]> git.ipfire.org Git - thirdparty/openssl.git/commitdiff
fips: change integrity check zeroization to use the OPENSSL_PEDANTIC_ZEROIZATION...
authorPauli <ppzgs1@gmail.com>
Wed, 27 Nov 2024 00:21:08 +0000 (11:21 +1100)
committerTomas Mraz <tomas@openssl.org>
Thu, 28 Nov 2024 14:13:35 +0000 (15:13 +0100)
Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Tim Hudson <tjh@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/26068)

providers/fips/self_test.c

index f4fd3f51ae32398df34d7d27bce585f234a5c3e5..c966f24b362995e65bed2bdf571592959b2aeffd 100644 (file)
@@ -289,7 +289,9 @@ err:
     OSSL_SELF_TEST_onend(ev, ret);
     EVP_MAC_CTX_free(ctx);
     EVP_MAC_free(mac);
+# ifdef OPENSSL_PEDANTIC_ZEROIZATION
     OPENSSL_cleanse(out, sizeof(out));
+# endif
     return ret;
 }
 #endif /* OPENSSL_NO_FIPS_POST */