]> git.ipfire.org Git - thirdparty/openssl.git/commitdiff
Enable LMS on provider compat fips build for 3.6 master
authorNeil Horman <nhorman@openssl.org>
Sun, 14 Sep 2025 17:13:00 +0000 (13:13 -0400)
committerNeil Horman <nhorman@openssl.org>
Sun, 14 Sep 2025 17:13:00 +0000 (13:13 -0400)
The LMS test for fips assumes that LMS is available in the provider in
any version equal to or later than 3.6.

We should probably augment the test such that instead of just checking
the openssl version, we instead query the provider to see if the needed
algs are available to use LMS.

But given the current state of affairs, it seems more sensible to just
enable lms in the 3.6 fips provider build to ensure lms gets tested.

Fixes openssl/project#1435

Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Paul Dale <ppzgs1@gmail.com>
Reviewed-by: Shane Lontis <shane.lontis@oracle.com>
(Merged from https://github.com/openssl/openssl/pull/28541)

.github/workflows/provider-compatibility.yml

index 98e5248fc02dcc87716b6719e09961d3e8ca6d6d..00ebb8f2c745d1492ac5af2c2b00cbf32faf05ba 100644 (file)
@@ -141,7 +141,7 @@ jobs:
             name: openssl-3.6,
             dir: branch-3.6,
             tgz: branch-3.6.tar.gz,
-            extra_config: "",
+            extra_config: "enable-lms",
           }, {
             name: master,
             dir: branch-master,