SYS$SHARE:CMA$OPEN_LIB_SHR/SHARE
|
SYS$SHARE:CMA$OPEN_LIB_SHR/SHARE
|
||||||
SYS$SHARE:CMA$OPEN_RTL/SHARE
|
SYS$SHARE:CMA$OPEN_RTL/SHARE
|
||||||
$EOD
|
$EOD
|
||||||
$!
|
$!
|
||||||
$! End The DEC C Option File Check.
|
$! End The VAX/AXP DEC C Option File Check.
|
||||||
$!
|
$!
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$!
|
$!
|
||||||
@@ -586,7 +556,7 @@ $ ELSE
|
|||||||
$!
|
$!
|
||||||
$! Check To See If We Have VAXC Or DECC.
|
$! Check To See If We Have VAXC Or DECC.
|
||||||
$!
|
$!
|
||||||
$ IF (ARCH.NES."VAX").OR.(F$TRNLNM("DECC$CC_DEFAULT").NES."")
|
$ IF (ARCH.EQS."AXP").OR.(F$TRNLNM("DECC$CC_DEFAULT").NES."")
|
||||||
$ THEN
|
$ THEN
|
||||||
$!
|
$!
|
||||||
$! Looks Like DECC, Set To Use DECC.
|
$! Looks Like DECC, Set To Use DECC.
|
||||||
@@ -696,7 +666,7 @@ $ CC = CC + "/''CC_OPTIMIZE'/''DEBUGGER'/STANDARD=ANSI89" + -
|
|||||||
$!
|
$!
|
||||||
$! Define The Linker Options File Name.
|
$! Define The Linker Options File Name.
|
||||||
$!
|
$!
|
||||||
$ OPT_FILE = "''EXE_DIR'VAX_DECC_OPTIONS.OPT"
|
$ OPT_FILE = "SYS$DISK:[]VAX_DECC_OPTIONS.OPT"
|
||||||
$!
|
$!
|
||||||
$! End DECC Check.
|
$! End DECC Check.
|
||||||
$!
|
$!
|
||||||
@@ -717,9 +687,9 @@ $!
|
|||||||
$! Compile Using VAXC.
|
$! Compile Using VAXC.
|
||||||
$!
|
$!
|
||||||
$ CC = "CC"
|
$ CC = "CC"
|
||||||
$ IF ARCH.NES."VAX"
|
$ IF ARCH.EQS."AXP"
|
||||||
$ THEN
|
$ THEN
|
||||||
$ WRITE SYS$OUTPUT "There is no VAX C on ''ARCH'!"
|
$ WRITE SYS$OUTPUT "There is no VAX C on Alpha!"
|
||||||
$ EXIT
|
$ EXIT
|
||||||
$ ENDIF
|
$ ENDIF
|
||||||
$ IF F$TRNLNM("DECC$CC_DEFAULT").EQS."/DECC" THEN CC = "CC/VAXC"
|
$ IF F$TRNLNM("DECC$CC_DEFAULT").EQS."/DECC" THEN CC = "CC/VAXC"
|
||||||
@@ -733,7 +703,7 @@ $ DEFINE/NOLOG SYS SYS$COMMON:[SYSLIB]
|
|||||||
$!
|
$!
|
||||||
$! Define The Linker Options File Name.
|
$! Define The Linker Options File Name.
|
||||||
$!
|
$!
|
||||||
$ OPT_FILE = "''EXE_DIR'VAX_VAXC_OPTIONS.OPT"
|
$ OPT_FILE = "SYS$DISK:[]VAX_VAXC_OPTIONS.OPT"
|
||||||
$!
|
$!
|
||||||
$! End VAXC Check
|
$! End VAXC Check
|
||||||
$!
|
$!
|
||||||
@@ -760,7 +730,7 @@ $ CC = GCC+"/NOCASE_HACK/''GCC_OPTIMIZE'/''DEBUGGER'/NOLIST" + -
|
|||||||
$!
|
$!
|
||||||
$! Define The Linker Options File Name.
|
$! Define The Linker Options File Name.
|
||||||
$!
|
$!
|
||||||
$ OPT_FILE = "''EXE_DIR'VAX_GNUC_OPTIONS.OPT"
|
$ OPT_FILE = "SYS$DISK:[]VAX_GNUC_OPTIONS.OPT"
|
||||||
$!
|
$!
|
||||||
$! End The GNU C Check.
|
$! End The GNU C Check.
|
||||||
$!
|
$!
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* nseq.c */
|
/* nseq.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 1999.
|
* project 1999.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
|
|||||||
26
apps/ocsp.c
26
apps/ocsp.c
@@ -1,5 +1,5 @@
|
|||||||
/* ocsp.c */
|
/* ocsp.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 2000.
|
* project 2000.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
@@ -98,7 +98,6 @@ int MAIN(int argc, char **argv)
|
|||||||
ENGINE *e = NULL;
|
ENGINE *e = NULL;
|
||||||
char **args;
|
char **args;
|
||||||
char *host = NULL, *port = NULL, *path = "/";
|
char *host = NULL, *port = NULL, *path = "/";
|
||||||
char *thost = NULL, *tport = NULL, *tpath = NULL;
|
|
||||||
char *reqin = NULL, *respin = NULL;
|
char *reqin = NULL, *respin = NULL;
|
||||||
char *reqout = NULL, *respout = NULL;
|
char *reqout = NULL, *respout = NULL;
|
||||||
char *signfile = NULL, *keyfile = NULL;
|
char *signfile = NULL, *keyfile = NULL;
|
||||||
@@ -174,12 +173,6 @@ int MAIN(int argc, char **argv)
|
|||||||
}
|
}
|
||||||
else if (!strcmp(*args, "-url"))
|
else if (!strcmp(*args, "-url"))
|
||||||
{
|
{
|
||||||
if (thost)
|
|
||||||
OPENSSL_free(thost);
|
|
||||||
if (tport)
|
|
||||||
OPENSSL_free(tport);
|
|
||||||
if (tpath)
|
|
||||||
OPENSSL_free(tpath);
|
|
||||||
if (args[1])
|
if (args[1])
|
||||||
{
|
{
|
||||||
args++;
|
args++;
|
||||||
@@ -188,9 +181,6 @@ int MAIN(int argc, char **argv)
|
|||||||
BIO_printf(bio_err, "Error parsing URL\n");
|
BIO_printf(bio_err, "Error parsing URL\n");
|
||||||
badarg = 1;
|
badarg = 1;
|
||||||
}
|
}
|
||||||
thost = host;
|
|
||||||
tport = port;
|
|
||||||
tpath = path;
|
|
||||||
}
|
}
|
||||||
else badarg = 1;
|
else badarg = 1;
|
||||||
}
|
}
|
||||||
@@ -881,12 +871,12 @@ end:
|
|||||||
sk_X509_pop_free(sign_other, X509_free);
|
sk_X509_pop_free(sign_other, X509_free);
|
||||||
sk_X509_pop_free(verify_other, X509_free);
|
sk_X509_pop_free(verify_other, X509_free);
|
||||||
|
|
||||||
if (thost)
|
if (use_ssl != -1)
|
||||||
OPENSSL_free(thost);
|
{
|
||||||
if (tport)
|
OPENSSL_free(host);
|
||||||
OPENSSL_free(tport);
|
OPENSSL_free(port);
|
||||||
if (tpath)
|
OPENSSL_free(path);
|
||||||
OPENSSL_free(tpath);
|
}
|
||||||
|
|
||||||
OPENSSL_EXIT(ret);
|
OPENSSL_EXIT(ret);
|
||||||
}
|
}
|
||||||
@@ -1344,7 +1334,7 @@ OCSP_RESPONSE *process_responder(BIO *err, OCSP_REQUEST *req,
|
|||||||
}
|
}
|
||||||
resp = query_responder(err, cbio, path, req, req_timeout);
|
resp = query_responder(err, cbio, path, req, req_timeout);
|
||||||
if (!resp)
|
if (!resp)
|
||||||
BIO_printf(bio_err, "Error querying OCSP responder\n");
|
BIO_printf(bio_err, "Error querying OCSP responsder\n");
|
||||||
end:
|
end:
|
||||||
if (ctx)
|
if (ctx)
|
||||||
SSL_CTX_free(ctx);
|
SSL_CTX_free(ctx);
|
||||||
|
|||||||
@@ -8,9 +8,8 @@
|
|||||||
HOME = .
|
HOME = .
|
||||||
RANDFILE = $ENV::HOME/.rnd
|
RANDFILE = $ENV::HOME/.rnd
|
||||||
|
|
||||||
# Extra OBJECT IDENTIFIER info:
|
# Uncomment out to enable OpenSSL configuration see config(3)
|
||||||
#oid_file = $ENV::HOME/.oid
|
# openssl_conf = openssl_init
|
||||||
oid_section = new_oids
|
|
||||||
|
|
||||||
# To use this configuration file with the "-extfile" option of the
|
# To use this configuration file with the "-extfile" option of the
|
||||||
# "openssl x509" utility, name here the section containing the
|
# "openssl x509" utility, name here the section containing the
|
||||||
@@ -19,13 +18,22 @@ oid_section = new_oids
|
|||||||
# (Alternatively, use a configuration file that has only
|
# (Alternatively, use a configuration file that has only
|
||||||
# X.509v3 extensions in its main [= default] section.)
|
# X.509v3 extensions in its main [= default] section.)
|
||||||
|
|
||||||
|
[openssl_init]
|
||||||
|
# Extra OBJECT IDENTIFIER info:
|
||||||
|
oid_section = new_oids
|
||||||
|
alg_section = algs
|
||||||
|
|
||||||
[ new_oids ]
|
[ new_oids ]
|
||||||
|
|
||||||
# We can add new OIDs in here for use by 'ca' and 'req'.
|
# We can add new OIDs in here for use by any config aware application
|
||||||
# Add a simple OID like this:
|
# Add a simple OID like this:
|
||||||
# testoid1=1.2.3.4
|
# shortname=Long Object Identifier Name, 1.2.3.4
|
||||||
# Or use config file substitution like this:
|
# Or use config file substitution like this:
|
||||||
# testoid2=${testoid1}.5.6
|
# testoid2=OID2 LONG NAME, ${testoid1}.5.6, OTHER OID
|
||||||
|
|
||||||
|
[ algs ]
|
||||||
|
# Algorithm configuration options. Currently just fips_mode
|
||||||
|
fips_mode = no
|
||||||
|
|
||||||
####################################################################
|
####################################################################
|
||||||
[ ca ]
|
[ ca ]
|
||||||
@@ -141,7 +149,7 @@ localityName = Locality Name (eg, city)
|
|||||||
organizationalUnitName = Organizational Unit Name (eg, section)
|
organizationalUnitName = Organizational Unit Name (eg, section)
|
||||||
#organizationalUnitName_default =
|
#organizationalUnitName_default =
|
||||||
|
|
||||||
commonName = Common Name (e.g. server FQDN or YOUR name)
|
commonName = Common Name (eg, YOUR name)
|
||||||
commonName_max = 64
|
commonName_max = 64
|
||||||
|
|
||||||
emailAddress = Email Address
|
emailAddress = Email Address
|
||||||
|
|||||||
@@ -235,19 +235,16 @@ int main(int Argc, char *Argv[])
|
|||||||
|
|
||||||
in_FIPS_mode = 0;
|
in_FIPS_mode = 0;
|
||||||
|
|
||||||
if(getenv("OPENSSL_FIPS")) {
|
|
||||||
#ifdef OPENSSL_FIPS
|
#ifdef OPENSSL_FIPS
|
||||||
|
if(getenv("OPENSSL_FIPS")) {
|
||||||
if (!FIPS_mode_set(1)) {
|
if (!FIPS_mode_set(1)) {
|
||||||
ERR_load_crypto_strings();
|
ERR_load_crypto_strings();
|
||||||
ERR_print_errors(BIO_new_fp(stderr,BIO_NOCLOSE));
|
ERR_print_errors(BIO_new_fp(stderr,BIO_NOCLOSE));
|
||||||
EXIT(1);
|
EXIT(1);
|
||||||
}
|
}
|
||||||
in_FIPS_mode = 1;
|
in_FIPS_mode = 1;
|
||||||
#else
|
|
||||||
fprintf(stderr, "FIPS mode not supported.\n");
|
|
||||||
EXIT(1);
|
|
||||||
#endif
|
|
||||||
}
|
}
|
||||||
|
#endif
|
||||||
|
|
||||||
if (bio_err == NULL)
|
if (bio_err == NULL)
|
||||||
if ((bio_err=BIO_new(BIO_s_file())) != NULL)
|
if ((bio_err=BIO_new(BIO_s_file())) != NULL)
|
||||||
@@ -336,8 +333,7 @@ int main(int Argc, char *Argv[])
|
|||||||
else prompt="OpenSSL> ";
|
else prompt="OpenSSL> ";
|
||||||
fputs(prompt,stdout);
|
fputs(prompt,stdout);
|
||||||
fflush(stdout);
|
fflush(stdout);
|
||||||
if (!fgets(p,n,stdin))
|
fgets(p,n,stdin);
|
||||||
goto end;
|
|
||||||
if (p[0] == '\0') goto end;
|
if (p[0] == '\0') goto end;
|
||||||
i=strlen(p);
|
i=strlen(p);
|
||||||
if (i <= 1) break;
|
if (i <= 1) break;
|
||||||
|
|||||||
@@ -8,9 +8,8 @@
|
|||||||
HOME = .
|
HOME = .
|
||||||
RANDFILE = $ENV::HOME/.rnd
|
RANDFILE = $ENV::HOME/.rnd
|
||||||
|
|
||||||
# Extra OBJECT IDENTIFIER info:
|
# Uncomment out to enable OpenSSL configuration see config(3)
|
||||||
#oid_file = $ENV::HOME/.oid
|
# openssl_conf = openssl_init
|
||||||
oid_section = new_oids
|
|
||||||
|
|
||||||
# To use this configuration file with the "-extfile" option of the
|
# To use this configuration file with the "-extfile" option of the
|
||||||
# "openssl x509" utility, name here the section containing the
|
# "openssl x509" utility, name here the section containing the
|
||||||
@@ -19,13 +18,22 @@ oid_section = new_oids
|
|||||||
# (Alternatively, use a configuration file that has only
|
# (Alternatively, use a configuration file that has only
|
||||||
# X.509v3 extensions in its main [= default] section.)
|
# X.509v3 extensions in its main [= default] section.)
|
||||||
|
|
||||||
|
[openssl_init]
|
||||||
|
# Extra OBJECT IDENTIFIER info:
|
||||||
|
oid_section = new_oids
|
||||||
|
alg_section = algs
|
||||||
|
|
||||||
[ new_oids ]
|
[ new_oids ]
|
||||||
|
|
||||||
# We can add new OIDs in here for use by 'ca' and 'req'.
|
# We can add new OIDs in here for use by any config aware application
|
||||||
# Add a simple OID like this:
|
# Add a simple OID like this:
|
||||||
# testoid1=1.2.3.4
|
# shortname=Long Object Identifier Name, 1.2.3.4
|
||||||
# Or use config file substitution like this:
|
# Or use config file substitution like this:
|
||||||
# testoid2=${testoid1}.5.6
|
# testoid2=OID2 LONG NAME, ${testoid1}.5.6, OTHER OID
|
||||||
|
|
||||||
|
[ algs ]
|
||||||
|
# Algorithm configuration options. Currently just fips_mode
|
||||||
|
fips_mode = no
|
||||||
|
|
||||||
####################################################################
|
####################################################################
|
||||||
[ ca ]
|
[ ca ]
|
||||||
@@ -141,7 +149,7 @@ localityName = Locality Name (eg, city)
|
|||||||
organizationalUnitName = Organizational Unit Name (eg, section)
|
organizationalUnitName = Organizational Unit Name (eg, section)
|
||||||
#organizationalUnitName_default =
|
#organizationalUnitName_default =
|
||||||
|
|
||||||
commonName = Common Name (e.g. server FQDN or YOUR name)
|
commonName = Common Name (eg, YOUR name)
|
||||||
commonName_max = 64
|
commonName_max = 64
|
||||||
|
|
||||||
emailAddress = Email Address
|
emailAddress = Email Address
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* pkcs12.c */
|
/* pkcs12.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project.
|
* project.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
@@ -68,12 +68,6 @@
|
|||||||
#include <openssl/pem.h>
|
#include <openssl/pem.h>
|
||||||
#include <openssl/pkcs12.h>
|
#include <openssl/pkcs12.h>
|
||||||
|
|
||||||
#ifdef OPENSSL_SYS_NETWARE
|
|
||||||
/* Rename these functions to avoid name clashes on NetWare OS */
|
|
||||||
#define uni2asc OPENSSL_uni2asc
|
|
||||||
#define asc2uni OPENSSL_asc2uni
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#define PROG pkcs12_main
|
#define PROG pkcs12_main
|
||||||
|
|
||||||
const EVP_CIPHER *enc;
|
const EVP_CIPHER *enc;
|
||||||
@@ -659,7 +653,7 @@ int MAIN(int argc, char **argv)
|
|||||||
|
|
||||||
if (!twopass) BUF_strlcpy(macpass, pass, sizeof macpass);
|
if (!twopass) BUF_strlcpy(macpass, pass, sizeof macpass);
|
||||||
|
|
||||||
if ((options & INFO) && p12->mac) BIO_printf (bio_err, "MAC Iteration %ld\n", p12->mac->iter ? ASN1_INTEGER_get (p12->mac->iter) : 1);
|
if (options & INFO) BIO_printf (bio_err, "MAC Iteration %ld\n", p12->mac->iter ? ASN1_INTEGER_get (p12->mac->iter) : 1);
|
||||||
if(macver) {
|
if(macver) {
|
||||||
#ifdef CRYPTO_MDEBUG
|
#ifdef CRYPTO_MDEBUG
|
||||||
CRYPTO_push_info("verify MAC");
|
CRYPTO_push_info("verify MAC");
|
||||||
|
|||||||
@@ -82,6 +82,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
PKCS7 *p7=NULL;
|
PKCS7 *p7=NULL;
|
||||||
int i,badops=0;
|
int i,badops=0;
|
||||||
BIO *in=NULL,*out=NULL;
|
BIO *in=NULL,*out=NULL;
|
||||||
@@ -177,7 +180,7 @@ bad:
|
|||||||
ERR_load_crypto_strings();
|
ERR_load_crypto_strings();
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
in=BIO_new(BIO_s_file());
|
in=BIO_new(BIO_s_file());
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* pkcs8.c */
|
/* pkcs8.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 1999-2004.
|
* project 1999-2004.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
|
|||||||
30
apps/rand.c
30
apps/rand.c
@@ -68,8 +68,7 @@
|
|||||||
|
|
||||||
/* -out file - write to file
|
/* -out file - write to file
|
||||||
* -rand file:file - PRNG seed files
|
* -rand file:file - PRNG seed files
|
||||||
* -base64 - base64 encode output
|
* -base64 - encode output
|
||||||
* -hex - hex encode output
|
|
||||||
* num - write 'num' bytes
|
* num - write 'num' bytes
|
||||||
*/
|
*/
|
||||||
|
|
||||||
@@ -77,12 +76,14 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
int i, r, ret = 1;
|
int i, r, ret = 1;
|
||||||
int badopt;
|
int badopt;
|
||||||
char *outfile = NULL;
|
char *outfile = NULL;
|
||||||
char *inrand = NULL;
|
char *inrand = NULL;
|
||||||
int base64 = 0;
|
int base64 = 0;
|
||||||
int hex = 0;
|
|
||||||
BIO *out = NULL;
|
BIO *out = NULL;
|
||||||
int num = -1;
|
int num = -1;
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
@@ -132,13 +133,6 @@ int MAIN(int argc, char **argv)
|
|||||||
else
|
else
|
||||||
badopt = 1;
|
badopt = 1;
|
||||||
}
|
}
|
||||||
else if (strcmp(argv[i], "-hex") == 0)
|
|
||||||
{
|
|
||||||
if (!hex)
|
|
||||||
hex = 1;
|
|
||||||
else
|
|
||||||
badopt = 1;
|
|
||||||
}
|
|
||||||
else if (isdigit((unsigned char)argv[i][0]))
|
else if (isdigit((unsigned char)argv[i][0]))
|
||||||
{
|
{
|
||||||
if (num < 0)
|
if (num < 0)
|
||||||
@@ -154,9 +148,6 @@ int MAIN(int argc, char **argv)
|
|||||||
badopt = 1;
|
badopt = 1;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (hex && base64)
|
|
||||||
badopt = 1;
|
|
||||||
|
|
||||||
if (num < 0)
|
if (num < 0)
|
||||||
badopt = 1;
|
badopt = 1;
|
||||||
|
|
||||||
@@ -169,13 +160,12 @@ int MAIN(int argc, char **argv)
|
|||||||
BIO_printf(bio_err, "-engine e - use engine e, possibly a hardware device.\n");
|
BIO_printf(bio_err, "-engine e - use engine e, possibly a hardware device.\n");
|
||||||
#endif
|
#endif
|
||||||
BIO_printf(bio_err, "-rand file%cfile%c... - seed PRNG from files\n", LIST_SEPARATOR_CHAR, LIST_SEPARATOR_CHAR);
|
BIO_printf(bio_err, "-rand file%cfile%c... - seed PRNG from files\n", LIST_SEPARATOR_CHAR, LIST_SEPARATOR_CHAR);
|
||||||
BIO_printf(bio_err, "-base64 - base64 encode output\n");
|
BIO_printf(bio_err, "-base64 - encode output\n");
|
||||||
BIO_printf(bio_err, "-hex - hex encode output\n");
|
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
setup_engine(bio_err, engine, 0);
|
e = setup_engine(bio_err, engine, 0);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
app_RAND_load_file(NULL, bio_err, (inrand != NULL));
|
app_RAND_load_file(NULL, bio_err, (inrand != NULL));
|
||||||
@@ -220,17 +210,9 @@ int MAIN(int argc, char **argv)
|
|||||||
r = RAND_bytes(buf, chunk);
|
r = RAND_bytes(buf, chunk);
|
||||||
if (r <= 0)
|
if (r <= 0)
|
||||||
goto err;
|
goto err;
|
||||||
if (!hex)
|
|
||||||
BIO_write(out, buf, chunk);
|
BIO_write(out, buf, chunk);
|
||||||
else
|
|
||||||
{
|
|
||||||
for (i = 0; i < chunk; i++)
|
|
||||||
BIO_printf(out, "%02x", buf[i]);
|
|
||||||
}
|
|
||||||
num -= chunk;
|
num -= chunk;
|
||||||
}
|
}
|
||||||
if (hex)
|
|
||||||
BIO_puts(out, "\n");
|
|
||||||
(void)BIO_flush(out);
|
(void)BIO_flush(out);
|
||||||
|
|
||||||
app_RAND_write_file(NULL, bio_err);
|
app_RAND_write_file(NULL, bio_err);
|
||||||
|
|||||||
27
apps/req.c
27
apps/req.c
@@ -1433,17 +1433,11 @@ start2: for (;;)
|
|||||||
|
|
||||||
BIO_snprintf(buf,sizeof buf,"%s_min",type);
|
BIO_snprintf(buf,sizeof buf,"%s_min",type);
|
||||||
if (!NCONF_get_number(req_conf,attr_sect,buf, &n_min))
|
if (!NCONF_get_number(req_conf,attr_sect,buf, &n_min))
|
||||||
{
|
|
||||||
ERR_clear_error();
|
|
||||||
n_min = -1;
|
n_min = -1;
|
||||||
}
|
|
||||||
|
|
||||||
BIO_snprintf(buf,sizeof buf,"%s_max",type);
|
BIO_snprintf(buf,sizeof buf,"%s_max",type);
|
||||||
if (!NCONF_get_number(req_conf,attr_sect,buf, &n_max))
|
if (!NCONF_get_number(req_conf,attr_sect,buf, &n_max))
|
||||||
{
|
|
||||||
ERR_clear_error();
|
|
||||||
n_max = -1;
|
n_max = -1;
|
||||||
}
|
|
||||||
|
|
||||||
if (!add_attribute_object(req,
|
if (!add_attribute_object(req,
|
||||||
v->value,def,value,nid,n_min,n_max, chtype))
|
v->value,def,value,nid,n_min,n_max, chtype))
|
||||||
@@ -1544,8 +1538,7 @@ start:
|
|||||||
buf[0]='\0';
|
buf[0]='\0';
|
||||||
if (!batch)
|
if (!batch)
|
||||||
{
|
{
|
||||||
if (!fgets(buf,sizeof buf,stdin))
|
fgets(buf,sizeof buf,stdin);
|
||||||
return 0;
|
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
@@ -1574,13 +1567,7 @@ start:
|
|||||||
#ifdef CHARSET_EBCDIC
|
#ifdef CHARSET_EBCDIC
|
||||||
ebcdic2ascii(buf, buf, i);
|
ebcdic2ascii(buf, buf, i);
|
||||||
#endif
|
#endif
|
||||||
if(!req_check_len(i, n_min, n_max))
|
if(!req_check_len(i, n_min, n_max)) goto start;
|
||||||
{
|
|
||||||
if (batch || value)
|
|
||||||
return 0;
|
|
||||||
goto start;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!X509_NAME_add_entry_by_NID(n,nid, chtype,
|
if (!X509_NAME_add_entry_by_NID(n,nid, chtype,
|
||||||
(unsigned char *) buf, -1,-1,mval)) goto err;
|
(unsigned char *) buf, -1,-1,mval)) goto err;
|
||||||
ret=1;
|
ret=1;
|
||||||
@@ -1609,8 +1596,7 @@ start:
|
|||||||
buf[0]='\0';
|
buf[0]='\0';
|
||||||
if (!batch)
|
if (!batch)
|
||||||
{
|
{
|
||||||
if (!fgets(buf,sizeof buf,stdin))
|
fgets(buf,sizeof buf,stdin);
|
||||||
return 0;
|
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
@@ -1639,12 +1625,7 @@ start:
|
|||||||
#ifdef CHARSET_EBCDIC
|
#ifdef CHARSET_EBCDIC
|
||||||
ebcdic2ascii(buf, buf, i);
|
ebcdic2ascii(buf, buf, i);
|
||||||
#endif
|
#endif
|
||||||
if(!req_check_len(i, n_min, n_max))
|
if(!req_check_len(i, n_min, n_max)) goto start;
|
||||||
{
|
|
||||||
if (batch || value)
|
|
||||||
return 0;
|
|
||||||
goto start;
|
|
||||||
}
|
|
||||||
|
|
||||||
if(!X509_REQ_add1_attr_by_NID(req, nid, chtype,
|
if(!X509_REQ_add1_attr_by_NID(req, nid, chtype,
|
||||||
(unsigned char *)buf, -1)) {
|
(unsigned char *)buf, -1)) {
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* rsautl.c */
|
/* rsautl.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 2000.
|
* project 2000.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
|
|||||||
@@ -171,6 +171,3 @@ void MS_CALLBACK tlsext_cb(SSL *s, int client_server, int type,
|
|||||||
unsigned char *data, int len,
|
unsigned char *data, int len,
|
||||||
void *arg);
|
void *arg);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
int MS_CALLBACK generate_cookie_callback(SSL *ssl, unsigned char *cookie, unsigned int *cookie_len);
|
|
||||||
int MS_CALLBACK verify_cookie_callback(SSL *ssl, unsigned char *cookie, unsigned int cookie_len);
|
|
||||||
|
|||||||
123
apps/s_cb.c
123
apps/s_cb.c
@@ -117,17 +117,12 @@
|
|||||||
#undef NON_MAIN
|
#undef NON_MAIN
|
||||||
#undef USE_SOCKETS
|
#undef USE_SOCKETS
|
||||||
#include <openssl/err.h>
|
#include <openssl/err.h>
|
||||||
#include <openssl/rand.h>
|
|
||||||
#include <openssl/x509.h>
|
#include <openssl/x509.h>
|
||||||
#include <openssl/ssl.h>
|
#include <openssl/ssl.h>
|
||||||
#include "s_apps.h"
|
#include "s_apps.h"
|
||||||
|
|
||||||
#define COOKIE_SECRET_LENGTH 16
|
|
||||||
|
|
||||||
int verify_depth=0;
|
int verify_depth=0;
|
||||||
int verify_error=X509_V_OK;
|
int verify_error=X509_V_OK;
|
||||||
unsigned char cookie_secret[COOKIE_SECRET_LENGTH];
|
|
||||||
int cookie_initialized=0;
|
|
||||||
|
|
||||||
int MS_CALLBACK verify_callback(int ok, X509_STORE_CTX *ctx)
|
int MS_CALLBACK verify_callback(int ok, X509_STORE_CTX *ctx)
|
||||||
{
|
{
|
||||||
@@ -343,12 +338,6 @@ void MS_CALLBACK msg_cb(int write_p, int version, int content_type, const void *
|
|||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
str_version = "???";
|
str_version = "???";
|
||||||
case DTLS1_VERSION:
|
|
||||||
str_version = "DTLS 1.0 ";
|
|
||||||
break;
|
|
||||||
case DTLS1_BAD_VER:
|
|
||||||
str_version = "DTLS 1.0 (bad) ";
|
|
||||||
break;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
if (version == SSL2_VERSION)
|
if (version == SSL2_VERSION)
|
||||||
@@ -412,10 +401,7 @@ void MS_CALLBACK msg_cb(int write_p, int version, int content_type, const void *
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (version == SSL3_VERSION ||
|
if (version == SSL3_VERSION || version == TLS1_VERSION)
|
||||||
version == TLS1_VERSION ||
|
|
||||||
version == DTLS1_VERSION ||
|
|
||||||
version == DTLS1_BAD_VER)
|
|
||||||
{
|
{
|
||||||
switch (content_type)
|
switch (content_type)
|
||||||
{
|
{
|
||||||
@@ -518,24 +504,6 @@ void MS_CALLBACK msg_cb(int write_p, int version, int content_type, const void *
|
|||||||
case 100:
|
case 100:
|
||||||
str_details2 = " no_renegotiation";
|
str_details2 = " no_renegotiation";
|
||||||
break;
|
break;
|
||||||
case 110:
|
|
||||||
str_details2 = " unsupported_extension";
|
|
||||||
break;
|
|
||||||
case 111:
|
|
||||||
str_details2 = " certificate_unobtainable";
|
|
||||||
break;
|
|
||||||
case 112:
|
|
||||||
str_details2 = " unrecognized_name";
|
|
||||||
break;
|
|
||||||
case 113:
|
|
||||||
str_details2 = " bad_certificate_status_response";
|
|
||||||
break;
|
|
||||||
case 114:
|
|
||||||
str_details2 = " bad_certificate_hash_value";
|
|
||||||
break;
|
|
||||||
case 115:
|
|
||||||
str_details2 = " unknown_psk_identity";
|
|
||||||
break;
|
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -572,9 +540,6 @@ void MS_CALLBACK msg_cb(int write_p, int version, int content_type, const void *
|
|||||||
case 15:
|
case 15:
|
||||||
str_details1 = ", CertificateVerify";
|
str_details1 = ", CertificateVerify";
|
||||||
break;
|
break;
|
||||||
case 3:
|
|
||||||
str_details1 = ", HelloVerifyRequest";
|
|
||||||
break;
|
|
||||||
case 16:
|
case 16:
|
||||||
str_details1 = ", ClientKeyExchange";
|
str_details1 = ", ClientKeyExchange";
|
||||||
break;
|
break;
|
||||||
@@ -656,9 +621,6 @@ void MS_CALLBACK tlsext_cb(SSL *s, int client_server, int type,
|
|||||||
extname = "server ticket";
|
extname = "server ticket";
|
||||||
break;
|
break;
|
||||||
|
|
||||||
case TLSEXT_TYPE_renegotiate:
|
|
||||||
extname = "renegotiate";
|
|
||||||
break;
|
|
||||||
|
|
||||||
default:
|
default:
|
||||||
extname = "unknown";
|
extname = "unknown";
|
||||||
@@ -672,86 +634,3 @@ void MS_CALLBACK tlsext_cb(SSL *s, int client_server, int type,
|
|||||||
BIO_dump(bio, (char *)data, len);
|
BIO_dump(bio, (char *)data, len);
|
||||||
(void)BIO_flush(bio);
|
(void)BIO_flush(bio);
|
||||||
}
|
}
|
||||||
|
|
||||||
int MS_CALLBACK generate_cookie_callback(SSL *ssl, unsigned char *cookie, unsigned int *cookie_len)
|
|
||||||
{
|
|
||||||
unsigned char *buffer, result[EVP_MAX_MD_SIZE];
|
|
||||||
unsigned int length, resultlength;
|
|
||||||
struct sockaddr_in peer;
|
|
||||||
|
|
||||||
/* Initialize a random secret */
|
|
||||||
if (!cookie_initialized)
|
|
||||||
{
|
|
||||||
if (!RAND_bytes(cookie_secret, COOKIE_SECRET_LENGTH))
|
|
||||||
{
|
|
||||||
BIO_printf(bio_err,"error setting random cookie secret\n");
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
cookie_initialized = 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* Read peer information */
|
|
||||||
(void)BIO_dgram_get_peer(SSL_get_rbio(ssl), &peer);
|
|
||||||
|
|
||||||
/* Create buffer with peer's address and port */
|
|
||||||
length = sizeof(peer.sin_addr);
|
|
||||||
length += sizeof(peer.sin_port);
|
|
||||||
buffer = OPENSSL_malloc(length);
|
|
||||||
|
|
||||||
if (buffer == NULL)
|
|
||||||
{
|
|
||||||
BIO_printf(bio_err,"out of memory\n");
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
memcpy(buffer, &peer.sin_addr, sizeof(peer.sin_addr));
|
|
||||||
memcpy(buffer + sizeof(peer.sin_addr), &peer.sin_port, sizeof(peer.sin_port));
|
|
||||||
|
|
||||||
/* Calculate HMAC of buffer using the secret */
|
|
||||||
HMAC(EVP_sha1(), cookie_secret, COOKIE_SECRET_LENGTH,
|
|
||||||
buffer, length, result, &resultlength);
|
|
||||||
OPENSSL_free(buffer);
|
|
||||||
|
|
||||||
memcpy(cookie, result, resultlength);
|
|
||||||
*cookie_len = resultlength;
|
|
||||||
|
|
||||||
return 1;
|
|
||||||
}
|
|
||||||
|
|
||||||
int MS_CALLBACK verify_cookie_callback(SSL *ssl, unsigned char *cookie, unsigned int cookie_len)
|
|
||||||
{
|
|
||||||
unsigned char *buffer, result[EVP_MAX_MD_SIZE];
|
|
||||||
unsigned int length, resultlength;
|
|
||||||
struct sockaddr_in peer;
|
|
||||||
|
|
||||||
/* If secret isn't initialized yet, the cookie can't be valid */
|
|
||||||
if (!cookie_initialized)
|
|
||||||
return 0;
|
|
||||||
|
|
||||||
/* Read peer information */
|
|
||||||
(void)BIO_dgram_get_peer(SSL_get_rbio(ssl), &peer);
|
|
||||||
|
|
||||||
/* Create buffer with peer's address and port */
|
|
||||||
length = sizeof(peer.sin_addr);
|
|
||||||
length += sizeof(peer.sin_port);
|
|
||||||
buffer = (unsigned char*) OPENSSL_malloc(length);
|
|
||||||
|
|
||||||
if (buffer == NULL)
|
|
||||||
{
|
|
||||||
BIO_printf(bio_err,"out of memory\n");
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
memcpy(buffer, &peer.sin_addr, sizeof(peer.sin_addr));
|
|
||||||
memcpy(buffer + sizeof(peer.sin_addr), &peer.sin_port, sizeof(peer.sin_port));
|
|
||||||
|
|
||||||
/* Calculate HMAC of buffer using the secret */
|
|
||||||
HMAC(EVP_sha1(), cookie_secret, COOKIE_SECRET_LENGTH,
|
|
||||||
buffer, length, result, &resultlength);
|
|
||||||
OPENSSL_free(buffer);
|
|
||||||
|
|
||||||
if (cookie_len == resultlength && memcmp(result, cookie, resultlength) == 0)
|
|
||||||
return 1;
|
|
||||||
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|||||||
111
apps/s_client.c
111
apps/s_client.c
@@ -221,13 +221,11 @@ static void sc_usage(void)
|
|||||||
BIO_printf(bio_err," -crlf - convert LF from terminal into CRLF\n");
|
BIO_printf(bio_err," -crlf - convert LF from terminal into CRLF\n");
|
||||||
BIO_printf(bio_err," -quiet - no s_client output\n");
|
BIO_printf(bio_err," -quiet - no s_client output\n");
|
||||||
BIO_printf(bio_err," -ign_eof - ignore input eof (default when -quiet)\n");
|
BIO_printf(bio_err," -ign_eof - ignore input eof (default when -quiet)\n");
|
||||||
BIO_printf(bio_err," -no_ign_eof - don't ignore input eof\n");
|
|
||||||
BIO_printf(bio_err," -ssl2 - just use SSLv2\n");
|
BIO_printf(bio_err," -ssl2 - just use SSLv2\n");
|
||||||
BIO_printf(bio_err," -ssl3 - just use SSLv3\n");
|
BIO_printf(bio_err," -ssl3 - just use SSLv3\n");
|
||||||
BIO_printf(bio_err," -tls1 - just use TLSv1\n");
|
BIO_printf(bio_err," -tls1 - just use TLSv1\n");
|
||||||
BIO_printf(bio_err," -dtls1 - just use DTLSv1\n");
|
BIO_printf(bio_err," -dtls1 - just use DTLSv1\n");
|
||||||
BIO_printf(bio_err," -fallback_scsv - send TLS_FALLBACK_SCSV\n");
|
BIO_printf(bio_err," -mtu - set the MTU\n");
|
||||||
BIO_printf(bio_err," -mtu - set the link layer MTU\n");
|
|
||||||
BIO_printf(bio_err," -no_tls1/-no_ssl3/-no_ssl2 - turn off that protocol\n");
|
BIO_printf(bio_err," -no_tls1/-no_ssl3/-no_ssl2 - turn off that protocol\n");
|
||||||
BIO_printf(bio_err," -bugs - Switch on all SSL implementation bug workarounds\n");
|
BIO_printf(bio_err," -bugs - Switch on all SSL implementation bug workarounds\n");
|
||||||
BIO_printf(bio_err," -serverpref - Use server's cipher preferences (only SSLv2)\n");
|
BIO_printf(bio_err," -serverpref - Use server's cipher preferences (only SSLv2)\n");
|
||||||
@@ -236,8 +234,7 @@ static void sc_usage(void)
|
|||||||
BIO_printf(bio_err," -starttls prot - use the STARTTLS command before starting TLS\n");
|
BIO_printf(bio_err," -starttls prot - use the STARTTLS command before starting TLS\n");
|
||||||
BIO_printf(bio_err," for those protocols that support it, where\n");
|
BIO_printf(bio_err," for those protocols that support it, where\n");
|
||||||
BIO_printf(bio_err," 'prot' defines which one to assume. Currently,\n");
|
BIO_printf(bio_err," 'prot' defines which one to assume. Currently,\n");
|
||||||
BIO_printf(bio_err," only \"smtp\", \"pop3\", \"imap\", \"ftp\" and \"xmpp\"\n");
|
BIO_printf(bio_err," only \"smtp\", \"pop3\", \"imap\", and \"ftp\" are supported.\n");
|
||||||
BIO_printf(bio_err," are supported.\n");
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
BIO_printf(bio_err," -engine id - Initialise and use the specified engine\n");
|
BIO_printf(bio_err," -engine id - Initialise and use the specified engine\n");
|
||||||
#endif
|
#endif
|
||||||
@@ -250,7 +247,6 @@ static void sc_usage(void)
|
|||||||
BIO_printf(bio_err," -status - request certificate status from server\n");
|
BIO_printf(bio_err," -status - request certificate status from server\n");
|
||||||
BIO_printf(bio_err," -no_ticket - disable use of RFC4507bis session tickets\n");
|
BIO_printf(bio_err," -no_ticket - disable use of RFC4507bis session tickets\n");
|
||||||
#endif
|
#endif
|
||||||
BIO_printf(bio_err," -legacy_renegotiation - enable use of legacy renegotiation (dangerous)\n");
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_TLSEXT
|
#ifndef OPENSSL_NO_TLSEXT
|
||||||
@@ -280,15 +276,14 @@ enum
|
|||||||
PROTO_SMTP,
|
PROTO_SMTP,
|
||||||
PROTO_POP3,
|
PROTO_POP3,
|
||||||
PROTO_IMAP,
|
PROTO_IMAP,
|
||||||
PROTO_FTP,
|
PROTO_FTP
|
||||||
PROTO_XMPP
|
|
||||||
};
|
};
|
||||||
|
|
||||||
int MAIN(int, char **);
|
int MAIN(int, char **);
|
||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
int off=0, clr = 0;
|
int off=0;
|
||||||
SSL *con=NULL,*con2=NULL;
|
SSL *con=NULL,*con2=NULL;
|
||||||
X509_STORE *store = NULL;
|
X509_STORE *store = NULL;
|
||||||
int s,k,width,state=0;
|
int s,k,width,state=0;
|
||||||
@@ -320,13 +315,11 @@ int MAIN(int argc, char **argv)
|
|||||||
BIO *sbio;
|
BIO *sbio;
|
||||||
char *inrand=NULL;
|
char *inrand=NULL;
|
||||||
int mbuf_len=0;
|
int mbuf_len=0;
|
||||||
struct timeval timeout, *timeoutp;
|
|
||||||
#ifndef OPENSSL_NO_ENGINE
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
char *engine_id=NULL;
|
char *engine_id=NULL;
|
||||||
char *ssl_client_engine_id=NULL;
|
char *ssl_client_engine_id=NULL;
|
||||||
ENGINE *ssl_client_engine=NULL;
|
ENGINE *e=NULL, *ssl_client_engine=NULL;
|
||||||
#endif
|
#endif
|
||||||
ENGINE *e=NULL;
|
|
||||||
#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MSDOS) || defined(OPENSSL_SYS_NETWARE)
|
#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MSDOS) || defined(OPENSSL_SYS_NETWARE)
|
||||||
struct timeval tv;
|
struct timeval tv;
|
||||||
#endif
|
#endif
|
||||||
@@ -340,14 +333,16 @@ int MAIN(int argc, char **argv)
|
|||||||
char *sess_out = NULL;
|
char *sess_out = NULL;
|
||||||
struct sockaddr peer;
|
struct sockaddr peer;
|
||||||
int peerlen = sizeof(peer);
|
int peerlen = sizeof(peer);
|
||||||
int fallback_scsv = 0;
|
|
||||||
int enable_timeouts = 0 ;
|
int enable_timeouts = 0 ;
|
||||||
long socket_mtu = 0;
|
long mtu = 0;
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
char *jpake_secret = NULL;
|
|
||||||
#endif
|
|
||||||
|
|
||||||
|
#if !defined(OPENSSL_NO_SSL2) && !defined(OPENSSL_NO_SSL3)
|
||||||
meth=SSLv23_client_method();
|
meth=SSLv23_client_method();
|
||||||
|
#elif !defined(OPENSSL_NO_SSL3)
|
||||||
|
meth=SSLv3_client_method();
|
||||||
|
#elif !defined(OPENSSL_NO_SSL2)
|
||||||
|
meth=SSLv2_client_method();
|
||||||
|
#endif
|
||||||
|
|
||||||
apps_startup();
|
apps_startup();
|
||||||
c_Pause=0;
|
c_Pause=0;
|
||||||
@@ -440,8 +435,6 @@ int MAIN(int argc, char **argv)
|
|||||||
}
|
}
|
||||||
else if (strcmp(*argv,"-ign_eof") == 0)
|
else if (strcmp(*argv,"-ign_eof") == 0)
|
||||||
c_ign_eof=1;
|
c_ign_eof=1;
|
||||||
else if (strcmp(*argv,"-no_ign_eof") == 0)
|
|
||||||
c_ign_eof=0;
|
|
||||||
else if (strcmp(*argv,"-pause") == 0)
|
else if (strcmp(*argv,"-pause") == 0)
|
||||||
c_Pause=1;
|
c_Pause=1;
|
||||||
else if (strcmp(*argv,"-debug") == 0)
|
else if (strcmp(*argv,"-debug") == 0)
|
||||||
@@ -487,13 +480,9 @@ int MAIN(int argc, char **argv)
|
|||||||
else if (strcmp(*argv,"-mtu") == 0)
|
else if (strcmp(*argv,"-mtu") == 0)
|
||||||
{
|
{
|
||||||
if (--argc < 1) goto bad;
|
if (--argc < 1) goto bad;
|
||||||
socket_mtu = atol(*(++argv));
|
mtu = atol(*(++argv));
|
||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
else if (strcmp(*argv,"-fallback_scsv") == 0)
|
|
||||||
{
|
|
||||||
fallback_scsv = 1;
|
|
||||||
}
|
|
||||||
else if (strcmp(*argv,"-bugs") == 0)
|
else if (strcmp(*argv,"-bugs") == 0)
|
||||||
bugs=1;
|
bugs=1;
|
||||||
else if (strcmp(*argv,"-keyform") == 0)
|
else if (strcmp(*argv,"-keyform") == 0)
|
||||||
@@ -537,12 +526,6 @@ int MAIN(int argc, char **argv)
|
|||||||
#endif
|
#endif
|
||||||
else if (strcmp(*argv,"-serverpref") == 0)
|
else if (strcmp(*argv,"-serverpref") == 0)
|
||||||
off|=SSL_OP_CIPHER_SERVER_PREFERENCE;
|
off|=SSL_OP_CIPHER_SERVER_PREFERENCE;
|
||||||
else if (strcmp(*argv,"-legacy_renegotiation") == 0)
|
|
||||||
off|=SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION;
|
|
||||||
else if (strcmp(*argv,"-legacy_server_connect") == 0)
|
|
||||||
{ off|=SSL_OP_LEGACY_SERVER_CONNECT; }
|
|
||||||
else if (strcmp(*argv,"-no_legacy_server_connect") == 0)
|
|
||||||
{ clr|=SSL_OP_LEGACY_SERVER_CONNECT; }
|
|
||||||
else if (strcmp(*argv,"-cipher") == 0)
|
else if (strcmp(*argv,"-cipher") == 0)
|
||||||
{
|
{
|
||||||
if (--argc < 1) goto bad;
|
if (--argc < 1) goto bad;
|
||||||
@@ -564,8 +547,6 @@ int MAIN(int argc, char **argv)
|
|||||||
starttls_proto = PROTO_IMAP;
|
starttls_proto = PROTO_IMAP;
|
||||||
else if (strcmp(*argv,"ftp") == 0)
|
else if (strcmp(*argv,"ftp") == 0)
|
||||||
starttls_proto = PROTO_FTP;
|
starttls_proto = PROTO_FTP;
|
||||||
else if (strcmp(*argv, "xmpp") == 0)
|
|
||||||
starttls_proto = PROTO_XMPP;
|
|
||||||
else
|
else
|
||||||
goto bad;
|
goto bad;
|
||||||
}
|
}
|
||||||
@@ -593,13 +574,6 @@ int MAIN(int argc, char **argv)
|
|||||||
servername= *(++argv);
|
servername= *(++argv);
|
||||||
/* meth=TLSv1_client_method(); */
|
/* meth=TLSv1_client_method(); */
|
||||||
}
|
}
|
||||||
#endif
|
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
else if (strcmp(*argv,"-jpake") == 0)
|
|
||||||
{
|
|
||||||
if (--argc < 1) goto bad;
|
|
||||||
jpake_secret = *++argv;
|
|
||||||
}
|
|
||||||
#endif
|
#endif
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
@@ -717,9 +691,6 @@ bad:
|
|||||||
SSL_CTX_set_options(ctx,SSL_OP_ALL|off);
|
SSL_CTX_set_options(ctx,SSL_OP_ALL|off);
|
||||||
else
|
else
|
||||||
SSL_CTX_set_options(ctx,off);
|
SSL_CTX_set_options(ctx,off);
|
||||||
|
|
||||||
if (clr)
|
|
||||||
SSL_CTX_clear_options(ctx, clr);
|
|
||||||
/* DTLS: partial reads end up discarding unread UDP bytes :-(
|
/* DTLS: partial reads end up discarding unread UDP bytes :-(
|
||||||
* Setting read ahead solves this problem.
|
* Setting read ahead solves this problem.
|
||||||
*/
|
*/
|
||||||
@@ -784,10 +755,6 @@ bad:
|
|||||||
SSL_set_session(con, sess);
|
SSL_set_session(con, sess);
|
||||||
SSL_SESSION_free(sess);
|
SSL_SESSION_free(sess);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (fallback_scsv)
|
|
||||||
SSL_set_mode(con, SSL_MODE_SEND_FALLBACK_SCSV);
|
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_TLSEXT
|
#ifndef OPENSSL_NO_TLSEXT
|
||||||
if (servername != NULL)
|
if (servername != NULL)
|
||||||
{
|
{
|
||||||
@@ -834,6 +801,7 @@ re_start:
|
|||||||
|
|
||||||
if ( SSL_version(con) == DTLS1_VERSION)
|
if ( SSL_version(con) == DTLS1_VERSION)
|
||||||
{
|
{
|
||||||
|
struct timeval timeout;
|
||||||
|
|
||||||
sbio=BIO_new_dgram(s,BIO_NOCLOSE);
|
sbio=BIO_new_dgram(s,BIO_NOCLOSE);
|
||||||
if (getsockname(s, &peer, (void *)&peerlen) < 0)
|
if (getsockname(s, &peer, (void *)&peerlen) < 0)
|
||||||
@@ -857,10 +825,10 @@ re_start:
|
|||||||
BIO_ctrl(sbio, BIO_CTRL_DGRAM_SET_SEND_TIMEOUT, 0, &timeout);
|
BIO_ctrl(sbio, BIO_CTRL_DGRAM_SET_SEND_TIMEOUT, 0, &timeout);
|
||||||
}
|
}
|
||||||
|
|
||||||
if (socket_mtu > 28)
|
if ( mtu > 0)
|
||||||
{
|
{
|
||||||
SSL_set_options(con, SSL_OP_NO_QUERY_MTU);
|
SSL_set_options(con, SSL_OP_NO_QUERY_MTU);
|
||||||
SSL_set_mtu(con, socket_mtu - 28);
|
SSL_set_mtu(con, mtu);
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
/* want to do MTU discovery */
|
/* want to do MTU discovery */
|
||||||
@@ -869,6 +837,8 @@ re_start:
|
|||||||
else
|
else
|
||||||
sbio=BIO_new_socket(s,BIO_NOCLOSE);
|
sbio=BIO_new_socket(s,BIO_NOCLOSE);
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
if (nbio_test)
|
if (nbio_test)
|
||||||
{
|
{
|
||||||
BIO *test;
|
BIO *test;
|
||||||
@@ -912,10 +882,6 @@ SSL_set_tlsext_status_ids(con, ids);
|
|||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
if (jpake_secret)
|
|
||||||
jpake_client_auth(bio_c_out, sbio, jpake_secret);
|
|
||||||
#endif
|
|
||||||
|
|
||||||
SSL_set_bio(con,sbio,sbio);
|
SSL_set_bio(con,sbio,sbio);
|
||||||
SSL_set_connect_state(con);
|
SSL_set_connect_state(con);
|
||||||
@@ -1022,40 +988,12 @@ SSL_set_tlsext_status_ids(con, ids);
|
|||||||
BIO_printf(sbio,"AUTH TLS\r\n");
|
BIO_printf(sbio,"AUTH TLS\r\n");
|
||||||
BIO_read(sbio,sbuf,BUFSIZZ);
|
BIO_read(sbio,sbuf,BUFSIZZ);
|
||||||
}
|
}
|
||||||
if (starttls_proto == PROTO_XMPP)
|
|
||||||
{
|
|
||||||
int seen = 0;
|
|
||||||
BIO_printf(sbio,"<stream:stream "
|
|
||||||
"xmlns:stream='http://etherx.jabber.org/streams' "
|
|
||||||
"xmlns='jabber:client' to='%s' version='1.0'>", host);
|
|
||||||
seen = BIO_read(sbio,mbuf,BUFSIZZ);
|
|
||||||
mbuf[seen] = 0;
|
|
||||||
while (!strstr(mbuf, "<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'"))
|
|
||||||
{
|
|
||||||
if (strstr(mbuf, "/stream:features>"))
|
|
||||||
goto shut;
|
|
||||||
seen = BIO_read(sbio,mbuf,BUFSIZZ);
|
|
||||||
mbuf[seen] = 0;
|
|
||||||
}
|
|
||||||
BIO_printf(sbio, "<starttls xmlns='urn:ietf:params:xml:ns:xmpp-tls'/>");
|
|
||||||
seen = BIO_read(sbio,sbuf,BUFSIZZ);
|
|
||||||
sbuf[seen] = 0;
|
|
||||||
if (!strstr(sbuf, "<proceed"))
|
|
||||||
goto shut;
|
|
||||||
mbuf[0] = 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
for (;;)
|
for (;;)
|
||||||
{
|
{
|
||||||
FD_ZERO(&readfds);
|
FD_ZERO(&readfds);
|
||||||
FD_ZERO(&writefds);
|
FD_ZERO(&writefds);
|
||||||
|
|
||||||
if ((SSL_version(con) == DTLS1_VERSION) &&
|
|
||||||
DTLSv1_get_timeout(con, &timeout))
|
|
||||||
timeoutp = &timeout;
|
|
||||||
else
|
|
||||||
timeoutp = NULL;
|
|
||||||
|
|
||||||
if (SSL_in_init(con) && !SSL_total_renegotiations(con))
|
if (SSL_in_init(con) && !SSL_total_renegotiations(con))
|
||||||
{
|
{
|
||||||
in_init=1;
|
in_init=1;
|
||||||
@@ -1152,7 +1090,7 @@ SSL_set_tlsext_status_ids(con, ids);
|
|||||||
if(!i && (!((_kbhit()) || (WAIT_OBJECT_0 == WaitForSingleObject(GetStdHandle(STD_INPUT_HANDLE), 0))) || !read_tty) ) continue;
|
if(!i && (!((_kbhit()) || (WAIT_OBJECT_0 == WaitForSingleObject(GetStdHandle(STD_INPUT_HANDLE), 0))) || !read_tty) ) continue;
|
||||||
#endif
|
#endif
|
||||||
} else i=select(width,(void *)&readfds,(void *)&writefds,
|
} else i=select(width,(void *)&readfds,(void *)&writefds,
|
||||||
NULL,timeoutp);
|
NULL,NULL);
|
||||||
}
|
}
|
||||||
#elif defined(OPENSSL_SYS_NETWARE)
|
#elif defined(OPENSSL_SYS_NETWARE)
|
||||||
if(!write_tty) {
|
if(!write_tty) {
|
||||||
@@ -1162,11 +1100,11 @@ SSL_set_tlsext_status_ids(con, ids);
|
|||||||
i=select(width,(void *)&readfds,(void *)&writefds,
|
i=select(width,(void *)&readfds,(void *)&writefds,
|
||||||
NULL,&tv);
|
NULL,&tv);
|
||||||
} else i=select(width,(void *)&readfds,(void *)&writefds,
|
} else i=select(width,(void *)&readfds,(void *)&writefds,
|
||||||
NULL,timeoutp);
|
NULL,NULL);
|
||||||
}
|
}
|
||||||
#else
|
#else
|
||||||
i=select(width,(void *)&readfds,(void *)&writefds,
|
i=select(width,(void *)&readfds,(void *)&writefds,
|
||||||
NULL,timeoutp);
|
NULL,NULL);
|
||||||
#endif
|
#endif
|
||||||
if ( i < 0)
|
if ( i < 0)
|
||||||
{
|
{
|
||||||
@@ -1177,11 +1115,6 @@ SSL_set_tlsext_status_ids(con, ids);
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if ((SSL_version(con) == DTLS1_VERSION) && DTLSv1_handle_timeout(con) > 0)
|
|
||||||
{
|
|
||||||
BIO_printf(bio_err,"TIMEOUT occured\n");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (!ssl_pending && FD_ISSET(SSL_get_fd(con),&writefds))
|
if (!ssl_pending && FD_ISSET(SSL_get_fd(con),&writefds))
|
||||||
{
|
{
|
||||||
k=SSL_write(con,&(cbuf[cbuf_off]),
|
k=SSL_write(con,&(cbuf[cbuf_off]),
|
||||||
@@ -1536,8 +1469,6 @@ static void print_stuff(BIO *bio, SSL *s, int full)
|
|||||||
EVP_PKEY_bits(pktmp));
|
EVP_PKEY_bits(pktmp));
|
||||||
EVP_PKEY_free(pktmp);
|
EVP_PKEY_free(pktmp);
|
||||||
}
|
}
|
||||||
BIO_printf(bio, "Secure Renegotiation IS%s supported\n",
|
|
||||||
SSL_get_secure_renegotiation_support(s) ? "" : " NOT");
|
|
||||||
#ifndef OPENSSL_NO_COMP
|
#ifndef OPENSSL_NO_COMP
|
||||||
comp=SSL_get_current_compression(s);
|
comp=SSL_get_current_compression(s);
|
||||||
expansion=SSL_get_current_expansion(s);
|
expansion=SSL_get_current_expansion(s);
|
||||||
|
|||||||
107
apps/s_server.c
107
apps/s_server.c
@@ -283,10 +283,11 @@ static char *engine_id=NULL;
|
|||||||
static const char *session_id_prefix=NULL;
|
static const char *session_id_prefix=NULL;
|
||||||
|
|
||||||
static int enable_timeouts = 0;
|
static int enable_timeouts = 0;
|
||||||
static long socket_mtu;
|
#ifdef mtu
|
||||||
#ifndef OPENSSL_NO_DTLS1
|
#undef mtu
|
||||||
static int cert_chain = 0;
|
|
||||||
#endif
|
#endif
|
||||||
|
static long mtu;
|
||||||
|
static int cert_chain = 0;
|
||||||
|
|
||||||
|
|
||||||
#ifdef MONOLITH
|
#ifdef MONOLITH
|
||||||
@@ -374,7 +375,7 @@ static void sv_usage(void)
|
|||||||
BIO_printf(bio_err," -tls1 - Just talk TLSv1\n");
|
BIO_printf(bio_err," -tls1 - Just talk TLSv1\n");
|
||||||
BIO_printf(bio_err," -dtls1 - Just talk DTLSv1\n");
|
BIO_printf(bio_err," -dtls1 - Just talk DTLSv1\n");
|
||||||
BIO_printf(bio_err," -timeout - Enable timeouts\n");
|
BIO_printf(bio_err," -timeout - Enable timeouts\n");
|
||||||
BIO_printf(bio_err," -mtu - Set link layer MTU\n");
|
BIO_printf(bio_err," -mtu - Set MTU\n");
|
||||||
BIO_printf(bio_err," -chain - Read a certificate chain\n");
|
BIO_printf(bio_err," -chain - Read a certificate chain\n");
|
||||||
BIO_printf(bio_err," -no_ssl2 - Just disable SSLv2\n");
|
BIO_printf(bio_err," -no_ssl2 - Just disable SSLv2\n");
|
||||||
BIO_printf(bio_err," -no_ssl3 - Just disable SSLv3\n");
|
BIO_printf(bio_err," -no_ssl3 - Just disable SSLv3\n");
|
||||||
@@ -404,7 +405,6 @@ static void sv_usage(void)
|
|||||||
BIO_printf(bio_err," not specified (default is %s)\n",TEST_CERT2);
|
BIO_printf(bio_err," not specified (default is %s)\n",TEST_CERT2);
|
||||||
BIO_printf(bio_err," -tlsextdebug - hex dump of all TLS extensions received\n");
|
BIO_printf(bio_err," -tlsextdebug - hex dump of all TLS extensions received\n");
|
||||||
BIO_printf(bio_err," -no_ticket - disable use of RFC4507bis session tickets\n");
|
BIO_printf(bio_err," -no_ticket - disable use of RFC4507bis session tickets\n");
|
||||||
BIO_printf(bio_err," -legacy_renegotiation - enable use of legacy renegotiation (dangerous)\n");
|
|
||||||
#endif
|
#endif
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -583,7 +583,7 @@ static int MS_CALLBACK ssl_servername_cb(SSL *s, int *ad, void *arg)
|
|||||||
|
|
||||||
if (servername)
|
if (servername)
|
||||||
{
|
{
|
||||||
if (strcasecmp(servername,p->servername))
|
if (strcmp(servername,p->servername))
|
||||||
return p->extension_error;
|
return p->extension_error;
|
||||||
if (ctx2)
|
if (ctx2)
|
||||||
{
|
{
|
||||||
@@ -742,10 +742,6 @@ BIO_printf(err, "cert_status: received %d ids\n", sk_OCSP_RESPID_num(ids));
|
|||||||
#endif
|
#endif
|
||||||
int MAIN(int, char **);
|
int MAIN(int, char **);
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
static char *jpake_secret = NULL;
|
|
||||||
#endif
|
|
||||||
|
|
||||||
int MAIN(int argc, char *argv[])
|
int MAIN(int argc, char *argv[])
|
||||||
{
|
{
|
||||||
X509_STORE *store = NULL;
|
X509_STORE *store = NULL;
|
||||||
@@ -764,7 +760,9 @@ int MAIN(int argc, char *argv[])
|
|||||||
int state=0;
|
int state=0;
|
||||||
SSL_METHOD *meth=NULL;
|
SSL_METHOD *meth=NULL;
|
||||||
int socket_type=SOCK_STREAM;
|
int socket_type=SOCK_STREAM;
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
ENGINE *e=NULL;
|
ENGINE *e=NULL;
|
||||||
|
#endif
|
||||||
char *inrand=NULL;
|
char *inrand=NULL;
|
||||||
int s_cert_format = FORMAT_PEM, s_key_format = FORMAT_PEM;
|
int s_cert_format = FORMAT_PEM, s_key_format = FORMAT_PEM;
|
||||||
char *passarg = NULL, *pass = NULL;
|
char *passarg = NULL, *pass = NULL;
|
||||||
@@ -772,16 +770,22 @@ int MAIN(int argc, char *argv[])
|
|||||||
int s_dcert_format = FORMAT_PEM, s_dkey_format = FORMAT_PEM;
|
int s_dcert_format = FORMAT_PEM, s_dkey_format = FORMAT_PEM;
|
||||||
X509 *s_cert = NULL, *s_dcert = NULL;
|
X509 *s_cert = NULL, *s_dcert = NULL;
|
||||||
EVP_PKEY *s_key = NULL, *s_dkey = NULL;
|
EVP_PKEY *s_key = NULL, *s_dkey = NULL;
|
||||||
int no_cache = 0;
|
|
||||||
#ifndef OPENSSL_NO_TLSEXT
|
#ifndef OPENSSL_NO_TLSEXT
|
||||||
EVP_PKEY *s_key2 = NULL;
|
EVP_PKEY *s_key2 = NULL;
|
||||||
X509 *s_cert2 = NULL;
|
X509 *s_cert2 = NULL;
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_TLSEXT
|
#ifndef OPENSSL_NO_TLSEXT
|
||||||
tlsextctx tlsextcbp = {NULL, NULL, SSL_TLSEXT_ERR_ALERT_WARNING};
|
tlsextctx tlsextcbp = {NULL, NULL, SSL_TLSEXT_ERR_ALERT_WARNING};
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
#if !defined(OPENSSL_NO_SSL2) && !defined(OPENSSL_NO_SSL3)
|
||||||
meth=SSLv23_server_method();
|
meth=SSLv23_server_method();
|
||||||
|
#elif !defined(OPENSSL_NO_SSL3)
|
||||||
|
meth=SSLv3_server_method();
|
||||||
|
#elif !defined(OPENSSL_NO_SSL2)
|
||||||
|
meth=SSLv2_server_method();
|
||||||
|
#endif
|
||||||
|
|
||||||
local_argc=argc;
|
local_argc=argc;
|
||||||
local_argv=argv;
|
local_argv=argv;
|
||||||
@@ -906,8 +910,6 @@ int MAIN(int argc, char *argv[])
|
|||||||
if (--argc < 1) goto bad;
|
if (--argc < 1) goto bad;
|
||||||
CApath= *(++argv);
|
CApath= *(++argv);
|
||||||
}
|
}
|
||||||
else if (strcmp(*argv,"-no_cache") == 0)
|
|
||||||
no_cache = 1;
|
|
||||||
else if (strcmp(*argv,"-crl_check") == 0)
|
else if (strcmp(*argv,"-crl_check") == 0)
|
||||||
{
|
{
|
||||||
vflags |= X509_V_FLAG_CRL_CHECK;
|
vflags |= X509_V_FLAG_CRL_CHECK;
|
||||||
@@ -918,8 +920,6 @@ int MAIN(int argc, char *argv[])
|
|||||||
}
|
}
|
||||||
else if (strcmp(*argv,"-serverpref") == 0)
|
else if (strcmp(*argv,"-serverpref") == 0)
|
||||||
{ off|=SSL_OP_CIPHER_SERVER_PREFERENCE; }
|
{ off|=SSL_OP_CIPHER_SERVER_PREFERENCE; }
|
||||||
else if (strcmp(*argv,"-legacy_renegotiation") == 0)
|
|
||||||
off|=SSL_OP_ALLOW_UNSAFE_LEGACY_RENEGOTIATION;
|
|
||||||
else if (strcmp(*argv,"-cipher") == 0)
|
else if (strcmp(*argv,"-cipher") == 0)
|
||||||
{
|
{
|
||||||
if (--argc < 1) goto bad;
|
if (--argc < 1) goto bad;
|
||||||
@@ -1031,7 +1031,7 @@ int MAIN(int argc, char *argv[])
|
|||||||
else if (strcmp(*argv,"-mtu") == 0)
|
else if (strcmp(*argv,"-mtu") == 0)
|
||||||
{
|
{
|
||||||
if (--argc < 1) goto bad;
|
if (--argc < 1) goto bad;
|
||||||
socket_mtu = atol(*(++argv));
|
mtu = atol(*(++argv));
|
||||||
}
|
}
|
||||||
else if (strcmp(*argv, "-chain") == 0)
|
else if (strcmp(*argv, "-chain") == 0)
|
||||||
cert_chain = 1;
|
cert_chain = 1;
|
||||||
@@ -1071,14 +1071,6 @@ int MAIN(int argc, char *argv[])
|
|||||||
if (--argc < 1) goto bad;
|
if (--argc < 1) goto bad;
|
||||||
s_key_file2= *(++argv);
|
s_key_file2= *(++argv);
|
||||||
}
|
}
|
||||||
|
|
||||||
#endif
|
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
else if (strcmp(*argv,"-jpake") == 0)
|
|
||||||
{
|
|
||||||
if (--argc < 1) goto bad;
|
|
||||||
jpake_secret = *(++argv);
|
|
||||||
}
|
|
||||||
#endif
|
#endif
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
@@ -1095,14 +1087,6 @@ bad:
|
|||||||
sv_usage();
|
sv_usage();
|
||||||
goto end;
|
goto end;
|
||||||
}
|
}
|
||||||
#ifndef OPENSSL_NO_DTLS1
|
|
||||||
if (www && socket_type == SOCK_DGRAM)
|
|
||||||
{
|
|
||||||
BIO_printf(bio_err,
|
|
||||||
"Can't use -HTTP, -www or -WWW with DTLS\n");
|
|
||||||
goto end;
|
|
||||||
}
|
|
||||||
#endif
|
|
||||||
|
|
||||||
SSL_load_error_strings();
|
SSL_load_error_strings();
|
||||||
OpenSSL_add_ssl_algorithms();
|
OpenSSL_add_ssl_algorithms();
|
||||||
@@ -1260,9 +1244,7 @@ bad:
|
|||||||
if (socket_type == SOCK_DGRAM) SSL_CTX_set_read_ahead(ctx, 1);
|
if (socket_type == SOCK_DGRAM) SSL_CTX_set_read_ahead(ctx, 1);
|
||||||
|
|
||||||
if (state) SSL_CTX_set_info_callback(ctx,apps_ssl_info_callback);
|
if (state) SSL_CTX_set_info_callback(ctx,apps_ssl_info_callback);
|
||||||
if (no_cache)
|
|
||||||
SSL_CTX_set_session_cache_mode(ctx, SSL_SESS_CACHE_OFF);
|
|
||||||
else
|
|
||||||
SSL_CTX_sess_set_cache_size(ctx,128);
|
SSL_CTX_sess_set_cache_size(ctx,128);
|
||||||
|
|
||||||
#if 0
|
#if 0
|
||||||
@@ -1330,9 +1312,6 @@ bad:
|
|||||||
|
|
||||||
if (state) SSL_CTX_set_info_callback(ctx2,apps_ssl_info_callback);
|
if (state) SSL_CTX_set_info_callback(ctx2,apps_ssl_info_callback);
|
||||||
|
|
||||||
if (no_cache)
|
|
||||||
SSL_CTX_set_session_cache_mode(ctx2,SSL_SESS_CACHE_OFF);
|
|
||||||
else
|
|
||||||
SSL_CTX_sess_set_cache_size(ctx2,128);
|
SSL_CTX_sess_set_cache_size(ctx2,128);
|
||||||
|
|
||||||
if ((!SSL_CTX_load_verify_locations(ctx2,CAfile,CApath)) ||
|
if ((!SSL_CTX_load_verify_locations(ctx2,CAfile,CApath)) ||
|
||||||
@@ -1510,10 +1489,6 @@ bad:
|
|||||||
SSL_CTX_set_session_id_context(ctx,(void*)&s_server_session_id_context,
|
SSL_CTX_set_session_id_context(ctx,(void*)&s_server_session_id_context,
|
||||||
sizeof s_server_session_id_context);
|
sizeof s_server_session_id_context);
|
||||||
|
|
||||||
/* Set DTLS cookie generation and verification callbacks */
|
|
||||||
SSL_CTX_set_cookie_generate_cb(ctx, generate_cookie_callback);
|
|
||||||
SSL_CTX_set_cookie_verify_cb(ctx, verify_cookie_callback);
|
|
||||||
|
|
||||||
#ifndef OPENSSL_NO_TLSEXT
|
#ifndef OPENSSL_NO_TLSEXT
|
||||||
if (ctx2)
|
if (ctx2)
|
||||||
{
|
{
|
||||||
@@ -1558,12 +1533,6 @@ end:
|
|||||||
if (dpass)
|
if (dpass)
|
||||||
OPENSSL_free(dpass);
|
OPENSSL_free(dpass);
|
||||||
#ifndef OPENSSL_NO_TLSEXT
|
#ifndef OPENSSL_NO_TLSEXT
|
||||||
if (tlscstatp.host)
|
|
||||||
OPENSSL_free(tlscstatp.host);
|
|
||||||
if (tlscstatp.port)
|
|
||||||
OPENSSL_free(tlscstatp.port);
|
|
||||||
if (tlscstatp.path)
|
|
||||||
OPENSSL_free(tlscstatp.path);
|
|
||||||
if (ctx2 != NULL) SSL_CTX_free(ctx2);
|
if (ctx2 != NULL) SSL_CTX_free(ctx2);
|
||||||
if (s_cert2)
|
if (s_cert2)
|
||||||
X509_free(s_cert2);
|
X509_free(s_cert2);
|
||||||
@@ -1613,11 +1582,8 @@ static int sv_body(char *hostname, int s, unsigned char *context)
|
|||||||
unsigned long l;
|
unsigned long l;
|
||||||
SSL *con=NULL;
|
SSL *con=NULL;
|
||||||
BIO *sbio;
|
BIO *sbio;
|
||||||
struct timeval timeout;
|
|
||||||
#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MSDOS) || defined(OPENSSL_SYS_NETWARE)
|
#if defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MSDOS) || defined(OPENSSL_SYS_NETWARE)
|
||||||
struct timeval tv;
|
struct timeval tv;
|
||||||
#else
|
|
||||||
struct timeval *timeoutp;
|
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
if ((buf=OPENSSL_malloc(bufsize)) == NULL)
|
if ((buf=OPENSSL_malloc(bufsize)) == NULL)
|
||||||
@@ -1669,6 +1635,7 @@ static int sv_body(char *hostname, int s, unsigned char *context)
|
|||||||
|
|
||||||
if (SSL_version(con) == DTLS1_VERSION)
|
if (SSL_version(con) == DTLS1_VERSION)
|
||||||
{
|
{
|
||||||
|
struct timeval timeout;
|
||||||
|
|
||||||
sbio=BIO_new_dgram(s,BIO_NOCLOSE);
|
sbio=BIO_new_dgram(s,BIO_NOCLOSE);
|
||||||
|
|
||||||
@@ -1684,10 +1651,10 @@ static int sv_body(char *hostname, int s, unsigned char *context)
|
|||||||
}
|
}
|
||||||
|
|
||||||
|
|
||||||
if (socket_mtu > 28)
|
if ( mtu > 0)
|
||||||
{
|
{
|
||||||
SSL_set_options(con, SSL_OP_NO_QUERY_MTU);
|
SSL_set_options(con, SSL_OP_NO_QUERY_MTU);
|
||||||
SSL_set_mtu(con, socket_mtu - 28);
|
SSL_set_mtu(con, mtu);
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
/* want to do MTU discovery */
|
/* want to do MTU discovery */
|
||||||
@@ -1706,11 +1673,6 @@ static int sv_body(char *hostname, int s, unsigned char *context)
|
|||||||
test=BIO_new(BIO_f_nbio_test());
|
test=BIO_new(BIO_f_nbio_test());
|
||||||
sbio=BIO_push(test,sbio);
|
sbio=BIO_push(test,sbio);
|
||||||
}
|
}
|
||||||
#ifndef OPENSSL_NO_JPAKE
|
|
||||||
if(jpake_secret)
|
|
||||||
jpake_server_auth(bio_s_out, sbio, jpake_secret);
|
|
||||||
#endif
|
|
||||||
|
|
||||||
SSL_set_bio(con,sbio,sbio);
|
SSL_set_bio(con,sbio,sbio);
|
||||||
SSL_set_accept_state(con);
|
SSL_set_accept_state(con);
|
||||||
/* SSL_set_fd(con,s); */
|
/* SSL_set_fd(con,s); */
|
||||||
@@ -1769,19 +1731,7 @@ static int sv_body(char *hostname, int s, unsigned char *context)
|
|||||||
if(_kbhit())
|
if(_kbhit())
|
||||||
read_from_terminal = 1;
|
read_from_terminal = 1;
|
||||||
#else
|
#else
|
||||||
if ((SSL_version(con) == DTLS1_VERSION) &&
|
i=select(width,(void *)&readfds,NULL,NULL,NULL);
|
||||||
DTLSv1_get_timeout(con, &timeout))
|
|
||||||
timeoutp = &timeout;
|
|
||||||
else
|
|
||||||
timeoutp = NULL;
|
|
||||||
|
|
||||||
i=select(width,(void *)&readfds,NULL,NULL,timeoutp);
|
|
||||||
|
|
||||||
if ((SSL_version(con) == DTLS1_VERSION) && DTLSv1_handle_timeout(con) > 0)
|
|
||||||
{
|
|
||||||
BIO_printf(bio_err,"TIMEOUT occured\n");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (i <= 0) continue;
|
if (i <= 0) continue;
|
||||||
if (FD_ISSET(fileno(stdin),&readfds))
|
if (FD_ISSET(fileno(stdin),&readfds))
|
||||||
read_from_terminal = 1;
|
read_from_terminal = 1;
|
||||||
@@ -1930,10 +1880,8 @@ again:
|
|||||||
#ifdef CHARSET_EBCDIC
|
#ifdef CHARSET_EBCDIC
|
||||||
ascii2ebcdic(buf,buf,i);
|
ascii2ebcdic(buf,buf,i);
|
||||||
#endif
|
#endif
|
||||||
if (write(fileno(stdout),buf,
|
write(fileno(stdout),buf,
|
||||||
(unsigned int)i) != i)
|
(unsigned int)i);
|
||||||
goto err;
|
|
||||||
|
|
||||||
if (SSL_pending(con)) goto again;
|
if (SSL_pending(con)) goto again;
|
||||||
break;
|
break;
|
||||||
case SSL_ERROR_WANT_WRITE:
|
case SSL_ERROR_WANT_WRITE:
|
||||||
@@ -2040,8 +1988,6 @@ static int init_ssl_connection(SSL *con)
|
|||||||
con->kssl_ctx->client_princ);
|
con->kssl_ctx->client_princ);
|
||||||
}
|
}
|
||||||
#endif /* OPENSSL_NO_KRB5 */
|
#endif /* OPENSSL_NO_KRB5 */
|
||||||
BIO_printf(bio_s_out, "Secure Renegotiation IS%s supported\n",
|
|
||||||
SSL_get_secure_renegotiation_support(con) ? "" : " NOT");
|
|
||||||
return(1);
|
return(1);
|
||||||
}
|
}
|
||||||
|
|
||||||
@@ -2085,14 +2031,12 @@ static int www_body(char *hostname, int s, unsigned char *context)
|
|||||||
{
|
{
|
||||||
char *buf=NULL;
|
char *buf=NULL;
|
||||||
int ret=1;
|
int ret=1;
|
||||||
int i,j,k,dot;
|
int i,j,k,blank,dot;
|
||||||
struct stat st_buf;
|
struct stat st_buf;
|
||||||
SSL *con;
|
SSL *con;
|
||||||
SSL_CIPHER *c;
|
SSL_CIPHER *c;
|
||||||
BIO *io,*ssl_bio,*sbio;
|
BIO *io,*ssl_bio,*sbio;
|
||||||
#ifdef RENEG
|
|
||||||
long total_bytes;
|
long total_bytes;
|
||||||
#endif
|
|
||||||
|
|
||||||
buf=OPENSSL_malloc(bufsize);
|
buf=OPENSSL_malloc(bufsize);
|
||||||
if (buf == NULL) return(0);
|
if (buf == NULL) return(0);
|
||||||
@@ -2163,6 +2107,7 @@ static int www_body(char *hostname, int s, unsigned char *context)
|
|||||||
SSL_set_msg_callback_arg(con, bio_s_out);
|
SSL_set_msg_callback_arg(con, bio_s_out);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
blank=0;
|
||||||
for (;;)
|
for (;;)
|
||||||
{
|
{
|
||||||
if (hack)
|
if (hack)
|
||||||
@@ -2399,9 +2344,7 @@ static int www_body(char *hostname, int s, unsigned char *context)
|
|||||||
BIO_puts(io,"HTTP/1.0 200 ok\r\nContent-type: text/plain\r\n\r\n");
|
BIO_puts(io,"HTTP/1.0 200 ok\r\nContent-type: text/plain\r\n\r\n");
|
||||||
}
|
}
|
||||||
/* send the file */
|
/* send the file */
|
||||||
#ifdef RENEG
|
|
||||||
total_bytes=0;
|
total_bytes=0;
|
||||||
#endif
|
|
||||||
for (;;)
|
for (;;)
|
||||||
{
|
{
|
||||||
i=BIO_read(file,buf,bufsize);
|
i=BIO_read(file,buf,bufsize);
|
||||||
|
|||||||
@@ -62,12 +62,6 @@
|
|||||||
#include <errno.h>
|
#include <errno.h>
|
||||||
#include <signal.h>
|
#include <signal.h>
|
||||||
|
|
||||||
#ifdef FLAT_INC
|
|
||||||
#include "e_os2.h"
|
|
||||||
#else
|
|
||||||
#include "../e_os2.h"
|
|
||||||
#endif
|
|
||||||
|
|
||||||
/* With IPv6, it looks like Digital has mixed up the proper order of
|
/* With IPv6, it looks like Digital has mixed up the proper order of
|
||||||
recursive header file inclusion, resulting in the compiler complaining
|
recursive header file inclusion, resulting in the compiler complaining
|
||||||
that u_int isn't defined, but only if _POSIX_C_SOURCE is defined, which
|
that u_int isn't defined, but only if _POSIX_C_SOURCE is defined, which
|
||||||
@@ -329,7 +323,7 @@ static int init_server_long(int *sock, int port, char *ip, int type)
|
|||||||
{
|
{
|
||||||
int ret=0;
|
int ret=0;
|
||||||
struct sockaddr_in server;
|
struct sockaddr_in server;
|
||||||
int s= -1;
|
int s= -1,i;
|
||||||
|
|
||||||
if (!ssl_sock_init()) return(0);
|
if (!ssl_sock_init()) return(0);
|
||||||
|
|
||||||
@@ -368,6 +362,7 @@ static int init_server_long(int *sock, int port, char *ip, int type)
|
|||||||
}
|
}
|
||||||
/* Make it 128 for linux */
|
/* Make it 128 for linux */
|
||||||
if (type==SOCK_STREAM && listen(s,128) == -1) goto err;
|
if (type==SOCK_STREAM && listen(s,128) == -1) goto err;
|
||||||
|
i=0;
|
||||||
*sock=s;
|
*sock=s;
|
||||||
ret=1;
|
ret=1;
|
||||||
err:
|
err:
|
||||||
@@ -385,7 +380,7 @@ static int init_server(int *sock, int port, int type)
|
|||||||
|
|
||||||
static int do_accept(int acc_sock, int *sock, char **host)
|
static int do_accept(int acc_sock, int *sock, char **host)
|
||||||
{
|
{
|
||||||
int ret;
|
int ret,i;
|
||||||
struct hostent *h1,*h2;
|
struct hostent *h1,*h2;
|
||||||
static struct sockaddr_in from;
|
static struct sockaddr_in from;
|
||||||
int len;
|
int len;
|
||||||
@@ -408,7 +403,6 @@ redoit:
|
|||||||
if (ret == INVALID_SOCKET)
|
if (ret == INVALID_SOCKET)
|
||||||
{
|
{
|
||||||
#if defined(OPENSSL_SYS_WINDOWS) || (defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK))
|
#if defined(OPENSSL_SYS_WINDOWS) || (defined(OPENSSL_SYS_NETWARE) && !defined(NETWARE_BSDSOCK))
|
||||||
int i;
|
|
||||||
i=WSAGetLastError();
|
i=WSAGetLastError();
|
||||||
BIO_printf(bio_err,"accept error %d\n",i);
|
BIO_printf(bio_err,"accept error %d\n",i);
|
||||||
#else
|
#else
|
||||||
@@ -463,6 +457,7 @@ redoit:
|
|||||||
BIO_printf(bio_err,"gethostbyname failure\n");
|
BIO_printf(bio_err,"gethostbyname failure\n");
|
||||||
return(0);
|
return(0);
|
||||||
}
|
}
|
||||||
|
i=0;
|
||||||
if (h2->h_addrtype != AF_INET)
|
if (h2->h_addrtype != AF_INET)
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,"gethostbyname addr is not AF_INET\n");
|
BIO_printf(bio_err,"gethostbyname addr is not AF_INET\n");
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* smime.c */
|
/* smime.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project.
|
* project.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
@@ -521,8 +521,8 @@ int MAIN(int argc, char **argv)
|
|||||||
{
|
{
|
||||||
if (!cipher)
|
if (!cipher)
|
||||||
{
|
{
|
||||||
#ifndef OPENSSL_NO_DES
|
#ifndef OPENSSL_NO_RC2
|
||||||
cipher = EVP_des_ede3_cbc();
|
cipher = EVP_rc2_40_cbc();
|
||||||
#else
|
#else
|
||||||
BIO_printf(bio_err, "No cipher selected\n");
|
BIO_printf(bio_err, "No cipher selected\n");
|
||||||
goto end;
|
goto end;
|
||||||
|
|||||||
58
apps/speed.c
58
apps/speed.c
@@ -254,19 +254,9 @@
|
|||||||
# endif
|
# endif
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
#ifndef HAVE_FORK
|
#if !defined(OPENSSL_SYS_VMS) && !defined(OPENSSL_SYS_WINDOWS) && !defined(OPENSSL_SYS_MACINTOSH_CLASSIC) && !defined(OPENSSL_SYS_OS2) && !defined(OPENSSL_SYS_NETWARE)
|
||||||
# if defined(OPENSSL_SYS_VMS) || defined(OPENSSL_SYS_WINDOWS) || defined(OPENSSL_SYS_MACINTOSH_CLASSIC) || defined(OPENSSL_SYS_OS2) || defined(OPENSSL_SYS_NETWARE)
|
|
||||||
# define HAVE_FORK 0
|
|
||||||
# else
|
|
||||||
# define HAVE_FORK 1
|
# define HAVE_FORK 1
|
||||||
#endif
|
#endif
|
||||||
#endif
|
|
||||||
|
|
||||||
#if HAVE_FORK
|
|
||||||
# undef NO_FORK
|
|
||||||
#else
|
|
||||||
# define NO_FORK
|
|
||||||
#endif
|
|
||||||
|
|
||||||
#undef BUFSIZE
|
#undef BUFSIZE
|
||||||
#define BUFSIZE ((long)1024*8+1)
|
#define BUFSIZE ((long)1024*8+1)
|
||||||
@@ -281,7 +271,7 @@ static void print_message(const char *s,long num,int length);
|
|||||||
static void pkey_print_message(const char *str, const char *str2,
|
static void pkey_print_message(const char *str, const char *str2,
|
||||||
long num, int bits, int sec);
|
long num, int bits, int sec);
|
||||||
static void print_result(int alg,int run_no,int count,double time_used);
|
static void print_result(int alg,int run_no,int count,double time_used);
|
||||||
#ifndef NO_FORK
|
#ifdef HAVE_FORK
|
||||||
static int do_multi(int multi);
|
static int do_multi(int multi);
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -303,12 +293,8 @@ static const char *names[ALGOR_NUM]={
|
|||||||
"aes-128 ige","aes-192 ige","aes-256 ige"};
|
"aes-128 ige","aes-192 ige","aes-256 ige"};
|
||||||
static double results[ALGOR_NUM][SIZE_NUM];
|
static double results[ALGOR_NUM][SIZE_NUM];
|
||||||
static int lengths[SIZE_NUM]={16,64,256,1024,8*1024};
|
static int lengths[SIZE_NUM]={16,64,256,1024,8*1024};
|
||||||
#ifndef OPENSSL_NO_RSA
|
|
||||||
static double rsa_results[RSA_NUM][2];
|
static double rsa_results[RSA_NUM][2];
|
||||||
#endif
|
|
||||||
#ifndef OPENSSL_NO_DSA
|
|
||||||
static double dsa_results[DSA_NUM][2];
|
static double dsa_results[DSA_NUM][2];
|
||||||
#endif
|
|
||||||
#ifndef OPENSSL_NO_ECDSA
|
#ifndef OPENSSL_NO_ECDSA
|
||||||
static double ecdsa_results[EC_NUM][2];
|
static double ecdsa_results[EC_NUM][2];
|
||||||
#endif
|
#endif
|
||||||
@@ -500,6 +486,9 @@ int MAIN(int, char **);
|
|||||||
|
|
||||||
int MAIN(int argc, char **argv)
|
int MAIN(int argc, char **argv)
|
||||||
{
|
{
|
||||||
|
#ifndef OPENSSL_NO_ENGINE
|
||||||
|
ENGINE *e = NULL;
|
||||||
|
#endif
|
||||||
unsigned char *buf=NULL,*buf2=NULL;
|
unsigned char *buf=NULL,*buf2=NULL;
|
||||||
int mret=1;
|
int mret=1;
|
||||||
long count=0,save_count=0;
|
long count=0,save_count=0;
|
||||||
@@ -590,6 +579,7 @@ int MAIN(int argc, char **argv)
|
|||||||
unsigned char DES_iv[8];
|
unsigned char DES_iv[8];
|
||||||
unsigned char iv[2*MAX_BLOCK_SIZE/8];
|
unsigned char iv[2*MAX_BLOCK_SIZE/8];
|
||||||
#ifndef OPENSSL_NO_DES
|
#ifndef OPENSSL_NO_DES
|
||||||
|
DES_cblock *buf_as_des_cblock = NULL;
|
||||||
static DES_cblock key ={0x12,0x34,0x56,0x78,0x9a,0xbc,0xde,0xf0};
|
static DES_cblock key ={0x12,0x34,0x56,0x78,0x9a,0xbc,0xde,0xf0};
|
||||||
static DES_cblock key2={0x34,0x56,0x78,0x9a,0xbc,0xde,0xf0,0x12};
|
static DES_cblock key2={0x34,0x56,0x78,0x9a,0xbc,0xde,0xf0,0x12};
|
||||||
static DES_cblock key3={0x56,0x78,0x9a,0xbc,0xde,0xf0,0x12,0x34};
|
static DES_cblock key3={0x56,0x78,0x9a,0xbc,0xde,0xf0,0x12,0x34};
|
||||||
@@ -759,7 +749,7 @@ int MAIN(int argc, char **argv)
|
|||||||
const EVP_CIPHER *evp_cipher=NULL;
|
const EVP_CIPHER *evp_cipher=NULL;
|
||||||
const EVP_MD *evp_md=NULL;
|
const EVP_MD *evp_md=NULL;
|
||||||
int decrypt=0;
|
int decrypt=0;
|
||||||
#ifndef NO_FORK
|
#ifdef HAVE_FORK
|
||||||
int multi=0;
|
int multi=0;
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
@@ -802,6 +792,9 @@ int MAIN(int argc, char **argv)
|
|||||||
BIO_printf(bio_err,"out of memory\n");
|
BIO_printf(bio_err,"out of memory\n");
|
||||||
goto end;
|
goto end;
|
||||||
}
|
}
|
||||||
|
#ifndef OPENSSL_NO_DES
|
||||||
|
buf_as_des_cblock = (DES_cblock *)buf;
|
||||||
|
#endif
|
||||||
if ((buf2=(unsigned char *)OPENSSL_malloc((int)BUFSIZE)) == NULL)
|
if ((buf2=(unsigned char *)OPENSSL_malloc((int)BUFSIZE)) == NULL)
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,"out of memory\n");
|
BIO_printf(bio_err,"out of memory\n");
|
||||||
@@ -876,7 +869,7 @@ int MAIN(int argc, char **argv)
|
|||||||
BIO_printf(bio_err,"no engine given\n");
|
BIO_printf(bio_err,"no engine given\n");
|
||||||
goto end;
|
goto end;
|
||||||
}
|
}
|
||||||
setup_engine(bio_err, *argv, 0);
|
e = setup_engine(bio_err, *argv, 0);
|
||||||
/* j will be increased again further down. We just
|
/* j will be increased again further down. We just
|
||||||
don't want speed to confuse an engine with an
|
don't want speed to confuse an engine with an
|
||||||
algorithm, especially when none is given (which
|
algorithm, especially when none is given (which
|
||||||
@@ -884,7 +877,7 @@ int MAIN(int argc, char **argv)
|
|||||||
j--;
|
j--;
|
||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
#ifndef NO_FORK
|
#ifdef HAVE_FORK
|
||||||
else if ((argc > 0) && (strcmp(*argv,"-multi") == 0))
|
else if ((argc > 0) && (strcmp(*argv,"-multi") == 0))
|
||||||
{
|
{
|
||||||
argc--;
|
argc--;
|
||||||
@@ -1264,7 +1257,7 @@ int MAIN(int argc, char **argv)
|
|||||||
BIO_printf(bio_err,"-evp e use EVP e.\n");
|
BIO_printf(bio_err,"-evp e use EVP e.\n");
|
||||||
BIO_printf(bio_err,"-decrypt time decryption instead of encryption (only EVP).\n");
|
BIO_printf(bio_err,"-decrypt time decryption instead of encryption (only EVP).\n");
|
||||||
BIO_printf(bio_err,"-mr produce machine readable output.\n");
|
BIO_printf(bio_err,"-mr produce machine readable output.\n");
|
||||||
#ifndef NO_FORK
|
#ifdef HAVE_FORK
|
||||||
BIO_printf(bio_err,"-multi n run n benchmarks in parallel.\n");
|
BIO_printf(bio_err,"-multi n run n benchmarks in parallel.\n");
|
||||||
#endif
|
#endif
|
||||||
goto end;
|
goto end;
|
||||||
@@ -1274,7 +1267,7 @@ int MAIN(int argc, char **argv)
|
|||||||
j++;
|
j++;
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifndef NO_FORK
|
#ifdef HAVE_FORK
|
||||||
if(multi && do_multi(multi))
|
if(multi && do_multi(multi))
|
||||||
goto show_res;
|
goto show_res;
|
||||||
#endif
|
#endif
|
||||||
@@ -1381,8 +1374,7 @@ int MAIN(int argc, char **argv)
|
|||||||
count*=2;
|
count*=2;
|
||||||
Time_F(START);
|
Time_F(START);
|
||||||
for (it=count; it; it--)
|
for (it=count; it; it--)
|
||||||
DES_ecb_encrypt((DES_cblock *)buf,
|
DES_ecb_encrypt(buf_as_des_cblock,buf_as_des_cblock,
|
||||||
(DES_cblock *)buf,
|
|
||||||
&sch,DES_ENCRYPT);
|
&sch,DES_ENCRYPT);
|
||||||
d=Time_F(STOP);
|
d=Time_F(STOP);
|
||||||
} while (d <3);
|
} while (d <3);
|
||||||
@@ -2140,7 +2132,7 @@ int MAIN(int argc, char **argv)
|
|||||||
{
|
{
|
||||||
ret=RSA_verify(NID_md5_sha1, buf,36, buf2,
|
ret=RSA_verify(NID_md5_sha1, buf,36, buf2,
|
||||||
rsa_num, rsa_key[j]);
|
rsa_num, rsa_key[j]);
|
||||||
if (ret <= 0)
|
if (ret == 0)
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,
|
BIO_printf(bio_err,
|
||||||
"RSA verify failure\n");
|
"RSA verify failure\n");
|
||||||
@@ -2470,7 +2462,7 @@ int MAIN(int argc, char **argv)
|
|||||||
}
|
}
|
||||||
if (rnd_fake) RAND_cleanup();
|
if (rnd_fake) RAND_cleanup();
|
||||||
#endif
|
#endif
|
||||||
#ifndef NO_FORK
|
#ifdef HAVE_FORK
|
||||||
show_res:
|
show_res:
|
||||||
#endif
|
#endif
|
||||||
if(!mr)
|
if(!mr)
|
||||||
@@ -2725,7 +2717,7 @@ static void print_result(int alg,int run_no,int count,double time_used)
|
|||||||
results[alg][run_no]=((double)count)/time_used*lengths[run_no];
|
results[alg][run_no]=((double)count)/time_used*lengths[run_no];
|
||||||
}
|
}
|
||||||
|
|
||||||
#ifndef NO_FORK
|
#ifdef HAVE_FORK
|
||||||
static char *sstrsep(char **string, const char *delim)
|
static char *sstrsep(char **string, const char *delim)
|
||||||
{
|
{
|
||||||
char isdelim[256];
|
char isdelim[256];
|
||||||
@@ -2767,13 +2759,7 @@ static int do_multi(int multi)
|
|||||||
fds=malloc(multi*sizeof *fds);
|
fds=malloc(multi*sizeof *fds);
|
||||||
for(n=0 ; n < multi ; ++n)
|
for(n=0 ; n < multi ; ++n)
|
||||||
{
|
{
|
||||||
if (pipe(fd) == -1)
|
pipe(fd);
|
||||||
{
|
|
||||||
fprintf(stderr, "pipe failure\n");
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
fflush(stdout);
|
|
||||||
fflush(stderr);
|
|
||||||
if(fork())
|
if(fork())
|
||||||
{
|
{
|
||||||
close(fd[1]);
|
close(fd[1]);
|
||||||
@@ -2783,11 +2769,7 @@ static int do_multi(int multi)
|
|||||||
{
|
{
|
||||||
close(fd[0]);
|
close(fd[0]);
|
||||||
close(1);
|
close(1);
|
||||||
if (dup(fd[1]) == -1)
|
dup(fd[1]);
|
||||||
{
|
|
||||||
fprintf(stderr, "dup failed\n");
|
|
||||||
exit(1);
|
|
||||||
}
|
|
||||||
close(fd[1]);
|
close(fd[1]);
|
||||||
mr=1;
|
mr=1;
|
||||||
usertime=0;
|
usertime=0;
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
/* apps/spkac.c */
|
/* apps/spkac.c */
|
||||||
|
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 1999. Based on an original idea by Massimiliano Pala
|
* project 1999. Based on an original idea by Massimiliano Pala
|
||||||
* (madwolf@openca.org).
|
* (madwolf@openca.org).
|
||||||
*/
|
*/
|
||||||
@@ -285,7 +285,7 @@ bad:
|
|||||||
pkey = NETSCAPE_SPKI_get_pubkey(spki);
|
pkey = NETSCAPE_SPKI_get_pubkey(spki);
|
||||||
if(verify) {
|
if(verify) {
|
||||||
i = NETSCAPE_SPKI_verify(spki, pkey);
|
i = NETSCAPE_SPKI_verify(spki, pkey);
|
||||||
if (i > 0) BIO_printf(bio_err, "Signature OK\n");
|
if(i) BIO_printf(bio_err, "Signature OK\n");
|
||||||
else {
|
else {
|
||||||
BIO_printf(bio_err, "Signature Failure\n");
|
BIO_printf(bio_err, "Signature Failure\n");
|
||||||
ERR_print_errors(bio_err);
|
ERR_print_errors(bio_err);
|
||||||
|
|||||||
@@ -266,7 +266,7 @@ static int check(X509_STORE *ctx, char *file, STACK_OF(X509) *uchain, STACK_OF(X
|
|||||||
|
|
||||||
ret=0;
|
ret=0;
|
||||||
end:
|
end:
|
||||||
if (i > 0)
|
if (i)
|
||||||
{
|
{
|
||||||
fprintf(stdout,"OK\n");
|
fprintf(stdout,"OK\n");
|
||||||
ret=1;
|
ret=1;
|
||||||
@@ -367,3 +367,4 @@ static int MS_CALLBACK cb(int ok, X509_STORE_CTX *ctx)
|
|||||||
ERR_clear_error();
|
ERR_clear_error();
|
||||||
return(ok);
|
return(ok);
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -167,7 +167,7 @@ int MAIN(int argc, char **argv)
|
|||||||
date=version=cflags=options=platform=dir=1;
|
date=version=cflags=options=platform=dir=1;
|
||||||
else
|
else
|
||||||
{
|
{
|
||||||
BIO_printf(bio_err,"usage:version -[avbofpd]\n");
|
BIO_printf(bio_err,"usage:version -[avbofp]\n");
|
||||||
ret=1;
|
ret=1;
|
||||||
goto end;
|
goto end;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -114,7 +114,7 @@ static const char *x509_usage[]={
|
|||||||
" -alias - output certificate alias\n",
|
" -alias - output certificate alias\n",
|
||||||
" -noout - no certificate output\n",
|
" -noout - no certificate output\n",
|
||||||
" -ocspid - print OCSP hash values for the subject name and public key\n",
|
" -ocspid - print OCSP hash values for the subject name and public key\n",
|
||||||
" -ocsp_uri - print OCSP Responder URL(s)\n",
|
" -ocspurl - print OCSP Responder URL(s)\n",
|
||||||
" -trustout - output a \"trusted\" certificate\n",
|
" -trustout - output a \"trusted\" certificate\n",
|
||||||
" -clrtrust - clear all trusted purposes\n",
|
" -clrtrust - clear all trusted purposes\n",
|
||||||
" -clrreject - clear all rejected purposes\n",
|
" -clrreject - clear all rejected purposes\n",
|
||||||
@@ -539,6 +539,7 @@ bad:
|
|||||||
if (reqfile)
|
if (reqfile)
|
||||||
{
|
{
|
||||||
EVP_PKEY *pkey;
|
EVP_PKEY *pkey;
|
||||||
|
X509_CINF *ci;
|
||||||
BIO *in;
|
BIO *in;
|
||||||
|
|
||||||
if (!sign_flag && !CA_flag)
|
if (!sign_flag && !CA_flag)
|
||||||
@@ -606,6 +607,7 @@ bad:
|
|||||||
print_name(bio_err, "subject=", X509_REQ_get_subject_name(req), nmflag);
|
print_name(bio_err, "subject=", X509_REQ_get_subject_name(req), nmflag);
|
||||||
|
|
||||||
if ((x=X509_new()) == NULL) goto end;
|
if ((x=X509_new()) == NULL) goto end;
|
||||||
|
ci=x->cert_info;
|
||||||
|
|
||||||
if (sno == NULL)
|
if (sno == NULL)
|
||||||
{
|
{
|
||||||
@@ -969,7 +971,7 @@ bad:
|
|||||||
else
|
else
|
||||||
{
|
{
|
||||||
pk=load_key(bio_err,
|
pk=load_key(bio_err,
|
||||||
keyfile, keyformat, 0,
|
keyfile, FORMAT_PEM, 0,
|
||||||
passin, e, "request key");
|
passin, e, "request key");
|
||||||
if (pk == NULL) goto end;
|
if (pk == NULL) goto end;
|
||||||
}
|
}
|
||||||
@@ -1149,8 +1151,7 @@ static int x509_certify(X509_STORE *ctx, char *CAfile, const EVP_MD *digest,
|
|||||||
/* NOTE: this certificate can/should be self signed, unless it was
|
/* NOTE: this certificate can/should be self signed, unless it was
|
||||||
* a certificate request in which case it is not. */
|
* a certificate request in which case it is not. */
|
||||||
X509_STORE_CTX_set_cert(&xsc,x);
|
X509_STORE_CTX_set_cert(&xsc,x);
|
||||||
X509_STORE_CTX_set_flags(&xsc, X509_V_FLAG_CHECK_SS_SIGNATURE);
|
if (!reqfile && !X509_verify_cert(&xsc))
|
||||||
if (!reqfile && X509_verify_cert(&xsc) <= 0)
|
|
||||||
goto end;
|
goto end;
|
||||||
|
|
||||||
if (!X509_check_private_key(xca,pkey))
|
if (!X509_check_private_key(xca,pkey))
|
||||||
|
|||||||
108
config
108
config
@@ -29,7 +29,7 @@ EXE=""
|
|||||||
for i
|
for i
|
||||||
do
|
do
|
||||||
case "$i" in
|
case "$i" in
|
||||||
-d) PREFIX="debug-";;
|
-d*) PREFIX="debug-";;
|
||||||
-t*) TEST="true";;
|
-t*) TEST="true";;
|
||||||
-h*) TEST="true"; cat <<EOF
|
-h*) TEST="true"; cat <<EOF
|
||||||
Usage: config [options]
|
Usage: config [options]
|
||||||
@@ -48,10 +48,10 @@ done
|
|||||||
|
|
||||||
# First get uname entries that we use below
|
# First get uname entries that we use below
|
||||||
|
|
||||||
[ "$MACHINE" ] || MACHINE=`(uname -m) 2>/dev/null` || MACHINE="unknown"
|
MACHINE=`(uname -m) 2>/dev/null` || MACHINE="unknown"
|
||||||
[ "$RELEASE" ] || RELEASE=`(uname -r) 2>/dev/null` || RELEASE="unknown"
|
RELEASE=`(uname -r) 2>/dev/null` || RELEASE="unknown"
|
||||||
[ "$SYSTEM" ] || SYSTEM=`(uname -s) 2>/dev/null` || SYSTEM="unknown"
|
SYSTEM=`(uname -s) 2>/dev/null` || SYSTEM="unknown"
|
||||||
[ "$BUILD" ] || VERSION=`(uname -v) 2>/dev/null` || VERSION="unknown"
|
VERSION=`(uname -v) 2>/dev/null` || VERSION="unknown"
|
||||||
|
|
||||||
|
|
||||||
# Now test for ISC and SCO, since it is has a braindamaged uname.
|
# Now test for ISC and SCO, since it is has a braindamaged uname.
|
||||||
@@ -399,8 +399,11 @@ exit 0
|
|||||||
# this is where the translation occurs into SSLeay terms
|
# this is where the translation occurs into SSLeay terms
|
||||||
# ---------------------------------------------------------------------------
|
# ---------------------------------------------------------------------------
|
||||||
|
|
||||||
|
# figure out if gcc is available and if so we use it otherwise
|
||||||
|
# we fallback to whatever cc does on the system
|
||||||
GCCVER=`(gcc -dumpversion) 2>/dev/null`
|
GCCVER=`(gcc -dumpversion) 2>/dev/null`
|
||||||
if [ "$GCCVER" != "" ]; then
|
if [ "$GCCVER" != "" ]; then
|
||||||
|
CC=gcc
|
||||||
# then strip off whatever prefix egcs prepends the number with...
|
# then strip off whatever prefix egcs prepends the number with...
|
||||||
# Hopefully, this will work for any future prefixes as well.
|
# Hopefully, this will work for any future prefixes as well.
|
||||||
GCCVER=`echo $GCCVER | LC_ALL=C sed 's/^[a-zA-Z]*\-//'`
|
GCCVER=`echo $GCCVER | LC_ALL=C sed 's/^[a-zA-Z]*\-//'`
|
||||||
@@ -409,18 +412,9 @@ if [ "$GCCVER" != "" ]; then
|
|||||||
# major and minor version numbers.
|
# major and minor version numbers.
|
||||||
# peak single digit before and after first dot, e.g. 2.95.1 gives 29
|
# peak single digit before and after first dot, e.g. 2.95.1 gives 29
|
||||||
GCCVER=`echo $GCCVER | sed 's/\([0-9]\)\.\([0-9]\).*/\1\2/'`
|
GCCVER=`echo $GCCVER | sed 's/\([0-9]\)\.\([0-9]\).*/\1\2/'`
|
||||||
fi
|
|
||||||
|
|
||||||
# Only set CC if not supplied already
|
|
||||||
if [ -z "$CC" ]; then
|
|
||||||
# figure out if gcc is available and if so we use it otherwise
|
|
||||||
# we fallback to whatever cc does on the system
|
|
||||||
if [ "$GCCVER" != "" ]; then
|
|
||||||
CC=gcc
|
|
||||||
else
|
else
|
||||||
CC=cc
|
CC=cc
|
||||||
fi
|
fi
|
||||||
fi
|
|
||||||
GCCVER=${GCCVER:-0}
|
GCCVER=${GCCVER:-0}
|
||||||
if [ "$SYSTEM" = "HP-UX" ];then
|
if [ "$SYSTEM" = "HP-UX" ];then
|
||||||
# By default gcc is a ILP32 compiler (with long long == 64).
|
# By default gcc is a ILP32 compiler (with long long == 64).
|
||||||
@@ -507,20 +501,7 @@ case "$GUESSOS" in
|
|||||||
OUT="irix-mips3-$CC"
|
OUT="irix-mips3-$CC"
|
||||||
;;
|
;;
|
||||||
mips4-sgi-irix64)
|
mips4-sgi-irix64)
|
||||||
echo "WARNING! If you wish to build 64-bit library, then you have to"
|
OUT="irix64-mips4-$CC"
|
||||||
echo " invoke './Configure irix64-mips4-$CC' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have about 5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
#CPU=`(hinv -t cpu) 2>/dev/null | head -1 | sed 's/^CPU:[^R]*R\([0-9]*\).*/\1/'`
|
|
||||||
#CPU=${CPU:-0}
|
|
||||||
#if [ $CPU -ge 5000 ]; then
|
|
||||||
# options="$options -mips4"
|
|
||||||
#else
|
|
||||||
# options="$options -mips3"
|
|
||||||
#fi
|
|
||||||
OUT="irix-mips3-$CC"
|
|
||||||
;;
|
;;
|
||||||
ppc-apple-rhapsody) OUT="rhapsody-ppc-cc" ;;
|
ppc-apple-rhapsody) OUT="rhapsody-ppc-cc" ;;
|
||||||
ppc-apple-darwin*) OUT="darwin-ppc-cc" ;;
|
ppc-apple-darwin*) OUT="darwin-ppc-cc" ;;
|
||||||
@@ -540,25 +521,12 @@ case "$GUESSOS" in
|
|||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
ppc64-*-linux2)
|
ppc64-*-linux2)
|
||||||
echo "WARNING! If you wish to build 64-bit library, then you have to"
|
OUT="linux-ppc64"
|
||||||
echo " invoke './Configure linux-ppc64' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have about 5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
OUT="linux-ppc"
|
|
||||||
;;
|
;;
|
||||||
ppc-*-linux2) OUT="linux-ppc" ;;
|
ppc-*-linux2) OUT="linux-ppc" ;;
|
||||||
ia64-*-linux?) OUT="linux-ia64" ;;
|
ia64-*-linux?) OUT="linux-ia64" ;;
|
||||||
sparc64-*-linux2)
|
sparc64-*-linux2)
|
||||||
echo "WARNING! If you *know* that your GNU C supports 64-bit/V9 ABI"
|
OUT="linux64-sparcv9" ;;
|
||||||
echo " and wish to build 64-bit library, then you have to"
|
|
||||||
echo " invoke './Configure linux64-sparcv9' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have about 5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
OUT="linux-sparcv9" ;;
|
|
||||||
sparc-*-linux2)
|
sparc-*-linux2)
|
||||||
KARCH=`awk '/^type/{print$3;exit(0);}' /proc/cpuinfo`
|
KARCH=`awk '/^type/{print$3;exit(0);}' /proc/cpuinfo`
|
||||||
case ${KARCH:-sun4} in
|
case ${KARCH:-sun4} in
|
||||||
@@ -595,7 +563,7 @@ case "$GUESSOS" in
|
|||||||
sh*-*-linux2) OUT="linux-generic32"; options="$options -DL_ENDIAN" ;;
|
sh*-*-linux2) OUT="linux-generic32"; options="$options -DL_ENDIAN" ;;
|
||||||
m68k*-*-linux2) OUT="linux-generic32"; options="$options -DB_ENDIAN" ;;
|
m68k*-*-linux2) OUT="linux-generic32"; options="$options -DB_ENDIAN" ;;
|
||||||
s390-*-linux2) OUT="linux-generic32"; options="$options -DB_ENDIAN -DNO_ASM" ;;
|
s390-*-linux2) OUT="linux-generic32"; options="$options -DB_ENDIAN -DNO_ASM" ;;
|
||||||
s390x-*-linux2) OUT="linux-generic64"; options="$options -DB_ENDIAN" ;;
|
s390x-*-linux2) OUT="linux-s390x" ;;
|
||||||
x86_64-*-linux?) OUT="linux-x86_64" ;;
|
x86_64-*-linux?) OUT="linux-x86_64" ;;
|
||||||
*86-*-linux2) OUT="linux-elf"
|
*86-*-linux2) OUT="linux-elf"
|
||||||
if [ "$GCCVER" -gt 28 ]; then
|
if [ "$GCCVER" -gt 28 ]; then
|
||||||
@@ -616,32 +584,13 @@ case "$GUESSOS" in
|
|||||||
ISA64=`(isalist) 2>/dev/null | grep sparcv9`
|
ISA64=`(isalist) 2>/dev/null | grep sparcv9`
|
||||||
if [ "$ISA64" != "" ]; then
|
if [ "$ISA64" != "" ]; then
|
||||||
if [ "$CC" = "cc" -a $CCVER -ge 50 ]; then
|
if [ "$CC" = "cc" -a $CCVER -ge 50 ]; then
|
||||||
echo "WARNING! If you wish to build 64-bit library, then you have to"
|
OUT="solaris64-sparcv9-cc"
|
||||||
echo " invoke './Configure solaris64-sparcv9-cc' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have about 5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
elif [ "$CC" = "gcc" -a "$GCC_ARCH" = "-m64" ]; then
|
elif [ "$CC" = "gcc" -a "$GCC_ARCH" = "-m64" ]; then
|
||||||
# $GCC_ARCH denotes default ABI chosen by compiler driver
|
# $GCC_ARCH denotes default ABI chosen by compiler driver
|
||||||
# (first one found on the $PATH). I assume that user
|
# (first one found on the $PATH). I assume that user
|
||||||
# expects certain consistency with the rest of his builds
|
# expects certain consistency with the rest of his builds
|
||||||
# and therefore switch over to 64-bit. <appro>
|
# and therefore switch over to 64-bit. <appro>
|
||||||
OUT="solaris64-sparcv9-gcc"
|
OUT="solaris64-sparcv9-gcc"
|
||||||
echo "WARNING! If you wish to build 32-bit library, then you have to"
|
|
||||||
echo " invoke './Configure solaris-sparcv9-gcc' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have about 5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
elif [ "$GCC_ARCH" = "-m32" ]; then
|
|
||||||
echo "NOTICE! If you *know* that your GNU C supports 64-bit/V9 ABI"
|
|
||||||
echo " and wish to build 64-bit library, then you have to"
|
|
||||||
echo " invoke './Configure solaris64-sparcv9-gcc' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have about 5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
;;
|
;;
|
||||||
@@ -708,23 +657,11 @@ case "$GUESSOS" in
|
|||||||
CPU_VERSION=${CPU_VERSION:-0}
|
CPU_VERSION=${CPU_VERSION:-0}
|
||||||
# See <sys/unistd.h> for further info on CPU_VERSION.
|
# See <sys/unistd.h> for further info on CPU_VERSION.
|
||||||
if [ $CPU_VERSION -ge 768 ]; then # IA-64 CPU
|
if [ $CPU_VERSION -ge 768 ]; then # IA-64 CPU
|
||||||
echo "WARNING! 64-bit ABI is the default configured ABI on HP-UXi."
|
|
||||||
echo " If you wish to build 32-bit library, the you have to"
|
|
||||||
echo " invoke './Configure hpux-ia64-cc' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have about 5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
OUT="hpux64-ia64-cc"
|
OUT="hpux64-ia64-cc"
|
||||||
elif [ $CPU_VERSION -ge 532 ]; then # PA-RISC 2.x CPU
|
elif [ $CPU_VERSION -ge 532 ]; then # PA-RISC 2.x CPU
|
||||||
OUT=${OUT:-"hpux-parisc2-${CC}"}
|
OUT=${OUT:-"hpux-parisc2-${CC}"}
|
||||||
if [ $KERNEL_BITS -eq 64 -a "$CC" = "cc" ]; then
|
if [ $KERNEL_BITS -eq 64 -a "$CC" = "cc" ]; then
|
||||||
echo "WARNING! If you wish to build 64-bit library then you have to"
|
OUT="hpux64-parisc2-${CC}"
|
||||||
echo " invoke './Configure hpux64-parisc2-cc' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have about 5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
elif [ $CPU_VERSION -ge 528 ]; then # PA-RISC 1.1+ CPU
|
elif [ $CPU_VERSION -ge 528 ]; then # PA-RISC 1.1+ CPU
|
||||||
OUT="hpux-parisc-${CC}"
|
OUT="hpux-parisc-${CC}"
|
||||||
@@ -741,22 +678,13 @@ case "$GUESSOS" in
|
|||||||
OBJECT_MODE=${OBJECT_MODE:-32}
|
OBJECT_MODE=${OBJECT_MODE:-32}
|
||||||
if [ "$CC" = "gcc" ]; then
|
if [ "$CC" = "gcc" ]; then
|
||||||
OUT="aix-gcc"
|
OUT="aix-gcc"
|
||||||
if [ $OBJECT_MODE -eq 64 ]; then
|
|
||||||
echo 'Your $OBJECT_MODE was found to be set to 64'
|
|
||||||
OUT="aix64-gcc"
|
|
||||||
fi
|
|
||||||
elif [ $OBJECT_MODE -eq 64 ]; then
|
elif [ $OBJECT_MODE -eq 64 ]; then
|
||||||
echo 'Your $OBJECT_MODE was found to be set to 64'
|
echo 'Your $OBJECT_MODE was found to be set to 64'
|
||||||
OUT="aix64-cc"
|
OUT="aix64-cc"
|
||||||
else
|
else
|
||||||
OUT="aix-cc"
|
OUT="aix-cc"
|
||||||
if [ $KERNEL_BITS -eq 64 ]; then
|
if [ $KERNEL_BITS -eq 64 ]; then
|
||||||
echo "WARNING! If you wish to build 64-bit kit, then you have to"
|
OUT="aix64-cc"
|
||||||
echo " invoke './Configure aix64-cc' *manually*."
|
|
||||||
if [ "$TEST" = "false" -a -t 1 ]; then
|
|
||||||
echo " You have ~5 seconds to press Ctrl-C to abort."
|
|
||||||
(trap "stty `stty -g`" 2 0; stty -icanon min 0 time 50; read waste) <&1
|
|
||||||
fi
|
|
||||||
fi
|
fi
|
||||||
fi
|
fi
|
||||||
if (lsattr -E -O -l `lsdev -c processor|awk '{print$1;exit}'` | grep -i powerpc) >/dev/null 2>&1; then
|
if (lsattr -E -O -l `lsdev -c processor|awk '{print$1;exit}'` | grep -i powerpc) >/dev/null 2>&1; then
|
||||||
@@ -773,8 +701,6 @@ case "$GUESSOS" in
|
|||||||
t3e-cray-unicosmk) OUT="cray-t3e" ;;
|
t3e-cray-unicosmk) OUT="cray-t3e" ;;
|
||||||
j90-cray-unicos) OUT="cray-j90" ;;
|
j90-cray-unicos) OUT="cray-j90" ;;
|
||||||
nsr-tandem-nsk) OUT="tandem-c89" ;;
|
nsr-tandem-nsk) OUT="tandem-c89" ;;
|
||||||
x86pc-*-qnx6) OUT="QNX6-i386" ;;
|
|
||||||
*-*-qnx6) OUT="QNX6" ;;
|
|
||||||
*) OUT=`echo $GUESSOS | awk -F- '{print $3}'`;;
|
*) OUT=`echo $GUESSOS | awk -F- '{print $3}'`;;
|
||||||
esac
|
esac
|
||||||
|
|
||||||
@@ -790,10 +716,6 @@ esac
|
|||||||
# options="$options -DATALLA"
|
# options="$options -DATALLA"
|
||||||
#fi
|
#fi
|
||||||
|
|
||||||
($CC -Wa,--help -c -o /dev/null -x assembler /dev/null 2>&1 | \
|
|
||||||
grep \\--noexecstack) 2>&1 > /dev/null && \
|
|
||||||
options="$options -Wa,--noexecstack"
|
|
||||||
|
|
||||||
# gcc < 2.8 does not support -march=ultrasparc
|
# gcc < 2.8 does not support -march=ultrasparc
|
||||||
if [ "$OUT" = solaris-sparcv9-gcc -a $GCCVER -lt 28 ]
|
if [ "$OUT" = solaris-sparcv9-gcc -a $GCCVER -lt 28 ]
|
||||||
then
|
then
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
/* $LP: LPlib/source/LPdir_vms.c,v 1.20 2004/08/26 13:36:05 _cvs_levitte Exp $ */
|
||||||
/*
|
/*
|
||||||
* Copyright (c) 2004, Richard Levitte <richard@levitte.org>
|
* Copyright (c) 2004, Richard Levitte <richard@levitte.org>
|
||||||
* All rights reserved.
|
* All rights reserved.
|
||||||
@@ -81,12 +82,6 @@ const char *LP_find_file(LP_DIR_CTX **ctx, const char *directory)
|
|||||||
size_t filespeclen = strlen(directory);
|
size_t filespeclen = strlen(directory);
|
||||||
char *filespec = NULL;
|
char *filespec = NULL;
|
||||||
|
|
||||||
if (filespeclen == 0)
|
|
||||||
{
|
|
||||||
errno = ENOENT;
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
/* MUST be a VMS directory specification! Let's estimate if it is. */
|
/* MUST be a VMS directory specification! Let's estimate if it is. */
|
||||||
if (directory[filespeclen-1] != ']'
|
if (directory[filespeclen-1] != ']'
|
||||||
&& directory[filespeclen-1] != '>'
|
&& directory[filespeclen-1] != '>'
|
||||||
|
|||||||
@@ -1,3 +1,4 @@
|
|||||||
|
/* $LP: LPlib/source/LPdir_win.c,v 1.10 2004/08/26 13:36:05 _cvs_levitte Exp $ */
|
||||||
/*
|
/*
|
||||||
* Copyright (c) 2004, Richard Levitte <richard@levitte.org>
|
* Copyright (c) 2004, Richard Levitte <richard@levitte.org>
|
||||||
* All rights reserved.
|
* All rights reserved.
|
||||||
@@ -64,16 +65,6 @@ const char *LP_find_file(LP_DIR_CTX **ctx, const char *directory)
|
|||||||
errno = 0;
|
errno = 0;
|
||||||
if (*ctx == NULL)
|
if (*ctx == NULL)
|
||||||
{
|
{
|
||||||
const char *extdir = directory;
|
|
||||||
char *extdirbuf = NULL;
|
|
||||||
size_t dirlen = strlen (directory);
|
|
||||||
|
|
||||||
if (dirlen == 0)
|
|
||||||
{
|
|
||||||
errno = ENOENT;
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
|
|
||||||
*ctx = (LP_DIR_CTX *)malloc(sizeof(LP_DIR_CTX));
|
*ctx = (LP_DIR_CTX *)malloc(sizeof(LP_DIR_CTX));
|
||||||
if (*ctx == NULL)
|
if (*ctx == NULL)
|
||||||
{
|
{
|
||||||
@@ -82,35 +73,15 @@ const char *LP_find_file(LP_DIR_CTX **ctx, const char *directory)
|
|||||||
}
|
}
|
||||||
memset(*ctx, '\0', sizeof(LP_DIR_CTX));
|
memset(*ctx, '\0', sizeof(LP_DIR_CTX));
|
||||||
|
|
||||||
if (directory[dirlen-1] != '*')
|
|
||||||
{
|
|
||||||
extdirbuf = (char *)malloc(dirlen + 3);
|
|
||||||
if (extdirbuf == NULL)
|
|
||||||
{
|
|
||||||
free(*ctx);
|
|
||||||
*ctx = NULL;
|
|
||||||
errno = ENOMEM;
|
|
||||||
return 0;
|
|
||||||
}
|
|
||||||
if (directory[dirlen-1] != '/' && directory[dirlen-1] != '\\')
|
|
||||||
extdir = strcat(strcpy (extdirbuf,directory),"/*");
|
|
||||||
else
|
|
||||||
extdir = strcat(strcpy (extdirbuf,directory),"*");
|
|
||||||
}
|
|
||||||
|
|
||||||
if (sizeof(TCHAR) != sizeof(char))
|
if (sizeof(TCHAR) != sizeof(char))
|
||||||
{
|
{
|
||||||
TCHAR *wdir = NULL;
|
TCHAR *wdir = NULL;
|
||||||
/* len_0 denotes string length *with* trailing 0 */
|
/* len_0 denotes string length *with* trailing 0 */
|
||||||
size_t index = 0,len_0 = strlen(extdir) + 1;
|
size_t index = 0,len_0 = strlen(directory) + 1;
|
||||||
|
|
||||||
wdir = (TCHAR *)calloc(len_0, sizeof(TCHAR));
|
wdir = (TCHAR *)malloc(len_0 * sizeof(TCHAR));
|
||||||
if (wdir == NULL)
|
if (wdir == NULL)
|
||||||
{
|
{
|
||||||
if (extdirbuf != NULL)
|
|
||||||
{
|
|
||||||
free (extdirbuf);
|
|
||||||
}
|
|
||||||
free(*ctx);
|
free(*ctx);
|
||||||
*ctx = NULL;
|
*ctx = NULL;
|
||||||
errno = ENOMEM;
|
errno = ENOMEM;
|
||||||
@@ -118,23 +89,17 @@ const char *LP_find_file(LP_DIR_CTX **ctx, const char *directory)
|
|||||||
}
|
}
|
||||||
|
|
||||||
#ifdef LP_MULTIBYTE_AVAILABLE
|
#ifdef LP_MULTIBYTE_AVAILABLE
|
||||||
if (!MultiByteToWideChar(CP_ACP, 0, extdir, len_0, (WCHAR *)wdir, len_0))
|
if (!MultiByteToWideChar(CP_ACP, 0, directory, len_0, (WCHAR *)wdir, len_0))
|
||||||
#endif
|
#endif
|
||||||
for (index = 0; index < len_0; index++)
|
for (index = 0; index < len_0; index++)
|
||||||
wdir[index] = (TCHAR)extdir[index];
|
wdir[index] = (TCHAR)directory[index];
|
||||||
|
|
||||||
(*ctx)->handle = FindFirstFile(wdir, &(*ctx)->ctx);
|
(*ctx)->handle = FindFirstFile(wdir, &(*ctx)->ctx);
|
||||||
|
|
||||||
free(wdir);
|
free(wdir);
|
||||||
}
|
}
|
||||||
else
|
else
|
||||||
{
|
(*ctx)->handle = FindFirstFile((TCHAR *)directory, &(*ctx)->ctx);
|
||||||
(*ctx)->handle = FindFirstFile((TCHAR *)extdir, &(*ctx)->ctx);
|
|
||||||
}
|
|
||||||
if (extdirbuf != NULL)
|
|
||||||
{
|
|
||||||
free (extdirbuf);
|
|
||||||
}
|
|
||||||
|
|
||||||
if ((*ctx)->handle == INVALID_HANDLE_VALUE)
|
if ((*ctx)->handle == INVALID_HANDLE_VALUE)
|
||||||
{
|
{
|
||||||
@@ -151,6 +116,7 @@ const char *LP_find_file(LP_DIR_CTX **ctx, const char *directory)
|
|||||||
return 0;
|
return 0;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (sizeof(TCHAR) != sizeof(char))
|
if (sizeof(TCHAR) != sizeof(char))
|
||||||
{
|
{
|
||||||
TCHAR *wdir = (*ctx)->ctx.cFileName;
|
TCHAR *wdir = (*ctx)->ctx.cFileName;
|
||||||
|
|||||||
@@ -30,7 +30,6 @@ AFLAGS=$(ASFLAGS)
|
|||||||
LIBS=
|
LIBS=
|
||||||
|
|
||||||
GENERAL=Makefile README crypto-lib.com install.com
|
GENERAL=Makefile README crypto-lib.com install.com
|
||||||
TEST=constant_time_test.c
|
|
||||||
|
|
||||||
LIB= $(TOP)/libcrypto.a
|
LIB= $(TOP)/libcrypto.a
|
||||||
SHARED_LIB= libcrypto$(SHLIB_EXT)
|
SHARED_LIB= libcrypto$(SHLIB_EXT)
|
||||||
@@ -41,8 +40,7 @@ SRC= $(LIBSRC)
|
|||||||
|
|
||||||
EXHEADER= crypto.h tmdiff.h opensslv.h opensslconf.h ebcdic.h symhacks.h \
|
EXHEADER= crypto.h tmdiff.h opensslv.h opensslconf.h ebcdic.h symhacks.h \
|
||||||
ossl_typ.h
|
ossl_typ.h
|
||||||
HEADER= cryptlib.h buildinf.h md32_common.h o_time.h o_str.h o_dir.h \
|
HEADER= cryptlib.h buildinf.h md32_common.h o_time.h o_str.h o_dir.h $(EXHEADER)
|
||||||
constant_time_locl.h $(EXHEADER)
|
|
||||||
|
|
||||||
ALL= $(GENERAL) $(SRC) $(HEADER)
|
ALL= $(GENERAL) $(SRC) $(HEADER)
|
||||||
|
|
||||||
|
|||||||
@@ -59,6 +59,8 @@ ax86-out.s: asm/aes-586.pl ../perlasm/x86asm.pl
|
|||||||
|
|
||||||
aes-x86_64.s: asm/aes-x86_64.pl
|
aes-x86_64.s: asm/aes-x86_64.pl
|
||||||
$(PERL) asm/aes-x86_64.pl $@
|
$(PERL) asm/aes-x86_64.pl $@
|
||||||
|
# GNU make "catch all"
|
||||||
|
aes-%.s: asm/aes-%.pl; $(PERL) $< $(CFLAGS) > $@
|
||||||
|
|
||||||
files:
|
files:
|
||||||
$(PERL) $(TOP)/util/files.pl Makefile >> $(TOP)/MINFO
|
$(PERL) $(TOP)/util/files.pl Makefile >> $(TOP)/MINFO
|
||||||
@@ -103,8 +105,7 @@ aes_cfb.o: ../../e_os.h ../../include/openssl/aes.h
|
|||||||
aes_cfb.o: ../../include/openssl/e_os2.h ../../include/openssl/opensslconf.h
|
aes_cfb.o: ../../include/openssl/e_os2.h ../../include/openssl/opensslconf.h
|
||||||
aes_cfb.o: aes_cfb.c aes_locl.h
|
aes_cfb.o: aes_cfb.c aes_locl.h
|
||||||
aes_core.o: ../../include/openssl/aes.h ../../include/openssl/e_os2.h
|
aes_core.o: ../../include/openssl/aes.h ../../include/openssl/e_os2.h
|
||||||
aes_core.o: ../../include/openssl/fips.h ../../include/openssl/opensslconf.h
|
aes_core.o: ../../include/openssl/opensslconf.h aes_core.c aes_locl.h
|
||||||
aes_core.o: aes_core.c aes_locl.h
|
|
||||||
aes_ctr.o: ../../include/openssl/aes.h ../../include/openssl/e_os2.h
|
aes_ctr.o: ../../include/openssl/aes.h ../../include/openssl/e_os2.h
|
||||||
aes_ctr.o: ../../include/openssl/opensslconf.h aes_ctr.c aes_locl.h
|
aes_ctr.o: ../../include/openssl/opensslconf.h aes_ctr.c aes_locl.h
|
||||||
aes_ecb.o: ../../include/openssl/aes.h ../../include/openssl/e_os2.h
|
aes_ecb.o: ../../include/openssl/aes.h ../../include/openssl/e_os2.h
|
||||||
@@ -121,11 +122,3 @@ aes_misc.o: ../../include/openssl/opensslconf.h
|
|||||||
aes_misc.o: ../../include/openssl/opensslv.h aes_locl.h aes_misc.c
|
aes_misc.o: ../../include/openssl/opensslv.h aes_locl.h aes_misc.c
|
||||||
aes_ofb.o: ../../include/openssl/aes.h ../../include/openssl/e_os2.h
|
aes_ofb.o: ../../include/openssl/aes.h ../../include/openssl/e_os2.h
|
||||||
aes_ofb.o: ../../include/openssl/opensslconf.h aes_locl.h aes_ofb.c
|
aes_ofb.o: ../../include/openssl/opensslconf.h aes_locl.h aes_ofb.c
|
||||||
aes_wrap.o: ../../e_os.h ../../include/openssl/aes.h
|
|
||||||
aes_wrap.o: ../../include/openssl/bio.h ../../include/openssl/buffer.h
|
|
||||||
aes_wrap.o: ../../include/openssl/crypto.h ../../include/openssl/e_os2.h
|
|
||||||
aes_wrap.o: ../../include/openssl/err.h ../../include/openssl/lhash.h
|
|
||||||
aes_wrap.o: ../../include/openssl/opensslconf.h
|
|
||||||
aes_wrap.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
|
||||||
aes_wrap.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
|
||||||
aes_wrap.o: ../../include/openssl/symhacks.h ../cryptlib.h aes_wrap.c
|
|
||||||
|
|||||||
@@ -201,6 +201,7 @@ void AES_cfb1_encrypt(const unsigned char *in, unsigned char *out,
|
|||||||
assert(in && out && key && ivec && num);
|
assert(in && out && key && ivec && num);
|
||||||
assert(*num == 0);
|
assert(*num == 0);
|
||||||
|
|
||||||
|
memset(out,0,(length+7)/8);
|
||||||
for(n=0 ; n < length ; ++n)
|
for(n=0 ; n < length ; ++n)
|
||||||
{
|
{
|
||||||
c[0]=(in[n/8]&(1 << (7-n%8))) ? 0x80 : 0;
|
c[0]=(in[n/8]&(1 << (7-n%8))) ? 0x80 : 0;
|
||||||
|
|||||||
@@ -85,9 +85,9 @@ int AES_wrap_key(AES_KEY *key, const unsigned char *iv,
|
|||||||
A[7] ^= (unsigned char)(t & 0xff);
|
A[7] ^= (unsigned char)(t & 0xff);
|
||||||
if (t > 0xff)
|
if (t > 0xff)
|
||||||
{
|
{
|
||||||
A[6] ^= (unsigned char)((t >> 8) & 0xff);
|
A[6] ^= (unsigned char)((t & 0xff) >> 8);
|
||||||
A[5] ^= (unsigned char)((t >> 16) & 0xff);
|
A[5] ^= (unsigned char)((t & 0xff) >> 16);
|
||||||
A[4] ^= (unsigned char)((t >> 24) & 0xff);
|
A[4] ^= (unsigned char)((t & 0xff) >> 24);
|
||||||
}
|
}
|
||||||
memcpy(R, B + 8, 8);
|
memcpy(R, B + 8, 8);
|
||||||
}
|
}
|
||||||
@@ -119,9 +119,9 @@ int AES_unwrap_key(AES_KEY *key, const unsigned char *iv,
|
|||||||
A[7] ^= (unsigned char)(t & 0xff);
|
A[7] ^= (unsigned char)(t & 0xff);
|
||||||
if (t > 0xff)
|
if (t > 0xff)
|
||||||
{
|
{
|
||||||
A[6] ^= (unsigned char)((t >> 8) & 0xff);
|
A[6] ^= (unsigned char)((t & 0xff) >> 8);
|
||||||
A[5] ^= (unsigned char)((t >> 16) & 0xff);
|
A[5] ^= (unsigned char)((t & 0xff) >> 16);
|
||||||
A[4] ^= (unsigned char)((t >> 24) & 0xff);
|
A[4] ^= (unsigned char)((t & 0xff) >> 24);
|
||||||
}
|
}
|
||||||
memcpy(B + 8, R, 8);
|
memcpy(B + 8, R, 8);
|
||||||
AES_decrypt(B, B, key);
|
AES_decrypt(B, B, key);
|
||||||
|
|||||||
1071
crypto/aes/asm/aes-s390x.pl
Normal file
1071
crypto/aes/asm/aes-s390x.pl
Normal file
File diff suppressed because it is too large
Load Diff
@@ -751,19 +751,7 @@ $code.=<<___;
|
|||||||
AES_set_encrypt_key:
|
AES_set_encrypt_key:
|
||||||
push %rbx
|
push %rbx
|
||||||
push %rbp
|
push %rbp
|
||||||
sub \$8,%rsp
|
|
||||||
|
|
||||||
call _x86_64_AES_set_encrypt_key
|
|
||||||
|
|
||||||
mov 8(%rsp),%rbp
|
|
||||||
mov 16(%rsp),%rbx
|
|
||||||
add \$24,%rsp
|
|
||||||
ret
|
|
||||||
.size AES_set_encrypt_key,.-AES_set_encrypt_key
|
|
||||||
|
|
||||||
.type _x86_64_AES_set_encrypt_key,\@abi-omnipotent
|
|
||||||
.align 16
|
|
||||||
_x86_64_AES_set_encrypt_key:
|
|
||||||
mov %esi,%ecx # %ecx=bits
|
mov %esi,%ecx # %ecx=bits
|
||||||
mov %rdi,%rsi # %rsi=userKey
|
mov %rdi,%rsi # %rsi=userKey
|
||||||
mov %rdx,%rdi # %rdi=key
|
mov %rdx,%rdi # %rdi=key
|
||||||
@@ -950,8 +938,10 @@ $code.=<<___;
|
|||||||
.Lbadpointer:
|
.Lbadpointer:
|
||||||
mov \$-1,%rax
|
mov \$-1,%rax
|
||||||
.Lexit:
|
.Lexit:
|
||||||
.byte 0xf3,0xc3 # rep ret
|
pop %rbp
|
||||||
.size _x86_64_AES_set_encrypt_key,.-_x86_64_AES_set_encrypt_key
|
pop %rbx
|
||||||
|
ret
|
||||||
|
.size AES_set_encrypt_key,.-AES_set_encrypt_key
|
||||||
___
|
___
|
||||||
|
|
||||||
sub deckey()
|
sub deckey()
|
||||||
@@ -983,14 +973,15 @@ $code.=<<___;
|
|||||||
.type AES_set_decrypt_key,\@function,3
|
.type AES_set_decrypt_key,\@function,3
|
||||||
.align 16
|
.align 16
|
||||||
AES_set_decrypt_key:
|
AES_set_decrypt_key:
|
||||||
push %rbx
|
push %rdx
|
||||||
push %rbp
|
call AES_set_encrypt_key
|
||||||
push %rdx # save key schedule
|
|
||||||
|
|
||||||
call _x86_64_AES_set_encrypt_key
|
|
||||||
mov (%rsp),%r8 # restore key schedule
|
|
||||||
cmp \$0,%eax
|
cmp \$0,%eax
|
||||||
jne .Labort
|
je .Lproceed
|
||||||
|
lea 24(%rsp),%rsp
|
||||||
|
ret
|
||||||
|
.Lproceed:
|
||||||
|
mov (%rsp),%r8 # restore key schedule
|
||||||
|
mov %rbx,(%rsp)
|
||||||
|
|
||||||
mov 240(%r8),%ecx # pull number of rounds
|
mov 240(%r8),%ecx # pull number of rounds
|
||||||
xor %rdi,%rdi
|
xor %rdi,%rdi
|
||||||
@@ -1032,10 +1023,7 @@ $code.=<<___;
|
|||||||
jnz .Lpermute
|
jnz .Lpermute
|
||||||
|
|
||||||
xor %rax,%rax
|
xor %rax,%rax
|
||||||
.Labort:
|
pop %rbx
|
||||||
mov 8(%rsp),%rbp
|
|
||||||
mov 16(%rsp),%rbx
|
|
||||||
add \$24,%rsp
|
|
||||||
ret
|
ret
|
||||||
.size AES_set_decrypt_key,.-AES_set_decrypt_key
|
.size AES_set_decrypt_key,.-AES_set_decrypt_key
|
||||||
___
|
___
|
||||||
@@ -1193,12 +1181,12 @@ AES_cbc_encrypt:
|
|||||||
.Lcbc_cleanup:
|
.Lcbc_cleanup:
|
||||||
cmpl \$0,$mark # was the key schedule copied?
|
cmpl \$0,$mark # was the key schedule copied?
|
||||||
lea $aes_key,%rdi
|
lea $aes_key,%rdi
|
||||||
|
mov $_rsp,%rsp
|
||||||
je .Lcbc_exit
|
je .Lcbc_exit
|
||||||
mov \$240/8,%ecx
|
mov \$240/8,%ecx
|
||||||
xor %rax,%rax
|
xor %rax,%rax
|
||||||
.long 0x90AB48F3 # rep stosq
|
.long 0x90AB48F3 # rep stosq
|
||||||
.Lcbc_exit:
|
.Lcbc_exit:
|
||||||
mov $_rsp,%rsp
|
|
||||||
popfq
|
popfq
|
||||||
pop %r15
|
pop %r15
|
||||||
pop %r14
|
pop %r14
|
||||||
|
|||||||
@@ -213,11 +213,11 @@ a_meth.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
|||||||
a_meth.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
a_meth.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
||||||
a_meth.o: ../../include/openssl/symhacks.h ../cryptlib.h a_meth.c
|
a_meth.o: ../../include/openssl/symhacks.h ../cryptlib.h a_meth.c
|
||||||
a_object.o: ../../e_os.h ../../include/openssl/asn1.h
|
a_object.o: ../../e_os.h ../../include/openssl/asn1.h
|
||||||
a_object.o: ../../include/openssl/bio.h ../../include/openssl/bn.h
|
a_object.o: ../../include/openssl/bio.h ../../include/openssl/buffer.h
|
||||||
a_object.o: ../../include/openssl/buffer.h ../../include/openssl/crypto.h
|
a_object.o: ../../include/openssl/crypto.h ../../include/openssl/e_os2.h
|
||||||
a_object.o: ../../include/openssl/e_os2.h ../../include/openssl/err.h
|
a_object.o: ../../include/openssl/err.h ../../include/openssl/lhash.h
|
||||||
a_object.o: ../../include/openssl/lhash.h ../../include/openssl/obj_mac.h
|
a_object.o: ../../include/openssl/obj_mac.h ../../include/openssl/objects.h
|
||||||
a_object.o: ../../include/openssl/objects.h ../../include/openssl/opensslconf.h
|
a_object.o: ../../include/openssl/opensslconf.h
|
||||||
a_object.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
a_object.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
||||||
a_object.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
a_object.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
||||||
a_object.o: ../../include/openssl/symhacks.h ../cryptlib.h a_object.c
|
a_object.o: ../../include/openssl/symhacks.h ../cryptlib.h a_object.c
|
||||||
@@ -292,8 +292,7 @@ a_type.o: ../../e_os.h ../../include/openssl/asn1.h
|
|||||||
a_type.o: ../../include/openssl/asn1t.h ../../include/openssl/bio.h
|
a_type.o: ../../include/openssl/asn1t.h ../../include/openssl/bio.h
|
||||||
a_type.o: ../../include/openssl/buffer.h ../../include/openssl/crypto.h
|
a_type.o: ../../include/openssl/buffer.h ../../include/openssl/crypto.h
|
||||||
a_type.o: ../../include/openssl/e_os2.h ../../include/openssl/err.h
|
a_type.o: ../../include/openssl/e_os2.h ../../include/openssl/err.h
|
||||||
a_type.o: ../../include/openssl/lhash.h ../../include/openssl/obj_mac.h
|
a_type.o: ../../include/openssl/lhash.h ../../include/openssl/opensslconf.h
|
||||||
a_type.o: ../../include/openssl/objects.h ../../include/openssl/opensslconf.h
|
|
||||||
a_type.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
a_type.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
||||||
a_type.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
a_type.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
||||||
a_type.o: ../../include/openssl/symhacks.h ../cryptlib.h a_type.c
|
a_type.o: ../../include/openssl/symhacks.h ../cryptlib.h a_type.c
|
||||||
@@ -365,21 +364,6 @@ asn1_par.o: ../../include/openssl/opensslconf.h
|
|||||||
asn1_par.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
asn1_par.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
||||||
asn1_par.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
asn1_par.o: ../../include/openssl/safestack.h ../../include/openssl/stack.h
|
||||||
asn1_par.o: ../../include/openssl/symhacks.h ../cryptlib.h asn1_par.c
|
asn1_par.o: ../../include/openssl/symhacks.h ../cryptlib.h asn1_par.c
|
||||||
asn_mime.o: ../../e_os.h ../../include/openssl/asn1.h
|
|
||||||
asn_mime.o: ../../include/openssl/asn1t.h ../../include/openssl/bio.h
|
|
||||||
asn_mime.o: ../../include/openssl/buffer.h ../../include/openssl/crypto.h
|
|
||||||
asn_mime.o: ../../include/openssl/e_os2.h ../../include/openssl/ec.h
|
|
||||||
asn_mime.o: ../../include/openssl/ecdh.h ../../include/openssl/ecdsa.h
|
|
||||||
asn_mime.o: ../../include/openssl/err.h ../../include/openssl/evp.h
|
|
||||||
asn_mime.o: ../../include/openssl/fips.h ../../include/openssl/lhash.h
|
|
||||||
asn_mime.o: ../../include/openssl/obj_mac.h ../../include/openssl/objects.h
|
|
||||||
asn_mime.o: ../../include/openssl/opensslconf.h
|
|
||||||
asn_mime.o: ../../include/openssl/opensslv.h ../../include/openssl/ossl_typ.h
|
|
||||||
asn_mime.o: ../../include/openssl/pkcs7.h ../../include/openssl/rand.h
|
|
||||||
asn_mime.o: ../../include/openssl/safestack.h ../../include/openssl/sha.h
|
|
||||||
asn_mime.o: ../../include/openssl/stack.h ../../include/openssl/symhacks.h
|
|
||||||
asn_mime.o: ../../include/openssl/x509.h ../../include/openssl/x509_vfy.h
|
|
||||||
asn_mime.o: ../cryptlib.h asn_mime.c
|
|
||||||
asn_moid.o: ../../e_os.h ../../include/openssl/asn1.h
|
asn_moid.o: ../../e_os.h ../../include/openssl/asn1.h
|
||||||
asn_moid.o: ../../include/openssl/bio.h ../../include/openssl/buffer.h
|
asn_moid.o: ../../include/openssl/bio.h ../../include/openssl/buffer.h
|
||||||
asn_moid.o: ../../include/openssl/conf.h ../../include/openssl/crypto.h
|
asn_moid.o: ../../include/openssl/conf.h ../../include/openssl/crypto.h
|
||||||
|
|||||||
@@ -136,16 +136,11 @@ ASN1_BIT_STRING *c2i_ASN1_BIT_STRING(ASN1_BIT_STRING **a,
|
|||||||
|
|
||||||
p= *pp;
|
p= *pp;
|
||||||
i= *(p++);
|
i= *(p++);
|
||||||
if (i > 7)
|
|
||||||
{
|
|
||||||
i=ASN1_R_INVALID_BIT_STRING_BITS_LEFT;
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
/* We do this to preserve the settings. If we modify
|
/* We do this to preserve the settings. If we modify
|
||||||
* the settings, via the _set_bit function, we will recalculate
|
* the settings, via the _set_bit function, we will recalculate
|
||||||
* on output */
|
* on output */
|
||||||
ret->flags&= ~(ASN1_STRING_FLAG_BITS_LEFT|0x07); /* clear */
|
ret->flags&= ~(ASN1_STRING_FLAG_BITS_LEFT|0x07); /* clear */
|
||||||
ret->flags|=(ASN1_STRING_FLAG_BITS_LEFT|i); /* set */
|
ret->flags|=(ASN1_STRING_FLAG_BITS_LEFT|(i&0x07)); /* set */
|
||||||
|
|
||||||
if (len-- > 1) /* using one because of the bits left byte */
|
if (len-- > 1) /* using one because of the bits left byte */
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -79,7 +79,7 @@ ASN1_STRING *d2i_ASN1_type_bytes(ASN1_STRING **a, const unsigned char **pp,
|
|||||||
|
|
||||||
if (tag >= 32)
|
if (tag >= 32)
|
||||||
{
|
{
|
||||||
i=ASN1_R_TAG_VALUE_TOO_HIGH;
|
i=ASN1_R_TAG_VALUE_TOO_HIGH;;
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
if (!(ASN1_tag2bit(tag) & type))
|
if (!(ASN1_tag2bit(tag) & type))
|
||||||
|
|||||||
@@ -57,7 +57,6 @@
|
|||||||
*/
|
*/
|
||||||
|
|
||||||
#include <stdio.h>
|
#include <stdio.h>
|
||||||
#include <limits.h>
|
|
||||||
#include "cryptlib.h"
|
#include "cryptlib.h"
|
||||||
#include <openssl/buffer.h>
|
#include <openssl/buffer.h>
|
||||||
#include <openssl/asn1_mac.h>
|
#include <openssl/asn1_mac.h>
|
||||||
@@ -144,11 +143,17 @@ static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
|
|||||||
BUF_MEM *b;
|
BUF_MEM *b;
|
||||||
unsigned char *p;
|
unsigned char *p;
|
||||||
int i;
|
int i;
|
||||||
|
int ret=-1;
|
||||||
ASN1_const_CTX c;
|
ASN1_const_CTX c;
|
||||||
size_t want=HEADER_SIZE;
|
int want=HEADER_SIZE;
|
||||||
int eos=0;
|
int eos=0;
|
||||||
size_t off=0;
|
#if defined(__GNUC__) && defined(__ia64)
|
||||||
size_t len=0;
|
/* pathetic compiler bug in all known versions as of Nov. 2002 */
|
||||||
|
long off=0;
|
||||||
|
#else
|
||||||
|
int off=0;
|
||||||
|
#endif
|
||||||
|
int len=0;
|
||||||
|
|
||||||
b=BUF_MEM_new();
|
b=BUF_MEM_new();
|
||||||
if (b == NULL)
|
if (b == NULL)
|
||||||
@@ -164,7 +169,7 @@ static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
|
|||||||
{
|
{
|
||||||
want-=(len-off);
|
want-=(len-off);
|
||||||
|
|
||||||
if (len + want < len || !BUF_MEM_grow_clean(b,len+want))
|
if (!BUF_MEM_grow_clean(b,len+want))
|
||||||
{
|
{
|
||||||
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ERR_R_MALLOC_FAILURE);
|
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ERR_R_MALLOC_FAILURE);
|
||||||
goto err;
|
goto err;
|
||||||
@@ -176,15 +181,8 @@ static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
|
|||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
if (i > 0)
|
if (i > 0)
|
||||||
{
|
|
||||||
if (len+i < len)
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ASN1_R_TOO_LONG);
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
len+=i;
|
len+=i;
|
||||||
}
|
}
|
||||||
}
|
|
||||||
/* else data already loaded */
|
/* else data already loaded */
|
||||||
|
|
||||||
p=(unsigned char *)&(b->data[off]);
|
p=(unsigned char *)&(b->data[off]);
|
||||||
@@ -208,11 +206,6 @@ static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
|
|||||||
{
|
{
|
||||||
/* no data body so go round again */
|
/* no data body so go round again */
|
||||||
eos++;
|
eos++;
|
||||||
if (eos < 0)
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ASN1_R_HEADER_TOO_LONG);
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
want=HEADER_SIZE;
|
want=HEADER_SIZE;
|
||||||
}
|
}
|
||||||
else if (eos && (c.slen == 0) && (c.tag == V_ASN1_EOC))
|
else if (eos && (c.slen == 0) && (c.tag == V_ASN1_EOC))
|
||||||
@@ -227,16 +220,10 @@ static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
|
|||||||
else
|
else
|
||||||
{
|
{
|
||||||
/* suck in c.slen bytes of data */
|
/* suck in c.slen bytes of data */
|
||||||
want=c.slen;
|
want=(int)c.slen;
|
||||||
if (want > (len-off))
|
if (want > (len-off))
|
||||||
{
|
{
|
||||||
want-=(len-off);
|
want-=(len-off);
|
||||||
if (want > INT_MAX /* BIO_read takes an int length */ ||
|
|
||||||
len+want < len)
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ASN1_R_TOO_LONG);
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
if (!BUF_MEM_grow_clean(b,len+want))
|
if (!BUF_MEM_grow_clean(b,len+want))
|
||||||
{
|
{
|
||||||
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ERR_R_MALLOC_FAILURE);
|
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ERR_R_MALLOC_FAILURE);
|
||||||
@@ -251,18 +238,11 @@ static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
|
|||||||
ASN1_R_NOT_ENOUGH_DATA);
|
ASN1_R_NOT_ENOUGH_DATA);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
/* This can't overflow because
|
|
||||||
* |len+want| didn't overflow. */
|
|
||||||
len+=i;
|
len+=i;
|
||||||
want -= i;
|
want -= i;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
if (off + c.slen < off)
|
off+=(int)c.slen;
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ASN1_R_TOO_LONG);
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
off+=c.slen;
|
|
||||||
if (eos <= 0)
|
if (eos <= 0)
|
||||||
{
|
{
|
||||||
break;
|
break;
|
||||||
@@ -272,15 +252,9 @@ static int asn1_d2i_read_bio(BIO *in, BUF_MEM **pb)
|
|||||||
}
|
}
|
||||||
}
|
}
|
||||||
|
|
||||||
if (off > INT_MAX)
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_D2I_READ_BIO,ASN1_R_TOO_LONG);
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
|
|
||||||
*pb = b;
|
*pb = b;
|
||||||
return off;
|
return off;
|
||||||
err:
|
err:
|
||||||
if (b != NULL) BUF_MEM_free(b);
|
if (b != NULL) BUF_MEM_free(b);
|
||||||
return -1;
|
return(ret);
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -116,7 +116,7 @@ int i2c_ASN1_INTEGER(ASN1_INTEGER *a, unsigned char **pp)
|
|||||||
int pad=0,ret,i,neg;
|
int pad=0,ret,i,neg;
|
||||||
unsigned char *p,*n,pb=0;
|
unsigned char *p,*n,pb=0;
|
||||||
|
|
||||||
if (a == NULL) return(0);
|
if ((a == NULL) || (a->data == NULL)) return(0);
|
||||||
neg=a->type & V_ASN1_NEG;
|
neg=a->type & V_ASN1_NEG;
|
||||||
if (a->length == 0)
|
if (a->length == 0)
|
||||||
ret=1;
|
ret=1;
|
||||||
@@ -273,7 +273,7 @@ ASN1_INTEGER *d2i_ASN1_UINTEGER(ASN1_INTEGER **a, const unsigned char **pp,
|
|||||||
{
|
{
|
||||||
ASN1_INTEGER *ret=NULL;
|
ASN1_INTEGER *ret=NULL;
|
||||||
const unsigned char *p;
|
const unsigned char *p;
|
||||||
unsigned char *s;
|
unsigned char *to,*s;
|
||||||
long len;
|
long len;
|
||||||
int inf,tag,xclass;
|
int inf,tag,xclass;
|
||||||
int i;
|
int i;
|
||||||
@@ -308,6 +308,7 @@ ASN1_INTEGER *d2i_ASN1_UINTEGER(ASN1_INTEGER **a, const unsigned char **pp,
|
|||||||
i=ERR_R_MALLOC_FAILURE;
|
i=ERR_R_MALLOC_FAILURE;
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
|
to=s;
|
||||||
ret->type=V_ASN1_INTEGER;
|
ret->type=V_ASN1_INTEGER;
|
||||||
if(len) {
|
if(len) {
|
||||||
if ((*p == 0) && (len != 1))
|
if ((*p == 0) && (len != 1))
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* a_mbstr.c */
|
/* a_mbstr.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 1999.
|
* project 1999.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
@@ -93,7 +93,7 @@ int ASN1_mbstring_ncopy(ASN1_STRING **out, const unsigned char *in, int len,
|
|||||||
int str_type;
|
int str_type;
|
||||||
int ret;
|
int ret;
|
||||||
char free_out;
|
char free_out;
|
||||||
int outform, outlen = 0;
|
int outform, outlen;
|
||||||
ASN1_STRING *dest;
|
ASN1_STRING *dest;
|
||||||
unsigned char *p;
|
unsigned char *p;
|
||||||
int nchar;
|
int nchar;
|
||||||
|
|||||||
@@ -139,7 +139,7 @@ int a2d_ASN1_OBJECT(unsigned char *out, int olen, const char *buf, int num)
|
|||||||
ASN1err(ASN1_F_A2D_ASN1_OBJECT,ASN1_R_INVALID_DIGIT);
|
ASN1err(ASN1_F_A2D_ASN1_OBJECT,ASN1_R_INVALID_DIGIT);
|
||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
if (!use_bn && l >= ((ULONG_MAX - 80) / 10L))
|
if (!use_bn && l > (ULONG_MAX / 10L))
|
||||||
{
|
{
|
||||||
use_bn = 1;
|
use_bn = 1;
|
||||||
if (!bl)
|
if (!bl)
|
||||||
@@ -285,35 +285,12 @@ err:
|
|||||||
ASN1_OBJECT_free(ret);
|
ASN1_OBJECT_free(ret);
|
||||||
return(NULL);
|
return(NULL);
|
||||||
}
|
}
|
||||||
|
|
||||||
ASN1_OBJECT *c2i_ASN1_OBJECT(ASN1_OBJECT **a, const unsigned char **pp,
|
ASN1_OBJECT *c2i_ASN1_OBJECT(ASN1_OBJECT **a, const unsigned char **pp,
|
||||||
long len)
|
long len)
|
||||||
{
|
{
|
||||||
ASN1_OBJECT *ret=NULL;
|
ASN1_OBJECT *ret=NULL;
|
||||||
const unsigned char *p;
|
const unsigned char *p;
|
||||||
int i, length;
|
int i;
|
||||||
|
|
||||||
/* Sanity check OID encoding.
|
|
||||||
* Need at least one content octet.
|
|
||||||
* MSB must be clear in the last octet.
|
|
||||||
* can't have leading 0x80 in subidentifiers, see: X.690 8.19.2
|
|
||||||
*/
|
|
||||||
if (len <= 0 || len > INT_MAX || pp == NULL || (p = *pp) == NULL ||
|
|
||||||
p[len - 1] & 0x80)
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_C2I_ASN1_OBJECT,ASN1_R_INVALID_OBJECT_ENCODING);
|
|
||||||
return NULL;
|
|
||||||
}
|
|
||||||
/* Now 0 < len <= INT_MAX, so the cast is safe. */
|
|
||||||
length = (int)len;
|
|
||||||
for (i = 0; i < length; i++, p++)
|
|
||||||
{
|
|
||||||
if (*p == 0x80 && (!i || !(p[-1] & 0x80)))
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_C2I_ASN1_OBJECT,ASN1_R_INVALID_OBJECT_ENCODING);
|
|
||||||
return NULL;
|
|
||||||
}
|
|
||||||
}
|
|
||||||
|
|
||||||
/* only the ASN1_OBJECTs from the 'table' will have values
|
/* only the ASN1_OBJECTs from the 'table' will have values
|
||||||
* for ->sn or ->ln */
|
* for ->sn or ->ln */
|
||||||
@@ -325,20 +302,20 @@ ASN1_OBJECT *c2i_ASN1_OBJECT(ASN1_OBJECT **a, const unsigned char **pp,
|
|||||||
else ret=(*a);
|
else ret=(*a);
|
||||||
|
|
||||||
p= *pp;
|
p= *pp;
|
||||||
if ((ret->data == NULL) || (ret->length < length))
|
if ((ret->data == NULL) || (ret->length < len))
|
||||||
{
|
{
|
||||||
if (ret->data != NULL) OPENSSL_free(ret->data);
|
if (ret->data != NULL) OPENSSL_free(ret->data);
|
||||||
ret->data=(unsigned char *)OPENSSL_malloc(length);
|
ret->data=(unsigned char *)OPENSSL_malloc(len ? (int)len : 1);
|
||||||
ret->flags|=ASN1_OBJECT_FLAG_DYNAMIC_DATA;
|
ret->flags|=ASN1_OBJECT_FLAG_DYNAMIC_DATA;
|
||||||
if (ret->data == NULL)
|
if (ret->data == NULL)
|
||||||
{ i=ERR_R_MALLOC_FAILURE; goto err; }
|
{ i=ERR_R_MALLOC_FAILURE; goto err; }
|
||||||
}
|
}
|
||||||
memcpy(ret->data,p,length);
|
memcpy(ret->data,p,(int)len);
|
||||||
ret->length=length;
|
ret->length=(int)len;
|
||||||
ret->sn=NULL;
|
ret->sn=NULL;
|
||||||
ret->ln=NULL;
|
ret->ln=NULL;
|
||||||
/* ret->flags=ASN1_OBJECT_FLAG_DYNAMIC; we know it is dynamic */
|
/* ret->flags=ASN1_OBJECT_FLAG_DYNAMIC; we know it is dynamic */
|
||||||
p+=length;
|
p+=len;
|
||||||
|
|
||||||
if (a != NULL) (*a)=ret;
|
if (a != NULL) (*a)=ret;
|
||||||
*pp=p;
|
*pp=p;
|
||||||
|
|||||||
@@ -267,12 +267,7 @@ int ASN1_item_sign(const ASN1_ITEM *it, X509_ALGOR *algor1, X509_ALGOR *algor2,
|
|||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (!EVP_SignInit_ex(&ctx,type, NULL))
|
EVP_SignInit_ex(&ctx,type, NULL);
|
||||||
{
|
|
||||||
outl=0;
|
|
||||||
ASN1err(ASN1_F_ASN1_ITEM_SIGN,ERR_R_EVP_LIB);
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
EVP_SignUpdate(&ctx,(unsigned char *)buf_in,inl);
|
EVP_SignUpdate(&ctx,(unsigned char *)buf_in,inl);
|
||||||
if (!EVP_SignFinal(&ctx,(unsigned char *)buf_out,
|
if (!EVP_SignFinal(&ctx,(unsigned char *)buf_out,
|
||||||
(unsigned int *)&outl,pkey))
|
(unsigned int *)&outl,pkey))
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* a_strex.c */
|
/* a_strex.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 2000.
|
* project 2000.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
@@ -74,11 +74,6 @@
|
|||||||
|
|
||||||
#define CHARTYPE_BS_ESC (ASN1_STRFLGS_ESC_2253 | CHARTYPE_FIRST_ESC_2253 | CHARTYPE_LAST_ESC_2253)
|
#define CHARTYPE_BS_ESC (ASN1_STRFLGS_ESC_2253 | CHARTYPE_FIRST_ESC_2253 | CHARTYPE_LAST_ESC_2253)
|
||||||
|
|
||||||
#define ESC_FLAGS (ASN1_STRFLGS_ESC_2253 | \
|
|
||||||
ASN1_STRFLGS_ESC_QUOTE | \
|
|
||||||
ASN1_STRFLGS_ESC_CTRL | \
|
|
||||||
ASN1_STRFLGS_ESC_MSB)
|
|
||||||
|
|
||||||
|
|
||||||
/* Three IO functions for sending data to memory, a BIO and
|
/* Three IO functions for sending data to memory, a BIO and
|
||||||
* and a FILE pointer.
|
* and a FILE pointer.
|
||||||
@@ -153,13 +148,6 @@ static int do_esc_char(unsigned long c, unsigned char flags, char *do_quotes, ch
|
|||||||
if(!io_ch(arg, tmphex, 3)) return -1;
|
if(!io_ch(arg, tmphex, 3)) return -1;
|
||||||
return 3;
|
return 3;
|
||||||
}
|
}
|
||||||
/* If we get this far and do any escaping at all must escape
|
|
||||||
* the escape character itself: backslash.
|
|
||||||
*/
|
|
||||||
if (chtmp == '\\' && flags & ESC_FLAGS) {
|
|
||||||
if(!io_ch(arg, "\\\\", 2)) return -1;
|
|
||||||
return 2;
|
|
||||||
}
|
|
||||||
if(!io_ch(arg, &chtmp, 1)) return -1;
|
if(!io_ch(arg, &chtmp, 1)) return -1;
|
||||||
return 1;
|
return 1;
|
||||||
}
|
}
|
||||||
@@ -304,6 +292,11 @@ static const signed char tag2nbyte[] = {
|
|||||||
4, -1, 2 /* 28-30 */
|
4, -1, 2 /* 28-30 */
|
||||||
};
|
};
|
||||||
|
|
||||||
|
#define ESC_FLAGS (ASN1_STRFLGS_ESC_2253 | \
|
||||||
|
ASN1_STRFLGS_ESC_QUOTE | \
|
||||||
|
ASN1_STRFLGS_ESC_CTRL | \
|
||||||
|
ASN1_STRFLGS_ESC_MSB)
|
||||||
|
|
||||||
/* This is the main function, print out an
|
/* This is the main function, print out an
|
||||||
* ASN1_STRING taking note of various escape
|
* ASN1_STRING taking note of various escape
|
||||||
* and display options. Returns number of
|
* and display options. Returns number of
|
||||||
@@ -567,7 +560,6 @@ int ASN1_STRING_to_UTF8(unsigned char **out, ASN1_STRING *in)
|
|||||||
if(mbflag == -1) return -1;
|
if(mbflag == -1) return -1;
|
||||||
mbflag |= MBSTRING_FLAG;
|
mbflag |= MBSTRING_FLAG;
|
||||||
stmp.data = NULL;
|
stmp.data = NULL;
|
||||||
stmp.length = 0;
|
|
||||||
ret = ASN1_mbstring_copy(&str, in->data, in->length, mbflag, B_ASN1_UTF8STRING);
|
ret = ASN1_mbstring_copy(&str, in->data, in->length, mbflag, B_ASN1_UTF8STRING);
|
||||||
if(ret < 0) return ret;
|
if(ret < 0) return ret;
|
||||||
*out = stmp.data;
|
*out = stmp.data;
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* a_strnid.c */
|
/* a_strnid.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 1999.
|
* project 1999.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
@@ -75,7 +75,7 @@ static int table_cmp(const void *a, const void *b);
|
|||||||
* certain software (e.g. Netscape) has problems with them.
|
* certain software (e.g. Netscape) has problems with them.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
static unsigned long global_mask = B_ASN1_UTF8STRING;
|
static unsigned long global_mask = 0xFFFFFFFFL;
|
||||||
|
|
||||||
void ASN1_STRING_set_default_mask(unsigned long mask)
|
void ASN1_STRING_set_default_mask(unsigned long mask)
|
||||||
{
|
{
|
||||||
@@ -96,7 +96,7 @@ unsigned long ASN1_STRING_get_default_mask(void)
|
|||||||
* default: the default value, Printable, T61, BMP.
|
* default: the default value, Printable, T61, BMP.
|
||||||
*/
|
*/
|
||||||
|
|
||||||
int ASN1_STRING_set_default_mask_asc(const char *p)
|
int ASN1_STRING_set_default_mask_asc(char *p)
|
||||||
{
|
{
|
||||||
unsigned long mask;
|
unsigned long mask;
|
||||||
char *end;
|
char *end;
|
||||||
|
|||||||
@@ -108,49 +108,3 @@ int ASN1_TYPE_set1(ASN1_TYPE *a, int type, const void *value)
|
|||||||
|
|
||||||
IMPLEMENT_STACK_OF(ASN1_TYPE)
|
IMPLEMENT_STACK_OF(ASN1_TYPE)
|
||||||
IMPLEMENT_ASN1_SET_OF(ASN1_TYPE)
|
IMPLEMENT_ASN1_SET_OF(ASN1_TYPE)
|
||||||
|
|
||||||
/* Returns 0 if they are equal, != 0 otherwise. */
|
|
||||||
int ASN1_TYPE_cmp(const ASN1_TYPE *a, const ASN1_TYPE *b)
|
|
||||||
{
|
|
||||||
int result = -1;
|
|
||||||
|
|
||||||
if (!a || !b || a->type != b->type) return -1;
|
|
||||||
|
|
||||||
switch (a->type)
|
|
||||||
{
|
|
||||||
case V_ASN1_OBJECT:
|
|
||||||
result = OBJ_cmp(a->value.object, b->value.object);
|
|
||||||
break;
|
|
||||||
case V_ASN1_NULL:
|
|
||||||
result = 0; /* They do not have content. */
|
|
||||||
break;
|
|
||||||
case V_ASN1_INTEGER:
|
|
||||||
case V_ASN1_NEG_INTEGER:
|
|
||||||
case V_ASN1_ENUMERATED:
|
|
||||||
case V_ASN1_NEG_ENUMERATED:
|
|
||||||
case V_ASN1_BIT_STRING:
|
|
||||||
case V_ASN1_OCTET_STRING:
|
|
||||||
case V_ASN1_SEQUENCE:
|
|
||||||
case V_ASN1_SET:
|
|
||||||
case V_ASN1_NUMERICSTRING:
|
|
||||||
case V_ASN1_PRINTABLESTRING:
|
|
||||||
case V_ASN1_T61STRING:
|
|
||||||
case V_ASN1_VIDEOTEXSTRING:
|
|
||||||
case V_ASN1_IA5STRING:
|
|
||||||
case V_ASN1_UTCTIME:
|
|
||||||
case V_ASN1_GENERALIZEDTIME:
|
|
||||||
case V_ASN1_GRAPHICSTRING:
|
|
||||||
case V_ASN1_VISIBLESTRING:
|
|
||||||
case V_ASN1_GENERALSTRING:
|
|
||||||
case V_ASN1_UNIVERSALSTRING:
|
|
||||||
case V_ASN1_BMPSTRING:
|
|
||||||
case V_ASN1_UTF8STRING:
|
|
||||||
case V_ASN1_OTHER:
|
|
||||||
default:
|
|
||||||
result = ASN1_STRING_cmp((ASN1_STRING *) a->value.ptr,
|
|
||||||
(ASN1_STRING *) b->value.ptr);
|
|
||||||
break;
|
|
||||||
}
|
|
||||||
|
|
||||||
return result;
|
|
||||||
}
|
|
||||||
|
|||||||
@@ -90,12 +90,6 @@ int ASN1_verify(i2d_of_void *i2d, X509_ALGOR *a, ASN1_BIT_STRING *signature,
|
|||||||
goto err;
|
goto err;
|
||||||
}
|
}
|
||||||
|
|
||||||
if (signature->type == V_ASN1_BIT_STRING && signature->flags & 0x7)
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_VERIFY, ASN1_R_INVALID_BIT_STRING_BITS_LEFT);
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
|
|
||||||
inl=i2d(data,NULL);
|
inl=i2d(data,NULL);
|
||||||
buf_in=OPENSSL_malloc((unsigned int)inl);
|
buf_in=OPENSSL_malloc((unsigned int)inl);
|
||||||
if (buf_in == NULL)
|
if (buf_in == NULL)
|
||||||
@@ -106,12 +100,7 @@ int ASN1_verify(i2d_of_void *i2d, X509_ALGOR *a, ASN1_BIT_STRING *signature,
|
|||||||
p=buf_in;
|
p=buf_in;
|
||||||
|
|
||||||
i2d(data,&p);
|
i2d(data,&p);
|
||||||
if (!EVP_VerifyInit_ex(&ctx,type, NULL))
|
EVP_VerifyInit_ex(&ctx,type, NULL);
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_VERIFY,ERR_R_EVP_LIB);
|
|
||||||
ret=0;
|
|
||||||
goto err;
|
|
||||||
}
|
|
||||||
EVP_VerifyUpdate(&ctx,(unsigned char *)buf_in,inl);
|
EVP_VerifyUpdate(&ctx,(unsigned char *)buf_in,inl);
|
||||||
|
|
||||||
OPENSSL_cleanse(buf_in,(unsigned int)inl);
|
OPENSSL_cleanse(buf_in,(unsigned int)inl);
|
||||||
@@ -144,18 +133,6 @@ int ASN1_item_verify(const ASN1_ITEM *it, X509_ALGOR *a, ASN1_BIT_STRING *signat
|
|||||||
unsigned char *buf_in=NULL;
|
unsigned char *buf_in=NULL;
|
||||||
int ret= -1,i,inl;
|
int ret= -1,i,inl;
|
||||||
|
|
||||||
if (!pkey)
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_ITEM_VERIFY, ERR_R_PASSED_NULL_PARAMETER);
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
if (signature->type == V_ASN1_BIT_STRING && signature->flags & 0x7)
|
|
||||||
{
|
|
||||||
ASN1err(ASN1_F_ASN1_ITEM_VERIFY, ASN1_R_INVALID_BIT_STRING_BITS_LEFT);
|
|
||||||
return -1;
|
|
||||||
}
|
|
||||||
|
|
||||||
EVP_MD_CTX_init(&ctx);
|
EVP_MD_CTX_init(&ctx);
|
||||||
i=OBJ_obj2nid(a->algorithm);
|
i=OBJ_obj2nid(a->algorithm);
|
||||||
type=EVP_get_digestbyname(OBJ_nid2sn(i));
|
type=EVP_get_digestbyname(OBJ_nid2sn(i));
|
||||||
|
|||||||
@@ -344,8 +344,6 @@ typedef struct ASN1_VALUE_st ASN1_VALUE;
|
|||||||
((void*) (1 ? p : (type*)0))
|
((void*) (1 ? p : (type*)0))
|
||||||
#define CHECKED_PPTR_OF(type, p) \
|
#define CHECKED_PPTR_OF(type, p) \
|
||||||
((void**) (1 ? p : (type**)0))
|
((void**) (1 ? p : (type**)0))
|
||||||
#define CHECKED_PTR_OF_TO_CHAR(type, p) \
|
|
||||||
((char*) (1 ? p : (type*)0))
|
|
||||||
|
|
||||||
#define TYPEDEF_D2I_OF(type) typedef type *d2i_of_##type(type **,const unsigned char **,long)
|
#define TYPEDEF_D2I_OF(type) typedef type *d2i_of_##type(type **,const unsigned char **,long)
|
||||||
#define TYPEDEF_I2D_OF(type) typedef int i2d_of_##type(type *,unsigned char **)
|
#define TYPEDEF_I2D_OF(type) typedef int i2d_of_##type(type *,unsigned char **)
|
||||||
@@ -614,7 +612,6 @@ typedef struct BIT_STRING_BITNAME_st {
|
|||||||
B_ASN1_GENERALIZEDTIME
|
B_ASN1_GENERALIZEDTIME
|
||||||
|
|
||||||
#define B_ASN1_PRINTABLE \
|
#define B_ASN1_PRINTABLE \
|
||||||
B_ASN1_NUMERICSTRING| \
|
|
||||||
B_ASN1_PRINTABLESTRING| \
|
B_ASN1_PRINTABLESTRING| \
|
||||||
B_ASN1_T61STRING| \
|
B_ASN1_T61STRING| \
|
||||||
B_ASN1_IA5STRING| \
|
B_ASN1_IA5STRING| \
|
||||||
@@ -769,7 +766,6 @@ DECLARE_ASN1_FUNCTIONS_fname(ASN1_TYPE, ASN1_ANY, ASN1_TYPE)
|
|||||||
int ASN1_TYPE_get(ASN1_TYPE *a);
|
int ASN1_TYPE_get(ASN1_TYPE *a);
|
||||||
void ASN1_TYPE_set(ASN1_TYPE *a, int type, void *value);
|
void ASN1_TYPE_set(ASN1_TYPE *a, int type, void *value);
|
||||||
int ASN1_TYPE_set1(ASN1_TYPE *a, int type, const void *value);
|
int ASN1_TYPE_set1(ASN1_TYPE *a, int type, const void *value);
|
||||||
int ASN1_TYPE_cmp(const ASN1_TYPE *a, const ASN1_TYPE *b);
|
|
||||||
|
|
||||||
ASN1_OBJECT * ASN1_OBJECT_new(void );
|
ASN1_OBJECT * ASN1_OBJECT_new(void );
|
||||||
void ASN1_OBJECT_free(ASN1_OBJECT *a);
|
void ASN1_OBJECT_free(ASN1_OBJECT *a);
|
||||||
@@ -936,12 +932,12 @@ void *ASN1_dup(i2d_of_void *i2d, d2i_of_void *d2i, char *x);
|
|||||||
#define ASN1_dup_of(type,i2d,d2i,x) \
|
#define ASN1_dup_of(type,i2d,d2i,x) \
|
||||||
((type*)ASN1_dup(CHECKED_I2D_OF(type, i2d), \
|
((type*)ASN1_dup(CHECKED_I2D_OF(type, i2d), \
|
||||||
CHECKED_D2I_OF(type, d2i), \
|
CHECKED_D2I_OF(type, d2i), \
|
||||||
CHECKED_PTR_OF_TO_CHAR(type, x)))
|
CHECKED_PTR_OF(type, x)))
|
||||||
|
|
||||||
#define ASN1_dup_of_const(type,i2d,d2i,x) \
|
#define ASN1_dup_of_const(type,i2d,d2i,x) \
|
||||||
((type*)ASN1_dup(CHECKED_I2D_OF(const type, i2d), \
|
((type*)ASN1_dup(CHECKED_I2D_OF(const type, i2d), \
|
||||||
CHECKED_D2I_OF(type, d2i), \
|
CHECKED_D2I_OF(type, d2i), \
|
||||||
CHECKED_PTR_OF_TO_CHAR(const type, x)))
|
CHECKED_PTR_OF(const type, x)))
|
||||||
|
|
||||||
void *ASN1_item_dup(const ASN1_ITEM *it, void *x);
|
void *ASN1_item_dup(const ASN1_ITEM *it, void *x);
|
||||||
|
|
||||||
@@ -1052,7 +1048,7 @@ ASN1_STRING *ASN1_pack_string(void *obj, i2d_of_void *i2d,
|
|||||||
ASN1_STRING *ASN1_item_pack(void *obj, const ASN1_ITEM *it, ASN1_OCTET_STRING **oct);
|
ASN1_STRING *ASN1_item_pack(void *obj, const ASN1_ITEM *it, ASN1_OCTET_STRING **oct);
|
||||||
|
|
||||||
void ASN1_STRING_set_default_mask(unsigned long mask);
|
void ASN1_STRING_set_default_mask(unsigned long mask);
|
||||||
int ASN1_STRING_set_default_mask_asc(const char *p);
|
int ASN1_STRING_set_default_mask_asc(char *p);
|
||||||
unsigned long ASN1_STRING_get_default_mask(void);
|
unsigned long ASN1_STRING_get_default_mask(void);
|
||||||
int ASN1_mbstring_copy(ASN1_STRING **out, const unsigned char *in, int len,
|
int ASN1_mbstring_copy(ASN1_STRING **out, const unsigned char *in, int len,
|
||||||
int inform, unsigned long mask);
|
int inform, unsigned long mask);
|
||||||
@@ -1221,7 +1217,6 @@ void ERR_load_ASN1_strings(void);
|
|||||||
#define ASN1_R_BAD_OBJECT_HEADER 102
|
#define ASN1_R_BAD_OBJECT_HEADER 102
|
||||||
#define ASN1_R_BAD_PASSWORD_READ 103
|
#define ASN1_R_BAD_PASSWORD_READ 103
|
||||||
#define ASN1_R_BAD_TAG 104
|
#define ASN1_R_BAD_TAG 104
|
||||||
#define ASN1_R_BMPSTRING_IS_WRONG_LENGTH 210
|
|
||||||
#define ASN1_R_BN_LIB 105
|
#define ASN1_R_BN_LIB 105
|
||||||
#define ASN1_R_BOOLEAN_IS_WRONG_LENGTH 106
|
#define ASN1_R_BOOLEAN_IS_WRONG_LENGTH 106
|
||||||
#define ASN1_R_BUFFER_TOO_SMALL 107
|
#define ASN1_R_BUFFER_TOO_SMALL 107
|
||||||
@@ -1261,13 +1256,11 @@ void ERR_load_ASN1_strings(void);
|
|||||||
#define ASN1_R_ILLEGAL_TIME_VALUE 184
|
#define ASN1_R_ILLEGAL_TIME_VALUE 184
|
||||||
#define ASN1_R_INTEGER_NOT_ASCII_FORMAT 185
|
#define ASN1_R_INTEGER_NOT_ASCII_FORMAT 185
|
||||||
#define ASN1_R_INTEGER_TOO_LARGE_FOR_LONG 128
|
#define ASN1_R_INTEGER_TOO_LARGE_FOR_LONG 128
|
||||||
#define ASN1_R_INVALID_BIT_STRING_BITS_LEFT 220
|
|
||||||
#define ASN1_R_INVALID_BMPSTRING_LENGTH 129
|
#define ASN1_R_INVALID_BMPSTRING_LENGTH 129
|
||||||
#define ASN1_R_INVALID_DIGIT 130
|
#define ASN1_R_INVALID_DIGIT 130
|
||||||
#define ASN1_R_INVALID_MIME_TYPE 200
|
#define ASN1_R_INVALID_MIME_TYPE 200
|
||||||
#define ASN1_R_INVALID_MODIFIER 186
|
#define ASN1_R_INVALID_MODIFIER 186
|
||||||
#define ASN1_R_INVALID_NUMBER 187
|
#define ASN1_R_INVALID_NUMBER 187
|
||||||
#define ASN1_R_INVALID_OBJECT_ENCODING 212
|
|
||||||
#define ASN1_R_INVALID_SEPARATOR 131
|
#define ASN1_R_INVALID_SEPARATOR 131
|
||||||
#define ASN1_R_INVALID_TIME_FORMAT 132
|
#define ASN1_R_INVALID_TIME_FORMAT 132
|
||||||
#define ASN1_R_INVALID_UNIVERSALSTRING_LENGTH 133
|
#define ASN1_R_INVALID_UNIVERSALSTRING_LENGTH 133
|
||||||
@@ -1310,11 +1303,9 @@ void ERR_load_ASN1_strings(void);
|
|||||||
#define ASN1_R_TIME_NOT_ASCII_FORMAT 193
|
#define ASN1_R_TIME_NOT_ASCII_FORMAT 193
|
||||||
#define ASN1_R_TOO_LONG 155
|
#define ASN1_R_TOO_LONG 155
|
||||||
#define ASN1_R_TYPE_NOT_CONSTRUCTED 156
|
#define ASN1_R_TYPE_NOT_CONSTRUCTED 156
|
||||||
#define ASN1_R_TYPE_NOT_PRIMITIVE 218
|
|
||||||
#define ASN1_R_UNABLE_TO_DECODE_RSA_KEY 157
|
#define ASN1_R_UNABLE_TO_DECODE_RSA_KEY 157
|
||||||
#define ASN1_R_UNABLE_TO_DECODE_RSA_PRIVATE_KEY 158
|
#define ASN1_R_UNABLE_TO_DECODE_RSA_PRIVATE_KEY 158
|
||||||
#define ASN1_R_UNEXPECTED_EOC 159
|
#define ASN1_R_UNEXPECTED_EOC 159
|
||||||
#define ASN1_R_UNIVERSALSTRING_IS_WRONG_LENGTH 211
|
|
||||||
#define ASN1_R_UNKNOWN_FORMAT 160
|
#define ASN1_R_UNKNOWN_FORMAT 160
|
||||||
#define ASN1_R_UNKNOWN_MESSAGE_DIGEST_ALGORITHM 161
|
#define ASN1_R_UNKNOWN_MESSAGE_DIGEST_ALGORITHM 161
|
||||||
#define ASN1_R_UNKNOWN_OBJECT_TYPE 162
|
#define ASN1_R_UNKNOWN_OBJECT_TYPE 162
|
||||||
|
|||||||
@@ -1,6 +1,6 @@
|
|||||||
/* crypto/asn1/asn1_err.c */
|
/* crypto/asn1/asn1_err.c */
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
* Copyright (c) 1999-2014 The OpenSSL Project. All rights reserved.
|
* Copyright (c) 1999-2008 The OpenSSL Project. All rights reserved.
|
||||||
*
|
*
|
||||||
* Redistribution and use in source and binary forms, with or without
|
* Redistribution and use in source and binary forms, with or without
|
||||||
* modification, are permitted provided that the following conditions
|
* modification, are permitted provided that the following conditions
|
||||||
@@ -195,7 +195,6 @@ static ERR_STRING_DATA ASN1_str_reasons[]=
|
|||||||
{ERR_REASON(ASN1_R_BAD_OBJECT_HEADER) ,"bad object header"},
|
{ERR_REASON(ASN1_R_BAD_OBJECT_HEADER) ,"bad object header"},
|
||||||
{ERR_REASON(ASN1_R_BAD_PASSWORD_READ) ,"bad password read"},
|
{ERR_REASON(ASN1_R_BAD_PASSWORD_READ) ,"bad password read"},
|
||||||
{ERR_REASON(ASN1_R_BAD_TAG) ,"bad tag"},
|
{ERR_REASON(ASN1_R_BAD_TAG) ,"bad tag"},
|
||||||
{ERR_REASON(ASN1_R_BMPSTRING_IS_WRONG_LENGTH),"bmpstring is wrong length"},
|
|
||||||
{ERR_REASON(ASN1_R_BN_LIB) ,"bn lib"},
|
{ERR_REASON(ASN1_R_BN_LIB) ,"bn lib"},
|
||||||
{ERR_REASON(ASN1_R_BOOLEAN_IS_WRONG_LENGTH),"boolean is wrong length"},
|
{ERR_REASON(ASN1_R_BOOLEAN_IS_WRONG_LENGTH),"boolean is wrong length"},
|
||||||
{ERR_REASON(ASN1_R_BUFFER_TOO_SMALL) ,"buffer too small"},
|
{ERR_REASON(ASN1_R_BUFFER_TOO_SMALL) ,"buffer too small"},
|
||||||
@@ -235,13 +234,11 @@ static ERR_STRING_DATA ASN1_str_reasons[]=
|
|||||||
{ERR_REASON(ASN1_R_ILLEGAL_TIME_VALUE) ,"illegal time value"},
|
{ERR_REASON(ASN1_R_ILLEGAL_TIME_VALUE) ,"illegal time value"},
|
||||||
{ERR_REASON(ASN1_R_INTEGER_NOT_ASCII_FORMAT),"integer not ascii format"},
|
{ERR_REASON(ASN1_R_INTEGER_NOT_ASCII_FORMAT),"integer not ascii format"},
|
||||||
{ERR_REASON(ASN1_R_INTEGER_TOO_LARGE_FOR_LONG),"integer too large for long"},
|
{ERR_REASON(ASN1_R_INTEGER_TOO_LARGE_FOR_LONG),"integer too large for long"},
|
||||||
{ERR_REASON(ASN1_R_INVALID_BIT_STRING_BITS_LEFT),"invalid bit string bits left"},
|
|
||||||
{ERR_REASON(ASN1_R_INVALID_BMPSTRING_LENGTH),"invalid bmpstring length"},
|
{ERR_REASON(ASN1_R_INVALID_BMPSTRING_LENGTH),"invalid bmpstring length"},
|
||||||
{ERR_REASON(ASN1_R_INVALID_DIGIT) ,"invalid digit"},
|
{ERR_REASON(ASN1_R_INVALID_DIGIT) ,"invalid digit"},
|
||||||
{ERR_REASON(ASN1_R_INVALID_MIME_TYPE) ,"invalid mime type"},
|
{ERR_REASON(ASN1_R_INVALID_MIME_TYPE) ,"invalid mime type"},
|
||||||
{ERR_REASON(ASN1_R_INVALID_MODIFIER) ,"invalid modifier"},
|
{ERR_REASON(ASN1_R_INVALID_MODIFIER) ,"invalid modifier"},
|
||||||
{ERR_REASON(ASN1_R_INVALID_NUMBER) ,"invalid number"},
|
{ERR_REASON(ASN1_R_INVALID_NUMBER) ,"invalid number"},
|
||||||
{ERR_REASON(ASN1_R_INVALID_OBJECT_ENCODING),"invalid object encoding"},
|
|
||||||
{ERR_REASON(ASN1_R_INVALID_SEPARATOR) ,"invalid separator"},
|
{ERR_REASON(ASN1_R_INVALID_SEPARATOR) ,"invalid separator"},
|
||||||
{ERR_REASON(ASN1_R_INVALID_TIME_FORMAT) ,"invalid time format"},
|
{ERR_REASON(ASN1_R_INVALID_TIME_FORMAT) ,"invalid time format"},
|
||||||
{ERR_REASON(ASN1_R_INVALID_UNIVERSALSTRING_LENGTH),"invalid universalstring length"},
|
{ERR_REASON(ASN1_R_INVALID_UNIVERSALSTRING_LENGTH),"invalid universalstring length"},
|
||||||
@@ -284,11 +281,9 @@ static ERR_STRING_DATA ASN1_str_reasons[]=
|
|||||||
{ERR_REASON(ASN1_R_TIME_NOT_ASCII_FORMAT),"time not ascii format"},
|
{ERR_REASON(ASN1_R_TIME_NOT_ASCII_FORMAT),"time not ascii format"},
|
||||||
{ERR_REASON(ASN1_R_TOO_LONG) ,"too long"},
|
{ERR_REASON(ASN1_R_TOO_LONG) ,"too long"},
|
||||||
{ERR_REASON(ASN1_R_TYPE_NOT_CONSTRUCTED) ,"type not constructed"},
|
{ERR_REASON(ASN1_R_TYPE_NOT_CONSTRUCTED) ,"type not constructed"},
|
||||||
{ERR_REASON(ASN1_R_TYPE_NOT_PRIMITIVE) ,"type not primitive"},
|
|
||||||
{ERR_REASON(ASN1_R_UNABLE_TO_DECODE_RSA_KEY),"unable to decode rsa key"},
|
{ERR_REASON(ASN1_R_UNABLE_TO_DECODE_RSA_KEY),"unable to decode rsa key"},
|
||||||
{ERR_REASON(ASN1_R_UNABLE_TO_DECODE_RSA_PRIVATE_KEY),"unable to decode rsa private key"},
|
{ERR_REASON(ASN1_R_UNABLE_TO_DECODE_RSA_PRIVATE_KEY),"unable to decode rsa private key"},
|
||||||
{ERR_REASON(ASN1_R_UNEXPECTED_EOC) ,"unexpected eoc"},
|
{ERR_REASON(ASN1_R_UNEXPECTED_EOC) ,"unexpected eoc"},
|
||||||
{ERR_REASON(ASN1_R_UNIVERSALSTRING_IS_WRONG_LENGTH),"universalstring is wrong length"},
|
|
||||||
{ERR_REASON(ASN1_R_UNKNOWN_FORMAT) ,"unknown format"},
|
{ERR_REASON(ASN1_R_UNKNOWN_FORMAT) ,"unknown format"},
|
||||||
{ERR_REASON(ASN1_R_UNKNOWN_MESSAGE_DIGEST_ALGORITHM),"unknown message digest algorithm"},
|
{ERR_REASON(ASN1_R_UNKNOWN_MESSAGE_DIGEST_ALGORITHM),"unknown message digest algorithm"},
|
||||||
{ERR_REASON(ASN1_R_UNKNOWN_OBJECT_TYPE) ,"unknown object type"},
|
{ERR_REASON(ASN1_R_UNKNOWN_OBJECT_TYPE) ,"unknown object type"},
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* asn1_gen.c */
|
/* asn1_gen.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 2002.
|
* project 2002.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
@@ -227,8 +227,6 @@ ASN1_TYPE *ASN1_generate_v3(char *str, X509V3_CTX *cnf)
|
|||||||
/* Allocate buffer for new encoding */
|
/* Allocate buffer for new encoding */
|
||||||
|
|
||||||
new_der = OPENSSL_malloc(len);
|
new_der = OPENSSL_malloc(len);
|
||||||
if (!new_der)
|
|
||||||
goto err;
|
|
||||||
|
|
||||||
/* Generate tagged encoding */
|
/* Generate tagged encoding */
|
||||||
|
|
||||||
@@ -448,8 +446,6 @@ static ASN1_TYPE *asn1_multi(int utype, const char *section, X509V3_CTX *cnf)
|
|||||||
int derlen;
|
int derlen;
|
||||||
int i, is_set;
|
int i, is_set;
|
||||||
sk = sk_ASN1_TYPE_new_null();
|
sk = sk_ASN1_TYPE_new_null();
|
||||||
if (!sk)
|
|
||||||
goto bad;
|
|
||||||
if (section)
|
if (section)
|
||||||
{
|
{
|
||||||
if (!cnf)
|
if (!cnf)
|
||||||
@@ -462,8 +458,7 @@ static ASN1_TYPE *asn1_multi(int utype, const char *section, X509V3_CTX *cnf)
|
|||||||
typ = ASN1_generate_v3(sk_CONF_VALUE_value(sect, i)->value, cnf);
|
typ = ASN1_generate_v3(sk_CONF_VALUE_value(sect, i)->value, cnf);
|
||||||
if (!typ)
|
if (!typ)
|
||||||
goto bad;
|
goto bad;
|
||||||
if (!sk_ASN1_TYPE_push(sk, typ))
|
sk_ASN1_TYPE_push(sk, typ);
|
||||||
goto bad;
|
|
||||||
typ = NULL;
|
typ = NULL;
|
||||||
}
|
}
|
||||||
}
|
}
|
||||||
@@ -479,8 +474,6 @@ static ASN1_TYPE *asn1_multi(int utype, const char *section, X509V3_CTX *cnf)
|
|||||||
derlen = i2d_ASN1_SET_OF_ASN1_TYPE(sk, NULL, i2d_ASN1_TYPE, utype,
|
derlen = i2d_ASN1_SET_OF_ASN1_TYPE(sk, NULL, i2d_ASN1_TYPE, utype,
|
||||||
V_ASN1_UNIVERSAL, is_set);
|
V_ASN1_UNIVERSAL, is_set);
|
||||||
der = OPENSSL_malloc(derlen);
|
der = OPENSSL_malloc(derlen);
|
||||||
if (!der)
|
|
||||||
goto bad;
|
|
||||||
p = der;
|
p = der;
|
||||||
i2d_ASN1_SET_OF_ASN1_TYPE(sk, &p, i2d_ASN1_TYPE, utype,
|
i2d_ASN1_SET_OF_ASN1_TYPE(sk, &p, i2d_ASN1_TYPE, utype,
|
||||||
V_ASN1_UNIVERSAL, is_set);
|
V_ASN1_UNIVERSAL, is_set);
|
||||||
|
|||||||
@@ -131,9 +131,6 @@ int ASN1_get_object(const unsigned char **pp, long *plength, int *ptag,
|
|||||||
*pclass=xclass;
|
*pclass=xclass;
|
||||||
if (!asn1_get_length(&p,&inf,plength,(int)max)) goto err;
|
if (!asn1_get_length(&p,&inf,plength,(int)max)) goto err;
|
||||||
|
|
||||||
if (inf && !(ret & V_ASN1_CONSTRUCTED))
|
|
||||||
goto err;
|
|
||||||
|
|
||||||
#if 0
|
#if 0
|
||||||
fprintf(stderr,"p=%d + *plength=%ld > omax=%ld + *pp=%d (%d > %d)\n",
|
fprintf(stderr,"p=%d + *plength=%ld > omax=%ld + *pp=%d (%d > %d)\n",
|
||||||
(int)p,*plength,omax,(int)*pp,(int)(p+ *plength),
|
(int)p,*plength,omax,(int)*pp,(int)(p+ *plength),
|
||||||
|
|||||||
@@ -213,8 +213,6 @@ static int asn1_parse2(BIO *bp, const unsigned char **pp, long length, int offse
|
|||||||
(tag == V_ASN1_T61STRING) ||
|
(tag == V_ASN1_T61STRING) ||
|
||||||
(tag == V_ASN1_IA5STRING) ||
|
(tag == V_ASN1_IA5STRING) ||
|
||||||
(tag == V_ASN1_VISIBLESTRING) ||
|
(tag == V_ASN1_VISIBLESTRING) ||
|
||||||
(tag == V_ASN1_NUMERICSTRING) ||
|
|
||||||
(tag == V_ASN1_UTF8STRING) ||
|
|
||||||
(tag == V_ASN1_UTCTIME) ||
|
(tag == V_ASN1_UTCTIME) ||
|
||||||
(tag == V_ASN1_GENERALIZEDTIME))
|
(tag == V_ASN1_GENERALIZEDTIME))
|
||||||
{
|
{
|
||||||
@@ -246,7 +244,7 @@ static int asn1_parse2(BIO *bp, const unsigned char **pp, long length, int offse
|
|||||||
ii=d2i_ASN1_BOOLEAN(NULL,&opp,len+hl);
|
ii=d2i_ASN1_BOOLEAN(NULL,&opp,len+hl);
|
||||||
if (ii < 0)
|
if (ii < 0)
|
||||||
{
|
{
|
||||||
if (BIO_write(bp,"Bad boolean\n",12) <= 0)
|
if (BIO_write(bp,"Bad boolean\n",12))
|
||||||
goto end;
|
goto end;
|
||||||
}
|
}
|
||||||
BIO_printf(bp,":%d",ii);
|
BIO_printf(bp,":%d",ii);
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* asn1t.h */
|
/* asn1t.h */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 2000.
|
* project 2000.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
|
|||||||
@@ -152,6 +152,7 @@ static ASN1_VALUE *b64_read_asn1(BIO *bio, const ASN1_ITEM *it)
|
|||||||
|
|
||||||
static int asn1_write_micalg(BIO *out, STACK_OF(X509_ALGOR) *mdalgs)
|
static int asn1_write_micalg(BIO *out, STACK_OF(X509_ALGOR) *mdalgs)
|
||||||
{
|
{
|
||||||
|
const EVP_MD *md;
|
||||||
int i, have_unknown = 0, write_comma, md_nid;
|
int i, have_unknown = 0, write_comma, md_nid;
|
||||||
have_unknown = 0;
|
have_unknown = 0;
|
||||||
write_comma = 0;
|
write_comma = 0;
|
||||||
@@ -161,6 +162,7 @@ static int asn1_write_micalg(BIO *out, STACK_OF(X509_ALGOR) *mdalgs)
|
|||||||
BIO_write(out, ",", 1);
|
BIO_write(out, ",", 1);
|
||||||
write_comma = 1;
|
write_comma = 1;
|
||||||
md_nid = OBJ_obj2nid(sk_X509_ALGOR_value(mdalgs, i)->algorithm);
|
md_nid = OBJ_obj2nid(sk_X509_ALGOR_value(mdalgs, i)->algorithm);
|
||||||
|
md = EVP_get_digestbynid(md_nid);
|
||||||
switch(md_nid)
|
switch(md_nid)
|
||||||
{
|
{
|
||||||
case NID_sha1:
|
case NID_sha1:
|
||||||
@@ -418,9 +420,9 @@ ASN1_VALUE *SMIME_read_ASN1(BIO *bio, BIO **bcont, const ASN1_ITEM *it)
|
|||||||
|
|
||||||
if(strcmp(hdr->value, "application/x-pkcs7-signature") &&
|
if(strcmp(hdr->value, "application/x-pkcs7-signature") &&
|
||||||
strcmp(hdr->value, "application/pkcs7-signature")) {
|
strcmp(hdr->value, "application/pkcs7-signature")) {
|
||||||
|
sk_MIME_HEADER_pop_free(headers, mime_hdr_free);
|
||||||
ASN1err(ASN1_F_SMIME_READ_ASN1,ASN1_R_SIG_INVALID_MIME_TYPE);
|
ASN1err(ASN1_F_SMIME_READ_ASN1,ASN1_R_SIG_INVALID_MIME_TYPE);
|
||||||
ERR_add_error_data(2, "type: ", hdr->value);
|
ERR_add_error_data(2, "type: ", hdr->value);
|
||||||
sk_MIME_HEADER_pop_free(headers, mime_hdr_free);
|
|
||||||
sk_BIO_pop_free(parts, BIO_vfree);
|
sk_BIO_pop_free(parts, BIO_vfree);
|
||||||
return NULL;
|
return NULL;
|
||||||
}
|
}
|
||||||
@@ -595,8 +597,6 @@ static STACK_OF(MIME_HEADER) *mime_parse_hdr(BIO *bio)
|
|||||||
int len, state, save_state = 0;
|
int len, state, save_state = 0;
|
||||||
|
|
||||||
headers = sk_MIME_HEADER_new(mime_hdr_cmp);
|
headers = sk_MIME_HEADER_new(mime_hdr_cmp);
|
||||||
if (!headers)
|
|
||||||
return NULL;
|
|
||||||
while ((len = BIO_gets(bio, linebuf, MAX_SMLEN)) > 0) {
|
while ((len = BIO_gets(bio, linebuf, MAX_SMLEN)) > 0) {
|
||||||
/* If whitespace at line start then continuation line */
|
/* If whitespace at line start then continuation line */
|
||||||
if(mhdr && isspace((unsigned char)linebuf[0])) state = MIME_NAME;
|
if(mhdr && isspace((unsigned char)linebuf[0])) state = MIME_NAME;
|
||||||
@@ -792,17 +792,12 @@ static int mime_hdr_addparam(MIME_HEADER *mhdr, char *name, char *value)
|
|||||||
static int mime_hdr_cmp(const MIME_HEADER * const *a,
|
static int mime_hdr_cmp(const MIME_HEADER * const *a,
|
||||||
const MIME_HEADER * const *b)
|
const MIME_HEADER * const *b)
|
||||||
{
|
{
|
||||||
if (!(*a)->name || !(*b)->name)
|
|
||||||
return !!(*a)->name - !!(*b)->name;
|
|
||||||
|
|
||||||
return(strcmp((*a)->name, (*b)->name));
|
return(strcmp((*a)->name, (*b)->name));
|
||||||
}
|
}
|
||||||
|
|
||||||
static int mime_param_cmp(const MIME_PARAM * const *a,
|
static int mime_param_cmp(const MIME_PARAM * const *a,
|
||||||
const MIME_PARAM * const *b)
|
const MIME_PARAM * const *b)
|
||||||
{
|
{
|
||||||
if (!(*a)->param_name || !(*b)->param_name)
|
|
||||||
return !!(*a)->param_name - !!(*b)->param_name;
|
|
||||||
return(strcmp((*a)->param_name, (*b)->param_name));
|
return(strcmp((*a)->param_name, (*b)->param_name));
|
||||||
}
|
}
|
||||||
|
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* asn_moid.c */
|
/* asn_moid.c */
|
||||||
/* Written by Stephen Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Stephen Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 2001.
|
* project 2001.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
|
|||||||
@@ -1,5 +1,5 @@
|
|||||||
/* asn_pack.c */
|
/* asn_pack.c */
|
||||||
/* Written by Dr Stephen N Henson (steve@openssl.org) for the OpenSSL
|
/* Written by Dr Stephen N Henson (shenson@bigfoot.com) for the OpenSSL
|
||||||
* project 1999.
|
* project 1999.
|
||||||
*/
|
*/
|
||||||
/* ====================================================================
|
/* ====================================================================
|
||||||
@@ -134,23 +134,15 @@ ASN1_STRING *ASN1_pack_string(void *obj, i2d_of_void *i2d, ASN1_STRING **oct)
|
|||||||
|
|
||||||
if (!(octmp->length = i2d(obj, NULL))) {
|
if (!(octmp->length = i2d(obj, NULL))) {
|
||||||
ASN1err(ASN1_F_ASN1_PACK_STRING,ASN1_R_ENCODE_ERROR);
|
ASN1err(ASN1_F_ASN1_PACK_STRING,ASN1_R_ENCODE_ERROR);
|
||||||
goto err;
|
return NULL;
|
||||||
}
|
}
|
||||||
if (!(p = OPENSSL_malloc (octmp->length))) {
|
if (!(p = OPENSSL_malloc (octmp->length))) {
|
||||||
ASN1err(ASN1_F_ASN1_PACK_STRING,ERR_R_MALLOC_FAILURE);
|
ASN1err(ASN1_F_ASN1_PACK_STRING,ERR_R_MALLOC_FAILURE);
|
||||||
goto err;
|
return NULL;
|
||||||
}
|
}
|
||||||
octmp->data = p;
|
octmp->data = p;
|
||||||
i2d (obj, &p);
|
i2d (obj, &p);
|
||||||
return octmp;
|
return octmp;
|
||||||
err:
|
|
||||||
if (!oct || !*oct)
|
|
||||||
{
|
|
||||||
ASN1_STRING_free(octmp);
|
|
||||||
if (oct)
|
|
||||||
*oct = NULL;
|
|
||||||
}
|
|
||||||
return NULL;
|
|
||||||
}
|
}
|
||||||
|
|
||||||
#endif
|
#endif
|
||||||
|
|||||||
Some files were not shown because too many files have changed in this diff Show More
Reference in New Issue
Block a user