Cleanse memory using the new OPENSSL_cleanse() function.
[openssl.git] / crypto / pkcs12 / p12_crpt.c
index 97be6a5fb538ad5b31bdff1759f8caac7ac54630..5e8958612b494e12a408362b112a3dcc37c22ebf 100644 (file)
@@ -118,7 +118,7 @@ int PKCS12_PBE_keyivgen (EVP_CIPHER_CTX *ctx, const char *pass, int passlen,
        }
        PBEPARAM_free(pbe);
        EVP_CipherInit_ex(ctx, cipher, NULL, key, iv, en_de);
-       memset(key, 0, EVP_MAX_KEY_LENGTH);
-       memset(iv, 0, EVP_MAX_IV_LENGTH);
+       OPENSSL_cleanse(key, EVP_MAX_KEY_LENGTH);
+       OPENSSL_cleanse(iv, EVP_MAX_IV_LENGTH);
        return 1;
 }