openssl: Use a longer key to test/initialize HMAC instances
OpenSSL enforces a minimum of 14 bytes (112 bits) on the key size when used in FIPS-mode (as required by SP 800-131A). So by using an empty string, instantiation always failed. 32 bytes (256 bits) should be safe for now. Closes strongswan/strongswan#557
This commit is contained in:
@@ -100,8 +100,9 @@ METHOD(mac_t, set_key, bool,
|
|||||||
private_mac_t *this, chunk_t key)
|
private_mac_t *this, chunk_t key)
|
||||||
{
|
{
|
||||||
if (!key.ptr)
|
if (!key.ptr)
|
||||||
{ /* HMAC_Init_ex() won't reset the key if a NULL pointer is passed */
|
{ /* HMAC_Init_ex() won't reset the key if a NULL pointer is passed,
|
||||||
key = chunk_from_str("");
|
* use a lenghty string in case there is a limit in FIPS-mode */
|
||||||
|
key = chunk_from_str("00000000000000000000000000000000");
|
||||||
}
|
}
|
||||||
return reset(this, key);
|
return reset(this, key);
|
||||||
}
|
}
|
||||||
@@ -188,7 +189,7 @@ static mac_t *hmac_create(hash_algorithm_t algo)
|
|||||||
#endif
|
#endif
|
||||||
|
|
||||||
/* make sure the underlying hash algorithm is supported */
|
/* make sure the underlying hash algorithm is supported */
|
||||||
if (!set_key(this, chunk_from_str("")))
|
if (!set_key(this, chunk_empty))
|
||||||
{
|
{
|
||||||
destroy(this);
|
destroy(this);
|
||||||
return NULL;
|
return NULL;
|
||||||
|
|||||||
Reference in New Issue
Block a user