We put almost everything in these internal static libraries: libcommon Block building code that can be used by all our implementations, legacy and non-legacy alike. libimplementations All non-legacy algorithm implementations and only them. All the code that ends up here is agnostic to the definitions of FIPS_MODE. liblegacy All legacy implementations. libnonfips Support code for the algorithm implementations. Built with FIPS_MODE undefined. Any code that checks that FIPS_MODE isn't defined must end up in this library. libfips Support code for the algorithm implementations. Built with FIPS_MODE defined. Any code that checks that FIPS_MODE is defined must end up in this library. The FIPS provider module is built from providers/fips/*.c and linked with libimplementations, libcommon and libfips. The Legacy provider module is built from providers/legacy/*.c and linked with liblegacy, libcommon and libcrypto. If module building is disabled, the object files from liblegacy and libcommon are added to libcrypto and the Legacy provider becomes a built-in provider. The Default provider module is built-in, so it ends up being linked with libimplementations, libcommon and libnonfips. For libcrypto in form of static library, the object files from those other libraries are simply being added to libcrypto. Reviewed-by: Matt Caswell <matt@openssl.org> (Merged from https://github.com/openssl/openssl/pull/10088)master
parent
e805c2d6d3
commit
dec95d7589
@ -1,3 +1,3 @@
|
||||
LIBS=../../libcrypto
|
||||
SOURCE[../../libcrypto]=buffer.c buf_err.c
|
||||
SOURCE[../../providers/fips]=buffer.c
|
||||
SOURCE[../../providers/libfips.a]=buffer.c
|
||||
|
@ -1,5 +1,5 @@
|
||||
LIBS=../../libcrypto
|
||||
SOURCE[../../libcrypto]=\
|
||||
lhash.c lh_stats.c
|
||||
SOURCE[../../providers/fips]=\
|
||||
SOURCE[../../providers/libfips.a]=\
|
||||
lhash.c
|
||||
|
@ -1,4 +1,4 @@
|
||||
LIBS=../../libcrypto
|
||||
$COMMON=property_string.c property_parse.c property.c defn_cache.c
|
||||
SOURCE[../../libcrypto]=$COMMON property_err.c
|
||||
SOURCE[../../providers/fips]=$COMMON
|
||||
SOURCE[../../providers/libfips.a]=$COMMON
|
||||
|
@ -1,3 +1,3 @@
|
||||
LIBS=../../libcrypto
|
||||
SOURCE[../../libcrypto]=stack.c
|
||||
SOURCE[../../providers/fips]=stack.c
|
||||
SOURCE[../../providers/libfips.a]=stack.c
|
||||
|
@ -1,30 +1,150 @@
|
||||
# We place all implementations in static libraries, and then let the
|
||||
# provider mains pilfer what they want through symbol resolution when
|
||||
# linking.
|
||||
#
|
||||
# The non-legacy implementations (libimplementations) must be made FIPS
|
||||
# agnostic as much as possible, as well as the common building blocks
|
||||
# (libcommon). The legacy implementations (liblegacy) will never be
|
||||
# part of the FIPS provider.
|
||||
#
|
||||
# If there is anything that isn't FIPS agnostic, it should be set aside
|
||||
# in its own source file, which is then included directly into other
|
||||
# static libraries geared for FIPS and non-FIPS providers, and built
|
||||
# separately.
|
||||
#
|
||||
# libcommon.a Contains common building blocks, potentially
|
||||
# needed both by non-legacy and legacy code.
|
||||
#
|
||||
# libimplementations.a Contains all non-legacy implementations.
|
||||
# liblegacy.a Contains all legacy implementaions.
|
||||
#
|
||||
# libfips.a Contains all things needed to support
|
||||
# FIPS implementations, such as code from
|
||||
# crypto/ and object files that contain
|
||||
# FIPS-specific code. FIPS_MODE is defined
|
||||
# for this library. The FIPS module uses
|
||||
# this.
|
||||
# libnonfips.a Corresponds to libfips.a, but built with
|
||||
# FIPS_MODE undefined. The default and legacy
|
||||
# providers use this.
|
||||
|
||||
SUBDIRS=common default
|
||||
|
||||
INCLUDE[../libcrypto]=common/include
|
||||
|
||||
# Libraries we're dealing with
|
||||
$LIBCOMMON=libcommon.a
|
||||
$LIBIMPLEMENTATIONS=libimplementations.a
|
||||
$LIBLEGACY=liblegacy.a
|
||||
$LIBNONFIPS=libnonfips.a
|
||||
$LIBFIPS=libfips.a
|
||||
|
||||
# Enough of our implementations include prov/ciphercommon.h (present in
|
||||
# providers/common/include), which includes crypto/ciphermode_platform.h
|
||||
# (present in include), which in turn may include very internal header
|
||||
# files in crypto/, so let's have a common include list for them all.
|
||||
$COMMON_INCLUDES=../crypto ../include common/include
|
||||
|
||||
INCLUDE[$LIBCOMMON]=$COMMON_INCLUDES
|
||||
INCLUDE[$LIBIMPLEMENTATIONS]=.. $COMMON_INCLUDES default/include
|
||||
INCLUDE[$LIBLEGACY]=$COMMON_INCLUDES
|
||||
INCLUDE[$LIBNONFIPS]=$COMMON_INCLUDES
|
||||
INCLUDE[$LIBFIPS]=.. $COMMON_INCLUDES
|
||||
DEFINE[$LIBFIPS]=FIPS_MODE
|
||||
|
||||
# Weak dependencies to provide library order information.
|
||||
# We make it weak so they aren't both used always; what is
|
||||
# actually used is determined by non-weak dependencies.
|
||||
DEPEND[$LIBIMPLEMENTATIONS]{weak}=$LIBFIPS $LIBNONFIPS
|
||||
DEPEND[$LIBCOMMON]{weak}=$LIBFIPS
|
||||
|
||||
# Strong dependencies. This ensures that any time libimplementations
|
||||
# is used, libcommon gets included as well.
|
||||
DEPEND[$LIBIMPLEMENTATIONS]=$LIBCOMMON
|
||||
DEPEND[$LIBNONFIPS]=../libcrypto
|
||||
# It's tempting to make libcommon depend on ../libcrypto. However,
|
||||
# since the FIPS provider module must NOT depend on ../libcrypto, we
|
||||
# need to set that dependency up specifically for the final products
|
||||
# that use $LIBCOMMON or anything that depends on it.
|
||||
|
||||
# Libraries common to all providers, must be built regardless
|
||||
LIBS{noinst}=$LIBCOMMON
|
||||
# Libraries that are common for all non-FIPS providers, must be built regardless
|
||||
LIBS{noinst}=$LIBNONFIPS $LIBIMPLEMENTATIONS
|
||||
|
||||
#
|
||||
# Default provider stuff
|
||||
#
|
||||
# Because the default provider is built in, it means that libcrypto must
|
||||
# include all the object files that are needed (we do that indirectly,
|
||||
# by using the appropriate libraries as source). Note that for shared
|
||||
# libraries, SOURCEd libraries are considered as if the where specified
|
||||
# with DEPEND.
|
||||
$DEFAULTGOAL=../libcrypto
|
||||
SOURCE[$DEFAULTGOAL]=$LIBIMPLEMENTATIONS $LIBNONFIPS
|
||||
|
||||
LIBS=$DEFAULTGOAL
|
||||
|
||||
#
|
||||
# FIPS provider stuff
|
||||
#
|
||||
# We define it this way to ensure that configdata.pm will have all the
|
||||
# necessary information even if we don't build the module. This will allow
|
||||
# us to make all kinds of checks on the source, based on what we specify in
|
||||
# diverse build.info files. libfips.a, fips.so and their sources aren't
|
||||
# built unless the proper LIBS or MODULES statement has been seen, so we
|
||||
# have those and only those within a condition.
|
||||
SUBDIRS=fips
|
||||
$FIPSGOAL=fips
|
||||
DEPEND[$FIPSGOAL]=$LIBIMPLEMENTATIONS $LIBFIPS
|
||||
INCLUDE[$FIPSGOAL]=../include
|
||||
IF[{- defined $target{shared_defflag} -}]
|
||||
SOURCE[$FIPSGOAL]=fips.ld
|
||||
GENERATE[fips.ld]=../util/providers.num
|
||||
ENDIF
|
||||
|
||||
IF[{- !$disabled{fips} -}]
|
||||
SUBDIRS=fips
|
||||
MODULES=fips
|
||||
IF[{- defined $target{shared_defflag} -}]
|
||||
SOURCE[fips]=fips.ld
|
||||
GENERATE[fips.ld]=../util/providers.num
|
||||
ENDIF
|
||||
INCLUDE[fips]=.. ../include common/include
|
||||
DEFINE[fips]=FIPS_MODE
|
||||
# This is the trigger to actually build the FIPS module. Without these
|
||||
# statements, the final build file will not have a trace of it.
|
||||
MODULES=$FIPSGOAL
|
||||
LIBS{noinst}=$LIBFIPS
|
||||
ENDIF
|
||||
|
||||
#
|
||||
# Legacy provider stuff
|
||||
#
|
||||
IF[{- !$disabled{legacy} -}]
|
||||
# The legacy implementation library
|
||||
SUBDIRS=legacy
|
||||
LIBS{noinst}=$LIBLEGACY
|
||||
DEPEND[$LIBLEGACY]=$LIBCOMMON $LIBNONFIPS
|
||||
|
||||
# The Legacy provider
|
||||
IF[{- $disabled{module} -}]
|
||||
LIBS=../libcrypto
|
||||
DEFINE[../libcrypto]=STATIC_LEGACY
|
||||
# Become built in
|
||||
# In this case, we need to do the same thing a for the default provider,
|
||||
# and make the liblegacy object files end up in libcrypto. We could also
|
||||
# just say that for the built-in legacy, we put the source directly in
|
||||
# libcrypto instead of going via liblegacy, but that makes writing the
|
||||
# implementation specific build.info files harder to write, so we don't.
|
||||
$LEGACYGOAL=../libcrypto
|
||||
SOURCE[$LEGACYGOAL]=$LIBLEGACY
|
||||
DEFINE[$LIBLEGACY]=STATIC_LEGACY
|
||||
DEFINE[$LEGACYGOAL]=STATIC_LEGACY
|
||||
ELSE
|
||||
MODULES=legacy
|
||||
# Become a module
|
||||
# In this case, we can work with dependencies
|
||||
$LEGACYGOAL=legacy
|
||||
MODULES=$LEGACYGOAL
|
||||
DEPEND[$LEGACYGOAL]=$LIBLEGACY
|
||||
IF[{- defined $target{shared_defflag} -}]
|
||||
SOURCE[legacy]=legacy.ld
|
||||
GENERATE[legacy.ld]=../util/providers.num
|
||||
ENDIF
|
||||
DEPEND[legacy]=../libcrypto
|
||||
INCLUDE[legacy]=.. ../include common/include
|
||||
ENDIF
|
||||
|
||||
# Common things that are valid no matter what form the Legacy provider
|
||||
# takes.
|
||||
INCLUDE[$LEGACYGOAL]=../include common/include
|
||||
ENDIF
|
||||
|
||||
|
@ -1,5 +1,6 @@
|
||||
SUBDIRS=digests ciphers macs kdfs exchange keymgmt signature
|
||||
$COMMON=provider_util.c
|
||||
|
||||
SOURCE[../../libcrypto]=$COMMON provider_err.c provlib.c
|
||||
SOURCE[../fips]=$COMMON
|
||||
SOURCE[../libcommon.a]=provider_err.c provlib.c
|
||||
$FIPSCOMMON=provider_util.c
|
||||
SOURCE[../libnonfips.a]=$FIPSCOMMON
|
||||
SOURCE[../libfips.a]=$FIPSCOMMON
|
||||
|
@ -1,21 +1,26 @@
|
||||
LIBS=../../../libcrypto
|
||||
# This source is common building blockss for all ciphers in all our providers.
|
||||
SOURCE[../../libcommon.a]=\
|
||||
cipher_common.c cipher_common_hw.c block.c \
|
||||
cipher_gcm.c cipher_gcm_hw.c \
|
||||
cipher_ccm.c cipher_ccm_hw.c
|
||||
|
||||
# These are our implementations
|
||||
$GOAL=../../libimplementations.a
|
||||
|
||||
IF[{- !$disabled{des} -}]
|
||||
$COMMON_DES=cipher_tdes.c cipher_tdes_hw.c
|
||||
ENDIF
|
||||
|
||||
$COMMON=cipher_common.c cipher_common_hw.c block.c \
|
||||
SOURCE[$GOAL]=\
|
||||
cipher_aes.c cipher_aes_hw.c \
|
||||
cipher_aes_xts.c cipher_aes_xts_hw.c \
|
||||
cipher_gcm.c cipher_gcm_hw.c \
|
||||
cipher_aes_gcm.c cipher_aes_gcm_hw.c \
|
||||
cipher_ccm.c cipher_ccm_hw.c \
|
||||
cipher_aes_ccm.c cipher_aes_ccm_hw.c \
|
||||
cipher_aes_wrp.c \
|
||||
$COMMON_DES
|
||||
|
||||
SOURCE[../../../libcrypto]=$COMMON
|
||||
INCLUDE[../../../libcrypto]=. ../../../crypto
|
||||
# Because some default ciphers need it
|
||||
INCLUDE[$GOAL]=.
|
||||
|
||||
SOURCE[../../fips]=$COMMON
|
||||
INCLUDE[../../fips]=. ../../../crypto
|
||||
# Finally, we have a few things that aren't FIPS agnostic
|
||||
SOURCE[../../libfips.a]=cipher_fips.c
|
||||
SOURCE[../../libnonfips.a]=cipher_fips.c
|
||||
|
@ -0,0 +1,16 @@
|
||||
/*
|
||||
* Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include "cipher_aes_xts.h"
|
||||
|
||||
#ifdef FIPS_MODE
|
||||
const int allow_insecure_decrypt = 0;
|
||||
#else
|
||||
const int allow_insecure_decrypt = 1;
|
||||
#endif /* FIPS_MODE */
|
@ -1,5 +1,7 @@
|
||||
$COMMON=sha2_prov.c sha3_prov.c digest_common.c
|
||||
# This source is common for all digests in all our providers.
|
||||
SOURCE[../../libcommon.a]=digest_common.c
|
||||
|
||||
SOURCE[../../../libcrypto]=$COMMON
|
||||
SOURCE[../../fips]=$COMMON
|
||||
SOURCE[../../legacy]= digest_common.c
|
||||
# These are our implementations
|
||||
$GOAL=../../libimplementations.a
|
||||
|
||||
SOURCE[$GOAL]=sha2_prov.c sha3_prov.c
|
||||
|
@ -1,13 +1,5 @@
|
||||
$COMMON=tls1_prf.c hkdf.c kbkdf.c pbkdf2.c sskdf.c
|
||||
$GOAL=../../libimplementations.a
|
||||
|
||||
LIBS=../../../libcrypto
|
||||
SOURCE[../../../libcrypto]=$COMMON
|
||||
INCLUDE[../../../libcrypto]=. ../../../crypto
|
||||
|
||||
IF[{- !$disabled{fips} -}]
|
||||
MODULES=../../fips
|
||||
SOURCE[../../fips]=$COMMON
|
||||
INCLUDE[../../fips]=. ../../../crypto
|
||||
ENDIF
|
||||
|
||||
|
||||
SOURCE[$GOAL]=tls1_prf.c hkdf.c kbkdf.c pbkdf2.c sskdf.c
|
||||
SOURCE[../../libfips.a]=pbkdf2_fips.c
|
||||
SOURCE[../../libnonfips.a]=pbkdf2_fips.c
|
||||
|
@ -0,0 +1,14 @@
|
||||
/*
|
||||
* Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
/*
|
||||
* Available in pbkdfe_fips.c, and compiled with different values depending
|
||||
* on we're in the FIPS module or not.
|
||||
*/
|
||||
extern const int kdf_pbkdf2_default_checks;
|
@ -0,0 +1,20 @@
|
||||
/*
|
||||
* Copyright 2019 The OpenSSL Project Authors. All Rights Reserved.
|
||||
*
|
||||
* Licensed under the Apache License 2.0 (the "License"). You may not use
|
||||
* this file except in compliance with the License. You can obtain a copy
|
||||
* in the file LICENSE in the source distribution or at
|
||||
* https://www.openssl.org/source/license.html
|
||||
*/
|
||||
|
||||
#include "pbkdf2.h"
|
||||
|
||||
/*
|
||||
* For backwards compatibility reasons,
|
||||
* Extra checks are done by default in fips mode only.
|
||||
*/
|
||||
#ifdef FIPS_MODE
|
||||
const int kdf_pbkdf2_default_checks = 1;
|
||||
#else
|
||||
const int kdf_pbkdf2_default_checks = 0;
|
||||
#endif /* FIPS_MODE */
|
@ -1,9 +1,8 @@
|
||||
LIBS=../../../libcrypto
|
||||
$GOAL=../../libimplementations.a
|
||||
|
||||
IF[{- !$disabled{dh} -}]
|
||||
SOURCE[../../../libcrypto]=\
|
||||
dh_kmgmt.c
|
||||
SOURCE[$GOAL]=dh_kmgmt.c
|
||||
ENDIF
|
||||
IF[{- !$disabled{dsa} -}]
|
||||
SOURCE[../../../libcrypto]=\
|
||||
dsa_kmgmt.c
|
||||
SOURCE[$GOAL]=dsa_kmgmt.c
|
||||
ENDIF
|
||||
|
@ -1,15 +1,9 @@
|
||||
$GOAL=../../libimplementations.a
|
||||
|
||||
$COMMON=gmac_prov.c hmac_prov.c kmac_prov.c
|
||||
|
||||
IF[{- !$disabled{cmac} -}]
|
||||
$COMMON=$COMMON cmac_prov.c
|
||||
ENDIF
|
||||
|
||||
LIBS=../../../libcrypto
|
||||
SOURCE[../../../libcrypto]=$COMMON
|
||||
INCLUDE[../../../libcrypto]=. ../../../crypto
|
||||
|
||||
IF[{- !$disabled{fips} -}]
|
||||
MODULES=../../fips
|
||||
SOURCE[../../fips]=$COMMON
|
||||
INCLUDE[../../fips]=. ../../../crypto
|
||||
ENDIF
|
||||
SOURCE[$GOAL]=$COMMON
|
||||
|
@ -1,7 +1,7 @@
|
||||
LIBS=../../../libcrypto
|
||||
$GOAL=../../libimplementations.a
|
||||
|
||||
IF[{- !$disabled{dsa} -}]
|
||||
SOURCE[../../../libcrypto]=\
|
||||
dsa.c
|
||||
SOURCE[$GOAL]=dsa.c
|
||||
ENDIF
|
||||
|
||||
|
||||
|
@ -1,6 +1,4 @@
|
||||
SUBDIRS=digests macs ciphers
|
||||
SUBDIRS=digests kdfs macs ciphers
|
||||
LIBS=../../libcrypto
|
||||
SOURCE[../../libcrypto]=\
|
||||
defltprov.c
|
||||
INCLUDE[../../libcrypto]=include
|
||||
$GOAL=../../libcrypto
|
||||
SOURCE[$GOAL]=defltprov.c
|
||||
INCLUDE[$GOAL]=include
|
||||
|
@ -1,15 +1,16 @@
|
||||
$GOAL=../../libimplementations.a
|
||||
|
||||
IF[{- !$disabled{blake2} -}]
|
||||
SOURCE[../../../libcrypto]=\
|
||||
SOURCE[$GOAL]=\
|
||||
blake2_prov.c blake2b_prov.c blake2s_prov.c
|
||||
ENDIF
|
||||
|
||||
IF[{- !$disabled{sm3} -}]
|
||||
SOURCE[../../../libcrypto]=\
|
||||
SOURCE[$GOAL]=\
|
||||
sm3_prov.c
|
||||
ENDIF
|
||||
|
||||
IF[{- !$disabled{md5} -}]
|
||||
SOURCE[../../../libcrypto]=\
|
||||
SOURCE[$GOAL]=\
|
||||
md5_prov.c md5_sha1_prov.c
|
||||
ENDIF
|
||||
|
@ -1,3 +1,2 @@
|
||||
LIBS=../../../libcrypto
|
||||
SOURCE[../../../libcrypto]=scrypt.c sshkdf.c x942kdf.c
|
||||
INCLUDE[../../../libcrypto]=. ../../../crypto
|
||||
$GOAL=../../libimplementations.a
|
||||
SOURCE[$GOAL]=scrypt.c sshkdf.c x942kdf.c
|
||||
|
@ -1,2 +1,3 @@
|
||||
|
||||
SOURCE[../fips]=fipsprov.c selftest.c
|
||||
INCLUDE[../fips]=../common/include
|
@ -1,30 +1,21 @@
|
||||
IF[{- $disabled{module} -}]
|
||||
$GOAL=../../../libcrypto
|
||||
ELSE
|
||||
$GOAL=../../legacy
|
||||
ENDIF
|
||||
$GOAL=../../liblegacy.a
|
||||
|
||||
IF[{- !$disabled{md2} -}]
|
||||
SOURCE[$GOAL]=\
|
||||
md2_prov.c
|
||||
SOURCE[$GOAL]=md2_prov.c
|
||||
ENDIF
|
||||
|
||||
IF[{- !$disabled{md4} -}]
|
||||
SOURCE[$GOAL]=\
|
||||
md4_prov.c
|
||||
SOURCE[$GOAL]=md4_prov.c
|
||||
ENDIF
|
||||
|
||||
IF[{- !$disabled{mdc2} -}]
|
||||
SOURCE[$GOAL]=\
|
||||
mdc2_prov.c
|
||||
SOURCE[$GOAL]=mdc2_prov.c
|
||||
ENDIF
|
||||
|
||||
IF[{- !$disabled{whirlpool} -}]
|
||||
SOURCE[$GOAL]=\
|
||||
wp_prov.c
|
||||
SOURCE[$GOAL]=wp_prov.c
|
||||
ENDIF
|
||||
|
||||
IF[{- !$disabled{rmd160} -}]
|
||||
SOURCE[$GOAL]=\
|
||||
ripemd_prov.c
|
||||
ENDIF
|
||||
SOURCE[$GOAL]=ripemd_prov.c
|
||||
ENDIF
|
||||
|
Loading…
Reference in new issue