Add non-FIPS algorithm blocking and selftest checking.
[openssl.git] / crypto / fips_err.h
1 /* crypto/fips_err.h */
2 /* ====================================================================
3  * Copyright (c) 1999-2010 The OpenSSL Project.  All rights reserved.
4  *
5  * Redistribution and use in source and binary forms, with or without
6  * modification, are permitted provided that the following conditions
7  * are met:
8  *
9  * 1. Redistributions of source code must retain the above copyright
10  *    notice, this list of conditions and the following disclaimer. 
11  *
12  * 2. Redistributions in binary form must reproduce the above copyright
13  *    notice, this list of conditions and the following disclaimer in
14  *    the documentation and/or other materials provided with the
15  *    distribution.
16  *
17  * 3. All advertising materials mentioning features or use of this
18  *    software must display the following acknowledgment:
19  *    "This product includes software developed by the OpenSSL Project
20  *    for use in the OpenSSL Toolkit. (http://www.OpenSSL.org/)"
21  *
22  * 4. The names "OpenSSL Toolkit" and "OpenSSL Project" must not be used to
23  *    endorse or promote products derived from this software without
24  *    prior written permission. For written permission, please contact
25  *    openssl-core@OpenSSL.org.
26  *
27  * 5. Products derived from this software may not be called "OpenSSL"
28  *    nor may "OpenSSL" appear in their names without prior written
29  *    permission of the OpenSSL Project.
30  *
31  * 6. Redistributions of any form whatsoever must retain the following
32  *    acknowledgment:
33  *    "This product includes software developed by the OpenSSL Project
34  *    for use in the OpenSSL Toolkit (http://www.OpenSSL.org/)"
35  *
36  * THIS SOFTWARE IS PROVIDED BY THE OpenSSL PROJECT ``AS IS'' AND ANY
37  * EXPRESSED OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
38  * IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
39  * PURPOSE ARE DISCLAIMED.  IN NO EVENT SHALL THE OpenSSL PROJECT OR
40  * ITS CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
41  * SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
42  * NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES;
43  * LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
44  * HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT,
45  * STRICT LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE)
46  * ARISING IN ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED
47  * OF THE POSSIBILITY OF SUCH DAMAGE.
48  * ====================================================================
49  *
50  * This product includes cryptographic software written by Eric Young
51  * (eay@cryptsoft.com).  This product includes software written by Tim
52  * Hudson (tjh@cryptsoft.com).
53  *
54  */
55
56 /* NOTE: this file was auto generated by the mkerr.pl script: any changes
57  * made to it will be overwritten when the script next updates this file,
58  * only reason strings will be preserved.
59  */
60
61 #include <stdio.h>
62 #include <openssl/err.h>
63 #include <openssl/fips.h>
64
65 /* BEGIN ERROR CODES */
66 #ifndef OPENSSL_NO_ERR
67
68 #define ERR_FUNC(func) ERR_PACK(ERR_LIB_FIPS,func,0)
69 #define ERR_REASON(reason) ERR_PACK(ERR_LIB_FIPS,0,reason)
70
71 static ERR_STRING_DATA FIPS_str_functs[]=
72         {
73 {ERR_FUNC(FIPS_F_DH_BUILTIN_GENPARAMS), "DH_BUILTIN_GENPARAMS"},
74 {ERR_FUNC(FIPS_F_DSA_BUILTIN_PARAMGEN), "DSA_BUILTIN_PARAMGEN"},
75 {ERR_FUNC(FIPS_F_DSA_BUILTIN_PARAMGEN2),        "DSA_BUILTIN_PARAMGEN2"},
76 {ERR_FUNC(FIPS_F_DSA_DO_SIGN),  "DSA_do_sign"},
77 {ERR_FUNC(FIPS_F_DSA_DO_VERIFY),        "DSA_do_verify"},
78 {ERR_FUNC(FIPS_F_EVP_CIPHERINIT_EX),    "EVP_CipherInit_ex"},
79 {ERR_FUNC(FIPS_F_EVP_DIGESTINIT_EX),    "EVP_DigestInit_ex"},
80 {ERR_FUNC(FIPS_F_FIPS_CHECK_DSA),       "FIPS_CHECK_DSA"},
81 {ERR_FUNC(FIPS_F_FIPS_CHECK_INCORE_FINGERPRINT),        "FIPS_check_incore_fingerprint"},
82 {ERR_FUNC(FIPS_F_FIPS_CHECK_RSA),       "fips_check_rsa"},
83 {ERR_FUNC(FIPS_F_FIPS_CIPHERINIT),      "FIPS_CIPHERINIT"},
84 {ERR_FUNC(FIPS_F_FIPS_DIGESTINIT),      "FIPS_DIGESTINIT"},
85 {ERR_FUNC(FIPS_F_FIPS_DSA_CHECK),       "FIPS_DSA_CHECK"},
86 {ERR_FUNC(FIPS_F_FIPS_MODE_SET),        "FIPS_mode_set"},
87 {ERR_FUNC(FIPS_F_FIPS_PKEY_SIGNATURE_TEST),     "fips_pkey_signature_test"},
88 {ERR_FUNC(FIPS_F_FIPS_SELFTEST_AES),    "FIPS_selftest_aes"},
89 {ERR_FUNC(FIPS_F_FIPS_SELFTEST_DES),    "FIPS_selftest_des"},
90 {ERR_FUNC(FIPS_F_FIPS_SELFTEST_DSA),    "FIPS_selftest_dsa"},
91 {ERR_FUNC(FIPS_F_FIPS_SELFTEST_HMAC),   "FIPS_selftest_hmac"},
92 {ERR_FUNC(FIPS_F_FIPS_SELFTEST_RNG),    "FIPS_selftest_rng"},
93 {ERR_FUNC(FIPS_F_FIPS_SELFTEST_SHA1),   "FIPS_selftest_sha1"},
94 {ERR_FUNC(FIPS_F_HASH_FINAL),   "HASH_FINAL"},
95 {ERR_FUNC(FIPS_F_RSA_BUILTIN_KEYGEN),   "RSA_BUILTIN_KEYGEN"},
96 {ERR_FUNC(FIPS_F_RSA_EAY_PRIVATE_DECRYPT),      "RSA_EAY_PRIVATE_DECRYPT"},
97 {ERR_FUNC(FIPS_F_RSA_EAY_PRIVATE_ENCRYPT),      "RSA_EAY_PRIVATE_ENCRYPT"},
98 {ERR_FUNC(FIPS_F_RSA_EAY_PUBLIC_DECRYPT),       "RSA_EAY_PUBLIC_DECRYPT"},
99 {ERR_FUNC(FIPS_F_RSA_EAY_PUBLIC_ENCRYPT),       "RSA_EAY_PUBLIC_ENCRYPT"},
100 {ERR_FUNC(FIPS_F_RSA_X931_GENERATE_KEY_EX),     "RSA_X931_generate_key_ex"},
101 {ERR_FUNC(FIPS_F_SSLEAY_RAND_BYTES),    "SSLEAY_RAND_BYTES"},
102 {0,NULL}
103         };
104
105 static ERR_STRING_DATA FIPS_str_reasons[]=
106         {
107 {ERR_REASON(FIPS_R_CANNOT_READ_EXE)      ,"cannot read exe"},
108 {ERR_REASON(FIPS_R_CANNOT_READ_EXE_DIGEST),"cannot read exe digest"},
109 {ERR_REASON(FIPS_R_CONTRADICTING_EVIDENCE),"contradicting evidence"},
110 {ERR_REASON(FIPS_R_EXE_DIGEST_DOES_NOT_MATCH),"exe digest does not match"},
111 {ERR_REASON(FIPS_R_FINGERPRINT_DOES_NOT_MATCH),"fingerprint does not match"},
112 {ERR_REASON(FIPS_R_FINGERPRINT_DOES_NOT_MATCH_NONPIC_RELOCATED),"fingerprint does not match nonpic relocated"},
113 {ERR_REASON(FIPS_R_FINGERPRINT_DOES_NOT_MATCH_SEGMENT_ALIASING),"fingerprint does not match segment aliasing"},
114 {ERR_REASON(FIPS_R_FIPS_MODE_ALREADY_SET),"fips mode already set"},
115 {ERR_REASON(FIPS_R_FIPS_SELFTEST_FAILED) ,"fips selftest failed"},
116 {ERR_REASON(FIPS_R_INVALID_KEY_LENGTH)   ,"invalid key length"},
117 {ERR_REASON(FIPS_R_KEY_TOO_SHORT)        ,"key too short"},
118 {ERR_REASON(FIPS_R_NON_FIPS_METHOD)      ,"non fips method"},
119 {ERR_REASON(FIPS_R_PAIRWISE_TEST_FAILED) ,"pairwise test failed"},
120 {ERR_REASON(FIPS_R_RSA_DECRYPT_ERROR)    ,"rsa decrypt error"},
121 {ERR_REASON(FIPS_R_RSA_ENCRYPT_ERROR)    ,"rsa encrypt error"},
122 {ERR_REASON(FIPS_R_SELFTEST_FAILED)      ,"selftest failed"},
123 {ERR_REASON(FIPS_R_TEST_FAILURE)         ,"test failure"},
124 {ERR_REASON(FIPS_R_UNSUPPORTED_PLATFORM) ,"unsupported platform"},
125 {0,NULL}
126         };
127
128 #endif
129
130 void ERR_load_FIPS_strings(void)
131         {
132 #ifndef OPENSSL_NO_ERR
133
134         if (ERR_func_error_string(FIPS_str_functs[0].error) == NULL)
135                 {
136                 ERR_load_strings(0,FIPS_str_functs);
137                 ERR_load_strings(0,FIPS_str_reasons);
138                 }
139 #endif
140         }