X-Git-Url: https://git.openssl.org/?a=blobdiff_plain;f=crypto%2Fo_fips.c;h=f56d5bb79d9216a36fa0421b668faad1ebff2b52;hb=a2fcab9978a0905c4286051993da63329fda8a19;hp=9474a0d9afa4199f113935f91865167c48c20dfc;hpb=b0b3d09063275680d9ad78568660d6c4357d61d6;p=openssl.git diff --git a/crypto/o_fips.c b/crypto/o_fips.c index 9474a0d9af..f56d5bb79d 100644 --- a/crypto/o_fips.c +++ b/crypto/o_fips.c @@ -1,5 +1,6 @@ -/* Written by Stephen henson (steve@openssl.org) for the OpenSSL - * project 2011. +/* + * Written by Stephen henson (steve@openssl.org) for the OpenSSL project + * 2011. */ /* ==================================================================== * Copyright (c) 2011 The OpenSSL Project. All rights reserved. @@ -9,7 +10,7 @@ * are met: * * 1. Redistributions of source code must retain the above copyright - * notice, this list of conditions and the following disclaimer. + * notice, this list of conditions and the following disclaimer. * * 2. Redistributions in binary form must reproduce the above copyright * notice, this list of conditions and the following disclaimer in @@ -57,36 +58,39 @@ #include "cryptlib.h" #ifdef OPENSSL_FIPS -#include -#include -#include +# include +# include +# include #endif int FIPS_mode(void) - { +{ + OPENSSL_init(); #ifdef OPENSSL_FIPS - return FIPS_module_mode(); + return FIPS_module_mode(); #else - return 0; + return 0; #endif - } +} int FIPS_mode_set(int r) - { - OPENSSL_init(); +{ + OPENSSL_init(); #ifdef OPENSSL_FIPS - if (!FIPS_module_mode_set(r)) - return 0; - if (r) - RAND_set_rand_method(FIPS_rand_get_method()); - else - RAND_set_rand_method(NULL); - return 1; +# ifndef FIPS_AUTH_USER_PASS +# define FIPS_AUTH_USER_PASS "Default FIPS Crypto User Password" +# endif + if (!FIPS_module_mode_set(r, FIPS_AUTH_USER_PASS)) + return 0; + if (r) + RAND_set_rand_method(FIPS_rand_get_method()); + else + RAND_set_rand_method(NULL); + return 1; #else - if (r == 0) - return 1; - CRYPTOerr(CRYPTO_F_FIPS_MODE_SET, CRYPTO_R_FIPS_MODE_NOT_SUPPORTED); - return 0; + if (r == 0) + return 1; + CRYPTOerr(CRYPTO_F_FIPS_MODE_SET, CRYPTO_R_FIPS_MODE_NOT_SUPPORTED); + return 0; #endif - } - +}