botan: Make RNG types configurable

This allows for usage of ESDM or jitterentropy as Botan RNG without
patching strongSwan.

Signed-off-by: Markus Theil <[email protected]>
This commit is contained in:
Markus Theil
2026-04-13 15:12:31 +02:00
committed by Tobias Brunner
parent 0d4a8cc9ba
commit fdd06d99ec
2 changed files with 20 additions and 5 deletions
+12
View File
@@ -4,3 +4,15 @@ charon.plugins.botan.internal_rng_only = no
If enabled, only Botan's internal RNG will be used throughout the plugin.
Otherwise, and if supported by Botan, rng_t implementations provided by
other loaded plugins will be used as RNG.
charon.plugins.botan.rng.strong = user-threadsafe
Name of the Botan RNG used for RNG_STRONG and RNG_WEAK quality.
Name of the Botan RNG instance to use for RNG_STRONG and RNG_WEAK quality
(e.g. user, user-threadsafe or system).
charon.plugins.botan.rng.true = system
Name of the Botan RNG used for RNG_TRUE quality.
Name of the Botan RNG instance to use for RNG_TRUE quality (e.g. user,
user-threadsafe or system).
+8 -5
View File
@@ -372,7 +372,7 @@ bool botan_dh_key_derivation(botan_privkey_t key, chunk_t pub, chunk_t *secret)
*/
const char *botan_map_rng_quality(rng_quality_t quality)
{
const char *rng_name;
const char *rng_name_default, *setting;
switch (quality)
{
@@ -385,18 +385,21 @@ const char *botan_map_rng_quality(rng_quality_t quality)
* with leak-detective (lots of reports of frees of unknown memory)
* there is a fallback to the default */
#ifdef BOTAN_TARGET_OS_HAS_THREADS
rng_name = "user-threadsafe";
rng_name_default = "user-threadsafe";
#else
rng_name = "user";
rng_name_default = "user";
#endif
setting = "strong";
break;
case RNG_TRUE:
rng_name = "system";
rng_name_default = "system";
setting = "true";
break;
default:
return NULL;
}
return rng_name;
return lib->settings->get_str(lib->settings, "%s.plugins.botan.rng.%s",
(char*)rng_name_default, lib->ns, setting);
}
#ifdef HAVE_BOTAN_RNG_INIT_CUSTOM