Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

FIPS: make it possible to specify the fipshmac binary #64

Open
wants to merge 1 commit into
base: master
Choose a base branch
from

Conversation

hramrach
Copy link
Contributor

@hramrach hramrach commented Jun 9, 2021

When patched with the distribution key the openssl script creating hmac with zero key does not work and all tests fail.

This makes the openssl invocation into a separate script which can be replaced by dstribution-provided fipshmac passed as FIPSHMAC make variable.

I considered writing a test program that includes fips.c and prints the key but that does not work with cross-compilation.

Storing the key in a separate file so that it can be both included in fips.c and used in the openssl script might be also an option.

@jschmidb
Copy link
Contributor

jschmidb commented Jun 9, 2021

Storing the key in a separate file so that it can be both included in fips.c and used in the openssl script might be an option.

Yes indeed. At the moment the hmac key must be specified/changed at two places. We may move the key into a separate file, as you suggest. I'm not sure about introducing a new dependency to fipshmac, but I'll check.

@hramrach
Copy link
Contributor Author

hramrach commented Jun 9, 2021

The idea of this patch is that on fips-free distribution or in CI environment you can test with openssl and when you use fips you will likely have fipshmac available. Not a great solution only checking the existence of the tool, though. It seems other utilities for fips handling exist, too.

@hramrach hramrach force-pushed the master branch 2 times, most recently from 6240b03 to 1b3e0bd Compare June 9, 2021 12:27
@hramrach hramrach changed the title FIPS: use fipshmac when available. FIPS: make it possible to specify the fipshmac binary Jun 9, 2021
@hramrach
Copy link
Contributor Author

hramrach commented Jun 9, 2021

This passes both on the CI and in the distro with FIPSHMAC=fipshmac and looks like overall improvement to readability.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants