[openssl-dev] Compile 1.0.2 release in FIPS mode

Lars Lavén lars.laven at columbitech.com
Mon Jan 26 13:18:34 UTC 2015


Hi,

I just tried to compile 1.0.2 in FIPS mode and unfortunately I get a compilation error. The function tls1_get_curvelist in ssl/t1_lib.c (line 437) still looks like it did in beta 3:


#ifdef OPENSSL_FIPS

                if (FIPS_mode())

                        {

                        *pcurves = fips_curves_default;

                        *pcurveslen = sizeof(fips_curves_default);

                        return;

                        }

#endif

It should rather be:


#ifdef OPENSSL_FIPS

                if (FIPS_mode())

                        {

                        *pcurves = fips_curves_default;

                        pcurveslen = sizeof(fips_curves_default);

                        return;

                        }

#endif


--
Kind regards,
Lars Lavén

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://mta.openssl.org/pipermail/openssl-dev/attachments/20150126/a165714e/attachment-0001.html>


More information about the openssl-dev mailing list