From: Dimitri John Ledkov Date: Wed, 17 Apr 2024 07:04:59 +0000 (+0200) Subject: Exclude X25519 and X448 from capabilities advertised by FIPS provider X-Git-Tag: openssl-3.4.0-alpha1~670 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=fccd1615eea5f81f2a12b2fb953e6606edbc59c8;p=thirdparty%2Fopenssl.git Exclude X25519 and X448 from capabilities advertised by FIPS provider Reviewed-by: Neil Horman Reviewed-by: Paul Dale Reviewed-by: Tomas Mraz (Merged from https://github.com/openssl/openssl/pull/24099) --- diff --git a/providers/common/capabilities.c b/providers/common/capabilities.c index f7234615e4c..2cb2ee58dec 100644 --- a/providers/common/capabilities.c +++ b/providers/common/capabilities.c @@ -189,10 +189,8 @@ static const OSSL_PARAM param_group_list[][10] = { TLS_GROUP_ENTRY("brainpoolP256r1", "brainpoolP256r1", "EC", 25), TLS_GROUP_ENTRY("brainpoolP384r1", "brainpoolP384r1", "EC", 26), TLS_GROUP_ENTRY("brainpoolP512r1", "brainpoolP512r1", "EC", 27), -# endif TLS_GROUP_ENTRY("x25519", "X25519", "X25519", 28), TLS_GROUP_ENTRY("x448", "X448", "X448", 29), -# ifndef FIPS_MODULE TLS_GROUP_ENTRY("brainpoolP256r1tls13", "brainpoolP256r1", "EC", 30), TLS_GROUP_ENTRY("brainpoolP384r1tls13", "brainpoolP384r1", "EC", 31), TLS_GROUP_ENTRY("brainpoolP512r1tls13", "brainpoolP512r1", "EC", 32),