Add configure option to disable testing key exchange methods
If this is used, the functionality to set a private key/value/seed for key exchange methods is removed (including from the interface to avoid accidentally forgetting to wrap implementations and uses of set_seed()). The set_seed() method is assigned outside the INIT() macro to avoid potentially undefined behavior (preprocessing directives in macro arguments). The test done by the crypto tester is a simple functionality test.
This commit is contained in:
@@ -70,6 +70,7 @@ ARG_WITH_SET([mpz_powm_sec], [yes], [use the more side-channel resistant
|
||||
ARG_WITH_SET([dev-headers], [no], [install strongSwan development headers to directory.])
|
||||
ARG_WITH_SET([printf-hooks], [auto], [force the use of a specific printf hook implementation (auto, builtin, glibc, vstr).])
|
||||
ARG_WITH_SET([rubygemdir], ["gem environment gemdir"], [path to install ruby gems to])
|
||||
ARG_WITH_SET([testable-ke], [yes], [make key exchange implementations testable by providing a set_seed() method])
|
||||
|
||||
if test -n "$PKG_CONFIG"; then
|
||||
systemdsystemunitdir_default=$($PKG_CONFIG --variable=systemdsystemunitdir systemd)
|
||||
@@ -1351,6 +1352,10 @@ if test x$unwind_backtraces = xtrue; then
|
||||
AC_SUBST(UNWINDLIB)
|
||||
fi
|
||||
|
||||
if test "x$testable_ke" = xyes; then
|
||||
AC_DEFINE([TESTABLE_KE], [1], [Define to 1 if key exchange methods should be testable.])
|
||||
fi
|
||||
|
||||
AM_CONDITIONAL(USE_DEV_HEADERS, [test "x$dev_headers" != xno])
|
||||
if test x$dev_headers = xyes; then
|
||||
dev_headers="$includedir/strongswan"
|
||||
|
||||
Reference in New Issue
Block a user