]> git.ipfire.org Git - thirdparty/tor.git/commitdiff
Log more OpenSSL engine statuses at startup.
authorNick Mathewson <nickm@torproject.org>
Mon, 18 Nov 2013 16:12:24 +0000 (11:12 -0500)
committerNick Mathewson <nickm@torproject.org>
Mon, 18 Nov 2013 16:12:24 +0000 (11:12 -0500)
Fixes ticket 10043; patch from Joshua Datko.

changes/ticket10043 [new file with mode: 0644]
src/common/crypto.c

diff --git a/changes/ticket10043 b/changes/ticket10043
new file mode 100644 (file)
index 0000000..21541be
--- /dev/null
@@ -0,0 +1,4 @@
+  o Minor features:
+    - When logging OpenSSL engine status at startup, log the status of
+      more engines. Fixes ticket 10043; patch from Joshua Datko.
+
index c1a2f339353ebd16c37b41b11a67565896ab878e..cbe992ef4e93a4bf7f150f3e3d842c18823bffc3 100644 (file)
@@ -307,12 +307,22 @@ crypto_global_init(int useAccel, const char *accelName, const char *accelDir)
                  " setting default ciphers.");
         ENGINE_set_default(e, ENGINE_METHOD_ALL);
       }
+      /* Log, if available, the intersection of the set of algorithms
+         used by Tor and the set of algorithms available in the engine */
       log_engine("RSA", ENGINE_get_default_RSA());
       log_engine("DH", ENGINE_get_default_DH());
+      log_engine("ECDH", ENGINE_get_default_ECDH());
+      log_engine("ECDSA", ENGINE_get_default_ECDSA());
       log_engine("RAND", ENGINE_get_default_RAND());
       log_engine("SHA1", ENGINE_get_digest_engine(NID_sha1));
-      log_engine("3DES", ENGINE_get_cipher_engine(NID_des_ede3_ecb));
-      log_engine("AES", ENGINE_get_cipher_engine(NID_aes_128_ecb));
+      log_engine("3DES-CBC", ENGINE_get_cipher_engine(NID_des_ede3_cbc));
+      log_engine("AES-128-ECB", ENGINE_get_cipher_engine(NID_aes_128_ecb));
+      log_engine("AES-128-CBC", ENGINE_get_cipher_engine(NID_aes_128_cbc));
+      log_engine("AES-128-CTR", ENGINE_get_cipher_engine(NID_aes_128_ctr));
+      log_engine("AES-128-GCM", ENGINE_get_cipher_engine(NID_aes_128_gcm));
+      log_engine("AES-256-CBC", ENGINE_get_cipher_engine(NID_aes_256_cbc));
+      log_engine("AES-256-GCM", ENGINE_get_cipher_engine(NID_aes_256_gcm));
+
 #endif
     } else {
       log_info(LD_CRYPTO, "NOT using OpenSSL engine support.");