Exclude X25519 and X448 from capabilities advertised by FIPS provider
authorDimitri John Ledkov <dimitri.ledkov@surgut.co.uk>
Wed, 17 Apr 2024 07:04:59 +0000 (09:04 +0200)
committerTomas Mraz <tomas@openssl.org>
Fri, 19 Apr 2024 08:32:27 +0000 (10:32 +0200)
Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Paul Dale <ppzgs1@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/24099)

providers/common/capabilities.c

index f7234615e4ca00e465e05fb7042b1f98633e9975..2cb2ee58dec7ee7b1d9401a9366cdc3f0b272670 100644 (file)
@@ -189,10 +189,8 @@ static const OSSL_PARAM param_group_list[][10] = {
     TLS_GROUP_ENTRY("brainpoolP256r1", "brainpoolP256r1", "EC", 25),
     TLS_GROUP_ENTRY("brainpoolP384r1", "brainpoolP384r1", "EC", 26),
     TLS_GROUP_ENTRY("brainpoolP512r1", "brainpoolP512r1", "EC", 27),
-#  endif
     TLS_GROUP_ENTRY("x25519", "X25519", "X25519", 28),
     TLS_GROUP_ENTRY("x448", "X448", "X448", 29),
-#  ifndef FIPS_MODULE
     TLS_GROUP_ENTRY("brainpoolP256r1tls13", "brainpoolP256r1", "EC", 30),
     TLS_GROUP_ENTRY("brainpoolP384r1tls13", "brainpoolP384r1", "EC", 31),
     TLS_GROUP_ENTRY("brainpoolP512r1tls13", "brainpoolP512r1", "EC", 32),