mirror of
https://github.com/wolfSSL/wolfssl.git
synced 2026-08-04 03:14:13 +02:00
Move WC_SIG_MIN_HASH_TYPE default into signature.h
This commit is contained in:
@@ -41,13 +41,6 @@
|
|||||||
#include <tests/api/api.h>
|
#include <tests/api/api.h>
|
||||||
#include <tests/api/test_signature.h>
|
#include <tests/api/test_signature.h>
|
||||||
|
|
||||||
/* Effective hash floor used by wc_SignatureVerify/Generate; mirrors the
|
|
||||||
* default in wolfcrypt/src/signature.c. A build may lower it (e.g.
|
|
||||||
* --enable-wolfclu defines WC_SIG_MIN_HASH_TYPE=WC_HASH_TYPE_MD5). */
|
|
||||||
#ifndef WC_SIG_MIN_HASH_TYPE
|
|
||||||
#define WC_SIG_MIN_HASH_TYPE WC_HASH_TYPE_SHA256
|
|
||||||
#endif
|
|
||||||
|
|
||||||
/* Testing wc_SignatureGetSize() for signature type ECC */
|
/* Testing wc_SignatureGetSize() for signature type ECC */
|
||||||
int test_wc_SignatureGetSize_ecc(void)
|
int test_wc_SignatureGetSize_ecc(void)
|
||||||
{
|
{
|
||||||
|
|||||||
@@ -53,16 +53,6 @@
|
|||||||
#endif
|
#endif
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
/* Minimum hash strength accepted by the wc_SignatureVerify/Generate
|
|
||||||
* convenience APIs. Default is SHA-256 to keep MD5 and SHA-1 (both with
|
|
||||||
* known collision attacks) out of new code. Define WC_SIG_MIN_HASH_TYPE
|
|
||||||
* to a weaker wc_HashType (e.g. WC_HASH_TYPE_SHA) to opt back into legacy
|
|
||||||
* behavior. The lower-level wc_SignatureVerifyHash/wc_SignatureGenerateHash
|
|
||||||
* APIs are unaffected. */
|
|
||||||
#ifndef WC_SIG_MIN_HASH_TYPE
|
|
||||||
#define WC_SIG_MIN_HASH_TYPE WC_HASH_TYPE_SHA256
|
|
||||||
#endif
|
|
||||||
|
|
||||||
static int wc_SignatureCheckHashStrength(enum wc_HashType hash_type)
|
static int wc_SignatureCheckHashStrength(enum wc_HashType hash_type)
|
||||||
{
|
{
|
||||||
int min_sz, this_sz;
|
int min_sz, this_sz;
|
||||||
|
|||||||
@@ -35,6 +35,16 @@
|
|||||||
extern "C" {
|
extern "C" {
|
||||||
#endif
|
#endif
|
||||||
|
|
||||||
|
/* Minimum hash strength accepted by the wc_SignatureVerify/Generate
|
||||||
|
* convenience APIs. Default is SHA-256 to keep MD5 and SHA-1 (both with
|
||||||
|
* known collision attacks) out of new code. Define WC_SIG_MIN_HASH_TYPE
|
||||||
|
* to a weaker wc_HashType (e.g. WC_HASH_TYPE_SHA) to opt back into legacy
|
||||||
|
* behavior. The lower-level wc_SignatureVerifyHash/wc_SignatureGenerateHash
|
||||||
|
* APIs are unaffected. */
|
||||||
|
#ifndef WC_SIG_MIN_HASH_TYPE
|
||||||
|
#define WC_SIG_MIN_HASH_TYPE WC_HASH_TYPE_SHA256
|
||||||
|
#endif
|
||||||
|
|
||||||
enum wc_SignatureType {
|
enum wc_SignatureType {
|
||||||
WC_SIGNATURE_TYPE_NONE = 0,
|
WC_SIGNATURE_TYPE_NONE = 0,
|
||||||
WC_SIGNATURE_TYPE_ECC = 1,
|
WC_SIGNATURE_TYPE_ECC = 1,
|
||||||
|
|||||||
Reference in New Issue
Block a user