]> git.ipfire.org Git - thirdparty/openssh-portable.git/commitdiff
Move OPENSSL_NO_RIPEMD160 to compat.
authorDarren Tucker <dtucker@zip.com.au>
Fri, 28 Oct 2016 03:26:58 +0000 (14:26 +1100)
committerDarren Tucker <dtucker@zip.com.au>
Fri, 28 Oct 2016 03:26:58 +0000 (14:26 +1100)
Move OPENSSL_NO_RIPEMD160 to compat and add ifdefs to mac.c around the
ripemd160 MACs.

digest-openssl.c
mac.c
openbsd-compat/openssl-compat.h

index 517d2a24c6890a9d90f4d2d36d44fe6018b501f3..13b63c2f006dea92061f1cdbbe0f40fb4a132391 100644 (file)
@@ -32,8 +32,7 @@
 #include "digest.h"
 #include "ssherr.h"
 
-#if !defined(HAVE_EVP_RIPEMD160) || defined(OPENSSL_NO_RIPEMD) || \
-    defined(OPENSSL_NO_RMD160)
+#ifndef HAVE_EVP_RIPEMD160
 # define EVP_ripemd160 NULL
 #endif /* HAVE_EVP_RIPEMD160 */
 #ifndef HAVE_EVP_SHA256
diff --git a/mac.c b/mac.c
index 6b12cd1970b111c3a38debcd6e93906496ac548e..5ba7fae195390ad2bbebb2f167486b3559a2eb86 100644 (file)
--- a/mac.c
+++ b/mac.c
@@ -64,8 +64,10 @@ static const struct macalg macs[] = {
 #endif
        { "hmac-md5",                           SSH_DIGEST, SSH_DIGEST_MD5, 0, 0, 0, 0 },
        { "hmac-md5-96",                        SSH_DIGEST, SSH_DIGEST_MD5, 96, 0, 0, 0 },
+#ifdef HAVE_EVP_RIPEMD160
        { "hmac-ripemd160",                     SSH_DIGEST, SSH_DIGEST_RIPEMD160, 0, 0, 0, 0 },
        { "hmac-ripemd160@openssh.com",         SSH_DIGEST, SSH_DIGEST_RIPEMD160, 0, 0, 0, 0 },
+#endif
        { "umac-64@openssh.com",                SSH_UMAC, 0, 0, 128, 64, 0 },
        { "umac-128@openssh.com",               SSH_UMAC128, 0, 0, 128, 128, 0 },
 
@@ -78,7 +80,9 @@ static const struct macalg macs[] = {
 #endif
        { "hmac-md5-etm@openssh.com",           SSH_DIGEST, SSH_DIGEST_MD5, 0, 0, 0, 1 },
        { "hmac-md5-96-etm@openssh.com",        SSH_DIGEST, SSH_DIGEST_MD5, 96, 0, 0, 1 },
+#ifdef HAVE_EVP_RIPEMD160
        { "hmac-ripemd160-etm@openssh.com",     SSH_DIGEST, SSH_DIGEST_RIPEMD160, 0, 0, 0, 1 },
+#endif
        { "umac-64-etm@openssh.com",            SSH_UMAC, 0, 0, 128, 64, 1 },
        { "umac-128-etm@openssh.com",           SSH_UMAC128, 0, 0, 128, 128, 1 },
 
index 3513d6011abace57e49f946cee6699e8a575865f..2ae42bacf233f0a68e9a87b27dbbdd2b816a9ec2 100644 (file)
@@ -69,6 +69,12 @@ void ssh_aes_ctr_iv(EVP_CIPHER_CTX *, int, u_char *, size_t);
 # endif
 #endif
 
+#if defined(HAVE_EVP_RIPEMD160)
+# if defined(OPENSSL_NO_RIPEMD) || defined(OPENSSL_NO_RMD160)
+#  undef HAVE_EVP_RIPEMD160
+# endif
+#endif
+
 /*
  * We overload some of the OpenSSL crypto functions with ssh_* equivalents
  * to automatically handle OpenSSL engine initialisation.