From 466076a7cc4b1e9add3228a80ad4c2059562ff1d Mon Sep 17 00:00:00 2001 From: John Safranek Date: Thu, 25 Feb 2021 11:07:26 -0800 Subject: [PATCH] FIPSv3 1. Remove the CAST IDs for the redundant RSA tests. 2. Remove the flags in configure.ac that enable the keys for the redundant RSA tests. --- configure.ac | 1 - wolfssl/wolfcrypt/fips_test.h | 2 -- 2 files changed, 3 deletions(-) diff --git a/configure.ac b/configure.ac index b46fe193b..3a901556e 100644 --- a/configure.ac +++ b/configure.ac @@ -2980,7 +2980,6 @@ AS_CASE([$FIPS_VERSION], [ENABLED_SHA512="yes"; AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_SHA512 -DWOLFSSL_SHA384"]) AS_IF([test "x$ENABLED_AESGCM" = "xno"], [ENABLED_AESGCM="yes"; AM_CFLAGS="$AM_CFLAGS -DHAVE_AESGCM"]) - AM_CFLAGS="$AM_CFLAGS -DUSE_CERT_BUFFERS_3072 -DUSE_CERT_BUFFERS_4096" AM_CFLAGS="$AM_CFLAGS -DWOLFSSL_VALIDATE_FFC_IMPORT -DHAVE_FFDHE_Q" AM_CFLAGS="$AM_CFLAGS -DHAVE_FFDHE_3072 -DHAVE_FFDHE_4096 -DHAVE_FFDHE_6144 -DHAVE_FFDHE_8192 -DFP_MAX_BITS=16384" ], diff --git a/wolfssl/wolfcrypt/fips_test.h b/wolfssl/wolfcrypt/fips_test.h index 7c16f4a4a..dc4ce092b 100644 --- a/wolfssl/wolfcrypt/fips_test.h +++ b/wolfssl/wolfcrypt/fips_test.h @@ -40,8 +40,6 @@ enum FipsCastId { FIPS_CAST_HMAC_SHA3_256, FIPS_CAST_DRBG, FIPS_CAST_RSA_SIGN_PKCS1v15, - FIPS_CAST_RSA_3072_SIGN_PKCS1v15, - FIPS_CAST_RSA_4096_SIGN_PKCS1v15, FIPS_CAST_ECC_CDH, FIPS_CAST_ECC_PRIMITIVE_Z, FIPS_CAST_DH_PRIMITIVE_Z,