From: Dr. Stephen Henson Date: Mon, 18 Apr 2011 17:31:28 +0000 (+0000) Subject: Override flag for XTS length limit. X-Git-Tag: OpenSSL-fips-2_0-rc1~536 X-Git-Url: https://git.openssl.org/gitweb/?p=openssl.git;a=commitdiff_plain;h=62dc7ed67c00a81801c7a3a7d37e54b2b7b04106 Override flag for XTS length limit. --- diff --git a/crypto/evp/e_aes.c b/crypto/evp/e_aes.c index 9b2f2a7441..2d33837478 100644 --- a/crypto/evp/e_aes.c +++ b/crypto/evp/e_aes.c @@ -519,7 +519,8 @@ static int aes_xts(EVP_CIPHER_CTX *ctx, unsigned char *out, return -1; #ifdef OPENSSL_FIPS /* Requirement of SP800-38E */ - if (FIPS_mode() && len > (1L<<20)*16) + if (FIPS_mode() && !(ctx->flags & EVP_CIPH_FLAG_NON_FIPS_ALLOW) && + (len > (1L<<20)*16)) { EVPerr(EVP_F_AES_XTS, EVP_R_TOO_LARGE); return -1;