From: Dr. Stephen Henson Date: Wed, 25 May 2011 15:33:29 +0000 (+0000) Subject: Don't advertise or use MD5 for TLS v1.2 in FIPS mode X-Git-Tag: OpenSSL_1_0_1-beta1~295 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=9c34782478f00faba7bac87bd03a0f4f1ee53747;p=oweals%2Fopenssl.git Don't advertise or use MD5 for TLS v1.2 in FIPS mode --- diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c index 391b330c68..1dbdc0183c 100644 --- a/ssl/t1_lib.c +++ b/ssl/t1_lib.c @@ -317,9 +317,15 @@ static unsigned char tls12_sigalgs[] = { int tls12_get_req_sig_algs(SSL *s, unsigned char *p) { + size_t slen = sizeof(tls12_sigalgs); +#ifdef OPENSSL_FIPS + /* If FIPS mode don't include MD5 which is last */ + if (FIPS_mode()) + slen -= 2; +#endif if (p) - memcpy(p, tls12_sigalgs, sizeof(tls12_sigalgs)); - return (int)sizeof(tls12_sigalgs); + memcpy(p, tls12_sigalgs, slen); + return (int)slen; } unsigned char *ssl_add_clienthello_tlsext(SSL *s, unsigned char *p, unsigned char *limit) @@ -1954,6 +1960,10 @@ const EVP_MD *tls12_get_hash(unsigned char hash_alg) { #ifndef OPENSSL_NO_MD5 case TLSEXT_hash_md5: +#ifdef OPENSSL_FIPS + if (FIPS_mode()) + return NULL; +#endif return EVP_md5(); #endif #ifndef OPENSSL_NO_SHA