From fa1af374701c3b500bd041a5e739b52b1aa2cf9f Mon Sep 17 00:00:00 2001 From: David Garske Date: Fri, 23 Oct 2020 15:38:38 -0700 Subject: [PATCH] Fix for FIPS ready CAVP tests. For now it requires ECC 192-bit. --- wolfssl/wolfcrypt/settings.h | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/wolfssl/wolfcrypt/settings.h b/wolfssl/wolfcrypt/settings.h index 0aded6eee..6c405794b 100644 --- a/wolfssl/wolfcrypt/settings.h +++ b/wolfssl/wolfcrypt/settings.h @@ -1756,8 +1756,8 @@ extern void uITRON4_free(void *p) ; #ifdef WOLFSSL_MIN_ECC_BITS #define ECC_MIN_KEY_SZ WOLFSSL_MIN_ECC_BITS #else - #if defined(HAVE_FIPS) && defined(HAVE_FIPS_VERSION) && HAVE_FIPS_VERSION == 2 - /* FIPSv2 includes 192-bit support */ + #if defined(HAVE_FIPS) && defined(HAVE_FIPS_VERSION) && HAVE_FIPS_VERSION >= 2 + /* FIPSv2 and ready (for now) includes 192-bit support */ #define ECC_MIN_KEY_SZ 192 #else #define ECC_MIN_KEY_SZ 224