From 9c34782478f00faba7bac87bd03a0f4f1ee53747 Mon Sep 17 00:00:00 2001 From: "Dr. Stephen Henson" Date: Wed, 25 May 2011 15:33:29 +0000 Subject: [PATCH] Don't advertise or use MD5 for TLS v1.2 in FIPS mode --- ssl/t1_lib.c | 14 ++++++++++++-- 1 file changed, 12 insertions(+), 2 deletions(-) diff --git a/ssl/t1_lib.c b/ssl/t1_lib.c index 391b330c68..1dbdc0183c 100644 --- a/ssl/t1_lib.c +++ b/ssl/t1_lib.c @@ -317,9 +317,15 @@ static unsigned char tls12_sigalgs[] = { int tls12_get_req_sig_algs(SSL *s, unsigned char *p) { + size_t slen = sizeof(tls12_sigalgs); +#ifdef OPENSSL_FIPS + /* If FIPS mode don't include MD5 which is last */ + if (FIPS_mode()) + slen -= 2; +#endif if (p) - memcpy(p, tls12_sigalgs, sizeof(tls12_sigalgs)); - return (int)sizeof(tls12_sigalgs); + memcpy(p, tls12_sigalgs, slen); + return (int)slen; } unsigned char *ssl_add_clienthello_tlsext(SSL *s, unsigned char *p, unsigned char *limit) @@ -1954,6 +1960,10 @@ const EVP_MD *tls12_get_hash(unsigned char hash_alg) { #ifndef OPENSSL_NO_MD5 case TLSEXT_hash_md5: +#ifdef OPENSSL_FIPS + if (FIPS_mode()) + return NULL; +#endif return EVP_md5(); #endif #ifndef OPENSSL_NO_SHA -- 2.25.1