From fccd1615eea5f81f2a12b2fb953e6606edbc59c8 Mon Sep 17 00:00:00 2001 From: Dimitri John Ledkov Date: Wed, 17 Apr 2024 09:04:59 +0200 Subject: [PATCH] Exclude X25519 and X448 from capabilities advertised by FIPS provider Reviewed-by: Neil Horman Reviewed-by: Paul Dale Reviewed-by: Tomas Mraz (Merged from https://github.com/openssl/openssl/pull/24099) --- providers/common/capabilities.c | 2 -- 1 file changed, 2 deletions(-) diff --git a/providers/common/capabilities.c b/providers/common/capabilities.c index f7234615e4..2cb2ee58de 100644 --- a/providers/common/capabilities.c +++ b/providers/common/capabilities.c @@ -189,10 +189,8 @@ static const OSSL_PARAM param_group_list[][10] = { TLS_GROUP_ENTRY("brainpoolP256r1", "brainpoolP256r1", "EC", 25), TLS_GROUP_ENTRY("brainpoolP384r1", "brainpoolP384r1", "EC", 26), TLS_GROUP_ENTRY("brainpoolP512r1", "brainpoolP512r1", "EC", 27), -# endif TLS_GROUP_ENTRY("x25519", "X25519", "X25519", 28), TLS_GROUP_ENTRY("x448", "X448", "X448", 29), -# ifndef FIPS_MODULE TLS_GROUP_ENTRY("brainpoolP256r1tls13", "brainpoolP256r1", "EC", 30), TLS_GROUP_ENTRY("brainpoolP384r1tls13", "brainpoolP384r1", "EC", 31), TLS_GROUP_ENTRY("brainpoolP512r1tls13", "brainpoolP512r1", "EC", 32), -- 2.34.1