Skip to content

Commit

Permalink
fipsmodule.cnf: set the signature digest checks option on installation
Browse files Browse the repository at this point in the history
Reviewed-by: Dmitry Belyavskiy <[email protected]>
Reviewed-by: Shane Lontis <[email protected]>
(Merged from openssl#25020)
  • Loading branch information
paulidale committed Aug 11, 2024
1 parent fc5c86b commit 2f33265
Showing 1 changed file with 8 additions and 7 deletions.
15 changes: 8 additions & 7 deletions util/mk-fipsmodule-cnf.pl
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@
my $ems_check = 1;
my $no_short_mac = 1;
my $drgb_no_trunc_dgst = 1;
my $kdf_digest_check = 1;
my $digest_check = 1;
my $dsa_sign_disabled = 1;
my $tdes_encrypt_disabled = 1;
my $pkcs15_pad_disable = 1;
Expand Down Expand Up @@ -59,13 +59,14 @@
tls1-prf-ems-check = $ems_check
no-short-mac = $no_short_mac
drbg-no-trunc-md = $drgb_no_trunc_dgst
signature-digest-check = $digest_check
dsa-sign-disabled = $dsa_sign_disabled
hkdf-digest-check = $kdf_digest_check
tls13-kdf-digest-check = $kdf_digest_check
tls1-prf-digest-check = $kdf_digest_check
sshkdf-digest-check = $kdf_digest_check
sskdf-digest-check = $kdf_digest_check
x963kdf-digest-check = $kdf_digest_check
hkdf-digest-check = $digest_check
tls13-kdf-digest-check = $digest_check
tls1-prf-digest-check = $digest_check
sshkdf-digest-check = $digest_check
sskdf-digest-check = $digest_check
x963kdf-digest-check = $digest_check
tdes-encrypt-disabled = $tdes_encrypt_disabled
rsa-pkcs15-padding-disabled = $pkcs15_pad_disable
rsa-sign-x931-pad-disabled = $rsa_sign_x931_pad_disabled
Expand Down

0 comments on commit 2f33265

Please sign in to comment.