From: Pauli Date: Wed, 27 Nov 2024 00:19:32 +0000 (+1100) Subject: pbkdf2: change FIPS zeroization to use the OPENSSL_PEDANTIC_ZEROIZATION define X-Git-Tag: openssl-3.5.0-alpha1~873 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=8d09e61be6bf22bbaacda5ec53e02f938f40c76d;p=thirdparty%2Fopenssl.git pbkdf2: change FIPS zeroization to use the OPENSSL_PEDANTIC_ZEROIZATION define Reviewed-by: Richard Levitte Reviewed-by: Tim Hudson (Merged from https://github.com/openssl/openssl/pull/26068) --- diff --git a/providers/implementations/kdfs/pbkdf2.c b/providers/implementations/kdfs/pbkdf2.c index d1398461482..b3833140641 100644 --- a/providers/implementations/kdfs/pbkdf2.c +++ b/providers/implementations/kdfs/pbkdf2.c @@ -93,7 +93,7 @@ static void *kdf_pbkdf2_new(void *provctx) static void kdf_pbkdf2_cleanup(KDF_PBKDF2 *ctx) { ossl_prov_digest_reset(&ctx->digest); -#ifdef FIPS_MODULE +#ifdef OPENSSL_PEDANTIC_ZEROIZATION OPENSSL_clear_free(ctx->salt, ctx->salt_len); #else OPENSSL_free(ctx->salt);