From: Mark Andrews Date: Wed, 11 Oct 2006 02:15:59 +0000 (+0000) Subject: Windows specific compile time test for: X-Git-Tag: v9.5.0a1~124 X-Git-Url: http://git.ipfire.org/gitweb/index.cgi?a=commitdiff_plain;h=0695629678cf1ed678dfdb1f03b95b0fef4eb48e;p=thirdparty%2Fbind9.git Windows specific compile time test for: 2089. [security] Raise the minimum safe OpenSSL versions to OpenSSL 0.9.7l and OpenSSL 0.9.8d. Versions prior to these have known security flaws which are (potentially) exploitable in named. [RT #16391] --- diff --git a/lib/dns/opensslrsa_link.c b/lib/dns/opensslrsa_link.c index 335816f71a9..611ad8788da 100644 --- a/lib/dns/opensslrsa_link.c +++ b/lib/dns/opensslrsa_link.c @@ -17,7 +17,7 @@ /* * Principal Author: Brian Wellington - * $Id: opensslrsa_link.c,v 1.9 2006/10/10 02:30:10 marka Exp $ + * $Id: opensslrsa_link.c,v 1.10 2006/10/11 02:15:59 marka Exp $ */ #ifdef OPENSSL @@ -43,6 +43,19 @@ #include #endif +/* + * We don't use configure for windows so enforce the OpenSSL version + * here. Unlike with configure we don't support overriding this test. + */ +#ifdef WIN +#if !((OPENSSL_VERSION_NUMBER >= 0x009070cfL && \ + OPENSSL_VERSION_NUMBER < 0x009080000L) || \ + OPENSSL_VERSION_NUMBER >= 0x0090804fL) +#error Please upgrade OpenSSL to 0.9.8d/0.9.7l or greater. +#endif +#endif + + /* * XXXMPA Temporarially disable RSA_BLINDING as it requires * good quality random data that cannot currently be guarenteed.