mirror of
https://github.com/wolfSSL/wolfssl.git
synced 2026-08-16 18:32:04 +02:00
(unversioned defined(HAVE_FIPS), not a version arm -- hmac.c is in-boundary and master's copy only compiles at v7+/MAJOR=8). This structurally closes the old-TLS MD5 PRF: wc_PRF_TLSv1 -> wc_PRF(md5_mac) -> wc_HmacSetKey(WC_MD5) -> BAD_FUNC_ARG. Separately, in wc_HKDF_Expand_ex, add `else if (ret == 0) return BAD_FUNC_ARG;` after the wc_HmacSizeByType call: the existing code guarded ret < 0 but not ret == 0, and hashSz is the divisor in the `outSz/hashSz + ((outSz % hashSz) != 0) > 255` check three lines below. wolfcrypt/src/kdf.c: delete the two WC_HASH_TYPE_MD5_SHA guards in wc_PRF / wc_PRF_TLS -- they were a domain error (that arg is wc_MACAlgorithm, where WC_HASH_TYPE_MD5_SHA == 9 == sm3_mac, so the guard blocked SM3, not MD5-SHA), and the hmac.c reject is the correct layer. wolfcrypt/src/evp.c: drop the MD5 EVP mapping at FIPS >= 5 (evp.c is out of boundary, so the version arm is live and correct here). tests/api/test_kdf.c: derive secLen from MAX_PRF_HALF rather than hardcoding 521/261 -- MAX_PRF_HALF is config-dependent (516 under HAVE_FFDHE_8192, 388 under FFDHE_6144, else 260), so the hardcoded value made the BUFFER_E expectation config-dependent.
Before creating any new configure files (.conf) read the CONF_FILES_README.md